Institution profile

University of Reggio Calabria

Academic institutioneurope · it
Official website
Research library2linked papers
Opportunities0open roles
Selected work

Representative Papers

A Privacy-Preserving Information-Sharing Protocol for Federated Authentication

Dec 01, 2025

In federated authentication systems, a privacy-security paradox arises: identity providers (IdPs) must detect cross-domain duplicate or fraudulent registrations while preventing leakage of users’ sensitive attributes or enabling cross-domain linkage. To resolve this, we propose a pseudonymous identifier mechanism based on oblivious pseudorandom functions (OPRFs) and domain-specific transformations. This mechanism enables globally consistent identity verification under full input confidentiality and, integrated with a blinded registration authority, supports a decentralized authentication framework. Experiments demonstrate efficient cross-domain uniqueness verification without exposing raw identity data, significantly mitigating identity spoofing. The scheme simultaneously achieves strong privacy guarantees—formally satisfying *k*-anonymity and unlinkability—and practical anti-fraud utility. It provides a scalable, standards-compatible, privacy-enhancing solution for multi-domain federated authentication.

0 citationsRead paper

Towards Privacy-Preserving Revocation of Verifiable Credentials with Time-Flexibility

Mar 27, 2025

To resolve the privacy-efficiency trade-off in verifiable credential revocation within self-sovereign identity (SSI), this paper proposes a privacy-preserving revocation mechanism supporting fine-grained temporal authorization. Methodologically, it pioneers the integration of anonymous hierarchical identity-based encryption (HIBE) with zero-knowledge–friendly signatures and verifiable timestamping protocols, enabling holders to autonomously restrict verifiers’ access to revocation status within configurable time windows. Contributions include: (i) issuer unlinkability—issuers cannot trace credential presentations; (ii) verifier privacy confinement—verifiers learn only whether a credential was revoked within the authorized interval, with no extraneous information disclosed; and (iii) regulatory compliance and enhanced verification efficiency. Experimental evaluation demonstrates that the scheme achieves strong privacy guarantees while reducing revocation verification overhead below that of state-of-the-art approaches.

0 citationsRead paper
Recent publications

Latest Papers

A Privacy-Preserving Information-Sharing Protocol for Federated Authentication

Dec 01, 2025

In federated authentication systems, a privacy-security paradox arises: identity providers (IdPs) must detect cross-domain duplicate or fraudulent registrations while preventing leakage of users’ sensitive attributes or enabling cross-domain linkage. To resolve this, we propose a pseudonymous identifier mechanism based on oblivious pseudorandom functions (OPRFs) and domain-specific transformations. This mechanism enables globally consistent identity verification under full input confidentiality and, integrated with a blinded registration authority, supports a decentralized authentication framework. Experiments demonstrate efficient cross-domain uniqueness verification without exposing raw identity data, significantly mitigating identity spoofing. The scheme simultaneously achieves strong privacy guarantees—formally satisfying *k*-anonymity and unlinkability—and practical anti-fraud utility. It provides a scalable, standards-compatible, privacy-enhancing solution for multi-domain federated authentication.

0 citationsRead paper

Towards Privacy-Preserving Revocation of Verifiable Credentials with Time-Flexibility

Mar 27, 2025

To resolve the privacy-efficiency trade-off in verifiable credential revocation within self-sovereign identity (SSI), this paper proposes a privacy-preserving revocation mechanism supporting fine-grained temporal authorization. Methodologically, it pioneers the integration of anonymous hierarchical identity-based encryption (HIBE) with zero-knowledge–friendly signatures and verifiable timestamping protocols, enabling holders to autonomously restrict verifiers’ access to revocation status within configurable time windows. Contributions include: (i) issuer unlinkability—issuers cannot trace credential presentations; (ii) verifier privacy confinement—verifiers learn only whether a credential was revoked within the authorized interval, with no extraneous information disclosed; and (iii) regulatory compliance and enhanced verification efficiency. Experimental evaluation demonstrates that the scheme achieves strong privacy guarantees while reducing revocation verification overhead below that of state-of-the-art approaches.

0 citationsRead paper