Understanding the Identity-Transformation Approach in OIDC-Compatible Privacy-Preserving SSO Services

arXiv:2506.01325 · cs.CR · Submitted 2025-06-02 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: Today's paper: "Understanding the Identity-Transformation Approach in OIDC-Compatible Privacy-Preserving SSO Services".

Elias: OpenID Connect (OIDC) enables users to log into multiple websites via an identity provider, but existing solutions often suffer from privacy risks like IdP-based login tracing and RP-based identity linkage.

Nadia: First, who's behind it and why it matters.

Paper summary: Nadia: So, to recap our discussion on "Understanding the Identity-Transformation Approach in OIDC-Compatible Privacy-Preserving SSO Services," we’ve established that UppreSSO proposes using identity transformations tied to Oblivious Pseudo-Random Functions to stop tracing at both the IdP and RP levels. The paper lays out how this system integrates these concepts into a practical SSO flow, aiming to solve those linkage issues head-on.

Elias: Exactly. The core of the work centers on assigning accounts using specific elliptic curve functions, like "PI DRP = F P IDRP (IDRP, t) = tIDRP = trG" and deriving the final account with "AccT = F A c c (PIDU, t) =

t−one: PIDU" to keep the secret random number "t" private between the user and the relying party.

Priya: From what I'm seeing in this paper, it seems they are focusing on defining a concrete system framework for how these identity transformations fit into existing OIDC protocols, rather than just theoretical math. It looks like they are building a functional model of how this works in practice with real users and services.

Nadia: Right, it’s about showing how these abstract cryptographic concepts can map onto the actual flow of an SSO interaction involving RPs, users, and an IdP to achieve those stated privacy goals. It establishes the framework for what UppreSSO is doing in a real-world context.

Elias: The paper sets up this system by assigning unique identifiers "IDU" to a user and "IDRP" to an RP from the honest-but-curious IdP, which then lets every RP synchronize all accounts at it from that honest source, setting up the whole transformation process.

Priya: It seems they are very careful about their assumptions regarding authenticated and confidential links between those entities; I wonder what happens if those links aren't perfectly secure in a real deployment scenario.

Nadia: Well, the paper assumes those links are established and that the software stack of an honest entity is implemented correctly to deliver messages as expected, which is standard for proving security in this context. The focus remains on how the transformations themselves manage the privacy leakage given those foundational assumptions.

Elias: This leads us into how they connect these transformations directly to Oblivious Pseudo-Random Functions, where "ID U = k" and "ID RP = x," which results in an account assignment of "AccT = PR (k, x) = z." It's a direct mathematical link they establish.

Priya: So, the implication here is that we can move toward SSO services where users have more direct control over what identifying information actually gets exposed during the authentication process when using this approach detailed in "Understanding the Identity-Transformation Approach in OIDC-Compatible Privacy-Preserving SSO Services".

Nadia: Right, it suggests a direction for designing these systems where the privacy protection isn't just an afterthought but is built into the fundamental identity flow from the start, which is a significant design consideration. The paper establishes a solid foundation for future work by investigating those extended OPRF properties we discussed earlier.

Elias: And that investigation directly opens up avenues to explore how to make these systems even more resilient against different adversarial models, which is what they are setting up for in their study of the generalized UppreSSO system.

Priya: So, ultimately, this paper provides a detailed blueprint for how identity transformations can be implemented in OIDC environments to achieve this dual protection against tracing and linkage issues by leveraging OPRFs effectively. It gives us a clear technical path forward for building more private authentication flows.

Conclusion: Nadia: So, to wrap up this part of our talk on "Understanding the Identity-Transformation Approach in OIDC-Compatible Privacy-Preserving SSO Services," we've seen that the central idea revolves around using identity transformations connected to OPRFs to stop tracing at both the IdP and RP levels.

Elias: Precisely, their work shows how carefully managing those temporary identities and using the structure of OPRFs lets them achieve user identification at the correct RP while making sure other RPs don't derive any meaningful account information from a token.

Priya: It seems like this has big implications for privacy-preserving identity management because it suggests we can move toward SSO services where users have more direct control over what identifying details get exposed during authentication.

Nadia: Right, it points toward designing systems where privacy protection is built right into the fundamental flow of identity from the very beginning, which is a significant design consideration for any modern app.

