Decentralized generation of multiple, uncorrelatable pseudonyms without trusted third parties

  • Authors:
  • Jan Lehnhardt;Adrian Spalka

  • Affiliations:
  • CompuGroup Medical Software GmbH, Dept. of Data Security and System Architecture, Koblenz, Germany;CompuGroup Medical Software GmbH, Dept. of Data Security and System Architecture, Koblenz, Germany and University of Bonn, Dept. of Computer Science III, Bonn, Germany

  • Venue:
  • TrustBus'11 Proceedings of the 8th international conference on Trust, privacy and security in digital business
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Regarding the increasing number of applications provided as external services, the importance of pseudonymous data as a means for privacy protection of user entities is growing. Along with it grows the relevance of secure and accurate generation, use and management of pseudonyms. In particular we consider the involvement of third parties in this process as potentially harmful, and therefore favor a decentralized pseudonym generation approach where the role of central components is reduced to a minimum. In this paper, we propose a pseudonym generation mechanism and focus on its implementation based on elliptic curve cryptography, in which every user entity can generate an arbitrary number of uncorrelatable pseudonyms with minimal effort, initially as well as at any later point in time. Because no sensitive information necessary for pseudonym generation is available on central components, our approach provides security as well as flexibility and usability.