Visible to the public OLYMPUS: A distributed privacy-preserving identity management system

TitleOLYMPUS: A distributed privacy-preserving identity management system
Publication TypeConference Paper
Year of Publication2020
AuthorsMoreno, R. T., Rodríguez, J. G., López, C. T., Bernabe, J. B., Skarmeta, A.
Conference Name2020 Global Internet of Things Summit (GIoTS)
Date PublishedJune 2020
PublisherIEEE
ISBN Number978-1-7281-6728-2
Keywordsblanket surveillance, Computer crime, computer network security, cryptography, cybercrimes, data privacy, digital identities, distributed privacy-preserving identity management system, GDPR, Human Behavior, Identity management, identity providers, Internet of Things, IoT, OLYMPUS H2020 EU project, privacy, privacy enhancing technologies, Privacy-preserving, pubcrawl, resilience, Resiliency, Scalability, security, service providers
Abstract

Despite the latest initiatives and research efforts to increase user privacy in digital scenarios, identity-related cybercrimes such as identity theft, wrong identity or user transactions surveillance are growing. In particular, blanket surveillance that might be potentially accomplished by Identity Providers (IdPs) contradicts the data minimization principle laid out in GDPR. Hence, user movements across Service Providers (SPs) might be tracked by malicious IdPs that become a central dominant entity, as well as a single point of failure in terms of privacy and security, putting users at risk when compromised. To cope with this issue, the OLYMPUS H2020 EU project is devising a truly privacy-preserving, yet user-friendly, and distributed identity management system that addresses the data minimization challenge in both online and offline scenarios. Thus, OLYMPUS divides the role of the IdP among various authorities by relying on threshold cryptography, thereby preventing user impersonation and surveillance from malicious or nosy IdPs. This paper overviews the OLYMPUS framework, including requirements considered, the proposed architecture, a series of use cases as well as the privacy analysis from the legal point of view.

URLhttps://ieeexplore.ieee.org/document/9119663
DOI10.1109/GIOTS49054.2020.9119663
Citation Keymoreno_olympus_2020