Anonymous Single-Sign-On for n designated services with traceability

04/19/2018
by   Jinguang Han, et al.
0

Anonymous Single-Sign-On authentication schemes have been proposed to allow users to access a service protected by a verifier without revealing their identity which has become more important due to the introduction of strong privacy regulations. In this paper we describe a new approach whereby anonymous authentication to different verifiers is achieved via authorisation tags and pseudonyms. The particular innovation of our scheme is authentication can only occur between a user and its designated verifier for a service, and the verification cannot be performed by any other verifier. The benefit of this authentication approach is that it prevents information leakage of a user's service access information, even if the verifiers for these services collude which each other. Our scheme also supports a trusted third party who is authorised to de-anonymise the user and reveal her whole services access information if required. Furthermore, our scheme is lightweight because it does not rely on attribute or policy-based signature schemes to enable access to multiple services. The scheme's security model is given together with a security proof, an implementation and a performance evaluation.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/19/2018

Anonymous Single Sign-on with Proxy Re-Verification

An anonymous Single Sign-On (ASSO) scheme allows users to access multipl...
research
06/26/2019

Smart Contract Federated Identity Management without Third Party Authentication Services

Federated identity management enables users to access multiple systems u...
research
08/08/2021

An Anonymous On-Street Parking Authentication Scheme via Zero-Knowledge Set Membership Proof

The amount of information generated grows as more and more sensor and Io...
research
03/28/2019

An Approach to Identity Management in Clouds without Trusted Third Parties

The management of sensitive data, including identity management (IDM), i...
research
01/26/2023

LemonLDAP::NG – A Full AAA Free Open Source WebSSO Solution

Nowadays, security is becoming a major issue and concern. More and more ...
research
05/30/2023

Accountable authentication with privacy protection: The Larch system for universal login

Credential compromise is hard to detect and hard to mitigate. To address...
research
09/28/2022

That Depends – Assessing User Perceptions of Authentication Schemes across Contexts of Use

Choosing authentication schemes for a specific purpose is challenging fo...

Please sign up or login with your details

Forgot password? Click here to reset