Attribute-based credentials for trust : identity in the information society /

Kai Rannenberg, Jan Camenisch, Ahmad Sabouri, editors.

Book Cover
Names: Rannenberg, Kai, | Camenisch, Jan, | Sabouri, Ahmad,
Published: Cham, Switzerland : Springer, [2014]
Topics: Data protection. | Data encryption (Computer science) | Data protection - Law and legislation - European Union countries.
Regions: Europe - European Union countries.
Genres: Electronic books.
505 0 |aForeword; Preface; Contents; 1 Introduction; 1.1 Identity Management and its Privacy Issues; 1.2 Privacy-ABCs for Privacy Enhanced Identity Management; 1.3 The ABC4Trust Project Goals; 1.4 Overview of the Pilots; 1.4.1 Online Course Evaluation; 1.4.2 School Community Interaction Platform; References; 2 An Architecture for Privacy-ABCs; 2.1 Concepts and Features of Privacy-ABCs; 2.1.1 User Attributes; 2.1.2 Existing Solutions; 2.1.3 Basic Concepts of Privacy-ABCs; Credentials; Presentation; Key Binding; Pseudonyms; Inspection; Credential Issuance
505 8 |a2.1.3.7 Revocation2.1.4 Security and Privacy Features; Basic Presentation; Key Binding; Advanced Issuance; Pseudonyms; Inspection; Revocation; 2.2 Architecture Highlights; 2.3 Architectural Design; 2.3.1 Overview of the Components; Application Layer; ABCE Layer; Crypto Layer; Storage & Communication Components; 2.4 Deployment of the Architecture; 2.4.1 Setup and Storage; 2.4.2 Presentation of a Token; 2.4.3 Issuance of a Credential; Simple Issuance; Advanced Issuance; 2.4.4 Inspection
505 8 |a2.4.5 Revocation2.5 Language Framework; 2.5.1 Example Scenario; 2.5.2 Credential Specification; 2.5.3 Issuer, Revocation, and System Parameters; 2.5.4 Presentation Policy with Basic Features; 2.5.5 Presentation and Issuance Token; 2.5.6 Presentation Policy with Extended Features; 2.5.7 Interaction with the User Interface; 2.6 Applicability to Existing Identity Infrastructures; 2.6.1 WS-*; 2.6.2 SAML; 2.6.3 OpenID; 2.6.4 OAuth; Authorization grant; Access token; 2.6.5 X.509 PKI; 2.6.6 Integration Summary; 2.7 Trust Relationships in the Ecosystem of Privacy-ABCs
505 8 |a2.7.1 The Meaning of Trust2.7.2 Related Work; 2.7.3 Trust Relationships; Assumptions; Trust by all the parties; Users' Perspective; Verifiers' Perspective; Issuers' Perspective; Inspectors' Perspective; Revocation Authorities' Perspective; 2.8 Policy-based View of the Architecture; References; 3 Cryptographic Protocols Underlying Privacy-ABCs; 3.1 Overview of Cryptographic Architecture; 3.1.1 Key Generation Orchestration; 3.1.2 Presentation Orchestration; 3.1.3 Verification Orchestration; 3.1.4 Issuance Orchestration
505 8 |a3.1.5 Building Blocks3.1.5.1 Proof Interfaces and ZkModules; 3.1.6 Proof Engine; 3.2 Cryptographic Primitives; 3.2.1 Algebraic Background; Groups; Hardness Assumptions; 3.2.2 Zero-Knowledge Proofs of Knowledge; Four Square Range Proof; 3.2.3 Commitment Schemes; Pedersen/Damg˚ard-Fujisaki Commitments; 3.2.4 Blind Signature Schemes; CL-Signatures; Brands Signatures; 3.2.5 Verifiable Encryption; The Camenisch-Shoup Encryption Scheme; 3.2.6 Scope-Exclusive Pseudonyms; Efficient Scope Exclusive Pseudonyms; 3.2.7 Revocation
520 |aThe need for information privacy and security continues to grow and gets increasingly recognized. In this regard, Privacy-preserving Attribute-based Credentials (Privacy-ABCs) are elegant techniques to provide secure yet privacy-respecting access control. This book addresses the federation and interchangeability of Privacy-ABC technologies. It defines a common, unified architecture for Privacy-ABC systems that allows their respective features to be compared and combined Further, this book presents open reference implementations of selected Privacy-ABC systems and explains how to deploy them i.
