Method and system for verifying the authenticity and integrity of data while maintaining privacy
The method and system for verifying anonymized data in telecommunications networks uses advanced cryptographic algorithms and a Pulse Gateway to ensure anonymity, integrity, and authentication, addressing the limitations of existing methods by providing efficient and robust data verification.
Patent Information
- Application Number
- PCT/ES2025/070397
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-03
- Filing Date
- 2025-06-30
- Publication Date
- 2026-01-08
AI Technical Summary
Existing data verification solutions in telecommunications networks face challenges in balancing privacy, anonymity, and integrity while being computationally efficient, with methods like homomorphic encryption, anonymization, and blockchain facing limitations such as high computational cost, susceptibility to re-identification attacks, and scalability issues.
A method and system using advanced cryptographic algorithms, digital signatures, and a Pulse Gateway for verifying anonymized data, ensuring anonymity, integrity, and authentication without sacrificing user privacy, leveraging hash functions and public-key cryptography.
Ensures secure data management with operational simplicity and robustness, minimizing communication overhead and addressing data breaches, while maintaining user anonymity and data integrity across various sectors.
Smart Images

Figure ES2025070397_08012026_PF_FP_ABST
Abstract
Description
[0001] METHOD AND SYSTEM FOR VERIFYING THE AUTHENTICITY AND INTEGRITY OF DATA WHILE PRESERVING PRIVACY
[0002] DESCRIPTION
[0003] OBJECT OF THE INVENTION
[0004] The present invention has applications in the telecommunications sector, within the field of digital information security and the processing and communication of digital content. In particular, it relates to information protection, data management, data masking, anonymization, and secure web browsing. More specifically, the present invention relates to a method and system for ensuring the integrity and authentication of data transmitted through telecommunications networks or systems, while preserving privacy.
[0005] BACKGROUND OF THE INVENTION
[0006] Currently, a variety of methodologies and technologies exist to address the challenges associated with information security and the protection of personal data. In the area of verifying data transmitted over telecommunications networks, with a particular focus on preserving privacy, anonymity, integrity, and authentication, some recent developments and existing limitations in the context of privacy protection during data transmission are presented below.
[0007] One of the major pillars of data security and protection is cryptography. Cryptography has been a cornerstone of data protection, with significant advancements in symmetric and asymmetric algorithms, public-key cryptography, and particularly in homomorphic encryption techniques. These techniques allow operations to be performed on encrypted data without decryption (yielding the same results as if equivalent operations were performed on the original unencrypted data). This enables the secure processing of sensitive data, preserving user privacy, and then yielding encrypted results that, once decrypted, are equivalent to calculations performed on the original plaintext (unencrypted) data. However, these techniques are computationally intensive and can result in slower processing times.They often require a compromise between security and computational efficiency since they frequently need high computational resources to run.
[0008] A second area of focus is anonymization techniques. The process or concept of anonymization (or data dissociation) consists of eliminating or reducing the remaining risk of re-identifying anonymized data. In other words, it is a technique that eliminates or reduces the possibility of identifying the data subject while maintaining the veracity and accuracy of the data processing results. Methods such as k-anonymity, i-diversity, and t-closeness have been developed in this field to anonymize datasets, protecting individual privacy. Although these techniques are effective in certain contexts, they can be susceptible to inference attacks, especially given the volume and variety of data available today.
[0009] Other options along the same lines include deletion, generalization, and data swapping. Deletion involves directly removing identifying information from a dataset; while effective in protecting privacy, this can significantly reduce the data's usefulness. Generalization involves replacing detailed data with broader categories, and data swapping modifies the dataset by exchanging data values between records. In both cases, the overall distribution of the data is maintained, but identifying individuals becomes more difficult, reducing data accuracy but improving privacy.
[0010] Another recent technique is differential privacy. This technique allows sharing information about a dataset by adding a certain amount of random noise to the query results, ensuring that the inclusion or exclusion of a single individual in the dataset does not significantly affect the outcome. This allows for obtaining useful insights from the data without compromising the privacy of individuals. The main advantage of differential privacy lies in its ability to offer mathematical guarantees of privacy under a well-defined risk model.
[0011] An alternative is federated learning. This machine learning approach allows models to be trained across multiple decentralized devices or servers containing local data samples, without exchanging the data itself. The process involves training local models on the devices and then aggregating these models on a central server to update a global model, which is then distributed back to the devices. The cycle repeats, improving the model with data from diverse sources without needing to share or centralize the data. The advantage of federated learning is that by keeping the data local and only sharing model updates, it inherently protects user data, reducing the risk of privacy breaches.Furthermore, it is compatible with differential privacy techniques, ensuring that data contributions to the model can be authenticated and verified without exposing the underlying data.
[0012] However, federated learning has some disadvantages, such as: the process of adding model updates from numerous devices can introduce significant communication overhead, impacting efficiency; federated learning is susceptible to model poisoning attacks, where malicious updates negatively influence the overall model; and using data that is not distributed independently and identically across devices can be complicated and lead to biased models.
