WO2012093928A1 - Pseudonym id privacy enhancement - Google Patents
Pseudonym id privacy enhancement Download PDFInfo
- Publication number
- WO2012093928A1 WO2012093928A1 PCT/MY2011/000248 MY2011000248W WO2012093928A1 WO 2012093928 A1 WO2012093928 A1 WO 2012093928A1 MY 2011000248 W MY2011000248 W MY 2011000248W WO 2012093928 A1 WO2012093928 A1 WO 2012093928A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- anonymizer
- key
- qkd
- service provider
- shared secret
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0852—Quantum cryptography
- H04L9/0855—Quantum cryptography involving additional nodes, e.g. quantum relays, repeaters, intermediate nodes or remote nodes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/42—Anonymization, e.g. involving pseudonyms
Definitions
- the present invention relates to a system and method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
- QKD quantum key distribution
- Pseudonym identifier is used to protect user identity in ordinary privacy enhancement system wherein user is anonymous to e-Service Provider.
- the weakness of pseudonym ID is traceability of a user's identity to the pseudonym ID because methodology used to create pseudonym ID is structured and predictable.
- pseudonym ID is generated using hash function based on user's identity.
- a timestamp is used as input to hash function to change value of pseudonym ID for each communication session, which is less linkable to user's identity.
- the methodology of the timestamp is fixed, structured and predictable, which allows hacking by tracing the linkage. Thus, the entire system is thereby exposed to identity theft attack.
- the present invention uses both privacy enhancement mechanisms and QKD to protect user privacy and to enhance system trust.
- the present invention introduces anonymizer in QKD network to provide privacy enhancement service and to reinforce unlinkability through randomness of q-anonymizer.
- the present invention provides the following advantages:- a) QKD based privacy;
- QKD Quantum Key Distribution
- secret key Once secret key has been established by QKD, it can be used for variety of purposes.
- One of the purposes of the present invention is to use it as a seed to generate pseudonym ID by using anonymizer to produce quantum network based pseudonym ID.
- QKD devices will become more robust, easier to configure, less expensive and smaller.
- the present invention provides a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
- the system comprising at least one client application (102), at least one q-anonymizer (106), at least one quantum key distribution (QKD) network between client application and q- anonymizer (104), at least one quantum key distribution (QKD) network between q- anonymizer and service provider ( 08) and a service provider (110).
- the at least one q- anonymizer (106) validates independent communication between client application and q- anonymizer and further anonymize user identity between client application and service provider.
- the at least one quantum key distribution (QKD) network between client application and q-anonymizer (104) generates shared secret key Ki and identifier key (ID) while the at least one quantum key distribution (QKD) network between q- anonymizer and service provider (108) generates shared secret key K 2 and identifier key (ID).
- QKD quantum key distribution
- the said q-anonymizer (104) anonymize user identity between client application and service provider by generating quantum key distribution (QKD) based pseudonym identifier (ID) using at least XOR function in order to protect user identities during communication over QKD network.
- QKD quantum key distribution network
- ID pseudonym identifier
- Another aspect of the present invention provides a method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
- the method comprising steps of initiating request to q-anonymizer (502), generating shared secret key and identifier key (ID) between client application and q- anonymizer via quantum key distribution (QKD) network (504), transmitting shared secret key K, and identifier key (ID) to client application and transmitting identifier key to q-anonymizer (506), retrieving shared secret key by q-anonymizer from quantum key distribution (QKD) network (508), establishing trusted communication between client application and q-anonymizer (514), generating shared secret key K 2 and identifier key (ID) between q-anonymizer and service provider via quantum key distribution (QKD) network (602), retrieving shared secret key K 2 and identifier key (ID) from quantum key distribution (QKD) network and transmitting identifier key (ID) to service provider by q- anonymizer (604), transmitting shared
- the method for retrieving shared secret key by q-anonymizer from quantum key distribution (QKD) network further comprises performing challenge response to determine if communication is trusted (512) wherein communication between client application and q-anonymizer will be aborted (514) if challenge response fails; else trusted communication is established.
