Method and device for transmitting or exchanging anonymous information within a trusted network
The method addresses the limitations of current communication protocols by using a shared secret function to fragment and recombine data through independent proxies within an anonymization network, enabling secure and anonymous point-to-multipoint communication within trusted networks.
Patent Information
- Application Number
- FR2021001055
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-02-04
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2041-02-04
AI Technical Summary
Current communication protocols for anonymous information exchange within trusted networks rely on trusted third parties, lack support for point-to-multipoint or multipoint-to-multipoint communication, and fail to ensure secure, real-time control and verification of network members.
The method involves generating complementary data fragments from an initial data packet using a shared secret function, transmitting these fragments through an anonymization network platform via independent proxies, and recombining them at the receiving end to reconstruct the original data packet, all without revealing the sender's identity.
This approach enables secure, anonymous, and trusted point-to-multipoint or multipoint-to-multipoint communication within networks, ensuring that only intended recipients access the information, while maintaining sender anonymity and allowing real-time network member verification.
Smart Images

Figure 00000021_0000 
Figure 00000021_0001 
Figure 00000022_0000
Abstract
Description
Title of the invention: Method and device for transmitting or exchanging anonymous information within a trusted network Field of the invention
[0001] The invention is in the technical field of communication protocols, and relates more particularly to a method of anonymous one-way transmission or anonymous two-way exchange of information within a network of partners, anonymously and securely without any trusted third party, while preserving the anonymity of the sender(s). State of the Art
[0002] Anonymization at the network level is currently in a very embryonic state. Current known solutions, such as the use of a virtual private network (VPN) or the Tor overlay network ("The Onion Router") or the anonymous I2P network (Invisible Internet Project), all rely on a "trusted third party" which, by construction, sees all upstream and downstream traffic exchanged between the communication endpoints.
[0003] Patent application WO / 2019 / 072470Al provides a solution to this problem by introducing two complementary concepts - the asymmetry of the uplink and downlink routes at the output of the exchange platform and the circulation of anonymous noise at all intermediate nodes of a given route - thanks to which, no element of the platform is in possession of all the content. However, this architecture only allows anonymized and secure point-to-point communication and it does not allow communication (i.e. transmission or exchange) from point to multipoint or from multipoint to multipoint.
[0004] There is also an emerging need which is not satisfied to enable exchanges on trusted networks of anonymous exchanges between partners sharing certain common needs but who for various reasons (e.g. regulatory, competition, image preservation, legal risks) do not wish to communicate this information directly to each other.
[0005] Also, in view of emerging needs and existing drawbacks, communications within trusted networks must have the following properties: - enable the rapid (or even near real-time) dissemination, in a one-way or two-way manner, of information to members of the trusted network (also called a “trust group”) or to members of subgroups (also called “trust circles”) of this network; - guarantee that only members of the trusted group will receive the information and that, consequently, no third party outside the group is able to access this information. This implies that there is no trusted third party likely to: (1) break the anonymity of the sender of a given piece of information; (2) access or modify this information, regardless of the level of protection (typically by encryption) intrinsic to this information; (3) know that data has been sent according to a variation where a noise generation system has been implemented; - allow, in a particular version called "guarantee", members of the network to be able to individually carry out this guarantee, that is to say that a member does not need to have confidence in the other members, to benefit from this guarantee; - allow the receiver(s) to qualify the information by a degree of confidence while its sender is (and must remain) unknown; - offer the possibility to each member of the network to control (i.e. verify) in real time the members of the network, and thus avoid an association between several members aimed at excluding one or more other members from certain transmissions or certain exchanges or aimed at breaking the anonymity of certain members or intercepting or modifying part of the transmissions or exchanges.
[0006] However, there is currently no solution that can cover all of these needs, including that of allowing each member of a network to control the other members of the network in real time, in particular in a low latency communication framework.
[0007] The following approaches provide partial solutions:
[0008] “Freenet” is a decentralized “peer-to-peer” (P2P) platform allowing censorship-resistant communications. In practice, it is an information-sharing service that allows an individual A to widely disseminate information, making it difficult to intercept and delete it by distributing encrypted blocks to certain members of the Freenet network who will be responsible, in effect, for ensuring their storage and retransmission on request. Each block is duplicated among several users, thus making it difficult to censor the information it contains. The information is then accessible through a link that will allow access and reassembly of the different blocks. Freenet is not anonymous in itself, but combined with Tor, it allows information to be disseminated anonymously to a large number of destinations. Freenet cannot guarantee access to the data only to partners. Indeed, anyone with the link will be able to access the information.Conceptually, Freenet is therefore more of a shared, distributed, persistent storage medium than a low-latency transmission medium.