[0013] Blockchain technologies, also known as Distributed Ledger Technologies (DTL), offer an innovative approach to data integrity and authentication using immutable blockchains. While promising, scalability, privacy management, and energy consumption remain significant challenges for these technologies. In short, a general problem with most existing secure cryptographic solutions is their high computational cost, which limits their applicability on resource-constrained devices, creating a trade-off between privacy and efficiency. Furthermore, anonymization techniques may not be sufficiently robust against sophisticated re-identification attacks, especially in the context of large volumes of interconnected data.Adding noise to differential privacy to protect privacy can degrade data usability, especially in queries requiring high accuracy. Furthermore, determining the appropriate level of noise to balance privacy and usability can be challenging and depends significantly on the specific application context. Finally, while blockchain offers a potential solution to several security challenges, its adoption is limited by scalability, privacy, and operational cost issues.
[0014] Therefore, it can be said that the state of the art in data verification solutions (while preserving privacy) reflects a rapidly evolving field with significant advancements but also considerable limitations. The proposed innovation seeks to address these limitations by offering a comprehensive solution that solves the problem of ensuring data privacy, anonymity, integrity, and authentication across a wide range of applications, overcoming existing limitations and drawbacks.
[0015] DESCRIPTION OF THE INVENTION
[0016] The present invention solves this problem by means of a method and system for verifying anonymized data, which improves the security of data transmission through a system that guarantees anonymity, integrity, and authentication without sacrificing user privacy in telecommunications networks. It achieves this by using advanced cryptographic algorithms along with novel data processing protocols to authenticate and verify data, maintaining complete user anonymity / privacy. This system is characterized by its computational efficiency and universal applicability, establishing a new approach to privacy-preserving data verification technologies. This method and system will be called VDA2 (Verification of Anonymized Data and its Authentication).
[0017] The proposed solution comprises a unified framework that integrates, for example, the creation of digital signatures, the use of hash functions and public-key cryptography, and an adaptable protocol. The method may include initialization phases, a two-factor authentication mechanism for specific user or information source verification, the creation of encrypted information that maintains anonymity during verification, decryption, and validation processes. A trusted entity will be responsible for generating and distributing digital certificates associated with the participants' private keys.However, the use of digital certificates or a public key infrastructure (PKI) is not a necessary condition for applying this invention, and other alternatives such as FIDO (Fast IDentity Online), a set of open standards for online authentication that seek to improve security and simplicity in the use of credentials, can be used.
[0018] There is an element that acts as an intermediary for data and information verification. This intermediary verification device is called a "Pulse Gateway," but it doesn't necessarily have to be a physical gateway; it can be any type of electronic device with communication and processing capabilities. There can be one or several; as many as needed to ensure the system's scalability and performance. The method leverages this gateway to provide reliable verification across multiple applications, from accessing online content to secure transactions, without compromising data integrity or user privacy.
[0019] The proposed invention differs from conventional techniques in its efficiency and universal applicability, offering a significant improvement in the protection of personal information and data management across a variety of critical sectors (such as IoT, healthcare, etc.), standing out for its operational simplicity and robustness compared to existing methods. Thus, the present invention, in comparison with other existing solutions such as Federated Learning, proposes a direct mechanism for data verification and authentication while preserving privacy and anonymity, specifically designed for telecommunications networks. It does not require iterative and decentralized model training, but rather focuses on secure and anonymous verification processes.The proposed solution is simpler than state-of-the-art approaches in terms of operational requirements, minimizing communication overhead and directly addressing the risks of data breaches or unauthorized access without the complexities associated with model training and aggregation. Furthermore, it avoids the possibility of model poisoning by not relying on aggregated updates for a global model, offering a more targeted solution for data integrity and authentication in digital communications.
