X.509-compatible anonymous identity authentication and supervision method on a blockchain
By using the standard SHA256 hash function and Merkle tree combined with an accumulator on the blockchain to generate zero-knowledge proofs, the high computational overhead and security issues of anonymous certificate schemes are solved. This achieves anonymous identity authentication and supervision compatible with the X.509 certificate format, and supports large-scale certificate registration and revocation.
Patent Information
- Application Number
- CN202411610810.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-12
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2044-11-12
AI Technical Summary
Existing anonymous certificate solutions suffer from high computational overhead and security issues on the blockchain, and are not effectively compatible with the X.509 certificate format, thus failing to support large-scale certificate registration and revocation.
By employing the standard SHA256 hash function, combined with Merkle trees and accumulators, and generating first and second zero-knowledge proofs, middleware is used to extract identity verification fields from X.509 certificates, reducing computational overhead and supporting large-scale certificate revocation.
It achieves efficient anonymous identity authentication and supervision on the blockchain, is compatible with the X.509 certificate format, provides basic privacy protection, and reduces the computational overhead of zero-knowledge proofs and the complexity of certificate revocation.
Smart Images

Figure CN119544225B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of identity authentication, and particularly relates to a blockchain anonymous identity authentication and supervision method compatible with X.509. BACKGROUND
[0002] Generally, network users need to prove that they are not robots, old enough to access age-restricted videos, or eligible to download e-books from a local public library without being tracked. The development of anonymous certificates is to solve these problems.
[0003] Privacy-protecting identity recognition is a clear contradiction in terms: one cannot want to both identify oneself and maintain privacy at the same time. But it is increasingly necessary on the Internet today. For example, domestic access to certain video content is age-restricted, and identity verification is required to access by providing identity card information. The tracking and data exposure risks brought by such requirements can be eliminated by privacy-protecting encryption technology: anonymous certificates allow users to assert that they meet certain access standards, such as being over 18 years old, without revealing any other information about themselves.
[0004] In the past decade, blockchains have become more popular than centralized systems due to their strong integrity and availability, as well as their transparent and permissionless nature. Although permissionless access in blockchains promotes decentralization, there is still a need to restrict access to users who meet certain access standards in blockchain (or on-chain) applications, which involves the above-mentioned privacy-protecting identity recognition problem, and therefore the development of anonymous certificates is needed to complete the access control of on-chain identity.
[0005] An anonymous certificate system should meet the two most basic features: unlinkability and revocability. Unlinkability ensures that the system does not reveal the connection between the user and the certificate authority, and revocability is needed for the supervision of user certificates. The certificate authority maintains a certificate revocation list, and the certificates appearing in the list are unusable certificates. The certificate presented by the user must not be on the list to be a legal certificate. Most existing anonymous certificate schemes choose to build a zero-knowledge proof system on the chain to complete the certificate issuance and verification work to ensure the unlinkability of the anonymous certificate system. For revocability, a sparse Merkle tree is mostly used to maintain a certificate list, and the list is a list of issued legal certificates. When revoked, the certificate is only deleted from the sparse Merkle tree.
[0006] However, whether constructing a zero-knowledge proof system on the chain or using a sparse Merkle tree to maintain a certificate list, high computational overhead is required. Most solutions choose to use zero-knowledge proof friendly cryptographic primitives to reduce the overhead of constructing a zero-knowledge proof system, such as using a low-overhead Poseidon hash function to replace the standard sha256 hash function, and customizing the certificate format to reduce the amount of data that needs to be proven to reduce computational overhead, but this involves two problems: first, the low-overhead hash function has not been proven to be a secure hash function, which can pose a security threat to the entire system; second, customizing the certificate format is not desirable, as there are industry standards for certificate formats, so anonymous certificate systems should follow the widely recognized standard certificate format, X.509 certificate format. The overhead brought by using a sparse Merkle tree to maintain a certificate list mainly comes from the fact that as the number of issued certificates increases, the size of the tree will also increase, and the computational overhead of verifying whether a certificate exists in the list will also increase.
[0007] The prior art paper "zk-creds: Flexible Anonymous Credentials from zkSNARKs and Existing Identity Infrastructure" describes an anonymous identity authentication method, where the certificate is in the form of a cryptographic commitment, which contains the user's key and the user's attribute information, i.e. age, gender, and other personal information. A cryptographic commitment is generated for the user's personal information, and since this is done independently by the user, it is considered to protect the user's privacy. When the certificate issuing center adds the user's cryptographic commitment to the certificate list, i.e. the certificate is a node in the Merkle tree, the path to the root node exists, and the issuer tells the user that the certificate has been issued. The paper proposes a solution to the problem of the increasing size of the Merkle tree as the number of issued certificates increases by constructing a Merkle forest. Specifically, multiple Merkle trees are constructed to form a forest list, and the user needs to specify that the certificate has a path to the root node in a certain tree and that the tree exists in the forest list to complete the certificate validity proof. When it comes to revocation, the issuing center will delete the corresponding certificate path from the Merkle forest.
