UPPRESSO: Untraceable and Unlinkable Privacy-PREserving Single Sign-On Services
Chengqian Guo (1), Jingqiang Lin (2), Quanwei Cai (3), Wei Wang (2),, Wentian Zhu (2), Jiwu Jing (4), Qiongxiao Wang (5), Bin Zhao (6), Fengjun Li, (7) ((1) Yuncheng Vocational, Technical University, China, (2) School of, Cyber Security, University of Science

TL;DR
UPPRESSO introduces a privacy-preserving SSO scheme that generates untraceable ephemeral identities, preventing identity tracking and profile linking across relying parties while maintaining compatibility with existing protocols.
Contribution
It proposes an identity-transformation approach for untraceable pseudo-identities in SSO, enhancing privacy without requiring additional client-side software.
Findings
Protects user identities against curious IdPs and colluding RPs.
Works with existing SSO protocols and browsers without plug-ins.
Achieves reasonable performance overheads.
Abstract
Single sign-on (SSO) allows a user to maintain only the credential for an identity provider (IdP) to log into multiple relying parties (RPs). However, SSO introduces privacy threats, as (a) a curious IdP could track a user's all visits to RPs, and (b) colluding RPs could learn a user's online profile by linking her identities across these RPs. This paper presents a privacypreserving SSO scheme, called UPPRESSO, to protect an honest user's online profile against (a) an honest-but-curious IdP and (b) malicious RPs colluding with other users. UPPRESSO proposes an identity-transformation approach to generate untraceable ephemeral pseudo-identities for an RP and a user from which the target RP derives a permanent account for the user, while the transformations also provide unlinkability. This approach protects the identities of the user and the target RPs in a login flow, while working…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Authentication Protocols Security · User Authentication and Security Systems · Cryptography and Data Security