[0009] “Zeronet” is a P2P information exchange network, conceptually similar to Freenet, but based on newer technologies (blockchain and BitTorrent). The main difference is that copies of the information are stored only by those who have accessed the information and not potentially by all members of the P2P network. Therefore, Zeronet has the same limitations as Freenet in terms of need.
[0010] Old publications relating to anonymous multicast have described mechanisms for hiding the control center of a network from an attacker (which is now used for Botnets), but the information only goes in one direction, because only the head of the network controls it.
[0011] The DAISY anonymization system, described in the article by Chan, Chi-Bun, and Cristina Nita-Rotaru, "DAISY: Increasing Scalability and Robustness of Anonymity Systems.", is based on a 3-tier architecture in which a central core of routers ("Core Delegate Network") aims to complicate the correlation between the inputs and outputs of the anonymization system. But the description of DAISY specifies that this solution cannot, as it stands, make anonymous group communications possible.
[0012] Tor hidden services can also be considered an anonymous broadband service, provided that the hidden service also implements access control. For example, the ICIJ (International Consortium of Investigative Journalists) uses SecureDrop, which is a hidden service on Tor, to receive information from whistleblowers and distribute it to all of its journalists. However, this hidden service is by construction a trusted third party because it will be the focal point of the information disseminated between the members of the network. It is the only one to control the dissemination to the members of the partner network and can therefore "choose" to restrict the dissemination of information to one or more members of the partner network. It sees all incoming and outgoing flows and is therefore theoretically likely to access or modify their content.
[0013] Furthermore, it is an intrinsically unidirectional system, which requires management at the application layer to make it bidirectional.
[0014] Furthermore, like the other solutions mentioned above, a Tor hidden service does not allow: - to ensure that the information is actually disseminated only to members of the network, even if an access control mechanism is added to the service; - to offer the possibility to each member of the network to control (i.e. verify) in real time the members of the network (and thus avoid an association of several members aimed at excluding one or more members from certain transmissions or certain exchanges); - to ensure that the information transmitted or exchanged cannot be intercepted and / or modified by a third party likely to carry out advanced attacks against current and future end-to-end encryption techniques; - to natively allow the creation of different circles of trust within the network of members; - to allow the possibility of hiding the event of transmission of a useful message.
[0015] The present invention meets these different needs. Summary of the invention
[0016] An object of the present invention is to provide an architecture and mechanism for anonymous transmission of information from point to multipoint or from multipoint to multipoint with low latency. The transmission is anonymized, secure and without trusted third parties. The invention allows the establishment of completely anonymous trusted networks for the anonymous one-way transmission or the anonymous two-way exchange of information.
[0017] Advantageously, the present invention aims to enable the exchange of information between partners, within a trusted network, in a truly anonymized, secure manner and without a trusted third party.
[0018] According to different embodiments, the invention also allows: - to guarantee to network members that no third party outside the network is able to access or modify the information transferred; - to guarantee to members of the network that no collusion by a subgroup of members is in progress against one or more other members; - to establish groups or circles of trust with differentiated levels of trust, in order to qualify the degree of trust of the anonymous information received by the receivers.
[0019] Generally speaking, the method of the invention is based on an architecture comprising a network anonymization solution (in practice it can be an overlay network of an underlying standard communication network); a set or group or circle of partners wishing to exchange information between them anonymously; and a set (or "pool") of proxies operated by independent actors, these actors being able to be partners of the group, and responsible for relaying the information from a transmitter of the group of partners to the other partners of the group.
[0020] Advantageously, the present invention introduces a new mode of communication which does not exist today, called “anonymous multicast” communication mode, i.e. providing the possibility of rapidly broadcasting, in a mono or bidirectional manner, information within a trusted group, without that none of the receivers is able to determine the sender of this information, and also without any other entity (typically a "trusted third party" but also a third party outside the trusted network) being able to make this determination.
[0021] The fields of industrial application of the invention are multiple such as those of energy, transport, banking to name but a few, but cover without limitation solutions implementing any single or multi-level trusted network for the anonymous exchange of data, including in particular: - a trusted network for the exchange of information to accelerate the detection of banking, payment or insurance fraud; - a trusted network for the exchange of information on cyber attacks; - a trusted network for the exchange of information between state intelligence services; - a trusted network for the exchange of information between journalists; - a trusted network for the exchange of confidential business information (e.g. about suppliers) between business partners.
[0022] In an alternative embodiment, the present invention allows the creation of an anonymous instant messaging architecture, which must remain compatible with obligations in terms of legal interceptions.