[0008] In order to reduce the overhead of building a zero-knowledge proof system to complete the certificate issuing and verification work, the prior art selects to use zero-knowledge proof friendly cryptographic primitives, which brings security problems to the whole system, but if not, the high overhead problem of building a zero-knowledge proof system on the chain will be faced, and the certificates of the existing scheme do not follow the universally recognized standard certificate format, that is, the X.509 certificate format; secondly, the overhead of the certificate revocation scheme of the prior art will increase exponentially with the increase of the certificate amount, and does not support large-scale certificate registration and revocation. SUMMARY
[0009] In order to solve the above problems existing in the prior art, the present application provides an anonymous identity authentication and supervision method on a block chain compatible with X.509. The technical problems to be solved by the present application are realized by the following technical solutions:
[0010] An anonymous identity authentication and supervision method on a block chain compatible with X.509 comprises:
[0011] S100, each user party calculates a self-legally-held middleware according to its own private key and its own legally-held certificate, and generates a first zero-knowledge proof by using the middleware;
[0012] S200, each user party proves to the service party that its identity certificate identification number is not in the revocation list of the service party by combining a Merkle tree and an accumulator, obtains a second zero-knowledge proof, and generates a plurality of secret values and public values in the proving process;
[0013] S300, when each user party sends a request to the service party, the user party provides the first zero-knowledge proof, the second zero-knowledge proof and the public value to the service party;
[0014] S400, the service party verifies the first zero-knowledge proof, the second zero-knowledge proof and the public value, and if all of them pass the verification, it is confirmed that the user party holds a legal certificate, and the request sent by the user party is responded.
[0015] Advantages:
[0016] The application provides a blockchain anonymous identity authentication and supervision method compatible with X.509. Each user side calculates a self-legally-held middleware according to a self private key and a self-held legal certificate, and generates a first zero-knowledge proof by using the middleware; each user side proves to a service side that an identity certificate identification number of the user side is not in a revocation list of the service side by combining a Merkle tree and an accumulator, obtains a second zero-knowledge proof, and generates a plurality of secret values and public values in the proving process; when each user side sends a request to the service side, the user side provides the first zero-knowledge proof, the second zero-knowledge proof and the public values to the service side, the service side performs authentication, and if the three are verified, the service side responds to the request sent by the user side. The application uses standard X.509 specification certificates to anonymously access various services of the service side and provides basic privacy protection, the X.509 specification certificate is a standard format certificate specified by a public key infrastructure and has authority. Meanwhile, the application designs a proof scheme supporting large-scale certificate revocation, and greatly reduces the zero-knowledge proof overhead of generating a proof not in the revocation list.
[0017] The application will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0018] Figure 1 is a system environment schematic diagram of the blockchain anonymous identity authentication and supervision method compatible with X.509 provided by the application;
[0019] Figure 2 is a flowchart of the blockchain anonymous identity authentication and supervision method compatible with X.509 provided by the application;
[0020] Figure 3 is a process schematic diagram of the Merkle tree combined with the accumulator provided by the application;
[0021] Figure 4 is a proof process schematic diagram of the zero-knowledge proof provided by the application. DETAILED DESCRIPTION
[0022] The application will be further described in detail below with reference to the accompanying drawings and embodiments. However, the implementation manner of the application is not limited to this.
[0023] REFERENCE Figure 1The regulatory method of the application relates to a CA institution, a service party and a user party. The application believes that the certificate provided for the user party should follow the standard certificate format, that is, the X.509 certificate format, so the anonymous certificate scheme proposed by the application is based on the X.509 certificate format. Secondly, considering the system security problem, the application believes that the standard sha256 hash function should be used as the cryptographic primitive of the zero-knowledge proof system, so the standard sha256 hash function is used in the places where the hash function is involved in the scheme of the application. Finally, the application proposes a certificate revocation scheme combining Merkle tree and accumulator, which solves the problem that the existing scheme does not support large-scale certificate registration and revocation.
[0024] The application aims to provide basic privacy protection for various services using standard X.509 specification certificates to anonymously access the services of a service party, while ensuring efficient system construction and certificate revocation functions.
