发明名称 Method and system for user attestation-signatures with attributes
摘要 The present invention discloses a method for generating and verifying a user attestation-signature value (DAA') and issuing an attestation value (cert) for the generation of the user attestation-signature value (DAA'). Further, the invention is related to a system for using a user attestation-signature value (DAA') that corresponds to at least one attribute (A, B, C, D), each with an attribute value (w, x, y, z), none, one or more of the attribute values (x, y) remaining anonymous for transactions, the system comprising: a user device (20) having a security module (22) that provides a module public key (PKTPM) and a security module attestation value (DAA), the user device (20) providing a user public key (PKUC) that inherently comprises none, one, or more user determined attribute value (x, y) and a proof value demonstrating that the user public key (PKUC) is validly derived from the module public key (PKTPM) of the security module (22); an attester computer (30) that provides none, one, or more attester determined attribute value (w, z) and an attestation value (cert) that bases on an attester secret key (SKAC), the user public key (PKUC), and an anonymous attribute value (w, z); and a verification computer (40) for verifying whether or not (i) the user attestation-signature value (DAA') was validly derived from the security module attestation value (DAA) provided by the security module (22) and the attestation value (cert), and (ii) the attestation value (cert) is associated with a subset (B, D) of at least one attribute, each attribute in the subset (B, D) having a revealed attribute value (x, z).
申请公布号 US2009049300(A1) 申请公布日期 2009.02.19
申请号 US20080131621 申请日期 2008.06.02
申请人 CAMENISCH JAN 发明人 CAMENISCH JAN
分类号 H04L9/32;G06F1/00;G06F21/57;G06F21/64 主分类号 H04L9/32
代理机构 代理人
主权项
地址