BBA+: Improving the Security and Applicability of Privacy-Preserving Point Collection

BBA+: Improving the Security and Applicability of Privacy-Preserving Point Collection
复制标题

DOI:
10.1145/3133956.3134071
复制
发表时间:
2017-10
期刊:
Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
G. Hartung;Max Hoffmann;Matthias Nagel;Andy Rupp
G. Hartung;Max Hoffmann;Matthias Nagel;Andy Rupp
中科院分区:
其他
文献类型:
--
作者:
G. Hartung;Max Hoffmann;Matthias Nagel;Andy Rupp

文献摘要

被引文献

相似文献

黑盒积累(BBA)最近被引入作为各种以用户为中心的协议(例如忠诚度、退款和激励系统)的构建块。宽松地说,这个构建块可以被视为一个加密的“存钱罐”,它允许用户以匿名和不可链接的方式收集积分(又名激励、硬币等)。存钱罐可能会在某个时候被用户“抢劫”,让她花掉收集到的积分,从而只透露存钱罐内的总金额及其唯一的序列号。在本文中,我们提出了 BBA+,一个以多种方式扩展 BBA 模型的定义框架:(1)我们支持离线系统,因为不需要永久连接到序列号数据库来检查所提供的存钱罐是否已被抢劫。 (2) 我们强制收集用户可能不会自愿收集的“负积分”,例如预付费或声誉系统所需的积分。 (3) \bbap 方案形式化的安全属性比 BBA 更强、更自然:本质上,我们要求存钱罐内声称的金额必须与该存钱罐合法收集的金额完全相同。由于存钱罐交易需要同时不可链接,因此定义此属性非常重要。 (4)我们还定义了一种更强的隐私形式,即前向隐私和后向隐私。除了框架之外,我们还展示了如何从加密构建块构建 BBA+ 系统,并展示基于智能手机的原型实施的有希望的结果。它们表明,我们当前的实例化可能已经在实践中可用,允许在一秒钟内运行事务——而我们还没有耗尽优化的潜力。
Black-box accumulation (BBA) has recently been introduced as a building-block for a variety of user-centric protocols such as loyalty, refund, and incentive systems. Loosely speaking, this building block may be viewed as a cryptographic "piggy bank" that allows a user to collect points (aka incentives, coins, etc.) in an anonymous and unlinkable way. A piggy bank may be "robbed" at some point by a user, letting her spend the collected points, thereby only revealing the total amount inside the piggy bank and its unique serial number. In this paper we present BBA+, a definitional framework extending the BBA model in multiple ways: (1) We support offline systems in the sense that there does not need to be a permanent connection to a serial number database to check whether a presented piggy bank has already been robbed. (2) We enforce the collection of "negative points" which users may not voluntarily collect, as this is, for example, needed in pre-payment or reputation systems. (3) The security property formalized for \bbap schemes is stronger and more natural than for BBA: Essentially, we demand that the amount claimed to be inside a piggy bank must be exactly the amount legitimately collected with this piggy bank. As piggy bank transactions need to be unlinkable at the same time, defining this property is highly non-trivial. (4) We also define a stronger form of privacy, namely forward and backward privacy. Besides the framework, we show how to construct a BBA+ system from cryptographic building blocks and present the promising results of a smartphone-based prototypical implementation. They show that our current instantiation may already be useable in practice, allowing to run transactions within a second---while we have not exhausted the potential for optimizations.