[0025] In combination Figures 1-4 The application provides an anonymous identity authentication and regulatory method on a blockchain compatible with X.509, which comprises the following steps.
[0026] S100. Each user party calculates the intermediate software that the user party legally holds according to the private key of the user party and the legal certificate held by the user party, and generates a first zero-knowledge proof by using the intermediate software; the first zero-knowledge proof is used to prove that the user party has generated legal intermediate software.
[0027] In a specific embodiment of the application, S100 comprises the following steps.
[0028] S110. Each user party calculates the intermediate software that the user party legally holds by using the public key of the issuing institution , the legal X.509 specification certificate Cert signed by the issuing institution and the private key corresponding to the public key. The intermediate software is represented as:
[0029] Hash=Sha256(id,sk)(1);
[0030] In the formula, id is the serial number field in the X.509 specification certificate Cert, sk is the private key field of the user party, and Hash represents the output result of the standard sha256 hash function.
[0031] Considering that the size of the standard X.509 certificate is between 1KB and 4KB, and that a huge amount of calculation is required for hashing the standard hash function sha256 in the zero-knowledge proof environment, the application proposes a middleware concept, that is, extracting the important field capable of proving the identity from the X.509 certificate as the middleware for subsequent use of the certificate in the zero-knowledge proof environment. The middleware meets the following two requirements: (1) extracting the field capable of proving the identity in the zero-knowledge proof environment, which is strongly bound to the original certificate and does not require high calculation overhead; (2) since the subsequent access service party anonymous proof of holding a legal certificate will use the zero-knowledge proof system of the service party, this case can allow the service party to perform trusted setting of the zero-knowledge proof system; however, the zero-knowledge proof system used when constructing the middleware must be publicly verifiable, not only verifiable by a certain service party, so as to ensure the usability of the middleware.
[0032] S120, each user party generates a first zero-knowledge proof π1 using its own middleware, and the first zero-knowledge proof π1 is expressed as:
[0033]
[0034] Hash=Sha256(id,sk)(3);
[0035] In the formula, Verify represents a verification function, and True indicates that the verification result is true.
[0036] In order to ensure that the calculated middleware and the X.509 certificate are strongly bound, the first zero-knowledge proof π1 needs to prove the following information: (1) the user party holds a legal X.509 certificate Cert signed by the public signing authority public key ; wherein is public information, and Cert is secret information; (2) the user party calculates the middleware Hash=Sha256(id,sk) according to the process of step S110, wherein Hash is public information, and sk and id are secret information.
[0037] S200, each user party combines a Merkle tree and an accumulator to prove to the service party that its identity certificate identification number is not in the revocation list of the service party, obtains a second zero-knowledge proof, and generates a plurality of secret values and public values in the proof process; the second zero-knowledge proof is used to prove that the identity certificate identification number of the user party is not in the revocation list of the service party, and that the user party legally holds the middleware;
[0038] After the step S100, the user needs to prove his legal identity when accessing the specific service of the service provider. At this time, the user needs to show the legal middleware he holds and prove the validity of the middleware according to the revocation list RL of the service provider. The present application combines the Merkle tree and the accumulator to construct a scheme for proving that the user is not in the revocation list RL.
[0039] As a specific embodiment of the present application, the S200 includes:
[0040] S210, each user proves to the service provider that the id of the user belongs to a certain value range id1<id<id k , wherein id1 and id k are the value ranges of the accumulator v selected by the user, and the value ranges contain k identity information from id1 to id k in total;
[0041] S220, each user proves to the service provider that the id value of the user is in the value range of the accumulator v, but does not belong to any one of the k identity information from id1 to id k , which is expressed as and obtains a plurality of secret values and public values;
[0042] As a specific embodiment of the present application, referring to Figure 3 , the S220 includes:
[0043] S221, each user calculates c=g0 c(α) , wherein α is the private information of the service provider, and the public information that the user can obtain is , wherein g0 is the generator on the finite field selected by the service provider, represents the power operation of g0 on α, α 2 , α 3 ,..., α k , v(α) is used to calculate the accumulator v selected by the user, v(α) is a polynomial with respect to the variable α, and is expressed as v(α)=a k α k +a k-1 α k-1 +...+a1α+a0, wherein a k ,a k-1 ,...,a1,a0 represent the polynomial coefficients, v=g0 v(α) , c(α) is the quotient obtained by performing the polynomial division of v(α) and (id+α), and d is the remainder obtained by performing the polynomial division of v(α) and (id+α);
[0044] S221, each user party selects an accumulator v as a secret value, and selects a random number t as a secret value, calculates v t = t v, and takes v t as a public value;
[0045] S223, each user party selects a generator g0 on a finite field selected by the service party as a public value, selects d as a secret value and selects t as a secret value, calculates and takes the result g0 dt as a public value;
[0046] S234, each user party selects t, c as secret values, calculates c t = t c, and takes the result c t as a public value;
[0047] S235, each user party takes c, t and the certificate serial number id of the user party as secret values, calculates c id·t = id t c, and takes the result c id·t as a public value;
[0048] S236, each user party proves to the service party that the id value is within the value range of the accumulator v, but does not belong to any of the k identity information from id1 to id k by calculating ;
[0049] S230, each user party proves to the service party that the accumulator v selected by the user party is an element of the Merkle tree; wherein the Merkle tree records the information of the entire revocation list RL;
[0050] S240, each user party generates a second zero-knowledge proof π2 using the proof process of S210-S230. The second zero-knowledge proof π2 is expressed as:
[0051] id1<id<id k (4);
[0052] v t = t v (5);
[0053]
[0054] c t = t c (7);
[0055] c id·t = id t c (8);
[0056] v ∈ Merkle-Tree (9);
[0057] Hash = Sha256(id, sk) (10) ;
[0058] In the formula, the Merkle-Tree represents a Merkle tree storing all revoked certificate serial numbers.
