Anonymous Access Authorization for Collaborative Anonymization Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing collaborative anonymization platforms lack effective access control mechanisms that compromise user anonymity during connection and usage, especially when interacting with multiple service providers, exposing vulnerabilities through mutual knowledge between operators.
Innovation Solution
A method and device implementing a role-distributed authorization mechanism using random private key generation and verification across multiple operators to ensure anonymous access to a collaborative anonymization platform without revealing user identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control mechanisms are implemented on collaborative anonymization platforms, then security and controlled access are improved, but user anonymity is compromised
Solution Approach 1:
The patent introduces a third-party authorization server as an intermediary that mediates between the user and the anonymization platform operators. This server issues authorization tokens that prove the user's right to access without revealing their identity to the operators. The intermediary handles the authentication logic centrally, allowing operators to verify access rights without seeing user identities, thus maintaining anonymity while enabling security control.
Solution Approach 2:
The authentication and authorization functions are extracted from the operators and placed in a separate authorization server. Operators only receive authorization tokens from this external service, which contain minimal information needed for access control. This extraction removes the vulnerability where operators could directly identify users, as the authentication logic is separated and token-based verification is used instead of direct user identity verification.
2Ease of operation
If roaming mechanisms are used for access control, then access authorization is improved, but mutual knowledge between operators creates security vulnerabilities
Solution Approach 1:
The authorization server acts as an intermediary that eliminates direct communication and mutual knowledge requirements between operators. Instead of operators needing to know each other's authentication details, the server issues tokens to users and operators verify access using these tokens. This intermediary approach allows authorization to work across operator boundaries without creating the harmful mutual knowledge vulnerability inherent in traditional roaming mechanisms.
Solution Approach 2:
The system uses authorization tokens as copies that carry access rights information without revealing user identities. These tokens are distributed by the authorization server and validated by operators, allowing access authorization to function without operators needing direct knowledge of each other's authentication systems. The token serves as a portable copy of authorization information that maintains security.
3Adaptability or versatility
If authentication mechanisms are added to anonymization platforms, then access control capability is improved, but the platform complexity increases
Solution Approach 1:
The authentication and authorization functionality is segmented into a separate authorization server that operates independently from the anonymization platform operators. This segmentation allows access control capability to be added without increasing operator complexity, as they only need to implement simple token verification rather than complex authentication systems. The authorization server handles the complexity centrally.
Solution Approach 2:
The authorization server provides universal access control functionality that can be used by multiple operators without each needing to implement their own authentication systems. This multi-functional service allows different operators to access the anonymization platform using a common authorization mechanism, improving adaptability while avoiding the complexity that would arise from each operator maintaining separate authentication infrastructure.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The invention relates to a computer-implemented device and method for allowing a user who has access rights granted by a first operator, totally anonymous and secure access, without any trusted third party, to a collaborative anonymization platform and/or to a service requiring anonymity properties based on such a platform operated by different operators.