Privacy-Preserving Outsourced Certificate Validation

نویسندگان

چکیده

Digital Covid certificates are the first widely deployed end-user cryptographic certificates. For service providers, such as airlines or event ticket vendors, that needed to check their (global) customers satisfy certain health policies, verification of was challenging though - not because cryptography involved, but due multitude issuers, different certificate types and evolving nature country-specific policies had be supported. As contain sensitive information, (online) presentation non-health related entities also poses clear privacy risk. To address both challenges, EU proposed a specification for outsourcing process validator service, executes informs providers result. The WHO announced adapt this approach general vaccination credentials beyond Covid-19. While being beneficial improve security solution requires strong trust assumption (central) validation learns all health-related details users. In our work, we propose formally model privacy-preserving variant an outsourced service. Therein attributes it is supposed verify, users identity. Still, validator’s assertion blindly bound user’s identity ensure desired user-binding. We analyze in show only meets subset those goals. Our analysis further shows protocol unnecessarily complex can significantly simplified while maintaining same (weak) level security. Finally, new construction provably satisfies

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Privacy-preserving face recognition with outsourced computation

Face recognition is one of the most important biometrics pattern recognitions, which has been widely applied in a variety of enterprise, civilian and law enforcement. The privacy of biometrics data raises important concerns, in particular if computations over biometric data is performed at untrusted servers. In previous work of privacy-preserving face recognition, in order to protect individual...

متن کامل

Privacy-Preserving Access of Outsourced Data via Oblivious RAM Simulation

Suppose a client, Alice, has outsourced her data to an external storage provider, Bob, because he has capacity for her massive data set, of size n, whereas her private storage is much smaller—say, of size O(n), for some constant r > 1. Alice trusts Bob to maintain her data, but she would like to keep its contents private. She can encrypt her data, of course, but she also wishes to keep her acce...

متن کامل

Privacy-Preserving in Outsourced Transaction Databases from Association Rules Mining

Data mining-as-a-service has been selected as considerable research issue by researchers. An organization (data owner) can outsource its mining needs like resources or expertise to a third party service provider (server). However, both the association rules and the items of the outsourced transaction database are private property of data owner. The data owner encrypts its data, send data and mi...

متن کامل

Privacy-Preserving Verification of Aggregate Queries on Outsourced Database

It is often desirable to be able to guarantee the integrity of historical data, ensuring that any subsequent modifications to the data can be detected. It would be especially convenient to extend such proofs of integrity to certain computations performed later using the historic data. We approach this question in the context of outsourced databases, where a data owner delegates the ability to a...

متن کامل

Privacy-preserving Mining of Association Rules from Outsourced Transaction Databases

Spurred by developments such as cloud computing, there has been considerable recent interest in the paradigm of datamining-as-service. A company (data owner) lacking in expertise or computational resources can outsource its mining needs to a third party service provider (server). However, both the items and the association rules of the outsourced database are considered private property of the ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Proceedings on Privacy Enhancing Technologies

سال: 2023

ISSN: ['2299-0984']

DOI: https://doi.org/10.56553/popets-2023-0113