METHOD AND DEVICE FOR CONTROLLING ANONYMOUS ACCESS TO A COLLABORATIVE ANONYMIZATION PLATFORM

DE602020069249T2Active Publication Date: 2026-03-25COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2020-12-09
Publication Date
2026-03-25

AI Technical Summary

Technical Problem

Existing collaborative anonymization platforms lack effective access control mechanisms that compromise user anonymity during connection and usage, especially when interacting with multiple service providers, exposing vulnerabilities through mutual knowledge between operators.

Method used

A method and device implementing a role-distributed authorization mechanism using random private key generation and verification across multiple operators to ensure anonymous access to a collaborative anonymization platform without revealing user identities.

Benefits of technology

Guarantees total anonymity during connection and usage by preventing operators from identifying users through network analysis, eliminating vulnerabilities present in existing roaming mechanisms.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention lies in the field of communication protocols, and more particularly relates to a method and device for controlling anonymous access to a collaborative anonymization platform.

[0002] Data security and controlled access to various collaborative systems are major challenges that organizations must address to limit the risks of intrusion and attacks. Existing collaborative anonymization platforms offer little to no access control, and therefore no security as such.

[0003] Today, the communication solutions offering the best levels of "privacy" (an anglicism for anonymity) are free and collaborative solutions based on peer-to-peer (P2P) protocols such as the Tor protocols ( « The Onion Router » ) or I2P ( Invisible Internet Project » These solutions do not require any particular authentication and access mechanism, partly because they are free, but also and especially because, by nature, an authentication and access mechanism is a priori incompatible with a high level of anonymization.

[0004] An improved solution described in the Applicant's patent application FR3072238 presents a collaborative anonymization platform with a level of privacy and security potentially far superior to existing solutions, but also performance in terms of quality of service compatible with modern and professional Internet uses, while allowing some control over exchanges to limit criminal uses of the platform.

[0005] All of these solutions describe the nominal operation of the overall system. However, to avoid diminishing the effectiveness of the anonymization platform in its normal operating mode, it is also necessary to guarantee that anonymity is not compromised during the transition phase. Typically, this means ensuring that access to a desired service occurs without any compromise to the user's level of privacy and security.

[0006] Furthermore, beyond simply accessing the platform, services (restricted or even commercial) wishing to benefit from real anonymization properties (i.e. from the network layer to the application layer) can be considered above the platform, such as an image processing service for health based on an artificial intelligence engine hosted in a remote computing center, or secure communication services such as "Telegram Messenger" or "Signal", or even applications for exchanging information on bank fraud.

[0007] There is therefore a need for a solution that allows access to a collaborative anonymization platform to be controlled without compromising the anonymity of the person requesting access.

[0008] An applicant for access to a collaborative anonymization platform may rely on several access providers for that platform, which are generally several communication operators and at least one anonymization service provider. Among the communication operators, one is presumed to have granted access rights to the collaborative anonymization platform, for example, through the subscription of an option within an internet access service contract. Since establishing access to the collaborative anonymization platform requires interaction between the applicant and the platform's access providers, it is essential that these interactions, while guaranteeing the applicant's anonymity, can only take place to the extent that the applicant can prove they were indeed granted access rights to the collaborative platform.

[0009] Solutions based on roaming mechanisms, used in the mobile telephony sector, allow a third-party operator to authenticate a customer of the originating operator without knowing the long-term secret shared between the customer and their originating operator for the encryption of communications. These mechanisms, in which the originating operator provides the third-party operator with information to exchange with its customer in order to then authorize communication, allow a user of a service who has been granted rights (in the example of telephony, rights for a communication service) to benefit from equivalent rights with another service provider, without being identified in the same way as they were identified by their originating operator.

[0010] These mechanisms are unsatisfactory from the perspective of the problem at hand, primarily because they require direct communication in roaming mode and mutual knowledge between the customer's two operators: the original network operator with whom the user subscribed and the third-party network operator to which they are requesting a connection. This mutual knowledge between the two operators represents an unacceptable potential vulnerability.

