TEEvil: Identity Lease via Trusted Execution Environments

03/01/2019
by   Ivan Puddu, et al.
0

We investigate identity lease, a new type of service in which users lease their identities to third parties by providing them with full or restricted access to their online accounts or credentials. We discuss how identity lease could be abused to subvert the digital society, facilitating the spread of fake news and subverting electronic voting by enabling the sale of votes. We show that the emergence of Trusted Execution Environments and anonymous cryptocurrencies, for the first time, allows the implementation of such a lease service while guaranteeing fairness, plausible deniability and anonymity, therefore shielding its users and renters from prosecution. To show that such a service can be practically implemented, we build an example system that we call TEEvil leveraging Intel SGX and ZCash. Finally, we discuss defense mechanisms and challenges in the mitigation of identity lease services.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/05/2022

Identity Management through a global Discovery System based on Decentralized Identities

Digital identities today continue to be a company resource instead of be...
research
10/06/2022

TrustVault: A privacy-first data wallet for the European Blockchain Services Infrastructure

The European Union is on course to introduce a European Digital Identity...
research
05/16/2018

reclaimID: Secure, Self-Sovereign Identities using Name Systems and Attribute-Based Encryption

In this paper we present reclaimID: An architecture that allows users to...
research
08/21/2020

MAGE: Mutual Attestation for a Group of Enclaves without Trusted Third Parties

Intel Software Guard Extensions (SGX) local and remote attestation mecha...
research
12/05/2017

Self-sovereign Identity - Opportunities and Challenges for the Digital Revolution

The interconnectedness of people, services and devices is a defining asp...
research
05/15/2019

TAPESTRY: A Blockchain based Service for Trusted Interaction Online

We present a novel blockchain based service for proving the provenance o...
research
07/15/2019

Anonymous and confidential file sharing over untrusted clouds

Using public cloud services for storing and sharing confidential data re...

Please sign up or login with your details

Forgot password? Click here to reset