Method and apparatus for generating authenticated user data - Patents.com

JP2025504403A5Pending Publication Date: 2026-03-26SW7 VENTURES (H K) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-01-04
Publication Date
2026-03-26

Smart Images

  • Figure 00000023_0000
    Figure 00000023_0000
  • Figure 00000023_0001
    Figure 00000023_0001
  • Figure 00000024_0000
    Figure 00000024_0000
Patent Text Reader

Abstract

Disclosed herein is a computer-implemented method for providing an authenticated credential that is modified upon generation of certified user data. Also disclosed is a computer-implemented method for enabling characterization of an unknown user from the certified user data, and a method for characterizing an unknown user from the certified user data. The generation of the certified user data avoids the risk of personal information leaking into the digital realm, except where an unknown user is required to be characterized or identified.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention is generally in the field of information security, and more particularly, to a method for generating authenticated user data that cannot be associated with a specific user without the cooperation of a trusted system. [Background technology]

[0002] Many people have one or more digital identities in addition to their official / legal identity, and many digital platforms only require a digital identity, which may be unique to the platform, in order for a person to operate on that platform. In many contexts, the digital identity is a customer account or "login" that enables interaction with the digital platform.

[0003] In some scenarios, e.g., obtaining a license to drive a car or interact with a tax authority, it is necessary to ensure that an individual's public identity, or at least their personal information, is verified before assigning a digital identity. For example, a digital ID for accessing a government platform is only provided after proof of identity. In some other scenarios, interacting with a second entity depends on a prior verification made by a first entity, e.g., a bank implicitly relies on a prior verification of an individual's public identity when an individual submits a passport to open an account. In these scenarios, a first entity (e.g., a government agency) may collude with a second entity (e.g., a bank) to track a user's actions on the second entity's digital platform.

[0004] The use of digital identities without the verification of the underlying public and personal information can lead to anonymity that is socially or legally unacceptable. For example, trolling, deliberate misinformation, and abuse in online media can occur with ultimate impunity because the responsible individuals cannot be identified. Alternatively, without verification, identities can be "spoofed," potentially leading to fraudulent activity.

[0005] It has long been agreed that in some scenarios, for example obtaining a license to drive a car or interact with tax authorities, there is a need to ensure that an individual's public identity is verified before assigning a digital identity. Many digital platforms are realizing that the need for a verified identity, or at least some verified personal information, also applies to their own services in order to remain compliant with regulations or to improve user experience.

[0006] However, there are important privacy implications of verifying an individual's public identity and / or personal information. If the process of verifying and storing a public identity or personal information exposes or stores a link between a pseudonym and that public identity, the privacy protections of such pseudonymization may be compromised or vulnerable to abuse, since the verifying / certifying entity knows the link between the digital identity and the official identity / personal information. Moreover, repositories of such links are natural targets of attack by malicious entities, such as hackers, and if compromised, the link between the pseudonym and the corresponding public identity / personal information may be obtained.

[0007] Thus, there is a need for a secure method that provides the benefits of identity verification while maintaining the privacy properties of pseudonyms in a way that avoids the underlying increased risk of personal and identifying information being leaked in the digital realm. Summary of the Invention

[0008] According to a first aspect of the present invention, there is provided a computer implemented method for providing an authenticated certificate that is modified upon generation of certified user data, the method comprising: verifying user data, the user data including personal information of the user; Associating the verified user data with a first data set; creating an authenticated certificate that is modified upon generation of the certified user data, the authenticated certificate including a modifiable portion that includes a representation of the first data set; providing an authenticated certificate for generation of authenticated user data; wherein the mutable portion is mutable such that, when modified, the authenticated certificate is not associated with the verified user data.

[0009] In some embodiments, the first data set includes one or more of a token, a database reference, or a serial number.

[0010] In some embodiments, the method further includes encrypting the first data set to form an encrypted first data set, the encrypted first data set forming a representation of the first data set.

[0011] In some embodiments, the mutable portion of the created authenticated certificate includes an identifier of the entity creating the authenticated certificate, and optionally, the identifier includes a signature signed using the entity's private key.

[0012] In some embodiments, the alterable portion comprises a re-randomizable portion.

[0013] In some embodiments, the method further includes storing an association between the first data set and the verified user data.

[0014] In some embodiments, the encryption step is performed using the trustee system's public key.

[0015] In some embodiments, the method further includes modifying a modifiable portion of the authenticated certificate to generate certified user data.

[0016] In some embodiments, the method further includes storing auxiliary data, the auxiliary data including an association between the verified user data and an encrypted version of the representation of the certified user data, and optionally, the encryption to create the encrypted version of the representation of the certified user data is performed using a public key of the trustee system.

[0017] In some embodiments, the personal information includes identifying information.

[0018] In some embodiments, the authenticated user data includes the user's cryptographic key.

[0019] According to a second aspect of the present invention there is provided a computer implemented method for enabling characterisation of an unknown user from attested user data, the attested user data comprising a mutable portion of an authenticated certificate, the mutable portion comprising an encrypted first data set, the authenticated certificate further comprising an identifier of an associated entity, the first data set being associated with user data verified by the associated entity prior to the modification of the portion, the verified user data comprising personal information of the unknown user, the method comprising: receiving a request from a requester, the request including an indication of authenticated user data; decrypting the encrypted first data set of the alterable portion of the certified user data to provide the first data set; providing a requester with a first data set associated with the verified user data to enable characterization of the unknown user data; Includes.

[0020] In some embodiments, the identifier of the associated entity includes one or more of: (i) a signature signed using the private key of the associated entity, optionally included in the modified portion; and (ii) a public key of the associated entity included in the authenticated certificate, optionally included in the unaltered portion of the authenticated certificate.

[0021] In some embodiments, the first data set includes one or more of a token, a database reference, or a serial number. In similar or other embodiments, the method is performed by a custody system and the first data set is encrypted using a public key of the custody system.

[0022] In some embodiments, the altered portion is a re-randomized portion, and the alteration is a re-randomization.

[0023] In some embodiments, the method further includes granting a request from the requester to enable characterization of the unknown user. In some such embodiments, the method is performed by a plurality of custody systems, and the step of decrypting the encrypted first data set of the modified portion of the attested user data occurs if a number of custody systems in the plurality of custody systems granting the request meets a threshold.

[0024] In some embodiments, the method further comprises checking the authenticity of the identifier of the associated entity.

[0025] In some embodiments, the association of the first data set with the verified user data occurs prior to encryption of the first data set.

[0026] In some embodiments the personal information is identification information and the method is a method that allows for identifying unknown data from authenticated user data.

[0027] According to a third aspect of the present invention there is provided a computer implemented method for characterising an unknown user from attested user data, the attested user data comprising an altered portion of an authenticated certificate, the altered portion comprising an encrypted first set of data, the authenticated certificate further comprising an identifier of an associated entity, the first set of data being associated with user data verified by the associated entity prior to alteration of the portion, the verified user data comprising personal information of the unknown user, the method comprising: providing a representation of the authenticated user data to one or more trusted systems; receiving a first data set from one or more depository systems; providing a first data set to an associated entity; receiving verified user data from an associated entity, the verified user data including personal information of the unknown user; Includes.

