• DocumentCode
    612042
  • Title

    Anon-Pass: Practical Anonymous Subscriptions

  • Author

    Lee, M.Z. ; Dunn, A.M. ; Waters, B. ; Witchel, E. ; Katz, Justin

  • fYear
    2013
  • fDate
    19-22 May 2013
  • Firstpage
    319
  • Lastpage
    333
  • Abstract
    We present the design, security proof, and implementation of an anonymous subscription service. Users register for the service by providing some form of identity, which might or might not be linked to a real-world identity such as a credit card, a web login, or a public key. A user logs on to the system by presenting a credential derived from information received at registration. Each credential allows only a single login in any authentication window, or epoch. Logins are anonymous in the sense that the service cannot distinguish which user is logging in any better than random guessing. This implies unlinkability of a user across different logins. We find that a central tension in an anonymous subscription service is the service provider\´s desire for a long epoch (to reduce server-side computation) versus users\´ desire for a short epoch (so they can repeatedly "re-anonymize" their sessions). We balance this tension by having short epochs, but adding an efficient operation for clients who do not need unlinkability to cheaply re-authenticate themselves for the next time period. We measure performance of a research prototype of our protocol that allows an independent service to offer anonymous access to existing services. We implement a music service, an Android-based subway-pass application, and a web proxy, and show that adding anonymity adds minimal client latency and only requires 33 KB of server memory per active user.
  • Keywords
    mobile computing; music; operating systems (computers); security of data; Android-based subway-pass application; Anon-Pass application; Web proxy; anonymous subscription service; authentication window; client latency; music service; user login; Couplings; Protocols; Public key; Servers; Streaming media; Subscriptions; Anonymous Subscriptions;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy (SP), 2013 IEEE Symposium on
  • Conference_Location
    Berkeley, CA
  • ISSN
    1081-6011
  • Print_ISBN
    978-1-4673-6166-8
  • Electronic_ISBN
    1081-6011
  • Type

    conf

  • DOI
    10.1109/SP.2013.29
  • Filename
    6547118