I don't think it is in use today, but an idea for a federated login that does not reveal usage information to the authentication service is SPRESSO, described here: http://arxiv.org/pdf/1508.01719.pdf