Minimal Information Disclosure in a Centralized Authorization System
Lavinia Egidi, Giovanni Porcelli · Electronic Notes in Theoretical Computer Science · 2003
We propose a centralized authorization system, in which user authorizations cannot be retrieved in a computationally feasible way without cooperation of user, authorization server and end-servers. A certain level of anonymity is also guaranteed to the users. The security of the protocol is based on standard cryptographic assumptions. We show that the complexity of the protocol compares to that of the SSL handshake protocol.