Understanding the Identity-Transformation Approach in OIDC-Compatible Privacy-Preserving SSO Services
Jingqiang Lin, Baitao Zhang, Wei Wang, Quanwei Cai, Jiwu Jing, Huiyang He

TL;DR
This paper investigates the identity-transformation approach in OIDC-compatible privacy-preserving SSO, analyzing its relation to oblivious pseudo-random functions (OPRFs) and proposing new transformations satisfying security and privacy requirements.
Contribution
It uncovers the relationship between identity transformations in SSO and OPRFs, and constructs new transformations based on OPRFs that meet various security and privacy criteria.
Findings
Established the link between identity transformations and OPRFs.
Proved SSO-related properties of OPRF protocols.
Designed new identity transformations satisfying security and privacy requirements.
Abstract
OpenID Connect (OIDC) enables a user with commercial-off-the-shelf browsers to log into multiple websites, called relying parties (RPs), by her username and credential set up in another trusted web system, called the identity provider (IdP). Identity transformations are proposed in UppreSSO to provide OIDC-compatible SSO services, preventing both IdP-based login tracing and RP-based identity linkage. While security and privacy of SSO services in UppreSSO have been proved, several essential issues of this identity-transformation approach are not well studied. In this paper, we comprehensively investigate the approach as below. Firstly, several suggestions for the efficient integration of identity transformations in OIDC-compatible SSO are explained. Then, we uncover the relationship between identity-transformations in SSO and oblivious pseudo-random functions (OPRFs), and present two…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAccess Control and Trust · Cryptography and Data Security · Web Application Security Vulnerabilities
