Anonymous Authentication via Intermediary Server and Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity authentication methods based on public key cryptography expose user identity information, failing to protect privacy and lacking traceability features necessary for control.
Innovation Solution
A method and system for authentication that involves a first and second authenticator, and an authentication server, where the second authenticator remains anonymous during authentication, with information exchange structured to protect privacy and enable traceability by using security domains and time-varying parameters to verify legitimacy without revealing identity information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If identity authentication is performed using public key cryptography, then legitimacy verification is achieved, but user identity information is exposed
Solution Approach 1:
The patent introduces a trusted third-party authentication server as an intermediary between the user and the verifying party. The authentication server performs the actual identity verification using secure cryptographic methods, while only returning verification results without exposing the user's identity information. This mediator approach allows legitimacy verification to be performed reliably while preventing direct exposure of sensitive identity data between the user and the verifying system.
2Loss of information
If privacy protection is implemented during authentication, then identity information is protected, but capability of traceability is lost
Solution Approach 1:
The patent segments the authentication information into multiple components: identity information, verification results, and traceability identifiers. The authentication server processes and verifies identity information securely while maintaining separate traceability records. This segmentation allows the system to protect sensitive identity information from exposure while simultaneously maintaining the capability to trace and control authentication events through separate identifier mechanisms.
3Speed
If direct authentication between parties is performed, then authentication speed is fast, but privacy exposure occurs
Solution Approach 1:
The authentication server acts as a mediator that enables fast authentication by pre-processing verification operations and returning ready-made verification results. This eliminates the need for complex real-time cryptographic operations between the user and verifying party, significantly speeding up authentication while the intermediary structure simultaneously prevents identity information exposure through controlled information disclosure.
Data Source
AI summary
A method and device device for authentication are provided. The method includes: a second authenticator transmitting to a first authenticator a first identity authentication message; the first authenticator transmitting to an authentication server a second identity authentication message; the authentication server verifying the validity of a secure domain where the second authenticator is at and of the first authenticator on the basis of the second identity authentication message; the authentication server returning to the first authenticator a third identity authentication message; the first authenticator transmitting to the second authenticator a fourth identity authentication message; the second authenticator proceeding to verification when the fourth identity authentication message is received; the second authenticator transmitting to the first authenticator a fifth identity authentication message; and the first authenticator proceeding when the fifth identity authentication message is received.


