Authentication of a user's identity or status
The method addresses privacy and resource issues in digital identity management by using a blind signature mechanism to selectively authenticate identity elements, enhancing user privacy and reducing computational load.
Patent Information
- Application Number
- FR2023013996
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-12
- Publication Date
- 2025-06-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing digital identity management systems, such as Federated Identity, compromise user privacy as the identity provider can track user access activities and infer service usage, while also being resource-intensive due to the need to manage and verify large sets of identity elements.
A method that allows users to selectively authenticate specific identity elements using a blind signature mechanism, where the authentication device generates a certificate for only the selected identity elements without revealing their identity, reducing computational load and protecting user privacy.
This approach enhances user privacy by preventing identity providers from tracking service usage and reduces computational resources by minimizing the number of identity elements processed, thereby improving authentication efficiency.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Authentication of the identity or quality of a user Prior art
[0001] The invention lies in the field of digital identity management. More specifically, the invention relates to a method for managing digital identity that preserves the privacy of users, in which an identity provider provides a user with a certification of one or more identity elements specific to this user, this or these identity elements belonging to a set of identity elements of the user that is available from said identity provider.
[0002] Many service providers, whether online or in a face-to-face relationship with the user, require the provision of user identity elements, more generally in order to deliver their service.
[0003] Traditionally, in a non-digital world, this provision of identity elements is carried out using (physical) titles issued by official authorities (identity cards, driving licenses, etc.) and supporting documents issued by recognized third-party certifiers (electricity bill, telecom bill, medical certificate, etc.).
[0004] The development of services accessible via the Internet requires the implementation of dedicated tools allowing the digitization of elements present on the aforementioned media, possibly in a structured manner and authorizing their sharing with the service provider, after consent from the user.
[0005] The major prescribers on the Internet have until now structured the field of digital identity management in line with their business model. They have, for example, through the OIDC protocol (in English "OpenID Connect"), developed an offer which centralizes the user's identity elements and, under its control, after identification / authentication and consent of the user, authorizes the service's access to all or part of the user's identity elements. One of the main problems with this type of architecture, known as Federated Identity, lies in the fact that the identity provider learns, each time a user consumes one of the services, when the operation takes place and which identity elements the user shares with the service provider to which he is accessing.The identity provider is thus able to compile the history of the user's access activities and identity elements required by the various services he has visited. This data then allows it to build a profile of the user's service consumption with the service providers and to use it for often commercial purposes.
[0006] Self-sovereign identity (SSI) is another approach to digital identity, which gives users full control over their identity elements: they can present them when accessing a service either to prove who they are or one of their qualities. Only the service provider and the user interact during the identity element sharing phase. In order to generate trust between the user and the service, the user presents identity elements that have been certified by a third party (the identity provider) that the service provider trusts. In this logic, the user holds identity elements concerning him, which have been issued and certified by one or more trusted entities, controls their dissemination to the service provider (after consent) and protects his privacy with respect to the identity provider by excluding it from the relationship he has with the service provider.
[0007] Self-sovereign identity is based on the implementation of an asynchronous authentication scheme for a user's identity elements, which scheme operates according to a particular protocol, for example the El Passo protocol as described at https: / / arxiv.org / pdf / 2002.10289.pdf, the BBS+ protocol as described at https: / / identity.foundation / bbs-signature / draft-irtf-cfrg-bbs-signatures.html, etc.
[0008] In the current configuration of the PPass protocol based on the BBS / BBS+ protocol which is currently being standardized at the IETF (Internet Engineering Task Force), the identity provider has the user's identity elements. It can be operated, for example, on behalf of or by an administrative entity legally having the user's identity elements. The role of identity provider can be extended to all organizations managing and legally possessing the user's identity elements. The identity provider(s) have(s) a system for managing the PPass protocol so as to interact with the user and his / her personal device and, secondly, means of interaction with third-party entities consuming the user's identity elements in the context of providing a service.An identity provider managing the user is able to identify him, authenticate him and generate a token that certifies the identity elements from this same identity provider. In the current cryptographic scheme, the identity provider managing the user has a set of identity elements of the user. The user, after identification / authentication with the identity provider, obtains all the identity elements concerning him. This set of identity elements is certified by a token specific to the identity provider issuing the identity elements, a token constructed using secret data present in the user's equipment. In a multi-identity provider context, the user can proceed similarly with various identity providers. A . At the end of the identity authentication operations, the user has on his device several sets of identity elements, each accompanied by their own token certifying them. Some identity providers may have a large number of user identity elements, such as sovereign identity providers for example. The calculations on a set of user identity elements are, at the generation and verification of the accompanying derived token, a linear function of the number of identity elements included in the set of identity elements, and therefore of the size of this set.
