Provenance Verification for Selective Disclosure of Attributes

The system uses digital signatures and zero-knowledge proofs to authenticate anonymized medical data, addressing issues of authenticity and fraud in data disclosure by ensuring that attributes belong to a single record, enhancing privacy and security in medical data sharing.

JP7705846B2Active Publication Date: 2025-07-10KONINKLIJKE PHILIPS NV
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022514156
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-10-11
Filing Date
2020-09-02
Publication Date
2025-07-10
Estimated Expiration
2040-09-02

AI Technical Summary

Technical Problem

Existing systems for anonymizing medical data face challenges in ensuring authenticity and preventing unauthorized access, particularly when direct contact between the issuer and recipient is not possible, leading to issues like fraud and replication of anonymized data.

Method used

A system utilizing an issuer device, selector device, and recipient device that employs digital signatures and zero-knowledge proofs to verify the authenticity of anonymized data, ensuring that attributes belong to a single record without revealing the secret record identifier, thereby allowing secure and selective disclosure.

Benefits of technology

The system provides improved privacy and authenticity guarantees, enabling recipients to verify the legitimacy of anonymized data without direct contact with the issuer, reducing the risk of fraud and replication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007705846000031
    Figure 0007705846000031
  • Figure 0007705846000032
    Figure 0007705846000032
  • Figure 0007705846000033
    Figure 0007705846000033
Patent Text Reader

Abstract

Some embodiments are directed to a system 100 for selectively disclosing attributes of a record. An issuer device 110 generates a digital signature over a message including the attributes and a secret record identifier. The record, the secret record identifier, and the signature are provided to a selector device. The selector device 111 selectively discloses the attributes of the record to a recipient device 112 and proves authenticity through a zero-knowledge proof of knowledge of the signature on the attributes. The recipient device 112 verifies the proof with respect to the issuer's public key and the received attributes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a system for selectively disclosing attributes of records, such as medical attributes. The present invention also relates to an issuer device, a selector device, and a recipient device for use in such a system. The present invention further relates to an issuer method, a selector method, and a recipient method corresponding to each device. The present invention also relates to a computer-readable storage medium.

Background Art

[0002] Using medical data such as genomic data for medical research and treatment holds great promise from the perspective of possible applications, but it also poses significant risks from the perspective of data privacy and security if not handled carefully. As more and more people's medical data becomes available, for example, the scope of medical research to find better or more personalized treatments is expanding. At the same time, such medical research involves highly confidential data, such as genotype and / or phenotype data. In many cases, for example, data from many different patients is used. Therefore, appropriate measures need to be taken to prevent unauthorized access to and modification of such data.

[0003] A known approach for restricting data disclosure in a medical research environment is anonymization. For example, in a known system, medical data is collected from one or more senders, such as data from various devices or medical trials, and stored on a central platform. A researcher requests medical data of patients with specific characteristics. According to laws and international standards, such data should be anonymized. Therefore, the platform selects data for one or more patients, anonymizes the data, for example, selects a subset of the medical data, such as phenotype and genotype data, and provides the anonymized data to the researcher.

[0004] More generally, anonymization, for example, providing an edited version of a personal information record that is sufficiently restricted in terms of the specificity and details of the personal information so that the personal information can no longer be linked to the data subject of that personal information, is being driven by legal pressures such as the GDPR and medical standards such as the GA4GH Beacon, and is becoming increasingly common. For example, anonymized data is used for medical research other than genomic research, but is also used in various other application areas such as financial services and advertising. More generally, for example, for records that do not contain personal information, anonymization is considered a form of selective disclosure, for example, determining which parts of the record to share with the recipient by the data provider.

[0005] From the perspective of the recipient of anonymized data, for example, a researcher who receives medical data about an anonymized patient, the fact that the data is anonymized poses a risk of fraud or tampering by malicious individuals. Anonymized data may not be linkable to the original source, so it can be difficult to distinguish between true data with a legitimate source and forged data without a legitimate source. Therefore, it is desirable to perform anonymization in such a way that the recipient, for example, the person paying for the data or the person inspecting the data for control purposes, can trust that the anonymized data is legitimate and, for example, comes from a trustworthy source. For example, when anonymized data is illegally replicated, a problematic situation can occur. In particular, when a monetary value is assigned to the data, for example, when a researcher pays for access to the data, there may be an incentive for such fraud, for example, artificially increasing the amount of data. Since the data is anonymized, it is difficult to confirm whether two records are truly different. In addition to malicious intent, replicated records can occur due to errors such as programming errors or operator errors. It is desirable that the recipient, for example, the researcher, be able to verify this.

[0006] A further complication is that the authentication means are difficult to use. For example, the authentication tags associated with records tend to be simple and can be replicated. Furthermore, such authentication tags need to be verifiable from anonymized data rather than from the complete records. What further complicates the problem is that the ultimate recipients of the data, such as researchers, do not have direct contact with the data issuers. Generally, there is an intermediary between the selector, such as between the issuer and the recipient, who, for example, sends the appropriate data to the appropriate researcher. However, this means that anonymization is preferably performed after the data has been provided to the selector. Summary of the Invention Problems to be Solved by the Invention

[0007] In practice, direct contact between the issuer and the recipient may not be possible. For example, the issuer may be an organization or machine that is no longer active or has ceased operations. Although it is preferable to be independent of the data issuer, there is a need for a secure method of anonymizing data that still allows verification by the data recipient.

[0008] Ensuring authenticity is carried out using conventional techniques, for example, by sending requests to all data senders and digitally approving the anonymized data to prove that it has been approved. However, this is cumbersome and often costly and may not even be possible, for example, if the sender is an organization or machine that has ceased operations. Therefore, more highly automated techniques are needed to guarantee the credibility of selectively disclosed records. Means for Solving the Problems

[0009] To address these and other issues, a system for selectively disclosing attributes of records is proposed as defined by the claims. The system includes an issuer device for providing records to a selector device for selective disclosure, a selector device for selectively disclosing a portion of the records to a recipient device, and a recipient device for selectively obtaining a portion of the records.

[0010] Records contain one or more attributes. In selective disclosure, the selector device determines one or more attributes to be disclosed as a subset of one or more attributes and one or more data entries to be disclosed as a subset of the plurality of data entries. The record is a personal information record, for example, where the attribute contains information about an individual. However, records containing other types of highly confidential information are equally possible.

[0011] Attributes generally come from a pre-defined set. For example, when multiple records are processed by the system, each record assigns values to the same set of attributes. For example, one or more records represent phenotypic information about an individual, such as length, hair color, diagnosis of a particular symptom, etc. The values of the attributes in an individual record are generally invariant during the lifetime of the record. Attributes are generally numerical values, categories, fixed-length strings, etc.

[0012] Various types of data are linked to the signature. For example, the data is encoded by a data line of a file in the variant call format (VCF) of genomic data of the individual represented by the record, for example, representing a single nucleotide polymorphism (SNP).

[0013] Furthermore, to enable selective disclosure of both attributes in a secure manner, it has been devised that the issuing device generates a digital signature on the attributes using the corresponding issuer private key that is known to the recipient device. As is known, a digital signature on a message enables a person with the issuer public key to prove that the message has been signed by the person holding the corresponding private key. In this case, the issuing device generates a digital signature for one or more attributes, for example, for an attribute message including one or more attributes.

[0014] Thus, these digital signatures make it possible to prove the authenticity of the attributes of the record, for example, the origin of the attributes of the record. In this case, as will be explained shortly, the digital signature is preferably selected so that it enables efficient execution of their so-called zero-knowledge proofs by the digital signature.

[0015] Thus, the issuing device according to an embodiment determines a secret record identifier, for example, a randomly generated identifier that is unique to a specific record, and includes the identifier in the attribute message and optionally in the data message that signs the record. The issuing device can then provide the record, the secret record identifier, and the digital signature to the selector device. The secret record identifier is thus used to ensure that each digital signature corresponds to a single record provided by the issuing device.

[0016] When selective disclosure is performed, the selector device can give the recipient device the attributes to be disclosed along with their signatures. However, although the attribute message can also contain non-disclosed attributes, the recipient device still usually needs those attributes to verify the signature. Also, since the signature contains the secret record identifier, the recipient usually needs the secret record identifier to verify the signature. Thus, in two different disclosures, if the recipient obtains a non-overlapping set of attributes from the same record, the recipient links these two different partial records to each other based on the secret record identifier. Or, the recipient uses the secret record identifier to link that partial record to another partial record received by a different recipient.

[0017] Furthermore, when the attribute message is anonymized, it becomes difficult for the recipient to verify whether any of the records have been replicated. Interestingly, as will be explained below, the secret record identifier remains hidden from the recipient device. Instead, the selector device is configured to determine a public record identifier from the secret record identifier. The public record identifier is given to the recipient device along with one or more of those attributes to be disclosed. For a given disclosure of a record, the public record identifier is bijective with the secret record identifier, i.e., two public record identifiers are equal if and only if the corresponding secret record identifiers are equal.

