IP Library › Granted Patent US 12,445,288
Granted Patent B2
US 12,445,288 · App. 17/644,091 · Granted Oct 14, 2025

Multi-issuer anonymous credentials for permissioned blockchains

Inventors: Kaoutar El Khiyaoui (Zurich, CH); Angelo De Caro (Zurich, CH); Elli Androulaki (Zurich, CH)
Assignee: International Business Machines Corporation
H04L9/3221H04L9/30H04L9/50H04L63/0421
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,288
App. No.
17/644,091
Granted
Oct 14, 2025
Kind
B2
Abstract

A user of a blockchain network may obtain credentials for the user from an issuer, the credentials based on one or more attributes of the user, wherein the issuer is selected from one or more authorized issuers, and wherein the credentials include a signature on the one or more attributes and a secret key; generate an operation composed of a payload and a second signature; compute a commitment to a public key of the issuer; prove, using a one-out-of-many proof, that the commitment is a valid commitment to a public key of one of the authorized issuers; prove, using a zero-knowledge proof, proof of knowledge of the signature and the credentials under the public key of the issuer; and prove, using a proof of knowledge, of values of the signed secret key and attributes.

Claims (45)

1. A system comprising:

a memory; and

a processor in communication with the memory, the processor being configured to perform processes comprising:

obtaining, by a node on a blockchain network, credentials for a user of the blockchain network from an issuer, the credentials based on one or more attributes of the user,

wherein the issuer is selected from a plurality of authorized issuers for the blockchain network, and

wherein the credentials include a first signature on the one or more attributes and a secret key;

generating, by the node, an operation composed of a payload and a second signature;

computing, by the node, a commitment to a public key of the issuer;

proving, by the node using a one-out-of-many proof, that the commitment is a valid commitment to a public key of one of the plurality of authorized issuers;

proving, by the node using a zero-knowledge proof, proof of knowledge of the first signature and the credentials under the public key of the issuer; and

proving, by the node, using a proof of knowledge of values of the signed secret key and the one or more attributes to grant the user access without revealing an identity of the user.

2. The system of claim 1 , wherein the first signature is a Groth signature.

3. The system of claim 1 , wherein the payload is encrypted using a semantically-secure encryption.

4. The system of claim 1 , wherein the proof of knowledge of values is a Schnorr proof.

5. The system of claim 1 , wherein a Groth signatures scheme facilitates zero-knowledge proof of knowledge of valid credentials.

6. The system of claim 1 , wherein the user proves, using the proof of knowledge of values, the credentials are valid.

7. The system of claim 1 , wherein the credentials are only valid during an epoch.

8. A method comprising:

obtaining, by a node on a blockchain network, credentials for a user of the blockchain network from an issuer, the credentials based on one or more attributes of the user,

wherein the issuer is selected from a plurality of authorized issuers for the blockchain network, and

wherein the credentials include a first signature on the one or more attributes and a secret key;

generating, by the node, an operation composed of a payload and a second signature;

computing, by the node, a commitment to a public key of the issuer;

proving, by the node using a one-out-of-many proof, that the commitment is a valid commitment to a public key of one of the plurality of authorized issuers;

proving, by the node using a zero-knowledge proof, proof of knowledge of the first signature and the credentials under the public key of the issuer; and

proving, by the node, using a proof of knowledge of values of the signed secret key and the one or more attributes to grant the user access without revealing an identity of the user.

9. The method of claim 8 , wherein the first signature is a Groth signature.

10. The method of claim 8 , wherein the payload is encrypted using a semantically-secure encryption.

11. The method of claim 8 , wherein the proof of knowledge of values is a Schnorr proof.

12. The method of claim 8 , wherein a Groth signatures scheme facilitates zero-knowledge proof of knowledge of valid credentials.

13. The method of claim 8 , wherein the user proves, using the proof of knowledge, the credentials are valid.

14. The method of claim 8 , wherein the credentials are only valid during an epoch.

15. A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause the processor to perform a method, the method comprising:

obtaining, by a node on a blockchain network, credentials for a user of the blockchain network from an issuer, the credentials based on one or more attributes of the user, wherein the issuer is selected from a plurality of authorized issuers for the blockchain network, and

wherein the credentials include a first signature on the one or more attributes and a secret key;

generating, by the node, an operation composed of a payload and a second signature;

computing, by the node, a commitment to a public key of the issuer;

proving, by the node using a one-out-of-many proof, that the commitment is a valid commitment to a public key of one of the plurality of authorized issuers;

proving, by the node using a zero-knowledge proof, proof of knowledge of the first signature and the credentials under the public key of the issuer; and

proving, by the node, using a proof of knowledge of values of the signed secret key and the one or more attributes to grant the user access without revealing an identity of the user.

