Cryptographic Pseudonym Mapping via Elliptic Curves

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic pseudonym mapping solutions require secure hardware, such as cryptoprocessors, which are costly and difficult to implement, and are vulnerable to attacks like rainbow table generation and malicious cooperation between data sources.

Innovation Solution

A cryptographic pseudonym mapping method using modular exponentiation on residue classes and elliptic curves, which does not require special hardware, ensuring a one-to-one mapping and preventing entities from accessing decryption keys or pseudonym mapping keys, utilizing blockchain technology for decentralized authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure hardware (cryptoprocessors) is used for pseudonym mapping, then security against attacks is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical secure hardware (cryptoprocessors) with a cryptographic mathematical system based on modular exponentiation on elliptic curves. The security is achieved through mathematical properties rather than physical hardware protection, eliminating the need for specialized secure devices while maintaining security against rainbow table attacks and malicious cooperation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the cryptographic parameters by using modular exponentiation on elliptic curves with specifically chosen large prime numbers and generator points. This mathematical parameter selection creates computational hardness that provides security equivalent to hardware-based solutions without requiring them.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If traditional cryptographic mapping is used, then pseudonym generation is achieved, but vulnerability to rainbow table attacks increases

Engineering Contradiction:
Improvepseudonym generationVSAvoidrainbow table attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent moves the cryptographic operation to a different mathematical dimension by using modular exponentiation on elliptic curve points rather than traditional hash functions or symmetric encryption. This dimensional change in the mathematical space makes rainbow table attacks computationally infeasible while maintaining efficient pseudonym generation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If data sources can access decryption keys, then mapping flexibility is improved, but security against malicious cooperation deteriorates

Engineering Contradiction:
Improvemapping flexibilityVSAvoidsecurity against malicious cooperation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the cryptographic key into multiple components: the public generator point G, the private large prime number p, and the mapping exponent k. No single entity possesses all components needed to compromise security, preventing malicious cooperation while allowing flexible pseudonym mapping through the public key infrastructure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11856099B2Cryptographic pseudonym mapping method, computer system, computer program and computer-readable medium
Publication Date: 2023.12.26 XTENDR ZRT
  • US11856099B2 patent drawing
  • US11856099B2 patent drawing
  • US11856099B2 patent drawing

AI summary

The invention is a cryptographic pseudonym mapping method for an anonymous data sharing system, the method being adapted for generating a pseudonymised database (DB) from data relating to entities and originating from data sources (DSi), wherein the data are identified at the data sources (DSi) by entity identifiers (D) of the respective entities, and wherein the data are identified in the pseudonymised database (DB) by pseudonyms (P) assigned to the respective entity identifiers (D) applying a one-to-one mapping, irrespective of the originating data source. According to the invention, more than one mapper (Mj) is applied, and a respective pseudonym (P) is generated by sequentially performing, in a permutation of the mappers (Mj), a number k of mappings utilizing the mapping cryptographic keys (hij) of the mappers (Mj) belonging to the particular data source (DSi) on each encrypted entity identifier (Ci0) encrypted by the data source (DSi).