[0009] In fact, calculations on a set of large identity elements can be costly in terms of machine resources both in the generation of the token certifying them by the identity provider, and in the derivation of said token by the user's equipment to generate a verifiable presentation intended to be transmitted to a service provider which the user wishes to access using his equipment, or even in the verification by the service provider of the validity of the derived token, with regard to the identity elements revealed by the user.
[0010] In order to overcome this drawback, one solution would be for an identity provider managing a given user to authenticate the user and generate as many tokens as there are user identity elements available from that same identity provider. However, such a solution is not desirable for the following reasons:
[0011] - the identity provider could, depending on the identity element it certifies, infer the service that the user wishes to access, which does not meet the requirements of protection of personal data and the user's privacy;
[0012] - the storage, in the user's equipment, of several tokens which certify each one an identity element of the set of identity elements, would occupy a lot of memory space in said equipment, whose storage resources are limited. Subject matter and summary of the invention
[0013] One of the aims of the invention is to remedy at least one of the drawbacks of the aforementioned state of the art by proposing a new technique for authenticating the identity or the quality of a user, when this user does not need to have all the identity elements concerning him provided by an identity provider.
[0014] For this purpose, an object of the present invention relates to a method for obtaining authentication of the identity or quality of a user from an authentication device, associated with an identity provider, which comprises a set of at least two identity elements of said user, said identity elements being stored in a terminal associated with the user and being known to the authentication device, said method comprising the following in said terminal: - authentication of the user with the authentication device using a secure communication established between the terminal and the authentication device, - selection, using a user interface of the terminal, of at least one identity element to be certified in said set, - sending a message to the authentication device, said message indicating, in a manner not identifiable by the authentication device, said selected identity element and said identity element remaining in said set, not selected, - reception from the authentication device of a certificate signed using a blind signature, said certificate certifying the validity of said selected identity element.
[0015] On the user terminal side, thanks to the invention, the user is able to request from the signing entity a signed certificate which certifies only the identity element(s) that the user needs to access a product and / or service provider, without revealing to the authentication device the identity element(s) included in the signed certificate. This allows the terminal associated with the user, during such access, to derive, from the signed certificate received from the signing entity, an access token from a product and / or service provider which would only need to verify the validity of this / these identity element(s).Considering that the number of identity elements selected by the user is less than the number of identity elements available both in the user terminal and in the authentication device, the computation time for deriving the access token in the user terminal is reduced by a linear factor which is a function of the number of identity elements selected by the user.
[0016] According to a particular embodiment, the selected identity element is associated with a first value and the non-selected identity element is associated with a second value, said message containing a commitment on the first value and on the second value.
[0017] Such an embodiment allows the user not to provide in clear text to the authentication device which identity element(s) the user wishes to certify or not to certify, but a commitment (or pledge) on the choice of the identity element(s) to be certified or not to certify. In the context of the invention, such a pledge advantageously allows the user not to disclose to the authentication device the identity element(s) that he wishes to certify or not to certify, with however the impossibility for the user to modify his commitment.
[0018] According to another particular embodiment, the first value and the second value are respectively 1 and 0.
[0019] According to yet another particular embodiment, the method for obtaining authentication of the identity or quality of a user further comprises: - a calculating a proof that the first value and the second value pledged are respectively 1 and 0, - sending said proof to said authentication device.
[0020] Such proof allows the user to demonstrate to the signing entity that the user knows how to reveal a pledge on the first and second values.
[0021] The various embodiments or features mentioned above may be added independently or in combination with each other, to the method for obtaining authentication of the identity or quality of a user as defined above.
[0022] The invention also relates to a terminal configured to obtain authentication of the identity or quality of a user from an authentication device, associated with an identity provider, which comprises a set of at least two identity elements of said user, said identity elements being stored in said terminal and being known to the authentication device, said terminal being further configured to: - authenticate a user associated with said terminal, with the authentication device, using a secure communication established between the terminal and the authentication device, - select, using a user interface of the terminal, at least one identity element to be certified in said set, - send a message to the authentication device, said message indicating, in a manner not identifiable by the authentication device,said selected identity element and said identity element remaining in said set, not selected, - receive from the authentication device a certificate signed using a blind signature, said certificate certifying the validity of said selected identity element.
[0023] The invention also relates to a method for generating an authentication of the identity or quality of a user with an authentication device, associated with an identity provider, which comprises a set of at least two identity elements of said user, said identity elements being stored in a terminal associated with the user and being known to the authentication device, said method comprising the following in the authentication device: - obtaining an authentication of the user using a secure communication established between a terminal associated with the user and the authentication device, - receiving a message from said terminal, the message indicating, in a manner not identifiable by the authentication device, at least one identity element to be certified selected from said set and said identity element remaining in said set, not selected,- calculation of a signed certificate using a blind signature, said certificate certifying the validity of said selected identity element, - sending said signed certificate to the terminal.