- the method for retrieving shared secret key K 2 and identifier key (ID) from quantum key distribution (QKD) network and transmitting identifier key (ID) to service provider by q-anonymizer further comprises performing challenge response to determine if communication is trusted (608) wherein communication between client application and q-anonymizer will be aborted (610) if challenge response fails; else trusted communication is established.
- Another aspect of the present invention provides a method (700) for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q-anonymizer for privacy enhancement.
- the method comprises retrieving shared secret keys and K 2 from quantum key distribution (QKD) network between client and service provider (702), generating final key by combining shared secret keys K n and K 2 using XOR function (704) and combining pseudonym identifier (ID) key with final key to produce quantum key distribution (QKD) network based pseudonym identifier (ID) (706).
- FIG. 1 illustrates a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
- QKD quantum key distribution
- FIG. 2 illustrates communications between Node 1 and Node 2 as well as between Node 2 and Node 3.
- FIG. 3 illustrates trusted communication between client and q-anonymizer.
- FIG. 4 illustrates q-anonymizer which anonymizes identity between client and service provider.
- FIG. 5 is a flowchart illustrating methodology for establishing trusted communication between client and Q-anonymizer.
- FIG. 6 is a flowchart illustrating methodology for establishing trusted communication between service provider and q-anonymizer by anonymizing user identity.
- FIG. 7 is a flowchart illustrating methodology for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q-anonymizer for privacy enhancement.
- QKD quantum key distribution
- ID pseudonym identifier
- the present invention provides a system and method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
- QKD quantum key distribution
- FIG. 1 illustrates a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
- the system comprising at least one client application (102), at least one q-anonymizer (106), at least one quantum key distribution (QKD) network between client application and q-anonymizer (104), at least one quantum key distribution (QKD) network between q-anonymizer and service provider (108) and a service provider (110).
- QKD box of quantum network (102, 108) generates shared keys K and K 2 and identifier (ID) key
- the at least one quantum key distribution (QKD) network between client application and q-anonymizer (104) generates shared secret key and identifier key (ID).
- the at least one quantum key distribution (QKD) network between q-anonymizer and service provider (108) generates shared secret key K 2 and identifier key (ID).
- the at least one q-anonymizer (106) validates independent communication between client application and q-anonymizer and further anonymize user identity between client application and service provider.
- the said q-anonymizer (104) anonymize user identity between client application and service provider by generating quantum key distribution (QKD) based pseudonym identifier (ID) using at least XOR function in order to protect user identities during communication over QKD network.
- QKD quantum key distribution
- ID pseudonym identifier
- FIG. 2 illustrates communications between Node 1 and Node 2 as well as between Node 2 and Node 3.
- client in node 1 receives shared key from QKD system and transmits key to q- anonymizer.
- the shared key K, and ID key are generated through quantum link.
- Both identical keys, ⁇ and K 2 are stored in database together with ID key in node 1 and 2.
- q-anonymizer retrieves shared key K, through link 1 in node 2. Communication is established between client and q-anonymizer.
- q- anonymizer retrieves shared key K 2 from QKD system wherein shared key K 2 and ID key is generated through link 2.
- Service provider in node 3 receives ID key from q- anonymizer.
- Service provider retrieves shared key K 2 from QKD system through link 2 using key ID which establishes communication between Q-anonymizer and service provider. Thereafter, K 2 is combined with pseudonym ID in order to obtain quantum- based pseudonym ID.
- FIG. 3 illustrates trusted communication between client and q-anonymizer.
- client application receives shared key Ki from QKD system.
- the key ID is sent to q-anonymizer wherein q- anonymizer retrieves key ⁇ from QKD system which establishes communication between client and q-anonymizer.
- q-anonymizer retrieves key K 2 from QKD system using link 2.
- Service provider receives key ID from Q-anonymizer. Using key ID, service provider receives shared key K 2 from QKD system which establishes communication between service provider and Q-anonymizer in node 2.
- FIG. 4 illustrates q-anonymizer which anonymizes identity between client and service provider.
- shared key K ⁇ will be combined with shared key K 2 using XOR function in q-anonymizer which results in the final key.
- Pseudonym ID will then be combined with final key to obtain Q Net-based pseudonym ID which protects user personnel identity for privacy.