[0023] To obtain the desired results, a method is proposed for anonymously transmitting information between a plurality N' of members of the same trusted network, the members of the trusted network communicating with each other via an anonymization network platform (104), the method being implemented by computer and comprising steps consisting of: - generate by a member of the trusted network, a plurality N of complementary data fragments from an initial data packet, such that the recombination of the N complementary fragments makes it possible to reconstruct the initial data packet; - transmit by said transmitting member via the anonymization network platform, each complementary fragment generated, respectively to an independent proxy among a plurality N of independent proxies; - retransmit by each independent proxy via the anonymization network platform, the complementary fragment received from said transmitting member to the plurality N' of members of the trusted network; and - recombine by each receiving member of the trusted network, the plurality N of complementary fragments received in order to reconstruct the initial data packet.
[0024] The invention may be implemented according to alternative or combined embodiments, where: - the method may comprise an initial step consisting of defining among the plurality N' of members of the trusted network, at least three receiving members, and / or defining among the plurality N of independent proxies, at least two proxies to relay the transmission of the complementary fragments to the receiving members. - the step of generating a plurality N of complementary fragments may consist of applying a shared secret function F() to said initial data packet, and the step of recombining the plurality N of complementary fragments received consists of applying the inverse shared secret function F 'O to said complementary fragments. - the shared secret function can for example be an XOR function with or without latency. - the step of generating a plurality N of complementary fragments may consist of generating Nl random fragments of length equal to the length of the initial data packet, and where the last fragment N is a fragment complementary to the previous ones. - the initial step may further comprise a step consisting of defining a shared secret function F() for a subset of the plurality N' of members of the trusted network. - the step of transmission by the sending member of the complementary fragments, may also include, at the same time or sequentially, the transmission to each proxy of the shared secret function, or may directly include the reassembly function via the complementary fragments. - the method may further comprise, after the recombination step, steps consisting, for at least one receiving member of the trusted network, in implementing the steps of the anonymous transmission method, in order to send an anonymous response to said anonymous sending member. - the step of retransmission by the proxies, may consist of at least two proxies retransmitting their received complementary fragment, to a subset of the plurality of receiving members. - the step of transmitting complementary fragments to proxies may consist of transmitting, in addition to the complementary fragments, data or random fragments devoid of meaning and recognized as noise at the application level. - the method may comprise, prior to the step of retransmission by the proxies of the complementary fragments received, a step of storage by the proxies of said complementary fragments received. - the step of retransmitting the complementary fragments by the proxies may further comprise a step consisting, for each proxy, of notifying the transmission of the complementary fragment to a member of the trusted network responsible for access to the anonymization network platform, said notification being able to be a message including information relating to the performance of the transmission, in particular information relating to the size, rate, single or bidirectional nature of the data packet. - the method may further comprise, after the step of recombination of the fragments, a step of generating a notation of the received data packet. - one, several or all proxies can be hosted by one or more members of the trusted network.
[0025] The invention also relates to a device for transmitting, via an anonymization network platform, data between a plurality N' of members of the same trusted network, the device comprising means for implementing the steps of the method of the invention.
[0026] The invention also relates to a computer program product which comprises code instructions making it possible to carry out the steps of the method of the invention, when the program is executed on a computer. Description of the figures
[0027] Other characteristics and advantages of the invention will appear with the aid of the following description and the figures of the appended drawings in which:
[0028] [Fig. 1] illustrates in a simplified manner an environment for implementing the present invention;
[0029] [Fig.2] illustrates an embodiment of an architecture of the invention;
[0030] [Fig.3] is a flow diagram of the anonymous transmission method of the invention, in a point-to-multipoint monodirectional embodiment;
[0031] [Fig.4a]
[0032] [Fig.4b] illustrate the steps of the one-way anonymous transmission method of the flow diagram of [Fig.3];
[0033] [Fig.5a]
[0034] [Fig.5b] illustrate the additional steps of the two-way anonymous exchange method according to one embodiment of the invention;
[0035] [Fig.6] illustrates an embodiment of the invention called “multi-circle”;
[0036] [Fig.7a]
[0037] [Fig.7b] illustrate an embodiment of the invention called “guarantee”. Detailed description of the invention
[0038] The context 100 for an implementation of the invention is illustrated in a simplified manner in [Fig.l], comprising a communication network 102 on which a network anonymization solution 104 exists. In one embodiment, the network anonymization solution 104 is a coverage anonymization network of the underlying traditional communication network 102.
