首页> 外文会议>International conference on cryptology and network security >Towards Attribute-Based Credentials in the Cloud
【24h】

Towards Attribute-Based Credentials in the Cloud

机译:迈向云中基于属性的凭证

获取原文

摘要

Attribute-based credentials (ABCs, sometimes also anonymous credentials) are a core cryptographic building block of privacy-friendly authentication systems, allowing users to obtain credentials on attributes and prove possession of these credentials in an unlinkable fashion. Thereby, users have full control over which attributes the user wants to reveal to a third party while offering high authenticity guarantees to the receiver. Unfortunately, up to date, all known ABC systems require access to all attributes in the clear at the time of proving possession of a credential to a third party. This makes it hard to offer privacy-preserving identity management systems "as a service," as the user still needs specific key material and/or dedicated software locally, e.g., on his device. We address this gap by proposing a new cloud-based ABC system where a dedicated cloud service ("wallet") can present the users' credentials to a third-party without accessing the attributes in the clear. This enables new privacy-preserving applications of ABCs "in the cloud." This is achieved by carefully integrating proxy re-encryption with structure-preserving signatures and zero-knowledge proofs of knowledge. The user obtains credentials on his attributes (encrypted under his public key) and uploads them to the wallet, together with a specific re-encryption key. To prove a possession, the wallet re-encrypts the cipher-texts to the public key of the receiving third party and proves, in zero-knowledge, that all computations were done honestly. Thereby, the wallet never sees any user attribute in the clear. We show the practical efficiency of our scheme by giving concrete benchmarks of a prototype implementation.
机译:基于属性的凭证(ABC,有时也称为匿名凭证)是隐私友好型身份验证系统的核心密码构造块,允许用户获取属性凭证并以不可链接的方式证明拥有这些凭证。从而,用户可以完全控制用户想要向第三方揭示哪些属性,同时为接收者提供高真实性保证。不幸的是,迄今为止,所有已知的ABC系统都要求在证明拥有第三方凭据时明确地访问所有属性。由于用户仍然在本地(例如,在他的设备上)仍需要特定的密钥材料和/或专用软件,这使得难以提供“作为服务”的保护隐私的身份管理系统。我们通过提出一个新的基于云的ABC系统来解决此差距,在该系统中,专用的云服务(“钱包”)可以将用户的凭据提供给第三方,而无需访问明文属性。这使“云中” ABC的新的隐私保护应用程序成为可能。这是通过将代理重新加密与保留结构的签名和知识的零知识证明仔细集成而实现的。用户获取有关其属性的凭证(在其公共密钥下加密),并将其与特定的重新加密密钥一起上载到钱包。为了证明所有权,钱包将密文重新加密为接收方第三方的公钥,并以零知识证明所有计算都是诚实进行的。因此,钱包永远不会看到任何用户属性。通过给出原型实现的具体基准,我们展示了该方案的实际效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号