Anonymous Access Authorization for Collaborative Anonymization Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing collaborative anonymization platforms lack effective access control mechanisms that compromise user anonymity during connection and usage, especially when interacting with multiple service providers, exposing vulnerabilities through mutual knowledge between operators.

Innovation Solution

A method and device implementing a role-distributed authorization mechanism using random private key generation and verification across multiple operators to ensure anonymous access to a collaborative anonymization platform without revealing user identities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control mechanisms are implemented on collaborative anonymization platforms, then security and controlled access are improved, but user anonymity is compromised

Engineering Contradiction:
Improveaccess control securityVSAvoiduser anonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a third-party authorization server as an intermediary that mediates between the user and the anonymization platform operators. This server issues authorization tokens that prove the user's right to access without revealing their identity to the operators. The intermediary handles the authentication logic centrally, allowing operators to verify access rights without seeing user identities, thus maintaining anonymity while enabling security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication and authorization functions are extracted from the operators and placed in a separate authorization server. Operators only receive authorization tokens from this external service, which contain minimal information needed for access control. This extraction removes the vulnerability where operators could directly identify users, as the authentication logic is separated and token-based verification is used instead of direct user identity verification.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If roaming mechanisms are used for access control, then access authorization is improved, but mutual knowledge between operators creates security vulnerabilities

Engineering Contradiction:
Improveaccess authorizationVSAvoidoperator identification vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The authorization server acts as an intermediary that eliminates direct communication and mutual knowledge requirements between operators. Instead of operators needing to know each other's authentication details, the server issues tokens to users and operators verify access using these tokens. This intermediary approach allows authorization to work across operator boundaries without creating the harmful mutual knowledge vulnerability inherent in traditional roaming mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses authorization tokens as copies that carry access rights information without revealing user identities. These tokens are distributed by the authorization server and validated by operators, allowing access authorization to function without operators needing direct knowledge of each other's authentication systems. The token serves as a portable copy of authorization information that maintains security.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If authentication mechanisms are added to anonymization platforms, then access control capability is improved, but the platform complexity increases

Engineering Contradiction:
Improveaccess control capabilityVSAvoidplatform complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication and authorization functionality is segmented into a separate authorization server that operates independently from the anonymization platform operators. This segmentation allows access control capability to be added without increasing operator complexity, as they only need to implement simple token verification rather than complex authentication systems. The authorization server handles the complexity centrally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authorization server provides universal access control functionality that can be used by multiple operators without each needing to implement their own authentication systems. This multi-functional service allows different operators to access the anonymization platform using a common authorization mechanism, improving adaptability while avoiding the complexity that would arise from each operator maintaining separate authentication infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4078893B1Method and device for controlling anonymous access to a collaborative anonymization platform
Publication Date: 2026.03.25 COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
  • EP4078893B1 patent drawingFigure 1~2
  • EP4078893B1 patent drawingFigure 3
  • EP4078893B1 patent drawingFigure 4

AI summary

The invention relates to a computer-implemented device and method for allowing a user who has access rights granted by a first operator, totally anonymous and secure access, without any trusted third party, to a collaborative anonymization platform and/or to a service requiring anonymity properties based on such a platform operated by different operators.