WO2012093928A1 - Pseudonym id privacy enhancement - Google Patents

Pseudonym id privacy enhancement Download PDF

Info

Publication number
WO2012093928A1
WO2012093928A1 PCT/MY2011/000248 MY2011000248W WO2012093928A1 WO 2012093928 A1 WO2012093928 A1 WO 2012093928A1 MY 2011000248 W MY2011000248 W MY 2011000248W WO 2012093928 A1 WO2012093928 A1 WO 2012093928A1
Authority
WO
WIPO (PCT)
Prior art keywords
anonymizer
key
qkd
service provider
shared secret
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/MY2011/000248
Other languages
French (fr)
Inventor
Setapa Sharipah
Khalid MOHD AMINUDIN MOHD
Abd Aziz Norazah
Mubarak MOHD FAIZAL
Ab Manan Jamalul-Lail
Abdul Kadir Azimah
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Mimos Bhd
Original Assignee
Mimos Bhd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Mimos Bhd filed Critical Mimos Bhd
Publication of WO2012093928A1 publication Critical patent/WO2012093928A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0852Quantum cryptography
    • H04L9/0855Quantum cryptography involving additional nodes, e.g. quantum relays, repeaters, intermediate nodes or remote nodes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/42Anonymization, e.g. involving pseudonyms

