Wenyi Xue;Yang Yang;Minming Huang;Yingjiu Li;Hwee Hwa Pang;Robert H. Deng
{"title":"DkvSSO: Delegatable Keyed-Verification Credentials for Efficient Anonymous Single Sign-On","authors":"Wenyi Xue;Yang Yang;Minming Huang;Yingjiu Li;Hwee Hwa Pang;Robert H. Deng","doi":"10.1109/TIFS.2025.3555196","DOIUrl":null,"url":null,"abstract":"Anonymous single sign-on (ASSO) is an anonymous multi-service authentication method for end users. However, existing ASSO schemes suffer from heavy ticket requesting and verifying overheads, limiting their applications in large-scale settings. To address this problem, we propose a novel concept called keyed-verification anonymous credentials with disposable delegation (KVAC-DD) in the multi-verifier setting. Next, we extend KVAC-DD to build an efficient ASSO system, dubbed DkvSSO. The construction of DkvSSO can be instantiated in efficient prime-order groups, avoiding costly operations required in previous ASSO systems. We formally prove the security of our proposed constructions. Extensive experiments show that DkvSSO is significantly more efficient than existing ASSO schemes, making it suitable to be deployed in large-scale settings.","PeriodicalId":13492,"journal":{"name":"IEEE Transactions on Information Forensics and Security","volume":"20 ","pages":"4196-4211"},"PeriodicalIF":6.3000,"publicationDate":"2025-03-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Transactions on Information Forensics and Security","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/10942396/","RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, THEORY & METHODS","Score":null,"Total":0}
引用次数: 0
Abstract
Anonymous single sign-on (ASSO) is an anonymous multi-service authentication method for end users. However, existing ASSO schemes suffer from heavy ticket requesting and verifying overheads, limiting their applications in large-scale settings. To address this problem, we propose a novel concept called keyed-verification anonymous credentials with disposable delegation (KVAC-DD) in the multi-verifier setting. Next, we extend KVAC-DD to build an efficient ASSO system, dubbed DkvSSO. The construction of DkvSSO can be instantiated in efficient prime-order groups, avoiding costly operations required in previous ASSO systems. We formally prove the security of our proposed constructions. Extensive experiments show that DkvSSO is significantly more efficient than existing ASSO schemes, making it suitable to be deployed in large-scale settings.
匿名单点登录(Anonymous single sign-on, aso)是一种针对终端用户的匿名多业务认证方式。然而,现有的aso方案存在大量的票请求和验证开销,限制了它们在大规模环境中的应用。为了解决这个问题,我们提出了一个新的概念,即在多验证者设置中具有一次性授权的密钥验证匿名凭证(KVAC-DD)。接下来,我们扩展KVAC-DD以构建一个高效的aso系统,称为DkvSSO。DkvSSO的构造可以在高效的素序群中实例化,避免了以前的aso系统所需要的昂贵操作。我们正式证明了我们所建议的结构的安全性。大量实验表明,DkvSSO比现有的aso方案效率更高,适合大规模部署。
期刊介绍:
The IEEE Transactions on Information Forensics and Security covers the sciences, technologies, and applications relating to information forensics, information security, biometrics, surveillance and systems applications that incorporate these features