Concepts and languages for privacy-preserving attribute-based authentication

被引:12
|
作者
Camenisch, Jan [1 ]
Dubovitskaya, Maria [1 ,2 ]
Enderlein, Robert R. [1 ,2 ]
Lehmann, Anja [1 ]
Neven, Gregory [1 ]
Paquin, Christian [3 ]
Preiss, Franz-Stefan [1 ]
机构
[1] IBM Res Zurich, Saumerstr 4, CH-8803 Ruschlikon, Switzerland
[2] Swiss Fed Inst Technol, Dept Comp Sci, CH-8092 Zurich, Switzerland
[3] Microsoft Res Redmond, Redmond, WA 98052 USA
关键词
Authentication; Privacy; Data-minimization; Anonymous credentials; Digital credentials;
D O I
10.1016/j.jisa.2014.03.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Existing cryptographic realizations of privacy-friendly authentication mechanisms such as anonymous credentials, minimal disclosure tokens, self-blindable credentials, and group signatures vary largely in the features they offer and in how these features are realized. Some features such as revocation or de-anonymization even require the combination of several cryptographic protocols. The variety and complexity of the cryptographic protocols hinder the understanding and hence the adoption of these mechanisms in practical applications. They also make it almost impossible to change the underlying cryptographic algorithms once the application has been designed. In this paper, we aim to overcome these issues and simplify both the design and deployment of privacy-friendly authentication mechanisms. We define and unify the concepts and features of privacy-preserving attribute-based credentials (Privacy-ABCs), provide a language framework in XML schema, and present the API of a Privacy-ABC system that supports all the features we describe. Our language framework and API enable application developers to use Privacy-ABCs with all their features without having to consider the specifics of the underlying cryptographic algorithmsdsimilar to as they do today for digital signatures, where they do not need to worry about the particulars of the RSA and DSA algorithms either. (C) 2014 Elsevier Ltd. All rights reserved.
引用
收藏
页码:25 / 44
页数:20
相关论文
共 50 条
  • [1] A Privacy-Preserving Attribute-Based Authentication Scheme for Cloud Computing
    Huang, Chanying
    Wei, Songjie
    Yan, Kedong
    Zhang, Gongxuan
    Fu, Anmin
    [J]. 2018 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2018, : 260 - 265
  • [2] Attribute-Based Pseudonymity for Privacy-Preserving Authentication in Cloud Services
    Sucasas, Victor
    Mantas, Georgios
    Papaioannou, Maria
    Rodriguez, Jonathan
    [J]. IEEE TRANSACTIONS ON CLOUD COMPUTING, 2023, 11 (01) : 168 - 184
  • [3] Concepts Around Privacy-Preserving Attribute-Based Credentials Making Authentication with Anonymous Credentials Practical
    Camenisch, Jan
    [J]. PRIVACY AND IDENTITY MANAGEMENT FOR EMERGING SERVICES AND TECHNOLOGIES, 2014, 421 : 53 - 63
  • [4] A Privacy-Preserving Attribute-Based Authentication System for Mobile Health Networks
    Guo, Linke
    Zhang, Chi
    Sun, Jinyuan
    Fang, Yuguang
    [J]. IEEE TRANSACTIONS ON MOBILE COMPUTING, 2014, 13 (09) : 1927 - 1941
  • [5] PAAS: A Privacy-Preserving Attribute-based Authentication System for eHealth Networks
    Guo, Linke
    Zhang, Chi
    Sun, Jinyuan
    Fang, Yuguang
    [J]. 2012 IEEE 32ND INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS), 2012, : 224 - 233
  • [6] Privacy-Preserving Auditing for Attribute-Based Credentials
    Camenisch, Jan
    Lehmann, Anja
    Neven, Gregory
    Rial, Alfredo
    [J]. COMPUTER SECURITY - ESORICS 2014, PT II, 2014, 8713 : 109 - 127
  • [7] A Privacy-Preserving Attribute-Based Access Control Scheme
    Xu, Yang
    Zeng, Quanrun
    Wang, Guojun
    Zhang, Cheng
    Ren, Ju
    Zhang, Yaoxue
    [J]. SECURITY, PRIVACY, AND ANONYMITY IN COMPUTATION, COMMUNICATION, AND STORAGE (SPACCS 2018), 2018, 11342 : 361 - 370
  • [8] Distance-Bounding, Privacy-Preserving Attribute-Based Credentials
    Bosk, Daniel
    Bouget, Simon
    Buchegger, Sonja
    [J]. CRYPTOLOGY AND NETWORK SECURITY, CANS 2020, 2020, 12579 : 147 - 166
  • [9] Privacy-Preserving Electronic Ticket Scheme with Attribute-Based Credentials
    Han, Jinguang
    Chen, Liqun
    Schneider, Steve
    Treharne, Helen
    Wesemeyer, Stephan
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (04) : 1836 - 1849
  • [10] Constraints Validation in Privacy-Preserving Attribute-Based Access Control
    Oleshchuk, Vladimir
    [J]. 2015 IEEE 8TH INTERNATIONAL CONFERENCE ON INTELLIGENT DATA ACQUISITION AND ADVANCED COMPUTING SYSTEMS: TECHNOLOGY AND APPLICATIONS (IDAACS), VOLS 1-2, 2015, : 429 - 431