- FIG. 5 is a flowchart illustrating methodology for establishing trusted communication between client and Q- anonymizer while FIG. 6 is a flowchart illustrating methodology for establishing trusted communication between service provider and q-anonymizer by anonymizing user identity.
- a method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD) comprising steps of initiating request to q-anonymizer (502) and generating shared secret key Ki and identifier key (ID) between client application and q-anonymizer via quantum key distribution (QKD) network (504).
- QKD quantum key distribution
- shared secret key Ki and identifier key (ID) is transmitted to client application and further transmitting identifier key to q-anonymizer (506).
- Shared secret key is retrieved by q-anonymizer from quantum key distribution (QKD) network (508).
- challenge response is performed to determine if communication is trusted (512) wherein communication between client application and q-anonymizer will be aborted (514) if challenge response fails; else trusted communication is established. Trusted communication is established between client application and q-anonymizer if challenge response is successful (512).
- shared secret key K 2 and identifier key (ID) is generated between q-anonymizer and service provider via quantum key distribution (QKD) network (602). Thereafter, shared secret key K 2 and identifier key (ID) is retrieved from quantum key distribution (QKD) network (604). Further, q-anonymizer transmits identifier key (ID) to service provider (604). Challenge response is performed to determine if communication is trusted (608) wherein communication between client application and q-anonymizer will be aborted (610) if challenge response fails; else trusted communication is established.
- Shared secret key K 2 is transmitted from quantum key distribution (QKD) network to service provider (606) which establishes trusted communication between service provider and q-anonymizer by anonymizing user identity (612).
- Quantum key distribution (QKD) network based pseudonym identifier (ID) is thereafter created in q-anonymizer for privacy enhancement (700).
- FIG. 7 is a flowchart illustrating methodology for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q- anonymizer for privacy enhancement.
- QKD quantum key distribution
- ID quantum key distribution network based pseudonym identifier
- FIG. 7 is a flowchart illustrating methodology for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q- anonymizer for privacy enhancement.
- QKD quantum key distribution
- ID quantum key distribution
- ID quantum key distribution
- Shared secret key K, and shared secret key K 2 are randomly generated via quantum key distribution (QKD) network to enhance unlinkability between client and service provider.
- Quantum key distribution network (QKD) based pseudonym identifier (ID) of the present invention will expire based on quantum key which generates only one session.
- User's identity is anonymous as pseudonym ID is combined with quantum key which allows for double layer to increase unlinkability, privacy.
- Q-anonymizer is trusted and is part of QKD network that is secure and private. Thus, the present invention prevents QKD network based pseudonym ID from being traced back to the user as only q-anonymizer will know the user identity.
- QKD Quantum Key Distribution
Landscapes
- Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- Electromagnetism (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
Abstract
The present invention provides system for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution. The system comprises at least one client application, at least one q-anonymizer, at least one quantum key distribution network between client application and q-anonymizer, at least one quantum key distribution network between q-anonymizer and service provider and a service provider. The at least one q-anonymizer validates independent communication between client application and q-anonymizer and further anonymize user identity between client application and service provider.
Description
PSEUDONYM ID PRIVACY ENHANCEMENT FIELD OF INVENTION The present invention relates to a system and method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
BACKGROUND ART
Pseudonym identifier (ID) is used to protect user identity in ordinary privacy enhancement system wherein user is anonymous to e-Service Provider. The weakness of pseudonym ID is traceability of a user's identity to the pseudonym ID because methodology used to create pseudonym ID is structured and predictable. At present, pseudonym ID is generated using hash function based on user's identity. A timestamp is used as input to hash function to change value of pseudonym ID for each communication session, which is less linkable to user's identity. The methodology of the timestamp is fixed, structured and predictable, which allows hacking by tracing the linkage. Thus, the entire system is thereby exposed to identity theft attack.
The present invention uses both privacy enhancement mechanisms and QKD to protect user privacy and to enhance system trust. The present invention introduces anonymizer in QKD network to provide privacy enhancement service and to reinforce unlinkability through randomness of q-anonymizer. The present invention provides the following advantages:- a) QKD based privacy;
b) strong privacy properties of QKD which enforces protection of personal data; c) identity is untraceable;
d) identical key which provide authenticity between client and q-anonymizer, q- anonymizer and service provider which protects network from phishing attack; e) trusted and auditable by q-anonymizer system.