[0028] In some embodiments, the identifier of the associated entity includes one or more of a signature signed using the private key of the associated entity, optionally included in the modified portion, and a public key of the associated entity included in the authenticated certificate, optionally included in the unaltered portion of the certified certificate.

[0029] In some embodiments, the first data set includes one or more of a token, a database reference, or a serial number.

[0030] In some embodiments, the altered portion is a re-randomized portion, and the alteration is a re-randomization.

[0031] In some embodiments, the method further includes at least one of: disclosing personal information of the unknown user; storing personal information of the unknown user; sanctioning or prosecuting the user; selecting second attested user data, where the selection of the second attested user data is based on personal information of the first attested user data; and adding the user's personal information to a blacklist.

[0032] In some embodiments, the association of the verified user data with the first data set occurs prior to encryption of the first data set.

[0033] In some embodiments, the personal information includes identification information and the method is a method of identifying an unknown user from authenticated user data.

[0034] According to a fourth aspect of the invention, there is a method comprising a step of the first aspect or one of its embodiments and a step of the second aspect or one of its embodiments, or a method comprising the first aspect or one of its embodiments and a step of the third aspect or one of its embodiments, or a method comprising a step of the second aspect or one of its embodiments and a step of the third aspect or one of its embodiments, or a method comprising a step of the first aspect or one of its embodiments and a step of the third aspect or one of its embodiments.

[0035] According to a fifth aspect of the present invention there is provided a computer program product comprising instructions which, when executed, cause one or more processors to perform the method of one of the above aspects.

[0036] According to a sixth aspect of the present invention, there is a computer readable medium comprising instructions that, when executed, cause one or more processors to perform the method of one of the above aspects.

[0037] According to a seventh aspect of the invention, there are one or more processors configured to carry out the method of one of the above aspects. [Brief description of the drawings]

[0038] [Figure 1] FIG. 1 is a block diagram of the architecture of a system capable of implementing a method for providing a certified certificate that is modified upon generation of certified user data. [Diagram 2] 2 is a block diagram of certified user data that may be generated by the system of FIG. 1. [Diagram 3] FIG. 2 is a flow diagram of a method for providing an authenticated credential that has been modified in the generation of certified user data, and a method for modification of the authenticated credential. [Figure 4] 1 is a block diagram of an architecture of a system for characterizing unknown users from authenticated user data and enabling characterization of unknown users; DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0039] The following detailed disclosure outlines the features of specific embodiments of the present invention. In addition, some (but by no means all) variations of the specific embodiments that can be implemented while remaining within the scope of the present invention are also described. The following description is divided into sections to aid the understanding of the subject matter of those skilled in the art, but the specific substructures of the detailed description should not be considered as limiting individual embodiments of the present invention. On the contrary, the features of the various sections can be combined as appropriate.

[0040] To understand the principles of the present invention as outlined below, reference should be made to the features shown in each of Figures 1-4, although the present invention is defined solely by the appended claims.

[0041] As used herein, the term "personal information" refers to information that can characterize an individual. For example, personal information can be an individual's place of residence or nationality. Alternatively, personal information can be details of accounts such as social media accounts (e.g., Facebook or Twitter) or public identifiers such as a pen name of an author. Alternatively, personal information can be an IP address associated with an individual's device. In some examples, personal information can be identification information that allows the public identity of a natural or legal person to be identified. For natural persons, examples of identification information include a passport, a driver's license, or a birth certificate. For legal entities such as companies or trusts, identification information can be in physical or digital form (such as a scan or photo of the original document), but in each case, an official document of the natural / legal person can allow the identification.

[0042] As used herein, the term "characterizing" refers to the determination of previously unknown personal information about a user, but does not necessarily allow the user's public / legal identity to be revealed. For example, a user's nationality or place of residence is information that characterizes a user when such information was previously unknown. However, knowledge of a user's nationality is personal information about a user, even though it does not allow the user's public identity to be determined. Similarly, a user may be characterized by being an employee of a company or organization, which is personal and potentially private information about the user, but does not allow the individual's public identity to be determined.

[0043] As used herein, the term "private information" refers to information contained in personal information and may be included in identity information. For example, if personal information includes identity information, the identity information may include a photograph of a natural person, and the private information may be any biometric information that can be extracted from the photograph. Alternatively, if identity information includes an address, such an address may also be private information. However, private information may also be captured within personal information that is not identity information, such as an individual's place of residence or legal domicile for tax purposes. Such information is private in the sense that it should not be disseminated beyond a need-to-know basis, but does not necessarily make it possible to determine an individual's legal / official identity.

[0044] As used herein, the term "associating" two or more entities / objects refers to the establishment of a link between two or more unrelated entities / objects such that, as a result of the association, one of the first entities / objects may be recognized as having a connection or relationship to one of the second entities / objects.

[0045] As used herein, an "authenticated certificate" refers to data produced by a digital identity provider that indicates that a user's personal information has been successfully verified and that verified user data has been created. An authenticated certificate is data that has been certified by a competent authority and includes alterable and, in some cases, immutable portions. The authenticated certificate, or portions thereof, are linked to the user's personal information via the verified user data, and the presence of the authenticated certificate indicates successful completion of the verification. The digital identity provider responsible for creating the authenticated certificate associates the certificate, or portions thereof, with the verified user data.

[0046] As used herein, "certified user data" refers to user data that represents successful completion of a validation process by a competent authority and the creation of an authenticated certificate. However, certified user data contrasts with authenticated certificates in that the digital identity provider responsible for creating the authenticated identity cannot associate the certified user data, or any portion thereof, with the verified user data without the cooperation of a trusted system.

[0047] The methods and system architectures described herein may be executed on any device incorporating a processor, such as a computer, a mobile phone, a tablet, a PDA, a local network, a cloud network, etc. The processor may execute instructions stored in associated memory to perform the steps described. The processor may include more than one core and / or run on a virtual machine. In some cases, the processor may be a set of processors in a distributed computing system, such as a network of computers. When distributed, parts or the entire method may be executed on different processors, cores, or networks.

[0048] Providing a digital certificate 1 shows a high level block diagram of a system architecture on which a computer-implemented method according to the present invention can be implemented. In a first step of the method, a user 100 submits personal information 150 to a digital identity provider 200. The personal information may be, for example, the user's driver's license. Because the driver's license contains personal information that allows the user's place of residence to be determined from the address, the license is private information that should be shared only on a need-to-know basis. Furthermore, because the license also allows the user 100 to be identified via the user's name, date of birth, and address (i.e., this allows the user's public identity to be determined), the driver's license also contains identifying information, including private information that should be shared only on a need-to-know basis.

[0049] The personal information 150 may take the form of an original copy of the user's driver's license or a previously certified copy of the user's driver's license (e.g., sent by registered mail or postal mail to the digital identity provider 200). Alternatively, the personal information 150 sent to the digital identity provider 200 may itself be a digital copy of the driver's license, such as a scan or photograph of the original document, or other data embedded with information present on the driver's license, such as the user's name and address.

