TY - GEN
T1 - SPROOF: A Decentralized Platform for Attribute-Based Authentication
AU - Brunner, C.
AU - Knirsch, F.
AU - Engel, D.
A2 - P., Mori
A2 - S., Furnell
A2 - O., Camp
N1 - Conference code: 241639
Cited By :2
Export Date: 14 December 2023
Correspondence Address: Brunner, C.; Center for Secure Energy Informatics, Austria; email: [email protected]
Funding details: Österreichische Forschungsförderungsgesellschaft, FFG, 865082
Funding details: Universität Innsbruck, uibk
Funding details: Salzburger Landesregierung
Funding text 1: The overall support of Rainer Böhme from the University of Innsbruck as the supervisor of [3] and especially the initial idea of using HD wallets to build pseudonym trees to enable the completeness feature is gratefully acknowledged. The authors also like to acknowledge Michael Fröwis and Pascal Schöttle for discussions about this topic. The financial support by the Federal State of Salzburg is gratefully acknowledged. Funding by the Austrian Research Promotion Agency (FFG) under project number 865082 (ProChain) is gratefully acknowledged.
References: Bartoletti, M., Pompianu, L., An analysis of bitcoin OP RETURN metadata (2017) FC 2017. LNCS, 10323, pp. 218-230. , https://doi.org/10.1007/978-3-319-70278-014, Brenner, M., et al. (eds) Springer, Cham; Benet, J., (2014) IPFS-content addressed, versioned, P2P file system (DRAFT 3), , https://doi.org/10.1109/ICPADS.2007.4447808, Technical report, IPFS https://ipfs.io/ipfs/QmR7GSQM93Cx5eAg6a6yRzNde1FQv7uL6X1o4k7zrJa3LX/ipfs.draft3.pdf; Brunner, C., (2017) Eduthereum: A System for Storing Educational Certificates in a Public Blockchain, , Master’s thesis, Universität Innsbruck; Brunner, C., Knirsch, F., Engel, D., SPROOF: a platform for issuing and verifying documents in a public blockchain (2019) Proceedings of the 5th International Conference on Information Systems Security and Privacy, pp. 15-25. , SciTePress, Prague, Czech Republic; Caronni, G., Walking the web of trust (2000) 9th International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WET ICE 2000), pp. 153-158. , https://doi.org/10.1109/ENABL.2000.883720, IEEE, Gaithersburg; Christidis, K., Devetsikiotis, M., Blockchains and smart contracts for the internet of things (2016) IEEE Access, 4, pp. 2292-2303. , https://doi.org/10.1109/ACCESS.2016.2566339; Croman, K., On scaling decentralized blockchains (2016) FC 2016. LNCS, 9604, pp. 106-125. , https://doi.org/10.1007/978-3-662-53357-48, Clark, J., Meiklejohn, S., Ryan, P.Y.A., Wallach, D., Brenner, M., Rohloff, K. (eds) Springer, Heidelberg; Damgård, I.B., Collision free hash functions and public key signature schemes (1988) Advances in Cryptology – EUROCRYPT, pp. 203-216. , https://doi.org/10.1007/3-540-39118-519, 1987; Diffie, W., Hellman, M., New directions in cryptography (1976) IEEE Trans. Inf. Theory, 22 (6), pp. 644-654. , https://doi.org/10.1109/TIT.1976.1055638; Durumeric, Z., Kasten, J., Bailey, M., Halderman, J.A., Analysis of the HTTPS certificate ecosystem (2013) Proceedings of the 2013 Conference on Internet Measurement Conference (IMC 2013), pp. 291-304. , https://doi.org/10.1145/2504730.2504755,https://arxiv.org/abs/1408.1023, ACM, Barcelona, Spain; Eyal, I., Gencer, A.E., Sirer, E.G., van Renesse, R., Bitcoin-NG: a scalable blockchain protocol (2016) Proceedings of the 13th Usenix Conference on Networked Systems Design and Implementation, pp. 45-59. , NSDI 2016, USENIX Association, Santa Clara, CA; Gauravaram, P., Security analysis of salt$——$password hashes (2012) International Conference on Advanced Computer Science Applications and Technologies (ACSAT), pp. 25-30. , https://doi.org/10.1109/ACSAT.2012.49, IEEE, Kuala Lumpur, Malaysia; Gräther, W., Blockchain for education: lifelong learning passport (2018) Proceedings of 1st ERCIM Blockchain Workshop 2018. European Society for Socially Embedded Technologies (EUSSET), , https://doi.org/10.18420/blockchain2018, Amsterdam; Gutoski, G., Stebila, D., Hierarchical deterministic bitcoin wallets that tolerate key leakage (2015) FC 2015. LNCS, 8975, pp. 497-504. , https://doi.org/10.1007/978-3-662-47854-731, Böhme, R., Okamoto, T. (eds) Springer, Heidelberg; Johnson, D., Menezes, A., Vanstone, S., The elliptic curve digital signature algo-rithm(ECDSA) (2001) Int.J.Inf.Secur, 1 (1), pp. 36-63. , https://doi.org/10.1007/s102070100002.http://www.cacr.math.uwaterloo.ca; Knirsch, F., Unterweger, A., Engel, D., Privacy-preserving blockchain-based electric vehicle charging with dynamic tariff decisions (2018) J. Comput. Sci.