Privacy-Preserving eID Derivation to Self-Sovereign Identity Systems with Offline Revocation

被引:5
作者
Abraham, Andreas [1 ]
Koch, Karl [1 ]
More, Stefan [1 ]
Ramacher, Sebastian [2 ]
Stopar, Miha [3 ]
机构
[1] Graz Univ Technol, Graz, Austria
[2] AIT Austrian Inst Technol, Vienna, Austria
[3] XLAB Doo, Ljubljana, Slovenia
来源
2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021) | 2021年
基金
欧盟地平线“2020”;
关键词
self-sovereign identity; eID derivation; offline revocation; zero-knowledge proofs; EFFICIENT REVOCATION; ACCUMULATORS; SIGNATURES;
D O I
10.1109/TrustCom53373.2021.00080
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Digital identities play a vital role in an increasingly digital world. These identities often rely on central authorities to issue and manage them. Central authorities have the drawback of being a central trusted party, representing a bottleneck and single point of failure with exclusive control of identity-related data. Self-sovereign identity (SSI) tackles those problems by utilizing distributed ledger technology and making users the sovereign owners of their identity data. Nevertheless, SSI, as recent technology, still lacks qualified identity data. This is especially a problem since sensitive services like eGovernment or banking services require identity data issued by a qualified identity provider; thus, SSI-based identities cannot be used for these services. In this paper, we propose a concept for deriving identity data from an existing identity system into an SSI in a fully privacy-preserving way by additionally supporting offline verification. This way, we enable a chain of trust from the existing identity system to the SSI system by introducing a novel trust model. Our concept utilizes novel cryptographic primitives to support efficient and privacy-preserving identity showing as well as revocation. To underline the feasibility of our concept, we implement a proof system and benchmark the related use cases.
引用
收藏
页码:506 / 513
页数:8
相关论文
共 37 条
[1]   Lift-and-Shift: Obtaining Simulation Extractable Subversion and Updatable SNARKs Generically [J].
Abdolmaleki, Behzad ;
Ramacher, Sebastian ;
Slamanig, Daniel .
CCS '20: PROCEEDINGS OF THE 2020 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2020, :1987-2005
[2]   Revocable and Offline-Verifiable Self-Sovereign Identities [J].
Abraham, Andreas ;
More, Stefan ;
Rabensteiner, Christof ;
Horandner, Felix .
2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, :1021-1028
[3]   Privacy-Preserving eID Derivation for Self-Sovereign Identity Systems [J].
Abraham, Andreas ;
Hoerandner, Felix ;
Omolola, Olamide ;
Ramacher, Sebastian .
INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2019), 2020, 11999 :307-323
[4]   Qualified eID Derivation into a Distributed Ledger based IdM System [J].
Abraham, Andreas ;
Theuermann, Kevin ;
Kirchengast, Emanuel .
2018 17TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (IEEE TRUSTCOM) / 12TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (IEEE BIGDATASE), 2018, :1406-1412
[5]  
Abraham Andreas, 2017, Technical Report
[6]   Design of Symmetric-Key Primitives for Advanced Cryptographic Protocols [J].
Aly, Abdelrahaman ;
Ashur, Tomer ;
Ben-Sasson, Eli ;
Dhooghe, Siemen ;
Szepieniec, Alan .
IACR TRANSACTIONS ON SYMMETRIC CRYPTOLOGY, 2020, 2020 (03) :1-45
[7]  
[Anonymous], 2017, DEFINITION REQUIREME
[8]  
[Anonymous], 2014, NDSS
[9]  
Barreto PSLM, 2003, LECT NOTES COMPUT SC, V2576, P257
[10]  
Benaloh J.C., 1993, EUROCRYPT, V765, P274, DOI [10.1007/3-540-48285-7_24, DOI 10.1007/3-540-48285-7_24]