[0050] 1, a digital identity provider 200 is an entity that has the ability to verify the authenticity of personal information 150 provided by a user 100 and issue to that user an authenticated certificate 400 that confirms that the user has undergone a verification process. The issuance of the certificate to the user (though not the contents of the authenticated certificate 400) is an indication to third parties that the personal information of the user 100 has been verified by the digital identity provider 200. An example of such a process is when a user identifies themselves to a tax office, or when a customer identifies themselves to a bank and uses their driver's license to do so.

[0051] The steps taken by the digital identity provider 200 are shown in FIG. 3. Upon receipt of the personal information 150 from the user 100, the digital identity provider 200 verifies the authenticity of the personal information 150 (S1) and a digital copy of the information is securely stored in a database 210 accessible by the digital identity provider 200 (S2). If the personal information 150 is non-digital (e.g., an original driver's license mailed by registered mail), a digital copy of the personal information 150 may be created and stored in the database 210. Verification of the personal information 150 may be, for example, inspection of the driver's license for a holographic mark, official seal, or other authenticating feature to verify the authenticity of the driver's license. In a digital context, verification of the digital copy of the personal information 150 may be inspection of the digital copy for a digital signature signed by the private key of the user 100 or by another entity such as a public authority. As will be apparent to one skilled in the art, other means of verifying the personal information 150 may also be implemented. In either case, the digital identity provider verifies the personal information 150 of the user 100. If the personal information 150 includes identifying information, the digital identity provider 200 verifies the identity of the user 100.

[0052] Once a user's personal information is verified, the data including the personal information may be stored forming verified user data 220. The verified user data 220 is based on personal information 150 derived from user data 100 and has the quality of providing a link back to the user 100 who provided it, from which the personal information 150 of the user 100 may be derived. Additionally, any private information captured within the personal information 150 of the user 100 may be obtained by any entity verifying the user's verified data 220. In the driver's license example, the user's address is private information included in the personal information 150 and is correspondingly included in the verified user data 220.

[0053] As further shown in FIG. 3, once the verified user data 220 is stored, the digital identity provider 200 associates (S3) a first data set with the verified user data 220. The first data set may be a database reference to allow a particular entity in the database 210 to be retrieved. The first data set may be any token created (at the time or earlier) to act as a database reference. Alternatively, the first data set may be a modified form of the verified user data 220, such as a cryptographic function or hash of the verified user data 220, where the hash or cryptographic function acts as the database reference. In this example, the verified user data 220 is associated with a serial number 300. The association of the verified user data 220 with the serial number 300 may be stored in the database 210, as also shown in FIG. 1. If the digital identity provider 200 is responsible for verifying the identity of multiple users, the verified user data 220A, 220B, 220C of each user may be stored (not shown) along with an association corresponding to 300A, 300B, 300C, respectively. Storing the association allows the digital identity provider 200 in possession of the serial number 300 or the verified user data 220 to use the association to obtain the other of the serial number 300 or the verified user data 220. In this example, knowledge of the serial number 300 allows for the retrieval of personal information 150 contained in the user's driver's license via the verified user data 220. More generally, knowledge of the first data set allows for the retrieval of personal information.

[0054] In the illustrated example, the digital identity provider establishes an association between a first data set (e.g., serial number 300) and verified user data 220, although it is emphasized that the use of such a serial number is exemplary and that alternative database references or tokens may be used instead.

[0055] In the illustrated example, the digital identity provider 200 has knowledge of the association between the municipal number 300 and the verified user data 220. As a result, the digital identity provider 200 in principle has knowledge of the personal information 150 by virtue of the digital identity provider 200 being the entity responsible for establishing the association. However, the digital identity provider 200 should provide only enough information to demonstrate to interested parties that it has verified the personal information of the user 100 and has done so via the creation of an authenticated certificate 400. It is therefore desirable to remove the requirement to "trust" the digital identity provider 200 for the user 100 so as not to reveal the association between the verified user data 200 and the serial number 300. This is accomplished via modification of at least a portion of the verified certificate 400 in a manner described further below, such that when modified, the authenticated certificate 400 is no longer associated with the verified user data 200 via the serial number 300.

[0056] If the first data set (serial number 300) were included directly in the verified certificate 400, an entity verifying the authenticated certificate 400 could unambiguously obtain the associated verified user data 220 with the assistance of the digital identity provider 200. To prevent such a risk, the authenticated certificate 400 includes an indication of the first data set. The indication may be checked, for example, an address from which the first data set is retrieved / verified by an entity authorized to retrieve / verify the first data set, or security may be achieved, for example, using an encrypted or hashed form of the first data set. In this example, the first data set (serial number in FIG. 1) may be directly encrypted, for example with an asymmetric scheme such as ElGamal. The serial number 300 is encrypted to provide an encrypted serial number 300E as a ciphertext. The encryption may use the public key of the custodian system 600. The public key of the custodian system is used so that the custodian system 600 can decrypt the encrypted serial number 300E to reveal the original serial number 300 in certain circumstances, as described below.

[0057] Upon successful completion, the digital identity provider 200 provides the user 100 with an authenticated certificate 400 (S4) to provide evidence to the user 100 or a third party that the user 100 has successfully completed the verification process. The creation and provision of the authenticated certificate 400 confirms that the user 100 has successfully gone through the verification process.

[0058] It should be noted that although the storing of the verified user data 220, the association of the first data set with the verified user data 220, the creation of the certificate, and the encryption of the first data set are described as occurring in a particular order, this ordering of steps is merely exemplary, and other orderings of steps are possible, as one of ordinary skill in the art will recognize.

[0059] 1, the authenticated certificate 400 issued to the user 100 includes a mutable portion 410 that may be modified by the user 100, as described below. The mutable portion 410 includes a representation of a first data set, which in the illustrated example is an encrypted first data set. The encrypted first data set is a decryptable portion of the modified portion 410 of the authenticated certificate 400, and in the exemplary embodiment includes ciphertext representing the encrypted serial number 300E, encrypted with the public key of the trustee system 600. In this example, the mutable portion 410 also includes a digital signature 420 of the digital identity provider 200, signed using the public key of the digital identity provider.

[0060] In some cases, the authenticated certificate 400 may contain multiple mutable parts, each of which may contain one or more decodable parts (e.g., multiple encrypted token / database references), or a single mutable part may contain multiple decodable parts. In this example, the token / database reference (serial number 300) is encrypted with the public key of the trustee system 600, but in general, when there are multiple decodable parts, the decodable parts are decodable by different entities, such as different trustee systems. For example, one trustee system may be able to decode only a subset of the decodable parts of the authenticated certificate 400, while another trustee system may be required to decode other parts. In some cases, each decodable part requires a different trustee system.

[0061] In some cases, the authenticated certificate 400 also includes an immutable portion 415. This portion may contain metadata, public information, or other data that is not related to the serial number 300 and does not allow association of the authenticated certificate 400 (or any portion thereof) with the verified user data 220. In some cases, a copy of the digital identity provider's public key 430 is also provided within the immutable portion 415. The public key 430 allows a third party to verify the signature of the digital identity provider 200 responsible for creating the authenticated certificate 400.

