Sciweavers

ACISP
2005
Springer

Security Analysis and Fix of an Anonymous Credential System

14 years 6 months ago
Security Analysis and Fix of an Anonymous Credential System
Anonymous credentials are an important privacy-enhancing technique that allows users to convince a service provider of their legitimacy for service accesses in an anonymous manner. Among others, a fundamental feature of anonymous credentials is unlinkability, that is, multiple showings of the same credential should not be linked by the service providers, the issuing organization, or the coalition of the two. Recently, Persiano et. al. proposed an interesting anonymous credential system, which was claimed to be unlinkable. In this paper, we prove that their unlinkability claim is false. In particular, we show that the issuing organization can easily relate two showings of the same credential, point out the flaw in their original security proof and present a fix to avoid our attack. Keyword: Anonymous Credentials, Privacy, Unlinkability, Chameleon Certificate.
Yanjiang Yang, Feng Bao, Robert H. Deng
Added 26 Jun 2010
Updated 26 Jun 2010
Type Conference
Year 2005
Where ACISP
Authors Yanjiang Yang, Feng Bao, Robert H. Deng
Comments (0)