A Framework for Evaluating Privacy Protection of Authentication Systems
Toru Nakamura, Shunsuke Inenaga, Daisuke Ikeda, Kensuke Baba, Hiroto Yasuura
Abstract
Open-access reader
Toru Nakamura, Shunsuke Inenaga, Daisuke Ikeda, Kensuke Baba, Hiroto Yasuura
Abstract
Open-access reader
Authentication plays a central role in a variety of social infrastructures such as access control or e-money. Not only should authentication systems be convenient, practical and secure, but also they are often required to protect users’ privacy. In this paper, we present an authentication framework for which identifiability, anonymity, linkability and unlinkability are well defined. Using our framework, we are able to evaluate and compare privacy protection properties of various authentication systems based on different core technologies. One of our main results is that authentication systems based on group signatures and one-time ID are shown to be equivalent in the sense of protecting users’ privacy (more precisely they both have anonymity and unlinkability).
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Authentication plays a central role in a variety of social infrastructures such as access control or e-money. Not only should authentication systems be convenient, practical and secure, but also they are often required to protect users’ privacy. In this paper, we present an authentication framework for which identifiability, anonymity, linkability and unlinkability are well defined. Using our framework, we are able to evaluate and compare privacy protection properties of various authentication systems based on different core technologies. One of our main results is that authentication systems based on group signatures and one-time ID are shown to be equivalent in the sense of protecting users’ privacy (more precisely they both have anonymity and unlinkability).
Key concepts: Anonymity, Computer security, Computer science, Authentication (law), Identifiability, Variety (cybernetics), Internet privacy, Privacy protection