key: 2007-attacking-anonymity-in-Direct-Anonymous-Attestation type: inproceedings title: "Direct Anonymous Attestation (DAA): Ensuring privacy with corrupt administrators" authors: - Ben Smyth - Mark D. Ryan - Liqun Chen year: 2007 month: 7 booktitle: "ESAS'07: 4th European Workshop on Security and Privacy in Ad hoc and Sensor Networks" series: LNCS volume: "4572" pages: 218--231 publisher: Springer doi: 10.1007/978-3-540-73275-4_16 description: >- This paper presents a vulnerability in the Direct Anonymous Attestation protocol which claims to protect user's privacy in the context of trusted computing. keywords: >- Direct Anonymous Attestation, DAA, trusted computing, Trusted Platform Module, TPM, user-controlled anonymity, anonymity, privacy, ProVerif, applied pi calculus abstract: >- The Direct Anonymous Attestation (DAA) scheme provides a means for remotely authenticating a trusted platform whilst preserving the user's privacy. The protocol has been adopted by the Trusted Computing Group (TCG) in the latest version of its Trusted Platform Module (TPM) specification. In this paper we show DAA places an unnecessarily large burden on the TPM host. We demonstrate how corrupt administrators can exploit this weakness to violate privacy. The paper provides a fix for the vulnerability. Further privacy issues concerning linkability are identified and a framework for their resolution is developed. In addition an optimisation to reduce the number of messages exchanged is proposed. supersededby: - key: 2012-Direct-Anonymous-Attestation-privacy-definition text: journal version links: - file: Smyth07-attacking-DAA.LNCS.pdf text: Conference paper - file: Smyth07-attacking-DAA.pdf text: Extended version - url: https://doi.org/10.1007/978-3-540-73275-4_16 text: Official version