Authentication of the identity or quality of a user
The method addresses privacy concerns in digital identity management by using a blind signature mechanism for selective identity element certification, reducing computation and storage burdens while protecting user privacy.
Patent Information
- Application Number
- PCT/EP2024/083634
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-12
- Filing Date
- 2024-11-26
- Publication Date
- 2025-06-19
AI Technical Summary
Existing digital identity management systems, such as Federated Identity, compromise user privacy as the identity provider can track access history and service consumption, which may be used for commercial purposes.
A method that allows users to selectively certify specific identity elements using a blind signature mechanism, enabling users to request authentication for only the necessary identity elements without revealing the entire set to the authentication device.
This approach reduces computation time for deriving access tokens by a linear factor, enhances user privacy by preventing identity providers from deducing service usage, and optimizes storage resources by minimizing the number of tokens stored on user devices.
Smart Images

Figure EP2024083634_19062025_PF_FP_ABST
Abstract
Description
[0001]Description Authentication of the identity or quality of a user Prior art The invention lies in the field of digital identity management. More specifically, the invention relates to a method for managing digital identity that preserves the privacy of users, in which an identity provider provides a user with a certification of one or more identity elements specific to this user, this or these identity elements belonging to a set of identity elements of the user that is available from said identity provider. Many service providers, online or in a face-to-face relationship with the user, require the provision of identity elements of the user, more generally in order to deliver their service. Traditionally, in a non-digital world,This provision of identity elements is carried out using (physical) documents issued by official authorities (identity cards, driving licenses, etc.) and supporting documents issued by recognized third-party certifiers (electricity bill, telecom bill, medical certificate, etc.). The development of services accessible via the Internet requires the implementation of dedicated tools allowing the digitization of the elements present on the aforementioned media, possibly in a structured manner and authorizing their sharing with the service provider, after consent from the user. The major prescribers on the Internet have until now structured the field of digital identity management in line with their business model. For example, through the OIDC protocol (in English "OpenID Connect"), they have developed an offer which centralizes the user's identity elements and, under their control,after identification / authentication and consent of the user, authorizes the service's access to all or part of the user's identity elements. One of the main problems with this type of architecture, known as Federated Identity, is that the identity provider learns, each time a user consumes one of the services, when the operation takes place and which identity elements the user shares with the service provider they are accessing. The identity provider is thus able to compile the history of the user's access activities and identity elements required by the various services they have visited. This data then allows it to build a profile of the user's service consumption with the service providers and to use it for often commercial purposes. Self-sovereign identity (SSI) is another approach to digital identity,which gives users full control over their identity elements: they can present them when accessing a service either to prove who they are or one of their qualities. Only the service provider and the user interact during the identity element sharing phase. In order to generate trust between the user and the service, the user presents identity elements that have been certified by a third party (the identity provider) that the service provider trusts. In this logic, the user holds identity elements concerning him, which have been issued and certified by one or more trusted entities,controls their dissemination to the service provider (after consent) and protects his privacy vis-à-vis the identity provider by excluding him from the relationship he has with the service provider. Self-sovereign identity is based on the implementation of an asynchronous authentication scheme for a user's identity elements, which scheme operates according to a particular protocol, for example the El Passo protocol as described at https: / / arxiv.org / pdf / 2002.10289.pdf, the BBS+ protocol as described at https: / / identity.foundation / bbs-signature / draft-irtf-cfrg-bbs-signatures.html, etc. In the current configuration of the PPass protocol based on the BBS / BBS+ protocol which is currently being standardized at the IETF ("Internet Engineering Task Force"), the identity provider has the user's identity elements. It can be operated, for example,on behalf of or by an administrative entity legally holding the user's identity elements. The role of identity provider can be extended to all organizations managing and legally holding the user's identity elements. The identity provider(s) have a system for managing the PPass protocol in order to interact with the user and their personal device and, secondly, the means of interaction with third-party entities consuming the user's identity elements in the context of providing a service. An identity provider managing the user is able to identify them, authenticate them and generate a token that certifies the identity elements from this same identity provider. In the current cryptographic scheme, the identity provider managing the user has a set of the user's identity elements. The user,after identification / authentication with the identity provider, obtains all the identity elements concerning him. This set of identity elements is certified by a token specific to the identity provider issuing the identity elements, a token constructed using secret data present in the user's equipment. In a multi-identity provider context, the user can proceed similarly with various identity providers. At the end of the identity authentication operations, the user has on his equipment several sets of identity elements, each accompanied by their own token certifying them. Some identity providers may have a large number of the user's identity elements, such as sovereign identity providers for example. The calculations on a set of the user's identity elements are, at the generation and verification of the derived token accompanying it,a linear function of the number of identity elements included in the set of identity elements, and therefore of the size of this set. In fact, calculations on a large set of identity elements can be expensive in terms of machine resources both in the generation of the token certifying them by the identity provider, and in the derivation of said token by the user's equipment to generate a verifiable presentation intended to be transmitted to a service provider which the user wishes to access using his equipment, or even in the verification by the service provider of the validity of the derived token, with regard to the identity elements revealed by the user. In order to overcome this drawback, a solution would be, for an identity provider managing a given user,to authenticate it and generate as many tokens as there are user identity elements available from the same identity provider. However, such a solution is not desirable for the following reasons: - the identity provider could, based on the identity element it certifies, deduce the service the user wishes to access, which does not meet the requirements for protecting the user's personal data and privacy; - storing, in the user's equipment, several tokens that each certify an identity element from the set of identity elements, would take up a lot of memory space in said equipment, the storage resources of which are limited. Purpose and summary of the invention One of the aims of the invention is to remedy at least one of the drawbacks of the aforementioned state of the art by proposing a new technique for authenticating the identity or quality of a user,when this user does not need to have all the identity elements concerning him provided by an identity provider. To this end, an object of the present invention relates to a method for obtaining authentication of the identity or quality of a user with an authentication device, associated with an identity provider, which comprises a set of at least two identity elements of said user, said identity elements being stored in a terminal associated with the user and being known to the authentication device, said method comprising the following in said terminal: - authentication of the user with the authentication device using a secure communication established between the terminal and the authentication device, - selection, using a user interface of the terminal, of at least one identity element to be certified in said set,- sending a message to the authentication device, said message indicating, in a manner not identifiable by the authentication device, said selected identity element and said identity element remaining in said set, not selected, - receiving from the authentication device a certificate signed using a blind signature, said certificate certifying the validity of said selected identity element. On the user terminal side, thanks to the invention, the user is able to request from the signing entity a signed certificate which certifies only the identity element(s) that the user needs to access a product and / or service provider, without revealing to the authentication device the identity element(s) included in the signed certificate. This allows the terminal associated with the user, during such access, to derive, from the signed certificate received from the signing entity,an access token from a product and / or service provider who would only need to verify the validity of this / these identity element(s). Given that the number of identity elements selected by the user is less than the number of identity elements available both in the user terminal and in the authentication device, the computation time for deriving the access token in the user terminal is reduced by a linear factor which is a function of the number of identity elements selected by the user. According to a particular embodiment, the selected identity element is associated with a first value and the non-selected identity element is associated with a second value,said message containing a commitment on the first value and on the second value. Such an embodiment allows the user not to provide in clear text to the authentication device which identity element(s) the user wishes to certify or not to certify, but a commitment (or pledge) on the choice of the identity element(s) to be certified or not to certify. In the context of the invention, such a pledge advantageously allows the user not to disclose to the authentication device the identity element(s) that he wishes to certify or not to certify, with however the impossibility for the user to modify his commitment. According to another particular embodiment, the first value and the second value are respectively 1 and 0. According to yet another particular embodiment,the method for obtaining authentication of the identity or quality of a user further comprises: - calculating proof that the first value and the second value pledged are respectively 1 and 0, - sending said proof to said authentication device. Such proof allows the user to demonstrate to the signatory entity that the user knows how to reveal a pledge on the first and second values. The various embodiments or features mentioned above can be added independently or in combination with each other, to the method for obtaining authentication of the identity or quality of a user as defined above. The invention also relates to a terminal configured to obtain authentication of the identity or quality of a user from an authentication device, associated with an identity provider,which comprises a set of at least two identity elements of said user, said identity elements being stored in said terminal and being known to the authentication device, said terminal being further configured to: - authenticate a user associated with said terminal, with the authentication device, using a secure communication established between the terminal and the authentication device, - select, using a user interface of the terminal, at least one identity element to be certified in said set, - send a message to the authentication device, said message indicating, in a manner not identifiable by the authentication device, said selected identity element and said identity element remaining in said set, not selected, - receive from the authentication device a certificate signed using a blind signature,said certificate certifying the validity of said selected identity element. The invention also relates to a method for generating an authentication of the identity or quality of a user with an authentication device, associated with an identity provider, which comprises a set of at least two identity elements of said user, said identity elements being stored in a terminal associated with the user and being known to the authentication device, said method comprising the following in the authentication device: - obtaining an authentication of the user using a secure communication established between a terminal associated with the user and the authentication device, - receiving a message from said terminal, the message indicating, in a manner not identifiable by the authentication device,at least one identity element to be certified selected from said set and said identity element remaining in said set, not selected, - calculation of a signed certificate using a blind signature, said certificate certifying the validity of said selected identity element, - sending said signed certificate to the terminal. The invention advantageously allows any signatory entity, typically an identity provider, which has clear identity elements of a user, such as for example his name, nationality, address, date of birth, telephone number, etc. to generate a signed certificate on at least one of these identity elements that the user wishes to certify, without however being able to identify which identity element it is. This invention thus proposes an innovative cryptographic mechanism which aims to ensure better protection of users' personal data with respect to identity providers,in particular by preventing identity providers from determining the uses or services that the user wishes to benefit from using the signed certificate. In the case, for example, where the user wishes to obtain from an identity provider a certificate of majority, in other words, a certificate relating only to his or her “date of birth”, the invention advantageously makes it possible to prevent the identity provider from deducing that this user intends to connect to sites reserved for adults, for example. According to a particular embodiment, the signed certificate is calculated from a commitment contained in said received message, said commitment relating to a first value associated with the selected identity element and to a second value associated with said non-selected identity element. According to another particular embodiment,the first value and the second value are respectively 1 and 0. According to yet another particular embodiment, the method for generating an authentication of the identity or the quality of a user further comprises: - a reception, from said terminal, of proof that the first value and the second value pledged are respectively 1 and 0, - a verification of said proof received. The various aforementioned embodiments or characteristics can be added independently or in combination with each other, to the method for generating an authentication of the identity or the quality of a user as defined above. The invention also relates to an authentication device configured to generate an authentication of the identity or the quality of a user, said device comprising a set of at least two identity elements of said user,said identity elements being stored in a terminal associated with the user and being known to the authentication device, said authentication device being configured to: - obtain authentication of the user using a secure communication established between a terminal associated with the user and the authentication device, - receive a message from said terminal, the message indicating, in a manner not identifiable by the authentication device, at least one identity element to be certified, selected from said set, and said identity element remaining in said set, not selected, - calculate a certificate signed using a blind signature, said certificate certifying the validity of said selected identity element,- send said signed certificate to the terminal. The invention also relates to a computer program comprising program code instructions for implementing the method for obtaining authentication of the identity or quality of a user, when said program is executed by a computer. The invention also relates to a computer program comprising program code instructions for implementing the method for generating authentication of the identity or quality of a user, when said program is executed by a computer. These programs can use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable form. The invention also relates to a computer-readable information medium,and comprising instructions of a computer program as mentioned above. The information carrier may be any entity or device capable of storing the program. For example, the carrier may comprise a storage means, such as a ROM, a non-volatile memory of the flash type or a magnetic recording means, for example a hard disk. Furthermore, the information carrier may be a transmissible medium such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means. The program according to the invention may in particular be downloaded from a network such as the Internet. Alternatively, the information carrier may be an integrated circuit in which the program is incorporated,the circuit being adapted to execute or to be used in the execution of any of the methods in question. Brief description of the drawings Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate exemplary embodiments thereof without any limiting character. In the figures: Figure 1 represents a system for authenticating the identity or quality of a user comprising a terminal associated with the user and an authentication device, in a particular embodiment of the present invention; Figure 2 represents in the form of a flowchart steps of a method for obtaining authentication of the identity or quality of a user,in a particular embodiment of the present invention; Figure 3 represents in the form of a flowchart details of the method for obtaining an authentication of the identity or quality of a user of Figure 2, in a particular embodiment of the present invention; Figure 4 represents in the form of a flowchart steps of a method for generating an authentication of the identity or quality of a user, in a particular embodiment of the present invention; Figure 5 represents in the form of a flowchart details of the method for generating an authentication of the identity or quality of a user of Figure 4, in a particular embodiment of the present invention; Figure 6 represents in the form of a flowchart the main exchanges established during the implementation of the method for obtaining and generating an authentication of the identity or quality of a user,in a particular embodiment of the present invention; Figure 7 represents the hardware architecture of the terminal of Figure 1, in a particular embodiment of the present invention; Figure 8 represents the hardware architecture of the authentication device of Figure 1, in a particular embodiment of the present invention. Description of embodiments With reference to Figure 1, a system SYS for authenticating the identity or quality of a user is illustrated, in a particular embodiment. The system SYS of Figure 1 comprises a terminal TER associated with a user UT and an authentication device AUT associated with an identity provider FI. The authentication device AUT is configured to certify one or more identity elements a, 1, …, has nof the UT user. Such identity elements may, for example, be of a sovereign type (surname, first name, date of birth, etc.). Such identity elements may also relate to the status of the UT user (majority, seniority, diplomas, etc.). Such identity elements belong to a set E of at least two identity elements, which set E is stored in a secure storage module MSS1 of the TER terminal, such as, for example, an SE ("Secure Element" in English), an HSM ("Hardware Security Module" in English), a TEE ("Trusted Execution Environment" in English), etc.In the embodiment described here, the terminal TER comprises a communication module COM1 which can be used to send to the authentication device AUT one or more identity elements ^^^^1, … ,^^^^^^^^ selected in advance by the user UT and receive, from the authentication device AUT, a signed certificate CS relating to the selected identity element(s). It is recalled that such a signed certificate or accreditation is a personal attestation allowing a user to convince a third party that he or she has a particular authorization or qualification. It is specific to an individual and generated by a trusted entity, designated by FI in the description, via the use of digital signatures.However, standard digital signature mechanisms require revealing the entirety of the certified data, even to prove the authenticity of only a part of it, and allow users to be traced. In this description, an anonymous accreditation mechanism is used as introduced by Chaum (David Chaum: Showing Credentials Without Identification: SIgnatures Transferred Between Unconditionally Unlinkable Pseudonyms. EUROCRYPT 1985: 241-244). Such a system allows a user to prove that his identity elements have been certified, without revealing superfluous information. The COM1 module can also be used to send to a service provider (not shown) an access token or verifiable presentation VP derived from the signed certificate CS, during an access phase of the user UT to the service provider, to prove to the service provider that the user UT meets the conditions for access to the service.In the case, for example, where the service provider is an online betting site and therefore requires a certificate of majority, the verifiable presentation VP will constitute proof that the user UT does indeed hold a driving license. In the embodiment described here, the terminal TER comprises a module MAUT1 for authenticating the user UT with the authentication device AUT. In the embodiment described, the terminal TER comprises a cryptographic module MCRY1, for example an electronic identity wallet configured to store at least one signed certificate CS issued by an identity provider FI associated with the authentication device AUT and to generate a verifiable presentation VP to be presented to a service provider to access a service, while protecting the confidentiality of its identity elements ^^^^1, … ,^^^^^^^^.The verifiable presentation VP comprises a signed certificate CS' calculated by the terminal TER by refreshing the signed certificate CS. In the embodiment described here, the terminal TER comprises a user interface UI of voice type, for example a microphone, or of text type, for example a keyboard, which is configured to receive the identity element(s) ^^^^1, … ,^^^^^^^^ which has and / or have been respectively selected by the user UT. In the embodiment described here, the authentication device AUT comprises a communication module COM2. This module can in particular be used by the authentication device AUT to obtain the identity element(s) ^^^^1, … ,^^^^^^^^ selected by the user UT for the authentication of his identity or his quality, and send to the terminal TER a signed certificate CS relating to the selected identity element(s).In the embodiment described here, the authentication device AUT comprises a cryptographic module MCRY2. This module can in particular be used to authenticate a user UT, generate and verify the validity of a signed certificate CS relating to one or more identity elements ^^^^1 … ,^^^^^^^^, and calculate proofs demonstrating for example that the signed certificate CS produced is valid. In the embodiment described here, the authentication device AUT comprises a secure storage module MSS2, in which the set E of identity elements ^^^^1 … ,^^^^^^^^ of the user UT is recorded. Thus, prior to the implementation of the method for authenticating the identity or the quality of the user UT, the identity elements ^^^^1, … ,^^^^^^^^ of the user UT are available at the authentication device AUT and known to the latter.Figure 2 represents in the form of a flowchart the main steps of a method for obtaining authentication of the identity or quality of a user, implemented by the terminal TER. In this example, the user UT uses his terminal TER to request the authentication device AUT associated with an identity provider FI to provide him with a signed certificate CS relating to at least one identity element ^^^^. ^^^^ selected by the user UT from the set E of identity elements ^^^^1, … ,^^^^^^^^ (1≤i≤n). During a step U1, a secure communication ch is established between the terminal TER and the authentication device AUT. During this communication, the terminal TER sends a request R to the authentication device AUT AUT UT user authentication. Such a query R AUT can include a public key ^^^^^^^^ ^^^^of the user UT or a pair of public and private keys (^^^^^^^^^^^^, ^^^^^^^^^^^) of the user UT.In the embodiment described here, when the authentication of the user UT is successful, during a step U2, the terminal TER receives, via the user interface IU, a selection of at least one identity element ^^^^ ^^^^ that the user UT wishes to certify by the authentication device AUT. During a step U3, the terminal TER calculates a cryptographic message M U which indicates to the authentication device, in a manner not identifiable by the latter, said at least one identity element ^^^^ ^^^^ which has been selected, as well as said identity elements^^^^1, … ,^^^^^^^^−1,^^^^^^^^+1, ..., ^^^^^^^^ which have not been selected by the user UT for certification. During a step U4, the terminal TER sends to the authentication device AUT said cryptographic message M U. During a step U5, the terminal TER receives, from the authentication device AUT, a signed certificate CS which blindly certifies the validity of said at least one identity element ^^^^ ^^^^ . The particular structure of this signed certificate, which certifies a subset of identity elements, here {^^^^ ^^^^}, whose cardinality is less than the set E of identity elements, thus advantageously allows the TER terminal to derive, from the signed certificate received, an access token from a product and / or service provider who would only need to verify the validity of this identity element ^^^^ ^^^^. Considering that the number of identity elements selected by the user is less than the number of identity elements available both in the terminal TER and in the authentication device AUT, the computation times for deriving the access token in the terminal TER are reduced by a linear factor which is a function of the number of identity elements selected by the user to be certified. In the embodiment described here, the terminal TER is configured to refresh the signed certificate, via the cryptographic module MCRY1, and send the refreshed signed certificate CS' to a service provider (not shown) in a verifiable presentation, along with the identity element ^^^^ ^^^^requested by this service provider. Figure 3 represents in the form of a flowchart details of the method for obtaining authentication of the identity or quality of a user as described with reference to Figure 2. In the embodiment described here, the selection U2 of at least one identity element ^^^^ ^^^^ includes: - setting a bit b to a first value V1 equal to 1 i associated with at least one identity element ^^^^ ^^^^ which has been selected; - setting to a second value V2 equal to 0, of a bit b1 associated with said identity element ^^^^1 which has not been selected; - …; - setting to the second value V2 equal to 0, of a bit b i-1 associated with said identity element ^^^^ ^^^^−1 which has not been selected; - setting the second value V2 equal to 0, of a bit b i+1 associated with said identity element ^^^^ ^^^^+1 which has not been selected; - …; - setting the second value V2 equal to 0, of a bit bn associated with said identity element ^^^^ ^^^^ which has not been selected. In another exemplary embodiment, V1=0 and V2=1. In the embodiment described here, the calculation U3 of the cryptographic message M u implements in U30 the calculation of a commitment or pledge ^^^^ on the value of each of the bits b1 to b n . This commitment ^^^^ includes: - a commitment ^^^^1 on the content of the second value V2 of b1; - a commitment ^^^^2 on the content of the second value V2 of b2; -…; - a commitment ^^^^ ^^^^ on the contents of the first value V1 of b i ; - … ; - a commitment ^^^^ ^^^^ on the contents of the second value V2 of b n. Pledging a value is a cryptographic process known to those skilled in the art which allows an issuer to commit a value to a recipient without revealing it at first glance and in such a way that this commitment can no longer be modified subsequently. This value can, if necessary, be revealed subsequently by the issuer. Thus, the recipient has the assurance that once the commitment has been published, the issuer can no longer change his mind about the value contained in this commitment. In a particular embodiment, the present disclosure may use the pledging scheme proposed by Pedersen in 1992 (Torben P. Pedersen. Non-interactive and information-theoretic secure verifiable secret sharing. In Joan Feigenbaum, editor, CRYPTO'91, volume 576 of LNCS, pages 129–140. Springer, Heidelberg, August 1992), which has the particularity of producing perfectly indistinguishable commitments (perfectly hiding in English).In the embodiment described herein, the calculation U3 of the cryptographic message M. u implements in U31 the calculation of a proof Π allowing the user UT to demonstrate to the identity provider FI that he knows how to reveal the ^^^^ pledges and that the pledged values are either 0 or 1. In a particular embodiment, the proof Π is a so-called zero-knowledge proof (ZKP) and comprises: - a proof on the pledge ^^^^1; - a proof ^^^^2on the pledge ^^^^2; - …; - a proof ^^^^ ^^^^ on the pledge ^^^^ ^^^^ ; - … ; - a proof ^^^^ ^^^^ on the pledge ^^^^ ^^^^. We recall that a so-called zero-knowledge proof of knowledge allows a verifier to convince himself that a certain prover knows a secret S satisfying a given predicate P, the proof revealing to the verifier no information about the secret S in question except the fact that it verifies the given predicate P. Subsequently, to represent zero-knowledge proofs, we will sometimes use the usual notation PoK{α,β, … : predicate on α,β, …}. In the embodiment described here, the message M Usent in U4 contains the commitment ^^^^ and the proof Π. Figure 4 represents in the form of a flowchart the main steps of a method for generating an authentication of the identity or quality of a user, implemented by the authentication device AUT. According to such a method, an identity provider FI is capable of certifying one or more identity elements that the user UT wishes to certify, without being