首页> 外文会议>International Conference on Information Security and Cryptology >P2A: Privacy Preserving Anonymous Authentication Based on Blockchain and SGX
【24h】

P2A: Privacy Preserving Anonymous Authentication Based on Blockchain and SGX

机译:P2A:基于区块链和SGX的隐私保留匿名身份验证

获取原文

摘要

Modern Identify-as-a-Service solutions solve the problems of burdensome user credential management and non-uniform security strength, by introducing an Identity Provider (IdP) that holds the users' identities and grants a user one-time access tokens when he/she tries to login to different online applications (known as the Relying Parties, RPs). However, the non-negligible problem of privacy leakage during authentication largely remains unattended. In this paper, we propose a Privacy Preserving Anonymous Authentication Scheme (P2A) with Blockchain and Intel Software Guard Extensions (SGX). The IdP in P2A manages the users' identities by issuing different kinds of transactions in the Blockchain, covering the registration, update, freeze/thaw, and deletion of identities. When the user wants to login to an RP, instead of asking for an one-time token from the IdP, he can generate an identity proof locally with SGX and login to the RP with an RP-specific pseudonym (PN). By resorting to the Blockchain, the RP will be convinced that the PN is associated with some registered identity on IdP and specific attributes of the user are satisfactory, without obtaining the real identity and raw attributes of the user. In this way, privacy leakages to the IdP and RPs are eliminated. P2A has a few exciting new features and security analysis shows it can resist various attacks even under strict assumptions.
机译:现代识别的AS-Service解决方案通过引入拥有用户身份的身份提供者(IDP)来解决繁琐的用户凭证管理和非统一安全实力的问题,并在他/时授予用户一次性访问令牌她试图登录不同的在线申请(称为依赖派对,RPS)。但是,在认证期间的不可忽视的隐私问题很大程度上仍然无人看管。在本文中,我们提出了一种隐私保留具有区块链和英特尔软件保护扩展(SGX)的匿名认证方案(P2A)。 P2A中的IDP通过在区块链中发出不同类型的事务来管理用户的身份,涵盖注册,更新,冻结/解冻和删除身份。当用户想要登录RP时,而不是从IDP询问一次性令牌时,他可以使用SGX在本地生成身份证明,并使用RP特定的假名(PN)登录RP。通过诉诸区间,RP将相信PN与IDP上的一些注册标识相关联,用户的特定属性是令人满意的,而无需获得用户的真实身份和原始属性。以这种方式,消除了IDP和RPS的隐私泄漏。 P2A有一些令人兴奋的新功能,安全分析表明,即使在严格的假设下也可以抵抗各种攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号