The Experts below are selected from a list of 360 Experts worldwide ranked by ideXlab platform

Elisa Bertino - One of the best experts on this subject based on the ideXlab platform.

  • prividex privacy preserving and secure exchange of Digital Identity assets
    The Web Conference, 2019
    Co-Authors: Hasini Gunasinghe, Elisa Bertino, Ashish Kundu, Hugo Krawczyk, Suresh N Chari, Kapil Singh
    Abstract:

    User's Digital Identity information has privacy and security requirements. Privacy requirements include confidentiality of the Identity information itself, anonymity of those who verify and consume a user's Identity information and unlinkability of online transactions which involve a user's Identity. Security requirements include correctness, ownership assurance and prevention of counterfeits of a user's Identity information. Such privacy and security requirements, although conflicting, are critical for Identity management systems enabling the exchange of users' Identity information between different parties during the execution of online transactions. Addressing all such requirements, without a centralized party managing the Identity exchange transactions, raises several challenges. This paper presents a decentralized protocol for privacy preserving exchange of users' Identity information addressing such challenges. The proposed protocol leverages advances in blockchain and zero knowledge proof technologies, as the main building blocks. We provide prototype implementations of the main building blocks of the protocol and assess its performance and security.

  • An Overview of VeryIDX - A Privacy-Preserving Digital Identity Management System for Mobile Devices
    2014
    Co-Authors: Federica Paci, Anna Squicciarini, Sam Kerr, Elisa Bertino, Jungha Woo
    Abstract:

    Abstract — Users increasingly use their mobile devices to communicate, to conduct business transaction and access resources and services. In such a scenario, Digital iden-tity management (DIM) technology is fundamental in cus-tomizing user experience, protecting privacy, underpinning accountability in business transactions, and in complying with regulatory controls. Users Identity consists of data, referred to as Identity attributes, that encode relevant-security properties of the clients. However, Identity attributes can be target of several attacks: the loss or theft of mobile devices results in a exposure of Identity attributes; Identity attributes that are send over WI-FI or 3G networks can be easily inter-cepted; Identity attributes can also be captured via Bluetooth connections without the user’s consent; and mobile viruses, worms and Trojan horses can access the Identity attributes stored on mobile devices if this information is not protected by passwords or PIN numbers. Therefore, assuring privacy and security of Identity attributes, as well as of any sensitive information stored on mobile devices is crucial. In this paper we address such problems by proposing an approach to manage user Identity attributes by assuring their privacy-preserving usage. The approach is based on the concept of privacy preserving multi-factor authentication achieved by a new cryptographic primitive which uses aggregate signatures on commitments that are then used for aggregate zero-knowledge proof of knowledge (ZKPK) protocols. We present the implementation of such approach on Nokia NFC cellular phones and report performance evaluation results. Index Terms — Digital Identity management, Identity at-tributes, privacy, mobile devices I

  • biometrics based identifiers for Digital Identity management
    Identity and Trust on the Internet, 2010
    Co-Authors: Abhilasha Bhargavspantzel, Elisa Bertino, Anna Cinzia Squicciarini, Xiangwei Kong, Weike Zhang
    Abstract:

    We present algorithms to reliably generate biometric identifiers from a user's biometric image which in turn is used for Identity verification possibly in conjunction with cryptographic keys. The biometric identifier generation algorithms employ image hashing functions using singular value decomposition and support vector classification techniques. Our algorithms capture generic biometric features that ensure unique and repeatable biometric identifiers. We provide an empirical evaluation of our techniques using 2569 images of 488 different individuals for three types of biometric images; namely fingerprint, iris and face. Based on the biometric type and the classification models, as a result of the empirical evaluation we can generate biometric identifiers ranging from 64 bits up to 214 bits. We provide an example use of the biometric identifiers in privacy preserving multi-factor Identity verification based on zero knowledge proofs. Therefore several Identity verification factors, including various traditional Identity attributes, can be used in conjunction with one or more biometrics of the individual to provide strong Identity verification. We also ensure security and privacy of the biometric data. More specifically, we analyze several attack scenarios. We assure privacy of the biometric using the one-way hashing property, in that no information about the original biometric image is revealed from the biometric identifier.