[0018] To prove to the recipient that the given value belongs to a single record signed by the issuer device, a zero-knowledge proof is devised for the selector device. As is known from cryptography, a zero-knowledge proof is a way in which a prover of a party can prove to a verifier of another party that the prover knows a value that satisfies a certain property. In a zero-knowledge proof, interestingly, this is achieved without the prover disclosing the value to the verifier. For example, in a zero-knowledge proof, the verifier knows the public key, and the prover can prove to the verifier that the prover knows the private key corresponding to that public key without showing the private key to the verifier.

[0019] In this case, the selector device performs a zero-knowledge proof using the recipient device, and the selector device proves the knowledge of the secret record identifier, the digital signature on the attribute message, and the digital signature on the data message. The selector device further proves that it has the knowledge of the secret record identifier corresponding to the public record identifier.

[0020] In other words, the selector device generally does not disclose the secret record identifier nor any digital signature to the recipient device, but instead discloses a proof that the selector device knows the valid identifier and signature. Specific examples of constructing such a proof efficiently are given below, but note that general techniques enabling the proof of knowledge of data satisfying any relationship are available in the literature, and in principle any digital signature scheme and any general zero-knowledge proof system can be used.

[0021] With respect to the attributes, the selector device proves that the digital signature on the attribute message is the digital signature on a message containing at least one or more attributes and the secret record identifier to be disclosed. The recipient device verifies this part of the proof regarding one or more attributes obtained by the recipient device from the selector device to confirm the correctness of the received attributes. The selector device also proves that the digital signature is signed with a secret key corresponding to the issuer public key that the recipient can verify using the issuer public key. By performing this part of the proof as the verifier, the recipient device thus obtains the guarantee that the attributes it obtained from the selector device are indeed part of the records given by the issuer device.

[0022] Interestingly, the selector device selects the public table key from both the secret record identifier and also from the public table key itself to determine the public record identifier. For example, the selector device could have generated a table key pair for obtaining the public table key, for example, a private table key and the corresponding public table key. Interestingly, the private table key is not required. For example, the public table key functions as a fixed point of an ID for applications where a private key is not required. Instead of generating a table key pair, the selector device could first directly obtain a point in the corresponding group G without first generating a private table key, or could have obtained G1 to obtain the public table key. For example, the phrase could be hashed to a point in the group and the phrase could be disclosed to the recipient device. The advantage of generating a random private key is to reduce the variance due to accidentally using the same public table key twice.

[0023] The public table key is given to the recipient device to prove the knowledge of the secret record identifier corresponding to the public record identifier and is used in zero-knowledge proofs. With the public table key, the selector device can control which disclosures the recipient device should be able to store records separately from each other. Using the same table key gives the guarantee that the public record identifiers are equal if and only if the corresponding secret record identifiers are equal. However, regardless of whether the corresponding secret record identifiers are equal, the public record identifiers calculated for different table keys will not be equal. In this way, the recipient device can verify duplicates in the set of data it receives, but it is still not possible to match the received data with data received at different times or by different recipient devices.

[0024] In one embodiment, separate digital signatures are calculated by the issuer on the data message containing each data entry, for example, one for each data entry. The issuer device according to one embodiment also includes the secret record identifier in the attribute message and in one or more data messages that the issuer device signs for that record. This allows the use of different signature schemes depending on the data type. However, it should be noted that this approach is optional since the data messages can be linked to records in other ways, for example, by including their hashes in the attributes.

[0025] Regarding data entries, the selector device proves that the digital signature on the data message contains the data entries to be disclosed, each containing a secret record identifier. For example, each message is a digital signature on a message that each contains a data entry and a second record identifier. The receiver device verifies this part of the proof regarding the data entries obtained by the receiver device from the selector device to confirm their correctness. The selector device also proves that the digital signature is signed with a private key corresponding to the issuer's public key and that the receiver can verify it using the issuer's public key. By performing this part of the proof as a verifier, the receiver device thus obtains the guarantee that the data entries it obtained from the selector device are part of the records provided by the issuer device. In particular, the proof guarantees that each of the digital signatures contains a secret record identifier and is thus part of the same record provided by the issuer device, but the receiver device still does not actually know the secret record identifier, preventing linking between partial records obtained in different selective disclosures.

[0026] Thus, a system is provided in which a selector device can provide a receiver device with the attributes of records along with improved privacy and / or authenticity guarantees. Further, various devices are provided that each give distinct features that contribute to various advantages. For example, the issuer device determines a secret record identifier and includes it in each digital signature of the record. The digital signature is preferably of a type on which an efficient zero-knowledge proof can be performed, examples of which are given below, but any type of digital signature can be used in combination with a suitable zero-knowledge proof system. As another example, the selector and receiver devices perform a zero-knowledge proof to confirm to the receiver device that the selectively disclosed values belong to a single record of the issuer device.

[0027] By the means described, the recipient device obtains the guarantee that the acquired attributes belong to a single record given by the issuer device. Nevertheless, the recipient device generally does not even know about non-disclosed attributes or data entries, or how many data entries the record contains. In particular, some of the records are linked by an identifier, which can be a secret record identifier unknown to the recipient device. The burden of performing selective disclosure is that the issuer device only needs to give the record to the selector device once and then does not need to be involved and is removed from the issuer device. The selective disclosure of a subset of a plurality of data entries generally involves calculations and communications that are proportional to the number of data entries disclosed rather than the total number of data entries. Therefore, the system is particularly suitable for large and / or dynamic sets of data entries. For example, instead of disclosing the entire genome, only the relevant parts can be disclosed in a disclosure that is proportional only to the number of relevant parts. Thus, selective disclosure of a part of the improved record is provided.

[0028] In one embodiment, the attributes of the record include one or more phenotypic attributes about an individual. The data entries of the record include one or more genomic parts of the individual. For example, the system is a system for providing genomic data to researchers in medical research. Considering the high density of genomic data and improving compliance with privacy regulations in various jurisdictions, it is important that such records are de-identified, and at the same time, the number of genomic parts in the record is large. For example, the record includes the entire continuous genome of an individual or most of it. In such cases, as described, selective disclosure of a subset of a set of genomic parts is possible, and thus the beneficial proportionality characteristics as described herein are particularly meaningful.

[0029] Various digital signature schemes can be used to sign attribute messages and data messages for multiple data entries. As previously explained, in principle any digital signature scheme can be used. Next, various particularly advantageous options will be described.

[0030] Various embodiments are based on anonymous credentials. Anonymous credentials themselves are known in the art as a way for a user to obtain a certificate regarding one or more of the user's attributes, such as the user's age and country of origin. The user can show the anonymous credential to a third party anonymously and prove that he / she meets certain characteristics, such as being at least 18 years old, without showing information that connects to the user. The attributes of the anonymous credential scheme are generally assumed to be numerical, and other types of attributes can be encoded in various ways. For example, a text attribute can be encoded as a numerical attribute by applying a one-way function to the text, etc.

[0031] Examples of such anonymous credential schemes are disclosed, for example, in "Signature schemes and anonymous credentials from bilinear maps" by J. Camenisch et al., Proceedings of CRYPTO'04 (incorporated herein by reference insofar as it describes the anonymous credential scheme) and "An Accumulator Based on Bilinear Maps and Efficient Revocation for Anonymous Credentials" by J. Camenisch et al., Proceedings of PKC'09 (incorporated herein by reference insofar as it describes the anonymous credential scheme).

[0032] Interestingly, in one embodiment, the digital signature on the attribute message, as presented herein, includes an anonymous credential signed with the issuer private key, meaning that the anonymous credential can also be used for the system presented herein. The anonymous credential has one or more attributes of the record and a secret record identifier as an attribute. In effect, the anonymous credential is used "in reverse." Conventionally, to obtain a credential for an attribute where the user and issuer may not know the value, the user and issuer execute an issuance protocol and, in response to a request by a third party to prove the property, the user uses the issued anonymous credential. In contrast, in this case, such an issuance protocol is not required and the issuer device can give the credential directly to the selector device. Unlike the conventional case, the selector device that holds the credential is generally an intermediary not related to the credential. For example, the selector device can hold various records for various entities, such as individuals not related to the selector device. The selector device can, in that case, selectively disclose some of these records at its own will and / or show or prove the properties of the attributes. Despite these differences, interestingly, the anonymous credential is still used as a fundamental element in the current system.

[0033] In some embodiments, the digital signature scheme used for the data message is the same as that for the attribute message. For example, the digital signature for a data entry is an anonymous credential having a secret record identifier and the data entry, or a one-way function applied to the data entry as an attribute. This leads to a particularly concise design.

[0034] In various embodiments, a selector device obtains a plurality of records, such as a plurality of records from a single issuer device, a plurality of records from a plurality of issuer devices, etc. The selector device thus acts as a centralized access point for a system for providing a recipient device with access to the plurality of records, e.g., selecting data and providing it to a recipient, such as a medical researcher who wants to perform research on genomic data.

