-
Notifications
You must be signed in to change notification settings - Fork 5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
New scheme for Privacy State Token: Scrappy #21
Comments
This is Abstracts of Scrappy
|
I would like to ask that is this repository a proper place to propose this? |
Is the particular proposal to add support for this as a new token type for the Private State Token API (fka Trust Token)? If so, then the https://github.com/WICG/trust-token-api is probably a better place to discuss that. If you'd like to present this variant of a token to the AFCG, then here is probably right to have that discussion. |
Thank you for your answers! I think that I would like to propose Scrappy as one of the token types for Private State Token. (Now I have found that Privacy State Token's interface is slightly different from Scrappy's required one. |
@dvorak42 |
If you can open an issue on the other repo, we can discuss more there. I think some of the attributes of Scrappy might be interesting for PST, though I haven't had time to do an in-depth read of it yet. I'll point out the issue to other folks on the team to see if they have thoughts. |
I re-read your comments and may misread |
Yes, the Private State Tokens repository. Unfortunately with IETF happening this week and preparation for it, I haven't had a chance to review the issue in more detail yet. |
@dvorak42 Regarding the review, please don't worry. Have fun at the IETF meeting! |
By the way, I could present it at the community group meeting if Scrappy is a little too complex. |
This week's meeting is a bit full, but perhaps you'd be able to present it at one of the April AFCG meetings? |
@dvorak42 |
That should work. I'll add you to the agenda for that date. (note the time
change for AFCG meetings due to Daylights Saving Time)
…On Tue, Mar 26, 2024, 8:42 AM akakou ***@***.***> wrote:
@dvorak42 <https://github.com/dvorak42>
Good! How about the meeting on April 13th?
—
Reply to this email directly, view it on GitHub
<#21 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AAEFHK5LGV3KVI6YM3I2SFTY2FULXAVCNFSM6AAAAABECVAADKVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDAMRQGMZDOOJVGE>
.
You are receiving this because you were mentioned.Message ID:
***@***.***>
|
Thank you!! |
We discussed in the meeting: https://github.com/antifraudcg/meetings/blob/main/2024/04-12.md |
Sorry, the link to the slide was incorrect, but I have now fixed it. |
This proposal is making Scrappy(SeCure Rate Assuring Protocol with PrivacY),
a new scheme with strong privacy for Privacy State Token..
Scrappy is a rate-limiter the same as Privacy Pass, but this restants to the timing correlation attack.
Also, Scrappy works as E2E (between users and web service) in the hot paths (i.e., sign and verify),
so that the issuer does not need to receive high access from users.
Slides: https://speakerdeck.com/akakou/scrappy-and-view-of-applying-to-web
Base paper: https://www.ndss-symposium.org/ndss-paper/scrappy-secure-rate-assuring-protocol-with-privacy/
Note
we can use other unique resources, the same as the Trust Token API.
Other Reference
Privacy State Token:
https://developers.google.com/privacy-sandbox/protections/private-state-tokens?hl=en
The text was updated successfully, but these errors were encountered: