Credential Transparency System

被引:1
|
作者
Chase, Melissa [1 ]
Fuchsbauer, Georg [2 ]
Ghosh, Esha [1 ]
Plouviez, Antoine [3 ]
机构
[1] Microsoft Res, Redmond, WA 98052 USA
[2] TU Wien, Vienna, Austria
[3] ENS INRIA, Paris, France
关键词
Credential transparency; SSO; anonymous credentials; zero-knowledge sets; accumulators; zero-knowledge proofs; SIGNATURES; SECURITY;
D O I
10.1007/978-3-031-14791-3_14
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A major component of the entire digital identity ecosystem are verifiable credentials. However, for users to have complete control and privacy of their digital credentials, they need to be able to store and manage these credentials and associated cryptographic key material on their devices. This approach has severe usability challenges including portability across devises. A more practical solution is for the users to trust a more reliable and available service to manage credentials on their behalf, such as in the case of Single Sign-On (SSO) systems and identity hubs. But the obvious downside of this design is the immense trust that the users need to place on these service providers. In this work, we introduce and formalize a credential transparency system (CTS) framework that adds strong transparency guarantees to a credential management system while preserving privacy and usability features of the system. CTS ensures that if a service provider presents any credential to an honest verifier on behalf of a user, and the user's device tries to audit all the shows presented on the user's behalf, the service provider will not be able to drop or modify any show information without getting caught. We define CTS to be a general framework that is compatible with a wide range of credential management systems including SSO and anonymous credential systems. We also provide a CTS instantiation and prove its security formally.
引用
收藏
页码:313 / 335
页数:23
相关论文
共 50 条
  • [1] Personal identification credential system
    Jackson, PA
    Cantrell, T
    Page, L
    Cudlitz, S
    Higgins, R
    Biometric Technology for Human Identification II, 2005, 5779 : 324 - 335
  • [2] An efficient anonymous credential system
    Akagi, Norio
    Manabe, Yoshifumi
    Okamoto, Tatsuaki
    FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, 2008, 5143 : 272 - 286
  • [3] Accountable credential management system for vehicular communication
    Khan, Salabat
    Zhu, Liehuang
    Yu, Xiaoyan
    Zhang, Zijian
    Rahim, Mussadiq Abdul
    Khan, Maqbool
    Du, Xiaojiang
    Guizani, Mohsen
    VEHICULAR COMMUNICATIONS, 2020, 25
  • [4] Security analysis and fix of an anonymous credential system
    Yang, YJ
    Bao, F
    Deng, RH
    INFORMATION SECURITY AND PRIVACY, PROCEEDINGS, 2005, 3574 : 537 - 547
  • [5] THE CREDENTIAL ELITE AND THE CREDENTIAL ROUTE TO SUCCESS
    KINGSTON, PW
    TEACHERS COLLEGE RECORD, 1981, 82 (04): : 589 - 600
  • [6] A credential-based system for the anonymous delegation of rights
    Demuynck, Liesje
    De Decker, Bart
    Joosen, Wouter
    NEW APPROACHES FOR SECURITY, PRIVACY AND TRUST IN COMPLEX ENVIRONMENTS, 2007, 232 : 169 - +
  • [7] An anonymous credential system and a privacy-aware PKI
    Persiano, P
    Visconti, I
    INFORMATION SECURITY AND PRIVACY, PROCEEDINGS, 2003, 2727 : 27 - 38
  • [8] A Blockchain Based Credential Verification System using IPFS
    Ambast, Swatesh Kumar
    Sumesh, T. A.
    2022 IEEE 19TH INDIA COUNCIL INTERNATIONAL CONFERENCE, INDICON, 2022,
  • [9] A User-manageable Credential System based on Blockchain
    Hong S.
    Kim H.
    Transactions of the Korean Institute of Electrical Engineers, 2022, 71 (01): : 210 - 217
  • [10] Voting Credential Management System for Electronic Voting Privacy
    Sarker, Arijet
    Byun, SangHyun
    Fan, Wenjun
    Psarakis, Maria
    Chang, Sang-Yoon
    2020 IFIP NETWORKING CONFERENCE AND WORKSHOPS (NETWORKING), 2020, : 594 - 598