  • Digital Identity Management and Trust Negotiation
    Security for Web Services and Service-Oriented Architectures, 2009
    Co-Authors: Elisa Bertino, Federica Paci, Lorenzo D. Martino, Anna Cinzia Squicciarini
    Abstract:

    As more and more activities and processes such as shopping, discussion, entertainment and business collaboration are conducted in the cyber world, Digital identities, be them user names, passwords, Digital certificates, or biometric features and Digital Identity management have become fundamental to underpinning accountability in business relationships, controlling the customization of the user experience, protecting privacy, and adhering to regulatory controls. In its broadest sense, Identity management revolves around the enterprise process of adding or removing (provisioning) Digital Identity information and managing their authentication and associated access rights (policy) to information systems and applications (“access management”).

  • privacy preserving Digital Identity management for cloud computing
    IEEE Data(base) Engineering Bulletin, 2009
    Co-Authors: Elisa Bertino, Federica Paci, Rodolfo Ferrini, Ning Shang
    Abstract:

    Digital Identity management services are crucial in cloud computing infrastructures to authenticate users and to support flexible access control to services, based on user Identity properties (also called attributes) and past interaction histories. Such services should preserve the privacy of users, while at the same time enhancing interoperability across multiple domains and simplifying management of Identity verification. In this paper we propose an approach addressing such requirements, based on the use of high-level Identity verification policies expressed in terms of Identity attributes, zero-knolwedge proof protocols, and semantic matching techniques. The paper describes the basic techniques we adopt and the architeture of a system developed based on these techniques, and reports performance experimental

Oskar Josef Gstrein - One of the best experts on this subject based on the ideXlab platform.

  • Digital Identity and Distributed Ledger Technology: Paving the Way to a Neo-Feudal Brave New World?
    Frontiers in Blockchain, 2020
    Co-Authors: Oskar Josef Gstrein, Dimitry Kochenov
    Abstract:

    While the Digital layer of social interaction continues to evolve, the recently proclaimed hopes in the development of Digital Identity could be both naif and dangerous. Rather than just asking ourselves how we could digitize existing features of Identity management, and corresponding financial transactions on a community or state level, we submit that truly useful and innovative Digital identities need to be accompanied by some significant rethinking of the essential basics behind the organization of the world. Once Digital technologies leave the realm of purely on-line or deeply local projects, the confrontation with the world of citizenship’s biases and the random distribution of rights and duties precisely on the presumption of the lack of any choice and absolute pre-emption of any disagreement comes into a direct conflict with all the benefits Distributed Ledger Technology purports to enable. Some proponents of Distributed Ledger Technology-based Identity systems envisage ‘cloud communities’ with truly ‘self-sovereign’ individuals picking and choosing which communities they belong to. We rather see a clear risk that when implemented at the global scale, Digital Identity systems could be deeply harmful, reinforcing and amplifying the most repugnant aspects of contemporary citizenship. In this contribution we present a categorization of existing Digital Identity systems from a governance perspective, and discuss it on basis of three corresponding case studies which allow us to infer opportunities and limitations of Distributed Ledger Technology based Identity. Subsequently, we put our findings in the context of existing preconditions of citizenship law, and conclude with a suggestion of a combination of several tests which we propose to avoid the plunge into a neo-feudal ‘brave new world’. We would like to draw attention to the perspective that applying Digital Identity without rethinking the totalitarian assumptions behind the citizenship status will result in perfecting the current inequitable system, which is a move away from striving towards justice and a more dignified future of humanity. We see the danger that those might be provided with plenty of opportunities who already do not lack such under current governance structures, while less privileged individuals will witness their already weak position becoming increasingly worse.

