Are you old enough to buy this?

If you suspend your transcription on amara.org, please add a timestamp below to indicate how far you progressed! This will help others to resume your work!

Please do not press “publish” on amara.org to save your progress, use “save draft” instead. Only press “publish” when you're done with quality control.

Video duration
Not yet available
Language
English
Abstract
Today, age verification in e-commerce implies identity verification, one way or the other. In this talk, we first look at existing solutions for age restriction and their shortcomings. We then present a design for a privacy-friendly method that binds age restriction to the ability to pay (rather than identification) and that is aligned with the [principle of subsidiarity](https://en.wikipedia.org/wiki/Subsidiarity). We show how this scheme is integrated with the [GNU Taler](https://taler.net) payment system, making it the first fully privacy-friendly payment system with age restriction.

Privacy in e-commerce is currently a sad story, especially with respect to age-restriction and -verification. Existing commercial solutions are mostly implemented by identity verification. Even privacy-friendly approaches, using attribute-based credentials, anchor on an external, higher authority which verifies the identity of the consumer before issuing a certificate.

The [principle of subsidiarity](https://en.wikipedia.org/wiki/Subsidiarity) suggests that the appropriate level of authority to set age restriction is the level of parents and caretakers - not merchants, banks or governmental institutions. Our design for an age verification scheme fully aligns with this principle.

The design is presented as an extension of [GNU Taler](https://taler.net), a privacy-friendly payment protocol. The extension augments the protocol with a zero-knowledge scheme for age verification that cryptographically augments coins for this purpose. Our scheme enables buyers to prove to be of sufficient age for a particular transaction without disclosing the age. The modification preserves the privacy and security properties of GNU Taler, in particular the anonymity of buyers and unlinkability of transactions.

We show how our scheme can be instantiated with various cryptographic signature schemes, how it is integrated with the GNU Taler payment system and what work is left to do.

This work is funded by the project [_Concrete Contracts_](https://concretecontracts.codeblau.de) by the [German Federal Ministry of Education and Research](https://www.forschung-it-sicherheit-kommunikationssysteme.de/projekte/concrete-contracts).

Talk ID
jev22-49228
Event:
jev22
Day
4
Room
HIP1
Start
2:30 p.m.
Duration
01:00:00
Track
E.T.I.
Type of
Talk
Speaker
oec
Talk Slug & media link
jev22-49228-are_you_old_enough_to_buy_this

The video is not yet available