[0035] In one embodiment, an issuer device is configured to obtain a record query and select one or more of the plurality of records to be disclosed according to the record query. For example, the recipient device provides the record query, or otherwise the record query is determined separately. Generally, the record query provides one or more conditions to be satisfied as a record. For example, the issuer device selects all records that satisfy the condition, the first X records that satisfy the condition, X random records that satisfy the condition, etc. For example, the condition is a condition regarding an attribute, such as the attribute being equal to a specific value or another attribute, the attribute being within a certain range, etc. The condition can also be a condition regarding a data entry, such as the presence of a data entry containing specific data, such as a genome having a specific mutation. The issuer device then selectively discloses the attributes of each current record of the selected records, for example, by repeating for each current record of the one or more selected records the determination of the attributes to be disclosed, the provision of the attributes of the current record, and the execution of a zero-knowledge proof. In this way, the recipient device receives the records relevant to its particular use.

[0036] In one embodiment, the selector device proves to the recipient device, using zero-knowledge proof for the current record, that the current record satisfies a record query. For example, the record query includes conditions regarding attributes not provided to the recipient device, such as age > 65. The zero-knowledge proof is used to prove that such conditions are met. It is also possible to prove properties of the data entry itself that are not provided to the recipient device. Conditions regarding the disclosed attributes generally do not need to be proven in zero knowledge because the recipient knows the conditions. Also, it is not strictly necessary to prove the complete record query; for example, only the most relevant conditions of the record query are proven for efficiency reasons. Interestingly, with zero-knowledge proof, the recipient device can receive a guarantee that the records received by the recipient device satisfy the record query. For example, the age was over 65, but the details, such as the exact age, were not known. Thus, a particularly beneficial combination of data minimization and authenticity is obtained.

[0037] In one embodiment, the selector device further obtains, for example, a data entry query received from the recipient device or otherwise determined. The selector device determines one or more data entries to be disclosed according to the data entry query. For example, the data entry query specifies one or more conditions that the data entry should satisfy, such as specifying one or more specific data entries, including genomic data at a specific location. In this way, it is possible to control which data entries to provide. A similar approach is used to determine which attributes to disclose.

[0038] Of course, in order to control which records and / or which parts of the records are disclosed, using record queries and / or data entry queries does not preclude the selector device from performing a verification of the data to be disclosed to the recipient device. For example, the selector device performs a verification that the attributes of the set of records to be disclosed to the recipient device satisfy certain data minimization properties, such as privacy properties like k-anonymity.

[0039] In one embodiment, the zero-knowledge proof includes a selector device that gives the recipient device a commitment to a secret record identifier and proves knowledge of the digital signature regarding the commitment. For example, the commitment is a Pedersen-type commitment known in the art. By giving the commitment to the recipient device, the recipient device can efficiently establish that the same secret record identifier is included in each digital signature by stipulating that each of the digital signatures includes the same secret record identifier.

[0040] In one embodiment, the zero-knowledge proof is a non-interactive zero-knowledge proof determined and sent by the selector device and received and verified by the recipient device. This reduces the required communication volume and / or enables data transfer when both are not online simultaneously.

[0041] The techniques described herein are applicable in a wide range of actual application examples. Such actual application examples include platforms for providing de-identified data sets to researchers, for example, in a medical or financial context. For example, such platforms are operated by several hospitals or external service providers. More generally, any kind of application example benefits from the techniques described herein when selective disclosure of records, particularly parts of records containing flexible or large sets of data entries, is required.

[0042] Embodiments of the present method are implemented as a computer-implemented method, on a computer or in dedicated hardware, or in a combination of both. Executable code for embodiments of the present method is stored on a computer program product. Examples of computer program products include memory devices, optical storage devices, integrated circuits, servers, online software, and the like. Preferably, the computer program product includes non-transitory program code stored on a computer-readable medium for executing embodiments of the present method when the program product is executed on a computer.

[0043] In one embodiment, the computer program includes computer program code adapted to execute all steps of embodiments of the present method when the computer program is executed on a computer. Preferably, the computer program is recorded on a computer-readable medium.

[0044] Another aspect of the present invention provides a method for making a computer program downloadable. This aspect is used when the computer program is uploaded to, for example, Apple's App Store, Google's Play Store, or Microsoft's Windows Store and the computer program is downloadable from such a store.

Brief Description of the Drawings

[0045] Further details, aspects, and embodiments of the present invention will be described by way of example only, with reference to the drawings. The elements in the figures are shown for simplicity and clarity and are not necessarily drawn to scale. In the figures, elements corresponding to those already described have the same reference numerals. In the drawings,

Fig. la

Fig. lb

Fig. 2

Fig. 3

Fig. 4

Fig. 5

Fig. 6

Fig. 7

Fig. 8

Fig. 9

Explanation of Signs

[0046] 000, 100 Selective Disclosure System 010, 110, 210 Issuer Device 011, 111, 311 Selector Device 012, 112, 412 Recipient Device 130, 131, 132 Memory 140, 141, 142 Processor 150, 151, 152 Network Interface 160 Computer Network 070, 170, 270 Issuer Private Key 071, 171, 471 Issuer Public Key 072, 172, 272, 372 Record 173, 273, 373 Secret Record Identifier 174, 374, 474 Zero-Knowledge Proof 175, 275, 375 Public Record Identifier 075 Digital Signature on Disclosed Attribute Digital signatures on 180, 280, 380 property messages 081~084, 181~184, 281~282, 381~384, 483~484 properties 241 identifier generation unit 242 property signature unit 341 selection unit 342 proof unit 441 verification unit 800 computer-readable medium 810 writable portion 820 computer program 910 integrated circuit 920 processing unit 922 memory 924 application-specific integrated circuit 926 communication element 930 interconnect 940 processor system

Best Mode for Carrying Out the Invention

[0047] The present invention can be implemented in many different forms, but it should be understood that this disclosure should be regarded as an exemplification of the principles of the present invention and that the present invention is not limited to the specific embodiments illustrated and described. With this understanding, one or more specific embodiments shown in the drawings will be described in detail below.

[0048] Hereinafter, for the sake of understanding, the elements of the embodiments are described as being in operation. However, it will become apparent that the functions described as being performed by the elements are arranged so that each element performs them.

[0049] Furthermore, the present invention is not limited to the embodiments, and the present invention resides in all novel features or combinations of features described herein or in mutually different dependent claims.

[0050] FIG. la shows an example of a system 000 for selectively disclosing attributes of a record without using an attribute-based signature or zero-knowledge proof, as defined by the claims.

[0051] An issuer device 010 that desires a selector device 011, such as a genomics platform, to be able to selectively disclose a portion of a record 072 is shown in the figure. The particular record 072 shown in the figure contains values for one or more of attributes 081 - 082, such as a predefined set of phenotypic and / or genotypic data. The issuer device 010 provides the record to the selector device 011.

[0052] When the selector device 011 desires to selectively disclose a portion of the record 011 to a recipient device 012, the selector device selects one or more of attributes 081 - 082, in this case attributes 083 and 084, for disclosure to the recipient device 012. The recipient device 012 receives the attributes 083, 084 to be disclosed.

[0053] The steps up to this point provide a selective disclosure. For example, only a part of the record is obtained by the recipient device 012, but authenticity is still not provided. For example, the recipient device 012 does not obtain a guarantee that the received attributes are from the issuer device 010 that is trusted, and / or that the received attributes belong to the same record, for example, that all refer to the same person. A digital signature 075 is employed to obtain such a guarantee. The digital signature 075 in this example is a conventional signature, for example, an RSA or ECDSA signature. The notation S(X;Y) employed throughout the figures and this specification indicates a signature using the private key A on the message Y. At the time of disclosure, the issuer device 010 provides the recipient device 012, for example, prompted by the selector device 011, with a digital signature 075 signed with the issuer private key 070 on the attributes to be disclosed. The recipient device 012 verifies the digital signature 075 with respect to the issuer public key 071 corresponding to the issuer private key 070. Digital signatures generally do not involve message recovery. For example, the message does not originate from the signature. Instead, the signature and the message are verified together with respect to the public key 071.

[0054] The above system can provide selective disclosure with authenticity guarantees, but it has the undesirable property that the issuer device 010 needs to be involved in each selective disclosure. This is a burden, often costly, and sometimes not possible, for example, the issuer device 010 or its organization may no longer exist. Thus, the problem considered below is how to perform selective disclosure in a manner that has equivalent authenticity guarantees but does not require the issuer device to be involved in the selective disclosure. Another problem is that an unauthorized or careless selector device 011 can copy some of the records disclosed to 012. For example, the anonymized record 072 can be disclosed multiple times. Once anonymized, it is not possible for device 012 to verify the copy. Even if two records are identical, this can be due to anonymization. In particular, when a small number of attributes are disclosed and / or a large number of records are involved, two or more records can accidentally be quite accurately identical. Removing such identical records distorts the inferences that can be drawn from the data. However, not removing exactly the same records risks the same problem.