Definitions

  • the present invention relates to a system and method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
  • QKD quantum key distribution
  • Pseudonym identifier is used to protect user identity in ordinary privacy enhancement system wherein user is anonymous to e-Service Provider.
  • the weakness of pseudonym ID is traceability of a user's identity to the pseudonym ID because methodology used to create pseudonym ID is structured and predictable.
  • pseudonym ID is generated using hash function based on user's identity.
  • a timestamp is used as input to hash function to change value of pseudonym ID for each communication session, which is less linkable to user's identity.
  • the methodology of the timestamp is fixed, structured and predictable, which allows hacking by tracing the linkage. Thus, the entire system is thereby exposed to identity theft attack.
  • the present invention uses both privacy enhancement mechanisms and QKD to protect user privacy and to enhance system trust.
  • the present invention introduces anonymizer in QKD network to provide privacy enhancement service and to reinforce unlinkability through randomness of q-anonymizer.
  • the present invention provides the following advantages:- a) QKD based privacy;
  • QKD Quantum Key Distribution
  • secret key Once secret key has been established by QKD, it can be used for variety of purposes.
  • One of the purposes of the present invention is to use it as a seed to generate pseudonym ID by using anonymizer to produce quantum network based pseudonym ID.
  • QKD devices will become more robust, easier to configure, less expensive and smaller.
  • the present invention provides a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
  • the system comprising at least one client application (102), at least one q-anonymizer (106), at least one quantum key distribution (QKD) network between client application and q- anonymizer (104), at least one quantum key distribution (QKD) network between q- anonymizer and service provider ( 08) and a service provider (110).
  • the at least one q- anonymizer (106) validates independent communication between client application and q- anonymizer and further anonymize user identity between client application and service provider.
  • the at least one quantum key distribution (QKD) network between client application and q-anonymizer (104) generates shared secret key Ki and identifier key (ID) while the at least one quantum key distribution (QKD) network between q- anonymizer and service provider (108) generates shared secret key K 2 and identifier key (ID).
  • QKD quantum key distribution
  • the said q-anonymizer (104) anonymize user identity between client application and service provider by generating quantum key distribution (QKD) based pseudonym identifier (ID) using at least XOR function in order to protect user identities during communication over QKD network.
  • QKD quantum key distribution network
  • ID pseudonym identifier
  • Another aspect of the present invention provides a method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
  • the method comprising steps of initiating request to q-anonymizer (502), generating shared secret key and identifier key (ID) between client application and q- anonymizer via quantum key distribution (QKD) network (504), transmitting shared secret key K, and identifier key (ID) to client application and transmitting identifier key to q-anonymizer (506), retrieving shared secret key by q-anonymizer from quantum key distribution (QKD) network (508), establishing trusted communication between client application and q-anonymizer (514), generating shared secret key K 2 and identifier key (ID) between q-anonymizer and service provider via quantum key distribution (QKD) network (602), retrieving shared secret key K 2 and identifier key (ID) from quantum key distribution (QKD) network and transmitting identifier key (ID) to service provider by q- anonymizer (604), transmitting shared
  • the method for retrieving shared secret key by q-anonymizer from quantum key distribution (QKD) network further comprises performing challenge response to determine if communication is trusted (512) wherein communication between client application and q-anonymizer will be aborted (514) if challenge response fails; else trusted communication is established.
  • the method for retrieving shared secret key K 2 and identifier key (ID) from quantum key distribution (QKD) network and transmitting identifier key (ID) to service provider by q-anonymizer further comprises performing challenge response to determine if communication is trusted (608) wherein communication between client application and q-anonymizer will be aborted (610) if challenge response fails; else trusted communication is established.
  • Another aspect of the present invention provides a method (700) for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q-anonymizer for privacy enhancement.
  • the method comprises retrieving shared secret keys and K 2 from quantum key distribution (QKD) network between client and service provider (702), generating final key by combining shared secret keys K n and K 2 using XOR function (704) and combining pseudonym identifier (ID) key with final key to produce quantum key distribution (QKD) network based pseudonym identifier (ID) (706).
  • FIG. 1 illustrates a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
  • QKD quantum key distribution
  • FIG. 2 illustrates communications between Node 1 and Node 2 as well as between Node 2 and Node 3.
  • FIG. 3 illustrates trusted communication between client and q-anonymizer.
  • FIG. 4 illustrates q-anonymizer which anonymizes identity between client and service provider.
  • FIG. 5 is a flowchart illustrating methodology for establishing trusted communication between client and Q-anonymizer.
  • FIG. 6 is a flowchart illustrating methodology for establishing trusted communication between service provider and q-anonymizer by anonymizing user identity.
  • FIG. 7 is a flowchart illustrating methodology for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q-anonymizer for privacy enhancement.
  • QKD quantum key distribution
  • ID pseudonym identifier
  • the present invention provides a system and method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
  • QKD quantum key distribution
  • FIG. 1 illustrates a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