[0039] Advantageously, the anonymization solution 104 does not necessarily have to have very advanced anonymization properties. Nevertheless, the level of anonymity offered by the invention is partly dependent on the robustness of the network anonymization solution. Thus, a simple VPN anonymization service is not recommended, and those skilled in the art will implement the invention preferably via anonymization networks such as Tor, I2P or preferably according to a platform based on the architecture of the aforementioned patent application WO2019 / 072470Al of the Applicant.
[0040] The architecture for implementing the method of the invention also comprises a network 106 of N' partners (Mi to MN) wishing to exchange information between them anonymously, and a reservoir of N independent proxies 108 (Pi to PN).
[0041] The proxies and the members of the trusted network (i.e. the partners) have network addresses (for example IP addresses) of the underlying traditional network 102.
[0042] The proxies are responsible for relaying information from a sending member to the partners or recipients of the trusted network 104. The proxies are not able to know and determine whether the data they transmit is useful data or not.
[0043] [Fig.2] illustrates an implementation 200 of the invention in the context 100 of the [Fig.l]. Although a traditional communication network 102 is shown, the latter does not participate in the implementation of the method of the invention, where communications are made only through the anonymization network 104.
[0044] The components involved for the implementation of the invention are at least: - a network anonymization solution 104, which in practice is an overlay network “above” the classic network 102; - a network or circle of trust (“Trust ring”) 106, composed of a plurality N' of MN- members or partners wishing to exchange information between them anonymously; - a reservoir 108 of a plurality N of PN proxies, operated by independent actors, and responsible for relaying information from a transmitter of the trusted network to the partners of the trusted network.
[0045] Optionally, one or more databases (202, 204) can be created, and act as registers of proxies, partners, and define the membership of these partners in the different circles of trust (i.e. sub-groups of the initial trust network).
[0046] The databases (202, 204) are controlled by all members of the trusted network, who can therefore consult them, securely or not, at any time, either via the anonymization network 104, or directly via the conventional network 102. In effect, both the proxy pool 108 and the members of the trusted network 106 have network addresses (for example IP addresses) visible to all elements of the underlying traditional network 102.
[0047] In a preferred embodiment of the invention, the members and the proxies communicate with each other anonymously through the anonymization network 104. However, in the case of one-way communication, the connection of the proxies to the members of the trusted network can be made in a non-anonymous manner.
[0048] Thus, the partners of the trusted network 106 have access at any time to the list of proxies, to the list of other partners and to the membership of these partners in the various possible trusted circles (subgroups). Since consultation of these databases is very common for those skilled in the art, this is not detailed in the description.
[0049] In one embodiment, the databases (202, 204) are defined as routing tables as illustrated in Tables I, II, III below.
[0050] The subgroups (or circles of trust) are defined upstream between the members of the trust group. Each member then chooses the circle(s) of trust to which he wants to send information by selecting the relevant pairs (proxies, groups) according to the predefined routing tables.
[0051] In a practical embodiment, the user communicates a target group identifier to each selected proxy.
[0052] Table I illustrates the general constitution of groups G; (by agreement between the members M; of a trust network), with for each group, the list of proxies P; and members of the circle of trust M; who are part of this group. For example, members Mb M2, M4 belong to group Gb and they can relay their information through proxies Pb P2 and P4.
[0053] [Tableauxl] Global Groups Gi Proxies Pj Members M, G1 PiP2P4 Mi M2 M4 G2 P2 P3P4 M2 M3 M4 G3 PiP2P3 Mi M2 M3 ... Table I
[0054] Table II illustrates the group membership parameters, corresponding proxies, and shared secret function used by a member Mi according to its ap membership in a group. Thus, for example, during exchanges in the group Gi (grouping according to table I the members Mb M2, M4, and the relays Pb P2, P4), the shared secret function used by Mi is the XOR function. During exchanges in the group G3, (grouping according to table I the members Mb M2, M3, and the relays Pb P2, P3), the shared secret function used by Mi is the 'XOR with latency' function. In one embodiment of the invention, the shared secret function may be defined by the members of the group during their first exchanges and modified over time, periodically or not.
[0055] [Tables2] M, Groups Proxies Function F() G1 PiP2P4 XOR G3 PiP2P3 XOR + latency ... Table II
[0056] Table III illustrates a routing table of a proxy indicating the parameters of group G; and the members belonging to the respective group. For example, the proxy P4 will relay information sent by a member of the group G2 to all the members of this group, i.e. M2, M3 and M4.
[0057] [Tables3] Member Groups G1 M i M2 M4 G2 M2 M3 M4 ... Table III
[0058] [Fig.3] shows a flow diagram 300 of the anonymous transmission method of the invention, in a point-to-multipoint monodirectional embodiment. The method begins when a member, for example 'Mf, of a circle of trust {Mb M2, ..., Mn] wishes to transmit anonymously to the members of the circle, information "Data". The partner trust network 206 is composed of at least three members (N' >3).
