IP Library Patent Application 12355862
Patent Application
App. No. 12/355,862

ANONYMOUS KEY ISSUING FOR ATTRIBUTE-BASED ENCRYPTION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/355,862
Abstract

The claimed subject matter provides systems and/or methods that establish a decryption key for use with an attribute authority. The system can include components that identify a pseudonym based a global identifier (GID) associated with a user, initiates communication with the attribute authority, and selects a first random value utilized to determine a first value. The system also includes components that select a second random value, employs the first value and the second random value to generate a second value and a third value, receives the second value and the third value, identifies a third random value, and employs the second value, the third value, the first random value, and the third random value to determine a fourth value which is employed to determine a fifth value. The fifth value is employed to derive the decryption key for use with the attribute authority.

Claims (35)

1 . A machine implemented system that effectuates obtaining a decryption key, or part thereof, from an attribute authority without revealing a global identifier (GID) to the attribute authority, comprising:

a processor configured for identifying a pseudonym based at least in part on the global identifier (GID), initiating communication with the attribute authority, selecting a first random value, sending and receiving a series of messages to the attribute authority, receiving values from the attribute authority, selecting a second random value, employing the received values from the attribute authority and the second random value to generate a third value, sending the third value to the attribute authority, receiving a final value from the attribute authority, utilizing the final value and the second random number to determine a fifth value, and utilizing the fifth value to derive the decryption key; and

a memory coupled to the processor for persisting data.

2 . The system of claim 1 , the initiating communication establishes a two party computation (2PC) where a first set of messages is dispatched executing computation of a blinding function applied to a combination of a user's secret and the attribute authority's secret, using the first random value.

3 . The system of claim 1 , the third value determined by subjecting the first value to an unblinding function, combining the unblinded first value with the second value, and employing a blinding function on the combined values using the second random value.

4 . The system of claim 3 , the blinding function utilizes one of multiplication or exponentiation on the combined values and the second random value.

5 . The system of claim 3 , the unblinding function utilizes one of exponentiation or division on the first value to determine the unblinded first value.

6 . The system of claim 1 , the fifth value determined by subjecting the final value received from the attribute authority to an unblinding function.

7 . The system of claim 1 , the global identifier (GID) persisted in the memory.

8 . A machine implemented method for establishing a decryption key for use with an attribute authority, comprising:

identifying a pseudonym based at least in part on a global identifier (GID);

initiating communication with the attribute authority;

selecting a first random value;

sending and receiving a series of messages to the attribute authority;

receiving values from the attribute authority;

selecting a second random value;

employing the received values from the attribute authority and the second random value to generate a third value;

sending the third value to the attribute authority;

receiving a final value from the attribute authority;

employing the final value and the second random number to determine a fifth value; and

utilizing the fifth value to derive the decryption key.

9 . The method of claim 8 , the initiating communication establishes a two party computation where a first set of messages is dispatched executing computation of a blinding function applied to a combination of a user's secret and the attribute authority's secret, using the first random value.

10 . The method of claim 8 , the third value determined by subjecting the first value to an unblinding function, combining the unblinded first value with the second value, and employing a blinding function on the combined values using the second random value

11 . The method of claim 10 , the blinding function utilizes one of multiplication or exponentiation on the combined values and the second random value.

12 . The method of claim 10 , the unblinding function utilizes one of exponentiation or division on the first value to determine the unblinded first value.

13 . The method of claim 8 , the fifth value determined by subjecting the final value received from the attribute authority to an unblinding function

14 . The method of claim 8 , the decryption key combinable with one or more other decryption keys obtained from one or more other attribute authorities that employ pseudonyms obtained from the global identifier (GID).

15 . A machine implemented system that issues to a user a decryption key or part thereof, comprising:

a memory that retains instructions related to receiving communication from a user, sending and receiving a series of messages to the user, deriving from these messages a first value, selecting a random value, using the first value and the random value and persisted secret values to determine a second value and a third value, sending the second value and the third value to the user, receiving a fourth value, computing a fifth value from the random value and the fourth value, and sending the fifth value to the user; and

a processor, coupled to the memory, configured to execute the instructions retained in the memory.

16 . The system of claim 15 , the receiving communication from a user establishes a two party computation (2PC) where a first set of messages is dispatched executing computation of a blinding function applied to a combination of a user's secret and the attribute authority's secret, and a random value chosen by the user.

17 . The system of claim 15 , subjecting the first value to a blinding function that employs the random value to determine the second value.

18 . The system of claim 15 , subjecting one of the persisted secret values to a blinding function that utilizes the random value to ascertain the third value.

19 . The system of claim 15 , the fifth value obtained by employing an unblinding function on the fourth value.

20 . The system of claim 19 , the unblinding function employs one of exponentiation or division to unmask the fourth value.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2015
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034766/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2009
From: CHASE, MELISSA E.; CHOW, SZE MING
To: MICROSOFT CORPORATION
Reel/Frame 022124/0047 →