able to identify which identity element or identity elements it is. During a step I1, the authentication device AUT generates a secure communication ch with the terminal TER, for example by using a random number that avoids replay. During a step I2, the authentication device AUT receives an authentication request R AUTfrom the terminal TER requesting the authentication device AUT to authenticate the user UT. During a step I3, the authentication device AUT proceeds to authenticate the user UT. If the authentication fails (N in Figure 4), the method for generating an authentication of the identity or quality of the user UT stops. If the authentication succeeds (O in Figure 4), during a step I4, the authentication device AUT receives the cryptographic message M U from the TER terminal. According to the invention, the message M U indicates to the authentication device, in a manner not identifiable by the latter, said at least one identity element ^^^^ ^^^^which has been selected, as well as said identity elements ^^^^1, … ,^^^^^^^^−1,^^^^^^^^+1, ..., ^^^^^^^^which have not been selected by the user UT for certification. During a step I5, the authentication device AUT calculates a signed certificate CS which certifies the validity of said at least one identity element ^^^^ ^^^^which has been selected. According to the invention, the signature used to obtain the signed certificate is a blind or partially blind signature A. It is recalled that a blind signature is a security mechanism used in cryptography to allow a party to sign a message without knowing the content of this message so that the confidentiality of the message is preserved. In such a mechanism, the party wishing to obtain a blind signature combines the message to be signed with a randomly generated blinding factor and sends the result of this combination to the signer. The signer signs the message without knowing its actual content, and sends the resulting signature to the requester. The requester can use the blinding factor to "unblind" the signature, i.e. to cancel the effect of the blinding factor and obtain the signature of the original message.In the embodiment described here, the blind signature A is calculated using the BBS / BBS+ signature scheme. During a step I6, the authentication device AUT sends the signed certificate CS to the terminal TER. In the embodiments described above with reference to FIGS. 2 to 5, at least one identity element ^^^^. ^^^^ has been selected by the user UT. It goes without saying, of course, that more than one identity element can be selected from the set E of identity elements. Figure 5 shows in flowchart form details of the method for generating an authentication of the identity or quality of a user, as described with reference to Figure 4. In the embodiment described here, the message M U received in I4 contains: - the commitment or pledge ^^^^ on the value of each of the bits b1 to b n, - the proof Π allowing the user UT to demonstrate to the identity provider FI that he knows how to reveal the ^^^^ pledges and that the pledged values are either 0 or 1. In the embodiment described here, the method for generating an authentication of the identity or quality of the user UT comprises a step I40, during which the authentication device AUT verifies the validity of the proof Π. If the result of the verification is negative (N in Figure 5), the method stops. If the result of the verification is positive (O in Figure 5), the authentication device calculates the signed certificate CS from the commitment ^^^^ contained in the message M U. Figure 6 represents in the form of a flow diagram the main exchanges established between the terminal TER and the authentication device AUT, in a particular embodiment of an authentication of the identity or the quality of a user UT, which implements the blind signature protocol BBS+ cited above. It is assumed that prior to the implementation of the exchanges between the terminal TER and the authentication device AUT: - the identity provider FI has randomly generated an integer ^^^^^^^^^ ^^^^ belonging to {1, 2, …,^^^^, where ^^^^ is a prime integer, and has calculated ^^^^^^^^^^^^ = ℎ^^^^^^^^^^^^, where ℎ is any generator of a cyclic group G of prime order ^^^^. The public and private keys of the identity provider FI are respectively ^^^^^^^^ ^^^^ and ^^^^^^^^ ^^^^; - the TER terminal associated with the user UT also stores a pair of keys, public and private, certified by a suitable certification authority: (^^^^^^^^ ^^^^^^^^^^^^, ^^^^^^^^^^^^ = ^^^^ ^^^^), where ^^^^ is any generator of a cyclic group G of prime order ^^^^. It is also assumed that the discrete logarithm of ℎ in base ^^^^ is unknown. We denote by E= (^^^^1, … ,^^^^^^^^), the set of identity elements of the user UT, and ℬ, the list of indices of the identity elements that the user wishes to authenticate / certify by the identity provider FI. During a step S1, a secure communication ch is established between the terminal TER and the authentication device AUT, for example via the sending, by the authentication device AUT, to the terminal TER, of a challenge ch. During a step S2, the authentication device AUT carries out an authentication of the user UT.For this purpose, the TER terminal sends an authentication request R. AUT to the AUT authentication device using for example the public key ^^^^^^^^ ^^^^ . If the authentication fails, the process of authenticating the identity or quality of the user UT stops. If the authentication succeeds, during a step S3, the user UT selects at least one identity element ^^^^^^^^ from the set of identity elements E = (^^^^1, … ,^^^^^^^^), for example the three elements ^^^^2,^^^^5,^^^^7. For this purpose, ℬ = {2, 5, 7}. During a step S4, the terminal TER calculates, for each generator ^^^^^^^^, for ^^^^ ∈ a bit ^^^^^^^^ (where ^^^^^^^^ = 1 if ^^^^ ∈ ℬ and 0 otherwise), such that ^^^^^^^^^ where ^^^^^^^^ is a random value chosen by the user UT, between 0 and p-1, and ^^^^ ∗ is the set {1, 2,…, ^^^^-1}. According to the invention, each associated with a specific type of identity element: for example ^^^^1 is associated with the attribute “name”, ^^^^2 with the attribute “first name”, ^^^^3 with the attribute “age”, ^^^^4 with the attribute “gender”, etc. During step S4, the terminal TER calculates a commitment ^^^^^^^^^^^^ on a secret value ^^^^′0 known only to the user UT, such that ^^^^^^^^^^^^ = ^^^^ ^^^^′ 0 0 ^^^^ ^^^^ ^ ^^ 0 ^ +1 . This commitment ^^^^^^^^^^^^ constitutes a secret attribute, because the user UT does not wish to reveal ^^^^0 ′ . In the embodiment described here, the commitments ^^^^ ^^^^ and ^^^^^^^^^^^^ are generated with the Pedersen pledging scheme mentioned above. During a step S5, the terminal TER calculates, for each ^^^^ ∈ {1, … , ^^^^}, a ZK proof, denoted ^^^^ ^^^^ , that the value pledged in ^^^^ ^^^^is either "0" or "1". This type of proof, known as an "OR proof" in the literature, is for example described in Ronald Cramer, Ivan Damgård, Berry Schoenmakers: Proofs of Partial Knowledge and Simplified Design of Witness Hiding Protocols. CRYPTO 1994: 174-187. Such a proof ^^^^ is written as follows^^^^^^^^^� ^^^^ ^^^^ ^^^^ boasts: ^^^^ ^^^^ = PoK ^^^^:^^^^^^^^ = ^^^^^^^^+1 ∨ ^^^^^^^^ = ^^^^^^^^+1.During step S5, the TER terminal also calculates a proof ^^^^ ^^^^ demonstrating that he knows how to reveal the secret value ^^^^0 ′ . The proof ^^^^ ^^^^ is written as follows: During a step S6, the terminal TER transmits the following elements to the identity provider FI: {^^^^^^^^,^^^^^^^^} ^ ^ ^ ^ ^ ^ ^ = ^1,^^^^^^^^^^^^,^^^^^^^^.During a step S7, the authentication device AUT verifies the validity of the evidence ^^^^ ^^^^ (1≤i≤n) and ^^^^ ^^^^ . If one of these proofs is not valid, the process of authenticating the identity or the quality of the user UT is terminated. If all these proofs are valid, during a step S8, the authentication device AUT calculates a partially blind signature BBS+, noted (^^^^, ^^^^), with its private key ^^^^^^^^^^^^, such that: - ^^^^0 ′′ and ^^^^ are values randomly chosen by the AUT authentication device in ^^^^ ^ ∗ ^ ^^ , and where - ^^^^′′ 0 is such that ^^^^0 = ^^^^′0 + ^^^^′′0 (mod p), ^^^^0 being a secret attribute known only to the user UT, for example his private key ^^^^^^^^ ^^^^ . Such a signature (^^^^, ^^^^) has the advantage of only applying to the attribute ^^^^0 (where ^^^^0 = ^^^^′0 + ^^^^′′0 (mod p)) and the identity elements of the user UT, whose indices belong to ℬ, where ℬ = {2, 5, 7} in the above example. The value of the attribute ^^^^0 is intended to remain secret. It can be used by the user UT to prove that the signature (^^^^, ^^^^) received from the authentication device is indeed his property. During a step S9, the authentication device AUT transmits the signature (^^^^, ^^^^) to the terminal TER. During a step S10, the terminal TER checks the validity of the signature (^^^^, ^^^^) as well as ^^^^0 ′′in accordance with the BBS+ partially blind signature protocol. If the signature (^^^^, ^^^^) is not valid, the BBS+ partially blind signature protocol is terminated. Otherwise, during a step S11, the TER terminal records the signature (^^^^, ^^^^) in its MCRY1 module (figure 1). The signature (^^^^, ^^^^) thus recorded certifies only the identity elements selected by the user UT, the storage resources of the TER terminal are advantageously preserved. In addition, when the TER terminal will be required to derive this signature to allow access by the TER terminal to a service provider, the computational costs monopolized for the derivation will be advantageously reduced. In addition to these advantages, it is recalled that the identity elements on which the signature is based (^^^^, ^^^^) are advantageously not identifiable by the FI identity provider thanks to the exchanges which have just been described above.The identity provider FI will therefore have no information on the use that will be made of the token derived from this signature, when the terminal TER accesses a service provider that only requires these identity elements. In particular, if the user UT has only requested a "certificate of majority" from the identity provider, the latter will ignore it. In the embodiment that has been described in relation to Figure 6, it has been shown that the terminal TER and the authentication device AUT each share a part of a secret attribute ^^^^0. The terminal TER holds the part ^^^^0. ′ as well as the part ^^^^0 ′′ and the AUT authentication device, that part ^^^^0 ′′. Such a feature advantageously allows the UT user to have no control over his secret attribute, thus preventing malicious users from using the same secret attribute as that of the UT user, which could be the case if, for example, one of these users imposes such a secret attribute on the UT user. This feature is of course not essential, the UT user being able to choose in S4 a secret attribute ^^^^0 known only to him. To this end, the commitment ^^^^^^^^^^^^ calculated in S4 would be such that ^^^^^^^^^^^^ = ^^^^ ^^^^ 0 0 ^^^^ ^^^^ ^ ^^ 0 ^ +1 . The signature (^^^^, ^^^^) calculated during step S8 by the authentication device AUT would then be such that: The TER terminal described above can be implemented by a computer ORD0 whose hardware architecture is shown in Figure 7. This computer ORD0 comprises in particular a processor P0, a RAM MV0, a ROM MM0 and communication means MC0. The ROM MM0 constitutes a recording medium within the meaning of the invention. It comprises a computer program PG-T in accordance with the invention. This computer program PG-T is a program comprising instructions for executing the steps of a method for obtaining authentication of the identity or quality of a user UT as described above with reference to Figures 2, 3 and 6. The program PG-T defines in particular the communication modules COM1, authentication MAUT1, cryptographic calculation MCRY1, and secure storage MSS1 of the TER terminal.The authentication device AUT described above can be implemented by a computer ORD1 whose hardware architecture is shown in Figure 8. This computer ORD1 comprises in particular a processor P1, a random access memory MV1, a read-only memory MM1 and communication means MC1. The read-only memory MM1 constitutes a recording medium within the meaning of the invention. It comprises a computer program PG-A in accordance with the invention. This computer program PG-A is a program comprising instructions for executing the steps of a method for generating authentication of the identity or quality of a user UT as described above with reference to Figures 4 to 6. The program PG-A defines in particular the communication modules COM2, authentication and cryptographic calculation MAUT2, cryptographic calculation MCRY1, and secure storage MSS2 of the authentication device AUT.