[0011] An approach to masking the author of a transaction, known as "Ring Signatures," is described in the article "How to Leak a Secret" by Ron Rivest, Adi Shamir, and Yael Tauman, ASIACRYPT 2001, Volume 2248 of Lecture Notes in Computer Science, pages 552-565. Ring Signatures are implemented, in particular, within the CryptoNote cryptocurrency and allow the author of a transaction to be hidden among a set of potential users. While a person skilled in the art could derive an application of this principle to the context of the invention, where an operator granting access rights to a platform to a user could conceal that user's identity through the use of a ring signature constructed based on their identity and that of several other potential users, this solution would not be generalizable because the number of potential users would remain relatively limited.

[0012] Furthermore, the operator who granted the access rights could be identified as the operator of the various candidate clients mentioned in the signature, which would represent a potentially unacceptable flaw.

[0013] There is therefore a need for a solution that can be applied to a large number of customers of one or more service providers who wish to connect to an anonymization platform. Such a solution must protect the identity of any operator who has granted access rights.

[0014] Another mechanism similar to roaming is the "Push" exchange mechanism described in RFC 2904, which allows a client to access a service by proving to the service provider the existence of a past interaction with an authorization server. While a person skilled in the art could generalize this system with an authorization server that would not deliver the proof of interaction directly to the user but would store it in a database potentially consulted by the service provider later, such a system would not offer support for transaction anonymity.

[0015] Therefore, there is a need for a solution that allows for total anonymity both during the transitional phase of connecting to a collaborative platform and during the nominal mode of using the platform.

[0016] The present invention makes it possible to overcome the drawbacks of known approaches and to meet the aforementioned needs.

[0017] Thus, one object of the invention is to provide an anonymous access solution to an anonymization platform.

[0018] The general principle of the invention is based on an authorization mechanism which aims to authorize access to a collaborative anonymization platform, in a totally anonymous, secure and untrusted third-party manner, and / or authorize access to a service requiring anonymity properties based on such a platform.

[0019] Advantageously, the access mechanism to an anonymization platform is based on a principle of role distribution between users and operators in order to do away with a trusted third party, the trusted third party being the limitation of known privacy solutions.

[0020] The invention is particularly advantageous for complementing the nominal phase operation of the collaborative anonymization platform developed by the Applicant and described in the aforementioned patent application, by providing a solution for the "transitional" phase which makes it possible to guarantee total anonymity during the connection phase to the platform while offering a mechanism for controlling access to the platform.

[0021] The invention is advantageously applicable to any anonymous paid and / or restricted service, marketed and / or offered by one or more operators of a collaborative anonymization platform. These services can be of very diverse natures such as: financial databases to guarantee the anonymity of users (and for example not to reveal the sectors or companies studied for future investments), artificial intelligence services for "e-health" (where the processing which is done remotely on computing centers which know the data (typically: images (X-rays, scans...), practitioners (general practitioners, surgeons), or even individuals directly, jeopardizes medical confidentiality).

