UPPRESSO: Untraceable and Unlinkable Privacy-PREserving Single Sign-On Services

10/20/2021
by   Chengqian Guo, et al.
0

Single sign-on (SSO) allows a user to maintain only the credential at the identity provider (IdP), instead of one credential for each relying party (RP), to login to numerous RPs. However, SSO introduces extra privacy leakage threats, as (a) the IdP could track all the RPs which a user is visiting, and (b) collusive RPs could learn a user's online profile by linking his identities across these RPs. Several privacy-preserving SSO solutions have been proposed to defend against either the curious IdP or collusive RPs, but none of them addresses both of these privacy leakage threats at the same time. In this paper, we propose a privacy-preserving SSO system, called UPPRESSO, to protect a user's login traces against both the curious IdP and collusive RPs simultaneously. We analyze the identity dilemma between the SSO security requirements and these privacy concerns, and convert the SSO privacy problems into an identity-transformation challenge. To the best of our knowledge, this is the first practical SSO solution which solves the privacy problems caused by both the curious IdP and collusive RPs. We build the UPPRESSO prototype system for web applications, with standard functions of OpenID Connect, while the function of Core Sign-On is slightly modified to calculate the transformed identities. The prototype system is implemented on top of open-source MITREid Connect, and the extensive evaluation shows that UPPRESSO introduces reasonable overheads and fulfills the requirements of both security and privacy.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/24/2020

EL PASSO: Privacy-preserving, Asynchronous Single Sign-On

We introduce EL PASSO, a privacy-preserving, asynchronous Single Sign-On...
research
11/09/2022

Harpocrates: Privacy-Preserving and Immutable Audit Log for Sensitive Data Operations

The audit log is a crucial component to monitor fine-grained operations ...
research
07/05/2020

Octopus: Privacy-Preserving Collaborative Evaluation of Loan Stacking

With the rise of online lenders, the loan stacking problem has become a ...
research
11/23/2022

A new Privacy Preserving and Scalable Revocation Method for Self Sovereign Identity – The Perfect Revocation Method does not exist yet

Digital Identities are playing an essential role in our digital lives. T...
research
07/27/2023

LinkDID: A Privacy-Preserving, Sybil-Resistant and Key-Recoverable Decentralized Identity Scheme

Decentralized identity mechanisms endeavor to endow users with complete ...
research
02/22/2018

Privacy-Preserving Boosting with Random Linear Classifiers for Learning from User-Generated Data

User-generated data is crucial to predictive modeling in many applicatio...
research
04/10/2020

A Framework for Behavior Privacy Preserving in Radio Frequency Signal

Recent years have witnessed the bloom development of the human-centered ...

Please sign up or login with your details

Forgot password? Click here to reset