  • Digital Identity and distributed ledger technology paving the way to a neo feudal brave new world
    Social Science Research Network, 2020
    Co-Authors: Oskar Josef Gstrein, Dimitry Kochenov
    Abstract:

    While the Digital layer of social interaction continues to evolve, the recently proclaimed hopes in the development of Digital Identity could be both naif and dangerous. Rather than just asking ourselves how we could digitize existing features of Identity management, and corresponding financial transactions on a community or state level, we submit that truly useful and innovative Digital identities need to be accompanied by some significant rethinking of the essential basics behind the organization of the world. Once Digital technologies leave the realm of purely on-line or deeply local projects, the confrontation with the world of citizenship’s biases and the random distribution of rights and duties precisely on the presumption of the lack of any choice and absolute pre-emption of any disagreement comes into a direct conflict with all the benefits Distributed Ledger Technology purports to enable. Some proponents of Distributed Ledger Technology-based Identity systems envisage ‘cloud communities’ with truly ‘self-sovereign’ individuals picking and choosing which communities they belong to. We rather see a clear risk that when implemented at the global scale, Digital Identity systems could be deeply harmful, reinforcing and amplifying the most repugnant aspects of contemporary citizenship. In this contribution we present a categorization of existing Digital Identity systems from a governance perspective, and discuss it on basis of three corresponding case studies which allow us to infer opportunities and limitations of Distributed Ledger Technology based Identity. Subsequently, we put our findings in the context of existing preconditions of citizenship law, and conclude with a suggestion of a combination of several tests which we propose to avoid the plunge into a neo-feudal ‘brave new world’. We would like to draw attention to the perspective that applying Digital Identity without rethinking the totalitarian assumptions behind the citizenship status will result in perfecting the current inequitable system, which is a move away from striving towards justice and a more dignified future of humanity. We see the danger that those might be provided with plenty of opportunity who already do not lack such under current governance structures, while less privileged individuals will witness their already weak position becoming increasingly worse.

  • ‘Self-Sovereign Identity’ management, data ownership and the future of Digital Identity
    2019
    Co-Authors: Andrej Zwitter, Oskar Josef Gstrein, Evan Yap
    Abstract:

    While ‘classical’ human Identity has kept philosophers busy for millennia, ‘Digital Identity’ seems primarily machine related. Telephone numbers, E-Mail inboxes, or Internet Protocol (IP)-addresses are irrelevant to define us as human beings at first glance. However, with the omnipresence of Digital space the Digital aspects of Identity gain importance. In our recent paper ‘Digital Identity and the Blockchain: Universal Identity Management and the concept of the ‘Self-Sovereign’ Individual’ we assess the theoretical conditions and the practical examples that establish the practice in first attempts to create self-sovereign Digital Identity systems. This treatment by necessity covers issues around Digital Identity, data ownership and privacy.

  • Digital Identity and the Blockchain: Universal Identity Management and the Concept of the “Self-Sovereign” Individual
    SSRN Electronic Journal, 2019
    Co-Authors: Andrej Zwitter, Oskar Josef Gstrein, Evan Yap
    Abstract:

    While ‘classical’ human Identity has kept philosophers busy since millennia, ‘Digital Identity’ seems primarily machine related. Telephone numbers, E-Mail inboxes, or Internet Protocol (IP)-addresses are irrelevant to define us as human beings at first glance. However, with the omnipresence of Digital space the Digital aspects of Identity gain importance. In this submission, we aim to put recent developments in context and provide a categorization to frame the landscape as developments proceed rapidly. First, we present selected philosophical perspectives on Identity. Secondly, we explore how the legal landscape is approaching Identity from a traditional dogmatic perspective both in national and international law. After blending the insights from those sections together in a third step, we will go on to describe and discuss current developments that are driven by the emergence of new tools such as ‘Distributed Ledger Technology’ and ‘Zero Knowledge Proof’. One of our main findings is that the management of Digital Identity is transforming from a purpose driven necessity towards a self-standing activity that becomes a resource for many Digital applications. In other words, whereas traditionally Identity is addressed in a predominantly sectoral fashion whenever necessary, new technologies transform Digital Identity management into a basic infrastructural service, sometimes even a commodity. This coincides with a trend to take the ‘control’ over Identity away from governmental institutions and corporate actors to ‘self-sovereign individuals’, who have now the opportunity to manage their Digital self autonomously. To make our conceptual statements more relevant, we present several already existing use cases in the public and private sector. Subsequently, we discuss potential risks that should be mitigated in order to create a desirable relationship between the individual, public institutions, and the private sector in a world where self-sovereign Identity management has become the norm. We will illustrate these issues along the discussion around privacy, as well as the development of backup mechanisms for Digital identities. Despite the undeniable potential for the management of Identity, we suggest that particularly at this point in time there is a clear need to make detailed (non-technological) governance decisions impacting the general design and implementation of self-sovereign Identity systems.

