A Privacy-Preserving Information-Sharing Protocol for Federated Authentication
In federated authentication systems, a privacy-security paradox arises: identity providers (IdPs) must detect cross-domain duplicate or fraudulent registrations while preventing leakage of users’ sensitive attributes or enabling cross-domain linkage. To resolve this, we propose a pseudonymous identifier mechanism based on oblivious pseudorandom functions (OPRFs) and domain-specific transformations. This mechanism enables globally consistent identity verification under full input confidentiality and, integrated with a blinded registration authority, supports a decentralized authentication framework. Experiments demonstrate efficient cross-domain uniqueness verification without exposing raw identity data, significantly mitigating identity spoofing. The scheme simultaneously achieves strong privacy guarantees—formally satisfying *k*-anonymity and unlinkability—and practical anti-fraud utility. It provides a scalable, standards-compatible, privacy-enhancing solution for multi-domain federated authentication.