VIETNAM NATIONAL UNIVERSITY HO CHI MINH CITY HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY NGUYEN ANH KHOI ATTRIBUTE-BASED PSEUDONYMITY FOR PRIVACY- PRESERVING AUTHENTICATION IN CLOUD SERVICES Major: COMPUTER SCIENCE Major code: 8480101 MASTER’S THESIS HO CHI MINH CITY, January 2024 THIS THESIS IS COMPLETED AT: HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY – VIETNAM NATIONAL UNIVERSITY HO CHI MINH CITY Scientific Instructor : Dr. Truong Tuan Anh Reviewer 1 : Dr. Phan Trong Nhan Reviewer 2 : Assoc. Nguyen Tuan Dang Master thesis defended at Ho Chi Minh City University Of Technology – Vietnam National University Ho Chi Minh City Date 30 Month 1 Year 2014.
Master thesis evaluation council consist of (Full name and title) 1. Le Hong Trang 2. Nguyen Thi Ai Thao 3. Phan Trong Nhan 4.
Nguyen Tuan Dang 5. Nguyen Van Vu Master thesis evaluation council and Head of Faculty’s confirmation after Master thesis’ correction (if any): CHAIRMAN OF COUNCIL DEAD OF FACULTY OF COMPUTER SCIENCE AND ENGINEERING i VIETNAM NATIONAL UNIVERSITY THE SOCIALIST REPUBLIC OF VIETNAM HO CHI MINH CITY Independence -Freedom - Happiness HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY MASTER THESIS MISSION Student name: NGUYEN ANH KHOI Student ID: 2070607 Date of Birth: November 19th 1998 Place of birth: Ho Chi Minh city Major: Computer Science Major Code: 106 TOPIC: Attribute-Based Pseudonymity For Privacy-Preserving Authentication In Cloud Services/ Bút danh dựa trên thuộc tính cho bảo mật quyền riêng tư xác thực trong các dịch vụ đám mây MISSION AND DETAIL: Propose and evaluate an attribute-based privacy- preserving authentication scheme for cloud services. Develop proposed signature scheme that allows service providers to authenticate users based on their attributes while preserving user privacy and ensuring compliance with pseudonyms and access control policies. DATE OF ASSIGNMENT: Septemper 4th 2023 DATE OF COMPLETION: December 18th 2023 INSTRUCTOR: Dr.
Truong Tuan Anh Ho Chi Minh city, April 2nd 2024 INSTRUCTOR CHAIRMAN OF FACULTY (Name and Signature) (Name and Signature) DEAD OF FACULTY OF COMPUTER SCIENCE AND ENGINEERING (Name and Signature) ii ACKNOWLEDGEMENTS I would like to express my deepest gratitude to all those who have supported and guided me throughout the completion of this thesis. Firstly, I am immensely thankful to Dr. Truong Tuan Anh for his invaluable guidance, expertise, and encouragement throughout this research journey. His insightful feedback and constructive criticism have played a crucial role in shaping this thesis.
I would also like to extend my gratitude to the faculty members of the International Master Program for their dedication to education and for providing a conducive learning environment. Their lectures, discussions, and academic resources have broadened my knowledge and enriched my understanding of the subject matter. Lastly, I would like to acknowledge the support and encouragement from my friends and family. Their unwavering belief in my abilities and their unconditional support have been a constant source of motivation throughout this endeavor.
iii ABSTRACT Attribute-based Authentication plays a crucial role in efficiently managing cloud-based services within the rapidly expanding market environment, providing scalable fine-grained access control settings. However, the adoption of such authentication mechanisms often compromises privacy preservation. The direct linkage between a user's attributes and their identity, spread across multiple service- providing organizations, raises concerns. To address these concerns, various solutions have been proposed, including Privacy Attribute-based credentials (Privacy-ABCs).
Privacy-ABCs offer pseudonym-based authentication, enabling users to establish anonymity through pseudonyms embedded with attributes. Nevertheless, Privacy-ABCs necessitate selective disclosure of attribute values to service providers, limiting their applicability. Alternatively, solutions like Mesh signatures and Attribute-based signatures (ABS) do not require selective disclosure but lack the capability to create pseudonyms for concealing real identities. This paper presents a novel pseudonym-based signature scheme that combines key features from Privacy Attribute-based credentials.
