Enhancing privacy in identity management systems

  • Authors:
  • Steven Gevers;Verslype Verslype;Bart De Decker

  • Affiliations:
  • K.U.Leuven, Leuven, Belgium;K.U.Leuven, Leuven, Belgium;K.U.Leuven, Leuven, Belgium

  • Venue:
  • Proceedings of the 2007 ACM workshop on Privacy in electronic society
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

User-privacy in existing identity management systems (IMS) can be improved.Indeed, private credential systems offer privacy enhancing capabilities not yet included in current IMS; e.g. proving claims such as age 18, with age an attribute. This paper introduces privacy enhanced claim URIs which enable to request personal data in a privacy friendly way. We show how many private credential capabilities can be achieved in current IMS without using private credentials and continue by showing how these URIs allow integration of private credential systems in Microsoft Cardspace. Since our approach is very simple and widely applicable, it allows to enhance privacy friendliness of today's online transactions.