[0020] Specifically, a first aspect of the present invention relates to a method for data verification, comprising the following steps: a) a first electronic device, the sending device, sends a message to a second electronic device, the receiving device, including a request to perform a data exchange action (a data-related action) with the receiving device; b) the receiving device sends the sender information concerning the receiving device and an identification of a third electronic device, the intermediary verifying device (the so-called Pulse Gateway); c) the sending device hashes the information concerning the receiving device, hashes data provided by the sending device (e.g., a user identifier), calculates a second hash of both concatenated hashes, and encrypts the result; the encrypted result is called a complex digital signature;d) the sending device sends a message to the receiving device comprising: information concerning the destination device, the hash of the sending device data, the complex digital signature and the following information encrypted with a key K generated by the sending device: the hash of the information concerning the destination device, the sending device data and the complex digital signature and wherein the message further comprises the encrypted key K (for example, with a public key of the intermediary verifying device);e) The receiving device hashes the information concerning the intended device and concatenates it with the hash of the data from the sending device received, and compares the result with the result of decrypting the complex digital signature it has received. If both results match (message integrity has been maintained), it goes to step f); otherwise, the method terminates (giving a result of lack of integrity); f) The receiving device sends the intermediary verifying device a message containing the information encrypted with the key K received from the sending device and the encrypted key K received from the sending device; g) The intermediary verifying device, using its private key, decrypts key K and, using key K, decrypts the received information, obtaining the hash of the information concerning the intended device, the data from the sending device, and the complex digital signature;(h) the intermediary verification device hashes the data received from the sending device and concatenates it with the hash of the information concerning the receiving device and compares the result with the result of decrypting the complex digital signature it has received; (i) the intermediary verification device determines, based at least on the comparison of both results, the success of the verification and if the verification is determined to be successful, a message is sent to the receiving device indicating that the verification is successful and, therefore, the data exchange action required by the sending device can be carried out;where communication between the sending device and the receiving device and between the latter and the intermediary verifying device is carried out through one or more communication networks (which may be, for example, 2G, 3G, 4G, 5G mobile telephone networks, local area networks, fiber optic networks or any other type of communication network).
[0021] In one embodiment, the data exchange action is accessing information through the receiving device, and the data provided by the sending device is a user identifier on that device. In this case, the verifying device can determine that the verification is successful only if the results match, or if, in addition to matching, the intermediary verifying device confirms that the user meets a specific condition: the sender's information is valid. This action could be accessing a web page through the receiving device (for example, a web server), and the information regarding the receiving device would be the identifier of a web page (for example, the URL) that the user wants to access.
[0022] In one embodiment, the data exchange action is to provide data (or a set of data) to the receiving device (for example, a data repository) so that it can access it (for example, to store it). In this case, the information about the receiving device would be a unique identifier of the receiving device, and the data provided by the sending device is the data (or set of data) that the sending device wants the receiving device to access. Furthermore, if verification is determined to be successful in step i), the verifying intermediary device would include the data (or set of data) in the message sent to the receiving device in step i).
[0023] In one embodiment, the encryption in step c) to obtain the complex digital signature is performed using a private key of the sending device and in steps e) and h) the complex digital signature is decrypted (deciphered) with a public key of the sending device.
[0024] In one embodiment, the identification of the third electronic device is a digital certificate of the third electronic device.
[0025] A second aspect of the present invention relates to a system for data verification while preserving privacy, which is performed by the previously proposed method. Specifically, the system comprises a first electronic device, the sender device, a second electronic device, the receiver device, and a third electronic device, the intermediary verifier device; wherein communication between the sender device and the receiver device, and between the receiver device and the intermediary verifier device, is carried out through one or more communication networks, and wherein:
[0026] The sending device is configured to (has the means to): send to the receiving device a message including a request to perform a data exchange action with the receiving device; receive from the receiving device information regarding the receiving device and an identification of the intermediary verifying device; perform a hash of the information regarding the receiving device, a hash of data provided by the sending device, calculate a second hash of both concatenated hashes and encrypt the result, the encrypted result is called a complex digital signature;send a message to the receiving device comprising: the information regarding the receiving device received, the hash of the data from the sending device, the complex digital signature and the following information encrypted with a key K generated by the sending device: the hash of the information regarding the receiving device, the data from the sending device and the complex digital signature and wherein the message further comprises the key K encrypted with a public key of the intermediary verifying device;
[0027] The receiving device is configured to (has the means to): hash the information concerning the receiving device, concatenate it with the hash of the data from the sending device received, and compare the result with the result of decrypting the complex digital signature it has received, and, if both results match, send to the intermediary verifying device a message containing the information encrypted with the key K received from the sending device and the encrypted key K received from the sending device; and the intermediary verifying device is configured to (has the means to): use its private key to decrypt key K and use key K to decrypt the received information, obtaining the hash of the information concerning the receiving device, the data from the sending device, and the complex digital signature;Perform the hash of the data received from the sending device and concatenate it with the hash of the information regarding the receiving device and compare the result with the result of decrypting the complex digital signature received; determine, based at least on the comparison of both results, the success of the verification and if the verification is determined to be successful, send a message to the receiving device indicating that the verification is successful and, therefore, the data exchange action required by the sending device can be performed.
[0028] In one embodiment, the data exchange action is accessing a web page through the receiving device; the data provided by the sending device is an identifier of a user of the sending device; and the intermediary verifying device determines that the verification is successful if the results match and if, from said user identifier, the intermediary verifying device verifies that the user meets a certain condition that the sender's information is valid.
[0029] In one embodiment, the data exchange action is to send data to the receiving device for storage, where the information concerning the receiving device is a unique identifier of the receiving device, where the data provided by the sending device is data that the sending device wants the receiving device to store, and where, if verification is successful, the verifying intermediary device sends a message to the receiving device including the data to be stored.