  • the system comprising at least one client application (102), at least one q-anonymizer (106), at least one quantum key distribution (QKD) network between client application and q-anonymizer (104), at least one quantum key distribution (QKD) network between q-anonymizer and service provider (108) and a service provider (110).
  • QKD box of quantum network (102, 108) generates shared keys K and K 2 and identifier (ID) key
  • the at least one quantum key distribution (QKD) network between client application and q-anonymizer (104) generates shared secret key and identifier key (ID).
  • the at least one quantum key distribution (QKD) network between q-anonymizer and service provider (108) generates shared secret key K 2 and identifier key (ID).
  • the at least one q-anonymizer (106) validates independent communication between client application and q-anonymizer and further anonymize user identity between client application and service provider.
  • the said q-anonymizer (104) anonymize user identity between client application and service provider by generating quantum key distribution (QKD) based pseudonym identifier (ID) using at least XOR function in order to protect user identities during communication over QKD network.
  • QKD quantum key distribution
  • ID pseudonym identifier
  • FIG. 2 illustrates communications between Node 1 and Node 2 as well as between Node 2 and Node 3.
  • client in node 1 receives shared key from QKD system and transmits key to q- anonymizer.
  • the shared key K, and ID key are generated through quantum link.
  • Both identical keys, ⁇ and K 2 are stored in database together with ID key in node 1 and 2.
  • q-anonymizer retrieves shared key K, through link 1 in node 2. Communication is established between client and q-anonymizer.
  • q- anonymizer retrieves shared key K 2 from QKD system wherein shared key K 2 and ID key is generated through link 2.
  • Service provider in node 3 receives ID key from q- anonymizer.
  • Service provider retrieves shared key K 2 from QKD system through link 2 using key ID which establishes communication between Q-anonymizer and service provider. Thereafter, K 2 is combined with pseudonym ID in order to obtain quantum- based pseudonym ID.
  • FIG. 3 illustrates trusted communication between client and q-anonymizer.
  • client application receives shared key Ki from QKD system.
  • the key ID is sent to q-anonymizer wherein q- anonymizer retrieves key ⁇ from QKD system which establishes communication between client and q-anonymizer.
  • q-anonymizer retrieves key K 2 from QKD system using link 2.
  • Service provider receives key ID from Q-anonymizer. Using key ID, service provider receives shared key K 2 from QKD system which establishes communication between service provider and Q-anonymizer in node 2.
  • FIG. 4 illustrates q-anonymizer which anonymizes identity between client and service provider.
  • shared key K ⁇ will be combined with shared key K 2 using XOR function in q-anonymizer which results in the final key.
  • Pseudonym ID will then be combined with final key to obtain Q Net-based pseudonym ID which protects user personnel identity for privacy.
  • FIG. 5 is a flowchart illustrating methodology for establishing trusted communication between client and Q- anonymizer while FIG. 6 is a flowchart illustrating methodology for establishing trusted communication between service provider and q-anonymizer by anonymizing user identity.
  • a method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD) comprising steps of initiating request to q-anonymizer (502) and generating shared secret key Ki and identifier key (ID) between client application and q-anonymizer via quantum key distribution (QKD) network (504).
  • QKD quantum key distribution
  • shared secret key Ki and identifier key (ID) is transmitted to client application and further transmitting identifier key to q-anonymizer (506).
  • Shared secret key is retrieved by q-anonymizer from quantum key distribution (QKD) network (508).
  • challenge response is performed to determine if communication is trusted (512) wherein communication between client application and q-anonymizer will be aborted (514) if challenge response fails; else trusted communication is established. Trusted communication is established between client application and q-anonymizer if challenge response is successful (512).
  • shared secret key K 2 and identifier key (ID) is generated between q-anonymizer and service provider via quantum key distribution (QKD) network (602). Thereafter, shared secret key K 2 and identifier key (ID) is retrieved from quantum key distribution (QKD) network (604). Further, q-anonymizer transmits identifier key (ID) to service provider (604). Challenge response is performed to determine if communication is trusted (608) wherein communication between client application and q-anonymizer will be aborted (610) if challenge response fails; else trusted communication is established.
  • Shared secret key K 2 is transmitted from quantum key distribution (QKD) network to service provider (606) which establishes trusted communication between service provider and q-anonymizer by anonymizing user identity (612).
  • Quantum key distribution (QKD) network based pseudonym identifier (ID) is thereafter created in q-anonymizer for privacy enhancement (700).
  • FIG. 7 is a flowchart illustrating methodology for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q- anonymizer for privacy enhancement.
  • QKD quantum key distribution
  • ID quantum key distribution network based pseudonym identifier
  • FIG. 7 is a flowchart illustrating methodology for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q- anonymizer for privacy enhancement.
  • QKD quantum key distribution
  • ID quantum key distribution
  • ID quantum key distribution
  • Shared secret key K, and shared secret key K 2 are randomly generated via quantum key distribution (QKD) network to enhance unlinkability between client and service provider.
  • Quantum key distribution network (QKD) based pseudonym identifier (ID) of the present invention will expire based on quantum key which generates only one session.
  • User's identity is anonymous as pseudonym ID is combined with quantum key which allows for double layer to increase unlinkability, privacy.
  • Q-anonymizer is trusted and is part of QKD network that is secure and private. Thus, the present invention prevents QKD network based pseudonym ID from being traced back to the user as only q-anonymizer will know the user identity.
  • QKD Quantum Key Distribution

