Privacy-Preserving Outsourced Certificate Validation

Tarek Galal, Anja Lehmann
{"title":"Privacy-Preserving Outsourced Certificate Validation","authors":"Tarek Galal, Anja Lehmann","doi":"10.56553/popets-2023-0113","DOIUrl":null,"url":null,"abstract":"Digital Covid certificates are the first widely deployed end-user cryptographic certificates. For service providers, such as airlines or event ticket vendors, that needed to check that their (global) customers satisfy certain health policies, the verification of such Covid certificates was challenging though - not because of the cryptography involved, but due to the multitude of issuers, different certificate types and the evolving nature of country-specific policies that had to be supported. As Covid certificates contain sensitive health information, their (online) presentation to non-health related entities also poses clear privacy risk. To address both challenges, the EU proposed a specification for outsourcing the verification process to a validator service, that executes the process and informs service providers of the result. The WHO announced to adapt this approach for general vaccination credentials beyond Covid-19. While being beneficial to improve security and privacy for service providers, their solution requires strong trust assumption for the (central) validation service that learns all health-related details of the users.\n \n In our work, we propose and formally model a privacy-preserving variant of such an outsourced validation service. Therein the validator learns the attributes it is supposed to verify, but not the users identity. Still, the validator’s assertion is blindly bound to the user’s identity to ensure the desired user-binding. We analyze the EU specification in our model and show that it only meets a subset of those goals. Our analysis further shows that the EU protocol is unnecessarily complex and can be significantly simplified while maintaining the same (weak) level of security. Finally, we propose a new construction for privacy-preserving certificate validation that provably satisfies all desired goals.","PeriodicalId":13158,"journal":{"name":"IACR Cryptol. ePrint Arch.","volume":"35 1","pages":"1232"},"PeriodicalIF":0.0000,"publicationDate":"2023-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IACR Cryptol. ePrint Arch.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.56553/popets-2023-0113","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Digital Covid certificates are the first widely deployed end-user cryptographic certificates. For service providers, such as airlines or event ticket vendors, that needed to check that their (global) customers satisfy certain health policies, the verification of such Covid certificates was challenging though - not because of the cryptography involved, but due to the multitude of issuers, different certificate types and the evolving nature of country-specific policies that had to be supported. As Covid certificates contain sensitive health information, their (online) presentation to non-health related entities also poses clear privacy risk. To address both challenges, the EU proposed a specification for outsourcing the verification process to a validator service, that executes the process and informs service providers of the result. The WHO announced to adapt this approach for general vaccination credentials beyond Covid-19. While being beneficial to improve security and privacy for service providers, their solution requires strong trust assumption for the (central) validation service that learns all health-related details of the users. In our work, we propose and formally model a privacy-preserving variant of such an outsourced validation service. Therein the validator learns the attributes it is supposed to verify, but not the users identity. Still, the validator’s assertion is blindly bound to the user’s identity to ensure the desired user-binding. We analyze the EU specification in our model and show that it only meets a subset of those goals. Our analysis further shows that the EU protocol is unnecessarily complex and can be significantly simplified while maintaining the same (weak) level of security. Finally, we propose a new construction for privacy-preserving certificate validation that provably satisfies all desired goals.
保护私隐外判证书验证
数字新冠证书是第一个广泛部署的最终用户加密证书。对于需要检查其(全球)客户是否满足某些健康政策的服务提供商(如航空公司或活动票务供应商)来说,验证此类Covid证书具有挑战性——不是因为涉及加密技术,而是因为发行者众多、不同的证书类型以及必须支持的特定国家政策的不断发展性质。由于Covid证书包含敏感的健康信息,它们(在线)呈现给非健康相关实体也会带来明显的隐私风险。为了解决这两个挑战,EU提出了一个将验证过程外包给验证器服务的规范,该验证器服务执行该过程并将结果通知服务提供者。世卫组织宣布将调整这一方法用于Covid-19以外的一般疫苗接种证书。虽然有助于提高服务提供商的安全性和隐私性,但他们的解决方案需要对了解用户所有健康相关详细信息的(中央)验证服务进行强信任假设。在我们的工作中,我们提出并正式建模了这种外包验证服务的隐私保护变体。在这个过程中,验证器学习它应该验证的属性,而不是用户身份。但是,验证器的断言被盲目地绑定到用户的标识,以确保所需的用户绑定。我们分析了模型中的EU规范,并表明它只满足这些目标的一个子集。我们的分析进一步表明,欧盟协议是不必要的复杂,可以大大简化,同时保持相同的(弱)安全级别。最后,我们提出了一种新的保护隐私的证书验证结构,该结构可证明地满足所有期望的目标。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信