[0030] Additional, specific, and preferred aspects, embodiments, and details of the invention are set forth in the accompanying independent and dependent claims. For a more complete understanding of the invention, its objects, and advantages, reference may be made to the following specification and the accompanying drawings.
[0031] BRIEF DESCRIPTION OF THE FIGURES
[0032] The following section briefly describes a series of drawings that help to better understand the invention and that expressly relate to an embodiment of said invention presented as a non-limiting example. FIGURE 1.- Schematically shows a message flow diagram for another application example, according to a preferred embodiment of the invention, where a user attribute (in this case, age) is verified.
[0033] FIGURE 2.- Shows schematically a message flow diagram for an application example, according to a preferred embodiment of the invention, where the non-fraudulent origin of a data is verified.
[0034] PREFERRED EMBODIMENT OF THE INVENTION
[0035] The present invention describes an advanced method and system for verifying the authenticity and integrity of anonymized data in telecommunications networks, focused on information security and user privacy protection. It enables secure data management, guaranteeing anonymity, privacy, and verification. Through the use of advanced cryptographic algorithms and unique data processing protocols, user privacy and anonymity are ensured, while simultaneously validating the integrity and authenticity of the transmitted data.
[0036] In short, as will be explained below, the present invention proposes a data verification system and method to preserve privacy, comprising generating complex digital signatures and verifying the authenticity and integrity of the data through an intermediate device (Pulse Gateway) without revealing the user's identity.
[0037] In one embodiment, the method proposed by the present invention performs the following steps (this is a generic example and not all steps are essential; other embodiments may include all or only some of these steps):
[0038] The electronic device that wants to perform a data exchange (also called the sending device or simply the sender) contacts the electronic device with which it wants to perform that exchange (the receiving device or simply the receiver). This data exchange could be, for example, sending certain information to the receiving device (for example, to store it there) or accessing information (for example, a web page) through the receiving device, or any other action.
[0039] The recipient sends the sender device data that allows its identification (for example, a website, an IP address, etc., in other words, it sends a unique identifier of the recipient), preferably along with the digital certificate of the intermediary device (Pulse Gateway) that will be used.
[0040] The sending device processes the data received from the recipient. In one implementation, a hash is calculated (a hash function is applied) of the recipient's identifier and a hash of a sender's identifier (or, more generally, of data provided by the sending device). This sender's identifier can be that of the sending electronic device or of a user of that electronic device. The resulting hashes are concatenated, and another hash is calculated. The output of this second hash is encrypted with a private key belonging to the sender (of the sending electronic device or of a user of that electronic device), and the result is called a complex digital signature. The sender then sends a message to the recipient. This message includes the recipient's identifier, the hash (the result of the hash) of the sender's identifier, and the complex digital signature.In addition, the message may contain the following encrypted information (for example, with a one-time key): the recipient's identifier hash, the sender's identifier, and the complex digital signature. This encryption key is attached to the message, encrypted with the public key of the intermediary verification device (Pulse Gateway) to be used.
[0041] When the recipient receives this message, they can access the unencrypted content. They calculate the hash of the recipient's identifier and concatenate it with the hash of the sender's identifier they received. They then perform a second hash of the concatenated result (output 1). Next, they decrypt the received complex digital signature using the sender's public key (output 2). If output 1 equals output 2, then the message maintains its integrity and authentication. The recipient then prepares the message to be sent to the intermediary device (called the Pulse Gateway).This message contains all the information the recipient received encrypted in the previous message (the recipient's identifier hash, the sender's identifier, and the complex digital signature). The recipient sends this encrypted information exactly as received (i.e., they do not decrypt it, nor could they decrypt it even if they wanted to, because they do not know the necessary key). This message can be digitally signed with a traditional digital signature. This intermediary element (also called a verification device) can be any type of electronic device, such as a server, a gateway, or any other type of device.
[0042] The gateway receives the message and processes its content. First, it decrypts the one-time key using its private key. Then, it decrypts the rest of the content with that key and obtains the hash of the recipient's identifier, the sender's identifier, and the complex digital signature. It calculates the hash of the sender's identifier and concatenates it with the hash of the recipient's identifier (output 3). Finally, it decrypts the complex digital signature (output 4). If outputs 3 and 4 are equal, integrity and authentication are guaranteed, and a success message is sent to the recipient so they can perform the requested action (data storage, successful data verification, content access, etc.). Otherwise, a failure message is sent. The success or failure message is communicated to the sender.
[0043] Communication between the sending and receiving devices and between these and the intermediary device (the gateway) will be carried out through one or more wired or wireless communication networks, which can be of any type (2G, 3G, 4G, 5G mobile network, local area network, fiber optic network or any other wireless or wired network).