Elias: And that opens up avenues for us to explore how to make these systems even tougher against different types of attackers through their study of the generalized UppreSSO system.

Priya: So, ultimately, this paper provides a technical blueprint for implementing these identity transformations in OIDC environments to get that dual protection against tracing and linkage issues.

Nadia: Indeed, the authors are essentially showing us how abstract cryptographic ideas can be mapped onto a practical SSO flow involving real users and services.

Elias: And they establish a solid foundation for future work by looking at those extended OPRF properties we discussed earlier, which is where the next layer of security usually goes.

Priya: So, this really gives us a clear technical path forward for building authentication flows that are inherently more private than what we see today.

School of Cyber Security, University of Science and Technology of China · School of Cryptology, University of Chinese Academy of Sciences

cs.CR

Submitted: 2025-06-02

Updated: 2026-10-06

Code: https://github.com/WICG/trusttoken-api

License: http://creativecommons.org/publicdomain/zero/1.0/

Importance score: 80/100

The gist: OpenID Connect (OIDC) enables users to log into multiple websites via an identity provider, but existing solutions often suffer from privacy risks like IdP-based login tracing and RP-based identity

Key concepts

Identity Transformations in UppreSSO
This is a method of changing identifiers on elliptic curves. It involves creating temporary, secret pseudo-identities for both the user and the website being visited. This process ensures that the actual identity used to sign a login token is hidden from external observers, protecting users from tracking.
Oblivious Pseudo-Random Functions (OPRFs)
OPRFs are mathematical tools that allow a party to select one of two inputs without revealing which one they chose. In this paper, the system uses OPRFs to automatically assign a unique account identifier to a user at each website, making the assignment process unlinkable and private.
RP Designation
This property ensures that only the intended Relying Party (RP) can derive meaningful account information. The system guarantees that other websites cannot successfully link or derive an account belonging to the user unless they possess specific, secret parameters related to the transformation process.

Terminology

Summary

OpenID Connect (OIDC) enables users to log into multiple websites via an identity provider, but existing solutions often suffer from privacy risks like IdP-based login tracing and RP-based identity linkage. This paper investigates the identity-transformation approach in UppreSSO to provide OIDC-compatible SSO services that prevent both of these threats, while also uncovering the relationship between these transformations and oblivious pseudo-random functions (OPRFs) to construct new privacy-preserving systems.

Identity Transformations in UppreSSO

The UppreSSO system implements identity transformations on elliptic curves to achieve privacy-preserving SSO. The core mechanism involves generating ephemeral pseudo-identities for the visited RP and the user, which are then signed in an identity token by the IdP. Specifically, accounts are assigned using functions like:

  1. A public account identifier: PI DRP = F P IDRP (IDRP, t) = [t]IDRP = [tr]G.

  2. A user pseudo-identity: PIDU = F P IDU (IDU, PIDRP) = [u t r]G.

  3. The final account derivation: AccT = F A c c (PIDU, t) = [t−1]PIDU = [t−1 u t r]G = [u r]G = FAcct∗ (IDU, IDRP).

This design allows the system to prevent IdP-based login tracing and RP-based identity linkage. A key aspect is that the secret random number "t is kept secret to the honest IdP and known only to the user and the visited RP, ensuring that the calculation of PIDRP by the user (but not the RP) before an identity token is requested, results in the correctly designated RP of the token."

Relationship with Oblivious Pseudo-Random Functions (OPRFs)

The paper uncovers a fundamental relationship between identity transformations in SSO and OPRFs. The four functions of UppreSSO—FAcct∗ , F P IDRP , F P IDU , and FAcct —mathematically utilize the same functions as the HashDH OPRF protocol, which is based on a pseudo-random function PR (k, x). The generalized UppreSSO system is built by adopting an OPRF protocol where ID U = k and ID RP = x, such that AccT = F A c c∗ (I D U, I D R P) = PR (k, x) = z is automatically assigned to a user at each RP.

Security Properties of Generalized UppreSSO Systems

The analysis extends the proofs of security and privacy in UppreSSO by examining variations in required properties. The paper defines two primary security properties:

  1. User Identification: Based on TK the designated honest RP derives only the meaningful account belonging to the user requesting TK. This property is ensured when an RP accepts any signed tokens to derive meaningful accounts.