Claims
CLAIMS
1. Method for obtaining authentication of the identity or quality of a user from an authentication device, associated with an identity provider, which comprises a set of at least two identity elements of said user, said identity elements being stored in a terminal associated with the user and being known to the authentication device, said method comprising the following in said terminal: - authentication (U1) of the user (UT) with the authentication device using a secure communication (ch) established between the terminal and the authentication device, - selection (U2), using a user interface of the terminal, of at least one identity element to be certified in said set, - sending (U3) a message to the authentication device, said message indicating, in a manner not identifiable by the authentication device,said selected identity element and said identity element remaining in said set, not selected, - receiving (U4) from the authentication device a certificate signed using a blind signature, said certificate certifying the validity of said selected identity element.
2. Method for obtaining an authentication according to claim 1, wherein said selected identity element is associated (U20) with a first value (V1) and said unselected identity element is associated (U20) with a second value (V2), said message containing a commitment on the first value and on the second value.
3. Method for obtaining an authentication according to claim 2, wherein the first value and the second value are respectively 1 and 0.
4. Method for obtaining an authentication according to claim 3,further comprising: - a calculation (U31) of a proof (Π) that the first value and the second value pledged are respectively 1 and 0, - a sending (U3) of said proof (Π) to said authentication device.,
5. A computer program comprising program code instructions for implementing the method of obtaining authentication according to any one of claims 1 to 4, when executed on a computer.
6. A computer-readable recording medium on which a computer program according to claim 5 is recorded.
7. A terminal (TER) configured to obtain authentication of the identity or quality of a user from an authentication device, associated with an identity provider, which comprises a set of at least two identity elements of said user, said identity elements being stored in said terminal and being known to the authentication device, said terminal being further configured to: - authenticate a user (UT) associated with said terminal, with the authentication device,using a secure communication established between the terminal and the authentication device, - selecting, using a user interface of the terminal, at least one identity element to be certified in said set, - sending a message to the authentication device, said message indicating, in a manner not identifiable by the authentication device, said selected identity element and said identity element remaining in said set, not selected, - receiving from the authentication device a certificate signed using a blind signature, said certificate certifying the validity of said selected identity element.
8. Method for generating an authentication of the identity or quality of a user with an authentication device, associated with an identity provider, which comprises a set of at least two identity elements of said user,said identity elements being stored in a terminal associated with the user and being known to the authentication device, said method comprising the following in the authentication device: - obtaining (I2) an authentication of the user (UT) using a secure communication (ch) established between a terminal associated with the user and the authentication device, - receiving (I4) a message from said terminal, the message indicating, in a manner not identifiable by the authentication device, at least one identity element to, certify selected from said set and said identity element remaining in said set, not selected, - calculation (I5) of a certificate signed using a blind signature, said certificate certifying the validity of said selected identity element, - sending (I6) to the terminal of said signed certificate.
9. Method for generating an authentication according to claim 8, wherein the signed certificate is calculated from a commitment contained in said received message, said commitment relating to a first value associated with the selected identity element and to a second value associated with said unselected identity element.
10. Method for generating an authentication according to claim 9, wherein wherein the first value and the second value are respectively 1 and 0.
11. A method of generating an authentication according to claim 10, further comprising: - receiving (I4), from said terminal, proof (Π) that the first value and the second value pledged are respectively 1 and 0, - verifying (I40) said received proof.
12. A computer program comprising program code instructions for implementing the method of generating an authentication according to any one of claims 8 to 11, when executed on a computer.
13. A computer-readable recording medium on which a computer program according to claim 12 is recorded.
14. Authentication device (AUT) configured to generate an authentication of the identity or quality of a user, said device comprising a set of at least two identity elements of said user, said identity elements being stored in a terminal associated with the user and being known to the authentication device, said authentication device being configured to: - obtain an authentication of the user (UT) using a secure communication (ch) established between a terminal associated with the user and the authentication device,. - receive a message from said terminal, the message indicating, in a manner not identifiable by the authentication device, at least one identity element to be certified, selected from said set, and said identity element remaining in said set, not selected, - calculate a signed certificate using a blind signature, said certificate certifying the validity of said selected identity element, - send said signed certificate to the terminal.
Citation Information
Patent Citations
Controlled-content recoverable blinded certificates
US20050066164A1