Rafail Ostrovsky - One of the best experts on this subject based on the ideXlab platform.

  • fast Digital Identity revocation extended abstract
    International Cryptology Conference, 1998
    Co-Authors: William Aiello, Sachin Lodha, Rafail Ostrovsky
    Abstract:

    The availability of fast and reliable Digital Identities is an essential ingredient for the successful implementation of the public-key infrastructure of the Internet. All Digital Identity schemes must include a method for revoking someone's Digital Identity in the case that this Identity is stolen (or canceled) before its expiration date (similar to the cancelation of a credit-cards in the case that they are stolen). In 1995, S. Micali proposed an elegant method of Identity revocation which requires very little communication between users and verifiers in the system. In this paper, we extend his scheme by reducing the overall CA to Directory communication, while still maintaining the same tiny user to vendor communication. We contrast our scheme to other proposals as well.

  • Fast Digital Identity revocation
    Lecture Notes in Computer Science, 1998
    Co-Authors: William Aiello, Sachin Lodha, Rafail Ostrovsky
    Abstract:

    The availability of fast and reliable Digital Identities is an essential ingredient for the successful implementation of the public-key infrastructure of the Internet. All Digital Identity schemes must include a method for revoking someone's Digital Identity in the case that this Identity is stolen (or canceled) before its expiration date (similar to the cancelation of a credit-cards in the case that they are stolen). In 1995, S. Micali proposed an elegant method of Identity revocation which requires very little communication between users and verifiers in the system. In this paper, we extend his scheme by reducing the overall CA to Directory communication, while still maintaining the same tiny user to vendor communication. We contrast our scheme to other proposals as well.

Dimitry Kochenov - One of the best experts on this subject based on the ideXlab platform.

  • Digital Identity and Distributed Ledger Technology: Paving the Way to a Neo-Feudal Brave New World?
    Frontiers in Blockchain, 2020
    Co-Authors: Oskar Josef Gstrein, Dimitry Kochenov
    Abstract:

    While the Digital layer of social interaction continues to evolve, the recently proclaimed hopes in the development of Digital Identity could be both naif and dangerous. Rather than just asking ourselves how we could digitize existing features of Identity management, and corresponding financial transactions on a community or state level, we submit that truly useful and innovative Digital identities need to be accompanied by some significant rethinking of the essential basics behind the organization of the world. Once Digital technologies leave the realm of purely on-line or deeply local projects, the confrontation with the world of citizenship’s biases and the random distribution of rights and duties precisely on the presumption of the lack of any choice and absolute pre-emption of any disagreement comes into a direct conflict with all the benefits Distributed Ledger Technology purports to enable. Some proponents of Distributed Ledger Technology-based Identity systems envisage ‘cloud communities’ with truly ‘self-sovereign’ individuals picking and choosing which communities they belong to. We rather see a clear risk that when implemented at the global scale, Digital Identity systems could be deeply harmful, reinforcing and amplifying the most repugnant aspects of contemporary citizenship. In this contribution we present a categorization of existing Digital Identity systems from a governance perspective, and discuss it on basis of three corresponding case studies which allow us to infer opportunities and limitations of Distributed Ledger Technology based Identity. Subsequently, we put our findings in the context of existing preconditions of citizenship law, and conclude with a suggestion of a combination of several tests which we propose to avoid the plunge into a neo-feudal ‘brave new world’. We would like to draw attention to the perspective that applying Digital Identity without rethinking the totalitarian assumptions behind the citizenship status will result in perfecting the current inequitable system, which is a move away from striving towards justice and a more dignified future of humanity. We see the danger that those might be provided with plenty of opportunities who already do not lack such under current governance structures, while less privileged individuals will witness their already weak position becoming increasingly worse.

