Electronic identities (eIDs) are crucial in an increasingly digitalized environment. Pseudonyms, as offered by Austria's governmental sector-specific personal identifiers (bPks), can significantly improve privacy by ensuring that personal data is not universally traceable across public services and private companies. However, the current architecture comes with several challenges regarding availability, privacy, and authenticity, due to a fully centralized design. This paper proposes bPk#, a distributed architecture to address these issues, reducing reliance on the central authority, while still providing all functional requirements to the existing bPk system. In particular, users are delegated the rights to compute their own pseudonyms, thereby minimizing metadata revealed to the central authority, while (subsets of) service providers may receive the right to compute pseudonyms only within their own domain, thereby reducing the availability needs of the central authority. To the best of our knowledge, we provide the first formal framework for such delegatable pseudonym systems, together with a generic construction for which we provide formal security proofs. Furthermore, we propose a concrete instantiation of our construction, together with a reference implementation demonstrating the practical efficiency.
翻译:电子身份(eID)在日益数字化的环境中至关重要。奥地利政府提供的部门特定个人标识符(bPk)所支持的化名,通过确保个人数据在公共服务和私营企业间不可通用追溯,显著提升了隐私保护。然而,由于完全中心化的设计,现有架构在可用性、隐私性和真实性方面面临诸多挑战。本文提出bpK#这一分布式架构以解决上述问题,在降低对中央权威机构依赖的同时,仍能提供现有bPk系统的全部功能需求。具体而言,用户被授予计算自身化名的权利,从而最小化向中央权威机构暴露的元数据;同时(部分)服务提供商可仅在其自身域内获得化名计算权限,进而降低中央权威机构的可用性需求。据我们所知,我们首次为此类可委托化名系统提供了形式化框架,并给出通用构造方案及其形式化安全证明。此外,我们提出了该构造方案的具体实例化,并通过参考实现验证了其实用效率。