[0024] The invention advantageously allows any signatory entity, typically a identity provider, which has clear identity elements of a user, such as for example his name, nationality, address, date of birth, telephone number, etc. to generate a signed certificate on at least one of these identity elements that the user wishes to certify, without however being able to identify which identity element it is. This invention thus proposes an innovative cryptographic mechanism which aims to ensure better protection of users' personal data with respect to identity providers, in particular by preventing identity providers from determining the uses or services that the user wishes to benefit from using the signed certificate.In the case, for example, where the user wishes to obtain from an identity provider a certificate of majority, in other words, a certificate relating only to his or her "date of birth", the invention advantageously makes it possible to prevent the identity provider from deducing that this user intends to connect to sites reserved for adults, for example.
[0025] According to a particular embodiment, the signed certificate is calculated from a commitment contained in said received message, said commitment relating to a first value associated with the selected identity element and to a second value associated with said non-selected identity element.
[0026] According to another particular embodiment, the first value and the second value are respectively 1 and 0.
[0027] According to yet another particular embodiment, the method for generating an authentication of the identity or quality of a user further comprises: - a reception, from said terminal, of proof that the first value and the second value pledged are respectively 1 and 0, - a verification of said proof received.
[0028] The various embodiments or characteristics mentioned above may be added independently or in combination with each other, to the method for generating an authentication of the identity or quality of a user as defined above.
[0029] The invention also relates to an authentication device configured to generate an authentication of the identity or quality of a user, said device comprising a set of at least two identity elements of said user, said identity elements being stored in a terminal associated with the user and being known to the authentication device, said authentication device being configured to: - obtain an authentication of the user using a secure communication established between a terminal associated with the user and the authentication device, - receive a message from said terminal, the message indicating, in a manner not identifiable by the authentication device, at least one identity element to be certified, selected from said set, and said identity element remaining in said together, not selected, - calculate a signed certificate using a blind signature, said certificate certifying the validity of said selected identity element, - send said signed certificate to the terminal.
[0030] The invention also relates to a computer program comprising program code instructions for implementing the method for obtaining authentication of the identity or quality of a user, when said program is executed by a computer.
[0031] The invention also relates to a computer program comprising program code instructions for implementing the method for generating authentication of the identity or quality of a user, when said program is executed by a computer.
[0032] These programs may use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0033] The invention also relates to a computer-readable information medium, and comprising instructions of a computer program as mentioned above. The information medium may be any entity or device capable of storing the program. For example, the medium may comprise a storage means, such as a ROM, a non-volatile memory of the flash type or even a magnetic recording means, for example a hard disk. Furthermore, the information medium may be a transmissible medium such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means. The program according to the invention may in particular be downloaded from a network of the Internet type.Alternatively, the information carrier may be an integrated circuit in which the program is incorporated, the circuit being adapted to perform or to be used in the performance of any of the methods in question. Brief description of the drawings
[0034] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate exemplary embodiments thereof which are not limiting in nature. In the figures:
[0035] [Fig-1] [Fig.l] represents a system for authenticating the identity or the quality of a user comprising a terminal associated with the user and an authentication device, in a particular embodiment of the present invention;
[0036] [Fig.2] [Fig.2] represents in the form of a flowchart the steps of a method of obtaining authentication of the identity or quality of a user, in a particular embodiment of the present invention;
[0037] [Fig.3] [Fig.3] represents in flowchart form details of the method of obtaining authentication of the identity or quality of a user of [Fig.2], in a particular embodiment of the present invention;
[0038] [Fig.4] [Fig.4] represents in the form of a flowchart the steps of a method of generation of an authentication of the identity or quality of a user, in a particular embodiment of the present invention;
[0039] [Fig.5] [Fig.5] represents in flowchart form details of the method for generating an authentication of the identity or quality of a user of [Fig.4], in a particular embodiment of the present invention;
[0040] [Fig.6] [Fig.6] represents in the form of a flow diagram the main exchanges established during the implementation of the method for obtaining and generating authentication of the identity or quality of a user, in a particular embodiment of the present invention;
[0041] [Fig.7] [Fig.7] represents the hardware architecture of the terminal of [Fig.l], in a particular embodiment of the present invention;
[0042] [Fig.8] [Fig.8] represents the hardware architecture of the authentication device of [Fig.l], in a particular embodiment of the present invention. Description of embodiments
[0043] With reference to [Fig.l], a system SYS for authenticating the identity or quality of a user is illustrated, in a particular embodiment.
