On the usefulness of proof-of-possession

Presentation outline

Motivation

Definitions

Attack 1 on Enrollment (1/2)
Replacing public key in enrollment request sent by victim

Attack 1 on Enrollment (2/2)
Does PoP help?

Attack 2 (1/2)
Using victim’s public key in own enrollment request

Attack 2 (2/2)
Does PoP help?

Does PoP do any harm?

Conclusion