  • Digital Identity and distributed ledger technology paving the way to a neo feudal brave new world
    Social Science Research Network, 2020
    Co-Authors: Oskar Josef Gstrein, Dimitry Kochenov
    Abstract:

    While the Digital layer of social interaction continues to evolve, the recently proclaimed hopes in the development of Digital Identity could be both naif and dangerous. Rather than just asking ourselves how we could digitize existing features of Identity management, and corresponding financial transactions on a community or state level, we submit that truly useful and innovative Digital identities need to be accompanied by some significant rethinking of the essential basics behind the organization of the world. Once Digital technologies leave the realm of purely on-line or deeply local projects, the confrontation with the world of citizenship’s biases and the random distribution of rights and duties precisely on the presumption of the lack of any choice and absolute pre-emption of any disagreement comes into a direct conflict with all the benefits Distributed Ledger Technology purports to enable. Some proponents of Distributed Ledger Technology-based Identity systems envisage ‘cloud communities’ with truly ‘self-sovereign’ individuals picking and choosing which communities they belong to. We rather see a clear risk that when implemented at the global scale, Digital Identity systems could be deeply harmful, reinforcing and amplifying the most repugnant aspects of contemporary citizenship. In this contribution we present a categorization of existing Digital Identity systems from a governance perspective, and discuss it on basis of three corresponding case studies which allow us to infer opportunities and limitations of Distributed Ledger Technology based Identity. Subsequently, we put our findings in the context of existing preconditions of citizenship law, and conclude with a suggestion of a combination of several tests which we propose to avoid the plunge into a neo-feudal ‘brave new world’. We would like to draw attention to the perspective that applying Digital Identity without rethinking the totalitarian assumptions behind the citizenship status will result in perfecting the current inequitable system, which is a move away from striving towards justice and a more dignified future of humanity. We see the danger that those might be provided with plenty of opportunity who already do not lack such under current governance structures, while less privileged individuals will witness their already weak position becoming increasingly worse.

Abhilasha Bhargavspantzel - One of the best experts on this subject based on the ideXlab platform.

  • biometrics based identifiers for Digital Identity management
    Identity and Trust on the Internet, 2010
    Co-Authors: Abhilasha Bhargavspantzel, Elisa Bertino, Anna Cinzia Squicciarini, Xiangwei Kong, Weike Zhang
    Abstract:

    We present algorithms to reliably generate biometric identifiers from a user's biometric image which in turn is used for Identity verification possibly in conjunction with cryptographic keys. The biometric identifier generation algorithms employ image hashing functions using singular value decomposition and support vector classification techniques. Our algorithms capture generic biometric features that ensure unique and repeatable biometric identifiers. We provide an empirical evaluation of our techniques using 2569 images of 488 different individuals for three types of biometric images; namely fingerprint, iris and face. Based on the biometric type and the classification models, as a result of the empirical evaluation we can generate biometric identifiers ranging from 64 bits up to 214 bits. We provide an example use of the biometric identifiers in privacy preserving multi-factor Identity verification based on zero knowledge proofs. Therefore several Identity verification factors, including various traditional Identity attributes, can be used in conjunction with one or more biometrics of the individual to provide strong Identity verification. We also ensure security and privacy of the biometric data. More specifically, we analyze several attack scenarios. We assure privacy of the biometric using the one-way hashing property, in that no information about the original biometric image is revealed from the biometric identifier.