[0055] Figure lb schematically shows an example of an embodiment of a system 100 for selectively disclosing the attributes of record 172. System 100 includes an issuer device 100, a selector device 111, and / or a recipient device 112.

[0056] The issuer device 110 is for providing the record 172 to the selector device 111 for selective disclosure. The issuer device 110 includes a processor 130 and a memory 140. The memory 140 is used for storing data and / or instructions. For example, the memory 140 includes software and / or data configured for the processor 130 to operate thereon. The memory 140 also stores an issuer private key 170 that forms a public-private key pair using the corresponding issuer public key 171. The memory 140 also stores the record 172. The record 172 includes one or more attributes 181-182. Only by way of example, two attributes are shown. The processor 130 is implemented as one or more processor circuits, such as a microprocessor, an ASIC, an FPGA, etc. The memory 140 includes computer program instructions executable by the processor 130. The processor 130 is configured, in some cases together with the memory 140, according to one embodiment of the issuer device. The issuer device 110 also includes a communication interface 150 configured to communicate with other devices, particularly the selector device 111. For example, the communication interface includes a connector, such as a wired connector, such as an Ethernet connector, or a wireless connector, such as an antenna, such as a Wi-Fi, 4G or 5G antenna. The communication interface can also be an internal or external data storage storage interface, a keyboard, an application interface (API), etc.

[0057] The issuer device 110 is configured to determine a secret record identifier 173. The issuer device 110 is also configured to generate a digital signature 180 using the issuer private key 170 for one or more attributes 181-182 and the secret record identifier 173. For example, the processor 130 applies a signature algorithm to an attribute message including one or more attributes 181-182 and the secret record identifier 173.

[0058] The issuer device 110 is configured to provide the selector device 111 with the record 172, the secret record identifier 173, and the digital signature 180 on the attribute message.

[0059] As shown in the figures and used throughout this specification, (X;Y) is used to refer to a digital signature signed on the message Y, for example on the attribute message, using the private key A. Digital signatures generally do not involve message recovery. For example, a digital signature is verified together with the message using the public key corresponding to the private key.

[0060] The selector device 111 is configured to selectively disclose the attributes of the record 172 to the recipient device 112. The selector device 111 includes a processor 131 and a memory 141. The memory 141 is used for storing data and / or instructions. For example, the memory 141 includes software and / or data configured for the processor 131 to operate thereon. The memory 141 also stores the record 172, the secret record identifier 173, and / or the digital signature 180 on the attribute message. The processor 131 is implemented as one or more processor circuits, such as a microprocessor, an ASIC, an FPGA, etc. The memory 141 includes computer program instructions executable by the processor 131. The processor 131, optionally together with the memory 141, is configured according to an embodiment of the selector device. The selector device 111 also includes a communication interface 151 configured to communicate with other devices, particularly the issuer device 110 and the recipient device 112. For example, the communication interface includes a connector, such as a wired connector, such as an Ethernet connector, or a wireless connector, such as an antenna, such as a Wi-Fi, 4G, or 5G antenna. The communication interface can also be an internal or external data storage storage interface, a keyboard, an application interface (API), etc.

[0061] The selector device 111 is configured to obtain the record 172, the secret record identifier 173, and the digital signature 180 on the attribute message. The selector device 111 is configured to verify the digital signature 180 using the issuer public key 171. If the signature 180 is incorrect, this is not necessary because it will also become apparent when the recipient device 112 verifies the signature 180 later.

[0062] The selector device 111 is further configured to determine one or more attributes to be disclosed as a subset of the one or more attributes 181-182. By way of example only, the figure shows two attributes 183-184 to be disclosed. The selector device 111 is configured to provide the one or more attributes 183, 184 to be disclosed to the recipient device 112.

[0063] The selector device 111 is further configured to determine the public record identifier 175 from the secret record identifier 173. The public record identifier is calculated from the secret record identifier in such a way that two corresponding public record identifiers are different if and only if the two corresponding secret record identifiers are different. Thus, it can be confirmed whether an anonymized record is a copy of some other anonymized record by comparing their public record identifiers.

[0064] Interestingly, the selector device is configured to generate a public table key. Generating a public table key can be done in the same way by generating a private table key, for example, in the form of a table key pair, but this is not necessary. The public table key is associated with a specific table of attributes to be disclosed to the recipient device. It is desirable to avoid the situation where information from the same record is disclosed to this recipient device or other recipient devices at other times and the two disclosures are pieced together. For example, in the first disclosure to the first recipient device, attributes 1 and 2 are disclosed, and in the second disclosure to the second recipient device, attributes 1 and 3 are disclosed. If the two recipient devices collude there, it may be possible to reconstruct a record in which attributes 1, 2, and 3 are integrated again. As a result, privacy is violated. Such a combination of records is particularly easy if the record has a unique record identifier. To avoid this possibility, a new table key is selected for each disclosure of data that should be combinable. The public record identifier is determined from the secret record identifier and the public table key. For example, determining the public record identifier includes applying a bilinear map, for example, to the public table key and group-points according to the secret record identifier.

[0065] The public table key is provided to the recipient device. The effect of different table keys is to have the same secret record identifier have different corresponding public record identifiers in two data disclosures, thus avoiding combining data based on the public record identifier.

[0066] On the other hand, if for some reason it is desirable that replication can be confirmed across different disclosures, the table key is omitted or the same table key is used in multiple disclosures.

[0067] The selector device 111 is further configured to perform a zero - knowledge proof 174 using the recipient device 112. The zero - knowledge proof is shown here as a message sent from the selector device 111 to the recipient device 112, for example a non - interactive zero - knowledge proof, although this is not necessary, for example a zero - knowledge proof that includes a plurality of messages exchanged between parties, for example an interactive zero - knowledge proof.

[0068] As used throughout this figure and the entire specification, the notation ZK(X;Y) indicates a zero - knowledge proof that value X satisfies a certain property with respect to value Y. For example, value X is included in what is called the so - called evidence of the zero - knowledge proof. The prover generally uses value X to perform the proof, and the verifier generally uses value Y to verify the proof.

[0069] In the zero - knowledge proof, the selector device · a secret record identifier 173, · a digital signature 180 on an attribute message, which is a digital signature on a message that includes at least one or more attributes 183 - 184 to be disclosed and the secret record identifier signed with a private key corresponding to the issuer public key 171 proves knowledge of.

[0070] The recipient device 112 is configured to selectively obtain attributes 183-184 of the record 172 from the selector device 111. The recipient device 112 includes a processor 132 and a memory 142. The memory 142 is used for storing data and / or instructions. For example, the memory 142 includes software and / or data configured for the processor 132 to operate thereon. The memory 142 also stores the issuer public key 171. The processor 132 is implemented as one or more processor circuits, such as a microprocessor, ASIC, FPGA, etc. The memory 142 includes computer program instructions executable by the processor 132. The processor 132 is configured, optionally together with the memory 142, according to an embodiment of the recipient device. The recipient device 112 also includes a communication interface 152 configured to communicate with other devices, particularly the selector device 111. For example, the communication interface includes a connector, such as a wired connector, such as an Ethernet connector, or a wireless connector, such as an antenna, such as a Wi-Fi, 4G, or 5G antenna. The communication interface can also be an internal or external data storage storage interface, a keyboard, an application interface (API), etc.

[0071] The recipient device 112 is configured to obtain one or more attributes 183-184 from the selector device 111. The recipient device 112 is further configured to perform a zero-knowledge proof using the selector device 111 with respect to the obtained values 183-184 and the issuer public key 174 to confirm that the obtained values 183-184 belong to the record 172 of the issuer device 110.

[0072] The various devices of system 100 communicate with each other via computer network 160. The computer network can be the Internet, an intranet, a LAN, a WLAN, etc. The computer network 160 is the Internet. The computer network is fully or partially wired and / or fully or partially wireless. For example, the computer network has an Ethernet connection. For example, the computer network has a wireless connection such as Wi-Fi, ZigBee, etc. The computer network 160 includes additional elements such as routers, hubs.

[0073] The various devices in FIG. 1 have respective user interfaces that include well-known elements such as one or more buttons, a keyboard, a display, a touch screen, etc. For example, the user interface of the recipient device 112 is configured to coordinate user interaction to obtain a portion of a record that satisfies a particular record query.

[0074] Interestingly, system 100 achieves what system 000 cannot. The selector device 111 can anonymize records, for example, by providing only a portion of the records to the recipient device 112. Further, the recipient device can verify that a portion of the records it received actually occurred at the issuer device 110, i.e., the recipient device can verify the authenticity and integrity of the received data. Further, the recipient device 112 can verify whether any of the public record identifiers are replicated or whether any of them cannot be verified by a zero-knowledge proof, thereby verifying whether some of the anonymized records are duplicates of each other. Further, the issuer device 110 only needs to be involved at the moment it provides the data to the selector device 111. No subsequent involvement of the issuer is required to prove to the recipient device 112 the absence of authenticity, integrity, or replication.

