Understanding the Identity-Transformation Approach in OIDC-Compatible Privacy-Preserving SSO Services

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lin, Jingqiang, Zhang, Baitao, Wang, Wei, Cai, Quanwei, Jing, Jiwu, He, Huiyang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915367721369600
author Lin, Jingqiang
Zhang, Baitao
Wang, Wei
Cai, Quanwei
Jing, Jiwu
He, Huiyang
author_facet Lin, Jingqiang
Zhang, Baitao
Wang, Wei
Cai, Quanwei
Jing, Jiwu
He, Huiyang
contents OpenID Connect (OIDC) enables a user with commercial-off-the-shelf browsers to log into multiple websites, called relying parties (RPs), by her username and credential set up in another trusted web system, called the identity provider (IdP). Identity transformations are proposed in UppreSSO to provide OIDC-compatible SSO services, preventing both IdP-based login tracing and RP-based identity linkage. While security and privacy of SSO services in UppreSSO have been proved, several essential issues of this identity-transformation approach are not well studied. In this paper, we comprehensively investigate the approach as below. Firstly, several suggestions for the efficient integration of identity transformations in OIDC-compatible SSO are explained. Then, we uncover the relationship between identity-transformations in SSO and oblivious pseudo-random functions (OPRFs), and present two variations of the properties required for SSO security as well as the privacy requirements, to analyze existing OPRF protocols. Finally, new identity transformations different from those designed in UppreSSO, are constructed based on OPRFs, satisfying different variations of SSO security requirements. To the best of our knowledge, this is the first time to uncover the relationship between identity transformations in OIDC-compatible privacy-preserving SSO services and OPRFs, and prove the SSO-related properties (i.e., key-identifier freeness, RP designation and user identification) of OPRF protocols, in addition to the basic properties of correctness, obliviousness and pseudo-randomness.
format Preprint
id arxiv_https___arxiv_org_abs_2506_01325
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Understanding the Identity-Transformation Approach in OIDC-Compatible Privacy-Preserving SSO Services
Lin, Jingqiang
Zhang, Baitao
Wang, Wei
Cai, Quanwei
Jing, Jiwu
He, Huiyang
Cryptography and Security
OpenID Connect (OIDC) enables a user with commercial-off-the-shelf browsers to log into multiple websites, called relying parties (RPs), by her username and credential set up in another trusted web system, called the identity provider (IdP). Identity transformations are proposed in UppreSSO to provide OIDC-compatible SSO services, preventing both IdP-based login tracing and RP-based identity linkage. While security and privacy of SSO services in UppreSSO have been proved, several essential issues of this identity-transformation approach are not well studied. In this paper, we comprehensively investigate the approach as below. Firstly, several suggestions for the efficient integration of identity transformations in OIDC-compatible SSO are explained. Then, we uncover the relationship between identity-transformations in SSO and oblivious pseudo-random functions (OPRFs), and present two variations of the properties required for SSO security as well as the privacy requirements, to analyze existing OPRF protocols. Finally, new identity transformations different from those designed in UppreSSO, are constructed based on OPRFs, satisfying different variations of SSO security requirements. To the best of our knowledge, this is the first time to uncover the relationship between identity transformations in OIDC-compatible privacy-preserving SSO services and OPRFs, and prove the SSO-related properties (i.e., key-identifier freeness, RP designation and user identification) of OPRF protocols, in addition to the basic properties of correctness, obliviousness and pseudo-randomness.
title Understanding the Identity-Transformation Approach in OIDC-Compatible Privacy-Preserving SSO Services
topic Cryptography and Security
url https://arxiv.org/abs/2506.01325