[0044] The system SYS of FIG. 1 comprises a terminal TER associated with a user UT and an authentication device AUT associated with an identity provider FI. The authentication device AUT is configured to certify one or more identity elements aH ..., an of the user UT. Such identity elements may for example be of the sovereign type (surname, first name, date of birth, etc.). Such identity elements may also relate to the quality of the user UT (majority, seniority, diplomas, etc.). Such identity elements belong to a set E of at least two identity elements, which set E is stored in a secure storage module MSS1 of the terminal TER, such as for example an SE (“Secure Element” in English), an HSM (“Hardware Security Module” in English), a TEE (“Trusted Execution Environment” in English), etc.In the embodiment described here, the terminal TER comprises a communication module C0M1 which can be used to send to the authentication device AUT one or more identity elements aP • • • ' selected in advance by the user UT and receive, from the authentication device AUT, a signed certificate CS relating to the selected identity element(s). It is recalled that such a signed certificate or accreditation is a personal attestation allowing a user to convince a third party that he has a particular authorization or qualification. It is specific to . an individual and generated by a trusted entity, referred to as FI in the description, through the use of digital signatures. However, standard digital signature mechanisms require revealing the entirety of the certified data, even to prove the authenticity of only part of it, and allow users to be traced.
[0045] In the present description, an anonymous accreditation mechanism is used as introduced by Chaum (David Chaum: Showing Credentials Without Identification: Signatures Transferred Between Unconditionally Unlinkable Pseudonyms. EUROCRYPT 1985: 241-244). Such a system allows a user to prove that his identity elements have been certified, without revealing superfluous information.
[0046] The C0M1 module can also be used to send to a service provider (not shown) an access token or verifiable presentation VP derived from the signed certificate CS, during an access phase of the user UT to the service provider, to prove to the service provider that the user UT meets the conditions for access to the service. In the case, for example, where the service provider is an online betting site and therefore requires a certificate of majority, the verifiable presentation VP will constitute proof that the user UT does indeed hold a driving license.
[0047] In the embodiment described here, the terminal TER comprises a module MAUT1 for authenticating the user UT with the authentication device AUT.
[0048] In the embodiment described, the terminal TER comprises a cryptographic module MCRY1, for example an electronic identity wallet configured to store at least one signed certificate CS issued by an identity provider FI associated with the authentication device AUT and to generate a verifiable presentation VP to be presented to a service provider to access a service, while protecting the confidentiality of its identity elements a”.
[0049] The verifiable presentation VP includes a signed certificate CS' calculated by the terminal TER by refreshing the signed certificate CS.
[0050] In the embodiment described here, the TER terminal comprises a user interface UI of voice type, for example a microphone, or of text type, for example a keyboard, which is configured to receive the identity element(s) ..., an which has C( / Or on( respectively selected by the user UT.
[0051] In the embodiment described here, the authentication device AUT comprises a communication module COM2. This module can in particular be used by the authentication device AUT to obtain the identity element(s) ai' ..., selected by the user UT for the authentication of his identity or his quality, and send to the terminal TER a signed certificate CS relating to ... the selected identity elements.
[0052] In the embodiment described here, the authentication device AUT comprises a cryptographic module MCRY2. This module can in particular be used to authenticate a user UT, generate and verify the validity of a signed certificate CS relating to one or more identity elements ai • • • ' ün, and calculate proofs demonstrating for example that the signed certificate CS produced is valid.
[0053] In the embodiment described here, the authentication device AUT comprises a secure storage module MSS2, in which the set E of identity elements ai a” of the user UT is recorded. Thus, prior to the implementation of the method for authenticating the identity or the quality of the user UT, the identity elements ai' • • • ' a” of the user UT are available at the authentication device AUT and known to the latter.
[0054] [Fig.2] represents in the form of a flowchart the main steps of a method for obtaining authentication of the identity or quality of a user, implemented by the TER terminal.
[0055] In this example, the user UT uses his terminal TER to request the authentication device AUT associated with an identity provider FI to provide him with a signed certificate CS relating to at least one identity element a> selected by the user UT in the set E of identity elements a„ (l <i<n).
[0056] During a step Ul, a secure communication ch is established between the terminal TER and the authentication device AUT. During this communication, the terminal TER sends to the authentication device AUT a request RAut for authentication of the user UT. Such a request RAUT may comprise a public key PKV of the user UT or a pair of public and private keys (PKlj, sklf) of the user UT.
[0057] In the embodiment described here, when the authentication of the user UT succeeds, during a step U2, the terminal TER receives, via the user interface IU, a selection of at least one identity element ai that the user UT wishes to certify by the authentication device AUT.
[0058] During a step U3, the terminal TER calculates a cryptographic message MG which indicates to the authentication device, in a manner not identifiable by the latter, said at least one identity element ai which has been selected, as well as said identity elements ai+b an which have not been selected by the user UT for certification.
[0059] During a step U4, the terminal TER sends said cryptographic message Mu to the authentication device AUT.
