MISO: Legacy-compatible Privacy-preserving Single Sign-on using Trusted Execution Environments

被引:0
|
作者
Xu, Rongwu [1 ]
Yang, Sen [2 ]
Zhang, Fan [2 ]
Fang, Zhixuan [1 ,3 ]
机构
[1] Tsinghua Univ, Beijing, Peoples R China
[2] Yale Univ, New Haven, CT 06520 USA
[3] Shanghai Qi Zhi Inst, Shanghai, Peoples R China
关键词
IDENTITY;
D O I
10.1109/EuroSP57164.2023.00029
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Single sign-on (SSO) allows users to authenticate to third-party applications through a central identity provider. Despite their wide adoption, deployed SSO systems suffer from privacy problems such as user tracking by the identity provider. While numerous solutions have been proposed by academic papers, none were adopted because they require modifying identity providers, a significant adoption barrier in practice. Solutions do get deployed, however, fail to eliminate major privacy issues. Leveraging Trusted Execution Environments (TEEs), we propose MISO, the first privacy-preserving SSO system that is completely compatible with existing identity providers (such as Google and Facebook). This means MISO can be easily integrated into existing SSO ecosystem today and benefit end users. MISO also enables new functionality that standard SSO cannot offer: MISO allows users to leverage multiple identity providers in a single SSO workflow, potentially in a threshold fashion, to better protect user accounts. We fully implemented MISO based on Intel SGX. Our evaluation shows that MISO can handle high user concurrency with practical performance.
引用
收藏
页码:352 / 372
页数:21
相关论文
共 37 条
  • [1] PriSign, A Privacy-Preserving Single Sign-On System for Cloud Environments
    Shi, Rui
    Yang, Yang
    Xie, Huiqin
    Feng, Huamin
    Shi, Guozhen
    Zhang, Jianyi
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (02):
  • [2] Decentralized, Privacy-Preserving, Single Sign-On
    Mir, Omid
    Roland, Michael
    Mayrhofer, Rene
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [3] A Framework for Privacy-Preserving Genomic Data Analysis Using Trusted Execution Environments
    Asvadishirehjini, Aref
    Kantarcioglu, Murat
    Malin, Bradley
    [J]. 2020 SECOND IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2020), 2020, : 138 - 147
  • [4] Ticket Transparency: Accountable Single Sign-On with Privacy-Preserving Public Logs
    Chu, Dawei
    Lin, Jingqiang
    Li, Fengjun
    Zhang, Xiaokun
    Wang, Qiongxiao
    Liu, Guangqi
    [J]. SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM, PT I, 2019, 304 : 511 - 531
  • [5] Enhanced Multi-Party Privacy-Preserving Record Linkage Using Trusted Execution Environments
    Han, Shumin
    Shen, Kuixing
    Shen, Derong
    Wang, Chuang
    [J]. MATHEMATICS, 2024, 12 (15)
  • [6] Privacy-preserving Web single sign-on: Formal security analysis and design
    Schmitz, Guido
    [J]. IT-INFORMATION TECHNOLOGY, 2022, 64 (1-2): : 43 - 48
  • [7] A Privacy-Preserving Scheme for Smart Grid Using Trusted Execution Environment
    Akguen, Mete
    Soykan, Elif Ustundag
    Soykan, Gurkan
    [J]. IEEE ACCESS, 2023, 11 : 9182 - 9196
  • [8] Privacy-preserving Payment Channel Networks using Trusted Execution Environment
    Li, Peng
    Luo, Xiaofei
    Miyazaki, Toshiaki
    Guo, Song
    [J]. ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,
  • [9] Privacy-preserving genotype imputation in a trusted execution environment
    Dokmai, Natnatee
    Kockan, Can
    Zhu, Kaiyuan
    Wang, XiaoFeng
    Sahinalp, S. Cenk
    Cho, Hyunghoon
    [J]. CELL SYSTEMS, 2021, 12 (10) : 983 - +
  • [10] PubSub-SGX: Exploiting Trusted Execution Environments for Privacy-Preserving Publish/Subscribe Systems
    Arnautov, Sergei
    Brito, Andrey
    Felber, Pascal
    Fetzer, Christof
    Gregor, Franz
    Krahn, Robert
    Ozga, Wojciech
    Martin, Andre
    Schiavoni, Valerio
    Silva, Fabio
    Tenorio, Marcus
    Thummel, Nikolaus
    [J]. 2018 IEEE 37TH INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS), 2018, : 123 - 132