Landscapes

  • Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Electromagnetism (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)

Abstract

The present invention provides system for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution. The system comprises at least one client application, at least one q-anonymizer, at least one quantum key distribution network between client application and q-anonymizer, at least one quantum key distribution network between q-anonymizer and service provider and a service provider. The at least one q-anonymizer validates independent communication between client application and q-anonymizer and further anonymize user identity between client application and service provider.

Description

PSEUDONYM ID PRIVACY ENHANCEMENT FIELD OF INVENTION The present invention relates to a system and method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
BACKGROUND ART
Pseudonym identifier (ID) is used to protect user identity in ordinary privacy enhancement system wherein user is anonymous to e-Service Provider. The weakness of pseudonym ID is traceability of a user's identity to the pseudonym ID because methodology used to create pseudonym ID is structured and predictable. At present, pseudonym ID is generated using hash function based on user's identity. A timestamp is used as input to hash function to change value of pseudonym ID for each communication session, which is less linkable to user's identity. The methodology of the timestamp is fixed, structured and predictable, which allows hacking by tracing the linkage. Thus, the entire system is thereby exposed to identity theft attack.
The present invention uses both privacy enhancement mechanisms and QKD to protect user privacy and to enhance system trust. The present invention introduces anonymizer in QKD network to provide privacy enhancement service and to reinforce unlinkability through randomness of q-anonymizer. The present invention provides the following advantages:- a) QKD based privacy;
b) strong privacy properties of QKD which enforces protection of personal data; c) identity is untraceable;
d) identical key which provide authenticity between client and q-anonymizer, q- anonymizer and service provider which protects network from phishing attack; e) trusted and auditable by q-anonymizer system.
The approach in the present invention provides solution towards predictability of pseudonym by using an alternative method provided by Quantum Key Distribution (QKD) network. The characteristic and features of QKD enables incorporation of random process which complicates traceability of user identity. QKD network is unconditionally secure and private based on trusted QKD infrastructure as Q-anonymizer will be trusted anonymizer's engine.
Once secret key has been established by QKD, it can be used for variety of purposes. One of the purposes of the present invention is to use it as a seed to generate pseudonym ID by using anonymizer to produce quantum network based pseudonym ID. As QKD research continues, QKD devices will become more robust, easier to configure, less expensive and smaller.
The subject matter claimed herein is not limited to embodiments that solve any disadvantages or that operate only in environments such as those described above. Rather, this background is only provided to illustrate one exemplary technology area where some embodiments described herein may be practiced.
SUMMARY OF INVENTION
The present invention provides a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD). The system comprising at least one client application (102), at least one q-anonymizer (106), at least one quantum key distribution (QKD) network between client application and q- anonymizer (104), at least one quantum key distribution (QKD) network between q- anonymizer and service provider ( 08) and a service provider (110). The at least one q- anonymizer (106) validates independent communication between client application and q- anonymizer and further anonymize user identity between client application and service provider.
Preferably, the at least one quantum key distribution (QKD) network between client application and q-anonymizer (104) generates shared secret key Ki and identifier key (ID) while the at least one quantum key distribution (QKD) network between q- anonymizer and service provider (108) generates shared secret key K2 and identifier key (ID).
Further, the said q-anonymizer (104) anonymize user identity between client application and service provider by generating quantum key distribution (QKD) based pseudonym identifier (ID) using at least XOR function in order to protect user identities during communication over QKD network. The said quantum key distribution network (QKD) based pseudonym identifier (ID) will expire based on quantum key which generates only one session.
Another aspect of the present invention provides a method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD). The method comprising steps of initiating request to q-anonymizer (502), generating shared secret key and identifier key (ID) between client application and q- anonymizer via quantum key distribution (QKD) network (504), transmitting shared secret key K, and identifier key (ID) to client application and transmitting identifier key to q-anonymizer (506), retrieving shared secret key by q-anonymizer from quantum key distribution (QKD) network (508), establishing trusted communication between client application and q-anonymizer (514), generating shared secret key K2 and identifier key (ID) between q-anonymizer and service provider via quantum key distribution (QKD) network (602), retrieving shared secret key K2 and identifier key (ID) from quantum key distribution (QKD) network and transmitting identifier key (ID) to service provider by q- anonymizer (604), transmitting shared secret key K2 from quantum key distribution (QKD) network to service provider (606), establishing trusted communication between service provider and q-anonymizer by anonymizing user identity (612) and creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q- anonymizer for privacy enhancement (700).
