Anonymous Flexible Credential Authorization via Pseudonym Authority
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authorization systems in computer communication networks compromise user privacy, lack scalability, and are not flexible in revoking access rights, as they often require a trusted third party and involve costly cryptographic computations, making them inefficient and inflexible.
Innovation Solution
A method and apparatus for a communication system that issues root pseudonyms, generates derived pseudonyms, and flexible credentials, allowing users to selectively demonstrate access rights without involving resource holders, enabling unlinkable anonymity, fine-grained revocability, and constant computational cost, regardless of the number of credentials or resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user credentials are retrieved from local database using unique identity, then secure authorization is achieved, but user privacy is compromised
Solution Approach 1:
The patent introduces a pseudonym authority as an intermediary that issues pseudonyms to users. Instead of using unique identities directly, users interact with the system through pseudonyms that are verified by the pseudonym authority. This mediator layer enables authorization without exposing the user's true identity, thus maintaining both security and privacy.
Solution Approach 2:
The patent creates pseudonym copies of user identities that can be used for authorization purposes. These pseudonyms are cryptographic representations that allow verification of credentials without revealing the underlying unique identity. The system verifies credentials against the pseudonym authority's records rather than against the user's actual identity, protecting privacy while maintaining authorization integrity.
2Reliability
If trusted third party is involved in all interactions, then unlinkable anonymity is achieved, but scalability is reduced
Solution Approach 1:
The pseudonym authority performs preliminary actions by issuing pseudonyms and credentials to users in advance. Once issued, these credentials can be used independently without requiring the pseudonym authority's involvement in each subsequent authorization interaction. This preliminary setup enables both anonymity and scalability, as users can autonomously present their credentials to multiple resource holders without repeated third-party involvement.
Solution Approach 2:
The system segments the authorization process into distinct phases: credential issuance by the pseudonym authority, and independent credential verification by resource holders. This segmentation allows the trusted third party to be involved only in the initial credential distribution phase, while subsequent authorization interactions are handled autonomously by users and resource holders, improving scalability while maintaining anonymity.
3Ease of operation
If entire credentials are demonstrated to resource protector, then fine-grained access control is lost, but computational overhead increases
Solution Approach 1:
The patent extracts only the necessary credential information needed for specific resource access from the user's complete credential set. The credential structure allows selective presentation of access rights corresponding to particular resources, rather than requiring demonstration of all credentials. This extraction mechanism enables fine-grained access control while reducing computational overhead by processing only relevant credential portions.
4Reliability
If credentials are reissued for each interaction, then unlinkable anonymity is maintained, but system efficiency decreases
Solution Approach 1:
The pseudonym authority performs preliminary credential issuance that remains valid across multiple interactions. Instead of reissuing credentials for each authorization event, the system uses pre-issued pseudonyms and credentials that can be repeatedly presented. This preliminary action maintains anonymity through pseudonym rotation capabilities while dramatically improving efficiency by eliminating repeated credential issuance operations.
Data Source
AI summary
A method and apparatus for distributed authorization by anonymous flexible credential are provided. Pseudonym authority issues a root pseudonym to a user. The user may generate large amount of derived pseudonym from the root pseudonym. The user may obtain resource credentials from resource protectors by using derived pseudonyms. The user may select a set of resource credentials, generate a flexible credential from this set of resource credentials and request access to the resource corresponding to the set of resource credentials to a resource protector by using the flexible credential and a derived pseudonym. Revocation list for each resource may be maintained in the system such that any one of resource credentials of any user may be revoked without affecting other resource credentials of that user.


