A self-certified and Sybil-free framework for secure digital identity domain buildup

  • Authors:
  • Christer Andersson;Markulf Kohlweiss;Leonardo A. Martucci;Andriy Panchenko

  • Affiliations:
  • Karlstads Universitet, Department of Computer Science, Karlstad, Sweden;Katholieke Universiteit Leuven, ESAT, COSIC, Leuven, Heverlee, Belgium;Karlstads Universitet, Department of Computer Science, Karlstad, Sweden;RWTH Aachen University, Department of Computer Science, Informatik IV, Aachen, Germany

  • Venue:
  • WISTP'08 Proceedings of the 2nd IFIP WG 11.2 international conference on Information security theory and practices: smart devices, convergence and next generation networks
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

An attacker who can control arbitrarily many user identitiescan break the security properties of most conceivable systems. This iscalled a "Sybil attack". We present a solution to this problem that doesnot require online communication with a trusted third party and that inaddition preserves the privacy of honest users. Given an initial so-called Sybil-free identity domain, our proposal can be used for deriving Sybilfreeunlinkable pseudonyms associated with other identity domains. Thepseudonyms are self-certified and computed by the users themselves fromtheir cryptographic long-term identities.