[0044] There are many possible use cases for this mechanism. For example, it can be used to verify that a characteristic / condition / attribute associated with a legitimate source is true (Figure 1), or it can be used to verify that data comes from a legitimate, non-fraudulent source (Figure 2). These are just two non-exhaustive examples. In all cases, it provides anonymity, integrity, and authentication of the source. It is important to note that the core design allows for the inclusion of additional levels of confidentiality as required. Figures 1 and 2 schematically show the message exchange (along with the message content and calculations necessary for its creation) for different use cases.
[0045] The following is an example of a use case in which a specific condition (or user characteristic or attribute) is verified before providing a particular service or offering certain information to a user. To facilitate the explanation, a concrete example (shown in Figure 1) will be used, verifying that an internet user wishing to access a specific webpage meets certain requirements (such as being of legal age for accessing adult websites or content), while simultaneously guaranteeing the user's anonymity and providing authentication and integrity of the messages exchanged (this is just one non-exhaustive example, and other implementations may include only some of the steps explained below):
[0046] Step 1 (101). The user requests access to the website whose content is for adults. This is done through their electronic device (11), which could be a mobile phone, tablet, personal computer, or any other device. Requesting access is interpreted as entering the URL (in the case of Figure 1, this would be www.xxx.yyy) into the browser so that the web client, from which the user is accessing the service, contacts the web server (12) of that page in the normal way. In this use case, using the terminology employed previously, the sending device would be the user's electronic device and the receiving device would be the web server.
[0047] Step 2 (102). The web server responds by sending in the response message the digital certificate (CERTGW) of an intermediary device (13) that will be used for verification (the so-called Pulse Gateway) and the URL of the web page (WEBURL) that the user wants to access. Note that the user already knows this URL, but this is done so that the client's web browser has this information directly without needing to interact with the user. This message can include information that to access this web page, it is necessary to verify a user attribute (in this case, age). Step 3 (103). The user's device (for example, the web browser) calculates a complex digital signature.To achieve this, the process involves obtaining the hash of the website's URL (H(WEBURL)) and the hash of a user ID (H(l D)) belonging to the user accessing the website. These hashes are then used as input for another hash function (which can be called a double hash), and the output is encrypted with the user's private key. This process generates the complex digital signature. The user ID should be understood as a unique identifier that verifies the user's age and is known only to the intermediary device (the Pulse Gateway). In other words, this user ID will be unknown to the web server and computationally intractable for the server to obtain.This user identifier could be associated with the user's digital certificate, which in Spain can only be obtained upon reaching the age of majority, or with an access key if there is prior registration as a user on the website, for example, using FIDO, among other options. This is a modular proposal, and the objective is that the information verifying the user's age will be known and evaluated solely by the Pulse Gateway, remaining completely unknown to the web server (thus ensuring user anonymity).
[0048] Step 4 (104). The user's device (e.g., the web browser) sends a message to the web server that includes: the web URL, the user identifier hash, and the complex digital signature. This message also includes, encrypted with a key K randomly generated by the user's device, the hash of the web URL, the user identifier, and the complex digital signature, and, encrypted with the gateway's (the Pulse Gateway's) public key KGW, the key K.
[0049] Step 5 (105). When the web server receives this message, it calculates the hash of the web URL, concatenates it with the hash of the user identifier it received, and then calculates the double hash. It also decrypts the complex signature it received (using the user's public key). If both outputs are the same, then integrity is verified (no data in this message has been tampered with). Otherwise, the user's device can be informed that the verification failed. Step 6 (106). Next, if integrity was verified in the previous step, the web server forwards the encrypted information it received to the Pulse Gateway: the hash of the web URL, the user identifier, and the complex signature. Remember, all of this was encrypted with key K, and key K was encrypted with the public key of the KGW gateway.The web server can include a request number (#REQ) for the request-response correspondence and digitally sign this message with a traditional digital signature.
[0050] Step 7 (107). When the Pulse Gateway receives this message, using its private key, the Pulse Gateway decrypts K. Then, using K, it decrypts the encrypted information it received, obtaining the hash of the web URL (H(WEBURL)), the user identifier (ID), and the complex digital signature. The Pulse Gateway has no information about the web page the user wants to access, only its hash.
[0051] Step 8 (108). The Pulse Gateway calculates the user identifier hash and concatenates it with the website hash obtained from the received message. It then calculates the double hash and, separately, decrypts (for example, using the sender's public key) the complex digital signature obtained in the previous step. Again, if both outputs match, integrity is guaranteed. This allows you to link the characteristic / condition you want to verify to its origin (the user) while offering desirable security features, such as privacy and integrity.
[0052] If both outputs match, the Pulse Gateway uses the user ID to check if the user meets the necessary condition for accessing the website (in this case, if they are of legal age). Depending on the type of user ID used, this check is automatic, as the user can only have that identifier if they meet the criterion (for example, it could be a digital certificate, which in Spain can only be obtained upon reaching the age of majority). In this way, the user demonstrates that they meet the criterion without revealing to the gateway the website they want to access (or the information they want to access, if it were another use case where the user wants to access certain information) and without the web server needing to know the user's identity.
