0단 자동
AI가 규칙대로 쓰고 그대로 게시했습니다. 사람이 따로 보지 않았습니다.
- 규칙 판
- 규칙 판 도입 이전 기사입니다.
- 남기는 것
- 규칙 판 · 모델 · 시각
- 판 기록
- 아직 없습니다.
Invisible Traces: Subversion Attacks on Batch-Issued Credentials
- 1.EU EUDI 지갑(2026년말 의무화)의 배치발급 ECDSA 자격증명에 대한 새로운 '전복(subversion) 공격' 제시
- 2.발급자가 프로토콜을 몰래 변형해 추적키 가진 검증자만 사용자를 비식별화하면서 사용자에게는 들키지 않는 공격 형식화
- 3.솔트 해시 기반 배치발급 자격증명이 이런 공격 앞에서 비연결성을 보장하지 못함을 입증하고 경량 대응책 제안
왜 중요한가?
2026년말 의무 도입되는 EU 디지털지갑(EUDI)의 핵심 프라이버시 요구인 비연결성이, 발급자가 감지 불가능하게 프로토콜을 변형하는 것만으로 깨질 수 있음을 보여 표준 설계 및 감사 절차에 즉각적인 재검토가 필요함을 시사한다.
언급 프로젝트
본문 미리보기
All EU member states are required to roll out a digital identity system - the European Digital Identity (EUDI) wallet - by the end of 2026. Strong privacy is at the core of the underlying regulation, which mandates the EUDI wallet to support selective disclosure and unlinkability. The wallet currently being developed relies on the batch issuance of one-time ECDSA credentials that sign attributes through individually salted hashes for selective disclosure. This solution is known to achieve only a
전체 내용이 궁금하다면?
원문을 직접 읽어보세요
이 글이 만들어진 과정
- 11:24AI 초안



