Revoking Delegatable Anonymous Credentials via Accumulator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Revoking delegatable anonymous credentials is challenging due to difficulties in anonymously proving that a credential is not revoked, especially in systems with delegatable credentials where chains of delegation are complex due to anonymity protections.

Innovation Solution

A method and system utilizing a dynamic universal accumulator with delegatable non-membership proofs that allow users to prove non-revocation of credentials without revealing their identity, enabling revocation of credentials from both the original and delegated entities, and supporting redelegation and unlinkability of proofs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anonymity protections are implemented in credential systems, then user privacy is protected, but the ability to trace and revoke delegated credentials is weakened

Engineering Contradiction:
Improvecredential revocation capabilityVSAvoiddelegation chain tracing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces accumulators as an intermediary mechanism that enables revocation verification without exposing delegation chains. The accumulator acts as a trusted mediator that holds the set of revoked credential identifiers, allowing verifiers to check revocation status anonymously through non-membership proofs while maintaining the anonymity properties of the delegation system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves the revocation information from the delegation chain dimension to a separate accumulator dimension. Instead of tracking revocation through the complex delegation chain, the system projects revocation status into a separate mathematical space (the accumulator) where efficient verification is possible without revealing chain relationships.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If delegatable credentials are allowed, then credential flexibility and reusability are improved, but the difficulty of proving non-revocation status increases

Engineering Contradiction:
Improvecredential delegabilityVSAvoidnon-revocation proof difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent replaces the mechanical approach of tracking individual delegation chains with a cryptographic mathematical system based on accumulators and non-membership proofs. This substitution enables efficient verification of non-revocation status without requiring traversal or analysis of the delegation chain structure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the parameter representation from individual credential identifiers in a chain to a aggregated accumulator value. The revocation status is represented not by listing all valid credentials but by a single accumulator state that enables efficient non-membership verification through cryptographic parameters.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional revocation methods are used, then credential invalidation is achieved, but user anonymity is compromised due to the need to prove non-membership in revoked sets

Engineering Contradiction:
Improverevocation effectivenessVSAvoiduser identity anonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the revocation verification process from the identity disclosure process. Users can prove their credentials are not revoked by demonstrating non-membership in the accumulator without revealing any information about their identity or delegation chain, separating the revocation proof from identity revelation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses disposable, anonymous proof tokens that allow users to verify their non-revoked status without creating permanent traces. Each non-membership proof can be generated and discarded independently, allowing users to prove validity without leaving enduring information that could compromise anonymity.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8839381B2Revoking delegatable anonymous credentials
Publication Date: 2014.09.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8839381B2 patent drawing
  • US8839381B2 patent drawing
  • US8839381B2 patent drawing

AI summary

The claimed subject matter provides a method for revoking delegatable anonymous credentials. The method includes receiving a request to revoke an anonymous credential. The anonymous credential may be representative of an ability to prove non-membership in an accumulator for a first entity. The method also includes revoking the anonymous credential from the first entity in response to the request to revoke the anonymous credential. Additionally, the method includes revoking the anonymous credential from a second entity in response to the request to revoke the anonymous credential. The first entity delegates the anonymous credential to the second entity.