Title :
A Privacy-Preserving 3rd-Party Proxy for Transactions that Use Digital Credentials
Author :
Shapiro, Daniel ; Thareja, Vishal ; Adams, Christopher
Author_Institution :
Univ. of Ottawa, Ottawa
Abstract :
In this paper we propose modifications and extensions to the digital credentials issuing and showing protocols to make them appropriate for an e-commerce environment in which the user has only a hand-held constrained device (such as a PDA or a cell phone), with limited memory and processing power. In particular, this device does not hold the digital credentials or conduct the corresponding protocols; this is done by a 3rd party (a proxy) on behalf of the user, who simply needs to authorize the transaction once it is complete. Our proposal frees the user from having to carry the digital credentials and protocol engine with him/her at all times (which may be unrealistic in some environments), while retaining the desired privacy properties (e.g., the 3rd party proxy performs computations on the user´s behalf and participates in the required protocols without learning any of the user´s private information). The complete architecture that we describe also includes mechanisms to prevent the following three forms of attack: password cracking, betrayal, and collusion.
Keywords :
authorisation; certification; data privacy; digital signatures; electronic commerce; mobile computing; protocols; public key cryptography; transaction processing; 3rd party proxy; PDA; betrayal attack; cell phone; collusion attack; digital credentials; e-commerce environment; handheld constrained device; password cracking; privacy preservation; protocols; transaction authorization; user private information; Bandwidth; Cellular phones; Credit cards; Information technology; Law; Legal factors; Licenses; Personal digital assistants; Proposals; Protocols;
Conference_Titel :
Electrical and Computer Engineering, 2007. CCECE 2007. Canadian Conference on
Conference_Location :
Vancouver, BC
Print_ISBN :
1-4244-1020-7
Electronic_ISBN :
0840-7789
DOI :
10.1109/CCECE.2007.248