IP Library Granted Patent US 12,341,891
Granted Patent B2
US 12,341,891 · App. 17/924,457 · Granted Jun 24, 2025

Anonymous authentication with token redemption

Inventors: David Isaac Van Cleve (Seattle, WA); Gang Wang (Frederick, MD)
Assignee: Google LLC
H04L9/3213H04L9/3257
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,891
App. No.
17/924,457
Granted
Jun 24, 2025
Kind
B2
Abstract

This disclosure relates to a method for anonymous attestation that includes receiving, by an application running on a client device and from a first content provider, an authentication request to authenticate a user to receive content from a second domain of a second content provider, redeeming, with an attestation token issuing system that issued an anonymous attestation token attesting to the user's authentication to the second content provider, the anonymous attestation token by transmitting the anonymous attestation token with a second request, receiving a redemption result representing whether the attestation token was successfully redeemed, signed by the attestation token issuing system using a digital signature and is operable to verify, to the second content provider, that the user is authenticated to the second content provider without identifying the user to the second content provider, and transmitting, to the first content provider, the redemption result.

Claims (72)

1. A method for anonymous attestation, comprising:

transmitting, by an application running on a client device and to a trusted program having access to credentials of a user of the client device that authenticate the user to an entity, a first request for an anonymous attestation token attesting to the user's authentication to a second content provider;

transmitting, by the trusted program and to an attestation token issuing system, a second request for the anonymous attestation token, the second request including a set of credentials for the user of the client device; and

receiving, by the application and from the attestation token issuing system, the anonymous attestation token comprising (i) an attestation token creation timestamp indicating a time of creation of the anonymous attestation token, and (ii) a first digital signature of the attestation token issuing system;

receiving, by the application running on the client device and from a first server hosted on a first domain of a first content provider, an authentication request to authenticate the user to receive content from a second domain of the second content provider, wherein the second content provider is different from the first content provider;

in response to receiving the authentication request, redeeming, by the application and with the attestation token issuing system that issued the anonymous attestation token attesting to the user's authentication to the second content provider, the anonymous attestation token by transmitting the anonymous attestation token with a third request;

receiving, by the application and from the attestation token issuing system in response to the third request, a redemption result representing whether the anonymous attestation token was successfully redeemed and is signed by the attestation token issuing system using a second digital signature, wherein the redemption result is operable to verify, to the second content provider, that the user is authenticated to the second content provider without identifying the user to the second content provider; and

transmitting, by the application and to the first content provider, the redemption result signed by the attestation token issuing system.

2. The method of claim 1 , wherein the redemption result is operable to verify to a recipient that the user is authenticated to the second content provider while allowing the user to remain anonymous without providing the first content provider with the set of credentials for the user.

3. The method of claim 1 , further comprising:

requesting, by the application and from the second content provider through an electronic resource of the first content provider, the content from the second content provider.

4. The method of claim 3 , further comprising:

receiving, by the application, the content from the second content provider.

5. The method of claim 1 , wherein the second digital signature is created according to a blind signature scheme.

6. The method of claim 1 , wherein the second digital signature is created using a group signature scheme and an anonymous certificate issued to the client device; and

the method comprises storing the anonymous certificate in a secure private keystore on the client device.

7. The method of claim 1 , wherein transmitting the redemption result signed by the attestation token issuing system further comprises providing additional data that (i) is signed by the application, and (ii) does not correlate the user with the set of credentials.

8. The method of claim 1 , wherein the second request indicates a number of attestation tokens to be issued.

9. The method of claim 1 , wherein the second request is signed with a third digital signature using a private key maintained by the application, and wherein the third digital signature can be verified using a public key (i) corresponding to the private key and (ii) published by the application.

10. The method of claim 9 , wherein the first digital signature is created using a private key maintained by the attestation token issuing system, and wherein the third digital signature can be verified using a public key (i) corresponding to the private key and (ii) published by the attestation token issuing system.

11. The method of claim 1 , wherein the redemption result comprises a single bit representing whether the anonymous attestation token was successfully redeemed.

