Building Privacy-Preserving Cryptographic Credentials from Federated Online Identities
Title | Building Privacy-Preserving Cryptographic Credentials from Federated Online Identities |
Publication Type | Conference Paper |
Year of Publication | 2016 |
Authors | Maheswaran, John, Jackowitz, Daniel, Zhai, Ennan, Wolinsky, David Isaac, Ford, Bryan |
Conference Name | Proceedings of the Sixth ACM Conference on Data and Application Security and Privacy |
Date Published | March 2016 |
Publisher | ACM |
Conference Location | New York, NY, USA |
ISBN Number | 978-1-4503-3935-3 |
Keywords | anonymity, anonymous communication, anonymous messaging, authentication, Human Behavior, Identity management, Metrics, network accountability, online social networks, pubcrawl, Resiliency, Scalability |
Abstract | Federated identity providers, e.g., Facebook and PayPal, offer a convenient means for authenticating users to third-party applications. Unfortunately such cross-site authentications carry privacy and tracking risks. For example, federated identity providers can learn what applications users are accessing; meanwhile, the applications can know the users' identities in reality. This paper presents Crypto-Book, an anonymizing layer enabling federated identity authentications while preventing these risks. Crypto-Book uses a set of independently managed servers that employ a (t,n)-threshold cryptosystem to collectively assign credentials to each federated identity (in the form of either a public/private keypair or blinded signed messages). With the credentials in hand, clients can then leverage anonymous authentication techniques such as linkable ring signatures or partially blind signatures to log into third-party applications in an anonymous yet accountable way. We have implemented a prototype of Crypto-Book and demonstrated its use with three applications: a Wiki system, an anonymous group communication system, and a whistleblower submission system. Crypto-Book is practical and has low overhead: in a deployment within our research group, Crypto-Book group authentication took 1.607s end-to-end, an overhead of 1.2s compared to traditional non-privacy-preserving federated authentication. |
URL | https://dl.acm.org/doi/10.1145/2857705.2857725 |
DOI | 10.1145/2857705.2857725 |
Citation Key | maheswaran_building_2016 |