[0062] While some or all of the contents of alterable portion 410 may be encrypted, hashed, or otherwise inaccessible to a third-party observer, one or both of (i) the provision of digital identity provider's public key 430 in immutable portion 415 and / or (ii) the formation of digital signature 420 as an alterable digital signature in alterable portion 410 indicate to a third-party observer that user 100 has undergone a verification process and, accordingly, the user's personal information has been verified. Either (i) or (ii) may provide the user's personal information (which may include identifying information) and may be revealed in certain circumstances, and may indicate that the digital identity provider participated in the verification process.

[0063] The authenticated certificate 400 is provided to the user (S4). The authenticated certificate 400 may be provided by sending it to the user via email, text message, or the like, but such a process brings its own security risks since the transmission may be intercepted. As a more secure alternative that avoids such risks, the digital identity provider 200 may provide the authenticated certificate 400 to the user 100 by providing the user 100 with a notice of where to look for the authenticated certificate. For example, the authenticated certificate 400 may be published on a private blockchain encrypted using the user's 100 public key, and a message may be sent to the user 100 informing the user 100 that the authenticated certificate 400 is available for use. Thus, the user 100 may freely access the authenticated certificate 400 using the user's private key. Other forms of distribution of the authenticated certificate 400 to the user 100 will be readily apparent to those skilled in the art.

[0064] 1, 2 and 3, at the time the authenticated certificate was created, the cryptogram of the serial number 300E was signed by the digital identity provider 200. Thus, verification of the authenticated certificate 400 reveals the encrypted serial number 300E contained therein, and the encryption of the serial number generally means that the serial number is not accessible by third parties. However, when provided with the serial number 300, the digital identity provider 200 can retrieve the associated verified user data 220 and, accordingly, obtain the personal information 150 and any private information contained therein. Because the association is stored in the database 210, the user 100 relies on the legitimate actions of the digital identity provider 200 to prevent the digital identity provider 200 itself from revealing the personal information of the user 100. The digital identity provider 200, having the encrypted serial number 300 to produce the ciphertext of the encrypted serial number 300E, may "remember" (e.g., store in memory or cache) which portion of the verified user data 220 is associated with the ciphertext, particularly if the digital identity provider 200 is designed to be used only by a single user 100. If such a correspondence between the ciphertext and the verified user data 220 is "remembered," the digital identity provider 200 may effectively associate the encrypted serial number 300E with the verified user data 220. Both (i) the legitimate behavior of the digital identity provider 200 and (ii) the ability of the identity provider 200 to associate the encrypted serial number 300E with the verified user data 220 in certain limited scenarios each pose a privacy risk outside of the user's control, since the user's verified user data 220, and therefore the user's personal information 150 and any personal information therein, may be obtained without the user's knowledge via the actions of the digital identity provider 200.

[0065] To avoid reliance on the digital identity provider 200, the representation of the first data set (serial number 300) includes the modified portion 410 of the authenticated certificate 400, and the authenticated certificate 400 is provided to or received by the user 100, and the modifiable portion 410 of the authenticated certificate 400 is then modified by the user 100 (S5). Once the modifiable portion 410 is modified, the authenticated certificate 400 generates (i.e. becomes) the certified user data 500, as shown in FIG. 2. A modification of the authenticated certificate 400 is any modification that makes the authenticated certificate 400, and in particular the modifiable portion 410, unable to be associated with the verified user data 220 by anyone (including the digital identity provider 200). A modification of the authenticated certificate 400 thus prevents the certified user data 500 from being linked to the verified user data via the representation of the first data set contained therein, or via any other part of the authenticated certificate.

[0066] In this example, where the serial number 300 is associated with already verified user data 220 and the ciphertext representing the encrypted serial number 300E comprises part of the alterable portion 410 of the authenticated certificate 400, the alteration is a re-randomization, and both the digital signature 420 and the encrypted serial number 300E (ciphertext) are each re-randomized using a re-randomization scheme.

[0067] In one particular example, the applied re-randomization scheme is applied to a digital signature on a ciphertext. The scheme re-randomizes the ciphertext, which has the effect of creating a new ciphertext with the same underlying plaintext (serial number 300 in this example). The scheme then allows the digital signature to be applied to be a valid signature on the new ciphertext. A security property of the scheme is that the signature can only be applied to another ciphertext with the same associated plaintext. It is not possible to determine whether two signed ciphertexts are associated with the same plaintext unless the ciphertexts are decrypted. One exemplary re-randomization scheme for signatures on ciphertexts is that of Bauer and Fuchsbauer (https: / / eprint.iacr.org / 2020 / 524).

[0068] When such a randomization scheme is applied to the authenticated certificate 400, the ciphertext 300E and the signature 420 are each modified (or, more specifically, re-randomized) by the user 100. The public key 430, which represents the identity of the original signer (which may be the digital identity provider 200), remains unchanged because it is contained within the immutable portion 415. The modified signature 420M is still a valid signature for the same public key 430.

[0069] 2, the re-randomization of the mutable portion 410 of the authenticated certificate 400 by the user 100 produces authenticated user data 500. The authenticated user data 500 includes an altered ciphertext of the mutable portion 410 of the authenticated certificate 400. The altered ciphertext includes an altered encrypted serial number 300M, which represents a re-randomized version of the ciphertext of the encrypted serial number 300E. The alteration means that when the digital identity provider 200 is presented with the altered ciphertext 300M contained within the authenticated user data 500, it will not be able to associate the ciphertext 300M with a particular portion of the verified user data 220, even if the digital identity provider 200 keeps a record of having created the ciphertext 300E. The modification to generate the certified user data 500 including the ciphertext 300M has the effect that the user 100 does not need to rely on the operation of the digital identity provider 200 for the security of the verified user data 220, because the correspondence between the ciphertext 300M and the verified user data 220 is not known to the digital identity provider 200.

[0070] However, from an inspection of the attested user data 500, and in particular the altered portion 410M therein, a third party can tell that the user 100 has gone through a verification process with the digital identity provider 200, because re-randomization has been applied such that the digital identity provider's signature 420M is valid for the new ciphertext 300M. Validity can be proven via inspection of the signature 420, the form of which is expected, or by using a public key. In this example, the unchanged portion 415 in the attested user data (in particular the public key 430) can indicate which digital identity provider 200 was responsible for the verification process and the creation of the authenticated certificate from which the authenticated user data 500 was produced. Thus, although a third party can tell that the user 100 has gone through a verification process, neither the third party nor the digital identity provider can link the attested user data 500 to the verified user data 220, and thus to the personal information 150 of the user 100. In this regard, the certified user data 500 (i.e., the authenticated certificate 400 once modified) is not linked to the verified user data 220 through any indication of the first data set contained therein.

[0071] Neither a third party inspecting the attested user data 500 nor the digital identity provider 200 can link the attested user data 500 or any part of it to the user 100, so the attested user data 500 provides proof of verification and a means to determine the user's personal information using a custodial system, but is otherwise completely anonymous. The user 100 can use the attested user data 500 or some feature of it as a digital identity, and the user's personal information 150 or any private information contained therein cannot be linked to the attested user data 500, so there is generally no opportunity for the personal information 150, and in particular the user's identifying and private details contained within the user's driver's license, to leak into the digital domain.