The approach in the present invention provides solution towards predictability of pseudonym by using an alternative method provided by Quantum Key Distribution
(QKD) network. The characteristic and features of QKD enables incorporation of random process which complicates traceability of user identity. QKD network is unconditionally secure and private based on trusted QKD infrastructure as Q-anonymizer will be trusted anonymizer's engine.
Once secret key has been established by QKD, it can be used for variety of purposes. One of the purposes of the present invention is to use it as a seed to generate pseudonym ID by using anonymizer to produce quantum network based pseudonym ID. As QKD research continues, QKD devices will become more robust, easier to configure, less expensive and smaller.
The subject matter claimed herein is not limited to embodiments that solve any disadvantages or that operate only in environments such as those described above. Rather, this background is only provided to illustrate one exemplary technology area where some embodiments described herein may be practiced.
SUMMARY OF INVENTION
The present invention provides a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD). The system comprising at least one client application (102), at least one q-anonymizer (106), at least one quantum key distribution (QKD) network between client application and q- anonymizer (104), at least one quantum key distribution (QKD) network between q- anonymizer and service provider ( 08) and a service provider (110). The at least one q- anonymizer (106) validates independent communication between client application and q- anonymizer and further anonymize user identity between client application and service provider.
Preferably, the at least one quantum key distribution (QKD) network between client application and q-anonymizer (104) generates shared secret key Ki and identifier key (ID) while the at least one quantum key distribution (QKD) network between q- anonymizer and service provider (108) generates shared secret key K2 and identifier key (ID).
Further, the said q-anonymizer (104) anonymize user identity between client application and service provider by generating quantum key distribution (QKD) based pseudonym identifier (ID) using at least XOR function in order to protect user identities during communication over QKD network. The said quantum key distribution network (QKD) based pseudonym identifier (ID) will expire based on quantum key which generates only one session.
Another aspect of the present invention provides a method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD). The method comprising steps of initiating request to q-anonymizer (502), generating shared secret key and identifier key (ID) between client application and q- anonymizer via quantum key distribution (QKD) network (504), transmitting shared secret key K, and identifier key (ID) to client application and transmitting identifier key to q-anonymizer (506), retrieving shared secret key by q-anonymizer from quantum key distribution (QKD) network (508), establishing trusted communication between client application and q-anonymizer (514), generating shared secret key K2 and identifier key
(ID) between q-anonymizer and service provider via quantum key distribution (QKD) network (602), retrieving shared secret key K2 and identifier key (ID) from quantum key distribution (QKD) network and transmitting identifier key (ID) to service provider by q- anonymizer (604), transmitting shared secret key K2 from quantum key distribution (QKD) network to service provider (606), establishing trusted communication between service provider and q-anonymizer by anonymizing user identity (612) and creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q- anonymizer for privacy enhancement (700).
Preferably, the method for retrieving shared secret key by q-anonymizer from quantum key distribution (QKD) network further comprises performing challenge response to determine if communication is trusted (512) wherein communication between client application and q-anonymizer will be aborted (514) if challenge response fails; else trusted communication is established. Further, the method for retrieving shared secret key K2 and identifier key (ID) from quantum key distribution (QKD) network and transmitting identifier key (ID) to service provider by q-anonymizer further comprises performing challenge response to determine if communication is trusted (608) wherein communication between client application and q-anonymizer will be aborted (610) if challenge response fails; else trusted communication is established.
Another aspect of the present invention provides a method (700) for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q-anonymizer for privacy enhancement. The method comprises retrieving shared secret keys and K2 from quantum key distribution (QKD) network between client and service provider (702), generating final key by combining shared secret keys Kn and K2 using XOR function (704) and combining pseudonym identifier (ID) key with final key to produce quantum key distribution (QKD) network based pseudonym identifier (ID) (706).
