首页> 外文OA文献 >Minimizing Information Disclosure in Authentication Transactions with Attribute-Based Credentials
【2h】

Minimizing Information Disclosure in Authentication Transactions with Attribute-Based Credentials

机译:使用基于属性的凭据将身份验证事务中的信息披露降至最低

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

With the rise of information and communication technologies, the need to authenticate individuals to authorize their access to online services or to hold them accountable for their actions has induced the development of a wide variety of authentication systems. Although for determining sole authorization it is mostly sufficient to verify an individual's unlinkable non-identifying properties, virtually all of these systems involve the disclosure of personally identifiable information. This raises numerous security and privacy issues because an uncontrolled dissemination of these data makes individuals vulnerable to identity theft, financial fraud, profiling, monitoring, discredit, or embarrassment. These issues are greatly amplified by technologies that ease data collection, aggregation, analysis, and distribution, by legislation that stipulates the retention of communication data, and by increasingly frequent data breaches where vast amounts of (personal) data records are compromised.Although there exist cryptographic techniques---namely anonymous credentials---that allow individuals to authenticate in a secure and privacy-preserving manner without having to disclose any personal or identifying information, there are no authentication systems that utilize these techniques. While the reasons for this are manifold, there are two major technical inhibitors. On the one hand, the available implementations are very complex and only usable with cryptographic expert knowledge, and, on the other hand, the cryptographic mechanisms alone do not suffice for building an authentication system.In this work, we overcome these inhibitors and present a functional authentication system on the basis of anonymous credentials that is usable without expert knowledge. With our system, service providers can formulate authentication requirements in terms of the minimal properties that users' certified attributes must have, and users can prove that their attributes fulfill these properties without disclosing their values. In situations where accountability is required, users can disclose personally identifying information such that it is only accessible if they misbehave or cause damage---which allows honest users to remain unidentifiable.The main building block of our system is a language framework with formal semantics for expressing the service providers' minimal authentication requirements as well as users' cryptographically backed claims in terms of attribute-based credentials. The framework abstracts away from cryptographic details and focuses solely on easily intelligible concepts. We also provide algorithms for transforming claims expressed in our language into the complex input specifications of the cryptographic implementations---which significantly eases their use for application developers---and for verifying claims with respect to a given policy. On the basis of these results, we develop a full-fledged prototype implementation to prove the concept and its efficiency: we show that our algorithms entail negligible computational overhead with respect to the time needed to generate and verify the cryptographic evidence that supports users' claims.Our system allows for reducing the information that is disclosed in authentication transactions to the necessary minimum and thereby mitigates the aforementioned issues of excessive data release. Its use is advantageous for both users and service providers in that the former benefit from privacy preservation and the latter from reducing the risks associated with holding large sets of sensitive personal information.
机译:随着信息和通信技术的兴起,对个人进行身份验证以授权其访问在线服务或要求其对自己的行为负责的需求引发了各种各样的身份验证系统的发展。尽管对于确定唯一授权,足以验证一个人的不可链接的非身份属性就足够了,但实际上所有这些系统都涉及公开个人身份信息。这引起了许多安全和隐私问题,因为这些数据的不受控制的传播使个人容易遭受身份盗窃,财务欺诈,分析,监视,信誉下降或尴尬的困扰。简化数据收集,汇总,分析和分发的技术,规定保留通信数据的法规以及越来越多的数据泄露事件(危害大量(个人)数据记录)的情况大大加剧了这些问题。密码技术-即匿名凭据-使个人能够以安全和隐私保护的方式进行身份验证,而不必透露任何个人信息或身份信息,没有使用这些技术的身份验证系统。尽管造成这种情况的原因多种多样,但有两个主要的技术障碍。一方面,可用的实现非常复杂,只有在具备加密专家知识的情况下才能使用,另一方面,仅加密机制不足以构建身份验证系统。在这项工作中,我们克服了这些障碍并提出了一个解决方案。基于匿名凭证的功能认证系统,无需专家知识即可使用。使用我们的系统,服务提供商可以根据用户的认证属性必须具有的最小属性来制定身份验证要求,并且用户可以证明其属性满足这些属性而不会泄露其值。在需要问责的情况下,用户可以公开个人身份信息,以便只有在他们的行为不当或造成损害时才可以访问这些信息,这使诚实的用户无法识别。我们系统的主要组成部分是具有正式语义的语言框架用于表示服务提供商的最低身份验证要求以及用户基于属性的凭据的加密后的主张。该框架从加密细节中抽象出来,仅专注于易于理解的概念。我们还提供了一些算法,可将用我们的语言表达的声明转换为加密实现的复杂输入规范-极大地简化了它们对应用程序开发人员的使用-并用于验证针对给定策略的声明。根据这些结果,我们开发了一个完整的原型实现来证明这一概念及其效率:我们证明,就生成和验证支持用户主张的密码证据所需的时间而言,我们的算法所需的计算开销可忽略不计我们的系统允许将身份验证事务中公开的信息减少到必要的最低限度,从而减轻上述过度释放数据的问题。它的使用对用户和服务提供商都是有利的,因为前者受益于隐私保护,后者受益于减少与保存大量敏感个人信息相关的风险。

著录项

  • 作者

    Preiss Franz Stefan;

  • 作者单位
  • 年度 2012
  • 总页数
  • 原文格式 PDF
  • 正文语种 nl
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号