[0060] During a step U5, the terminal TER receives, from the authentication device AUT, a signed certificate CS which blindly certifies the validity of said at least one identity element ai. The particular structure of this signed certificate, which certifies a subset of identity elements, here {ai}, whose cardinality is less than the set E of identity elements, thus advantageously allows the TER terminal to derive, from the received signed certificate, an access token from a product and / or service provider who would only need to verify the validity of this identity element ai. Given that the number of identity elements selected by the user is less than the number of identity elements available both in the TER terminal and in the AUT authentication device, the calculation times for deriving the access token in the TER terminal are reduced by a linear factor which is a function of the number of identity elements selected by the user to be certified.
[0061] In the embodiment described here, the terminal TER is configured to refresh the signed certificate, via the cryptographic module MCRY1, and send the refreshed signed certificate CS' to a service provider (not shown) in a verifiable presentation, along with the identity element ai requested by this service provider.
[0062] [Fig. 3] represents in flowchart form details of the method of obtaining authentication of the identity or quality of a user as described with reference to [Fig. 2].
[0063] In the embodiment described here, the selection U2 of at least one identity element ai comprises:
[0064] - setting to a first value V1 equal to 1, a bit b; associated with said at least one ai identity element that was selected;
[0065] - setting to a second value V2 equal to 0, a bit bi associated with said element identity ai that has not been selected;
[0066] -...;
[0067] - setting to the second value V2 equal to 0, a bit bu associated with said element ai-i identity that was not selected;
[0068] - setting to the second value V2 equal to 0, a bit bi+i associated with said element identity ai+i which has not been selected;
[0069] -...;
[0070] - setting to the second value V2 equal to 0, a bit bn associated with said element identity a>< which was not selected.
[0071] In another exemplary embodiment, Vl=0 and V2=1.
[0072] In the embodiment described here, the calculation U3 of the cryptographic message Mu implements in U30 the calculation of a commitment or pledge C on the value of each of the bits bi to bn. This commitment C includes:
[0073] - a commitment Cisur the content of the second value V2 of bi;
[0074] - a commitment C2 on the content of the second value V2 of b2;
[0075] ;
[0076] - a commitment Cj on the content of the first value VI of b; ;
[0077]
[0078] - a commitment Cn on the content of the second value V2 of bn.
[0079] The pledging of a value is a cryptographic process known to those skilled in the art. profession that allows an issuer to commit to a value to a recipient without revealing it at first and in such a way that this commitment cannot be modified later. This value can, if necessary, be revealed subsequently by the issuer.
[0080] Thus, the recipient has the assurance that once the commitment is published, the issuer can no longer change his mind about the value contained in this commitment.
[0081] In a particular embodiment, the present disclosure may use the pledging scheme proposed by Pedersen in 1992 (Torben P. Pedersen. Non-interactive and information-theoretic secure verifiable secret sharing. In Joan Feigenbaum, editor, CRYPTO'91, volume 576 of LNCS, pages 129-140. Springer, Heidelberg, August 1992), which has the particularity of producing perfectly indistinguishable commitments (perfectly hiding in English).
[0082] In the embodiment described here, the calculation U3 of the cryptographic message Mu implements in U31 the calculation of a proof H allowing the user UT to demonstrate to the identity provider FI that he knows how to reveal the n pledges Ct and that the pledged values are either 0 or 1. In a particular embodiment, the proof H is a so-called zero-knowledge proof (ZKP) and comprises:
[0083] - proof of pledge;
[0084] - proof Æ2 on pledge C2;
[0085] -...;
[0086] - proof 71 i on the pledge C, ;
[0087] -...;
[0088] - proof on the pledge Cn
[0089] It is recalled that a proof of knowledge known as zero knowledge disclosure allows a verifier to convince himself that a certain prover knows a secret S satisfying a given predicate P, the proof revealing to the verifier no information about the secret S in question except the fact that it verifies the given predicate P. Subsequently, to represent zero-knowledge proofs, we will sometimes use the usual notation PoK {and, P, ... : predicate on a, p, ...}. In the embodiment described here, the message Mu sent in U4 contains the commitment C and the proof H.
[0090] [Fig.4] represents in the form of a flowchart the main steps of a method for generating an authentication of the identity or quality of a user, implemented by the authentication device AUT. According to such a method, an identity provider FI is capable of certifying one or more identity elements that the user UT wishes to certify, without being able to identify which identity element or identity elements it is.
[0091] During a step II, the authentication device AUT generates a secure communication ch with the terminal TER, for example by using a random number which avoids replay.
[0092] During a step 12, the authentication device AUT receives an authentication request RAUT from the terminal TER asking the authentication device AUT to authenticate the user UT.
[0093] During a step 13, the authentication device AUT authenticates the user UT.