The present invention consists of features and a combination of parts hereinafter fully described and illustrated in the accompanying drawings, it being understood that various changes in the details may be made without departing from the scope of the invention or sacrificing any of the advantages of the present invention.
BRIEF DESCRIPTION OF ACCOMPANYING DRAWINGS
To further clarify various aspects of some embodiments of the present invention, a more particular description of the invention will be rendered by references to specific embodiments thereof, which are illustrated in the appended drawings. It is appreciated that these drawings depict only typical embodiments of the invention and are therefore not to be considered limiting of its scope. The invention will be described and explained with additional specificity and detail through the accompanying drawings in which:
FIG. 1 illustrates a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
FIG. 2 illustrates communications between Node 1 and Node 2 as well as between Node 2 and Node 3. FIG. 3 illustrates trusted communication between client and q-anonymizer.
FIG. 4 illustrates q-anonymizer which anonymizes identity between client and service provider. FIG. 5 is a flowchart illustrating methodology for establishing trusted communication between client and Q-anonymizer.
FIG. 6 is a flowchart illustrating methodology for establishing trusted communication between service provider and q-anonymizer by anonymizing user identity.
FIG. 7 is a flowchart illustrating methodology for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q-anonymizer for privacy enhancement.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
The present invention provides a system and method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD). Hereinafter, this specification will describe the present invention according to the preferred embodiments. It is to be understood that limiting the description to the preferred embodiments of the invention is merely to facilitate discussion of the present invention and it is envisioned without departing from the scope of the appended claims.
Reference is first made to FIG. 1. FIG. 1 illustrates a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD). As illustrated in FIG. 1 , the system comprising at least one client application (102), at least one q-anonymizer (106), at least one quantum key distribution (QKD) network between client application and q-anonymizer (104), at least one quantum key distribution (QKD) network between q-anonymizer and service provider (108) and a service provider (110).
QKD box of quantum network (102, 108) generates shared keys K and K2 and identifier (ID) key wherein the at least one quantum key distribution (QKD) network between client application and q-anonymizer (104) generates shared secret key and identifier key (ID). The at least one quantum key distribution (QKD) network between q-anonymizer and service provider (108) generates shared secret key K2 and identifier key (ID).
The at least one q-anonymizer (106) validates independent communication between client application and q-anonymizer and further anonymize user identity between client application and service provider. The said q-anonymizer (104) anonymize user identity between client application and service provider by generating quantum key distribution (QKD) based pseudonym identifier (ID) using at least XOR function in order to protect user identities during communication over QKD network.
Reference is now being made to FIG. 2. FIG. 2 illustrates communications between Node 1 and Node 2 as well as between Node 2 and Node 3. As illustrated in FIG. 2, client in node 1 receives shared key from QKD system and transmits key to q- anonymizer. The shared key K, and ID key are generated through quantum link. Both identical keys, ^ and K2, are stored in database together with ID key in node 1 and 2.
Upon receiving ID key, q-anonymizer retrieves shared key K, through link 1 in node 2. Communication is established between client and q-anonymizer. In node 2, q- anonymizer retrieves shared key K2 from QKD system wherein shared key K2 and ID key is generated through link 2. Service provider in node 3 receives ID key from q- anonymizer. Service provider retrieves shared key K2 from QKD system through link 2 using key ID which establishes communication between Q-anonymizer and service provider. Thereafter, K2 is combined with pseudonym ID in order to obtain quantum- based pseudonym ID.
Reference is now being made to FIG. 3. FIG. 3 illustrates trusted communication between client and q-anonymizer. As illustrated in FIG. 3, client application receives shared key Ki from QKD system. The key ID is sent to q-anonymizer wherein q- anonymizer retrieves key Ί from QKD system which establishes communication between client and q-anonymizer. In node 2, q-anonymizer retrieves key K2 from QKD system using link 2. Service provider receives key ID from Q-anonymizer. Using key ID, service provider receives shared key K2 from QKD system which establishes communication between service provider and Q-anonymizer in node 2.
Reference is now being made to FIG. 4. FIG. 4 illustrates q-anonymizer which anonymizes identity between client and service provider. As illustrated in FIG. 4, shared key K† will be combined with shared key K2 using XOR function in q-anonymizer which results in the final key. Pseudonym ID will then be combined with final key to obtain Q Net-based pseudonym ID which protects user personnel identity for privacy.
