File Download

There are no files associated with this item.

  Links for fulltext
     (May Require Subscription)
Supplementary

Article: BLAC: Revoking repeatedly misbehaving anonymous users without relying on TTPs

TitleBLAC: Revoking repeatedly misbehaving anonymous users without relying on TTPs
Authors
KeywordsUser misbehavior
Privacy-enhanced revocation
Privacy
Anonymous blacklisting
Anonymous authentication
Issue Date2010
Citation
ACM Transactions on Information and System Security, 2010, v. 13, n. 4, article no. 39 How to Cite?
AbstractSeveral credential systems have been proposed in which users can authenticate to service providers anonymously. Since anonymity can give users the license to misbehave, some variants allow the selective deanonymization (or linking) of misbehaving users upon a complaint to a Trusted Third Party (TTP). The ability of the TTP to revoke a user's privacy at any time, however, is too strong a punishment for misbehavior. To limit the scope of deanonymization, some systems have been proposed in which users can be deanonymized only if they authenticate "too many times," such as "double spending" with electronic cash. While useful in some applications, such techniques cannot be generalized to more subjective definitions of misbehavior, for example, using such schemes it is not possible to block anonymous users who "deface too many Web pages" on a Web site. We present BLAC, the first anonymous credential system in which service providers can revoke the credentials of misbehaving users without relying on a TTP. Since revoked users remain anonymous, misbehaviors can be judged subjectively without users fearing arbitrary deanonymization by a TTP. Additionally, our construction supports a d-strikes-out revocation policy, whereby users who have been subjectively judged to have repeatedly misbehaved at least d times are revoked from the system. Thus, for the first time, it is indeed possible to block anonymous users who have "defaced too many Web pages" using our scheme. © 2010 ACM.
Persistent Identifierhttp://hdl.handle.net/10722/280773
ISSN
2018 Impact Factor: 2.667
2019 SCImago Journal Rankings: 0.673
ISI Accession Number ID

 

DC FieldValueLanguage
dc.contributor.authorTsang, Patrick P.-
dc.contributor.authorAu, Man Ho-
dc.contributor.authorKapadia, Apu-
dc.contributor.authorSmith, Sean W.-
dc.date.accessioned2020-02-17T14:34:54Z-
dc.date.available2020-02-17T14:34:54Z-
dc.date.issued2010-
dc.identifier.citationACM Transactions on Information and System Security, 2010, v. 13, n. 4, article no. 39-
dc.identifier.issn1094-9224-
dc.identifier.urihttp://hdl.handle.net/10722/280773-
dc.description.abstractSeveral credential systems have been proposed in which users can authenticate to service providers anonymously. Since anonymity can give users the license to misbehave, some variants allow the selective deanonymization (or linking) of misbehaving users upon a complaint to a Trusted Third Party (TTP). The ability of the TTP to revoke a user's privacy at any time, however, is too strong a punishment for misbehavior. To limit the scope of deanonymization, some systems have been proposed in which users can be deanonymized only if they authenticate "too many times," such as "double spending" with electronic cash. While useful in some applications, such techniques cannot be generalized to more subjective definitions of misbehavior, for example, using such schemes it is not possible to block anonymous users who "deface too many Web pages" on a Web site. We present BLAC, the first anonymous credential system in which service providers can revoke the credentials of misbehaving users without relying on a TTP. Since revoked users remain anonymous, misbehaviors can be judged subjectively without users fearing arbitrary deanonymization by a TTP. Additionally, our construction supports a d-strikes-out revocation policy, whereby users who have been subjectively judged to have repeatedly misbehaved at least d times are revoked from the system. Thus, for the first time, it is indeed possible to block anonymous users who have "defaced too many Web pages" using our scheme. © 2010 ACM.-
dc.languageeng-
dc.relation.ispartofACM Transactions on Information and System Security-
dc.subjectUser misbehavior-
dc.subjectPrivacy-enhanced revocation-
dc.subjectPrivacy-
dc.subjectAnonymous blacklisting-
dc.subjectAnonymous authentication-
dc.titleBLAC: Revoking repeatedly misbehaving anonymous users without relying on TTPs-
dc.typeArticle-
dc.description.naturelink_to_subscribed_fulltext-
dc.identifier.doi10.1145/1880022.1880033-
dc.identifier.scopuseid_2-s2.0-78651408573-
dc.identifier.volume13-
dc.identifier.issue4-
dc.identifier.spagearticle no. 39-
dc.identifier.epagearticle no. 39-
dc.identifier.eissn1557-7406-
dc.identifier.isiWOS:000285713900011-
dc.identifier.issnl1094-9224-

Export via OAI-PMH Interface in XML Formats


OR


Export to Other Non-XML Formats