IssuerMaterial.html 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293
  1. <!-- HTML header for doxygen 1.8.10-->
  2. <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
  3. <html xmlns="http://www.w3.org/1999/xhtml">
  4. <head>
  5. <meta http-equiv="Content-Type" content="text/xhtml;charset=UTF-8"/>
  6. <meta http-equiv="X-UA-Compatible" content="IE=9"/>
  7. <meta name="generator" content="Doxygen 1.8.11"/>
  8. <title>Intel&reg; Enhanced Privacy ID SDK: Sample Issuer Material</title>
  9. <link href="tabs.css" rel="stylesheet" type="text/css"/>
  10. <script type="text/javascript" src="jquery.js"></script>
  11. <script type="text/javascript" src="dynsections.js"></script>
  12. <link href="navtree.css" rel="stylesheet" type="text/css"/>
  13. <script type="text/javascript" src="resize.js"></script>
  14. <script type="text/javascript" src="navtreedata.js"></script>
  15. <script type="text/javascript" src="navtree.js"></script>
  16. <script type="text/javascript">
  17. $(document).ready(initResizable);
  18. $(window).load(resizeHeight);
  19. </script>
  20. <link href="doxygen.css" rel="stylesheet" type="text/css" />
  21. <link href="epidstyle.css" rel="stylesheet" type="text/css"/>
  22. </head>
  23. <body>
  24. <div id="top"><!-- do not remove this div, it is closed by doxygen! -->
  25. <div id="titlearea">
  26. <table cellspacing="0" cellpadding="0">
  27. <tbody>
  28. <tr style="height: 56px;">
  29. <td id="projectalign" style="padding-left: 0.5em;">
  30. <div id="projectname"><a
  31. onclick="storeLink('index.html')"
  32. id="projectlink"
  33. class="index.html"
  34. href="index.html">Intel&reg; Enhanced Privacy ID SDK</a>
  35. &#160;<span id="projectnumber">3.0.0</span>
  36. </div>
  37. </td>
  38. </tr>
  39. </tbody>
  40. </table>
  41. </div>
  42. <!-- end header part -->
  43. <!-- Generated by Doxygen 1.8.11 -->
  44. </div><!-- top -->
  45. <div id="side-nav" class="ui-resizable side-nav-resizable">
  46. <div id="nav-tree">
  47. <div id="nav-tree-contents">
  48. <div id="nav-sync" class="sync"></div>
  49. </div>
  50. </div>
  51. <div id="splitbar" style="-moz-user-select:none;"
  52. class="ui-resizable-handle">
  53. </div>
  54. </div>
  55. <script type="text/javascript">
  56. $(document).ready(function(){initNavTree('IssuerMaterial.html','');});
  57. </script>
  58. <div id="doc-content">
  59. <div class="header">
  60. <div class="headertitle">
  61. <div class="title">Sample Issuer Material </div> </div>
  62. </div><!--header-->
  63. <div class="contents">
  64. <div class="toc"><h3>Table of Contents</h3>
  65. <ul><li class="level1"><a href="#IssuerMaterial_Groups">Sample Groups</a><ul><li class="level2"><a href="#IssuerMaterial_Groups_groupa">Sample Group A</a></li>
  66. <li class="level2"><a href="#IssuerMaterial_Groups_groupb">Sample Group B</a></li>
  67. </ul>
  68. </li>
  69. <li class="level1"><a href="#IssuerMaterial_GroupRls">Group Based Revocation Lists</a></li>
  70. <li class="level1"><a href="#IssuerMaterial_CmpGroups">Compressed Member Private Key</a><ul><li class="level2"><a href="#IssuerMaterial_CmpGroups_groupa">Compressed Sample Group A</a></li>
  71. <li class="level2"><a href="#IssuerMaterial_CmpGroups_groupb">Compressed Sample Group B</a></li>