Reference is now being made to FIG. 5 and FIG. 6 respectively. FIG. 5 is a flowchart illustrating methodology for establishing trusted communication between client and Q- anonymizer while FIG. 6 is a flowchart illustrating methodology for establishing trusted communication between service provider and q-anonymizer by anonymizing user identity. As illustrated in FIG. 5, a method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD) comprising steps of initiating request to q-anonymizer (502) and generating shared secret key Ki and identifier key (ID) between client application and q-anonymizer via quantum key distribution (QKD) network (504). Thereafter, shared secret key Ki and identifier key (ID) is transmitted to client application and further transmitting identifier key to q-anonymizer
(506). Shared secret key is retrieved by q-anonymizer from quantum key distribution (QKD) network (508). Further, challenge response is performed to determine if communication is trusted (512) wherein communication between client application and q-anonymizer will be aborted (514) if challenge response fails; else trusted communication is established. Trusted communication is established between client application and q-anonymizer if challenge response is successful (512).
As illustrated in FIG. 6, shared secret key K2 and identifier key (ID) is generated between q-anonymizer and service provider via quantum key distribution (QKD) network (602). Thereafter, shared secret key K2 and identifier key (ID) is retrieved from quantum key distribution (QKD) network (604). Further, q-anonymizer transmits identifier key (ID) to service provider (604). Challenge response is performed to determine if communication is trusted (608) wherein communication between client application and q-anonymizer will be aborted (610) if challenge response fails; else trusted communication is established.
Shared secret key K2 is transmitted from quantum key distribution (QKD) network to service provider (606) which establishes trusted communication between service provider and q-anonymizer by anonymizing user identity (612). Quantum key distribution (QKD) network based pseudonym identifier (ID) is thereafter created in q-anonymizer for privacy enhancement (700).
Reference is now being made to FIG. 7. FIG. 7 is a flowchart illustrating methodology for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q- anonymizer for privacy enhancement. As illustrated in FIG. 7, quantum key distribution (QKD) network based pseudonym identifier (ID) is created in q-anonymizer for privacy enhancement by retrieving shared secret keys K, and K2 from quantum key distribution (QKD) network between client and service provider (702). Thereafter, final key is generated by combining shared secret keys K1 and K2 using XOR function (704) and combining pseudonym identifier (ID) key with final key to produce quantum key distribution (QKD) network based pseudonym identifier (ID) (706).
Shared secret key K, and shared secret key K2 are randomly generated via quantum key distribution (QKD) network to enhance unlinkability between client and service provider. Quantum key distribution network (QKD) based pseudonym identifier (ID) of the present
invention will expire based on quantum key which generates only one session. User's identity is anonymous as pseudonym ID is combined with quantum key which allows for double layer to increase unlinkability, privacy. Q-anonymizer is trusted and is part of QKD network that is secure and private. Thus, the present invention prevents QKD network based pseudonym ID from being traced back to the user as only q-anonymizer will know the user identity.
The approach in the present invention provides solution towards predictability of pseudonym by using an alternative method provided by Quantum Key Distribution (QKD) network. The characteristic and features of QKD enables incorporation of random process which complicates traceability of user identity. QKD network is unconditionally secure and private based on trusted QKD infrastructure as Q-anonymizer will be trusted anonymizer's engine.
The present invention may be embodied in other specific forms without departing from its essential characteristics. The described embodiments are to be considered in all respects only as illustrative and not restrictive. The scope of the invention is, therefore indicated by the appended claims rather than by the foregoing description. All changes, which come within the meaning and range of equivalency of the claims, are to be embraced within their scope.
Claims
1. A system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD) comprising:
at least one client application (102);
at least one q-anonymizer (106);
at least one QKD network between client application and q-anonymizer (104);
at least one QKD network between q-anonymizer and service provider (108); and
a service provider (110);
characterized in that the at least one q-anonymizer (106) validates independent communication between client application and q- anonymizer and further anonymize user identity between client application and service provider.