[0059] The second zero-knowledge proof π2 proves the following information: (1) the correct calculation according to steps 4.2.2 to 4.2.5 is performed, (2) the user side id exists in a certain value range id1 < id < id k , wherein id1 and id k are accumulators selected by the user side, i.e., the accumulators contain k identity information from id1 to id k in total. (3) the user side holds a legal middleware.
[0060] S300, when each user side sends a request to the service side, the service side is provided with the first zero-knowledge proof, the second zero-knowledge proof and the public value;
[0061] S400, the service side verifies the first zero-knowledge proof, the second zero-knowledge proof and the public value, and if all of them pass the verification, it is confirmed that the user side holds a legal certificate, and the request sent by the user side is responded.
[0062] As a specific embodiment of the present application, reference is made to Figure 4 , S400 includes:
[0063] S410, when the service side receives the request of the user side, it calculates c αt = c t · α by using its own private information and the received public value.
[0064] Since α is secret information held by the service side, the service side can calculate c αt = c t · α by itself.
[0065] S420, the service side verifies the first zero-knowledge proof π1, the second zero-knowledge proof π2 and ; if all of them pass the verification, it is confirmed that the user side sending the request holds a legal certificate, and the request sent by the user side is responded.
[0066] The present application proposes a middleware concept, which extracts important fields capable of proving identity from X.509 certificates as middleware for subsequent use of certificates in a zero-knowledge proof environment. Since the size of standard X.509 specification certificates is between 1 KB and 4 KB, using this idea can greatly reduce the calculation overhead of a zero-knowledge proof system constructed by using standard specification certificates.
[0067] The application proposes a low-cost and large-scale certificate level attestation scheme that supports attestation of not being in the revocation list, in combination with a Merkle tree and an accumulator. The user side proves that the certificate serial number value exists in the domain value of a certain accumulator, but is not an element of the accumulator, and proves that the accumulator belongs to a Merkle tree that stores all revoked user side serial numbers, that is, the certificate serial number is not in the revocation list. The accumulator can contain multiple certificate information, and proving that an element does not belong to the accumulator does not require the construction of a zero-knowledge proof system, so the zero-knowledge proof computing overhead is only to prove that the accumulator belongs to the Merkle tree, even for large-scale certificate quantities, and will not bring great zero-knowledge proof computing overhead.
[0068] It should be noted that the terms "first", "second" in the present application are only for the purpose of description, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present application, the meaning of "multiple" is two or more, unless otherwise explicitly and specifically limited.
[0069] Although the present application is described herein in conjunction with various embodiments, other variations of the disclosed embodiments can be understood and implemented by those skilled in the art with reference to the drawings, the disclosure, and the appended claims in the process of implementing the claimed application. In the claims, the word "comprising" does not exclude other components or steps, and "one" or "an" does not exclude a plurality.
[0070] The above is a further detailed description of the present application in combination with specific preferred embodiments, and cannot be considered as limiting the specific implementation of the present application to these descriptions. For ordinary skilled persons in the art to which the present application belongs, several simple deductions or replacements can be made without departing from the concept of the present application, and all should be considered as falling within the scope of protection of the present application.