[0059] In the remainder of the description, for reasons of simplification, the terms 'members', 'partners', 'issuer' designate physical entities and / or hardware and software means configured for these physical entities to implement any function allowing, among other things, to fragment, transmit, receive, reconstruct data via the anonymization network, according to the steps of the method of the invention.
[0060] In a first step 302, the method allows the transmitter to fragment the information to be transmitted into a plurality N of fragments, then in a following step 304, the method allows the transmitter to transmit each fragment N; generated to a proxy P; from the proxy pool.
[0061] [Fig.4a] illustrates steps 302 and 304 of the one-way anonymous transmission method of the flow diagram of [Fig.3], using the example of the architecture of [Fig.2],
[0062] Thus, in step 302, from a “Data” packet, the transmitter Mi generates N complementary fragments (Fragment 1, Fragment 2, ... Fragment N) through a shared secret function F(), in such a way that the recombination of these N complementary fragments makes it possible to find the initial “Data” packet, and which can be expressed according to the following equation: F '({complementary fragment;}i=i..N) = Data).
[0063] In one embodiment, the sender defines the recipients or a trusted group of the information to be received.
[0064] In one embodiment, the shared secret function F() may be an XOR (®). The transmitter Mi generates Nl random fragments of length equal to the length of the “Data” packet, and such that the last fragment is complementary and equal to:
[0065] y ragment ® J random fragment^ ® Data •
[0066] In the next step 304, the transmitter Mi transmits each fragment to a different proxy via the anonymization network platform 104. Thus, it transmits the first fragment 'Fragment 1' to a first proxy, for example Pb through an anonymous connection MrPi; it transmits the second fragment 'Fragment 2' to a second proxy, for example P2, through an anonymous connection MrP2; etc. until the last fragment 'Fragment N' transmitted to an Nth proxy, for example PN, through an anonymous connection MrPN.
[0067] It should be noted that the anonymous connection MrPi established to transmit a fragment to a proxy P; can be established only during the delay of the transmission of the fragment from the transmitter to the proxy, or else be maintained if a response is expected from the proxies Pi.
[0068] Thus, step 304 allows each proxy P to receive random noise (i.e. a fragment) from an unknown member of the trusted network.
[0069] According to alternative embodiments, the number of proxies can be predefined or be defined by the transmitter before sending information.
[0070] The number of proxies constituting the proxy pool 108 is at least two proxies (N>2).
[0071] The method continues with a step 306 in which each proxy which has received a complementary fragment, retransmits via the anonymization network platform, this fragment to all the members of the trusted network (or to all the members of a trusted network subgroup), then with a step 308 where each member which has received a plurality of fragments, reconstitutes the “Data” packet using the inverse shared secret function F '().
[0072] According to alternative embodiments, the shared secret function F() can be predefined for a circle of trust and therefore known to each member of the group; it can be defined by the transmitter and transmitted via the proxies with the complementary fragments, and relayed to the recipients in the retransmission step 306; it can also be defined according to the application for which the method of the invention is implemented.
[0073] Thus, the person skilled in the art, beyond the indicated example of an XOR function, can implement any other function making it possible to establish a shared secret functionality between partners.
[0074] [Fig.4b] illustrates steps 306 and 308 of the one-way anonymous transmission method of the flow diagram of [Fig.3], using the example of the architecture of [Fig.2],
[0075] Thus, in step 306, each proxy Pi relays and retransmits to all the partners of the trusted network {MiN>, the complementary fragment 'Fragment;' that it received from the transmitter Ml, through a previously established anonymous connection MrPi.
[0076] It should be noted that the anonymous connection P;-M; established to retransmit a fragment from a proxy P; to a recipient M; can be established only during the delay of the transmission of the fragment from the proxy to this recipient, or else be maintained if a response is expected from the members of the circle of trust {Mi}.
[0077] When the members of the circle of trust have received the fragments sent by the proxies, the method allows, at step 308, each member of the network Mi to recombine all of the complementary fragments relayed by the pool of proxies {Pi}, through the inverse shared-secret function F *(), and thus obtain the initial “Data” packet of the information that the transmitter wishes to share.
[0078] Variant embodiments of the information exchange method of the invention are described according to Figures 5 to 7.
[0079] In an alternative embodiment, the method of the invention is implemented for a bidirectional transmission between a transmitter Mi and all the members {MJ of a circle of trust of which the transmitter is a part, and involving a response from each of the M;. Such a situation may for example be in the case where the information “Data” is a query request on a particular BDD database which is hosted by each Mj.