12. A method for anonymous attestation, the method comprising:

receiving, by an application running on a client device and from a first server hosted on a first domain of a first content provider, an authentication request to authenticate a user to receive content from a second domain of a second content provider different from the first content provider;

in response to receiving the authentication request, redeeming, by the application and with an attestation token issuing system that issued an anonymous attestation token attesting to the user's authentication to the second content provider, the anonymous attestation token by transmitting the anonymous attestation token with a second request;

receiving, by the application and from the attestation token issuing system in response to the second request, a redemption result representing whether the anonymous attestation token was successfully redeemed and is signed by the attestation token issuing system using a digital signature, wherein the redemption result is operable to verify, to the second content provider, that the user is authenticated to the second content provider without identifying the user to the second content provider; and

transmitting, by the application and to the first content provider, the redemption result signed by the attestation token issuing system,

wherein the second content provider is a news provider,

wherein the first content provider is a news aggregator domain, and

wherein transmitting, by the application and to the first content provider, the redemption result signed by the attestation token issuing system is performed in response to a user action requesting access to a resource hosted by the news provider.

13. A method for anonymous attestation, the method comprising:

receiving, by an application running on a client device and from a first server hosted on a first domain of a first content provider, an authentication request to authenticate a user to receive content from a second domain of a second content provider different from the first content provider;

in response to receiving the authentication request, redeeming, by the application and with an attestation token issuing system that issued an anonymous attestation token attesting to the user's authentication to the second content provider, the anonymous attestation token by transmitting the anonymous attestation token with a second request;

receiving, by the application and from the attestation token issuing system in response to the second request, a redemption result representing whether the anonymous attestation token was successfully redeemed and is signed by the attestation token issuing system using a digital signature, wherein the redemption result is operable to verify, to the second content provider, that the user is authenticated to the second content provider without identifying the user to the second content provider; and

transmitting, by the application and to the first content provider, the redemption result signed by the attestation token issuing system,

wherein the second content provider is a media hosting platform, and

wherein the first content provider is a social media platform, and

wherein transmitting, by the application and to the first content provider, the redemption result signed by the attestation token issuing system is performed in response to a user action requesting access to a resource hosted by the media hosting platform.

14. A system, comprising:

one or more processors of a client device; and

one or more memories having stored thereon computer readable instructions configured to cause the one or more processors to perform operations comprising:

transmitting, by an application running on the client device and to a trusted program having access to credentials of a user of the client device that authenticate the user to an entity, a first request for the anonymous attestation token attesting to the user's authentication to a second content provider;

transmitting, by the trusted program and to an attestation token issuing system, a second request for the anonymous attestation token, the second request including a set of credentials for the user of the client device; and

receiving, by the application and from the attestation token issuing system, an anonymous attestation token comprising (i) an attestation token creation timestamp indicating a time of creation of the anonymous attestation token, and (ii) a first digital signature of the attestation token issuing system;

receiving, by the application running on the client device and from a first server hosted on a first domain of a first content provider, an authentication request to authenticate the user to receive content from a second domain of the second content provider, wherein the second content provider is different from the first content provider;

in response to receiving the authentication request, redeeming, by the application and with the attestation token issuing system that issued the anonymous attestation token attesting to the user's authentication to the second content provider, the anonymous attestation token by transmitting the anonymous attestation token with a third request;

receiving, by the application and from the attestation token issuing system in response to the third request, a redemption result representing whether the anonymous attestation token was successfully redeemed and is signed by the attestation token issuing system using a second digital signature, wherein the redemption result is operable to verify, to the second content provider, that the user is authenticated to the second content provider without identifying the user to the second content provider; and

transmitting, by the application and to the first content provider, the redemption result signed by the attestation token issuing system.

15. The system of claim 14 , wherein the redemption result is operable to verify to a recipient that the user is authenticated to the second content provider while allowing the user to remain anonymous without providing the first content provider with the set of credentials for the user.

16. The system of claim 14 , wherein:

the second content provider is a news provider,

the first content provider is a news aggregator domain, and

transmitting, by the application and to the first content provider, the redemption result signed by the attestation token issuing system is performed in response to a user action requesting access to a resource hosted by the news provider.