16. The computer program product of claim 15 , wherein the first signature is a Groth signature.

17. The computer program product of claim 15 , wherein the payload is encrypted using a semantically-secure encryption.

18. The computer program product of claim 15 , wherein the proof of knowledge of values is a Schnorr proof.

19. The computer program product of claim 15 , wherein a Groth signatures scheme facilitates zero-knowledge proof of knowledge of valid credentials.

20. The computer program product of claim 15 , wherein the user proves, using the proof of knowledge of values, the credentials are valid.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2021
From: EL KHIYAOUI, KAOUTAR; DE CARO, ANGELO; ANDROULAKI, ELLI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058377/0955 →
Continuity (1)
Related Publication 20230188353A1 · Jun 15, 2023
References Cited (22)
US 10915552B2 · Camenisch · 2021 [cited by applicant]
US 20200014537A1 · Ortiz · 2020 [cited by examiner]
US 20200145192A1 · Elkhiyaoui · 2020 [cited by examiner]
US 20210312078A1 · Jayachandran · 2021 [cited by examiner]
US 20230299959A1 · Fukuoka · 2023 [cited by examiner]
CN 109413078A · 2019 [cited by applicant]
CN 113554436A · 2021 [cited by applicant]
CN 116263834A · 2023 [cited by applicant]
JP 2023087665A · 2023 [cited by applicant]
N. Guo, Y. Jin and K. Yim, “Anonymous Credential-Based Privacy-Preserving Identity Verification for Business Processes,” 2014 Eighth International Conference on Innovative Mobile and Internet Services in Ubiquitous Comp… [cited by examiner]
Groth, J., Kohlweiss, M. (2015). One-Out-of-Many Proofs: Or How to Leak a Secret and Spend a Coin. In: Oswald, E., Fischlin, M. (eds) Advances in Cryptology—EUROCRYPT 2015. EUROCRYPT 2015. Lecture Notes in Computer Scie… [cited by examiner]
Garman, C., Green, M., & Miers, I. Decentralized Anonymous Credentials. 2014. IACR Cryptol. ePrint Arch., 2013, 622. (Year: 2014 ). [cited by examiner]
Androulaki et al., “Privacy-preserving Auditable Token Payments in a Permissioned Blockchain System,” Proceedings of the 2nd ACM Conference on Advances in Financial Technologies, Oct. 2020, pp. 255-267. [cited by applicant]
Belenkiy et al., “P-signatures and Noninteractive Anonymous Credentials,” Theory of Cryptography, Fifth Theory of Cryptography Conference (TCC 2008), Mar. 19-21, 2008, 18 pages. [cited by applicant]
Belenkiy et al., “Randomizable Proofs and Delegatable Anonymous Credentials, ”CRYPTO 2009, Aug. 2009, pp. 108-125. [cited by applicant]
Bemmann et al., “Fully-Featured Anonymous Credentials with Reputation System,” Proceedings of the 13th International Conference on Availability, Reliability and Security, Sep. 5, 2018, 22 pages. [cited by applicant]
Camenisch et al., “Efficient Attributes for Anonymous Credentials,” ACM Transactions on Information and System Security, vol. 15, Issue 1, Article No. 4, Mar. 2012, 30 pages. [cited by applicant]
Camenisch et al., “Practical UC-Secure Delegatable Credentials with Attributes and Their Application to Blockchain,” Conference on Computer and Communications Security (CCS '17), Oct. 30-Nov. 3, 2017, pp. 683-699. [cited by applicant]
Camenisch et al., “Signature Schemes and Anonymous Credentials from Bilinear Maps,” Advances in Cryptology—CRYPTO 2004, 24th Annual International CryptologyConference, 15-19 Aug. 15-19, 2004, 17 pages. [cited by applicant]
Ra et al., “An Anonymous Protocol with User Identification and Linking Capabilities for User Privacy in a Permissioned Blockchain,” Electronics 9, No. 8, Jul. 22, 2020, 22 pages. [cited by applicant]
Groth, “Efficient Fully Structure-Preserving Signatures for Large Messages,” Cryptology ePrint Archive: Report 2015/824, Aug. 22, 2015, 22 pages. <https://eprint.iacr.org/2015/824>. [cited by applicant]
The State Intellectual Property Office of People's Republic of China, “First Office Action”, Aug. 15, 2025, 12 Pages, CN Application No. 202211485099.X. [cited by applicant]
Cited By (1)
US 12,719,688