[0022] To achieve the desired results, a computer-implemented method for controlling anonymous access to a collaborative anonymization platform operated by different operators is proposed in an independent claim, for a user having access rights to the collaborative anonymization platform through a first operator or access provider. The method comprises the following steps: to issue a request for access to a service on the collaborative anonymization platform, for a user with access rights to said platform granted by a first operator OP1; to receive a list of pairs (PEi; Keyi) where each pair contains an identifier of an entry point PEi to said platform by one operator among the plurality of operators, and contains a random public key Keyi generated for this entry point; to randomly generate a random private value Vx; to select 'n' pairs (PEn, Keyn) where a first pair (PE1, Key1) has an identifier of an entry point PE1 to said platform by the first operator OP1, and where each other pair ((PE2, Key2), ..., (PEi, Keyi), ..., (PEn, Keyn)) has an identifier of an entry point to said platform by another operator; to communicate: to the first operator via the selected entry point PE1, a first private key Fx(Vx, Key2, ..., Clén), constructed, according to a predefined associative and commutative 'Fx' encryption operation, from the private random value Vx and all the public keys associated with the 'n-1' other selected entry points except the public key Clé1 of the entry point PE1 of the first pair (PE1, Clé1); and for each operator of each other selected pair, a private key Fx(Vx, Clé1, ... , Cléi, ..., Clén) constructed, according to the 'Fx' encryption operation, from the private random value Vx and all the public keys associated with the 'n-1' other entry points except the public key of said entry point of each other pair; to register via the collaborative anonymization platform in a private key database, a user private key constructed from the first private key Fx(Vx, Clé2, ..., Clén) and the public key Clé1 associated with the first entry point; implement on the collaborative anonymization platform, a private key verification algorithm, the algorithm operating iteratively between the first operator and each of the other operators selected to verify in the private key database, the validity of the user's private key; and validate or deny the user access to the collaborative anonymization platform via each operator's entry point, depending on the result of the verification.

[0023] According to alternative or combined embodiments: The private key communication step includes the steps of: calculating a first number called the "first user private number" (Vx x Key2 x ... x Keyn) from the private random value Vx and the public keys associated with the 'n-1' entry points selected for the other operators; and calculating for each other operator a second number called the "second user private number" (Vx x Key1 x ... x Keyi x ... x Keyn) from the private random value Vx and all the public keys associated with the 'n-1' other entry points except the public key of said entry point.The implementation step on the collaborative anonymization platform of a verification and validation algorithm for private keys between two operators includes the following steps: (306) for the first operator: generating, from the first received user private number and the public key associated with the first operator's entry point, a number called the "first user-operator private number" ((Vx x Key2 x ... x Keyi x ... x Keyn) x Key1); and registering, via the collaborative anonymization platform, the first user-operator private number ((Vx x Key2 x... x Keyi x ... x Keyn) x Key1) in a private key database (206); (308) for each of the other operators: generating, from the second received user private number and the public key associated with the entry point of said other operator, a number called the "second user-operator private number" ((Vx x Key1 x ...x Key1) x Key2); and verify via the collaborative anonymization platform whether the second user-operator private number ((Vx x Key1 x ... x Key1) x Key2) is registered in said private key database (206). The step of registering a user-operator private number in the private key database also includes registering a lifetime parameter for said number. The process further includes, after the registration step, a step of counting down the lifetime parameter. The pair selection step is performed automatically according to predefined selection criteria. The Fx encryption operation is a modular power-up type operation. The Fx encryption operation is a so-called "one-way accumulator" operation.

[0024] The invention covers a computer program product comprising non-transient code instructions for performing the steps of the claimed process when the program is executed on a computer.

[0025] The invention further covers an anonymous access control device for a collaborative anonymization platform operated by different operators, for a user having access rights to the collaborative anonymization platform by a first operator or access provider, the device includes means to implement the steps of the process according to any one of the claims.

[0026] Other features, details and advantages of the invention will become apparent from the description provided with reference to the accompanying drawings given by way of example, which represent, respectively: [ Fig.1 ] is a topological representation of an infrastructure enabling the implementation of the invention; [ Fig.2 ] illustrates a representation of an example of an implementation of the invention according to the topology of the figure 1 ; Fig.3 ] illustrates the procedures executed between the entities of the figure 2 in an embodiment of the invention; and [ Fig.4 ] illustrates the steps carried out by the method of the invention in an embodiment.

[0027] There figure 1 illustrates a general environment 100 in which the invention is advantageously implemented, for example, as illustrated by the figure 2 The environment includes a collaborative anonymization platform 102 (also referred to as an "anonymous" service) which is operated collaboratively by at least three independent operators, of which at least two independent operators (104, 108) are used to access the platform.

[0028] To operate without a trusted third party, the platform requires at least three independent operators. In the context of the described invention, connecting to the anonymization service to connect to the anonymization platform anonymously requires connecting to at least two independent operators (OP1, OP2).