2. A system according to Claim 1 wherein the at least one quantum key distribution (QKD) network between client application and q-anonymizer (104) generates shared secret key K, and identifier key (ID).
3. A system according to Claim 1, wherein the at least one QKD network between q-anonymizer and service provider (108) generates shared secret key K2 and identifier key (ID).
4. A system according to Claim 1 , wherein the said q-anonymizer (104) anonymize user identity between client application and service provider by generating QKD based pseudonym ID using at least XOR function in order to protect user identities during communication over QKD network.
5. A system according to Claim 1 and Claim 4, wherein the said QKD based pseudonym ID will expire based on quantum key which generates only one session.
6. A method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD) comprising steps of:
initiating request to q-anonymizer (502);
generating shared secret key Ki and ID key between client application and q-anonymizer via QKD network (504);
transmitting shared secret key K1 and ID key to client application and transmitting ID key to q-anonymizer (506);
retrieving shared secret key Ki by q-anonymizer from QKD network (508); establishing trusted communication between client application and q- anonymizer (514);
generating shared secret key K2 and ID key between q-anonymizer and service provider via QKD network (602);
retrieving shared secret key K2 and ID key from QKD network and transmitting ID key to service provider by q-anonymizer (604); transmitting shared secret key K2 from QKD network to service provider (606);
establishing trusted communication between service provider and q- anonymizer by anonymizing user identity (612); and
creating QKD network based pseudonym identifier (ID) in q-anonymizer for privacy enhancement (700).
7. A method according to Claim 6 wherein retrieving shared secret key K, by q- anonymizer from QKD network further comprises performing challenge response to determine if communication is trusted (510) wherein communication between client application and q-anonymizer will be aborted (512) if challenge response fails; else trusted communication is established.
8. A method according to Claim 6 wherein retrieving shared secret key K2 and ID key from QKD network and transmitting ID key to service provider by q- anonymizer further comprises performing challenge response to determine if communication is trusted (608) wherein communication between client application and q-anonymizer will be aborted (610) if challenge response fails; else trusted communication is established.
A method (700) according to Claim 6 wherein creating QKD network based pseudonym ID in q-anonymizer for privacy enhancement further comprises:
retrieving shared secret keys ΚΊ and K2 from QKD network between client and service provider (702);
generating final key by combining shared secret keys Κ and K2 using XOR function (704); and
combining pseudonym ID key with final key to produce QKD network based pseudonym ID (706).
10. A method according to Claim 6 wherein shared secret key and shared secret key K2 are randomly generated via QKD network to enhance unlinkability between client and service provider.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| MYPI2011000002 MY150354A (en) | 2011-01-03 | 2011-01-03 | Pseudonym id privacy enhancement |
| MYPI2011000002 | 2011-01-03 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2012093928A1 true WO2012093928A1 (en) | 2012-07-12 |
Family
ID=46457610
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/MY2011/000248 Ceased WO2012093928A1 (en) | 2011-01-03 | 2011-12-27 | Pseudonym id privacy enhancement |
Country Status (2)
| Country | Link |
|---|---|
| MY (1) | MY150354A (en) |
| WO (1) | WO2012093928A1 (en) |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN108768629A (en) * | 2018-05-24 | 2018-11-06 | 中国科学院信息工程研究所 | A kind of credible relaying quantum communications method and system |
| CN111262699A (en) * | 2020-03-03 | 2020-06-09 | 成都量安区块链科技有限公司 | Quantum security key service method and system |
| CN114978479A (en) * | 2021-02-20 | 2022-08-30 | 南京如般量子科技有限公司 | Quantum secret communication service method and system based on shared quantum key card |
| CN116506121A (en) * | 2023-06-26 | 2023-07-28 | 广东广宇科技发展有限公司 | Quantum key distribution method |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7234059B1 (en) * | 2001-08-09 | 2007-06-19 | Sandia Corporation | Anonymous authenticated communications |
