Skip to main navigation Skip to search Skip to main content

PE(AR) 2: Privacy-enhanced anonymous authentication with reputation and revocation

  • Kin Ying Yu
  • , Tsz Hon Yuen
  • , Sherman S.M. Chow
  • , Siu Ming Yiu
  • , Lucas C.K. Hui

Research output: Chapter in Book/Report/Conference proceedingConference PaperResearchpeer-review

Abstract

Anonymous authentication schemes allow users to act freely without being tracked. The users may not want to trust a third party in ensuring their privacy, yet a service provider (SP) should have the authority to blacklist a misbehaving user. They are seemingly contradicting requirements. PEREA was the most efficient solution to this problem. However, there are a few drawbacks which make it vulnerable and not practical enough. In this paper, we propose PE(AR) 2, which not only fixes PEREA's vulnerability, but also significantly improves its computation efficiency. Apart from revoking repeated misbehaving users, our system also rewards anonymous users via a built-in reputation system. Our scheme does not require the SP to timely review all previously authenticated sessions, and does not have the dependency on the blacklist size for user-side computation (c.f. EPID/BLAC(R)). Our benchmark on PE(AR) 2 shows that an SP can handle over 160 requests/second - a 460-fold efficiency improvement over PEREA, when the credentials store 1000 single-use tickets.

Original languageEnglish
Title of host publicationComputer Security, ESORICS 2012 - 17th European Symposium on Research in Computer Security, Proceedings
PublisherSpringer
Pages679-696
Number of pages18
ISBN (Print)9783642331664
DOIs
Publication statusPublished - 2012
Externally publishedYes
EventEuropean Symposium On Research In Computer Security 2012 - Pisa, Italy
Duration: 10 Sept 201212 Sept 2012
Conference number: 17th
https://link.springer.com/book/10.1007/978-3-642-33167-1 (Proceedings)

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
Volume7459
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceEuropean Symposium On Research In Computer Security 2012
Abbreviated titleESORICS 2012
Country/TerritoryItaly
CityPisa
Period10/09/1212/09/12
Internet address

Cite this