IP Library Granted Patent US 8,650,403
Granted Patent B2
US 8,650,403 · App. 13/375,736 · Granted Feb 11, 2014

Crytographic method for anonymous authentication and separate identification of a user

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,650,403
App. No.
13/375,736
Granted
Feb 11, 2014
Kind
B2
Abstract

The invention relates to cryptographic method for the anonymous authentication and the identification of a user entity (U i ) respectively by a checking entity (D) and an identifying entity (O). According to this method, the checking entity (D) receives ( 130 ) from the user entity (U 1 ) at least one first signature (σ) and a first message (m), and checks ( 140 ) the first signature (σ) using the first message (m) in order to authenticate the user (U), and the identifying entity (O) receives ( 150 ) from the checking entity (D) a second signature (σ′) connected to the first signature (σ) and identifies ( 160 ) the user using the second signature and a secret key particular thereto. The invention also relates to a cryptographic system for implementing said method.

Claims (26)

1. A cryptographic method for anonymous authentication and identification of a user entity by a checking entity and an identifying entity respectively, wherein:

the checking entity receives from the user entity at least one first signature and a first message and verifies the first signature by means of the first message in order to authenticate the user entity; and

the identifying entity receives from the checking entity a second signature linked to the first signature and identifies the user entity by means of the second signature and a secret key specific to the identifying entity;

wherein said method is executed by a processor device.

2. The cryptographic method according to claim 1 , wherein the checking entity generates the second signature from the first signature as a function of at least a first part of the first message received.

3. A cryptographic method for anonymous authentication and identification of a user entity by a checking entity and an identifying entity respectively, wherein:

the checking entity receives from the user entity at least one first signature and a first message and verifies the first signature by means of the first message in order to authenticate the user entity; and

the identifying entity receives from the checking entity a second signature linked to the first signature and identifies the user entity by means of the second signature and a secret key specific to the identifying entity;

wherein the checking entity generates the second signature from the first signature as a function of at least a first part of the first message received and wherein the checking entity generates a second message from the first message by replacing the first part of the first message with substitution data, and sends the second message to the identifying unit; and

wherein said method is executed by a processor device.

4. The cryptographic method according to claim 3 , wherein the checking entity is able to provide a service to the user entity if the checking entity authenticates the user entity wherein the identifying entity is able to invoice the user entity for this service, and wherein the first part indicates a service requested by the user entity and the second message comprises at least one part indicating the invoicing level related to the requested service.

5. The cryptographic method according to claim 4 , wherein the substitution data comprises the part indicating the invoicing level related to the requested service.

6. The cryptographic method according to claim 4 , wherein the first message comprises a second part indicating the invoicing level related to the requested service, and wherein the substitution data of the first message is sent by the user entity to the checking entity.

7. The cryptographic method according to claim 6 , wherein it comprises, in the identifying entity, the verification of the second signature by means of the second message.

8. The cryptographic method according to claim 1 , wherein the first message comprises a first part, wherein, in the user entity, the first signature is generated as a function of the first message and the second signature is generated as a function of a second message, said second message corresponding to the first message in which the first part has been replaced by substitution data.

9. The cryptographic method according to claim 8 , wherein the second signature comprises at least one supplemental part comprised in the first signature (a), wherein said method comprises a verification step in the verification entity, to verify that the first and second signatures comprise said supplemental part.

10. The cryptographic method according to claim 8 , wherein the checking entity is able to provide a service to the user entity if the checking entity authenticates the user entity, wherein the identifying entity is able to invoice the user entity for this service, and wherein said first part indicates a service requested by the user entity and said substitution data indicates an invoicing level related to the requested service.

11. A cryptographic method for anonymous authentication and identification of a user entity by a checking entity and an identifying entity respectively, wherein:

the checking entity receives from the user entity at least one first signature and a first message and verifies the first signature by means of the first message in order to authenticate the user entity; and

the identifying entity receives from the checking entity a second signature linked to the first signature and identifies the user entity by means of the second signature and a secret key specific to the identifying entity;

further comprising preliminarily registering the user entity with a management entity in which the user entity obtains at least one element from the management entity, said element being used to generate the first signature;

wherein said method is executed by a processor device.

12. The cryptographic method according to claim 11 , wherein said element is a certificate generated by the management entity as a function of a random number generated by the user entity.

13. The cryptographic method according to claim 12 , wherein the management entity provides the certificate to the identifying entity and wherein the identification of the user entity is done using at least a part of the certificate, a secret key specific to the identifying entity, and at least a part of the second signature.

14. A cryptographic system for the separate authentication and identification of a user entity, comprising at least one user entity and a checking entity and an identifying entity, said system being able to implement a cryptographic method according to claim 1 .

15. A cryptographic system for the separate authentication and identification of a user entity, said cryptographic system comprising at least one user entity, a checking entity, an identifying entity, and a management entity, wherein said cryptographic system is able to implement a cryptographic method according to claim 11 .

Assignments (2)
CHANGE OF NAME Recorded Apr 16, 2014
From: FRANCE TELECOM
To: ORANGE
Reel/Frame 032698/0396 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2012
From: CANARD, SEBASTIEN; JAMBERT, AMANDINE; MALVILLE, ERIC
To: FRANCE TELECOM
Reel/Frame 028033/0317 →