  72. </ul>
  73. </li>
  74. <li class="level1"><a href="#IssuerMaterial_CmpGroupRls">Compressed Group Based Revocation Lists</a></li>
  75. </ul>
  76. </div>
  77. <div class="textblock"><p>The Intel&reg; EPID SDK does not include issuer APIs. That means you cannot generate the following items for validation:</p>
  78. <ul>
  79. <li>Group public key, which corresponds to the issuing private key kept by the issuer</li>
  80. <li>Member private keys</li>
  81. <li>Signature based revocation list (SigRL)</li>
  82. <li>Private key based revocation list (PrivRL)</li>
  83. <li>Group based revocation list (GroupRL)</li>
  84. </ul>
  85. <p>For validation purposes, you can use pre-generated sample data. This sample issuer material includes sample groups and revocation lists.</p>
  86. <p>Sample compressed key material is not included in the package.</p>
  87. <h1><a class="anchor" id="IssuerMaterial_Groups"></a>
  88. Sample Groups</h1>
  89. <h2><a class="anchor" id="IssuerMaterial_Groups_groupa"></a>
  90. Sample Group A</h2>
  91. <p>Group A (<code>groupa</code>) contains eight group members and sample revocation lists:</p>
  92. <p><br />
  93. </p>
  94. <h3>Members in Group A</h3>
  95. <table class="doxtable">
  96. <tr>
  97. <th>Group Member </th><th>Revocation Status </th></tr>
  98. <tr>
  99. <td>groupa/member0 </td><td>Non-revoked </td></tr>
  100. <tr>
  101. <td>groupa/member1 </td><td>Non-revoked </td></tr>
  102. <tr>
  103. <td>groupa/privrevokedmember0 </td><td>Revoked in PrivRL </td></tr>
  104. <tr>
  105. <td>groupa/privrevokedmember1 </td><td>Revoked in PrivRL </td></tr>
  106. <tr>
  107. <td>groupa/privrevokedmember2 </td><td>Revoked in PrivRL </td></tr>
  108. <tr>
  109. <td>groupa/sigrevokedmember0 </td><td>Revoked in SigRL </td></tr>
  110. <tr>
  111. <td>groupa/sigrevokedmember1 </td><td>Revoked in SigRL </td></tr>
  112. <tr>
  113. <td>groupa/sigrevokedmember2 </td><td>Revoked in SigRL </td></tr>
  114. </table>
  115. <p><br />
  116. </p>
  117. <h3>Revocation Lists for Group A</h3>
  118. <table class="doxtable">
  119. <tr>
  120. <th>Description </th><th>Directory Location </th><th>Revoked Members </th></tr>
  121. <tr>
  122. <td>Private key based revocation list </td><td><code>groupa/privrl.bin</code> </td><td>privrevokedmember0, <br />
  123. privrevokedmember1, <br />
  124. privrevokedmember2 </td></tr>
  125. <tr>
  126. <td>Signature based revocation list </td><td><code>groupa/sigrl.bin</code> </td><td>sigrevokedmember0, <br />
  127. sigrevokedmember1, <br />
  128. sigrevokedmember2 </td></tr>
  129. <tr>
  130. <td>Empty private key based revocation list </td><td><code>groupa/privrl_empty.bin</code> </td><td>None </td></tr>
  131. <tr>
  132. <td>Empty signature based revocation list </td><td><code>groupa/sigrl_empty.bin</code> </td><td>None </td></tr>
  133. </table>
  134. <p><br />
  135. </p>
  136. <h2><a class="anchor" id="IssuerMaterial_Groups_groupb"></a>
  137. Sample Group B</h2>
  138. <p>Group B (<code>groupb</code>) contains four group members and sample revocation lists:</p>
  139. <p><br />
  140. </p>
  141. <h3>Members in Group B</h3>
  142. <table class="doxtable">
  143. <tr>
  144. <th>Group Member </th><th>Revocation Status </th></tr>
  145. <tr>
