Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/644527.644533acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
Article

Privacy in browser-based attribute exchange

Published:21 November 2002Publication History

ABSTRACT

Browser-based attribute-exchange protocols enable users of normal web browsers to conveniently send attributes, such as authentication or demographic data, to web sites. Such protocols might become very common and almost mandatory in general consumer scenarios over the next few years. We derive the privacy requirements on such protocols from general privacy principles and study their consequences for the protocol design. We also survey to what extent proposals like Microsoft's Passport, IBM's e-Community Single Signon, SAML, Shibboleth, the Liberty Alliance specifications and a protocol BBAE of our own conform to these design consequences, and how one could go forward.

References

  1. APP01 A P3P Preference Exchange Language 1.0 (APPEL1.0); W3C Working Draft 26 February 2001, http://www.w3.org/TR/P3P-preferences.html]]Google ScholarGoogle Scholar
  2. BLK+01 Kathy Bohrer, Xuan Liu, Dogan Kesdogan, Edith Schonberg, Moninder Singh, Susan L. Spraragen: Personal Information Management and Distribution; 4th Intern. Conf. on Electronic Commerce Research (ICECR-4), Dallas, Nov. 2001]]Google ScholarGoogle Scholar
  3. Cha81 David Chaum: Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms; Communications of the ACM 24/2 (1981) 84--88]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. Cha85 David Chaum: Security without Identification: Transaction Systems to make Big Brother Obsolete; Communications of the ACM 28/10 (1985) 1030--1044]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. CL00 Jan Camenisch, Anna Lysyanskaya: An efficient system for non-transferable anonymous credentials with optional anonymity revocation; Eurocrypt 2001, LNCS 2045, Springer-Verlag, Berlin, 93--117]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. CV02 Jan Camenisch, Els Van Herreweghen: Design and Implementation of the Idemix Anonymous Credential System; to appear at ACM CCS 2002, Washington, Nov. 2002]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. DH76 Whitfield Diffie, Martin E. Hellman: New Directions in Cryptography; IEEE Transactions on Information Theory 22/6 (1976) 644--654]]Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. FSS+01 Kevin Fu, Emil Sit, Kendra Smith, Nick Feamster: Dos and Don'ts of Client Authentication on the Web; Proc. 10th USENIX Security Symposium, 2001]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. Gat99 Gator: The Smart Online Companion; first release 1999, http://www.gator.com/]]Google ScholarGoogle Scholar
  10. GGK+99 Eran Gabber, Phillip B. Gibbons, David M. Kristol, Yossi Matias, Alain Mayer: Consistent, Yet Anonymous, Web Access with LPWA; Communications of the ACM 42/2 (1999) 42--47]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. Gol01 Y. Y. Goland: Zero Install Single Sign On Solution for a HTTP Browser; Internet Draft, Nov. 2001, http://www.ietf.cnri.reston.va.us/internet-drafts/draft-goland-sso-human-00.txt]]Google ScholarGoogle Scholar
  12. Har02 Harris Interactive: First Major Post-9/11 Privacy Survey Finds Consumers Demanding Companies Do More To Protect Privacy; Rochester, Feb. 2002, http://www.harrisinteractive.com/news/allnewsbydate.asp? NewsID=429]]Google ScholarGoogle Scholar
  13. HTT99 Hypertext Transfer Protocol -- HTTP/1.1; Internet RFC 2616, 1999]]Google ScholarGoogle Scholar
  14. IBM97 IBM Consumer Wallet; first release 1997, White Paper 1999, http://www-3.ibm.com/software/webservers/commerce/payment/wallet.pdf]]Google ScholarGoogle Scholar
