skip to main content
10.1145/2994620.2994637acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
short-paper
Open Access

UnlimitID: Privacy-Preserving Federated Identity Management using Algebraic MACs

Published:24 October 2016Publication History

ABSTRACT

UnlimitID is a method for enhancing the privacy of commodity OAuth and applications such as OpenID Connect, using anonymous attribute-based credentials based on algebraic Message Authentication Codes (aMACs). OAuth is one of the most widely used protocols on the Web, but it exposes each of the requests of a user for data by each relying party (RP) to the identity provider (IdP). Our approach allows for the creation of multiple persistent and unlinkable pseudo-identities and requires no change in the deployed code of relying parties, only in identity providers and the client.

References

  1. M. Chase, S. Meiklejohn, and G. Zaverucha. Algebraic MACs and keyed-verification anonymous credentials. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, pages 1205--1216, 2014. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. A. Dey and S. Weis. Pseudoid: Enhancing privacy in federated login. HotPETS Workshop, 2010.Google ScholarGoogle Scholar
  3. D. Fett, R. Küsters, and G. Schmitz. SPRESSO: A secure, privacy-respecting single sign-on system for the Web. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pages 1358--1369. ACM, 2015. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. D. Fett, R. Küsters, and G. Schmitz. A comprehensive formal security analysis of OAuth 2.0. 2016. arXiv preprint arXiv:1601.01229. Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. H. Halpin and B. Cook. Federated identity as capabilities. In Annual Privacy Forum, pages 125--139, 2012. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. D. Hardt. The OAuth 2.0 authorization framework, 2012. https://tools.ietf.org/html/rfc6749.Google ScholarGoogle Scholar
  7. E. Kasper. Fast elliptic curve cryptography in openssl. In Financial Cryptography and Data Security - FC 2011 Workshops, pages 27--39, 2011. Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. J. Maheswaran, D. Jackowitz, E. Zhai, D. I. Wolinsky, and B. Ford. Building privacy-preserving cryptographic credentials from federated online identities. In Proceedings of the ACM Conference on Data and Application Security and Privacy, pages 3--13. ACM, 2016. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. N. Sakimura, J. Bradley, M. Jones, B. de Medeiros, and C. Mortimore. OpenID Connect Core 1.0, 2014. http://openid.net/specs/openid-connect-core-1_0.html.Google ScholarGoogle Scholar

Index Terms

  1. UnlimitID: Privacy-Preserving Federated Identity Management using Algebraic MACs

            Recommendations

            Comments

            Login options

            Check if you have access through your login credentials or your institution to get full access on this article.

            Sign in

            PDF Format

            View or Download as a PDF file.

            PDF

            eReader

            View online with eReader.

            eReader