Preferably, the method for retrieving shared secret key by q-anonymizer from quantum key distribution (QKD) network further comprises performing challenge response to determine if communication is trusted (512) wherein communication between client application and q-anonymizer will be aborted (514) if challenge response fails; else trusted communication is established. Further, the method for retrieving shared secret key K2 and identifier key (ID) from quantum key distribution (QKD) network and transmitting identifier key (ID) to service provider by q-anonymizer further comprises performing challenge response to determine if communication is trusted (608) wherein communication between client application and q-anonymizer will be aborted (610) if challenge response fails; else trusted communication is established.
Another aspect of the present invention provides a method (700) for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q-anonymizer for privacy enhancement. The method comprises retrieving shared secret keys and K2 from quantum key distribution (QKD) network between client and service provider (702), generating final key by combining shared secret keys Kn and K2 using XOR function (704) and combining pseudonym identifier (ID) key with final key to produce quantum key distribution (QKD) network based pseudonym identifier (ID) (706).
The present invention consists of features and a combination of parts hereinafter fully described and illustrated in the accompanying drawings, it being understood that various changes in the details may be made without departing from the scope of the invention or sacrificing any of the advantages of the present invention. BRIEF DESCRIPTION OF ACCOMPANYING DRAWINGS
To further clarify various aspects of some embodiments of the present invention, a more particular description of the invention will be rendered by references to specific embodiments thereof, which are illustrated in the appended drawings. It is appreciated that these drawings depict only typical embodiments of the invention and are therefore not to be considered limiting of its scope. The invention will be described and explained with additional specificity and detail through the accompanying drawings in which:
FIG. 1 illustrates a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD).
FIG. 2 illustrates communications between Node 1 and Node 2 as well as between Node 2 and Node 3. FIG. 3 illustrates trusted communication between client and q-anonymizer.
FIG. 4 illustrates q-anonymizer which anonymizes identity between client and service provider. FIG. 5 is a flowchart illustrating methodology for establishing trusted communication between client and Q-anonymizer.
FIG. 6 is a flowchart illustrating methodology for establishing trusted communication between service provider and q-anonymizer by anonymizing user identity.
FIG. 7 is a flowchart illustrating methodology for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q-anonymizer for privacy enhancement. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
The present invention provides a system and method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD). Hereinafter, this specification will describe the present invention according to the preferred embodiments. It is to be understood that limiting the description to the preferred embodiments of the invention is merely to facilitate discussion of the present invention and it is envisioned without departing from the scope of the appended claims.
Reference is first made to FIG. 1. FIG. 1 illustrates a system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD). As illustrated in FIG. 1 , the system comprising at least one client application (102), at least one q-anonymizer (106), at least one quantum key distribution (QKD) network between client application and q-anonymizer (104), at least one quantum key distribution (QKD) network between q-anonymizer and service provider (108) and a service provider (110).
QKD box of quantum network (102, 108) generates shared keys K and K2 and identifier (ID) key wherein the at least one quantum key distribution (QKD) network between client application and q-anonymizer (104) generates shared secret key and identifier key (ID). The at least one quantum key distribution (QKD) network between q-anonymizer and service provider (108) generates shared secret key K2 and identifier key (ID).
The at least one q-anonymizer (106) validates independent communication between client application and q-anonymizer and further anonymize user identity between client application and service provider. The said q-anonymizer (104) anonymize user identity between client application and service provider by generating quantum key distribution (QKD) based pseudonym identifier (ID) using at least XOR function in order to protect user identities during communication over QKD network.
Reference is now being made to FIG. 2. FIG. 2 illustrates communications between Node 1 and Node 2 as well as between Node 2 and Node 3. As illustrated in FIG. 2, client in node 1 receives shared key from QKD system and transmits key to q- anonymizer. The shared key K, and ID key are generated through quantum link. Both identical keys, ^ and K2, are stored in database together with ID key in node 1 and 2. Upon receiving ID key, q-anonymizer retrieves shared key K, through link 1 in node 2. Communication is established between client and q-anonymizer. In node 2, q- anonymizer retrieves shared key K2 from QKD system wherein shared key K2 and ID key is generated through link 2. Service provider in node 3 receives ID key from q- anonymizer. Service provider retrieves shared key K2 from QKD system through link 2 using key ID which establishes communication between Q-anonymizer and service provider. Thereafter, K2 is combined with pseudonym ID in order to obtain quantum- based pseudonym ID.
Reference is now being made to FIG. 3. FIG. 3 illustrates trusted communication between client and q-anonymizer. As illustrated in FIG. 3, client application receives shared key Ki from QKD system. The key ID is sent to q-anonymizer wherein q- anonymizer retrieves key Ί from QKD system which establishes communication between client and q-anonymizer. In node 2, q-anonymizer retrieves key K2 from QKD system using link 2. Service provider receives key ID from Q-anonymizer. Using key ID, service provider receives shared key K2 from QKD system which establishes communication between service provider and Q-anonymizer in node 2.
Reference is now being made to FIG. 4. FIG. 4 illustrates q-anonymizer which anonymizes identity between client and service provider. As illustrated in FIG. 4, shared key K† will be combined with shared key K2 using XOR function in q-anonymizer which results in the final key. Pseudonym ID will then be combined with final key to obtain Q Net-based pseudonym ID which protects user personnel identity for privacy.
Reference is now being made to FIG. 5 and FIG. 6 respectively. FIG. 5 is a flowchart illustrating methodology for establishing trusted communication between client and Q- anonymizer while FIG. 6 is a flowchart illustrating methodology for establishing trusted communication between service provider and q-anonymizer by anonymizing user identity. As illustrated in FIG. 5, a method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD) comprising steps of initiating request to q-anonymizer (502) and generating shared secret key Ki and identifier key (ID) between client application and q-anonymizer via quantum key distribution (QKD) network (504). Thereafter, shared secret key Ki and identifier key (ID) is transmitted to client application and further transmitting identifier key to q-anonymizer (506). Shared secret key is retrieved by q-anonymizer from quantum key distribution (QKD) network (508). Further, challenge response is performed to determine if communication is trusted (512) wherein communication between client application and q-anonymizer will be aborted (514) if challenge response fails; else trusted communication is established. Trusted communication is established between client application and q-anonymizer if challenge response is successful (512).
As illustrated in FIG. 6, shared secret key K2 and identifier key (ID) is generated between q-anonymizer and service provider via quantum key distribution (QKD) network (602). Thereafter, shared secret key K2 and identifier key (ID) is retrieved from quantum key distribution (QKD) network (604). Further, q-anonymizer transmits identifier key (ID) to service provider (604). Challenge response is performed to determine if communication is trusted (608) wherein communication between client application and q-anonymizer will be aborted (610) if challenge response fails; else trusted communication is established.
Shared secret key K2 is transmitted from quantum key distribution (QKD) network to service provider (606) which establishes trusted communication between service provider and q-anonymizer by anonymizing user identity (612). Quantum key distribution (QKD) network based pseudonym identifier (ID) is thereafter created in q-anonymizer for privacy enhancement (700).
Reference is now being made to FIG. 7. FIG. 7 is a flowchart illustrating methodology for creating quantum key distribution (QKD) network based pseudonym identifier (ID) in q- anonymizer for privacy enhancement. As illustrated in FIG. 7, quantum key distribution (QKD) network based pseudonym identifier (ID) is created in q-anonymizer for privacy enhancement by retrieving shared secret keys K, and K2 from quantum key distribution (QKD) network between client and service provider (702). Thereafter, final key is generated by combining shared secret keys K1 and K2 using XOR function (704) and combining pseudonym identifier (ID) key with final key to produce quantum key distribution (QKD) network based pseudonym identifier (ID) (706).
Shared secret key K, and shared secret key K2 are randomly generated via quantum key distribution (QKD) network to enhance unlinkability between client and service provider. Quantum key distribution network (QKD) based pseudonym identifier (ID) of the present invention will expire based on quantum key which generates only one session. User's identity is anonymous as pseudonym ID is combined with quantum key which allows for double layer to increase unlinkability, privacy. Q-anonymizer is trusted and is part of QKD network that is secure and private. Thus, the present invention prevents QKD network based pseudonym ID from being traced back to the user as only q-anonymizer will know the user identity.
The approach in the present invention provides solution towards predictability of pseudonym by using an alternative method provided by Quantum Key Distribution (QKD) network. The characteristic and features of QKD enables incorporation of random process which complicates traceability of user identity. QKD network is unconditionally secure and private based on trusted QKD infrastructure as Q-anonymizer will be trusted anonymizer's engine.
The present invention may be embodied in other specific forms without departing from its essential characteristics. The described embodiments are to be considered in all respects only as illustrative and not restrictive. The scope of the invention is, therefore indicated by the appended claims rather than by the foregoing description. All changes, which come within the meaning and range of equivalency of the claims, are to be embraced within their scope.

