IP Library › Granted Patent US 7,444,512
Granted Patent B2
US 7,444,512 · App. 10/412,366 · Granted Oct 28, 2008

Establishing trust without revealing identity

Assignee: Intel Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,444,512
App. No.
10/412,366
Granted
Oct 28, 2008
Kind
B2
Abstract

A method, system, and apparatus are provided for establishing trust without revealing identity. According to one embodiment, values in a first proof corresponding to a first statement are precomputed, a request for a second proof is received from a challenger, and the first and second proofs are completed.

Claims (25)

1. A method comprising:

pre-computing values in a first proof corresponding to a first statement, the values are pre-computed at a first device based on information received from a second device, the first statement having a first key to a target device that the second device is seeking to access, wherein pre-computing includes selecting a parameter, and based on the parameter, verifying trust between the second device and the target device;

receiving a proof request from the second device;

verifying validity of the first proof, and generating a second proof based on the values, the second proof corresponding to a second statement, the second statement having a second key to the target device;

sending the second proof to the second device, the second proof revealing trustworthiness of the target device without revealing identity of the target device; and

establishing trust between the target device and the second device, the second device to access the target device, wherein the trust is established via a direct proof protocol providing for one or more of constructing the first and second proofs randomly or pseudo-randomly, and constructing the first and second proofs by performing proof computation via the pre-computing values during a pre-computation stage.

2. The method of claim 1 , wherein the second proof comprises a proof that the second statement is true if the first statement is true.

3. The method of claim 1 , wherein the parameter comprises an assurance parameter.

4. A system comprising:

a first device coupled with a second device and a target device, the second device seeking to access the target device, the first device to

pre-compute values in a first proof corresponding to a first statement, the values are pre-computed based on information received from the second device, the first statement having a first key to a target device that the second device is seeking to access, wherein pre-computing includes selecting a parameter, and based on the parameter, verifying trust between the second device and the target device,

receive a proof request from the second device,

verify validity of the first proof, and generate a second proof based on the values, the second proof corresponding to a second statement, the second statement having a second key to the target device,

send the second proof to the second device, the second proof revealing trustworthiness of the target device without revealing identity of the target device, and

establish trust between the target device and the second device, the second device to access the target device, wherein the trust is established via a direct proof protocol providing for one or more of constructing the first and second proofs randomly or pseudo-randomly, and constructing the first and second proofs by performing proof computation via the pre-computing values during a pre-computation stage.

5. The system of claim 4 , wherein the second proof comprises a proof that the second statement is true if the first statement is true.

6. The system of claim 4 , wherein the parameter comprises an assurance parameter.

7. A machine-readable medium comprising instructions which, when executed, cause a machine to:

pre-calculate values in a first proof corresponding to a first statement, the values are pre-computed at a first device based on information received from a second device, the first statement having a first key to a target device that the second device is seeking to access, wherein pre-computing includes selecting a parameter, and based on the parameter, verifying trust between the target device and the second device;

receive a proof request from the second device;

verify validity of the first proof, and generate a second proof based on the values, the second proof corresponding to a second statement, the second statement having a second key to the target device;

send the second proof to the second device, the second proof revealing trustworthiness of the target device without revealing identity of the target device; and

establish trust between the target device and the second device, the second device to access the target device, wherein the trust is established via a direct proof protocol providing for one or more of constructing the first and second proofs randomly or pseudo-randomly, and constructing the first and second proofs by performing proof computation via the pre-computing values during a pre-computation stage.

8. The machine-readable medium of claim 7 , wherein the second proof comprises a proof that a second statement is true if the first statement is true.

9. The machine-readable medium of claim 7 , wherein the parameter comprises an assurance parameter.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2003
From: BRICKELL, ERNIE F.
To: INTEL CORPORATION
Reel/Frame 013969/0296 →
Continuity (1)
Related Publication 20040205341A1 · Oct 14, 2004