[0053] Step 9 (109). If the verification process is successful, a success message is sent to the web server. Otherwise, a failure message is sent indicating that the user does not meet the (age) requirement. These messages can include the request number (#REQ) sent by the web server in the previous message (to identify which request is being responded to) and can also be digitally signed with a traditional digital signature. In an alternative embodiment, if the verification fails, no message is sent to the web server, and if the server does not receive a message from the Gateway within a certain period of time, it will assume that the verification was unsuccessful.
[0054] Step 10 (110). The web server communicates with the user, providing access to the website (if successful) or informing them that access is denied (if unsuccessful).
[0055] The following is an example of a use case in which the origin of data (which is not fraudulent) is verified before a device (sender) wants another device (recipient) to make it accessible. The proposed solution ensures that the data is linked to its origin (the sending device), thus guaranteeing that the data does not come from a fraudulent source, while also ensuring data integrity. To facilitate the explanation, a specific example (shown in Figure 2) will be used, verifying that data (which a user wants to store in a repository) is not fraudulent (that it is linked to the sender), while simultaneously guaranteeing the anonymity of the source and providing authentication and integrity of the exchanged messages (this is just one non-exhaustive example, and other implementations may include only some of the steps explained below):
[0056] Step 1 (201). The user wants to send data (or a set of data) to a recipient device so that it can access it, for example, to store it in a data repository (22). This is done through their electronic device (21), which could be a mobile phone, a tablet, a personal computer, a vehicle communication module, or any other electronic device, and which, in the example in Figure 1, is located in a vehicle. In this use case, using the nomenclature employed previously, the sending device would be the user's electronic device, and the receiving device would be the data repository.
[0057] Step 2 (202). The repository responds by sending in the response message the digital certificate (CERTGW) of an intermediary device (23) that will be used for verification (the so-called Pulse Gateway) and the repository identifier (I DREPO). This message may inform the user that data must be validated before it can be stored. This validation will be done with partial or total anonymity of the data source: partial anonymity will be achieved if digital certificates (public key / private key) are used to encrypt the digital signature (since in that case the repository must know the identity of the sender to decrypt the digital signature), or total anonymity will be achieved if other encryption / authentication systems such as FIDO are used to obtain the complex digital signature.
[0058] Step 3 (203). The user's device calculates a digital signature (referred to here as a complex digital signature). This is done by obtaining the hash of the repository identifier (H(I DREPO)) and the hash of the data to be stored (H(data)); then, both hashes are used as input to another hash function (which can be called a double hash) and the output is encrypted with the user's private key (or using a FIDO authentication system). This is how the complex digital signature is obtained.
[0059] Step 4 (204). The user device sends a message to the data repository: the repository identifier, the hash of the data identifier, and the complex digital signature. This message also includes, encrypted with a key K randomly generated by the user device, the hash of the repository identifier, the data, and the complex digital signature, and, encrypted with the gateway's (the Pulse Gateway's) public key KGW, the key K.
[0060] Step 5 (205). When the repository receives this message, it calculates the hash of the repository identifier, concatenates it with the hash of the data, and then calculates the double hash. Separately, it decrypts the complex signature it received. If both outputs are equal, then integrity is verified (no data in this message has been tampered with).
[0061] Step 6 (206). Next, if integrity has been verified in the previous step, the repository forwards the encrypted information it received to the Pulse Gateway. This information includes the repository identifier hash, the data, and the complex digital signature, all encrypted with key K, and key K encrypted with the KGW gateway's public key. The repository can then digitally sign this message with a traditional digital signature.
[0062] Step 7 (207). When the Pulse Gateway receives this message, using its private key, the Pulse Gateway decrypts K. Then, using K, it decrypts the encrypted information it has received, obtaining the hash of the repository identifier, the data, and the complex digital signature.
[0063] Step 8 (208). The Pulse Gateway calculates the data hash, concatenates it with the repository identifier hash obtained from the received message. It then calculates the double hash and, separately, decrypts the complex digital signature obtained in the previous step (for example, using the sender's public key). Again, if both outputs match, integrity is guaranteed. In this way, the proposed solution ensures a link between the data to be stored and its origin (the sending device), thus guaranteeing that the data does not come from a fraudulent source and ensuring data integrity.
[0064] Additionally, in one implementation the Pulse Gateway can check if the data is valid and / or has not been manipulated (for example, by consulting a database or checking that the data format is correct).
[0065] Step 9 (209). If the verification process is successful, a success message is sent to the repository. Otherwise, a failure message is sent indicating that the data is invalid and should not be stored. This message can include the data (in the case of successful verification) for the repository to store (because until now, the repository has not had access to the unencrypted data). The message (success or failure) can also be digitally signed with a traditional digital signature.
[0066] Step 10 (210). The repository communicates with the user (device), indicating that the data has been verified and stored (in case of success) or informing the user that the data has not been verified and therefore has not been stored (in case of failure).