  146. <td>groupb/member0 </td><td>Non-revoked </td></tr>
  147. <tr>
  148. <td>groupb/member1 </td><td>Non-revoked </td></tr>
  149. <tr>
  150. <td>groupb/privrevokedmember0 </td><td>Revoked in PrivRL </td></tr>
  151. <tr>
  152. <td>groupb/sigrevokedmember0 </td><td>Revoked in SigRL </td></tr>
  153. </table>
  154. <p><br />
  155. </p>
  156. <h3>Revocation Lists for Group B</h3>
  157. <table class="doxtable">
  158. <tr>
  159. <th>Description </th><th>Directory Location </th><th>Revoked Members </th></tr>
  160. <tr>
  161. <td>Private key based revocation list </td><td><code>groupb/privrl.bin</code> </td><td>privrevokedmember0 </td></tr>
  162. <tr>
  163. <td>Signature based revocation list </td><td><code>groupb/sigrl.bin</code> </td><td>sigrevokedmember0 </td></tr>
  164. <tr>
  165. <td>Empty private key based revocation list </td><td><code>groupb/privrl_empty.bin</code> </td><td>None </td></tr>
  166. <tr>
  167. <td>Empty signature based revocation list </td><td><code>groupb/sigrl_empty.bin</code> </td><td>None </td></tr>
  168. </table>
  169. <h1><a class="anchor" id="IssuerMaterial_GroupRls"></a>
  170. Group Based Revocation Lists</h1>
  171. <p>If an entire group is no longer valid, the issuer can revoke it using the group based revocation list. Two sample group based revocation lists are provided with the SDK.</p>
  172. <p><br />
  173. </p>
  174. <h3>Sample GrpRLs</h3>
  175. <table class="doxtable">
  176. <tr>
  177. <th>Group Based Revocation List </th><th>Description </th></tr>
  178. <tr>
  179. <td><code>grprl_empty.bin</code> </td><td>No entries </td></tr>
  180. <tr>
  181. <td><code>grprl.bin</code> </td><td>One entry in which <code>groupb</code> is revoked </td></tr>
  182. </table>
  183. <h1><a class="anchor" id="IssuerMaterial_CmpGroups"></a>
  184. Compressed Member Private Key</h1>
  185. <p>Sample Groups</p>
  186. <p>Intel&reg; EPID SDK supports use of compressed member private keys. The groups described here use compressed compressed member private keys but structuarlly corospond to groups described above.</p>
  187. <h2><a class="anchor" id="IssuerMaterial_CmpGroups_groupa"></a>
  188. Compressed Sample Group A</h2>
  189. <p>Group A (<code>groupa</code>) contains eight group members and sample revocation lists:</p>
  190. <p><br />
  191. </p>
  192. <h3>Members in Group A</h3>
  193. <table class="doxtable">
  194. <tr>
  195. <th>Group Member </th><th>Revocation Status </th></tr>
  196. <tr>
  197. <td>groupa/member0 </td><td>Non-revoked </td></tr>
  198. <tr>
  199. <td>groupa/member1 </td><td>Non-revoked </td></tr>
  200. <tr>
  201. <td>groupa/privrevokedmember0 </td><td>Revoked in PrivRL </td></tr>
  202. <tr>
  203. <td>groupa/privrevokedmember1 </td><td>Revoked in PrivRL </td></tr>
  204. <tr>
  205. <td>groupa/privrevokedmember2 </td><td>Revoked in PrivRL </td></tr>
  206. <tr>
  207. <td>groupa/sigrevokedmember0 </td><td>Revoked in SigRL </td></tr>
  208. <tr>
  209. <td>groupa/sigrevokedmember1 </td><td>Revoked in SigRL </td></tr>
  210. <tr>
  211. <td>groupa/sigrevokedmember2 </td><td>Revoked in SigRL </td></tr>
  212. </table>
  213. <p><br />
  214. </p>
  215. <h3>Revocation Lists for Group A</h3>
  216. <table class="doxtable">
  217. <tr>
  218. <th>Description </th><th>Directory Location </th><th>Revoked Members </th></tr>