[0075] Figure 2 schematically shows an example of an embodiment of the issuer device 210 for providing records to a selector device for selective disclosure, for use, for example, in the system 100 of FIG. 1b.

[0076] Figure 2 schematically shows functional units that can be functional units of the processor of the issuer device 210 (not shown individually). For example, Figure 2 is used as a blueprint for a possible functional composition of the processor. For example, the functional units shown in Figure 2, such as units 241-243, are stored in the device 210, for example, in the electronic memory of the device 210, and are fully or partially implemented in computer instructions executable by the microprocessor of the device 210. In hybrid embodiments, the functional units are implemented partly, for example, in hardware as a coprocessor, and partly stored in software and executed on the device 210. For purposes of detailed explanation, Figure 2 also shows various elements stored by the device 210 at various stages of operation of the device 210.

[0077] A record 272 containing one or more attributes 281-282 is shown in the figure. For example, record 272 is a genomic record. In such a case, attributes 281-282 include one or more of an individual's phenotypic attributes, such as age, BMI, flags indicating a diagnosis of one or more symptoms, etc. In this example, the attributes are integers or other types of values encoded as integers. The integers are generally from the range 0,..., N-1, where the value N is defined by the signature scheme used, for example, as described below.

[0078] Instead of directly coding information into the attributes, a hash of the information in the attributes is encoded. This works similarly, except that the information can be disclosed if it is included in the disclosed part of the attribute. The recipient device then calculates the hash from the information and calculates that the signature was indeed calculated for the correct hash. In this case, the hash functions as the disclosed attribute.

[0079] An alternative way to link a larger amount of data is to include the data in a separate message, such as a data message. The data message is then signed and linked to a secret record identifier. The zero-knowledge proof is then extended when proving that the signature for the data message is indeed linked to the secret record identifier corresponding to the public record identifier. This is a different type of signature S2 than the signature S1 used for attributes.

[0080] As an example to illustrate, a larger amount of data that can be conveniently included in either of the two above-described manners is genomic information. For example, the data entry of record 272 represents a single nucleotide polymorphism (SNP) of a human genome. For example, record 272 is drawn from a variant call format (VCF) file or is encoded by a variant call format file. As is known in bioinformatics, VCF files are used to store gene sequence variations with respect to a reference genome. Optionally, the VCF file can also store phenotypic information. A portion of the VCF file is shown below.

[0081]

Table 1

[0082] For example, in the case of a record corresponding to a VCF file as exemplified above, the data entry of the record corresponds to a row of the VCF file. For example, the data entry is a string representing one row of the VCF file. The hash of the VCF file is included as an attribute. Alternatively, the VCF file can be signed and linked to a secret record identifier.

[0083] The identifier generation unit 241 is further shown in the figure. The identifier generation unit 241 generates a secret record identifier 273. Generally, the secret record identifier 273 is an integer from the same range 0,..., N - 1 as the attributes 281-282, for example. It is beneficial to generate the secret record identifier 273 randomly from a large domain and to minimize the probability of collisions between identifiers generated by other devices, for example. For example, the identifier generation unit 241 generates the secret record identifier 273 randomly from at least 2 30 pieces, at least 2 62 pieces, or 2 126 possible values.

[0084] The issuer private key 270, which is generated by the issuer device 210 or otherwise obtained separately, is also shown. The issuer private key 270 can be any kind of private key that is compatible with the digital signature scheme used to generate the digital signature 280 described below.

[0085] The attribute signature unit 242 is further shown. The attribute signature unit 242 generates a digital signature 280 on the attribute message using the issuer private key 270. The attribute message includes one or more attributes 281-282 and the secret record identifier 273. As explained elsewhere, in principle any signature scheme S1 can be used, but it is particularly beneficial for the digital signature 280 to be an anonymous credential, in other words, for the signature generation to be an algorithm for generating an anonymous credential. The secret record identifier 273 is used as an attribute of the anonymous credential.

[0086] As a specific example, the anonymous credential scheme is as follows. Given an ordered list of attributes m, the signature is a quadruple (c, s, γ, σ), and the attribute signature unit 242 randomly generates the values c, s, and γ, and σ is

Number

Number

Number

[0087] The issuer device 210 further provides the selector device with the record 272, the secret record identifier 273, and the digital signature 280 on the attribute message, for example, sending them via a communication interface (not shown).

[0088] So far, the signature process has been described for a single record 272. The same units 241 - 243 are also used to generate respective secret identifiers and sets of signatures for multiple records. The issuer device 210 also updates the attributes of the records by appropriately determining new attribute message signatures for units 242, 243. If individual data, such as genomic information, is used, these are provided to the selector in the same way.

[0089] FIG. 3 schematically shows an example of an embodiment of a selector device 311 for selectively disclosing attributes of a record 372 for use, for example, in the system 100 of FIG. 1b, to a recipient device.

[0090] FIG. 3 schematically shows functional units (not shown individually) that can be functional units of a processor of the selector device 311. For example, FIG. 3 is used as a blueprint of a possible functional organization of the processor. For example, the functional units shown in FIG. 3, such as units 341-342, are stored in the device 311, for example, in the electronic memory of the device 311, and are fully or partially implemented in computer instructions executable by the microprocessor of the device 311. In a hybrid embodiment, the functional units are partially implemented in hardware, for example, as a coprocessor, and partially stored in software and executed on the device 311. For the sake of detailed explanation, FIG. 3 also shows various elements stored by the device 311 at various stages of the operation of the device 311.

[0091] A record 372 including one or more attributes 381-382, a secret record identifier 370, and a digital signature 380 on an attribute message generated using an issuer private key are shown in the figure, and the attribute message includes one or more attributes 381-382 and the secret record identifier 370. For example, the record, the secret record identifier, and the digital signature correspond to those in FIG. 2. For example, this data is obtained from the issuer device.

[0092] Also shown is a selection unit 341. The selection unit 341 determines one or more attributes to be disclosed to the recipient device as a subset of one or more attributes 381-382. In this particular example, attributes 383, 384 are selected. The attributes to be disclosed are determined, for example, based on a data entry query provided by the recipient device. For example, the data entry query indicates a specific data entry and / or criteria for selecting the data entry to be disclosed, as well as criteria for the attributes as well. The selection unit 341 further performs selections based on criteria and / or management not provided by the recipient device, such as those provided by the issuer device along with the record, for example, based on a privacy policy.

[0093] For example, record 372 may contain information that identifies an individual, such as data that can potentially be used to identify a specific individual. Examples include full name, social security number, driver's license number, bank account number, passport number, and e-mail address. Such information is removed from record 372 before sending the information to the recipient device. Record 372 may also contain attributes that do not directly identify an individual but nevertheless require privacy attention, such as age, weight, etc. If such information is not required, sending these attributes to the receiving device can be avoided.

[0094] A proof unit 342 is further shown. The proof unit 342 performs a zero-knowledge proof 374 using the recipient device. Known in cryptography, and as explained elsewhere, a zero-knowledge proof is for proving a statement to a verifier by a prover. The zero-knowledge proof preferably satisfies the properties of completeness, soundness, and zero-knowledge.

[0095] Completeness means that when the statement is true, a prover following the protocol convinces a verifier following the protocol. Soundness means that when the statement is false, there is no chance that a cheating prover can convince a verifier following the protocol. In the case of a proof of knowledge, completeness also means that not only is the statement true, but the prover knows a specific value called the witness that appears in the statement. Completeness is generally valid up to a certain soundness error where a cheating verifier succeeds in convincing the verifier. However, zero-knowledge proofs include multiple instances of the protocol to reduce the soundness error. Zero-knowledge means that the verifier learns no information from the proof other than the fact that the statement is true. Zero-knowledge is computational and / or statistical.

[0096] In this case, the selector device secret record identifier 373, digital signature 380 on the attribute message, which is a digital signature on a message containing at least one or more attributes 383, 384 to be disclosed and the secret record identifier 373 signed with the private key corresponding to the issuer's public key uses a zero-knowledge proof 374 to prove knowledge of. In other words, the witness of the zero-knowledge proof includes the secret record identifier and the signature, and the public values whose validity has been proven include the attributes 383, 384, and the issuer's public key.

[0097] In particular, to prove that the signature 380 includes the secret record identifier 373 without disclosing the secret record identifier to the recipient device, the proof unit 342 constructs a commitment to the secret record identifier, such as a Pedersen-type commitment, and gives it to the recipient device. Thus, the zero-knowledge proof 374 proves that the same secret record identifier 373 is included in each signature and in the commitment. For various types of zero-knowledge proofs and signature schemes, this is an efficient way to prove the existence of a common secret identifier.

[0098] There are many different types of zero-knowledge proofs, such as Σ protocols like the Schnorr protocol, non-interactive zero-knowledge proofs obtained from interactive zero-knowledge protocols by heuristics like the Fiat-Shamir heuristic, succinct non-interactive arguments of knowledge (zk-SNARKs), etc., which are known in the art and can be easily applied.