[0080] The method for this variant comprises the anonymous transmission steps 302 to 308 previously described from a transmitter Mb. In this variant, the anonymous connections MrPi established to transmit a fragment to a proxy P, and the anonymous connections PrMj established to retransmit a fragment from a proxy P; to a recipient Mj are maintained.
[0081] The method 300 further comprises steps where each member of the circle of trust who has received the request from a sender unknown to them will implement the same anonymous transmission mechanisms of the method of the invention, to in turn send an anonymous response to the anonymous sender.
[0082] Thus, a member who sends information of the “Response” type becomes a transmitter within the meaning of the method 300 of the invention.
[0083] Figures 5a and 5b illustrate the sequence of steps of the two-way anonymous exchange method according to one embodiment of the invention.
[0084] A partner Mj of a group having received, after recomposition of a packet, a request calling for a response, implements the anonymous transmission method. It decomposes in a step 502, by application of the shared secret function F(), its “Response” data packet into a plurality N of complementary fragments (FragmentMjl, FragmentMJ2, ..., FragmentMJN) corresponding to the number of proxies, then transmits in a step 504 each fragment of this response to each proxy, through the anonymous connection Pi-Mj which was previously established by the proxy Pi with the member Mj and which was maintained.
[0085] In a following step 506, each proxy retransmits the received fragment to the recipient member Mi through the anonymous connection MrPi previously established and which has been maintained. Then, in a following step 508 which is functionally similar to step 308, the recipient member Mi applies the inverse shared-secret function F 'O on the plurality of fragments Mj, to reconstruct the "Response" packet sent by the member Mj of the circle of trust, which remains unknown to it.
[0086] In the case where simultaneous transmissions or exchanges could occur within the trusted network, the transmitter M1 can associate with the complementary fragments i a common identifier that it will have generated, and thus allow the recipients Mi to associate the correct fragments with each other.
[0087] In an alternative embodiment of the invention, the retransmission by the P; proxies of the fragment i to the pool of recipients {Mi}, can be done directly without going through the anonymization network. However, in such a case, and also in the case where the transmission would also involve a response by each Mi, in order to guarantee the anonymity of the response, it is necessary that the application level commands that the transmission of these responses follows the principle of the invention (i.e. steps 302 to 308). This procedure is recommended in order to avoid a potential analysis of its content, typically a reading of the size of the response in the case where “traffic flow confidentiality” techniques, such as “padding” for example, could not be implemented.
[0088] A variant of the invention, called a “multi-circle” variant, is illustrated in [Fig. 6]. In this embodiment, one or more or all of the proxies have different retransmission rules, i.e., each sends the fragment that it received from a transmitter Mi to a subset of the members {Mi} of the circle of trust, which is specific to this transmitter (subset j of {Mi}). The retransmission rules can be pre-established by the members of the circle of trust. They can be centralized in the database of members 204 and proxies 202.
[0089] Thus, a transmitter Mi can thus decide to send a “Data” packet only to a chosen subset of recipients in such a way that the receiving members of this subset are composed only of the set of members which are at the intersection of the subsets of the chosen proxies. The members outside this intersection but which are included in certain subsets, will then not receive all of the fragments, and will therefore not be able to find the initial “Data” packet.
[0090] Thus advantageously, several circles of trust can be created, as illustrated in [Fig.6] where the transmitter Mi chooses to transmit a data packet “Data” on two complementary fragments (Fragment1, Fragment2), relayed by two proxies P2 and PN (steps 602, 604).
[0091] According to the anonymized transmission method of the invention, the proxies P2 and PN each retransmit the received fragments to a different subset of recipients. Thus, the proxy P2 retransmits the fragment Fragment1 to the recipients Mi and M2, the proxy PN retransmits the fragment Fragment2 to the recipients M2 and MN. It appears that M2 being the only one to receive the two complementary fragments (Fragment1, Fragment2), it is therefore the only one able to recombine them, according to the principles of application of the inverse shared-secret function, and thus access the “Data” information.
[0092] A variant of the invention, called the “Guaranteed” variant, is illustrated in Figures 7a and 7b. In this embodiment, one or more or all of the proxies may be hosted by one or more of the partners of the trusted network. [Fig.7a] more specifically illustrates step 304 of the method of the invention where the transmitter sends the complementary fragments of the data packet to all of the proxies including the one that it hosts and controls, and [Fig.7b] more specifically illustrates step 306 of the method of the invention where each proxy, including the one hosted by the Mb transmitter, retransmits the received fragment to the members of the circle of trust.