  2. RP Designation: At any honest RPs other than the designated one, no meaningful account is derived based on TK. This can be achieved either by checking only tokens binding matching PIDRP or by ensuring that adversaries cannot find parameters satisfying certain equations related to the underlying OPRF.

Extended Properties of OPRFs

The research proposes and analyzes three extended properties for OPRFs:

  1. Key-identifier freeness: Ensuring that All messages (i.e., z′ and μ in particular) and the public parameters (e.g., q and N) cannot be exploited to distinguish an OPRF key from others. This property is necessary for RP unlinkability when PIDRP is checked or not by an RP.

  2. RP designation w/o PIDRP checking: This property ensures that adversaries cannot find tˇ and TK binding PIDRP = F P IDRP (IDRP, t, μ̂) and PIDÛ = F P IDU (IDÛ, PIDRP, μ) satisfying that FAcct (PIDÛ, IDRP, t, μˇ) = FAcct∗ (ID Uˇ, IDRP), where I D Uˆ ≠ I D Uˇ.

  3. User Identification w/o PIDRP checking: This property ensures that adversaries "cannot find tˇ and some protocol instance (x, x̂′, ẑ′, t, μ̂) generated with unknown ˆk which satisfy that UBL (ẑ′, x,t, μˇ) = PR (ˇk, x), where ˆk ≠ ˇk and ˆk, ˇk ∈ k.

Improvements for AI systems

Based on a rigorous analysis of the provided scientific paper, here are specific improvements to AI systems that could be achieved by implementing its proposed identity-transformation approach:


The core contribution of this paper is establishing a mathematically rigorous link between Identity Transformations in OIDC and Oblivious Pseudo-Random Functions (OPRFs). This relationship allows for the construction of novel privacy-preserving SSO services.

Here are the specific improvements and capabilities:

[] improve AI systems by implementing the generalized UppreSSO system based on an arbitrary OPRF scheme (e.g., DYHE or 2HashRSA with careful key selection).

[] enable AI systems to provide Account Uniqueness and User Identification guarantees even when Relying Parties (RPs) are malicious and colluding, without requiring the RP to check the derived pseudo-identity in every single token.

[] allow AI systems to maintain RP Unlinkability, meaning that even if malicious RPs collude with other users, they cannot link a login from one honest user visiting one RP to a login from another honest user visiting a different RP.

The resulting improved AI system (Generalized UppreSSO) can perform the following specific functions:

[] Log into multiple services (RPs) using a single set of credentials without revealing the user's identity or allowing RPs to track which service they visited (eliminating IdP-based login tracing).

[] Ensure that an AI user cannot be impersonated by another AI user at a specific RP, even if the adversary manipulates timing variables or tokens, because the system relies on the properties of the underlying OPRF rather than simple token binding checks.

[] Prevent malicious RPs from linking separate login sessions across different services to build a comprehensive profile of an AI user's activity (eliminating RP-based identity linkage).

In summary, this research enables the creation of highly secure, privacy-preserving Single Sign-On (SSO) services compatible with OIDC that resist both tracing by the Identity Provider and linking by colluding Relying Parties.

Abstract

Single sign-on (SSO) enables a user to log into multiple websites, called relying parties (RPs), by her username and credential set up in another trusted web system, called the identity provider (IdP). Identity transformations are proposed in UppreSSO to provide privacy-preserving SSO services, preventing both IdP-based login tracing and RP-based identity linkage. While the security and privacy guarantees of UppreSSO have been proved, several essential issues on the identity-transformation approach are not well studied. In this paper, we comprehensively investigate this approach as below. Firstly, several suggestions to efficiently integrate identity transformations into OpenID Connect (OIDC) are explained. Then, we uncover the relationship between identity transformations in SSO and oblivious pseudo-random functions (OPRFs), and present two variations of the properties required for SSO security as well as other requirements, to analyze existing OPRF protocols. Finally, new identity transformations different from those proposed in UppreSSO, are constructed based on some OPRFs. To the best of our knowledge, this is the first time to uncover the relationship between identity transformations in SSO services and OPRFs, and prove the SSO-related properties (i.e., output uniqueness, key-identifier freeness, and collision resistance on 1st/2nd-input) of typical OPRFs.

Sources

Related papers