With a Little Help from My Friends: Constructing Practical Anonymous Credentials

With a Little Help from My Friends: Constructing Practical Anonymous Credentials
复制标题

DOI:
10.1145/3460120.3484582
复制
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
L. Hanzlik;Daniel Slamanig
L. Hanzlik;Daniel Slamanig
中科院分区:
其他
文献类型:
--
作者:
L. Hanzlik;Daniel Slamanig

文献摘要

被引文献

相似文献

匿名凭证 (AC) 是一种强大的加密工具,可用于安全使用数字服务,同时旨在为用户提供强有力的隐私保证,同时为服务提供商提供强有力的身份验证保证。它们允许用户有选择地证明拥有凭证中编码的属性,而无需透露有关自己的任何其他有意义的信息。尽管对 AC 系统进行了大量研究,但移动应用等 AC 的现代用例提出了迄今为止尚未充分考虑的各种要求。其中包括防止凭证共享以及应对平台的资源限制(例如智能卡中的 SIM 卡等智能卡)。这些方面通常超出了空调结构的范围,因此迄今为止,可以认为完全实用的空调系统还难以实现。在本文中,我们通过引入并形式化核心/辅助匿名凭证(CHAC)的概念来解决这个问题。该模型考虑了受限的核心设备(例如 SIM 卡)和强大的辅助设备(例如智能手机)。关键思想是核心设备执行的操作不依赖于凭证的大小或属性的数量,但同时辅助设备在没有其帮助的情况下无法使用凭证。我们使用签名与灵活公钥 (SFPK) 的组合、可聚合的基于属性的等价类签名 (AAEQ) 的新概念以及具体实例化,提出了一种可证明安全的 CHAC 通用构造。我们方案的关键特征是显示令牌的大小与凭证中属性的数量无关,并且核心设备只需要计算单个椭圆曲线标量乘法,而不管属性的数量。我们通过在 Multos 智能卡作为核心、Android 智能手机作为辅助设备上实施我们的方案,确认了 CHAC 的实际效率。显示凭证在智能卡上需要不到 500 毫秒,在智能手机上需要大约 200 毫秒(即使是具有 1000 个属性的凭证)。
Anonymous credentials (ACs) are a powerful cryptographic tool for the secure use of digital services, when simultaneously aiming for strong privacy guarantees of users combined with strong authentication guarantees for providers of services. They allow users to selectively prove possession of attributes encoded in a credential without revealing any other meaningful information about themselves. While there is a significant body of research on AC systems, modern use-cases of ACs such as mobile applications come with various requirements not sufficiently considered so far. These include preventing the sharing of credentials and coping with resource constraints of the platforms (e.g., smart cards such as SIM cards in smartphones). Such aspects are typically out of scope of AC constructions, and, thus AC systems that can be considered entirely practical have been elusive so far. In this paper we address this problem by introducing and formalizing the notion of core/helper anonymous credentials (CHAC). The model considers a constrained core device (e.g., a SIM card) and a powerful helper device (e.g., a smartphone). The key idea is that the core device performs operations that do not depend on the size of the credential or the number of attributes, but at the same time the helper device is unable to use the credential without its help. We present a provably secure generic construction of CHACs using a combination of signatures with flexible public keys (SFPK) and the novel notion of aggregatable attribute-based equivalence class signatures (AAEQ) along with a concrete instantiation. The key characteristics of our scheme are that the size of showing tokens is independent of the number of attributes in the credential(s) and that the core device only needs to compute a single elliptic curve scalar multiplication, regardless of the number of attributes. We confirm the practical efficiency of our CHACs with an implementation of our scheme on a Multos smart card as the core and an Android smartphone as the helper device. A credential showing requires less than 500 ms on the smart card and around 200 ms on the smartphone (even for a credential with 1000 attributes).