[0094] If the authentication fails (N in [Fig.4]), the method of generating an authentication of the identity or quality of the user UT stops.
[0095] If the authentication is successful (O in Figure 4), during a step 14, the authentication device AUT receives the cryptographic message Mu from the terminal TER. According to the invention, the message Mu indicates to the authentication device, in a manner not identifiable by the latter, said at least one identity element ai which has been selected, as well as said identity elements ai+b^which were not selected by the UT user for certification.
[0096] During a step 15, the authentication device AUT calculates a signed certificate CS which certifies the validity of said at least one identity element ^ / which has been selected. According to the invention, the signature used to obtain the signed certificate is a blind or partially blind signature A.
[0097] It is recalled that a blind signature is a security mechanism used in cryptography to allow a party to sign a message without knowing the content of this message so that the confidentiality of the message is preserved. In such a mechanism, the party wishing to obtain a blind signature combines the message to be signed with a randomly generated blinding factor and sends the result of this combination to the signer. The signer signs the message without knowing its actual content, and sends the resulting signature to the requester. The requester can use the blinding factor to "unblind" the signature, i.e. to cancel the effect of the blinding factor and obtain the signature of the original message.
[0098] In the embodiment described herein, the blind signature A is calculated using the BBS / BBS+ signature scheme.
[0099] During a step 16, the authentication device AUT sends the signed certificate CS to the terminal TER.
[0100] In the embodiments described above with reference to Figures 2 to 5, at least one identity element ai has been selected by the user UT. It goes without saying that more than one identity element can be selected from the set E of identity elements.
[0101] [Fig.5] represents in flowchart form details of the method of generating an authentication of the identity or quality of a user, as described with reference to [Fig.4].
[0102] In the embodiment described here, the MG message received at 14 contains:
[0103] - the commitment or pledge C on the value of each of the bits bi to bn,
[0104] - proof II allowing the user UT to demonstrate to the identity provider FI that he knows how to reveal the n pledges Q and that the pledged values are worth either 0 or 1.
[0105]
[0106]
[0107]
[0108]
[0109]
[0110] [YES]
[0112] In the embodiment described here, the method for generating an authentication of the identity or quality of the user UT comprises a step 140, during which the authentication device AUT verifies the validity of the proof II. If the result of the check is negative (N in [Fig.5]), the process stops. If the verification result is positive (O in Figure 5), the authentication device calculates the signed certificate CS from the commitment C contained in the message Mu. [Fig.6] represents in the form of a flow diagram the main exchanges established between the TER terminal and the AUT authentication device, in a particular embodiment of an authentication of the identity or the quality of a UT user, which implements the BBS+ blind signature protocol cited above. It is assumed that prior to the implementation of the exchanges between the TER terminal and the AUT authentication device: - the identity provider FI randomly generated an integer ski belonging to {1, 2, ..., P, where P is a prime integer, and calculated _ ^1, where h is any generator of a cyclic group G of prime order P. The public and private keys of the identity provider FI are respectively PKj and sk1; - the TER terminal associated with the user UT also stores a pair of keys, public and private, certified by a suitable certification authority: (PKu, skv — ^kr; ), where P is any generator of a cyclic group G of prime order P. It is further assumed that the discrete logarithm of h in base S is unknown. We denote by E= (ai' • • • ' a") the set of identity elements of the user UT, and ®, the list of indices of the identity elements that the user wishes to authenticate / certify by the FI identity provider.
[0113] During a step SI, a secure communication ch is established between the terminal TER and the authentication device AUT, for example via the sending, by the authentication device AUT, to the terminal TER, of a challenge ch.
[0114] During a step S2, the authentication device AUT carries out an authentication of the user UT. For this purpose, the terminal TER sends an authentication request RAUT to the authentication device AUT using for example the public key PKV.
[0115] If the authentication fails, the process of authenticating the identity or quality of the UT user stops.
[0116] If the authentication is successful, during a step S3, the user UT selects at least one identity element aî from the set of identity elements E= (^i' a«), for example the three elements For this purpose, S = {2, 5, 7}.
[0117] During a step S4, the terminal TER calculates, for each generator for ze {1, ..., n}, a commitment C on a bit bj (where bj = 1 if z £ ® and 0 otherwise), such that C^ = ghigr' where f J Zp, °ù Ki is a random value chosen by the user UT, between 0 and p-1, and Zp is the set {1, 2,..., Pl}. According to the invention, each ! ] n is associated with a specific type of identity element: for example is associated with the “name” attribute, S2 with the “first name” attribute, S3 with the “age” attribute, *4 with the “gender” attribute, etc.
[0118] During step S4, the terminal TER calculates a commitment Com on a secret value üq known only to the user UT, such that Com = gfygr° This commitment Com constitutes a secret attribute, because the user UT does not wish to reveal 4
[0119] In the embodiment described herein, the commitments Ci and Coin are generated with the Pedersen pledging scheme mentioned above.
