| US 7,490,069 B2 | ||
| Anonymous payment with a verification possibility by a defined party | ||
| Jan Camenisch, Rueschlikon (Switzerland) | ||
| Assigned to International Business Machines Corporation, Armonk, N.Y. (US) | ||
| Filed on May 29, 2003, as Appl. No. 10/448,098. | ||
| Claims priority of application No. 02405432 (EP), filed on May 30, 2002. | ||
| Prior Publication US 2005/0010535 A1, Jan. 13, 2005 | ||
| Int. Cl. H04K 1/00 (2006.01); H04L 9/00 (2006.01) | ||
| U.S. Cl. 705—74 [705/79; 713/180] | 14 Claims |

| 1. A computerized method for verifying an anonymous payment by a defined party in a communication system providing a public
key infrastructure, the method comprising:
receiving a validation message from a merchant party via an input port of a computer, the validation message comprising a
proof signature produced by a customer party and an encrypted payment message, the proof signature being derived from a zero-knowledge
proof 1) of knowledge of a customer secret key, a customer certificate, and at least one customer attribute, 2) that the encrypted
payment message encrypts said customer attribute, and 3) that said customer certificate is valid and is related to said customer
secret key, thereby allowing said customer secret key, said customer certificate, and said at least one customer attribute
to remain anonymous to said merchant party;
verifying, by said computer, a validity of the proof signature based on an issuing public key, a verification public key,
and the encrypted payment message;
decrypting, by said computer, at least part of the encrypted payment message based on a verification secret key corresponding
to the verification public key, thereby obtaining a customer information related to the at least one customer attribute; and
in an event of the validity of the proof signature, the computer using the obtained customer information for initializing
an authentication of the payment, and, in an event the proof siginature is not valid, the computer provides an indication
that the proof siginature was not valid.
|