Cryptographic Identities for Private Device Membership

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing group communication systems expose group communication identifiers, such as phone numbers or email addresses, during collaborative sessions, compromising user privacy and device security.

Innovation Solution

Utilizing cryptographic identities and tree data structures to verify device authorization without revealing user or device identifiers, allowing secure access to collaborative items within group communication sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If group communication identifiers (phone numbers, email addresses) are exposed during collaborative sessions, then device authorization and user identification can be verified, but user privacy and device security are compromised

Engineering Contradiction:
Improvedevice authorization verificationVSAvoiduser privacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces cryptographic identities as an intermediary between devices. Instead of directly exposing group communication identifiers, each device generates cryptographic identities from its public key and the group communication identifier. These cryptographic identities serve as mediators that allow authorization verification without revealing the actual user identifiers, thus resolving the contradiction between reliable verification and privacy protection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the identifying information from the group communication identifier by generating cryptographic identities that contain only the necessary authorization data. The actual phone numbers or email addresses are taken out and replaced with cryptographic representations, allowing verification while removing the harmful exposure of personal information

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If cryptographic identities are used to verify device authorization, then user privacy is protected, but system complexity increases due to cryptographic operations

Engineering Contradiction:
Improveuser privacy protectionVSAvoidcryptographic operation complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent performs preliminary cryptographic operations by generating cryptographic identities in advance during device initialization or group creation. The cryptographic identities are pre-computed and stored, so that during actual collaborative sessions, the system only needs to exchange and verify these pre-generated identities rather than performing complex cryptographic operations in real-time, thus reducing operational complexity while maintaining privacy protection

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12437052B2Proving membership using cryptographic identities
Publication Date: 2025.10.07 APPLE INC
  • US12437052B2 patent drawing
  • US12437052B2 patent drawing
  • US12437052B2 patent drawing

AI summary

Aspects of the subject technology include obtaining, by a first device associated with a first user account, one or more item-specific public keys of one or more devices associated with a second user account and generating a data structure representing the one or more devices associated with the second user account based on the one or more item-specific public keys. Aspects may also include providing an identifier of the data structure to a server for association with the item and generating an invitation for the second user account to access the item. Aspects may further include providing the invitation to a second device of the one or more devices associated with the second user account to provide the second device with access to the item via the server based on at least a portion of the data structure and a respective item-specific public key of the second device.