  219. <tr>
  220. <td>Private key based revocation list </td><td><code>groupa/privrl.bin</code> </td><td>privrevokedmember0, <br />
  221. privrevokedmember1, <br />
  222. privrevokedmember2 </td></tr>
  223. <tr>
  224. <td>Signature based revocation list </td><td><code>groupa/sigrl.bin</code> </td><td>sigrevokedmember0, <br />
  225. sigrevokedmember1, <br />
  226. sigrevokedmember2 </td></tr>
  227. <tr>
  228. <td>Empty private key based revocation list </td><td><code>groupa/privrl_empty.bin</code> </td><td>None </td></tr>
  229. <tr>
  230. <td>Empty signature based revocation list </td><td><code>groupa/sigrl_empty.bin</code> </td><td>None </td></tr>
  231. </table>
  232. <p><br />
  233. </p>
  234. <h2><a class="anchor" id="IssuerMaterial_CmpGroups_groupb"></a>
  235. Compressed Sample Group B</h2>
  236. <p>Group B (<code>groupb</code>) contains four group members and sample revocation lists:</p>
  237. <p><br />
  238. </p>
  239. <h3>Members in Group B</h3>
  240. <table class="doxtable">
  241. <tr>
  242. <th>Group Member </th><th>Revocation Status </th></tr>
  243. <tr>
  244. <td>groupb/member0 </td><td>Non-revoked </td></tr>
  245. <tr>
  246. <td>groupb/member1 </td><td>Non-revoked </td></tr>
  247. <tr>
  248. <td>groupb/privrevokedmember0 </td><td>Revoked in PrivRL </td></tr>
  249. <tr>
  250. <td>groupb/sigrevokedmember0 </td><td>Revoked in SigRL </td></tr>
  251. </table>
  252. <p><br />
  253. </p>
  254. <h3>Revocation Lists for Group B</h3>
  255. <table class="doxtable">
  256. <tr>
  257. <th>Description </th><th>Directory Location </th><th>Revoked Members </th></tr>
  258. <tr>
  259. <td>Private key based revocation list </td><td><code>groupb/privrl.bin</code> </td><td>privrevokedmember0 </td></tr>
  260. <tr>
  261. <td>Signature based revocation list </td><td><code>groupb/sigrl.bin</code> </td><td>sigrevokedmember0 </td></tr>
  262. <tr>
  263. <td>Empty private key based revocation list </td><td><code>groupb/privrl_empty.bin</code> </td><td>None </td></tr>
  264. <tr>
  265. <td>Empty signature based revocation list </td><td><code>groupb/sigrl_empty.bin</code> </td><td>None </td></tr>
  266. </table>
  267. <h1><a class="anchor" id="IssuerMaterial_CmpGroupRls"></a>
  268. Compressed Group Based Revocation Lists</h1>
  269. <p>If an entire group is no longer valid, the issuer can revoke it using the group based revocation list. Two sample group based revocation lists are provided with the SDK.</p>
  270. <p><br />
  271. </p>
  272. <h3>Sample GrpRLs</h3>
  273. <table class="doxtable">
  274. <tr>
  275. <th>Group Based Revocation List </th><th>Description </th></tr>
  276. <tr>
  277. <td><code>grprl_empty.bin</code> </td><td>No entries </td></tr>
  278. <tr>
  279. <td><code>grprl.bin</code> </td><td>One entry in which <code>groupb</code> is revoked </td></tr>
  280. </table>
  281. </div></div><!-- contents -->
  282. </div><!-- doc-content -->
  283. <!-- HTML footer for doxygen 1.8.10-->
  284. <!-- start footer part -->
  285. <div id="nav-path" class="navpath"><!-- id is needed for treeview function! -->
  286. <ul>
  287. <li class="footer">
  288. &copy; 2016 Intel Corporation
  289. </li>
  290. </ul>
  291. </div>
  292. </body>
  293. </html>