Aggregated Certificate Anonymous Service Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anonymous accreditation systems are inefficient in terms of calculation time and bandwidth, and they often compromise user anonymity due to the need for large-scale cryptographic data and increased traceability, especially when dealing with multiple certifying organizations.
Innovation Solution
A method for anonymous access to services involving the allocation of certificates by multiple certifying entities, where users calculate an aggregated certificate from multiple certificates, and provide proof of knowledge to verify access without revealing unnecessary attributes, using bilinear environments and cryptographic hash functions to ensure efficiency and anonymity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If group signature techniques are used to sign all attributes, then user anonymity is preserved, but computation time and proof size increase significantly
Solution Approach 1:
The patent segments the accreditation system into multiple independent certificates, each covering specific attributes. Instead of signing all attributes together as in group signatures, each attribute or attribute group gets its own certificate. This allows the user to selectively disclose only the necessary attributes for a given service, avoiding the need to process and hide all attributes simultaneously, thereby reducing computation time and proof size while maintaining anonymity for undisclosed attributes.
Solution Approach 2:
The patent extracts only the necessary attributes from the user's accreditation data for each service request. Rather than dealing with all attributes as in traditional group signatures, the system allows the user to present only the subset of attributes required by the service provider. This extraction approach reduces the computational burden of hiding and processing unnecessary attributes while preserving anonymity for the extracted subset.
2Loss of information
If group signature techniques are used to sign all attributes, then user anonymity is preserved, but the size of the proof increases
Solution Approach 1:
The patent divides the accreditation into multiple smaller certificates rather than one large group signature. Each certificate corresponds to specific attributes and can be independently verified. When a user needs to access a service, only the relevant certificates containing necessary attributes are presented, significantly reducing the proof size compared to presenting all attributes in a group signature structure.
Solution Approach 2:
The system extracts and presents only the minimal set of certificates containing attributes required for the specific service. This selective extraction avoids including unnecessary attributes in the proof, thereby reducing the overall proof size while maintaining the necessary anonymity properties for undisclosed attributes.
3Productivity
If blind signature techniques are used, then accreditation efficiency is improved, but user traceability increases
Solution Approach 1:
The patent uses segmented certificates that can be selectively disclosed rather than relying on blind signatures. Each certificate is self-contained and verifiable independently, providing efficiency similar to blind signatures without the traceability issues. The selective disclosure mechanism allows the user to present only necessary certificates, maintaining anonymity while achieving efficient verification.
4Adaptability or versatility
If multiple certificates from different organizations are used, then service access flexibility is improved, but procedure complexity increases
Solution Approach 1:
The patent provides a unified framework for managing multiple certificates from different certifying entities. The user can aggregate multiple certificates and selectively disclose relevant ones based on service requirements. The verification process handles multiple certificates through a standardized procedure, simplifying the overall complexity compared to managing separate verification processes for each certificate type.
Solution Approach 2:
The patent creates a universal certificate structure that can accommodate attributes from various certifying entities (town halls, universities, etc.). This multi-functional certificate system allows the same verification procedure to handle different types of accreditations, reducing procedure complexity while maintaining flexibility for accessing diverse services.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method of anonymous access to a service, comprising the allocation (100), by at least one certifying entity (Cj), of a plurality of certificates (σι,σΝ·) to a user entity (U), the certificates being calculated on the basis of at least one attribute (mk) associated with the user entity, the calculation (200), by the user entity (U), an aggregated certificate (aa) on the basis of a plurality of certificates (σ1,σΝ) among the certificates allocated to the user entity (U), the calculation (300), by the user entity (U), of a proof of knowledge (ΡοΚσ) of the aggregated certificate (aa) and a verification (400), performed by a verifying entity (V), of at least one of these certificates by means of said proof of knowledge (ΡοΚσ), the access to the service being provided by the verifying entity to the user entity as a function of the result of this verification. The invention furthermore relates to a corresponding computer program, the user entity (U), verifying entity (V) and certificating entity (Q) corresponding as well as to a system of anonymous accreditation (SAA) for anonymous access to a service comprising these various entities.