  15. IBM99 IBM Multi-National Consumer Privacy Survey, conducted by Louis Harris & Associates, Inc.; IBM Global Services, October 1999]]Google ScholarGoogle Scholar
  16. IBM02 IBM: Enterprise Security Architecture using IBM Tivoli Security Solutions; April 2002, http://www.redbooks.ibm.com/abstracts/sg246014.html]]Google ScholarGoogle Scholar
  17. IM02 IBM Corporation, Microsoft: Security in a Web Services World: A Proposed Architecture and Roadmap, V 1.0; April 2002, http://www-106.ibm.com/developerworks/library/ws-secmap/]]Google ScholarGoogle Scholar
  18. KR00 David P. Kormann, Aviel D. Rubin: Risks of the Passport Single Signon Protocol; Computer Networks 33 (2001) 51--58]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  19. KSW02 Günter Karjoth, Matthias Schunter, Michael Waidner: Platform for Enterprise Privacy Practices; to appear in these proceedings.]]Google ScholarGoogle Scholar
  20. Lib02 Liberty Alliance Project (founded 2001): Specifications Version 1.0, July 2002, http://www.projectliberty.org/specs/liberty-specifications-v1.0.zip]]Google ScholarGoogle Scholar
  21. Mic01 Microsoft Corporation: .NET Passport documentation (started 1999), in particular Technical Overview, Sept. 2001, and SDK 2.1 Documentation; http://www.passport.com and http://msdn.microsoft.com/downloads]]Google ScholarGoogle Scholar
  22. Mic02 Microsoft Corporation: Microsoft Federated Security and Identity Roadmap, June 2002, http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnwebsrv/html/wsfederate.asp?frame=true]]Google ScholarGoogle Scholar
  23. P3P02 The Platform for Privacy Preferences 1.0 (P3P1.0) Specification; W3C Recommendation, April 2002, http://www.w3.org/TR/2002/REC-P3P-20020416/]]Google ScholarGoogle Scholar
  24. Pas99 Passlogix: v-Go Single Signon; first release 1999, White Paper 2000, http://www.passlogix.com/media/pdfs/usable_security.pdf]]Google ScholarGoogle Scholar
  25. PKI02 Public-Key Infrastructure (X.509) Working Group: An Internet Attribute Certificate Profile for Authorization; RFC 3281, 2002, http://www.ietf.org/rfc/rfc3281.txt]]Google ScholarGoogle Scholar
  26. PW02 Birgit Pfitzmann, Michael Waidner: BBAE -- A General Protocol for Browser-based Attribute Exchange; IBM Research Report RZ 3455 (# 93800), Sept 2002, http://www.zurich.ibm.com/security/publications/2002.html]]Google ScholarGoogle Scholar
  27. Rob99 Roboform: Free Web Form Filler and Password Manager; first release 1999, http://www.siber.com/roboform/]]Google ScholarGoogle Scholar
  28. SAM02 OASIS Security Assertion Markup Language (SAML); Committee specification 01, May 2002 (started Jan. 2001), http://www.oasis-open.org/committees/security/docs]]Google ScholarGoogle Scholar
  29. Shi02 Shibboleth-Architecture DRAFT v05; May 2002 (v1 in 2001) http://middleware.internet2.edu/shibboleth/docs/draft-internet2-shibboleth-arch-v05.pdf]]Google ScholarGoogle Scholar
  30. Sle01 Marc Slemko: Microsoft Passport to Trouble; Rev. 1.18, Nov. 5, 2001 http://alive.znep.com/~marcs/passport/]]Google ScholarGoogle Scholar
  31. Wes67 Alan F. Westin: Privacy and Freedom; Atheneum, New York NY, 1967]]Google ScholarGoogle Scholar
  32. Wil02 Joe Wilcox: Customers wary of online IDs and Survey: Passport required-not appealing, CNET News.com, April 2002, http://news.com.com/2100-1001-892808.html and http://news.com.com/2100-1001-884730.html]]Google ScholarGoogle Scholar
  33. XML02 XML-Signature Syntax and Processing; W3C Recommendation, Feb. 2002, http://www.w3.org/TR/xmldsig-core/]]Google ScholarGoogle Scholar
  34. Zer99 Zeroknowledge: Freedom Personal Firewall; first release 1999, http://www.freedom.net/products/firewall/index.html]]Google ScholarGoogle Scholar

Index Terms

  1. Privacy in browser-based attribute exchange

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader