Research and Security Analysis of Anonymous Identity Authentication in Trusted Computing
Yang Yang, Huanguo Zhang, Fan He, Bo Zhang
Abstract
Yang Yang, Huanguo Zhang, Fan He, Bo Zhang
Abstract
This paper introduces two anonymous identity authentication solution adopted by the Trusted Computing Group, i.e. privacy certification authority (Privacy CA) and direct anonymous attestation scheme (DAA). Both of the two solutions provide a means for remotely authenticating a trusted platform whilst preserving the userpsilas privacy. In this paper we give high level overview of DAA and focus on the analysis of security properties, such as pseudonymous authentication, random oracles and rogue tagging etc. We summarize the security and anonymity issues discovered recently and discuss a possible privacy flaw in the scheme that a colluding issuer and verifier can break anonymity to identify the real TPM. We also suggest possible way of fixing this weakness.
OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
This paper introduces two anonymous identity authentication solution adopted by the Trusted Computing Group, i.e. privacy certification authority (Privacy CA) and direct anonymous attestation scheme (DAA). Both of the two solutions provide a means for remotely authenticating a trusted platform whilst preserving the userpsilas privacy. In this paper we give high level overview of DAA and focus on the analysis of security properties, such as pseudonymous authentication, random oracles and rogue tagging etc. We summarize the security and anonymity issues discovered recently and discuss a possible privacy flaw in the scheme that a colluding issuer and verifier can break anonymity to identify the real TPM. We also suggest possible way of fixing this weakness.
Key concepts: Direct Anonymous Attestation, Anonymity, Computer security, Computer science, Trusted Computing, Authentication (law), Identity (music), Issuer