ACM Home Page
Please provide us with feedback. Feedback
Enhancing privacy of federated identity management protocols: anonymous credentials in WS-security
Full text PdfPdf (138 KB)
Source Workshop On Privacy In The Electronic Society archive
Proceedings of the 5th ACM workshop on Privacy in electronic society table of contents
Alexandria, Virginia, USA
SESSION: Short papers table of contents
Pages: 67 - 72  
Year of Publication: 2006
ISBN:1-59593-556-8
Authors
Jan Camenisch  IBM Zurich Research
Thomas Gross  IBM Zurich Research
Dieter Sommer  IBM Zurich Research
Sponsors
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 17,   Downloads (12 Months): 115,   Citation Count: 1
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1179601.1179613
What is a DOI?

ABSTRACT

Federated Identity Management (FIM) allows for securely provisioning certified user identities and attributes to relying parties. It establishes higher security and data quality compared to user-asserted attributes and provides for stronger user privacy protection than technologies based upon user-side attribute certificates. Therefore, industry pursues the deployment of FIM solutions as one cornerstone of the WS-Security framework. Current research proposes even more powerful methods for security and privacy protection in identity management with so called anonymous credential systems. Being based on new, yet well-researched, signature schemes and cryptographic zero-knowledge proofs, these systems have the potential to improve the capabilities of FIM by superior privacy protection, user control, and multiple use of single credentials. Unfortunately, anonymous credential systems and their semantics being based upon zero-knowledge proofs are incompatible with the XML Signature Standard which is the basis for the WS-Security and most FIM frameworks. We put forth a general construction for integrating anonymous credential systems with the XML Signature Standard and FIM protocols. We apply this method to the WS-Security protocol framework and thus obtain a very flexible WS-Federation Active Requestor Profile with strong user control and superior privacy protection.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

1
 
2
BANGERTER, E., CAMENISCH, J., AND LYSYANSKAYA, A. A cryptographic framework for the controlled release of certified data. In Twelfth International Workshop on Security Protocols 2004 (2004), LNCS, Springer Verlag.
 
3
BRANDS, S. Rethinking Public Key Infrastructure and Digital Certificates-Building in Privacy. PhD thesis, Eindhoven Institute of Technology, Eindhoven, The Netherlands, 1999.
 
4
CAMENISCH, J., GROSS, T., AND SOMMER, D. Enhancing privacy of federated identity management protocols -- anonymous credentials in ws-security. Tech. rep., Purdue University, 2006.
5
 
6
 
7
CAMENISCH, J., SOMMER, D., AND ZIMMERMANN, R. A general certification framework with applications to privacy-enhancing certificate infrastructures. In SEC 2006 (2006).
 
8
 
9
DODIS, Y., AND YAMPOLSKIY, A. A verifiable random function with short proofs an keys. In Public Key Cryptography (2005), vol. 3386 of LNCS, pp. 416--431.
 
10
EASTLAKE 3RD, D., REAGLE, J., AND SOLO, D. XML-Signature syntax and processing, Mar. 2002. http://www.w3.org/TR/xmldsig-core/.
 
11
 
12
KALER, C., AND NADALIN, A. Web services federation language (ws-federation), version 1, July 2003.
 
13
KALER, C., AND NADALIN, A. Ws-federation active requestor profile, version 1, July 2003.
 
14
OASIS. Ws-security standard, 2004.


Collaborative Colleagues:
Jan Camenisch: colleagues
Thomas Gross: colleagues
Dieter Sommer: colleagues