[0029] The anonymous service can be a network service or an application service, for which a user / customer has a right of access granted by one of the operators of the collaborative anonymization platform. In one embodiment, the operator is the customer's Internet Service Provider (ISP).

[0030] The client device for accessing the anonymous service includes at least two physical interfaces (202-1, 202-2) each connected to a network operator (104, 108), including the client's ISP.

[0031] For reasons of simplicity of description and not to limit the invention, although the examples of figures 1 et 2 Since the models only show a finite number of operators (10⁴, 10⁸), a person skilled in the art can extend the described principles to a plurality of operators while introducing modifications and / or implementation variants resulting from the generalization. Thus, the client device can have one or more than two physical interfaces to establish one or more than two connections with a plurality of operators.

[0032] In a logical-level embodiment of the invention, where the connection to two platform operators is made via a single physical network interface, the anonymous service relies on a network-level anonymization service that possesses the two aforementioned characteristics (connection to two independent operators and granted access rights). In this case, the client can connect logically (rather than physically) to two operators of the anonymization platform.

[0033] Returning to the figure 1 The network operators each present PEi entry points on the platform 102. Each PEi is operated by one of the operators of the collaborative anonymization platform. Thus, for example, the first operator OP1 104, which for the remainder of the description is referred to as the incumbent operator or internet service provider ISP of customer 202 (or the provider of the anonymous application service), manages entry points to the platform (106-1 to 106-i), and the second operator OP2 108 manages entry points to the platform (110-1 to 110-j).

[0034] There figure 2 further illustrates a database or public key registry 204 (Public_key_reg.) which the client device accesses during the implementation of the connection process, and a private key database (AC) 206 coupled to operators 104, 108 and used as a temporary database during the anonymous connection process.

[0035] Each operator entry point (EIP) to the collaborative anonymization platform randomly generates a public key (Key), which may or may not be updatable, and which is stored in the public database 204. The database thus contains a set of "entry point, public key" pairs {(EIP; Key)}. This database is accessible directly via the internet service provider or via the collaborative anonymization platform for the application-level implementation of the invention.

[0036] In an embodiment where the keys are updated, additional attributes well known to the person of the art can be added to the "entry point, public key" pairs, such as a Time-To-Live (TTL) indicating the time during which the keys are kept.

[0037] THE figures 3 And 4describe an implementation of the invention's process according to an embodiment, where the figure 3 shows the existing flows between the different entities of the figure 2 and where the figure 4 illustrates the steps of the method of the invention involving two operators.

[0038] It should be noted that the same references are used on the different figures for identical elements.

[0039] The general principle of anonymous connection of a client 202 to a collaborative anonymization platform 102, consists, at the client level, in that it: 300: retrieves all the entry point, public key pairs {(PEi; Keyi)} contained in the public register 204; 302: randomly generates a private random value Vx; 304: sends to each selected operator ISP and OP2, via one of its entry points, a number called "user private number" (Vx x Key2) and (Vx x Key1), calculated from the private random value Vx and the public key associated with the entry point of the other operator; and 310: receives from the second operator OP2 an authorization to access the platform 102 (or a rejection).

[0040] Furthermore, the process includes phases carried out at the level of each independent operator, which consist of the following: 306: The first operator (ISP) registers, via the collaborative anonymization platform, in the private key database 206, a number called "user-operator private number" ((Vx x Key2) x Key1), generated from the user private number calculated for this operator and the public key associated with the entry point of this operator; and 308: The second operator OP2 checks, via the collaborative anonymization platform, whether a "user-operator private number" ((Vx x Key1) x Key2), generated from the user private number calculated for this operator and the public key associated with the entry point of this operator, is stored in the private key database 206, in order to return or not an access authorization to the user.