[0072] Commensurate with the reduced risk to a user's personal information, a third party such as a digital platform host 700, e.g., a forum or website host, may allow a forum or website user to use the certified certificate 500, or some feature thereof, as the platform's digital identity, while being safe in the knowledge that the user's identity has been verified by the digital identity provider, but that the certified user data 500 cannot be used back to the personal information 150 to determine the user's 100 personal information or any private information contained therein.

[0073] The user 100 can generate more than one set of attested user data 500 from the authenticated certificate 400 by altering (e.g., re-randomizing) the alterable portion 410 of the authenticated certificate 400 in a number of different ways. This allows the user 100 to generate logins for multiple platforms from a single verification process at the digital identity provider 200, where each set of attested user data corresponds to a different "login" for a different digital platform.

[0074] In some examples, the attested user data 500 forms the public portion of the user's cryptographic signing key. One benefit that arises is that the user can prove ownership of the attested user data at any time. This ability is useful when an owner wants to associate (in a cryptographically bound manner) the attested user data 500 with another form of identity, such as an account, profile, or digital wallet.

[0075] In some examples, after user 100 creates certified user data 500, the user may further encrypt certified user data 500 or portions thereof using a public key, such as the public key of depository system 600. In one example, user 100 further encrypts modified serial number 300M to create further encrypted modified serial number 300ME (not shown). User 100 then transmits the further encrypted form of certified user data 500 (of exemplary serial number 300ME) as ancillary data to digital identity provider 200 for association with one or more of serial number 300, authenticated certificate 400, verified user data, etc. Thus, digital identity provider 200 accumulates a record of each piece of certified user data created by user 100, but cannot access that record in the ancillary data because certified user data 500 has been further encrypted (without further encryption of certified user data 500, the association of certified user data 500 with serial number 300 is accessible to digital identity provider 200). Although this example refers to the further encryption of a modified serial number, in general the further encryption does not require to be a (modified) serial number, but instead may be a modified database reference, or generally a modified first data set.

[0076] In such an example, the accumulation of records may allow the host 700 or regulator / agency 800 to later require the custody system 600 to reveal some (all) of the digital identities generated by a given person by requesting that further encryption of the attested user data 500 stored by the digital identity provider 200 be decrypted using the custody system's private key. This provides a mechanism by which an individual can be removed from the platform, rather than just one of their digital identities, by which each piece of attested user data associated with a particular user 100 can be identified. To perform such decryption, the host or regulator provides the custody system 600 with an indication of the auxiliary data for the custody system 600 to decrypt.

[0077] (characterizing unknown users) The generation of the attested user data 500 provides the user 100 with a mechanism to prove that the user's personal information 150 has been verified and provides a digital identity for use on the digital platform 1000, but does not enable the digital identity provider 200 to reveal the user's 100 personal information from the attested user data 500. Furthermore, the digital platform host 700 is also unable to discern the user's 100 personal information from the attested user data 500.

[0078] The attested user data 500, or some feature thereof, may be used as the user's login to the digital platform and may be referred to as a "certonym" (meaning certified pseudonym). For example, if the digital platform is a website, the user's searches, posts, or comments may be logged, directly or indirectly, with a representation of the attested user data 500. If the platform is a digital wallet, the user's transactions may be logged, directly or indirectly, with a representation of the attested user data 500. In any case, in other instances, the logging is aimed at tracing actions back to the attested user data 500 responsible for each action. In some circumstances, the user 100 may also cryptographically attest the user's ownership of the attested user data 500, where the attested user data 500 forms the user's 100 cryptographic key.

[0079] In most applications, the certified anonymity behind such an arrangement is generally acceptable. However, there are scenarios where an otherwise unknown user behind a digital identity using the digital platform 1000 must be characterized and possibly identified from the certified user data 500. One example is during an emergency. In another example, the actions of an unknown user connected with the certified user data 500 are not acceptable. For example, if the platform 1000 is a website, the certified user data 500 may form a component of a login of an (unknown) user 100, which is found to be "trolling" comments or content created by other users or hosts. Another example of an unacceptable application is when the platform is a digital wallet, the certified user data 500 is a login to the digital wallet, and the unknown user is found to be conducting fraudulent or otherwise illicit transactions. In such a scenario, it is required that the unknown user behind the digital identity including the certified user data 500 be identified. In these scenarios, a mechanism is required to reverse the process of generating attested user data 500, otherwise allowing users 100 to act in impermissible ways with impunity, as is currently possible in pure pseudonymous state of the art systems.

[0080] Figure 4 features a user 100 that has already generated attested user data 500 according to the invention illustrated in the schemes of Figures 1-3 and has interacted with a digital platform using the attested user data 500. This example refers to a scenario in which the user 100 behind the attested user data 500 makes fraudulent comments on a website, although this example should not be understood as limiting.

[0081] If the user's behavior is unacceptable, for example if the user 100 is involved in continually violating comment rules or policies, the first step for the host 700 is to identify the verified user data 500 responsible for the comments. At this point, the host 700 does not know the public identity or any personal information of the user 100 behind the verified user data 500, and does not have access to any personal information 150 about the user 100 and verified user data 220. Thus, the user 100 remains an unknown user.

[0082] Although the user 100 cannot be identified, the host 700 can determine attested user data 500 responsible for unacceptable behavior, for example, by examining comments or logs of activity on the website.

[0083] Once the associated certified user data 500 is identified, the host 700 validates the certified user data 500. As shown in FIG. 2, contained within the certified user data 500 are both one or more public keys 430 present in the unaltered portion 415 of the certified user data 500, and / or an identifier of the digital identity provider 200 (the associated entity), such as the altered digital signature 420M present in the altered portion 410M of the certified user data 500. Accompanying each of these elements is a ciphertext, in this example the ciphertext 300M of the altered encrypted serial number 300. Although the host 700 cannot decrypt the ciphertext 300M, the host 700 can recognize the format of one or more of these elements to determine that the certified user data 500 it is examining is the certified user data previously generated from the authenticated certificate 400. In this sense, the fact that the authenticated user data 500 has the correct format is an indication that the host is examining the authenticated user data 500 (as opposed to any other data).

[0084] Optionally, the host 700 may check against the public key 430 of the digital identity provider 200 that the modified signature 420M is a valid signature.

[0085] Furthermore, the presence of the identifier, but not the content, reveals the presence of verified user data 220 and associated serial number 300, neither of which are included within attested user data 500. Rather, attested user data 500 itself indicates that verifying user data has already been done at digital identity provider 200 and that, in principle, digital identity provider 200 knows or has stored the correspondence between verified user data 220 and another piece of data, e.g., the (decrypted) ciphertext of the first data set (serial number 300 in the illustrated example).

