Anonymous Attestation via Intermediary Credential Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anonymous attestation cryptographic protocols are limited by the computational expense of credential validation, which is prohibitive for low-power devices like those in the Internet of Things, restricting their use to larger devices with sufficient processing resources.

Innovation Solution

Delegating computationally expensive credential validation tasks to a separate intermediary device, which is a consumer electronics device distinct from the target device, while keeping secret information secure, allowing smaller devices to use anonymous attestation protocols without compromising security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credential validation is performed on the target device itself, then security is maintained, but the processing burden and energy consumption become prohibitive for low-power devices

Engineering Contradiction:
ImprovesecurityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces an intermediary device that acts as a mediator between the target device and the credential validation process. The intermediary device performs the computationally expensive credential validation operations, while the target device only needs to provide minimal authentication data. This resolves the contradiction by maintaining security (through proper validation) while dramatically reducing energy consumption on the target device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication system into distinct functional components: the target device (which holds secret information), the intermediary device (which performs validation), and the verifier (which receives attestation). By dividing the validation burden to the intermediary device, the system maintains security while enabling low-power operation for resource-constrained target devices.

Inventive Principle:
Principle #1Segmentation

2Use of energy by moving object

If credential validation is delegated to an intermediary device, then energy consumption is reduced, but device complexity increases

Engineering Contradiction:
Improveenergy consumptionVSAvoidsystem complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The intermediary device is designed to perform multiple functions: it validates credentials from multiple different target devices, manages cryptographic operations, and communicates with various verifiers. This multi-functionality justifies the added complexity by consolidating validation capabilities that would otherwise need to exist in every target device, thereby reducing overall system energy consumption.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If anonymous attestation protocols are implemented on low-power devices, then privacy is protected, but computational resources are insufficient

Engineering Contradiction:
Improveprivacy protectionVSAvoidcomputational power
Core Design Contradiction:
Loss of informationVSPower

Solution Approach 1:

The intermediary device serves as a computational bridge that enables anonymous attestation protocols on low-power devices. It performs the heavy cryptographic validation work that would be impossible on resource-constrained devices, while the target devices only need to participate in lightweight authentication exchanges, thus preserving privacy without requiring high computational power.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses cryptographic credentials and public keys as digital representations that can be validated without requiring the actual secret information to leave the target device. This allows low-power devices to participate in anonymous attestation by working with lightweight cryptographic artifacts rather than performing heavy computations with full credential data.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11349827B2Anonymous attestation
Publication Date: 2022.05.31 QUALCOMM TECHNOLOGIES INC
  • US11349827B2 patent drawing
  • US11349827B2 patent drawing
  • US11349827B2 patent drawing

AI summary

An anonymous attestation cryptographic protocol is provided for enabling a target (device 4) to attest to a predetermined property of the device without needing to reveal its identity to a verifier (8). When obtaining a credential from an issuer (6) to attest to the predetermined property, the credential is validated by an intermediary device (2) which is a separate consumer electronics device to the target device (4) itself. This allows the relatively processor-intensive calculations required for validating the credential to be performed on a separate device (2) from the device (4) for which the attestation has been made, allowing anonymous attestation protocols to be used for lower powered target devices such as sensors in the internet of things.