[0041] There figure 4This illustrates the steps of the 400 anonymous connection method of the invention. The method begins when a user / client who has access rights to a collaborative anonymization platform via their incumbent operator (generally their ISP, Internet Service Provider) wishes to access a service operated on the collaborative anonymization platform by an OP2 operator or another operator. The user sends a 402 access request to their operator. The method then allows the client to receive a list of {(PEi; Cléi)} pairs, where each pair contains an identifier of an entry point to the platform via an operator and a public key associated with the entry point.

[0042] In a subsequent step 406, the process randomly generates a private value Vx, and allows the user to select 408 a first entry point PE1 operated by their ISP, and a second entry point PE2 operated by the second operator. In an alternative embodiment, the order of steps 406 and 408 can be reversed. The selection of the entry point for each operator can be, according to different embodiments, either discretionary or automated based on predefined criteria.

[0043] In a subsequent step 410, the process generates, for each selected entry point, a 'user private number' defining a private key. Each user private number is generated from the private random value Vx and the public key associated with the other selected entry point for the other operator. Thus, for the first entry point PE1 of the incumbent operator, a first user private number (Vx x Key2) is generated defining a user private key for the first operator, and for the second entry point PE2 of the second operator, a second user private number (Vx x Key1) is generated defining a second user private key for the second operator.

[0044] In an advantageous embodiment, the encryption operation designated by "Fx" for generating user private numbers is a predefined encryption operation such that its inverse operation (i.e., recovering 'a' and 'b' from 'a Fx b') is extremely difficult to achieve. This operation must also be both associative and commutative.

[0045] In a preferred embodiment, the operation "Fx" is a known function of raising to a modular power.

[0046] In one embodiment, the applied 'Fx' operation is known to the person skilled in the art by the anglicism "accumulators", and can be based on "Merkle trees", and "non-Merkle accumulators" which can for example be of the type "RSA accumulators" or "Elliptic Curve accumulators".

[0047] An example of an 'Fx' operation based on "accumulators" is described in the article by J. Benaloh and M. de Mare, "One-way accumulators: A decentralized alternative to digital signatures", Advances in Cryptology-Eurocrypt'93, LNCS, vol. 765, Springer-Verlag, 1993, pp. 274-285.

[0048] In a subsequent step 412, the process allows each operator (the ISP and the second operator) to be communicated with their corresponding private user number. Thus, in the illustrated example, the process allows the first operator 104 to receive the private user number (Vx x Key2) generated from the public key Key2 associated with the other entry point selected for the other operator, and sends the second operator 106 the private user number (Vx x Key1) generated from the public key Key1 associated with the entry point selected for the ISP.

[0049] The next step 414 consists of verifying and validating the private keys on the collaborative anonymization platform. Specifically, the process allows the first ISP operator to add 306 to the private database (AC), accessible only through the collaborative anonymization platform, a 'private user-operator' number ((Vx x Key2) x Key1) defining a private user-first operator key, and generated by the encryption operation Fx from the private user number received from the user - (Vx x Key2) - and the key - (Key1) - associated with the entry point chosen for the first operator.

[0050] In one embodiment, the registration of the 'private user-operator' number in the private database (AC) is associated with the registration of a predefined lifetime parameter. This advantageously allows for automatic cleanup of the private database (AC) following, for example, unsuccessful login attempts, thus preventing continuous and unnecessary growth of the database content.

[0051] Step 414 further consists of the second operator OP2 querying 308, via the collaborative anonymization platform, the private database (AC) to check if a user-operator private number - ((Vx x Key1) x Key2) - defining a user-second operator private key, and generated by the encryption operation Fx from the user private number received from the user - (Vx x Key1) - and the key (Key2) associated with the entry point chosen for the second operator, is recorded there.

[0052] If the verification result is positive, the process allows, in a subsequent step (416), for the user to be granted access to the collaborative anonymization platform. Indeed, if, during the verification step, the second operator receives confirmation of the existence of the private key in the private database (AC), this information indicates that a past transaction has already taken place between this same user and an operator (i.e., the historical operator), and the second operator can therefore authorize the user to access the collaborative anonymization platform via its network.