  • automatic compliance of privacy policies in federated Digital Identity management
    Policies for Distributed Systems and Networks, 2008
    Co-Authors: Anna Cinzia Squicciarini, Abhilasha Bhargavspantzel, M C Mont, Elisa Bertino
    Abstract:

    Privacy [4] in the Digital world is an important problem which is becoming even more pressing as new collaborative applications are developed. The lack of privacy preserving mechanisms is particularly problematic in federated Identity management contexts. In such a context, users can seamlessly interact with a variety of federated web services, through the use of single-sign-on mechanisms and the capability of sharing personal data among these web services. We argue that comprehensive privacy policies should be stated by federated service providers and proactively checked by these providers, before disclosing users' data to federated partners. To address such requirements, we introduce mechanisms and algorithms for policy compliance checking between federated service providers, based on an innovative policy subsumption approach. We formally introduce and analyze our approach.

  • policy languages for Digital Identity management in federation systems
    IEEE International Workshop on Policies for Distributed Systems and Networks, 2006
    Co-Authors: Elisa Bertino, Abhilasha Bhargavspantzel, Anna Squicciarini
    Abstract:

    The goal of service provider federations is to support a controlled method by which distributed organizations can provide services to qualified individuals and manage their Identity attributes at an inter-organizational level. In order to make access control decisions the history of activities should be accounted for, therefore it is necessary to record information on interactions among the federation entities. To achieve these goals we propose a comprehensive assertion language able to support description of static and dynamic properties of the federation system. The assertions are a powerful means to describe the behavior of the entities interacting in the federation, and to define policies controlling access to services and privacy policies. We also propose a log-based approach for capturing the history of activities within the federation implemented as a set of tables stored at databases at the various organizations in the federation. We illustrate how, by using different types of queries on such tables, security properties of the federation can be verified.

  • traceable and automatic compliance of privacy policies in federated Digital Identity management
    Lecture Notes in Computer Science, 2006
    Co-Authors: Anna Cinzia Squicciarini, Abhilasha Bhargavspantzel, Alexei Czeskis, Elisa Bertino
    Abstract:

    Digital Identity is defined as the Digital representation of the information known about a specific individual or organization. An emerging approach for protecting identities of individuals while at the same time enhancing user convenience is to focus on inter-organization management of Identity information. This is referred to as federated Identity management. In this paper we develop an approach to support privacy controlled sharing of Identity attributes and harmonization of privacy policies in federated environments. Policy harmonizations mechanisms make it possible to determine whether or not the transfer of Identity attributes from one entity to another violate the privacy policies stated by the former. We also provide mechanisms for tracing the release of user's Identity attributes within the federation. Such approach entails a form of accountability since an entity non-compliant with the users original privacy preferences can be identified. Finally, a comprehensive security analysis details security properties is also offered.

  • establishing and protecting Digital Identity in federation systems
    Digital Identity Management, 2005
    Co-Authors: Abhilasha Bhargavspantzel, Anna Squicciarini, Elisa Bertino
    Abstract:

    We develop solutions for the security and privacy of user Identity information in a federation. By federation we mean a group of organizations or service providers which have built trust among each other and enable sharing of user Identity information amongst themselves. We first propose a flexible approach to establish a single sign-on (SSO) ID in the federation. Then we show how a user can leverage this SSO ID to establish certified and un-certified user Identity attributes without the dependence on PKI for user authentication. This makes the process more usable and privacy preserving. Our major contribution in this paper is a novel solution for protection against Identity theft of these Identity attributes. We provide protocols based on cryptographic techniques, namely zero knowledge proofs and distributed hash tables. We show how we can preserve privacy of the user Identity without jeopardizing security. We formally prove correctness and provide complexity results for our protocols. The complexity results show that our approach is efficient. In the paper we also show that the protocol is robust enough even in case semi-trusted "honest-yet curious" service providers thus preventing against insider threat. In our analysis we give the desired properties of the cryptographic tools used and identify open problems. We believe that the approach represents a precursor to new and innovative cryptographic techniques which can provide solutions for the security and privacy problems in federated Identity management.