[0067] In an alternative embodiment, the roles of the data repository and the Pulse Gateway can be reversed. That is, the actions and steps previously described as being performed by the repository will be performed by the Pulse Gateway (except for data storage, which remains the repository's responsibility), and vice versa. In this way, the repository stores and verifies the data without knowing the sending device in any way, as it has no contact with it.
[0068] In summary, this paper describes an advanced method and system for verifying the authenticity and integrity of data in telecommunications networks while preserving the anonymity of the sender, focusing on information security and user privacy protection. This technical innovation lies in the telecommunications and computer science sectors, proposing a novel solution for securely managing data and guaranteeing anonymity, privacy, and verification. Through the use of advanced cryptographic algorithms and unique data processing protocols, the system ensures user privacy and anonymity while validating the integrity and authenticity of the transmitted data. This invention offers a significant improvement in the protection of personal information and data management across a variety of critical sectors, standing out for its operational simplicity and robustness compared to existing methods.
[0069] The solution proposed in the present invention is extremely simple, yet efficient. It can be applied in a wide range of scenarios, such as IoT (Internet of Things), healthcare, smart cities, manufacturing, automotive, web access (as illustrated in the example presented), and, in general, any application requiring secure data transmission while preserving user anonymity. In other words, the proposed solution can be applied in any situation where it is necessary to verify information, guaranteeing the anonymity (privacy) of its origin (the information or data must not be able to be associated with its creator) and, at the same time, ensuring that the information is reliable and comes from an authenticated source.In addition to its compatibility with software and hardware elements / devices, the proposed approach differs in efficiency, universal applicability and above all simplicity from other proposals in the scientific literature (such as those based on Differential Privacy, homomorphic encryption, data anonymization techniques or Federated Learning, for example), added to the fact that not all of them are able to combine both privacy and authentication features and that the proposed procedure is compatible with them.For example, by implementing the presented procedure it is technologically feasible (as illustrated) to create a solution that accommodates the demands of providers of restricted access content (e.g., adult content) and the freedoms of citizens, guaranteeing their anonymity and privacy, while protecting unauthorized users (e.g., protecting minors from the dangers of accessing services and applications unsuitable for their age, in the case of adult content).
[0070] Note that in this text, relational terms such as first and second, superior and inferior, and the like, may be used solely to distinguish one entity or action from another, without necessarily requiring or actually implying that relationship or order between said entities or actions. Furthermore, the term “comprises” and its derivatives (such as “comprising,” etc.) should not be understood in an exclusive sense; that is, these terms should not be interpreted as excluding the possibility that what is described and defined may include additional elements, stages, etc.
[0071] Some preferred embodiments of the invention are described in the dependent claims that follow.
[0072] Having sufficiently described the nature of the invention, as well as its practical implementation, it should be noted that its various parts may be manufactured in a variety of materials, sizes, and shapes. Variations may also be introduced into its construction or process as practice may advise, provided they do not alter the fundamental principle of the present invention. The description and drawings merely illustrate the principles of the invention. Therefore, it should be appreciated that those skilled in the art may devise various arrangements which, although not explicitly described or shown herein, represent the principles of the invention and are included within its scope. Furthermore, all examples described should be considered non-limiting with respect to such examples and conditions specifically described.Furthermore, everything set forth in this document relating to the principles, aspects and realizations of the invention, as well as the specific examples thereof, encompass equivalences thereof.
Claims
CLAIMS 1. A method for data verification while preserving privacy, comprising the following steps: a) a first electronic device, the sending device, sends a message to a second electronic device, the receiving device, including a request to perform a data exchange action with the receiving device; b) the receiving device sends the sender information concerning the receiving device and an identification of a third electronic device, the intermediary verifying device; c) the sending device hashes the information concerning the receiving device and a piece of data provided by the sending device, calculates a second hash of the two concatenated hashes, and encrypts the result; the encrypted result is called a complex digital signature;d) the sending device sends a message to the receiving device comprising: information about the receiving device, the hash of the sending device's data, the complex digital signature and the following information encrypted with a key K generated by the sending device: the hash of the information about the receiving device, the sending device's data and the complex digital signature and wherein the message further comprises key K encrypted with a public key of the intermediary verifying device; e) the receiving device hashes the information about the receiving device and concatenates it with the hash of the received sending device's data and compares the result with the result of decrypting the complex digital signature it has received; if both results match, go to step f) and if they do not match, the method terminates;f) the receiving device sends to the intermediary verifying device a message containing the information encrypted with the key K received from the sending device and the encrypted key K received from the sending device; g) the intermediary verifying device using its private key decrypts the key K and using the key K decrypts the received information, obtaining the hash of the information relating to the receiving device, the data of the sending device and the complex digital signature; (h) the intermediary verification device hashes the data received from the sending device and concatenates it with the hash of the information concerning the receiving device and compares the result with the result of decrypting the complex digital signature it has received; (i) the intermediary verification device determines, based at least on the comparison of both results, the success of the verification and if the verification is determined to be successful, a message is sent to the receiving device indicating that the verification is successful and, therefore, the data exchange action required by the sending device can be carried out; wherein communication between the sending device and the receiving device and between the latter and the intermediary verification device is carried out through one or more communication networks.