[0053] Thus, advantageously, the process of the invention makes it possible to guarantee that: Neither the initial operator that granted access rights to the platform to the client / user, nor the anonymization service, nor the second operator (or more generally, any other operators) that the client uses to access the anonymization platform, are able to "break" the anonymization; that is to say, none of them are able, through network analysis of connection requests to the service, to associate with the service user any data allowing their identification; the operator that granted access rights to the client / user will not be able to know the other operator(s) used by the client to access the anonymization platform; the second or all other operators will not be able to know the initial operator that granted access rights to the client / user, which is a major difference with the "roaming" mechanisms used, for example, in mobile telephony;The network platform or anonymization logic will not be able to know which operators are used by the client: nothing else can be deduced other than the information that a new legitimate connection to the platform has taken place.

[0054] The example has been described on the basis of two operators, but the process is applicable and generalizable for a plurality of operators, allowing, depending on the properties of the collaborative anonymization platform, the degree of anonymity of the user to be strengthened.

[0055] Thus, a person skilled in the art can derive the generalization according to the following scenario, similar to that described for two operators: After selecting 'n' pairs (Entry Point (EPn); Key (Clén)) of different operators from a set of pairs existing in a public database, the entry points providing access to a collaborative anonymization platform by a plurality of operators, and where each operator can have the same or a different number of entry points, a user sends (i.e., the method allows sending from the client device) to a first entry point PE1 selected for a first operator (i.e., generally the incumbent operator of the ISP client), a first user-private number - ((Vx x Key2 x ... x Clén)) - constructed from a random value Vx and the keys associated with the 'n-1' entry points selected for the other operators; the first operator records in the private database of the device of the invention coupled to the platform, a record of a user-operator private number - ((Vx x Key2 x ... x Clén)x Key ) x Key1) - constructed from the first user private number - ((Vx x Key2 x ...x Key) - and the key - Key1 - associated with the first entry point PE1; the user sends to an entry point PE2 of a second operator, a second user private number - (Vx x Key1 x Key3 x ... x Key) - constructed from the random value Vx and the keys associated with the 'n-1' entry points selected for the other operators; the second operator OP2 queries the private database to see if a record exists for a user-operator private number - ((Vx x Key1 x Key3 x ... x Key) x Key2) - constructed from the second user private number - (Vx x Key1 x Key3 x ... x Key) - and the key - Key2 - associated with the second operator's entry point PE2; the user obtains an access validation or a refusal of access to the collaborative anonymization platform via the second operator.then iteratively: the user sends for each other selected entry point up to the nth - PEn - a corresponding user private number - (Vx x Key1 x ... x Key-1) - and each respective operator queries the private database to check for the existence of a corresponding user-operator private number - ((Vx x Key1 x ... x Key-1) x Key) - and grant or deny access to the platform via the corresponding operator.

[0056] In another embodiment of the invention, the first operator can record the user-operator private number in the private database with a time-to-live (TTL) parameter for the number 'n'. A counter counts down the TTL parameter with each successful query of the database by another operator, so that when all 'n' entry points have been checked, the TTL is zero. The private access database can then delete the record.

[0057] The described invention can be implemented using hardware and / or software. It can be available as a computer program product executed by a processor that includes code instructions to execute the steps of the process in the various embodiments.

