fulfill the requirements uniqueness of the generated
pseudonyms, privacy in terms of hiding the origina-
tors identifier and unlinkability of individualdata sets.
Since the second variant is more efficient in terms of
computational costs and space it has been suggested
for the use within smartcards.
Beside proposing two practical generators, a proto-
col has been proposed through which a smartcard
can efficiently authenticate anonymously to a medi-
cal database (with respect to a pseudonym). Based
on this protocol medical registers can be extended
and updated anonymously by the patient. Further-
more such an authentication protocol can be used to
make entries in several databases. For each database,
a fresh pseudonym is used so that entries of different
databases are mutually computationally unlinkable.
Concerning collision-free number generation further
information on implementation issues and extended
constructionscan be found in (Schaffer and Schartner,
2007) and (Schaffer, 2007) respectively.
