Multi-Party Authentication Using a Privacy-Preserving Accumulator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contemporary authentication processes require disclosure of confidential or personal information, which poses risks of data theft and undesired disclosure to untrustworthy parties.
Innovation Solution
Implementing an independent accumulator that stores user confidential information and generates a proxy or unique identifier for each set of user information, allowing verification without disclosing the user's personal information to requestors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication processes are used to verify user identity, then authentication reliability is improved, but user privacy and security deteriorate due to disclosure of confidential information
Solution Approach 1:
The patent introduces a third-party authentication service that acts as an intermediary between the user and the service provider. This service holds verified copies of user credentials and performs authentication without requiring the user to disclose sensitive information to the service provider, thereby maintaining authentication reliability while protecting user privacy and reducing data theft risk
Solution Approach 2:
The authentication system is segmented into separate functional components: credential verification is performed by a dedicated authentication service, while the service provider only receives authentication results. This segmentation allows the verification process to be conducted securely without exposing confidential information to all parties in the system
2Measurement precision
If user confidential information is disclosed to service providers for verification, then authentication accuracy is improved, but information security deteriorates due to exposure to untrustworthy parties
Solution Approach 1:
A third-party authentication service serves as an intermediary that performs the actual verification of user credentials. The service provider sends authentication requests to this intermediary and receives only the verification result, not the underlying confidential information. This maintains authentication accuracy while preventing undesired disclosure to potentially untrustworthy parties
Solution Approach 2:
The verification function is extracted from the service provider and placed in a dedicated authentication service. This extraction allows the service provider to obtain verification results without obtaining the confidential information itself, thereby maintaining authentication accuracy while eliminating the risk of undesired disclosure
3Object-affected harmful factors
If minimal verification is performed to protect privacy, then user privacy is improved, but authentication reliability deteriorates
Solution Approach 1:
The third-party authentication service performs complete and rigorous verification of user credentials, ensuring high authentication reliability. Meanwhile, the service provider interacts only with this intermediary and receives simple verification results, maintaining strong privacy protection. The intermediary enables both goals to coexist by bearing the burden of thorough verification
Data Source
AI summary
In various examples, a user may be authenticated without disclosing any confidential or private information of the user. An independent accumulator stores user confidential information, and accumulates items issued by various parties for the user. When another entity requests to verify the item and the user, the accumulator may verify the user by verifying his or her possession of the item and his or her private information. The accumulator may also verify the item with the issuing party and verify that the item was intended for the user. Once verification has occurred, the accumulator informs the requesting entity that their request is confirmed. In this manner, entities may verify items of a user, without requiring the user to disclose any of his or her confidential or private information to the requestor.


