EL PASSO: Privacy-preserving, Asynchronous Single Sign-On

02/24/2020
by   Zhiyi Zhang, et al.
0

We introduce EL PASSO, a privacy-preserving, asynchronous Single Sign-On (SSO) system. It enables personal authentication while protecting users' privacy against both identity providers and relying parties, and allows selective attribute disclosure. EL PASSO is based on anonymous credentials, yet it supports users' accountability. Selected authorities may recover the identity of allegedly misbehaving users, and users can prove properties about their identity without revealing it in the clear. EL PASSO does not require specific secure hardware or a third party (other than existing participants in SSO). The generation and use of authentication credentials are asynchronous, allowing users to sign on when identity providers are temporarily unavailable. We evaluate EL PASSO in a distributed environment and prove its low computational cost, yielding faster sign-on operations than OIDC from a regular laptop, one-second user-perceived latency from a low-power device, and scaling to more than 50 sign-on operations per second at a relying party using a single 4-core server in the cloud.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/03/2021

Exploring Privacy Implications in OAuth Deployments

Single sign-on authentication systems such as OAuth 2.0 are widely used ...
research
10/20/2021

UPPRESSO: Untraceable and Unlinkable Privacy-PREserving Single Sign-On Services

Single sign-on (SSO) allows a user to maintain only the credential at th...
research
12/14/2022

"I Knew It Was Me": Understanding Users' Interaction with Login Notifications

Login notifications are intended to inform users about recent sign-ins a...
research
03/28/2019

An Approach to Identity Management in Clouds without Trusted Third Parties

The management of sensitive data, including identity management (IDM), i...
research
05/30/2023

Accountable authentication with privacy protection: The Larch system for universal login

Credential compromise is hard to detect and hard to mitigate. To address...
research
12/08/2020

On Aadhaar Identity Management System

A unique identification for citizens can lead to effective governance to...
research
07/27/2023

LinkDID: A Privacy-Preserving, Sybil-Resistant and Key-Recoverable Decentralized Identity Scheme

Decentralized identity mechanisms endeavor to endow users with complete ...

Please sign up or login with your details

Forgot password? Click here to reset