[0093] In this configuration, the partners who have a proxy have a guarantee, when they send or receive information passing through the proxy that they control, that no one, outside the group of recipients identified by the sender, is able to access (or modify) the “Data” information, even in the event of collusion of all the other members (or proxies) of the trusted network.
[0094] Another variant of the invention, called the “External Protection” variant, consists in one, or more, or all of the partners in the circle of trust generating “noise”, i.e. sending non-useful data or random fragments devoid of meaning, in order to drown the useful data (the complementary fragments of a “Data” or “Response” packet) in a wider traffic. These useless data or fragments are recognized as noise by the application level. Advantageously, this makes it possible to prevent proxies or an external observer who would analyze the network flows and the proxies from knowing whether the data which is passing through is useful data or not.
[0095] Such noise can be generated in at least two ways. In a first approach, the noise can be generated at the application level, i.e. at the level of the "Data" packets and therefore before fragmentation by the shared-secret function F(). This is done by generating content, random or not, which is marked by the protocol and before fragmentation as non-useful content (for example via a particular bit in the protocol header). In another approach, the noise can be generated at the level of the trusted network protocol. This is done by generating, randomly or not, and sending them, a number of fragments less than the number N of proxies or the number of proxies required for the circle of trust considered (i.e. subset j of {Mi}).This generation can be pseudo-random or be carried out from intelligent devices based on the current exchange flow, in reaction to a change in the flow compared to both total and useful traffic flows.
[0096] Another variant of the invention, called the “Mailbox” variant, consists in that one or more or all of the partners in the circle of trust can choose to query the proxies to which they have access in order to retrieve all of the fragments to which they have the right to have access. In this configuration, the messages are not automatically relayed by the proxies. This mode can also be used when resuming a connection.
[0097] Another variant of the invention, called the “Storage” variant, consists in that one or more or all of the proxies can store the fragments that they relay. These fragments then remain accessible to authorized partners.
[0098] Another variant of the invention, called the “Payment” variant, consists in the method of the invention being established between all the members of a network of trusted and a particular member who is in charge of access to the network. In this configuration, at each flow transmission, the proxies relay the information to all members of the trusted network (as detailed by the method of the present invention) with a particular message notifying the data transfer to the particular member in charge of access to the network, this message being able to include information relating to the performance of this transfer, such as for example, information relating to the size, the flow rate, the mono or bidirectional nature of the packet, etc. This particular message can for example be composed of the header of the useful message with random noise in place of the fragment, this prevents the proxies from sending undue particular messages.
[0099] Advantageously, this variant makes it possible to define a way of deducing the cost on the objective of using the anonymization platform for the entire trusted network. From this, an invoice can be issued to all the members of the trusted network, the trusted network being responsible for defining a method of distributing this charge, for example a division of the amount of the invoice by the number of members of the trusted network.
[0100] Another variant of the invention, called the “Reward” variant, consists of the exchanges being rated by all the receivers of the information, on a basis which is defined by each of the trusted networks. Advantageously, such a rating makes it possible to remunerate the partners providing information deemed useful to the platform. The remuneration can be delegated to the different proxies. The remuneration can possibly be based on a cryptocurrency system.
[0101] The person skilled in the art understands that the different variants of the invention - "Guarantee", "Multi-circles", "External protection", "Mailbox", "Storage", "Payment" and "Reward" - can be combined with each other to offer the whole spectrum of additional properties in a flexible manner.
[0102] A communication method, called “anonymous multicast”, and derived variants have thus been described, which offer numerous advantages which are: - to enable partners to build a network of trust in which these partners can transmit (one-way communication) or exchange (two-way communication) information between them anonymously; - that the transmission or exchange is made without a trusted third party capable of breaking anonymity and / or accessing (or modifying) the content of the transmission or exchange; - to build a network of trust composed of one or a plurality of different circles of trust; - to allow an issuer or initiator of an exchange to be the only one to control the level of trust used; - to offer one or more members of the network a guarantee enabling them to verify that the information has actually been disseminated only to members of the network while preserving the anonymity of the sender; - to allow a transmitter, but also each of the receivers in a chosen circle of trust, to be able to verify for themselves that the content of the information could not have been intercepted or modified by a third party, and that there could have been no collusion between other members of the network against them. This provides a guarantee that other members of the network could not reconstruct a trusted third party; - to guarantee that during a transmission, only members of the group of partners will receive the information and that, consequently, no third party outside the group is able to access this information. This implies that there is no trusted third party capable of breaking the anonymity of the sender of a given piece of information, and of accessing or modifying this information regardless of the level of protection (typically encryption) intrinsic to this information. - to prevent proxies and third parties outside the network from knowing if useful content is sent or retrieved by one of the network members. - to allow the receiver(s) to qualify the information by a “degree of trust” while its sender is (and must remain) unknown. This degree of trust is deduced by the receiver by analyzing the proxies which relayed the information defining this circle of trust; - to enable members of a circle of trust to be able to individually obtain this guarantee, i.e. a member does not need to trust other members to benefit from this guarantee.
