A Threshold-Based Authentication System Which Provides Attributes Using Secret Sharing

Tomohiro Ito, Daisuke Kotani, Yasuo Okabe · 2017

In identity federation, each service provider verifies the identity of a user based on authentication performed by an authentication server called an Identity Provider (IdP). When the IdP suffers from a trouble such that an unauthorized person has cracked into the IdP or the IdP is unreachable due to a network problem, all services in the federation may be stopped by the single trouble. Simple replication of servers for the IdP might cause privacy concern because plain attribute values of registered users are copied to multiple servers, including servers that may not necessarily be trusted. In order to maintain the function as an IdP even under such troubles, we propose a system in which servers of the IdP are distributed and cooperate using threshold-based authentication and secret sharing. Even when some of IdPs are not available, the proposed system can provide authentication and authorization to all services in the federation by performing authentication procedure with the rest IdPs. Since attribute values are distributed to IdPs using secret sharing, an attacker cannot know the attribute values even if he successfully usurps administrator-level privilege of an IdP. We also design and implement the proposed system. We measure the execution time and verify that the computation time is sufficiently small. Furthermore, we show that our system is robust with respect to both fault tolerance and security.

Read the paper · More papers on PaperTik