Claims

1. Method allowing an anonymous access to a collaborative anonymization platform operated by a plurality of operators, each operator having an identical or different number of points of entry PEi to said platform, the method being implemented by computer and comprising the steps of: - sending out (402) a request for access to a service of the collaborative anonymization platform, for a user (202) having access rights to said platform granted by a first operator OP1; - receiving (404) a list of data pairs (PEi; Keyi) where each data pair contains an identifier of a point of entry PEi to said platform by an operator from amongst the plurality of operators, and contains a random public key Keyi generated for this point of entry; - generating (406), in a random manner, a private random value Vx; - selecting (408) 'n' data pairs (PEn, Keyn), from the list of data pairs (PEi; Keyi) where a first data pair (PE1, Key1) has an identifier of point of entry PE1 to said platform by the first operator OP1, and where each other data pair ((PE2, Key2), ..., (PEi, Keyi), ..., (PEn, Keyn)) has an identifier of point of entry to said platform by another operator; - communicating (412): - to the first operator via the selected point of entry PE1, a first private key Fx(Vx, Key2, ..., Keyn), constructed, according to a predefined associative and commutative encryption operation 'Fx', from the private random value Vx and from all the public keys associated with the 'n-1' other selected points of entry except for the public key Key1 of the point of entry PE1 of the first data pair (PE1, Key1); and - to each operator of each other selected data pair, a private key Fx(Vx, Key1, ..., Keyi, ..., Keyn) constructed, according to the encryption operation 'Fx', from the private random value Vx and from all the public keys associated with the 'n-1' other points of entry except for the public key of said point of entry of each other data pair; - recording, via the collaborative anonymization platform in a database of private keys (206), a user private key constructed from the first private key Fx(Vx, Key2, ..., Keyn) and from the public key Key1 associated with the first point of entry; - implementing (414), on the collaborative anonymization platform, an algorithm for verifying private keys, the algorithm operating in an iterative manner between the first operator and each of the other selected operators in order to verify, in the database of private keys, the validity of the user private key; and - validating (416) or refusing access for the user to the collaborative anonymization platform via the point of entry of each operator, depending on the result of the verification.

2. Method according to claim 1, wherein the step of communicating the private keys comprises the steps (410) of: - calculating a first number called "first private user number" (Vx x Key2 x ... x Keyn) from the private random value Vx and from the public keys associated with the 'n-1' points of entry selected for the other operators, where the first private key is based on the first private user number; and - calculating, for each other operator, a second number called "second private user number" (Vx x Key1 x ... x Keyi x ... x Keyn) from the private random value Vx and from all the public keys associated with the 'n-1' other points of entry except for the public key of said point of entry, where the private key is based on the second private user number.

3. Method according to claim 1 or 2, wherein the step of implementing (414), on the collaborative anonymization platform, an algorithm for verifying and for validating private keys between the first operator and each of the other operators, comprises the steps of: - (306) for the first operator: - generating, from the first private user number received and from the public key associated with the point of entry of the first operator, a number called "first private user-operator number" ((Vx x Key2 x ... x Keyi x ... x Keyn) x Key1); and - recording, via the collaborative anonymization platform, the private user key where the private user key is based on the first private user-operator number ((Vx x Key2 x... x Keyi x ... x Keyn) x Key1) in a database of private keys (206); - (308) for each of the other operators, the algorithm for verifying private keys consisting of: - generating, from the second private user number received and from the public key associated with the point of entry of said other operator, a number called "second private user-operator number" ((Vx x Key1 x ... x Keyn) x Keyi); and - verifying, via the collaborative anonymization platform, whether the "second private user-operator number" ((Vx x Key1 x ... x Keyn) x Keyi) is recorded in said database of private keys (206).

4. Method according to claim 3, wherein the step of recording the private user key in the database of private keys, further comprises the recording of a lifetime parameter for said private key.

5. Method according to claim 4 further comprising, after the recording step, a step of counting down the lifetime parameter.

6. Method according to any one of claims 1 to 5, wherein the step of selection of the 'n' data pairs (PEn, Keyn) is carried out automatically according to predefined selection criteria.

7. Method according to any one of claims 1 to 6, wherein the encryption operation Fx is an operation of the modular exponentiation type.

8. Method according to any one of claims 1 to 6, wherein the encryption operation Fx is an operation referred to as "one-way accumulators".

9. Computer program product, said computer program comprising non-transitory code instructions allowing the steps of the method according to any one of claims 1 to 8 to be carried out, when said program is executed on a computer.

10. Device for anonymous access control to a collaborative anonymization platform operated by various operators (104, 108), for a user (202) having access rights to the collaborative anonymization platform by a first operator or access provider, the device comprising means of implementing the steps of the method according to any one of claims 1 to 8.