[0086] In some examples, rather than the host 700 verifying whether the certified user data 500 has the correct format and / or verifying the identity of the digital identity provider 200, the host 700 instead allows the certified user data 500 to be verified by a third party. The third party may be a regulator 800, a trustee system 600, or another entity. The certified user data 500 may be sent to the third party to check the format of the certified user data 500, or the third party may be provided with the certified user data, for example, via publication. The third party may then examine the certified user data 500 and verify that the certified user data 500 is of the correct format in a manner similar to that outlined above for the host 700. The third party, such as the regulator 800, then provides a confirmation to the host 700. Alternatively, upon receipt of the confirmation, the host 700 is indicated that the verification process has already taken place by the digital identity provider 200.

[0087] Next, as shown in FIG. 4, the host 700 sends a request 710 to the depository system 600. The request is sent to the depository system 600 (U1). The request may include a copy of the certified user data 500 itself, or may include an indication of the location of the certified user data 500 (such as a server address for the certified user data 500) and the means by which the depository system 600 is allowed to retrieve or examine the certified user data 500. The host 700 may send the request 710 itself, or may ask a third party, such as a regulator 800, to send the request 710 to the depository system 600 on its behalf. As a further alternative, the host 700 may report unacceptable behavior and the certified user data to a third party or regulator 800, who may initiate the sending of the request 710 to the depository system 600.

[0088] Upon receiving the request 710, the trustee system 600 verifies the certified user 500's representation of the ciphertext 300M. Because the ciphertext 300M was originally encrypted with the trustee system's public key prior to the alteration, the trustee system 600 can use its private key to decrypt the ciphertext 300M to reveal the serial number 300. In this example, the ciphertext, which is the altered encrypted serial number 300M, is formed as a re-randomization of the encrypted serial number 300E, Both are valid ciphertexts that encrypt the same plaintext (serial number 300) under the private key of the trustee system 600. Because re-randomization preserves the underlying plaintext of the ciphertext, the trustee system's private key can be used directly to decrypt the modified encrypted serial number 300M to obtain serial number 300.

[0089] If multiple decryptable portions / encrypted tokens / database references / serial numbers are present in the attested user data (because, as previously mentioned, the original authenticated certificate 400 contained a mutable portion 410 with multiple decryptable portions, or multiple mutable portions each with their own decryptable portion), the custody system 600 can choose which decryptable portions to decrypt, leaving the encrypted portions to keep. The choice may be optional for the custody system 600, or may be indicated to the custody system 600 by the requester. Furthermore, in some situations, the custody system 600 may only be able to decrypt a subset of the decryptable portions, and one or more other custody systems are required to decrypt the remaining portions.

[0090] Although in principle only a single custodian system 600 in possession of the correct private key is required, in some embodiments of the invention multiple custodians 600 can decrypt the ciphertext (altered encrypted serial number 300M) contained within the attested user data 500. For example, the custodian system 600 may be a distributed custodian system 600 with multiple nodes responsible for decrypting the ciphertext 300M, for example each node decrypting a part of the ciphertext with a threshold encryption / decryption scheme, or multiple nodes decrypting the text with some nodes providing redundancy or checking functions.

[0091] Additionally, the trustee system 600 (distributed or not) may authenticate the request 710 to decrypt the certified user data 500, for example by verifying the authority of the host 700 or regulatory agency 800 requesting decryption of the ciphertext 300M. For example, the request 710 may include the requester's digital signature and the requester's public key, so that the requester's authority to request decryption is verified. If multiple trustee systems 600 are used, decryption of the ciphertext 300M will only occur if a threshold of trustee systems indicates that authority exists in more than, for example, 50% of the trustee systems 600.

[0092] Once the depository system 600 decrypts the modified encrypted serial number 300M, it provides the unencrypted serial number 300 to the requester (U2). In some cases, the serial number 300 may be transmitted to the requester, but similar to other examples already outlined, the transmission is susceptible to interception. Thus, in some examples, the serial number 300 is stored in a location accessible to the requester, for example, the depository system 600 may re-encrypt the serial number 300 with the requester's public key and inform the requester of the location (e.g., a private blockchain) so that the requester can access the serial number 300 using the requester's private key. In this example, the serial number is used as the first data set, but the requester may be provided with an alternative token, an alternative database reference, or another form of the first data set that matches a portion of the data previously associated with the user data 220 verified by the digital identity provider 200.

[0093] Although not shown, any such requests 710 may be publicly logged so that they may be viewed by third parties, possibly by the user 100, to deter misuse of the ability to make requests 710 by the host 700 or regulatory body 800. Publication of such a log may hinder the host 700 or regulatory body 800 from seeking to uncover personal information of the user 100 behind the attested user data 500 without the knowledge of the user 100 or another third party. In some cases, the log is a necessary, public, permanent record of the requests 710, such as publication to a public blockchain.

[0094] Once the unencrypted serial number 300 is provided to the host 700 (or to a regulatory agency 800, if appropriate), the host provides the serial number to the digital identity provider 200 (U3). The digital identity provider that the host 700 should approach is determined by the certified user data 500, which includes one or both of the digital signature 420M and the public key 430, both of which are indicative of the digital identity provider 200. In a similar manner to providing the certified user data 500 to the trustee system 600, the host 700 can send the serial number (a first set of data) to the digital identity provider, or alternatively send a message to the digital identity provider indicating where the serial number can be found.

[0095] Upon receiving a representation of the serial number 300, the digital identity provider 200 may respond by showing a representation of the verified user data 220, including the personal information 150 associated with the user 100. To do so, the digital identity provider 200 consults the database 210 to find the verified user data 220 associated with the serial number 300. In some examples, the digital identity provider 200 may verify the authority of the host 700, regulator 800, or other entity providing the serial number 300. For example, the serial number 300 may be affixed with the digital signature of the requester (i.e., the host 700 or regulator 800) and the requester's public key to grant the requester's authority to request that the digital identity provider 200 reveal the association.

[0096] Once the host 700 or regulator 800 is provided with the verified user data 220 including personal information 150, the host 700 or regulator 800 may act on the information. For example, the personal information may cause the host 700 to publish information about currently known users 100, thereby revealing the personal information of users responsible for unacceptable behavior, and if the information is identifying information, the publication may reveal the identity of the users 100 to others in a "name and blame" manner. Alternatively, the host 700 may store the personal information of the currently known users 100 for future reference, or if the information includes identifying information, store the identifying information of the currently known users 100 for future reference. The host 700 may sanction the users 100, for example, by banning access to websites or any digital platforms for which the host is responsible, or by limiting the user's ability to comment. The user's personal information may be added to a blacklist or reported to legal authorities for prosecution. In another example, the host 700 may select a second portion of the attested user data and request the custodian system to decrypt the modified encrypted first data set (the modified encrypted serial number in some examples) contained within the second portion of the attested data. In one scenario, the host may wish to verify whether the two portions of the attested user data (the attested user data 500 and the second portion of the attested user data) have the same underlying user 100. In each instance, as a result of an action taken with the attested user data 500, the host 700 (or a regulatory agency 800, which may instead perform any of the above actions) may revoke the attested anonymity previously enjoyed by the user 100, and the user's personal information may be revealed. In examples where the user stores auxiliary data at the digital identity provider 200, the accumulation of records at the digital identity provider 200 may be provided to the host 700 or the regulatory agency 800. If those records are encrypted with the public key of the custodian system 600, the host or regulatory agency may request that those records be decrypted by the custodian system 600.The decryption request proceeds similarly to the original request of Figure 4 and may be logged and granted in a similar manner as described above. Once decryption by the depository system 600 is complete, each piece of attested user data associated with the user 100 is revealed and action is taken against each of their digital identities, such as removing them from their associated digital platforms.

