• No results found

ZKAPS: HOW TO USE PRIVACY PASS FOR PAYMENT-BASED ACCESS TO YOUR APPLICATION

N/A
N/A
Protected

Academic year: 2021

Share "ZKAPS: HOW TO USE PRIVACY PASS FOR PAYMENT-BASED ACCESS TO YOUR APPLICATION"

Copied!
36
0
0

Loading.... (view fulltext now)

Full text

(1)

ZKAPS: HOW TO USE PRIVACY PASS

FOR PAYMENT-BASED ACCESS TO

YOUR APPLICATION

zkSummit 5 - 03/31/20

Anna Kaplan

Least Authority/

Technical University of

Munich

(2)

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

AGENDA

1. The initial use case

2. Details about PrivateStorage

3. Privacy Pass - the original implementation

4. Our use: Zero Knowledge Access Passes (ZKAPs) 5. Possibilities for extensions

(3)

LEAST AUTHORITY BUILT A PRIVATE CLOUD STORAGE SOLUTION

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

In 2013: a solution called S4 (Simple Secure Storage Service), based on

(4)

LEAST AUTHORITY BUILT A PRIVATE CLOUD STORAGE SOLUTION

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

What’s it about?

Client-side encryption

Sharding of ciphertext

Potential for decentralised storage servers (grid)

Not ACL: No user accounts, no passwords, but OCAP: Access based on

(5)

OUR PROBLEM: FIAT CURRENCY PAYMENT PROCESSING

Name

Email address

▸ Location (for VAT)

Transaction Data

…and sharing with these other companies

= collecting personal data just for payments

(6)

HOW TO SEPARATE SERVICE ACCOUNTING AND PROVIDER?

(7)

FROM S4 (SIMPLE SECURE STORAGE SERVICE) TO PRIVATE STORAGE

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

Least Authority and Private Internet Access (privacy focused VPN

provider) announce PrivateStorage

PrivacyStorage is private, secure and end-to-end encrypted cloud

storage solution, based on Least Authority’s Tahoe-LAFS and developed from S4

Private Storage therefore implements Zero Knowledge Access Passes

(8)

PRIVACY PASS

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

https://privacypass.github.io/ Work by Alex Davidson, Ian Goldberg, Nick Sullivan, George Tankersley, and Filippo Valsorda, 2018

(9)

PRIVACY PASS - MOTIVATION

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

Developed by

Cloudflare needs to prevent malicious attacks, e.g. comment

spam or SQL attacks, from the web

Cloudflare does this through IP reputation assessment

How to know that’s a “good" IP address? I have a great solution

(10)

Screenshot by me, 10/29/2019

(11)
(12)

PRIVACY PASS - BACKGROUND

Idea based on Ecash (Chaum 1983):

▸ You take a token, blind it, get a blind signature

▸ Issuance and Redemption are unlinkable

After Real World Crypto 2016: How to apply the idea of blinded signatures to not

always having to solve CAPTCHAs?

▸ Filippo Valsorda and George Tankersley came up with first specification for a

blinded token to be issued when a CAPTCHA is solved, and can be redeemed later

▸ Take a token, blind it, send it to Cloudflare with CAPTCHA solution, get a blind

signature in response, which you can later redeem

▸ These are unlinkable for Cloudflare

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

(13)

PRIVACY PASS - BACKGROUND

Problem: Ecash was based on RSA. 1980s cryptography is slow!

At PETS 2016, Davidson, Tankersley, and Valsorda asked for help and Dan Boneh

mentioned EC-OPRFs.