| US20090041239A1 (en) * | 2005-05-27 | 2009-02-12 | Nec Corporation | Pseudo-random function calculating device and method and number-limited anonymous authentication system and method |
-
2011
- 2011-01-03 MY MYPI2011000002 patent/MY150354A/en unknown
- 2011-12-27 WO PCT/MY2011/000248 patent/WO2012093928A1/en not_active Ceased
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7234059B1 (en) * | 2001-08-09 | 2007-06-19 | Sandia Corporation | Anonymous authenticated communications |
| US20090041239A1 (en) * | 2005-05-27 | 2009-02-12 | Nec Corporation | Pseudo-random function calculating device and method and number-limited anonymous authentication system and method |
Non-Patent Citations (1)
| Title |
|---|
| SETAPA ET AL.: "Pseudonym and Privacy Using Quantum Key Distribution (QKD) in E-business", IJCSNS INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, vol. 11, no. 8, August 2011 (2011-08-01), pages 151 - 154, Retrieved from the Internet <URL:http://paper.ijcsns.org/07_book/201108/20110822.pdf> [retrieved on 20120221] * |
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN108768629A (en) * | 2018-05-24 | 2018-11-06 | 中国科学院信息工程研究所 | A kind of credible relaying quantum communications method and system |
| CN111262699A (en) * | 2020-03-03 | 2020-06-09 | 成都量安区块链科技有限公司 | Quantum security key service method and system |
| CN114978479A (en) * | 2021-02-20 | 2022-08-30 | 南京如般量子科技有限公司 | Quantum secret communication service method and system based on shared quantum key card |
| CN116506121A (en) * | 2023-06-26 | 2023-07-28 | 广东广宇科技发展有限公司 | Quantum key distribution method |
| CN116506121B (en) * | 2023-06-26 | 2023-10-31 | 广东广宇科技发展有限公司 | Quantum key distribution method |
Also Published As
| Publication number | Publication date |
|---|---|
| MY150354A (en) | 2013-12-31 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12155757B2 (en) | Systems and methods for deployment, management and use of dynamic cipher key systems | |
| KR101730757B1 (en) | Method and system for accessing device by a user | |
| CN107438005B (en) | SM9 joint digital signature method and device | |
| CN104052608B (en) | Certificate-free remote anonymous authentication method based on third party in cloud application | |
| Darwish et al. | Decentralizing privacy implementation at cloud storage using blockchain-based hybrid algorithm | |
| CN106416123A (en) | password-based authentication | |
| CN111639345B (en) | Method and system for secure multi-party cloud computing based on homomorphic encryption | |
| WO2012169153A1 (en) | Encrypted statistical processing system, device, method, and program | |
| Chen et al. | A privacy protection user authentication and key agreement scheme tailored for the Internet of Things environment: PriAuth | |
| WO2019049615A1 (en) | Anonymous broadcast method, key exchange method, anonymous broadcast system, key exchange system, communication device, and program | |
| CN106713349B (en) | Inter-group proxy re-encryption method capable of resisting attack of selecting cipher text | |
| Ramacher et al. | Privacy-preserving authenticated key exchange: stronger privacy and generic constructions | |
| CN114866244A (en) | Controllable anonymous authentication method, system and device based on ciphertext block chaining encryption | |
| WO2012093928A1 (en) | Pseudonym id privacy enhancement | |
| Leu et al. | Improving security level of LTE authentication and key agreement procedure | |
| CN114915494B (en) | A method, system, device and storage medium for anonymous authentication | |
| Belguith et al. | CUPS: secure opportunistic cloud of things framework based on attribute‐based encryption scheme supporting access policy update | |
| CN111656728B (en) | A device, system and method for secure data communication | |
| CN107637013A (en) | Key exchange method, key exchange system, key distribution device, communication device, and program | |
| Routray et al. | Context-aware attribute based access control for cloud-based scada systems | |
| Li et al. | PUOKMS: Password-protected updatable oblivious key management system for cloud storage | |
| CN119583043A (en) | A group message encryption method, system and device based on quantum key distribution | |
| Mehta et al. | Group authentication using paillier threshold cryptography | |
| CN112035820B (en) | Data analysis method used in Kerberos encryption environment | |
| CN116545741A (en) | Agent re-encryption reverse firewall method based on blockchain |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 11855031 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 11855031 Country of ref document: EP Kind code of ref document: A1 |