17. The system of claim 14 , wherein:

the second content provider is a media hosting platform,

the first content provider is a social media platform, and

wherein transmitting, by the application and to the first content provider, the redemption result signed by the attestation token issuing system is performed in response to a user action requesting access to a resource hosted by the media hosting platform.

18. A non-transitory computer readable medium storing instructions that upon execution by one or more computers cause the one or more computers to perform operations comprising:

transmitting, by an application running on a client device and to a trusted program having access to credentials of a user of the client device that authenticate the user to an entity, a first request for the anonymous attestation token attesting to the user's authentication to a second content provider;

transmitting, by the trusted program and to an attestation token issuing system, a second request for the anonymous attestation token, the second request including a set of credentials for the user of the client device; and

receiving, by the application and from the attestation token issuing system, an anonymous attestation token comprising (i) an attestation token creation timestamp indicating a time of creation of the anonymous attestation token, and (ii) a first digital signature of the attestation token issuing system;

receiving, by the application running on the client device and from a first server hosted on a first domain of a first content provider, an authentication request to authenticate the user to receive content from a second domain of the second content provider, wherein the second content provider is different from the first content provider;

in response to receiving the authentication request, redeeming, by the application and with the attestation token issuing system that issued the anonymous attestation token attesting to the user's authentication to the second content provider, the anonymous attestation token by transmitting the anonymous attestation token with a third request;

receiving, by the application and from the attestation token issuing system in response to the third request, a redemption result representing whether the anonymous attestation token was successfully redeemed and is signed by the attestation token issuing system using a second digital signature, wherein the redemption result is operable to verify, to the second content provider, that the user is authenticated to the second content provider without identifying the user to the second content provider; and

transmitting, by the application and to the first content provider, the redemption result signed by the attestation token issuing system.

19. The non-transitory computer readable medium of claim 18 , wherein:

the second content provider is a news provider,

the first content provider is a news aggregator domain, and

transmitting, by the application and to the first content provider, the redemption result signed by the attestation token issuing system is performed in response to a user action requesting access to a resource hosted by the news provider.