[0097] From the above, a system with the architecture shown in Fig. 4 shows how the attested user data 500 can be reconnected with the verified user data 220 and ultimately with the personal information 150 of the user 100, so that users cannot act with impunity on digital platforms. Thus, in this case, when the alterable portion 410 of the certificate 400 is altered and the attested user data 500 is generated, the severing of the link between the first data set contained within the authenticated certificate 400 and the verified user data 220 is reversible and the link may be re-established.

[0098] The present invention provides a user with a system for generating attested user data that acts as a digital identity, providing the advantages of anonymity to the user, privacy of the user's data, and minimization of risk of information leakage, while providing an indication to a host or regulator that the user's personal information has been previously verified by a digital identity provider. Furthermore, if the user commits fraud or the situation is otherwise legitimate, the anonymity of the user's attested data may be removed.

[0099] Although the actions of individual entities of the system are described in the examples set forth above, as one skilled in the art will recognize, the various entities also collectively provide the benefits of the system. As just a few examples, from the digital identity provider's 200 perspective, once the user's personal information 150 is verified, the digital identity provider 200 and the user 100 work together to generate an authenticated certificate 400, which then verifies the user's 100 information. From the user's 100 perspective, in exchange for providing the personal information 150 to the digital identity provider 200, an authenticated certificate 400 is received or provided that the user may modify to generate authenticated user data 500. The host 700 (possibly under the oversight of a regulator 800) may recognize that the user 100 has undergone a verification process with the digital identity provider 200, and may choose to accept the authenticated user data 500 produced by that digital identity provider as part of a login to access the host's digital platform, secure in the knowledge that the user may be characterized or identified as necessary. The host 700 / regulatory agency 800 may work together to request and ultimately reveal personal information 150 of the user 100, but each may do so only in circumstances where the trustee system 600 supports it. If such circumstances exist, the trustee system 600 works with the host 700 / regulatory agency 800 to prevent the (unknown) user 100 from acting with impunity on the digital platform. However, in the meantime, the user 100 may monitor the submissions to the trustee system, thereby restraining the host 700 or the regulator 800 from abusing the ability to reveal the user behind the verified user 500. Similarly, the trustee system 600 and the host 700 / regulatory agency 800 work together to request and ultimately reveal personal information of the user in suitable circumstances from the verified user data 500 created. Thus, each entity in the system may cooperate to realize the benefits arising from the system.

[0100] It will be appreciated that the above disclosure provides specific examples of certain implementations of the present invention and that modifications may be made within the scope of the appended claims, such modifications will similarly take advantage of the methods and systems outlined herein for privacy and data protection and will be apparent to those skilled in the art, and the specific scenarios outlined herein should not be considered limiting. (Mode of the Invention) (Mode 1) 1. A computer-implemented method for providing an authenticated certificate that is modified upon generation of certified user data, the method comprising: verifying user data, the user data including personal information of the user; associating the verified user data with a first data set; creating an authenticated certificate that is modified upon generation of the certified user data, the authenticated certificate including a modifiable portion that includes a representation of the first data set; providing an authenticated certificate for generation of certified user data, the mutable portion being mutable such that when modified, the authenticated certificate cannot be associated with the verified user data; A method comprising: (Mode 2) 2. The method of claim 1, wherein the first data set includes one or more of a token, a database reference, or a serial number. (Mode 3) 3. The method of claim 1 or 2, wherein the method further comprises the step of encrypting the first data set, the Andoized first data set forming a representation of the first data set. (Mode 4) The method of any one of Aspects 1 to 3, wherein the mutable portion of the created authenticated certificate includes an identifier of the entity creating the authenticated certificate, and optionally, the identifier includes a signature signed using the entity's private key. (Mode 5) The method of any one of the preceding aspects, wherein the alterable portion comprises a re-randomizable portion. (Mode 6) The method according to any one of the preceding aspects, further comprising storing an association between the first data set and the verified user data. (Mode 7) The method of Aspect 3 or any aspect dependent therefrom, wherein the encrypting step is performed using a public key of the trustee system. (Mode 8) The method of any one of the preceding aspects, further comprising modifying an alterable portion of the authenticated certificate to generate certified user data. (Mode 9) A method as described in any one of the preceding aspects, comprising a step of storing auxiliary data, the auxiliary data including an association between the verified user data and an encrypted version of the representation of the certified user data, and optionally, the encryption to create the encrypted version of the representation of the certified user data is performed using a public key of the trusted system. (Mode 10) 13. The method of any one of the preceding aspects, wherein the personal information includes identifying information. (Mode 11) The method according to any one of the preceding aspects, wherein the authenticated user data includes a user's cryptographic key. (Mode 12) 1. A computer-implemented method for enabling characterization of an unknown user from attested user data, the attested user data including an altered portion of an authenticated certificate, the altered portion including an encrypted first data set, the authenticated certificate further including an identifier of an associated entity, the first data set being associated with user data verified by the associated entity prior to the alteration of the portion, the verified user data including personal information of the unknown user, the method comprising: receiving a request from a requestor, the request including an indication of authenticated user data; decrypting the encrypted first data set of the altered portion of the authenticated user data to provide the first data set; providing a first data set associated with the verified user data to a requester to enable characterization of the unknown user; A method comprising: (Mode 13) The identifiers of the associated entities are a signature signed using the public key of the relevant entity, optionally included in the altered portion; and the public key of the associated entity contained within the authenticated certificate, optionally contained within an unaltered portion of the authenticated certificate; 13. The method of embodiment 12, comprising one or more of: (Mode 14) 14. The method of claim 12 or 13, wherein the first data set includes one or more of a token, a database reference, or a serial number. (Mode 15) 15. The method of one of Aspects 12 to 14, wherein the method is performed by a depository system and the first data set is encrypted using a public key of the depository system. (Mode 16) 16. The method of any one of embodiments 12 to 15, wherein the altered portion is a re-randomized portion, and the alteration is re-randomization. (Mode 17) A method according to any one of Aspects 12 to 16, further comprising the step of accepting a request from a requester to enable characterization of the unknown user. (Mode 18) The method according to aspect 17 and aspects dependent thereon, wherein the method is performed by a plurality of trustee systems, and the step of decrypting the encrypted first data set of the modified portion included in the certified user data is performed only if a number of the trustee systems among the plurality of trustee systems that grant the request meets a threshold. (Mode 19) The method according to any one of Aspects 12 to 18, further comprising checking the validity of the identifiers of the associated entities. (Mode 20) 19. The method of any one of aspects 12 to 19, wherein associating the first data set with the verified user data occurs prior to encryption of the first data set. (Mode 21) 21. The method of any one of aspects 12 to 20, wherein the personal information includes identification information and the method is a method that allows identification of an unknown user from authenticated user data. (Mode 22) 1. A method of characterizing an unknown user from authenticated user data, the authenticated user data comprising a modified portion of an authenticated certificate, the modified portion comprising an encrypted first data set, the authenticated certificate further comprising an identifier of an associated entity, the first data set being associated with user data verified by the associated entity prior to the modification of said portion, the verified user data comprising personal information of the unknown user, the method comprising: providing a representation of the authenticated user data to one or more trusted systems; receiving a first data set from one or more depository systems; providing a first data set to an associated entity; receiving verified user data from an associated entity, the verified user data including personal information of the unknown user; A method comprising: (Mode 23) The identifiers of the associated entities are a signature signed using the private key of the relevant entity, optionally included in the altered portion; and the public key of the relevant entity contained within the authenticated certificate, optionally contained in an unaltered portion of the authenticated certificate; 23. The method of embodiment 22, comprising one or more of: (Mode 24) 24. The method of claim 22 or 23, wherein the first data set includes one or more of a token, a database reference, or a serial number. (Mode 25) 25. The method of any one of embodiments 22 to 24, wherein the altered portion is a re-randomized portion, and the alteration is re-randomization. (Mode 26) (i) disclosing personal information of unknown users; (ii) storing personal information of the unknown user; and (iii) sanctioning or subjecting the user to prosecution; (iv) selecting second authenticated user data, the selection of the second authenticated user data being based on personal information of the first authenticated user data; (v) adding the user's personal information to a blacklist; 26. The method according to any one of aspects 22 to 25, further comprising at least one step of: (Mode 27) 27. The method of any one of Aspects 22 to 26, wherein associating the first data set with the verified user data occurs prior to encryption of the first data set. (Mode 28) The method according to any one of Aspects 22 to 27, wherein the personal information includes identification information and the method is a method of identifying an unknown user from authenticated user data. (Mode 29) A method according to one or more of aspects 1 to 11 and a method according to one or more of aspects 12 to 21; or A method according to one or more of aspects 1 to 11 and one or more of aspects 22 to 28; or The method according to one or more of the aspects 12 to 21 and the method according to one or more of the aspects 22 to 28, or A method according to one or more of aspects 1 to 11, a method according to one or more of aspects 12 to 21, and a method according to one or more of aspects 22 to 28; A method comprising the steps of: (Mode 30) A computer program product comprising instructions that, when executed, cause one or more processors to perform the method of one of aspects 1 to 29. (Mode 31) A computer-readable medium comprising instructions that, when executed, cause one or more processors to perform a method of one of aspects 1 to 29. (Mode 32) A processor configured to perform one of the methods of aspect 1 to aspect 29.