-Res. Dev. (CSRD), 33 (1), pp. 71-79; Kosba, A., Miller, A., Shi, E., Wen, Z., Papamanthou, C., Hawk: the blockchain model of cryptography and privacy-preserving smart contracts (2016) 2016 IEEE Symposium on Security and Privacy (SP), pp. 839-858. , IEEE, San Jose; Nakamoto, S., (2008) Bitcoin: a peer-to-peer electronic cash system, , https://bitcoin.org/bitcoin.pdf, Technical report; Reid, F., Harrigan, M., An analysis of anonymity in the bitcoin system (2013) Security and Privacy in Social Networks, pp. 197-223. , https://doi.org/10.1007/978-1-4614-4139-710, Alt-shuler, Y., Elovici, Y., Cremers, A.B., Aharony, N., Pentland, A. (eds) Springer, New York; (2018) Sovrin: a protocol and token for self-sovereign identity and decentralized trust, , https://sovrin.org/wp-content/uploads/2018/03/Sovrin-Protocol-and-Token-White-Paper.pdf, Sovrin Foundation: Technical Report, January; Unterweger, A., Knirsch, F., Leixnering, C., Engel, D., Lessons learned from implementing a privacy-preserving smart contract in ethereum (2018) 9th IFIP International Conference on New Technologies. Mobility and Security (NTMS), pp. 1-5. , IEEE, Paris, France; Vasek, M., Bonneau, J., Castellucci, R., Keith, C., Moore, T., The bitcoin brain drain: a short paper on the use and abuse of bitcoin brain wallets (2016) 20th International Conference on Financial Cryptography and Data Security (FC 2016), , Springer, Christ Church; Wood, G., (2017) Ethereum: a secure decentralised generalised transaction ledger, , https://ethereum.github.io/yellowpaper/paper.pdf, Technical report, Ethereum; Wood, G., (2017) Polkadot: vision for a heterogeneous multi-chain framework, , https://github.com/w3f/polkadot-white-paper/raw/master/PolkaDotPaper.pdf, Technical report, Parity.io; Wüst, K., Gervais, A., Do you need a Blockchain (2017), https://eprint.iacr.org/2017/375.pdf, Technical report, International Association for Cryptologic ResearchUR - https://www.scopus.com/inward/record.uri?eid=2-s2.0-85088271200&doi=10.1007%2f978-3-030-49443-8_1&partnerID=40&md5=450dd20e313daa5836ded97c354954c7
PY - 2020/6
Y1 - 2020/6
N2 - Paper documents are still very common for all types of records of personal achievements, ID cards and many other types documents issued to an individual or a company. These paper documents, however, often come at the cost of expensive printing and issuing, loss of data or malicious counterfeits. The origin and integrity is often hard or even impossible to be verified. Digital signatures solve some of these issues, however, this still requires centralized trusted infrastructures and still does not allow for easy verification or recovery of lost documents. Furthermore, attribute-based authentication is not possible with traditional signature schemes. In this paper, we present a decentralized platform for signing and verifying digital documents that is based on the previously presented SPROOF platform and additionally supports attribute-based authentication. This platform allows for issuing, managing and verifying digital documents in a public blockchain. In the proposed approach, all data needed for verification of documents and issuers is stored decentralized, transparent, and integrity protected. The platform is permissionless and thus no access restrictions apply. Rather, following principles of the Web of Trust, issuers can confirm each other in a decentralized way. Additionally, scalability and privacy issues are taken into consideration. © 2020, Springer Nature Switzerland AG.
AB - Paper documents are still very common for all types of records of personal achievements, ID cards and many other types documents issued to an individual or a company. These paper documents, however, often come at the cost of expensive printing and issuing, loss of data or malicious counterfeits. The origin and integrity is often hard or even impossible to be verified. Digital signatures solve some of these issues, however, this still requires centralized trusted infrastructures and still does not allow for easy verification or recovery of lost documents. Furthermore, attribute-based authentication is not possible with traditional signature schemes. In this paper, we present a decentralized platform for signing and verifying digital documents that is based on the previously presented SPROOF platform and additionally supports attribute-based authentication. This platform allows for issuing, managing and verifying digital documents in a public blockchain. In the proposed approach, all data needed for verification of documents and issuers is stored decentralized, transparent, and integrity protected. The platform is permissionless and thus no access restrictions apply. Rather, following principles of the Web of Trust, issuers can confirm each other in a decentralized way. Additionally, scalability and privacy issues are taken into consideration. © 2020, Springer Nature Switzerland AG.
KW - Blockchain
KW - Certificate
KW - Digital document
KW - Privacy-friendly
KW - Pseudonym
KW - Information systems
KW - Information use
KW - Network security
KW - Access restriction
KW - Attribute-based
KW - Digital Documents
KW - ID cards
KW - Paper documents
KW - Privacy issue
KW - Signature Scheme
KW - Web of trust
KW - Authentication
U2 - 10.1007/978-3-030-49443-8_1
DO - 10.1007/978-3-030-49443-8_1
M3 - Conference contribution
SN - 978-3-030-49442-1
VL - 1221 CCIS
T3 - Communications in Computer and Information Science
BT - Information Systems Security and Privacy
PB - Springer
T2 - 5th International Conference on Information Systems Security and Privacy, ICISSP 2019
Y2 - 23 February 2019 through 25 February 2019
ER -