The scheme facilitates the self- generation of unlinkable pseudonyms, ensuring anonymity for users while integrating a secret sharing mechanism akin to Attribute-based signatures and Mesh signatures. This integration enables efficient attribute verification. Moreover, the proposed scheme offers verifiable delegation, allowing users to share specific attributes in accordance with a service provider's policy. By merging the strengths of different approaches, this scheme provides a comprehensive solution that addresses the limitations of existing methods.
The proposed pseudonym-based signature scheme contributes to enhancing privacy preservation in attribute-based authentication for cloud services. It offers users the ability to establish anonymous identities, safeguarding their sensitive information behind pseudonyms. Furthermore, the scheme ensures attribute verification through secret sharing techniques, enhancing security and trust in the authentication process. The verifiable delegation feature provides flexibility for attribute sharing, aligning with service providers' policies and facilitating efficient access control.
Overall, this proposed scheme presents a comprehensive approach iv towards privacy-preserving attribute-based authentication in the context of cloud services. v TÓM TẮT Xác thực dựa theo thuộc tính đóng góp một vai trò quan trọng trong việc quản lý hiệu quả các dịch vụ thuộc hệ thống đám mây thuộc nền thị trường đang được mở rộng nhanh chóng, cung cấp cho những thiết lập kiểm soát truy cập có thể mở rộng. Tuy nhiên, sự áp dụng các cơ chế thường gây xâm nhập đến sự bảo đảm an toàn cá nhân. Mối liên kết trực tiếp giữa các thuộc tính và danh tính của người dùng bị lan truyền đến các tổ chức cung cấp dịch vụ gây nên mối lo ngại này.
Để đối ứng các mối lo này, nhiều phương pháp xử lý khác nhau đã được đề xuất đến, trong đó bao gồm hệ thống chứng thực dựa theo thuộc tính cá nhân (Privacy Attribute Based Credential - Privacy-ABCs). Privacy-ABCs cung cấp hệ thống xác thực dựa theo bí danh, cho phép người dùng thiết lập tính ẩn danh qua các bí danh được nhúng từ các thuộc tính. Tuy nhiên, Privacy-ABCs đòi hỏi sự tiết lộ các giá trị thuộc tính cho các nhà cung cấp dịch vụ, hạn chế khả năng ứng dụng của chúng. Ngoài ra, các giải pháp như Chữ ký lưới (Mesh signature) và Chữ ký dựa trên thuộc tính (Attribute Based Signature - ABS) không yêu cầu tiết lộ có chọn lọc nhưng thiếu khả năng tạo bí danh để che giấu danh tính thực.
Bài viết này trình bày một hệ thống chữ ký dựa trên bút danh mới kết hợp các tính năng chính từ thông tin xác thực dựa trên Privacy-ABCs. Hệ thống này tạo điều kiện cho việc tự tạo các bút danh không thể liên kết, đảm bảo tính ẩn danh cho người dùng đồng thời tích hợp cơ chế chia sẻ bí mật giống ABS và Mesh signature. Sự tích hợp này cho phép xác minh thuộc tính một cách hiệu quả. Hơn nữa, hệ thống này cung cấp khả năng ủy quyền có thể kiểm chứng, cho phép người dùng chia sẻ các thuộc tính cụ thể theo chính sách của nhà cung cấp dịch vụ.
Bằng cách kết hợp những điểm mạnh của các phương pháp khác nhau, sơ đồ này cung cấp một giải pháp toàn diện nhằm giải quyết những hạn chế của các phương pháp hiện có. vi PLEDGE: I solemnly pledge and affirm that this thesis represents my own original work. All sources used in this research have been duly acknowledged and referenced. Furthermore, I affirm that the findings and conclusions presented in this thesis are based on a comprehensive analysis of the data and adhere to the highest standards of academic integrity.
