Re: Age verification
Mark Lomas <ukcrypto-Qv/Mekd6ICy057r0afFFoQC/[email protected]> Fri, 2 Dec 2016 20:43:07 +0000
| Newsgroups | gmane.law.cryptography.uk |
|---|---|
| Message-ID | <CACAki+taT8koX-VcNn2Jb+pxV-7SAi4sQos6NZkNyfMkXPGbWw@mail.gmail.com> |
--047d7b5d9bdd6ae32e0542b2fc34 Content-Type: text/plain; charset=UTF-8 A temporary secret is insufficient because an adult can give such a secret to a child, similar to asking your older brother to buy you some cigarettes. Of the examples you give, only two are amenable to solution - nightclub entry and local alcohol sales. I can imagine a tamper-proof device that contains a biometric reader, accepts remote attestations (e.g. from my bank), confirms a customer's age but does not otherwise identify them. I deliberately say 'local' because if you offer a remote service it is open to the older brother attack. Mark On 2 December 2016 at 14:36, Graham Cobb <[email protected]> wrote: > Age verification is back in the news again due to the DE Bill. I have > wondered for a while whether crypto could allow us to create some sort > of double-blind age verification system: where the identity (name, date > of birth, etc) of the person is hidden from the entity needing > verification, and the identity of the resource being accessed is hidden > from the entity providing verification. Ideally, of course, it would be > triple blind: third parties such as law enforcement cannot find out what > resource was accessed by what person, at least not after the fact (maybe > they could with prior notification that a particular person or a > particular resource was to be monitored). > > I had in mind something like: > > 1. Assume that some entities exist who can provide acceptable age > verification (I will use a bank as an example below but it could be any > private or state entity). > > 2. Bank verifies your age. > > 3. You request them to sign a certificate stating that you are over a > specific age (say 18). > > 4. Bank provides the certificate to you. > > 5. You pass the certificate to the entity needing the proof (say, a > nightclub). > > 6. Nightclub validates the certificate against the bank's public key > (without needing to contact the bank). > > The hard part would seem to be proving that the certificate relates to > the actual person who is presenting it (to a practical level of > certainty similar to traditional techniques), without allowing the > nightclub to find out who that person is! I assume it would have to be > based on some sort of temporary secret which you would have to present > along with the certificate. > > I am sure the naive approach above would not work for various reasons > but I wonder what work has been done on this? It seems that proof of age > for everything from creating social media accounts, to shopping, to > drinking, to accessing porn, to ... is becoming more common and it is > essential that we have some way of proving age without disclosing who we > are, or what we want the proof for. > > Graham > > --047d7b5d9bdd6ae32e0542b2fc34 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">A temporary secret is insufficient because an adult can gi= ve such a secret to a child, similar to asking your older brother to buy yo= u some cigarettes.<br><div><br></div><div>Of the examples you give, only tw= o are amenable to solution - nightclub entry and local alcohol sales. I can= imagine a tamper-proof device that contains a biometric reader, accepts re= mote attestations (e.g. from my bank), confirms a customer's age but do= es not otherwise identify them.</div><div><br></div><div>I deliberately say= 'local' because if you offer a remote service it is open to the ol= der brother attack.</div><div><br></div><div>Mark</div><div><br></div></div= ><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On 2 December 20= 16 at 14:36, Graham Cobb <span dir=3D"ltr"><<a href=3D"mailto:g+ukcrypto= @cobb.uk.net" target=3D"_blank">[email protected]</a>></span> wrote= :<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-le= ft:1px #ccc solid;padding-left:1ex">Age verification is back in the news ag= ain due to the DE Bill.=C2=A0 I have<br> wondered for a while whether crypto could allow us to create some sort<br> of double-blind age verification system: where the identity (name, date<br> of birth, etc) of the person is hidden from the entity needing<br> verification, and the identity of the resource being accessed is hidden<br> from the entity providing verification.=C2=A0 Ideally, of course, it would = be<br> triple blind: third parties such as law enforcement cannot find out what<br= > resource was accessed by what person, at least not after the fact (maybe<br= > they could with prior notification that a particular person or a<br> particular resource was to be monitored).<br> <br> I had in mind something like:<br> <br> 1. Assume that some entities exist who can provide acceptable age<br> verification (I will use a bank as an example below but it could be any<br> private or state entity).<br> <br> 2. Bank verifies your age.<br> <br> 3. You request them to sign a certificate stating that you are over a<br> specific age (say 18).<br> <br> 4. Bank provides the certificate to you.<br> <br> 5. You pass the certificate to the entity needing the proof (say, a<br> nightclub).<br> <br> 6. Nightclub validates the certificate against the bank's public key<br= > (without needing to contact the bank).<br> <br> The hard part would seem to be proving that the certificate relates to<br> the actual person who is presenting it (to a practical level of<br> certainty similar to traditional techniques), without allowing the<br> nightclub to find out who that person is! I assume it would have to be<br> based on some sort of temporary secret which you would have to present<br> along with the certificate.<br> <br> I am sure the naive approach above would not work for various reasons<br> but I wonder what work has been done on this? It seems that proof of age<br= > for everything from creating social media accounts, to shopping, to<br> drinking, to accessing porn, to ... is becoming more common and it is<br> essential that we have some way of proving age without disclosing who we<br= > are, or what we want the proof for.<br> <span class=3D"HOEnZb"><font color=3D"#888888"><br> Graham<br> <br> </font></span></blockquote></div><br></div> --047d7b5d9bdd6ae32e0542b2fc34--