[0120] During a step S5, the terminal TER calculates, for each ig {1, ..., n], a proof ZK, noted ^i, that the value pledged in C, is worth either "0" or "1". This type of proof, known as "OR proof" in the literature, is for example described in the document Ronald Cramer, Ivan Damgârd, Berry Schoenmakers: Proofs of Partial Knowledge and Simplified Design of Witness Hiding Protocols. CRYPTO 1994: 174-187.
[0121] Such a proof is written as follows: ni= PoK a\c / ~^ay C:-ga .. g ôn+i 1 ôn+[
[0122] During step S5, the terminal TER also calculates a proof demonstrating that it knows how to reveal the secret value d^. The proof is written as follows: next: ^-PoK^. Com = ^}
[0123] During a step S6, the terminal TER transmits to the identity provider FI the following elements {G, Com, TTy
[0124] During a step S7, the authentication device AUT verifies the validity of the evidence (l <i<n) et si l’une de ces preuves n’est pas valide, il est mis fin au procédé d’authentification l’identité ou la qualité l’utilisateur ut.
[0125] If all these proofs are valid, during a step S8, the authentication device AUT calculates a partially blind signature BBS+, noted (A, r), with its private key skh such that: / ..T-rn AWd.WHERE:
[0126] - dÿ and r are values randomly chosen by the authentication device AUT in Zp, and where
[0127] - üq is such that + d® (modpp ao being a secret attribute known only to the UT user, for example his PKV private key.
[0128] Such a signature (A, r) has the advantage of only relating to the attribute ao (where a0 — üq 4- Üq (modp)) and the identity elements of the user UT, whose indices belong to ®, where ® ={ 2, 5, 7] in the above-mentioned example.
[0129] The value of the ao attribute is intended to remain secret. It can be used by the user UT to prove that the signature (A, r) received from the authentication device is indeed his property.
[0130] During a step S9, the authentication device AUT transmits the signature (A, r) to the terminal TER.
[0131] During a step S10, the terminal TER checks the validity of the signature (A, r) as well as üq in accordance with the partially blind signature protocol BBS+. If the signature (A, r) is not valid, the partially blind signature protocol BBS+ is terminated. Otherwise, during a step SU, the terminal TER records the signature (A, r) in its module MCRY1 ([Fig. 1]).
[0132] The signature (A, r) thus recorded certifies only the identity elements selected by the user UT, the storage resources of the TER terminal are advantageously preserved. In addition, when the TER terminal will be required to derive this signature to allow access of the TER terminal to a service provider, the costs in calculations monopolized for the derivation will be advantageously reduced. In addition to these advantages, it is recalled that the identity elements on which the signature relates (A, r) are advantageously not identifiable by the FI identity provider thanks to the exchanges which have just been described above. The FI identity provider will therefore have no information on the use which will be made of the token derived from this signature, during access from the TER terminal to a service provider which would only require these identity elements. In particular, if the UT user has only requested a “certificate of majority” from the identity provider, the latter will ignore it.
[0133] In the embodiment which has been described in relation to FIG. 6, it has been shown that the terminal TER and the authentication device AUT each share a part of a secret attribute ao. The terminal TER holds the part a'® as well as the part and the authentication device AUT, that the part üq. Such a functionality advantageously allows the user UT to have no control over his secret attribute, thus preventing malicious users from using the same secret attribute as that of the user UT, which could be the case if for example one of these users imposes such a secret attribute on the user UT.
[0134] This functionality is of course not essential, the UT user being able to choose in S4 a secret attribute known only to him.
[0135] For this purpose, the commitment Com calculated in S4 would be such that Coin =
[0136] The signature (A, r) calculated during step S8 by the authentication device AUT would then be such that: A = (gComf^C^}
[0137] The TER terminal described above can be implemented by an ORD0 computer whose hardware architecture is shown in [Fig.7].
[0138] This ORD0 computer includes in particular a PO processor, a MV0 RAM, a MM0 ROM and MCO communication means.
[0139] The read-only memory MM0 constitutes a recording medium within the meaning of the invention. It comprises a computer program PG-T in accordance with the invention. This computer program PG-T is a program comprising instructions for executing the steps of a method for obtaining authentication of the identity or quality of a user UT as described previously with reference to Figures 2, 3 and 6. The program PG-T defines in particular the communication modules C0M1, authentication MAUT1, cryptographic calculation MCRY1, and secure storage MSS1 of the terminal TER.
[0140] The authentication device AUT described above can be implemented by a computer ORD1 whose hardware architecture is shown in [Fig.8].
[0141] This ORD1 computer includes in particular a PI processor, a MV1 RAM, a MM1 ROM and MCI communication means.