I understand the importance of academic honesty and the consequences of plagiarism. Therefore, I have taken great care to ensure that all information, data, and ideas from external sources are properly cited and attributed. I have also adhered to the ethical guidelines and regulations set forth by the Faculty. I am committed to upholding the principles of intellectual honesty, integrity, and professionalism throughout my academic and professional journey.
I pledge to continue fostering a culture of responsible research and to strive for excellence in all future endeavors. Nguyen Anh Khoi April 2nd, 2024 vii TABLE OF CONTENTS 1. Authentication in Cloud services. Role-based access control for authentication in Cloud services.
Privacy problem in Authentication. The notion of identity confidentiality (Pfitzmann and Hansen, 2008). Privacy-Attribute based credentials (Privacy-ABCs). Attribute-based signature (ABS) and Mesh signature.
Attribute-based pseudonymity for privacy-preserving authentication in cloud services. Component and Interactions in Attribute-Based Pseudonymity For Privacy- Preserving Authentication. Certification Authorities’ trustworthiness. Secure channel reliability.
Comparison with other works. RECOMMENDATIONS FOR FUTURE RESEARCH. 47 ix TABLE OF FIGURES Figure 1.1 Three types of Cloud Services.2 Four different environments of cloud services.3 Overview of how RBAC works.4 Fine-grained Access Control described inside a smart healthcare system.5 Illustration of ABAC concept, and how the admin is able to know every information of the user.1 Illustration of the definition of anonymity.2 An example of how Privacy-ABCs work, illustrated between two person figures.3 Illustration of how ABS works.1 Illustration of a Pseudonym system.2 Application of Pseudonym System in requesting access.3 Mathematical graph of the Elliptic Curve algorithm.4 Illustration of the general flow between three sides.5 The graph from Fig.4 summarized the processes into function names.6 Illustration of the KeyGen flow.7 Illustration of the CreGen flow.8 Illustration of the PseuGen flow.9 Illustration of the Sign flow (1/3).10 Illustration of the Sign flow (2/3).11 Illustration of the Sign flow (3/3).12 Illustration of the SignCheck flow.13 Illustration of the Revoke flow.1 Result of 20 attempts tested on the system.1 Summary of the flow that provides input value for SignCheck. INTRODUCTION Cloud services[1][2] have been steadily implemented as a vital part of everyone’s life, for the purpose of giving service to users the best and most convenient way, enhancing their experience.
In other words, it is a wide range of services that provides end-users and organizations access to resources and applications without any additional requirement other than the internet and any device that can connect to the internet (e.g personal computers, smart phones, tablets, and any other IoT devices).1 Three types of Cloud Services. Source: Realvasi Digital Marketplace (2021) Generally, there are three basic types of cloud services (Fig.1): Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS)[3]. SaaS consists of a variety of different services of storage and backups and web servers, as well as project management tools. It provides a complete product that is run and managed by a service provider.
SaaS can be utilized to create a service using existing software solutions without the need to build and maintain one, which in return, people rather view SaaS like an end-user application. SaaS is widely used in web-based mail services, office suites, platforms for communications such as team - Page 2 of 47 - messaging and video conferences, and more, with solutions which are available within SaaS. Google Workspace is a popular service that falls into this category, containing a collection of Saas productivity tools, including popular applications like Gmail as a mailing service, Google Docs for document processing, Google Sheet for spreadsheets, and Google Slides for presentation purposes. Dropbox and Zoom are also services which operate on SaaS, one being a cloud-based hosting service, giving user storage space on the cloud, the latter being a video conference and collaboration platform for host and joining video meetings.
IaaS is a solution for cloud providers who want to manage SaaS tools without having to maintain it themselves, mainly scalability and cost-effective features. It provides basic building blocks for cloud IT and access to networking features, computers and data storage spaces. It offers scalable and reliable data storage for dynamic management, high performance computing power to effectively analyze large volumes of data and complex calculations, and reliable networking capabilities (e.g virtual networks, load balancers, firewalls, and VPN - virtual private networks). IaaS plays a significant role in handling big data and analytics workloads, with the necessary computing power and storage capability it provides, enabling businesses to make data-driven decisions.
It maintains all storage servers and networking hardware, eliminating the need for resource-intensive, on-site installations.