Claims

1. A computer implementation method for providing an authenticated certificate by using a first dataset associated with user data validated by a related entity, wherein the validated user data includes the user's personal information, the method is performed by an issuing entity, and the method is A step of encrypting a first dataset in order to form an encrypted first dataset using the public key of a contracted system, wherein the encrypted first dataset forms a representation of the first dataset, A step of creating the authenticated certificate which is modified in the generation of the authenticated user data, wherein the authenticated certificate comprises a modifiable portion including the representation of the first dataset, A step of providing the authenticated certificate for the generation of the verified user data, wherein the modifiable portion is modifiable, and when modified, the authenticated certificate is no longer associated with the verified user data. A method that includes [a certain feature].

2. The method according to claim 1, wherein the first dataset includes one or more tokens, database references, or serial numbers.

3. The method according to claim 1, wherein the modifiable portion of the authenticated certificate created includes an identifier of the entity creating the authenticated certificate, and optionally the identifier includes a signature signed using the private key of the entity.

4. The method according to claim 1, wherein the modifiable portion includes a re-randomizable portion.

5. The method according to claim 1, wherein the association between the first dataset and the verified user data is stored by the association entity, and optionally, the computer implementation method that provides the authenticated certificate also uses an identifier of the association entity.

6. The method according to claim 1, further comprising the step of modifying the modifiable portion of the authenticated certificate in order to generate the certified user data.

7. The method according to claim 1, further comprising the step of storing auxiliary data, the auxiliary data including associations between verified user data and encrypted versions of representations of the verified user data, and optionally, the encryption for creating the encrypted versions of representations of the verified user data is performed using the public key of the entrusted system.

8. The method according to claim 1, wherein the personal information includes identification information and / or the certified user data includes an encryption key.

9. A computer implementation method enabling the characterization of an unknown user from certified user data, wherein the certified user data is generated through modification of an authenticated certificate, the certified user data includes a modified portion created through modification of a mutable portion of the authenticated certificate, both the modified portion and the mutable portion include an encrypted first dataset, the encrypted first dataset is created through encryption of the first dataset using at least one public key of at least one entrusted system, the first dataset is associated with user data validated by an entity, the validated user data includes personal information of the unknown user, the mutable portion is mutable, and when modified, the authenticated certificate is no longer associated with the validated user data, the certified user data includes an identifier of an entity, the method is performed by the at least one entrusted system, and the method is A step of receiving a request from a requester, which includes the certified user data or a display of the certified user data, wherein the display of the certified user data enables the certified user data to be obtained by the at least one entrusted system. If the request includes displaying the certified user data, the steps include obtaining the certified user data based on the display of the certified user data, To provide the first dataset, the steps include decrypting the encrypted first dataset of the modified portion contained within the certified user data, To enable the characterization of the unknown user, the steps include providing the requester with the first dataset associated with the verified user data, Methods that include...

10. A computer implementation method for characterizing an unknown user from verified user data, wherein the verified user data is generated through modification of an authenticated certificate, the verified user data includes a modified portion created through modification of a mutable portion of an authenticated certificate, both the modified portion and the mutable portion include an encrypted first dataset, the encrypted first dataset is created through encryption of the first dataset using at least one public key of at least one entrusted system, the first dataset is associated by a related entity, the verified user data includes personal information of the unknown user, the mutable portion is mutable, and when modified, the authenticated certificate is no longer associated with the verified user data, and the verified user data includes an identifier of the related entity. The method is performed by an entity whose purpose is to characterize the unknown user, and the method is A step of providing the certified user data or a representation of the certified user data to the at least one contracted system, wherein the representation of the certified user data enables the certified user data to be retrieved by the at least one contracted system. The steps include receiving the first dataset from at least one of the contracted systems, The steps include providing the first dataset to the related entities, The steps include receiving verified user data, including the personal information of the unknown user, from the aforementioned related entity, Methods that include...

11. The identifier of the related entity is A signature signed using the private key of the aforementioned related entity, optionally including the signature contained in the modified portion, The public key of the related entity included in the authenticated certificate, optionally, the public key included in the unmodified portion of the authenticated certificate, The method according to claim 10, comprising one or more of the above.

12. The method according to claim 10, wherein the modified portion is a re-randomized portion, and the modification is re-randomized.

13. A computer program product that, when executed, includes instructions causing one or more processors to perform the method according to any one of claims 1 to 12.

14. A computer-readable medium that, when executed, includes instructions causing one or more processors to perform the method according to any one of claims 1 to 12.

15. A processor configured to perform the method described in any one of claims 1 to 12.