Claims

1. A system (100) for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD) comprising:
at least one client application (102);
at least one q-anonymizer (106);
at least one QKD network between client application and q-anonymizer (104);
at least one QKD network between q-anonymizer and service provider (108); and
a service provider (110);
characterized in that the at least one q-anonymizer (106) validates independent communication between client application and q- anonymizer and further anonymize user identity between client application and service provider.
2. A system according to Claim 1 wherein the at least one quantum key distribution (QKD) network between client application and q-anonymizer (104) generates shared secret key K, and identifier key (ID).
3. A system according to Claim 1, wherein the at least one QKD network between q-anonymizer and service provider (108) generates shared secret key K2 and identifier key (ID).
4. A system according to Claim 1 , wherein the said q-anonymizer (104) anonymize user identity between client application and service provider by generating QKD based pseudonym ID using at least XOR function in order to protect user identities during communication over QKD network.
5. A system according to Claim 1 and Claim 4, wherein the said QKD based pseudonym ID will expire based on quantum key which generates only one session.
6. A method for solving predictability of pseudonym by using privacy enhancement mechanism and quantum key distribution (QKD) comprising steps of:
initiating request to q-anonymizer (502);
generating shared secret key Ki and ID key between client application and q-anonymizer via QKD network (504);
transmitting shared secret key K1 and ID key to client application and transmitting ID key to q-anonymizer (506);
retrieving shared secret key Ki by q-anonymizer from QKD network (508); establishing trusted communication between client application and q- anonymizer (514);
generating shared secret key K2 and ID key between q-anonymizer and service provider via QKD network (602);
retrieving shared secret key K2 and ID key from QKD network and transmitting ID key to service provider by q-anonymizer (604); transmitting shared secret key K2 from QKD network to service provider (606);
establishing trusted communication between service provider and q- anonymizer by anonymizing user identity (612); and
creating QKD network based pseudonym identifier (ID) in q-anonymizer for privacy enhancement (700).
7. A method according to Claim 6 wherein retrieving shared secret key K, by q- anonymizer from QKD network further comprises performing challenge response to determine if communication is trusted (510) wherein communication between client application and q-anonymizer will be aborted (512) if challenge response fails; else trusted communication is established.
8. A method according to Claim 6 wherein retrieving shared secret key K2 and ID key from QKD network and transmitting ID key to service provider by q- anonymizer further comprises performing challenge response to determine if communication is trusted (608) wherein communication between client application and q-anonymizer will be aborted (610) if challenge response fails; else trusted communication is established.
A method (700) according to Claim 6 wherein creating QKD network based pseudonym ID in q-anonymizer for privacy enhancement further comprises:
retrieving shared secret keys ΚΊ and K2 from QKD network between client and service provider (702);
generating final key by combining shared secret keys Κ and K2 using XOR function (704); and
combining pseudonym ID key with final key to produce QKD network based pseudonym ID (706).
10. A method according to Claim 6 wherein shared secret key and shared secret key K2 are randomly generated via QKD network to enhance unlinkability between client and service provider.
PCT/MY2011/000248 2011-01-03 2011-12-27 Pseudonym id privacy enhancement Ceased WO2012093928A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
MYPI2011000002 MY150354A (en) 2011-01-03 2011-01-03 Pseudonym id privacy enhancement
MYPI2011000002 2011-01-03

Publications (1)

Publication Number Publication Date
WO2012093928A1 true WO2012093928A1 (en) 2012-07-12

Family

ID=46457610

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/MY2011/000248 Ceased WO2012093928A1 (en) 2011-01-03 2011-12-27 Pseudonym id privacy enhancement

Country Status (2)

