Credential Transparency System

被引:1
|
作者
Chase, Melissa [1 ]
Fuchsbauer, Georg [2 ]
Ghosh, Esha [1 ]
Plouviez, Antoine [3 ]
机构
[1] Microsoft Res, Redmond, WA 98052 USA
[2] TU Wien, Vienna, Austria
[3] ENS INRIA, Paris, France
关键词
Credential transparency; SSO; anonymous credentials; zero-knowledge sets; accumulators; zero-knowledge proofs; SIGNATURES; SECURITY;
D O I
10.1007/978-3-031-14791-3_14
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A major component of the entire digital identity ecosystem are verifiable credentials. However, for users to have complete control and privacy of their digital credentials, they need to be able to store and manage these credentials and associated cryptographic key material on their devices. This approach has severe usability challenges including portability across devises. A more practical solution is for the users to trust a more reliable and available service to manage credentials on their behalf, such as in the case of Single Sign-On (SSO) systems and identity hubs. But the obvious downside of this design is the immense trust that the users need to place on these service providers. In this work, we introduce and formalize a credential transparency system (CTS) framework that adds strong transparency guarantees to a credential management system while preserving privacy and usability features of the system. CTS ensures that if a service provider presents any credential to an honest verifier on behalf of a user, and the user's device tries to audit all the shows presented on the user's behalf, the service provider will not be able to drop or modify any show information without getting caught. We define CTS to be a general framework that is compatible with a wide range of credential management systems including SSO and anonymous credential systems. We also provide a CTS instantiation and prove its security formally.
引用
收藏
页码:313 / 335
页数:23
相关论文
共 50 条
  • [21] A cryptographic credential based access control mechanism for industrial control system
    Shi, Sha
    Wen, Qiaoyan
    International Journal of Advancements in Computing Technology, 2012, 4 (07) : 152 - 158
  • [22] Efficient Proofs of Attributes in Pairing-Based Anonymous Credential System
    Sudarsono, Amang
    Nakanishi, Toru
    Funabiki, Nobuo
    PRIVACY ENHANCING TECHNOLOGIES, 2011, 6794 : 246 - 263
  • [23] CMM: Credential migration management system based on trusted computing in CGSP
    Jin H.
    Yi C.
    Frontiers of Computer Science in China, 2007, 1 (2): : 200 - 207
  • [24] A Concept for Grid Credential Lifecycle Management and Heuristic Credential Abuse Detection
    Kunz, Christopher
    Wiebelitz, Jan
    Piger, Stefan
    Grimm, Christian
    ICNS: 2009 FIFTH INTERNATIONAL CONFERENCE ON NETWORKING AND SERVICES, 2009, : 505 - 510
  • [25] A Concept for Grid Credential Lifecycle Management and Heuristic Credential Abuse Detection
    Kunz, Christopher
    Wiebelitz, Jan
    Piger, Stefan
    Grimm, Christian
    EIGHTH INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED COMPUTING, PROCEEDINGS, 2009, : 245 - 248
  • [26] ATRC: An Anonymous Traceable and Revocable Credential System Using Blockchain for VANETs
    Liu, Yang
    He, Debiao
    Luo, Min
    Wang, Huaqun
    Liu, Qin
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2024, 73 (02) : 2482 - 2494
  • [27] On-Line E-Wallet System with Decentralized Credential Keepers
    Stig Frode Mjølsnes
    Chunming Rong
    Mobile Networks and Applications, 2003, 8 : 87 - 99
  • [28] Controlling owner and transparency: Information transparency and disclosure rankings system
    Xu, Hao-Feng
    Lin, Mei-Feng
    AFRICAN JOURNAL OF BUSINESS MANAGEMENT, 2011, 5 (29): : 11589 - 11598
  • [29] A Security Credential Management System for V2X Communications
    Brecht, Benedikt
    Therriault, Dean
    Weimerskirch, Andre
    Whyte, William
    Kumar, Virendra
    Hehn, Thorsten
    Goudy, Roy
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2018, 19 (12) : 3850 - 3871
  • [30] A Security Credential Management System for V2V Communications
    Whyte, William
    Weimerskirch, Andre
    Kumar, Virendra
    Hehn, Thorsten
    2013 IEEE VEHICULAR NETWORKING CONFERENCE (VNC), 2013, : 1 - 8