OPRF: Oblivious Pseudo-Random Function

Batched Elliptic Curve VOPRF with redemption (Tankersley)

▸ Multiple simultaneous OPRFs based on Elliptic Curve multiplication ▸ VRF-like public verification

▸ Batched validation for more efficiency

VOPRFs 🆚 Ecash: Ecash is publicly verifiable 🆚 VOPRFs only verifiable in the

redemption phase by the issuer

(14)

IDEA: “MODERNIZED ECASH” WITH NO CASH INVOLVED

🧚

Blind Token, solved CAPTCHA Blind Signature

Token Make digital

signature Mint private key 🔑

ISSUANCE

🧚

Token, Signature 📦 Validate Mint public key

REDEMPTION

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

🎟

🎟

🗺

🎟

🎟

Unblind

👩🎤

(15)

WHERE DO ZERO-KNOWLEDGE PROOFS COME INTO PLAY?

EC-VOPRFs use a Discrete Log Equivalence Proof

Short ZKP that two pairs of points have the same Discrete Log,

denounced DLEQ(P:R == Q:S).

(16)

CURRENT STATE AND OTHER IDEAS TO THINK ABOUT

Privacy Pass exists as an extension for Firefox or Chrome

Other ideas to use this idea:

Anonymous session resumption for TLS

Anonymous referral code mechanism (e.g. discount codes) - used

in Brave browser for ads

Single bit ZKP (e.g. Am I over 18?) ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

(17)

OUR USE: ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

(18)

OUR USE: ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

👩🎤

(19)

OUR USE: ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

👩🎤

(20)

OUR USE: ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

👩🎤

(21)

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

👩🎤

🧻🧻

🧻🧻

🧻

OUR USE: ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

🧚

(22)

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

👩🎤

🧻🧻

🧻🧻

🧻

OUR USE: ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

🧚

(23)

Unblind

🧚

Blind Token, solved CAPTCHA Blind Signature

Token Make digital

signature Mint private key 🔑

ISSUANCE

🧚

Token, Signature 📦 Validate Mint public key

REDEMPTION

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

🎟

🎟

🗺

🎟

🎟

👩🎤

👩🎤

(24)

🧚

Blind Token, solved CAPTCHA Blind Signature

Token Make digital

signature Mint private

key 🔑

ISSUANCE

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

🎟

🎟

🗺

🎟

🎟

Unblind

👩🎤

(25)

🧚

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

H: Hash function

ISSUANCE

👩🎤

(26)

🧚

bT1, bT2, bT3, …; solved CAPTCHA

t1, t2, t3, …

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

🎟

🎟

🎟

Ti=H(ti) b: blinding factor H: Hash function

🎟

🗺

ISSUANCE

👩🎤

(27)

🧚

bT1, bT2, bT3, …; solved CAPTCHA

Z1 = sbT1, Z2 = sbT2, Z2 = sbT3, …

t1, t2, t3, …

Check CAPTCHA

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

🎟

🎟

🎟

Ti=H(ti) b: blinding factor H: Hash function

🎟

🎟

🗺

🗺

▸ Calculate DLEQ

ISSUANCE

DLEQ

👩🎤

(28)

🧚

bT1, bT2, bT3, …; solved CAPTCHA

Z1 = sbT1, Z2 = sbT2, Z2 = sbT3, …

t1, t2, t3, …

Check CAPTCHA

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

🎟

🎟

🎟

Ti=H(ti) b: blinding factor H: Hash function

🎟

🎟

🗺

🗺

▸ Calculate DLEQ

ISSUANCE

DLEQ

👩🎤

Unblind: (1/b)Zi = sTi = Ni Store (ti, Ni) ▸ Check DLEQ

🎟

(29)

🧚

bT1, bT2, bT3, …; solved CAPTCHA Z1 = sbT1, Z2 = sbT2, Z2 = sbT3, … t1, t2, t3, … ▸ Check CAPTCHA

🧚

Token, Signature 📦

REDEMPTION

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

🎟

🎟

🎟

Ti=H(ti) b: blinding factor Unblind: (1/b)Zi = sTi = Ni Store (ti, Ni) H: Hash function

🎟

🎟

🗺

🗺

▸ Calculate DLEQ ▸ Check DLEQ

🎟

✍ DLEQ

ISSUANCE

Validate Mint public key

👩🎤

👩🎤

(30)

