FORT: Right-proving and Attribute-blinding Self-sovereign Authentication

02/18/2022
by   Xavier Salleras, et al.
0

Nowadays, there is a plethora of services that are provided and paid for online, like video streaming subscriptions, car or parking sharing, purchasing tickets for events, etc. Online services usually issue tokens directly related to the identities of their users after signing up into their platform, and the users need to authenticate using the same credentials each time they are willing to use the service. Likewise, when using in-person services like going to a concert, after paying for this service the user usually gets a ticket which proves that he/she has the right to use that service. In both scenarios, the main concerns are the centralization of the systems, and that they do not ensure customers' privacy. The involved Service Providers are Trusted Third Parties, authorities that offer services and handle private data about users. In this paper, we design and implement FORT, a decentralized system that allows customers to prove their right to use specific services (either online or in-person) without revealing sensitive information. To achieve decentralization we propose a solution where all the data is handled by a Blockchain. We describe and uniquely identify users' rights using Non-Fungible Tokens (NFTs), and possession of these rights is demonstrated by using Zero-Knowledge Proofs, cryptographic primitives that allow us to guarantee customers' privacy. Furthermore, we provide benchmarks of FORT which show that our protocol is efficient enough to be used in devices with low computing resources, like smartphones or smartwatches, which are the kind of devices commonly used in our use case scenario.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/29/2020

SANS: Self-sovereign Authentication for Network Slices

5G communications proposed significant improvements over 4G in terms of ...
research
01/23/2023

Citadel: Self-Sovereign Identities on Dusk Network

The amount of sensitive information that service providers handle about ...
research
07/22/2019

ZKlaims: Privacy-preserving Attribute-based Credentials using Non-interactive Zero-knowledge Techniques

In this paper we present ZKlaims: a system that allows users to present ...
research
07/31/2020

Password-authenticated Decentralized Identities

Password-authenticated identities, where users establish username-passwo...
research
05/14/2021

VICEROY: GDPR-/CCPA-compliant Enforcement of Verifiable Accountless Consumer Requests

Recent data protection regulations (such as GDPR and CCPA) grant consume...
research
06/26/2023

Long-living Service for Cooperative Knowledge Use in Decentralized Data Stores

Personal Data Stores (PDS) like SoLiD is an emerging data and knowledge ...
research
06/28/2018

Dynamic traffic resources allocation under elastic demand of users with space-time prism constraints

We present a conceptual framework for the dynamic traffic resources allo...

Please sign up or login with your details

Forgot password? Click here to reset