Claims
Claims
1. A method (300) for anonymously transmitting information, the transmission being a point-to-multipoint communication or a multipoint-to-multipoint communication between members of the same trusted network, a trusted network being predefined by a plurality of members and a plurality of independent proxies, the communication within a trusted network being carried out on an anonymization network platform (104) masking the IP addresses of the members of said trusted network, the method being implemented by computer and comprising steps consisting in: - generating (302), by a member of a trusted network comprising N' members and N proxies, a plurality N of complementary fragments of data from an initial data packet, such that the recombination of the N complementary fragments makes it possible to reconstruct the initial data packet;- transmitting (304), by said sending member via the anonymization network platform, each complementary fragment generated, respectively to an independent proxy among the N proxies; - retransmitting (306), by each independent proxy via the anonymization network platform, the complementary fragment received from said sending member to the plurality N' of members of the trusted network; and - recombining (308) by each receiving member of the trusted network, the plurality N of complementary fragments received in order to reconstruct the initial data packet.;
2. The method according to claim 1 comprising an initial step of defining among the plurality N' of members of the trusted network, at least three receiving members, and / or of defining among the plurality N of independent proxies, at least two proxies to relay the transmission of the complementary fragments to the receiving members.
3. The method according to claim 1 or 2 wherein the step of generating a plurality N of complementary fragments consists of applying a shared-secret function F() on said initial data packet, and the step of recombining the plurality N of complementary fragments received consists of applying the inverse shared-secret function F 'O on said complementary fragments.
4. The method of claim 3 wherein the secret function- shared is an XOR function with or without latency.
5. The method according to claim 4 wherein the step of generating a plurality N of complementary fragments consists of generating Nl random fragments of length equal to the length of the initial data packet, and where the last fragment N is a fragment complementary to the previous ones.
6. The method of any one of claims 2 to 5 wherein the initial step further comprises a step of defining a shared-secret function F() for a subset of the plurality N' of members of the trusted network.
7. The method according to claim 6 wherein the step of transmitting by said transmitting member the complementary fragments, comprises at the same time or sequentially the transmission to each proxy of the shared secret function, or, directly comprises the reassembly function, via the complementary fragments.
8. The method according to any one of claims 1 to 7 further comprising after the recombination step, the implementation by at least one receiving member of the trusted network, of the steps of generating (302), transmitting (304), retransmitting (306) and recombining (308) of claim 1, in order to send an anonymous response to said anonymous sending member.
9. The method according to any one of claims 1 to 8 wherein the step of retransmission by the proxies, consists in that at least two proxies retransmit their received complementary fragment, to a subset of the plurality of receiving members.
10. The method according to any one of claims 1 to 9 wherein the step of transmitting complementary fragments to the proxies consists of transmitting, in addition to the complementary fragments, data or random fragments devoid of meaning and recognized as noise at the application level.
11. The method according to any one of claims 1 to 10 further comprising, before the step of retransmission by the proxies of the complementary fragments received, a step of storage by the proxies of said complementary fragments received.
12. The method according to any one of claims 1 to 11 in which the step of retransmitting the complementary fragments by the proxies further comprises a step consisting of each proxy notifying the transmission of the complementary fragment, to a member of the trusted network responsible for access to the anonymization network platform, said notification being able to be a message including information relating to the performance of the transmission, in particular information relating to the size, the flow rate, the mono or bidirectional nature of the data packet.
13. The method according to any one of claims 1 to 12 further comprising after the step of recombination of the fragments, a step of generating a notation of the received data packet.
14. The method of any one of claims 1 to 13 wherein one, more, or all of the proxies are hosted by one or more of the members of the trusted network.
15. A computer program product, said computer program comprising code instructions for carrying out the steps of the method according to any one of claims 1 to 14, when said program is executed on a computer.
16. A device for anonymous transmission of information, the transmission being a point-to-multipoint communication or a multipoint-to-multipoint communication between members of the same trusted network, a trusted network being predefined by a plurality of members and a plurality of independent proxies, the communication within a trusted network taking place on an anonymization network platform (104) masking the IP addresses of the members of said trusted network, the device comprising means for implementing the steps of the method according to any one of claims 1 to 14.