🧚

bT1, bT2, bT3, …; solved CAPTCHA Z1 = sbT1, Z2 = sbT2, Z2 = sbT3, … t1, t2, t3, … ▸ Check CAPTCHA

🧚

REDEMPTION

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

🎟

🎟

🎟

Ti=H(ti) b: blinding factor H: Hash function

🎟

🎟

🗺

🗺

▸ Calculate DLEQ

ISSUANCE

DLEQ shk = H(tu, Nu) R: request data

👩🎤

👩🎤

Unblind: (1/b)Zi = sTi = Ni Store (ti, Ni) ▸ Check DLEQ

🎟

✍ (tu, HMAC(shk, R))

(31)

🧚

bT1, bT2, bT3, …; solved CAPTCHA Z1 = sbT1, Z2 = sbT2, Z2 = sbT3, … t1, t2, t3, … ▸ Check CAPTCHA

🧚

(tu, HMAC(shk, R))

REDEMPTION

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

🎟

🎟

🎟

Ti=H(ti) b: blinding factor H: Hash function

🎟

🎟

🗺

🗺

▸ Calculate DLEQ

ISSUANCE

DLEQ R: request data ▸ Recalculate ▸ Check tu for double-spend on list ▸ Calculate Tu, sTu, shk; check HMAC; store tu 📦 shk = H(tu, Nu) R: request data

👩🎤

👩🎤

Unblind: (1/b)Zi = sTi = Ni Store (ti, Ni) ▸ Check DLEQ

🎟

*** this is not the full specification ***

(32)

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

OUR USE: ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

(33)

ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

OUR USE: ZERO KNOWLEDGE ACCESS PASSES (ZKAPS)

https://github.com/PrivateStorageio/ZKAPAuthorizer/blob/master/src/ _zkapauthorizer/controller.py#L479

(34)

USE UNLINKABLE ACCESS PASSES FOR YOUR USE CASE!

(35)

LINKS AND REFERENCES

https://privacypass.github.io/

https://privacypass.github.io/protocol/

https://github.com/brave-intl/challenge-bypass-ristretto

https://github.com/LeastAuthority/python-challenge-bypass-ristretto

https://github.com/PrivateStorageio/ZKAPAuthorizer

https://leastauthority.com/blog/the-path-from-s4-to-privatestorage/

(36)

EVERY PROGRAM AND

EVERY PRIVILEGED

USER OF THE SYSTEM

SHOULD OPERATE USING

THE LEAST AMOUNT OF

PRIVILEGE NECESSARY

TO COMPLETE THE JOB.

Jerome Saltzer

https://leastauthority.com [email protected] Twitter: @Kaplannie @LeastAuthority

References

Related documents

Pada penelitian ini penulis mensimulasikan menggunakan mobil simulasi (remote control) dihubungkan dengan sensor ultrasonik HY-SRF05 yang digunakan untuk mendeteksi dan

For investments including Planning or Acquisitions spending, complete the following table on milestones used to measure cost and schedule performance, representing only one level

In this report, we describe the results of a study of 90 diabetic children with regard to three competencies: (1) ability to recall the personal diet plan in exchanges, (2) ability

a) To develop profile of contractual claim in term of head of claim, causes of claim, type of project, parties involved, standard form of contract, time of

To solve this trouble, fine aggregates was substituted up to 40% copper slag and determining its compressive and splitting tensile strength of concrete and also the performance

Economic offences committed criminals shares 3% of the total criminal. It has been observed that the main reason for the commission of offences in Coimbatore city by the criminals

Such a report shall include, but not be limited to: a status report on implementation of the program including the number of individuals enrolled profiled by age and

ABSTRACT: An electrochemically-driven enantioselective nickel-catalyzed reductive cross- coupling of alkenyl bromides and benzyl chlorides is reported.. The reaction forms