[0099] However, it is particularly beneficial when a signature scheme S1 for attributes that admits an efficient proof of knowledge of the signature is used instead of relying on general techniques. For example, basing the signature scheme S1 on an anonymous credential scheme, such as the one by Camenisch et al. described above, can be beneficial as they admit efficient zero-knowledge proofs. For example, the use of signatures based on the principle of exponentiating group elements is also particularly efficient in this case as it admits efficient zero-knowledge proofs.

[0100] Next, a particularly beneficial implementation based on attribute signature 380 will be described in detail. As described in "An Accumulator Based on Bilinear Maps and Efficient Revocation for Anonymous Credentials" by J. Camenisch et al., presented in the proceedings of PKC’09, the Camenisch-Stadler notation is used. Attribute signature 380 has the

Number

[0101] It should be noted that zero-knowledge proofs can be made non-interactively, for example using the Fiat-Shamir heuristic, but are presented here as interactive proofs. The proofs can also be extended to prove properties about attribute values, for example to prove that a record satisfies a record query, such as 30 < BMI < 40. Proofs for multiple records can also be performed in parallel and / or combined into one non-interactive zero-knowledge proof using known techniques.

[0102] Specifically, in this example, the proof unit 342 calculates a public record identifier for record m. For example, a secret table key a is selected and the public table key K = h a is calculated for the table. The public / secret table key pair is unique for this particular table. The public table key can also be selected as a random point in G by other means, for example by randomly generating the coefficients of a point, for example by hashing a phrase, for example a public phrase. For each column of the anonymized dataset, the creator then generates a unique public record identifier ID as follows,

Number

Number

Number

Number

Number

[0103] In the first part of the zero-knowledge proof, the proof unit 342 includes one or more attributes to be disclosed and a secret record identifier corresponding to the commitment X described above, and proves the knowledge of the signature 380 as a signature on a message signed with the private key x corresponding to the public key y = h x corresponding to mult = ρc, and setting tmp = open·c, the first part of the zero-knowledge proof is used to prove the following.

Number

[0104] Here,

Number

Number

Number

[0105] In the second part of the zero-knowledge proof, for example

Number

[0106] The effect of the commitment is that even if the corresponding data is blinded from the receiving device, the selector device is still set to a specific value of the underlying data. The commitment does not need to be made public. In the above, e is used to denote a cryptographic pairing known in the art, such as a Type 3 elliptic curve pairing such as a pairing on a 256-bit Barreto-Naehrig (BN) curve. The pairing on the BN curve is formally shown as follows, [Number] . The various generators used above, such as the generator of H, the introduced generator h, etc., are generators of G1 generated by the nothing-up-my-sleeves method, such as hashing the base generator of G1 until a point is encountered.

[0107] In a further zero-knowledge proof, [Number] it is possible to clearly prove that it is so, for example, the knowledge of the secret identifier in the commitment X is proved. Interestingly, since X is also used in the second part of the above zero-knowledge proof, this is not essential. The above proof is based on a Schnorr proof system such as that disclosed in U.S. Patent Application No. US4995082A. Interestingly, the above proof deviates from Camenisch's zero-knowledge proof.

[0108] The above procedure has been described for a single record, but it will be understood that the selector device 311 can be easily adapted when storing multiple records and related information from, for example, multiple issuer devices. In this way, the selector device 311 also selectively discloses a portion of the multiple records. For example, as described elsewhere, the selector device 311 obtains a record query and selects one or more of the multiple records according to the record query. The steps performed by units 341 and 342 are repeated for each selected record, and selective disclosure is performed for each record.

[0109] Interestingly, zero-knowledge proofs for records can also be used to prove that the current record satisfies the record query. For example, the record query includes conditions regarding attributes, such as age > 65, 40 < age < 65, etc. For example, in certain cases where the Camenisch anonymous credential adapted as signature 380 is used, well-known techniques for proving properties regarding the attributes of such a credential are readily used.

[0110] FIG. 4 schematically shows an example of an embodiment of the recipient device 412 for selectively obtaining the attributes of a record from a selector device, for use, for example, in the system 100 of FIG. 1b.

[0111] FIG. 4 schematically shows functional units (not shown individually) that are functional units of the processor of the recipient device 412. For example, FIG. 4 is used as a blueprint of a possible functional organization of the processor. For example, the functional units shown in FIG. 4, such as unit 441, are stored in the device 412, for example, in the electronic memory of the device 412, and are implemented in whole or in part in computer instructions executable by the microprocessor of the device 412. In hybrid embodiments, the functional units are implemented partially in hardware, for example, as a coprocessor, and are stored partially in software and executed on the device 412. For purposes of detailed explanation, FIG. 4 also shows various elements stored by the device 412 at various stages of its operation.

[0112] The issuer public key 471 stored in the memory of the recipient device 412 is shown in the figure. The authenticity of a part of the record is established with respect to this public key. In this example, two of the attributes 483, 484 of the record are further shown. The recipient device 412 receives this information from the selector device as described elsewhere.

[0113] The verification unit 441 is also shown in the figure. The verification unit 441 performs a zero-knowledge proof using the selector device with respect to the obtained values 483, 484 and the issuer public key 471. Here, a non-interactive zero-knowledge proof 474 is shown in which the verification unit 441 verifies non-interactively, but the proof is not so, for example, a proof request is generated using the verification unit 441 and given to the selector device, which is also interactive. The proof is, as described, from the perspective of the prover, with respect to the selector device 311. The proof 474 confirms that the obtained values 483 to 484 belong to the record of the issuer device corresponding to the issuer public key 481. Thus, the selector device proves that the knowledge of the secret record identifier, i.e., the digital signature on the message, includes at least one or more attributes 483 to 484 to be disclosed and the secret record identifier signed with the private key corresponding to the issuer public key 471.

[0114] The verification of zero - knowledge proofs is performed in correspondence with a zero - knowledge proof system used by the selector device to prove the statements described above. In this particular example, as described above, proofs in multiple parts described with respect to the selector device 311 can be used. For example, the recipient device 412 receives a commitment from the selector device to a secret identifier. The selector device, as described above, in that case, proves the knowledge of a secret record identifier, and a signature on attributes 483 - 484, which is verified by the verification unit 441.

[0115] Although not explicitly shown in the figure, as previously explained, the selective disclosure techniques described herein are, in some cases, applied to multiple records from different issuer devices, and in that case, the verification unit 442 repeats the above - described procedure for each disclosed record. The recipient device also provides a record query to the recipient device to affect which records are retrieved.

[0116] Thus, by the various means described above, the recipient device 412 obtains appropriate authenticity guarantees regarding the information it needs, such as attributes 483, 484, and public key 471, without requiring access to other confidential data such as non - disclosed attributes, secret record identifiers, or issuer private keys.

[0117] The verification unit 441 is further configured to identify whether two or more received public record identifiers are repeated. If the recipient device 412 receives two anonymized records with the same public record identifier calculated using the same public table key (if used), the corresponding secret record identifiers were also equal. At this point, a warning is generated and / or the operation is interrupted.

[0118] After verification, the researchers can use the disclosed attributes, but do not have access to non - disclosed attributes, such as privacy - confidential information.

[0119] The following gives an overview of certain efficient embodiments. However, note that zero-knowledge protocols can be similarly constructed for other types of signatures. In certain embodiments,

[0120] the issuer has a private key with public key y = h x Data is represented in the form of a plurality of records, for example, a vector m containing attributes m i For each vector, the signature is computed by randomly selecting the values c, s, and y, where the latter is the secret record identifier. The attribute signature has the following form. [Number]

[0121] where h, [Number] and [Number] Similar to h, i H is a set of generators h of a group G of prime order q. The signature for the vector m is represented as a tuple of four values (c, s, y, σ). The issuer provides the selector with the vector m, the corresponding signature including the secret record identifier, and the public key y.

[0122] The selector computes the public record identifier for the vector m. For example, for a table, a private table key a is selected and the public table key K = h a is computed. The public / private table key pair is unique for this particular table, for example, for the present disclosure of data to a recipient device. For each record, the selector then generates a unique public record identifier ID as follows. [Number]

[0123] The selector forwards some, but not all, of the attributes to the recipient, and forwards the public record identifier ID. To prove provenance, the following protocol is executed. The selector, e.g., the proof unit 342, generates random blinding values p, t, and open, and computes the values mult = pc, and tmp = open·c. The proof unit 342 constructs the following commitments to be sent to the recipient device.

Number

Number

Number

Number

[0124] The proof unit 342 then uses the verifier for a zero-knowledge proof of knowledge of the values s, s, u, p, t, open, mult, tmp, m l ,..., m n .

[0125] The first part of the zero-knowledge proof is used to prove the following.