[0142] The MM1 read-only memory constitutes a recording medium within the meaning of the invention. It comprises a computer program PG-A in accordance with the invention. This computer program PG-A is a program comprising instructions for executing the steps of a method for generating an authentication of the identity or quality of a user UT as described previously with reference to Figures 4 to 6. The program PG-A defines in particular the communication modules COM2, authentication and cryptographic calculation MAUT2, cryptographic calculation MCRY1, and secure storage MSS2 of the authentication device AUT.
Claims
Claims
1. Method for obtaining authentication of the identity or quality of a user from an authentication device, associated with an identity provider, which comprises a set of at least two identity elements of said user, said identity elements being stored in a terminal associated with the user and being known to the authentication device, said method comprising the following in said terminal: - authentication (Ul) of the user (UT) with the authentication device using a secure communication (ch) established between the terminal and the authentication device, - selection (U2), using a user interface of the terminal, of at least one identity element to be certified in said set, - sending (U3) a message to the authentication device, said message indicating, in a manner not identifiable by the authentication device,said selected identity element and said identity element remaining in said set, not selected, - reception (U4) from the authentication device of a certificate signed using a blind signature, said certificate certifying the validity of said selected identity element.,
2. A method of obtaining authentication according to claim 1, wherein said selected identity element is associated (U20) with a first value (VI) and said non-selected identity element is associated (U20) with a second value (V2), said message containing a commitment on the first value and on the second value.
3. A method of obtaining authentication according to claim 2, wherein the first value and the second value are 1 and 0 respectively.
4. Method for obtaining an authentication according to claim 3, further comprising: - a calculation (U31) of a proof (II) that the first value and the second value pledged are respectively 1 and 0, - a sending (U3) of said proof (II) to said authentication device.
5. A computer program comprising program code instructions for implementing the method of obtaining authentication according to any one of claims 1 to 4, when executed on a computer.
6. A computer-readable recording medium on which is en- registered a computer program according to claim 5.
7. Terminal (TER) configured to obtain authentication of the identity or quality of a user from an authentication device, associated with an identity provider, which comprises a set of at least two identity elements of said user, said identity elements being stored in said terminal and being known to the authentication device, said terminal being further configured to: - authenticate a user (UT) associated with said terminal, with the authentication device, using a secure communication established between the terminal and the authentication device, - select, using a user interface of the terminal, at least one identity element to be certified in said set, - send a message to the authentication device, said message indicating, in a manner not identifiable by the authentication device,said selected identity element and said identity element remaining in said set, not selected, - receive from the authentication device a certificate signed using a blind signature, said certificate certifying the validity of said selected identity element.,
8. Method for generating an authentication of the identity or quality of a user with an authentication device, associated with an identity provider, which comprises a set of at least two identity elements of said user, said identity elements being stored in a terminal associated with the user and being known to the authentication device, said method comprising the following in the authentication device: - obtaining (12) an authentication of the user (UT) using a secure communication (ch) established between a terminal associated with the user and the authentication device, - receiving (14) a message from said terminal, the message indicating, in a manner not identifiable by the authentication device, at least one identity element to be certified selected from said set and said identity element remaining in said set, not selected,- calculation (15) of a certificate signed using a blind signature, said certificate certifying the validity of said selected identity element, - sending (16) to the terminal of said signed certificate.,
9. A method of generating an authentication according to claim 8, wherein the signed certificate is calculated from a commitment contained in said received message, said commitment relating to a first value associated with the selected identity element and to a second value associated with said non-selected identity element.
10. A method of generating an authentication according to claim 9, wherein the first value and the second value are 1 and 0 respectively.
11. Method for generating an authentication according to claim 10, further comprising: - a reception (14), from said terminal, of proof (II) that the first value and the second value pledged are respectively 1 and 0, - a verification (140) of said proof received.
12. A computer program comprising program code instructions for implementing the method of generating an authentication according to any one of claims 8 to 11, when executed on a computer.
13. A computer-readable recording medium having recorded thereon a computer program according to claim 12.
14. Authentication device (AUT) configured to generate an authentication of the identity or quality of a user, said device comprising a set of at least two identity elements of said user, said identity elements being stored in a terminal associated with the user and being known to the authentication device, said authentication device being configured to: - obtain an authentication of the user (UT) using a secure communication (ch) established between a terminal associated with the user and the authentication device, - receive a message from said terminal, the message indicating, in a manner not identifiable by the authentication device, at least one identity element to be certified, selected from said set, and said identity element remaining in said set, not selected, - calculate a signed certificate using a blind signature,said certificate certifying the validity of said selected identity element, - send said signed certificate to the terminal.,
Citation Information
Patent Citations
Controlled-content recoverable blinded certificates
US20050066164A1