20. The non-transitory computer readable medium of claim 18 , wherein:

the second content provider is a media hosting platform,

the first content provider is a social media platform, and

wherein transmitting, by the application and to the first content provider, the redemption result signed by the attestation token issuing system is performed in response to a user action requesting access to a resource hosted by the media hosting platform.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2023
From: VAN CLEVE, DAVID ISAAC; WANG, GANG
To: GOOGLE LLC
Reel/Frame 063427/0189 →
Continuity (1)
Related Publication 20230308277A1 · Sep 28, 2023
References Cited (47)
US 10735205B1 · Wentz · 2020 [cited by examiner]
US 11374910B2 · Kravitz · 2022 [cited by examiner]
US 11405365B2 · Kravitz · 2022 [cited by examiner]
US 11770251B2 · Nainar · 2023 [cited by examiner]
US 12028455B2 · Wagner · 2024 [cited by examiner]
US 20070244833A1 · Camenisch · 2007 [cited by examiner]
US 20080270790A1 · Brickell · 2008 [cited by examiner]
US 20090193509A1 · Cardone · 2009 [cited by examiner]
US 20100185864A1 · Gerdes, Jr. · 2010 [cited by examiner]
US 20100325441A1 · Laurie · 2010 [cited by examiner]
US 20110126276A1 · Dykeman et al. · 2011 [cited by applicant]
US 20120159577A1 · Belinkiy · 2012 [cited by examiner]
US 20120167189A1 · Aichroth et al. · 2012 [cited by applicant]
US 20140282984A1 · Schlesinger et al. · 2014 [cited by applicant]
US 20140359289A1 · Camenisch et al. · 2014 [cited by applicant]
US 20150341340A1 · Lu · 2015 [cited by examiner]
US 20160127341A1 · Yan · 2016 [cited by applicant]
US 20160241552A1 · Lindemann · 2016 [cited by examiner]
US 20180165781A1 · Rodriguez · 2018 [cited by examiner]
US 20200014537A1 · Ortiz · 2020 [cited by examiner]
US 20200336470A1 · Kravitz · 2020 [cited by examiner]
US 20210064780A1 · Riedel · 2021 [cited by examiner]
US 20210218742A1 · Cook · 2021 [cited by examiner]
US 20210312440A1 · Badal-Badalian · 2021 [cited by examiner]
US 20220021537A1 · Wagner · 2022 [cited by examiner]
US 20220321354A1 · Ladd · 2022 [cited by examiner]
US 20220385642A1 · Kravitz · 2022 [cited by examiner]
US 20230188358A1 · Wang · 2023 [cited by examiner]
CN 101336436 · 2008 [cited by applicant]
KR 1020120070663 · 2012 [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2021/047736, mailed on Mar. 7, 2024, 13 pages. [cited by applicant]
Office Action in Japanese Appln. No. 2022-570379, mailed on Mar. 25, 2024, 7 pages (with English translation). [cited by applicant]
Base91.sourceforge.net [online], “basE91 encoding” Oct. 2006, retrieved on Jan. 24, 2023, retrieved from URL <https://base91.sourceforge.net/>, 3 pages. [cited by applicant]
Developer.android.com [online], “Android Interface Definition Language (AIDL)” Jul. 2022, retrieved on Jan. 24, 2023, retrieved from URL <https://developer.android.com/guide/components/aidl?hl-en>, 19 pages. [cited by applicant]
Developer.android.com [online], “Bundle” May 2018, retrieved on Jan. 24, 2023, retrieved from URL <https://developer.android.com/reference/android/os/Bundle>, 65 pages. [cited by applicant]
Developer.android.com [online], “Protect against security threats with SafetyNet” Jul. 2017, retrieved on Jan. 24, 2023, retrieved from URL <https://developer.android.com/training/safetynet>, 3 pages. [cited by applicant]
Developer.android.com [online], “SafetyNet Attestation API” Jul. 2018, retrieved on Jan. 24, 2023, retrieved from URL <https://developer.android.com/training/safetynet/attestation#use-response-server>, 17 pages. [cited by applicant]
Developers.google.com [online], “SafetyNetClient” Jul. 2017, retrieved on Jan. 24, 2023, retrieved from URL <https://developers.google.com/android/reference/com/google/android/gms/safetynet/SafetyNetClient>, 5 pages. [cited by applicant]
Github.com [online], “Trust-Token-Api” Aug. 2019, retrieved on Jan. 24, 2023, retrieved from URL <https://github.com/WICG/trust-token-api>, 13 pages. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2021/047736, mailed on Apr. 29, 2022, 18 pages. [cited by applicant]
Rfc-editor.org [online], “Hypertext Transfer Protocol (HTTP/1.1): Message Syntax and Routing” Jun. 2014, retrieved on Jan. 24, 2023, retrieved from URL <https://www.rfc-editor.org/info/rfc7230>, 89 pages. [cited by applicant]
Source.android.com [online], “AIDL Overview” Nov. 2022, retrieved on Jan. 24, 2023, retrieved from URL <https://source.android.com/docs/core/architecture/aidl#example>, 2 pages. [cited by applicant]
Notice of Allowance in Japanese Appln. No. 2022-570379, mailed on Sep. 2, 2024, 5 pages (with English translation). [cited by applicant]
Office Action in Korean Appln. No. 10-2022-7038973, mailed on May 8, 2025, 18 pages (with English translation). [cited by applicant]
Lee et al., “Anonymous access control framework based on group signature.” 2010 2nd International Conference on Information Technology Convergence and Services. IEEE, Aug. 2010, 5 pages. [cited by applicant]
Office Action in Chinese Appln. No. 202180035302.0, mailed on Mar. 25, 2025, 18 pages (with English translation). [cited by applicant]
Ya, “Token-Based Wireless Mobile Network Privacy Preserving and Authentication Protocol” Computer Applications and Software, vol. 36. No. 5, May 2019, 81-85 (with English abstract). [cited by applicant]