Number

Number

Number

[0126] Here, H1 corresponds to the disclosed attributes, H2 corresponds to the non-disclosed attributes, and together H1 ∪ H2 = H. Note that the attributes may optionally be encoded as a hash, for example, in a proof and / or signature. The latter is convenient when the attributes can be large. The values y, h, h i ,

Number

Number

[0127] Surprisingly, the above proof is formulated as a proof of exponential knowledge that simultaneously obtains known values from known bottoms. This is proven using the Schnorr protocol. The bilinear map e is, for example, by a so-called type-1 bilinear map, or a type-3 bilinear map, etc.

[0128] This system is extended using individual signatures for data entries. For example, in one embodiment of system 100 for selectively disclosing attributes, a record contains multiple data entries. This extension is optional. The issuer's processor is a device configured to generate multiple digital signatures on multiple data messages for multiple data entries using a data message for a data entry that includes the issuer private key, the data entry, and a secret record identifier. The digital signature on the data message is provided to the selector device. The processor of the selector device is configured to determine one or more data entries to be disclosed as a subset of the multiple data entries. A zero-knowledge proof of the selector and the recipient device proves that the digital signature on the data message for the data entry to be disclosed is the digital signature on a message that includes the data entry to be disclosed, each including a secret record identifier, and is signed using a private key corresponding to the issuer public key. In one embodiment, the processor of the issuer device calculates, for example, g 1 / (x+γ+H(m)) the inverse power of the value (x + g + H(m)) of the group element g to generate a digital signature on a data message such as. The value is based on at least the issuer private key x, the secret record identifier γ, and the data entry m. However, other digital signatures may also be used.

[0129] Figure 5 schematically shows an example of an embodiment of an issuer method 500 that provides a record for selective disclosure to a selector device. Method 500 is generally computer-implemented.

[0130] Issuer method 500 includes storing 510 an issuer private key that forms a public key-private key pair using the corresponding issuer public key, and a record that includes one or more attributes.

[0131] Publisher method 500 includes determining 520 a secret record identifier.

[0132] The issuer method 500 includes generating a digital signature on the attribute message using the issuer private key, where the attribute message includes one or more attributes and a secret record identifier.

[0133] The issuer method 500 includes providing the selector device with a record, a secret record identifier, a digital signature on the attribute message, and a digital signature on the data message.

[0134] FIG. 6 schematically shows an example of an embodiment of a selector method 600 for selectively disclosing the attributes of a record to a recipient device. The method 600 is generally computer-implemented.

[0135] The selector method 600 includes storing a record that includes one or more attributes, a secret record identifier, a digital signature on an attribute message generated using the issuer private key, where the attribute message includes one or more attributes and the secret record identifier, and a digital signature on a data message and the secret record identifier generated using the issuer private key.

[0136] The selector method 600 includes obtaining a record, a secret record identifier, a digital signature on the attribute message, and a digital signature on the data message.

[0137] The selector method 600 includes determining one or more attributes to be disclosed as a subset of the one or more attributes.

[0138] The selector method 600 includes determining a public record identifier from the secret record identifier.

[0139] The selector method 600 includes providing the recipient device with the one or more attributes to be disclosed.

[0140] The selector method 600 includes performing a zero-knowledge proof using the recipient device 650, · A secret record identifier, · The knowledge of the digital signature on the attribute message is proved, which is a digital signature on a message signed with a private key corresponding to the issuer's public key and including at least one or more attributes to be disclosed and the secret record identifier.

[0141] FIG. 7 schematically shows an example of an embodiment of a recipient method 700 for selectively obtaining attributes of a record from a selector device. The method 700 is generally computer-implemented.

[0142] The recipient method 700 includes storing the issuer's public key 710.

[0143] The recipient method 700 includes obtaining one or more attributes from the selector device 720.

[0144] The recipient method 700 includes performing a zero-knowledge proof using the selector device with respect to the obtained value and the issuer's public key to confirm that the obtained value belongs to the record of the issuer device corresponding to the issuer's public key. The selector device · A secret record identifier, · A digital signature on a message including at least one or more attributes to be disclosed and the secret record identifier and signed with a private key corresponding to the issuer's public key proves the knowledge of.

[0145] As will be apparent to those skilled in the art, many different ways of implementing this method are possible. For example, the order of steps can be changed and some steps can be performed in parallel. Additionally, steps from other methods can be inserted between steps. The inserted steps may represent improvements to the method as described herein or may be unrelated to the method. For example, some steps can be performed at least partially in parallel. Further, a given step may not be fully completed before the next step is started.

[0146] Embodiments of the method are implemented using software that includes instructions for causing a processor system to execute method 500, 600, or 700. The software may include only those steps performed by specific sub-entities of the system. The software can be stored on a suitable storage medium such as a hard disk, floppy disk, memory, optical disk, etc. The software can be sent as a signal over a wire, wirelessly, or using a data network such as the Internet. The software is enabled for download and / or remote use on a server. Embodiments of the method are implemented using a bitstream programmed to design programmable logic such as a field programmable gate array (FPGA) to perform the method.

[0147] It should be understood that the present invention also extends to a computer program adapted to carry out the present invention, in particular a computer program on or in a carrier. The program may be in the form of object code, such as source code, object code, intermediate source code, and partially compiled form, or any other form suitable for use in implementing embodiments of the method. Embodiments relating to computer program products include computer-executable instructions corresponding to each of at least one of the processing steps of the methods described. These instructions are subdivided into subroutines and / or stored in one or more files linked statically or dynamically. Another embodiment relating to computer program products includes computer-executable instructions corresponding to each of at least one of the means of the systems and / or products described.

[0148] FIG. 8 shows a computer-readable medium 800 having a writable portion 810 that includes a computer program 820, the computer program 820 including instructions for causing a processor system to execute an issuer method, a selector method, or a recipient method, according to an embodiment. The computer program 820 is recorded on the computer-readable medium 800 as a physical trace or by magnetization. However, any other suitable embodiment is equally conceivable. Further, although the computer-readable medium 800 is shown here as an optical disk, it should be understood that the computer-readable medium 800 can be any suitable computer-readable medium that is non-recordable or recordable, such as a hard disk, solid state memory, flash memory, etc. The computer program 820 includes instructions for causing a processor system to execute one or the aforementioned methods.

[0149] FIG. 9 shows a schematic illustration of a processor system 940 according to an embodiment. The processor system includes one or more integrated circuits 910. The architecture of the one or more integrated circuits 910 is schematically shown in FIG. 7b. The circuit 910 includes a processing unit 920, such as a CPU, for executing computer program components for performing the method according to an embodiment and / or for implementing modules or units thereof. The circuit 910 includes a memory 922 for storing programming code, data, and the like. A part of the memory 922 is read-only. The circuit 910 includes a communication element 926, such as an antenna, a connector, or both. The circuit 910 includes an application-specific integrated circuit 924 for performing some or all of the processing defined in the present method. The processor 920, the memory 922, the application-specific IC 924, and the communication element 926 are connected to each other via an interconnect 930, such as a bus. The processor system 910 is configured for contact and / or non-contact communication using an antenna and / or a connector, respectively.

[0150] For example, in one embodiment, the processor system 940, such as an issuer device, a selector device, or a receiver device, includes a processor circuit and a memory circuit, and the processor is configured to execute software stored in the memory circuit. For example, the processor circuit can be an Intel Core i7 processor, an ARM Cortex-R8, or the like. In one embodiment, the processor circuit can be an ARM Cortex M0. The memory circuit can be a ROM circuit or a non-volatile memory, such as a flash memory. The memory circuit can be a volatile memory, such as an SRAM memory. In the latter case, the device includes a non-volatile software interface, such as a hard drive, a network interface, or the like, configured to provide software.

[0151] Generally, each device comprises a microprocessor that executes appropriate software stored in the device. For example, the software is downloaded and / or stored in a corresponding memory, such as volatile memory like RAM or non-volatile memory like flash. Alternatively, the device is implemented wholly or partly in programmable logic, such as a field-programmable gate array (FPGA). The device is implemented wholly or partly as a so-called application-specific integrated circuit (ASIC), such as an integrated circuit (IC) customized for those specific applications. For example, the circuit is implemented in CMOS using a hardware description language such as Verilog, VHDL, etc.

[0152] In one embodiment, the issuer device comprises an identifier generation circuit and an attribute signature circuit. In one embodiment, the selector device comprises a selection circuit and a proof circuit. In one embodiment, the receiver device comprises a verification circuit. The device may comprise additional circuits. The circuit implements the corresponding unit described herein. The circuit is a processor circuit and a storage circuit, and the processor circuit executes instructions electronically represented in the storage circuit. The processor circuit is implemented in a distributed manner, for example, as a plurality of sub-processor circuits. A part of the storage may be read-only. The circuit may also be an FPGA, an ASIC, etc. The storage may be distributed over a plurality of distributed sub-storages. Part or all of the memory may be electronic memory, magnetic memory, etc. For example, the storage may have volatile and non-volatile parts.

[0153] It should be noted that the above embodiments do not limit the present invention but illustrate it, and those skilled in the art can design many alternative embodiments.

