Title :
UPBA: User-Authenticated Property-Based Attestation
Author :
Manulis, Mark ; Steiner, Marion
Author_Institution :
Cryptographic Protocols Group, Tech. Univ. Darmstadt, Darmstadt, Germany
Abstract :
Remote attestation of computing platforms, using trusted hardware, guarantees the integrity, and by this the trustworthiness of a host to remote parties. While classical binary attestation attests the configuration itself, property-based attestation (PBA) attests properties and thus offers higher privacy guarantees to the host and its user. Nonetheless, both techniques are free from any user authentication mechanisms. Especially in distributed applications involving user interactions, the remote party may require assurance for the trustworthiness of the host and the authenticity of its user. Independence of user authentication from platform attestation may become an obstacle due to potential relay attacks. The User-Authenticated Property-Based Attestation (UPBA), introduced in this work, can assure a remote party that some computing platform is trustworthy, and that it is used at that very moment by some particular user. Our basic protocol is secure and practical. We prove its security formally, discuss its compatibility with current trusted computing technology, and illustrate several nice enhancements.
Keywords :
data privacy; security of data; UPBA; classical binary attestation; computing platforms; distributed applications; privacy guarantees; remote attestation; trusted hardware; user authentication mechanisms; user-authenticated property-based attestation; Authentication; Computers; Privacy; Protocols; Public key; Relays;
Conference_Titel :
Privacy, Security and Trust (PST), 2011 Ninth Annual International Conference on
Conference_Location :
Montreal, QC
Print_ISBN :
978-1-4577-0582-3
DOI :
10.1109/PST.2011.5971972