Towards user-friendly credential transfer on open credential platforms

  • Authors:
  • Kari Kostiainen;N. Asokan;Alexandra Afanasyeva

  • Affiliations:
  • Nokia Research Center, Helsinki;Nokia Research Center, Helsinki;Saint-Petersburg State University of Aerospace Instrumentation

  • Venue:
  • ACNS'11 Proceedings of the 9th international conference on Applied cryptography and network security
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Hardware-based "trusted execution environments" (TrEEs) are becoming widely available and open credentials platforms allow any service provider to issue credentials to such TrEEs. Credential transfer in an open system poses usability challenges: Certain credential issuers may disallow direct credential migration and require explicit credential re-provisioning, and each credential provisioning typically requires separate user authentication. Additionally, the lack of secure user input mechanisms on existing TrEEs makes the required user identity binding to TrEEs challenging. In this paper we present a practical credential transfer protocol that can be implemented using devices available today. Our protocol makes credential transfer user-friendly with delegated, automatic re-provisioning, and can be integrated to a typical device initialization process.