CRDec 6, 2016

PRIMA: Privacy-Preserving Identity and Access Management at Internet-Scale

arXiv:1612.01787v127 citations
Originality Highly original
AI Analysis

This addresses privacy concerns for users and service providers in internet-scale identity management, offering a novel solution to a known bottleneck.

The paper tackles the privacy threats in federated identity management by proposing PRIMA, a credential-based authentication system that prevents identity providers from tracking users across services, with performance evaluations showing it can process 1,426 to 3,332 requests per second depending on key size.

The management of identities on the Internet has evolved from the traditional approach (where each service provider stores and manages identities) to a federated identity management system (where the identity management is delegated to a set of identity providers). On the one hand, federated identity ensures usability and provides economic benefits to service providers. On the other hand, it poses serious privacy threats to users as well as service providers. The current technology, which is prevalently deployed on the Internet, allows identity providers to track the user's behavior across a broad range of services. In this work, we propose PRIMA, a universal credential-based authentication system for supporting federated identity management in a privacy-preserving manner. Basically, PRIMA does not require any interaction between service providers and identity providers during the authentication process, thus preventing identity providers to profile users' behavior. Moreover, throughout the authentication process, PRIMA provides a mechanism for controlled disclosure of the users' private information. We have conducted comprehensive evaluations of the system to show the feasibility of our approach. Our performance analysis shows that an identity provider can process 1,426 to 3,332 requests per second when the key size is varied from 1024 to 2048-bit, respectively.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes