×

USER CONTROLLED ANONYMITY WHEN EVALUATING INTO A ROLE

  • US 20090024850A1
  • Filed: 09/23/2008
  • Published: 01/22/2009
  • Est. Priority Date: 06/17/2004
  • Status: Active Grant
First Claim
Patent Images

1. A system for anonymous role authentication, comprising:

  • an anonymous authentication controller communicatively connected to role authenticator via a network;

    said anonymous authentication controller for requesting a role authentication certificate from said role authenticator;

    said anonymous authentication controller for providing a credential that enables said role authenticator to determine that said particular user is a member of a particular role and a plurality of blinded role authentication certificates identifying said particular role;

    said role authenticator, responsive to receiving said credential that specifies said particular user is a member of said particular role and receiving said plurality of blinded role authentication certificates, for requesting blinding factors for a only a random selection of said plurality of blinded role authentication certificates;

    said anonymous authentication controller, responsive to receiving said request for said blinding factors for only said random selection of said plurality of blinded role authentication certificates, for returning said selection of blinding factors for only said random selection of said plurality of blinded role authentication certificates;

    said role authenticator, responsive to receiving said returned selection of blinding factors, for unblinding said random selection of said plurality of blinded role authentication certificates and comparing roles specified in said unblinded selection of said plurality of blinded role authenticated certificates with said particular role;

    said role authenticator, responsive to detecting said roles specified in said unblinded selection of said plurality of blinded role authenticated certificates match said particular role, for applying a digital signature to a remaining blinded selection of said plurality of blinded role authentication certificates and returning said signed remaining blinded selection of said plurality of blinded role authentication certificates to said anonymous authentication controller, wherein said signed remaining blinded selection of said plurality of blinded role authentication certificates authenticate that a holder of said role authentication certificate is a member of a particular role without allowing said role authenticator issuing said role authentication certificate to track an identity of a particular user holding said role authentication certificate;

    said anonymous authentication controller, responsive to verifying that said digital signature of said role authenticator on said signed remaining blinded selection of said plurality of blinded role authentication certificates does not contain a subliminal channel that allows said role authenticator to include an identity of said particular user, for unblinding said signed remaining blinded selection of said plurality of blinded role authentication certificates while preserving said digital signature of said role authenticator;

    said anonymous authentication controller for establishing an anonymous channel for anonymously presenting one of unblended signed role certificates as said role authentication certificate to a resource protector via said network, wherein said resource protector requires said particular user to authenticate into said particular role to access a resource, wherein said role authentication certificate authenticates said particular user into said particular role without enabling said resource protector to ascertain said identity of said particular user.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×