Claims
1. A method for anonymous identity authentication and supervision on X.509 compatible blockchain, characterized in that, Comprise: S100, each user party calculates the middleware that the user party holds legally according to the private key of the user party and the legal certificate held by the user party, and generates the first zero-knowledge proof by using the middleware; S200, each user party proves that the identity certificate identification number of the user party is not in the revocation list of the service party by combining the Merkle tree and the accumulator, obtains the second zero-knowledge proof, and generates a plurality of secret values and public values in the proof process; S300, when each user party sends a request to the service party, the user party provides the first zero-knowledge proof, the second zero-knowledge proof and the public value to the service party; S400, the service party verifies the first zero-knowledge proof, the second zero-knowledge proof and the public value, if all the three are verified, the service party confirms that the user party holds the legal certificate, and responds to the request sent by the user party; S100 comprises: S110, each user side utilizes the public key of the signing authority a signed legal X.509 specification certificate Cert and the public key a corresponding private key, calculates the middleware that is legally held by itself; the middleware is represented as Hash = Sha256 (id, sk) (1); In the formula, id is the serial number field in the X.509 specification certificate Cert, sk is the private key field of the user party, and Hash represents the output result of the standard sha256 hash function; S120, each user party generates the first zero-knowledge proof π1 by using the middleware of the user party, and the first zero-knowledge proof π1 is expressed as: Hash = Sha256 (id, sk) (3); In the formula, Verify represents a verification function, and True represents that the verification result is true; S200 comprises: S210, each user direction service party proves that the id belongs to a certain value range id1<id<id k , wherein id1 and id k are the value range of the accumulator v selected by the user party, which contains a total of k identity information from id1 to id k ; S220, each user direction service party to prove their own id value in the value range of the accumulator v, but does not belong to id k Any one of the k identity information, expressed as And get a plurality of secret values and public values; S230, each user party proves to the service party that the accumulator v selected by the user party is an element of the Merkle tree; wherein the Merkle tree records the information of the entire revocation list RL; S240, each user party generates the second zero-knowledge proof π2 by using the proof process of S210-S230; S220 comprises: S221, each user party computes c = g0 using accumulator v c(α) where α is the private information of the service party, and the public information that the user party can obtain is g0 is the generator on the finite field selected by the service party, represents the power operation of g0 on α, α 2 , α 3 ,..., α k , respectively, and v(α) is used to calculate the accumulator v selected by the user party, v(α) is a polynomial about variable α, and is expressed as v(α) = a k α k +a k-1 α k-1 +...+a1α+a0, where a k ,a k-1 ,...,a1,a0 represent polynomial coefficients, then v = g0 v(α) c(α) is the quotient obtained by performing polynomial division of v(α) and (id+α), and d is the remainder obtained by performing polynomial division of v(α) and (id+α). S222, each user party selects an accumulator v as a secret value, and randomly selects a random number t as a secret value, calculates v t = t · v, and takes v t as a public value; S223, each user party selects a generator g0 on the finite field selected by the service party as a public value, selects d as a secret value and selects t as a secret value, and calculates and sends the result g0 dt as a public value; S234, each user party chooses t, c as secret values, computes c t = t c, and makes the result c t as public value; S235, each user party takes c, t and the user party's certificate serial number id as secret values, calculates c id·t = id · t · c, and takes the result c id·t as public value; S236, each user side proves to the service side by calculating The id value proving itself to the service side is within the value range of the accumulator v, but does not belong to the id k Any one of the k identity information; The second zero-knowledge proof π2 is expressed as: id1 < id < id k (4); v t = t · v (5); c t = t c (7); c id·t = id · t · c (8); v ∈ Merkle-Tree (9); Hash = Sha256 (id, sk) (10); In the formula, Merkle-Tree represents a Merkle tree storing all revoked certificate serial numbers; S400 comprises: S410, when the service party receives the request of the user party, the service party calculates c by using its own private information and the received public value αt = c t · α; S420, the service party verifies the first zero-knowledge proof π1, the second zero-knowledge proof π2, and If all three are verified, it is confirmed that the user party sending the request holds a legal certificate, and the request sent by the user party is responded to. 2.The X.509 compatible anonymous identity authentication and supervision method on the blockchain according to claim 1, characterized in that, The first zero-knowledge proof is used to prove that the user party generates the legal middleware. 3.The X.509-compatible anonymous identity authentication and supervision on blockchain method of claim 1, wherein, The second zero-knowledge proof is used to prove that the identity certificate identification number of the user party is not in the revocation list of the service party, and the user party legally holds the middleware.
Citation Information
Patent Citations
Blockchain-based trustable gurantees
CN111357026A
Complete anonymous authentication method based on block chain
CN114615278A