[0154] In the claims, reference signs placed between parentheses shall not be construed as limiting the claims. The use of the verb "comprise" and its conjugations does not exclude the presence of elements or steps other than those described in the claims. The singular form does not exclude the presence of a plurality of such elements. The present invention is implemented by means of hardware including several distinct elements and by means of a computer suitably programmed. In device claims enumerating several means, several of these means may be embodied by one and the same item of hardware. The mere fact that a particular means is recited repeatedly in mutually different dependent claims does not indicate that a combination of these means cannot advantageously be used.

[0155] In the claims, references within parentheses refer to reference signs in the drawings of the exemplary embodiments or to the formulae of the embodiments and thus enhance the clarity of the claims. These references shall not be construed as limiting the claims.

Claims

1. A system for selectively disclosing attributes of a record, the system comprising an issuer device, a selector device, and a recipient device, wherein the issuer device is for providing a record to the selector device for selective disclosure, and the issuer device stores an issuer private key that forms a public key-private key pair with a corresponding issuer public key, the record including one or more attributes, in a memory, determines a secret record identifier, generates a digital signature for the one or more attributes and the secret record identifier using the issuer private key, and provides the record, the secret record identifier, and the digital signature to the selector device, and a processor for performing the above, and is provided with, wherein the selector device is for selectively disclosing the attributes of the record to the recipient device, and the selector device stores the record, the secret record identifier, and the digital signature, in a memory, determines one or more attributes to be disclosed as a subset of the one or more attributes, determines a public record identifier from the secret record identifier, provides the one or more attributes to be disclosed and the public record identifier to the recipient device, and performs a zero-knowledge proof using the recipient device, the zero-knowledge proof being that the selector device has knowledge of the secret record identifier corresponding to the public record identifier and the digital signature on at least the one or more attributes to be disclosed and the secret record identifier, signed with a private key corresponding to the issuer public key, generated by the issuer device for the one or more attributes and the secret record identifier, and performs the zero-knowledge proof to prove such knowledge, and a processor for performing the above, and is provided with, wherein the recipient device is for selectively obtaining the attributes of the record from the selector device, and the recipient device stores the issuer public key in a memory, and obtains the one or more attributes determined to be disclosed and the public record identifier from the selector device. To confirm that the obtained attribute belongs to the record of the issuer device, perform the zero-knowledge proof using the selector device for the obtained attribute and the issuer public key, and A processor for performing A system comprising.

2. The system according to claim 1, wherein the attribute includes one or more medical attributes about an individual.

3. An issuer device for providing a record to a selector device for selective disclosure, wherein the issuer device An issuer private key that forms a public key-private key pair with a corresponding issuer public key, and The record including one or more attributes A memory for storing Determining a secret record identifier for use in the selective disclosure by the selector device, and Generating a digital signature for use in the selective disclosure by the selector device, wherein the digital signature is generated for the one or more attributes and the secret record identifier using the issuer private key, and in the selective disclosure, the selector device determines a public record identifier from the secret record identifier and provides a subset of the public record identifier and the one or more attributes to the recipient device without disclosing the secret record identifier or the digital signature, generating Providing the record, the secret record identifier, and the digital signature A processor for performing An issuer device comprising.

4. The issuer device according to claim 3, wherein the digital signature includes an anonymous credential signed with the issuer private key, the anonymous credential having the one or more attributes, and the secret record identifier as an attribute.

5. A selector device for selectively disclosing the attributes of a record to a recipient device, wherein the selector device A memory for storing the record including one or more attributes, a secret record identifier, and a digital signature for the one or more attributes and the secret record identifier generated using an issuer private key And Obtaining the record, the secret record identifier, and the digital signature for the one or more attributes and the secret record identifier Determining one or more attributes to be disclosed as a subset of the one or more attributes Determining a public record identifier from the secret record identifier Providing the one or more attributes to be disclosed and the public record identifier to the recipient device Performing a zero-knowledge proof using the recipient device, the zero-knowledge proof being that the selector device The secret record identifier corresponding to the public record identifier, and A digital signature on at least the one or more attributes to be disclosed and the secret record identifier, signed with a private key corresponding to the issuer public key, the digital signature being generated for the one or more attributes using the issuer private key Performing the zero-knowledge proof that proves knowledge of A processor for performing A selector device comprising

6. The memory stores a plurality of records, and the processor Repeats the determining, the providing, and the performing of the zero-knowledge proof for one or more selected records among the plurality of records. The selector device according to claim 5

7. The memory stores a plurality of records, and the processor Obtaining a record query, and Selecting one or more of the plurality of records according to the record query The selector device according to claim 6, which performs

8. The processor performs a zero-knowledge proof on the record to further prove that the record of the one or more selected records satisfies the record query. The selector device according to claim 7

9. The processor generates a public table key, the public record identifier is determined from the secret record identifier and the public table key, and the public table key is provided to the recipient device. The selector device according to any one of claims 6 to 8

10. Performing the zero-knowledge proof includes providing a commitment to the secret record identifier to the recipient device and proving knowledge of the digital signature regarding the commitment. The selector device according to claim 8 or 9

11. A recipient device that selectively obtains record attributes from a selector device, wherein the recipient device stores an issuer public key in a memory; obtains one or more attributes and a public record identifier determined to be disclosed from the selector device; performs a zero-knowledge proof using the selector device with respect to the obtained attributes and the issuer public key to confirm that the obtained attributes belong to a record of an issuer device corresponding to the issuer public key, wherein the zero-knowledge proof is such that the selector device has knowledge of a secret record identifier corresponding to the public record identifier; and a digital signature for at least the one or more attributes to be disclosed and the secret record identifier, signed with a private key corresponding to the issuer public key; and performs the zero-knowledge proof that proves the knowledge; A processor that performs the above; A recipient device comprising the above.

12. The recipient device according to claim 11, wherein the zero-knowledge proof is performed by obtaining a non-interactive zero-knowledge proof from the selector device and verifying the non-interactive zero-knowledge proof.

13. The recipient device according to claim 11 or 12, wherein obtaining the one or more attributes and the public record identifier determined to be disclosed and performing the zero-knowledge proof are repeated for a plurality of records.

14. The recipient device according to claim 13, wherein the processor identifies whether two or more received public record identifiers are repeated.

15. An issuer method for providing records to a selector device for selective disclosure, the issuer method forming a public key-private key pair with a corresponding issuer public key using an issuer private key; storing the record including one or more attributes; and determining a secret record identifier for use in the selective disclosure by the selector device. ​ A step of generating a digital signature for use in the selective disclosure by the selector device, wherein the digital signature is generated for the one or more attributes and the secret record identifier using the issuer private key, and in the selective disclosure, the selector device determines a public record identifier from the secret record identifier and provides a subset of the public record identifier and the one or more attributes to a recipient device without disclosing the secret record identifier or the digital signature, the step of generating; The step of providing the record, the secret record identifier, and the digital signature for the one or more attributes and the secret record identifier; An issuer method having the above.

16. A selector method for selectively disclosing attributes of a record to a recipient device, the selector method comprising: Storing the record including one or more attributes, a secret record identifier, and a digital signature generated using an issuer private key for the one or more attributes and the secret record identifier; The step of storing; The step of obtaining the record, the secret record identifier, and the digital signature; The step of determining one or more attributes to be disclosed as a subset of the one or more attributes; The step of determining a public record identifier from the secret record identifier; The step of providing the one or more attributes to be disclosed to the recipient device; The step of performing a zero-knowledge proof using the recipient device, the zero-knowledge proof being: The secret record identifier corresponding to the public record identifier; The digital signature generated for the one or more attributes using the issuer private key, which is a digital signature for at least the one or more attributes to be disclosed and the secret record identifier, signed using a private key corresponding to the issuer public key; The step of performing the zero-knowledge proof in which knowledge of the above is proved; A selector method having the above.

17. A recipient method for selectively obtaining attributes of a record from a selector device, the recipient method comprising: The step of storing an issuer public key; The step of obtaining one or more attributes from the selector device; To confirm that the obtained attribute belongs to the record of the issuer device corresponding to the issuer public key, for the obtained attribute and the issuer public key, performing a zero-knowledge proof using the selector device, wherein the zero-knowledge proof is that the selector device proves knowledge of a secret record identifier corresponding to a public record identifier and a digital signature for at least one or more attributes to be disclosed and the secret record identifier, signed with a private key corresponding to the issuer public key and performing the zero-knowledge proof. A method for a recipient, comprising the steps. **Claim 18** A computer-readable storage medium containing non-transitory data representing instructions for causing a processor system to execute the method according to any one of claims 15 to 17.

Citation Information

Patent Citations

  • Method for digital signiture

    JP1997171349A

  • Attribute certification program and device

    JP2002215027A

  • Information anonymization method, information anonymization processing device, and anonymized information operation system

    JP2017091185A

  • Data Perturbation and Anonymization Using One Way Hash

    US20120303616A1

  • Attributes in cryptographic credentials

    US20120324231A1