2. Method according to claim 1, wherein the data exchange action is accessing information through the receiving device and wherein the data provided by the sending device is an identifier of a user of the sending device.
3. Method according to claim 2 wherein in step i), the intermediary verification device determines that the verification is successful if the results match and if, from said user identifier, the intermediary verification device verifies that the user meets a certain condition the sender information is valid.
4. Method according to any of claims 2 or 3, wherein the data exchange action is accessing a web page through the recipient device and the information relating to the recipient device is the identification of a web page that the user wants to access.
5. Method according to any of claims 2-4, wherein the recipient device is a web server.
6. Method according to claim 1, wherein the data exchange action is to provide data to the receiving device so that it has access to it, where the information concerning the intended device is a unique identifier of the receiving device, where the data provided by the sending device is the data to which the sending device wants the receiving device to have access, and where, if in step i) the verification is determined to be successful, the intermediary verifying device includes the data in the message sent to the receiving device in step i).
7. Method according to claim 6, wherein the recipient device is a repository and wherein said repository stores the data if in step i) it is determined that the verification is successful.
8. Method according to any of the preceding claims wherein the encryption in step c) is performed using a private key of the sending device and in steps e) and h) it is decrypted using a public key of the sending device.
9. Method according to any of the preceding claims wherein the intermediary verifying device is a gateway device.
10. Method according to any of the preceding claims wherein one or more communication networks are wireless networks.
11. Method according to claim 10 wherein the one or more communication networks are networks of at least one of the following types: 2G, 3G, 4G, 5G mobile telephone network, local area network, fiber optic network.
12. Method according to any of the preceding claims wherein the identification of the third electronic device is a digital certificate of the third electronic device.
13. A system for data verification while preserving privacy, where the system comprises a first electronic device, the sender device, a second electronic device, the receiver device, and a third electronic device, the intermediary verification device; where communication between the sender device and the receiver device and between the receiver device and the receiver device The verification intermediary is carried out through one or more communication networks and where: The sending device is configured to: send to the receiving device a message including a request to perform a data exchange action with the receiving device; receive from the receiving device information regarding the receiving device and an identification of the intermediary verifying device; perform a hash of the information regarding the receiving device, a hash of data provided by the sending device, calculate a second hash of both concatenated hashes and encrypt the result; the encrypted result is called a complex digital signature;send a message to the receiving device comprising: the information regarding the receiving device received, the hash of the data from the sending device, the complex digital signature and the following information encrypted with a key K generated by the sending device: the hash of the information regarding the receiving device, the data from the sending device and the complex digital signature and wherein the message further comprises the key K encrypted with a public key of the intermediary verifying device; The receiving device is configured to: hash the information concerning the receiving device, concatenate it with the hash of the data from the sending device received, and compare the result with the result of decrypting the complex digital signature it has received; and, if both results match, send to the intermediary verifying device a message containing the information encrypted with the key K received from the sending device and the encrypted key K received from the sending device; and the intermediary verifying device is configured to: use its private key to decrypt key K and use key K to decrypt the received information, obtaining the hash of the information concerning the receiving device, the data from the sending device, and the complex digital signature; Perform the hash of the received data from the sending device and concatenate it with the hash of the information regarding the receiving device and compare the result with the result of decrypting the complex digital signature that has been received; determine, based at least on the comparison of both results, the success of the verification and if it is determined that the verification is successful, send a message to the receiving device indicating that the verification is successful and, therefore, the data exchange action required by the sending device can be performed.
14. System according to claim 13, wherein the data exchange action is accessing a web page through the receiving device and wherein the data provided by the sending device is an identifier of a user of the sending device; and wherein the intermediary verifying device determines that the verification is successful if the results match and if, from said user identifier, the intermediary verifying device verifies that the user meets a certain condition and the sender's information is valid.
15. System according to claim 13, wherein the data exchange action is to send data to the receiving device for storage, wherein the information concerning the receiving device is a unique identifier of the receiving device, wherein the data provided by the sending device is data that the sending device wants the receiving device to store, and wherein, if verification is successful, the verifying intermediary device sends a message to the receiving device including the data to be stored.
Citation Information
Patent Citations
Method of authentication of users in data processing systems
ES2456815T3
Device and method for identifying a website
ES2755763T3
System and method for information protection
ES2859569T3
Blockchain data protection based on a generic account model and homomorphic encryption
ES2880458T3
Mutual Anti-piracy authentication system in smartphone-type software tokens and in the SMS thereof
WO2013045716A1