Country Link
MY (1) MY150354A (en)
WO (1) WO2012093928A1 (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108768629A (en) * 2018-05-24 2018-11-06 中国科学院信息工程研究所 A kind of credible relaying quantum communications method and system
CN111262699A (en) * 2020-03-03 2020-06-09 成都量安区块链科技有限公司 Quantum security key service method and system
CN114978479A (en) * 2021-02-20 2022-08-30 南京如般量子科技有限公司 Quantum secret communication service method and system based on shared quantum key card
CN116506121A (en) * 2023-06-26 2023-07-28 广东广宇科技发展有限公司 Quantum key distribution method

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7234059B1 (en) * 2001-08-09 2007-06-19 Sandia Corporation Anonymous authenticated communications
US20090041239A1 (en) * 2005-05-27 2009-02-12 Nec Corporation Pseudo-random function calculating device and method and number-limited anonymous authentication system and method

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7234059B1 (en) * 2001-08-09 2007-06-19 Sandia Corporation Anonymous authenticated communications
US20090041239A1 (en) * 2005-05-27 2009-02-12 Nec Corporation Pseudo-random function calculating device and method and number-limited anonymous authentication system and method

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
SETAPA ET AL.: "Pseudonym and Privacy Using Quantum Key Distribution (QKD) in E-business", IJCSNS INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, vol. 11, no. 8, August 2011 (2011-08-01), pages 151 - 154, Retrieved from the Internet <URL:http://paper.ijcsns.org/07_book/201108/20110822.pdf> [retrieved on 20120221] *

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108768629A (en) * 2018-05-24 2018-11-06 中国科学院信息工程研究所 A kind of credible relaying quantum communications method and system
CN111262699A (en) * 2020-03-03 2020-06-09 成都量安区块链科技有限公司 Quantum security key service method and system
CN114978479A (en) * 2021-02-20 2022-08-30 南京如般量子科技有限公司 Quantum secret communication service method and system based on shared quantum key card
CN116506121A (en) * 2023-06-26 2023-07-28 广东广宇科技发展有限公司 Quantum key distribution method
CN116506121B (en) * 2023-06-26 2023-10-31 广东广宇科技发展有限公司 Quantum key distribution method

Also Published As

Publication number Publication date
MY150354A (en) 2013-12-31

Similar Documents

Publication Publication Date Title
US12155757B2 (en) Systems and methods for deployment, management and use of dynamic cipher key systems
KR101730757B1 (en) Method and system for accessing device by a user
CN107438005B (en) SM9 joint digital signature method and device
CN104052608B (en) Certificate-free remote anonymous authentication method based on third party in cloud application
Darwish et al. Decentralizing privacy implementation at cloud storage using blockchain-based hybrid algorithm
CN106416123A (en) password-based authentication
CN111639345B (en) Method and system for secure multi-party cloud computing based on homomorphic encryption
WO2012169153A1 (en) Encrypted statistical processing system, device, method, and program
Chen et al. A privacy protection user authentication and key agreement scheme tailored for the Internet of Things environment: PriAuth
WO2019049615A1 (en) Anonymous broadcast method, key exchange method, anonymous broadcast system, key exchange system, communication device, and program
CN106713349B (en) Inter-group proxy re-encryption method capable of resisting attack of selecting cipher text
Ramacher et al. Privacy-preserving authenticated key exchange: stronger privacy and generic constructions
CN114866244A (en) Controllable anonymous authentication method, system and device based on ciphertext block chaining encryption
WO2012093928A1 (en) Pseudonym id privacy enhancement
Leu et al. Improving security level of LTE authentication and key agreement procedure
CN114915494B (en) A method, system, device and storage medium for anonymous authentication
Belguith et al. CUPS: secure opportunistic cloud of things framework based on attribute‐based encryption scheme supporting access policy update
CN111656728B (en) A device, system and method for secure data communication
CN107637013A (en) Key exchange method, key exchange system, key distribution device, communication device, and program
Routray et al. Context-aware attribute based access control for cloud-based scada systems
Li et al. PUOKMS: Password-protected updatable oblivious key management system for cloud storage
CN119583043A (en) A group message encryption method, system and device based on quantum key distribution
Mehta et al. Group authentication using paillier threshold cryptography
CN112035820B (en) Data analysis method used in Kerberos encryption environment
CN116545741A (en) Agent re-encryption reverse firewall method based on blockchain

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11855031

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11855031

Country of ref document: EP

Kind code of ref document: A1