Credential Transparency System

被引:1
|
作者
Chase, Melissa [1 ]
Fuchsbauer, Georg [2 ]
Ghosh, Esha [1 ]
Plouviez, Antoine [3 ]
机构
[1] Microsoft Res, Redmond, WA 98052 USA
[2] TU Wien, Vienna, Austria
[3] ENS INRIA, Paris, France
关键词
Credential transparency; SSO; anonymous credentials; zero-knowledge sets; accumulators; zero-knowledge proofs; SIGNATURES; SECURITY;
D O I
10.1007/978-3-031-14791-3_14
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A major component of the entire digital identity ecosystem are verifiable credentials. However, for users to have complete control and privacy of their digital credentials, they need to be able to store and manage these credentials and associated cryptographic key material on their devices. This approach has severe usability challenges including portability across devises. A more practical solution is for the users to trust a more reliable and available service to manage credentials on their behalf, such as in the case of Single Sign-On (SSO) systems and identity hubs. But the obvious downside of this design is the immense trust that the users need to place on these service providers. In this work, we introduce and formalize a credential transparency system (CTS) framework that adds strong transparency guarantees to a credential management system while preserving privacy and usability features of the system. CTS ensures that if a service provider presents any credential to an honest verifier on behalf of a user, and the user's device tries to audit all the shows presented on the user's behalf, the service provider will not be able to drop or modify any show information without getting caught. We define CTS to be a general framework that is compatible with a wide range of credential management systems including SSO and anonymous credential systems. We also provide a CTS instantiation and prove its security formally.
引用
收藏
页码:313 / 335
页数:23
相关论文
共 50 条
  • [31] Safeguarding Academic Accounts and Resources with the University Credential Abuse Auditing System
    Zhang, Jing
    Berthier, Robin
    Rhee, Will
    Bailey, Michael
    Pal, Partha
    Jahanian, Farnam
    Sanders, William H.
    2012 42ND ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2012,
  • [32] On-line e-wallet system with decentralized credential keepers
    Mjolsnes, SF
    Rong, CM
    MOBILE NETWORKS & APPLICATIONS, 2003, 8 (01): : 87 - 99
  • [33] Implementing credential networks
    Jonczy, Jacek
    Haenni, Rolf
    TRUST MANAGEMENT, PROCEEDINGS, 2006, 3986 : 164 - 178
  • [34] The Exercise is Medicine® Credential
    Riebe, Deborah
    ACSMS HEALTH & FITNESS JOURNAL, 2012, 16 (02) : 29 - 30
  • [35] Foreign credential recognition
    Vogel, Lauren
    CANADIAN MEDICAL ASSOCIATION JOURNAL, 2011, 183 (08) : E470 - E470
  • [36] MLS A TRADE CREDENTIAL
    HOLE, C
    WILSON LIBRARY BULLETIN, 1991, 66 (01) : 8 - &
  • [37] Transparency, trust, and the patent system
    Karachalios, Konstantinos
    Elahi, Shirin
    JOURNAL OF INTELLECTUAL PROPERTY LAW & PRACTICE, 2009, 4 (11) : 809 - 814
  • [38] Monitoring System ensures Transparency
    不详
    BWK, 2011, 63 (11): : 66 - 68
  • [39] Towards User-Friendly Credential Transfer on Open Credential Platforms
    Kostiainen, Kari
    Asokan, N.
    Afanasyeva, Alexandra
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY (ACNS 2011), 2011, 6715 : 395 - 412
  • [40] OLI credential debuts
    不详
    LABORATORY MEDICINE, 2004, 35 (05) : 271 - 272