Anonymous identity authentication method and device, electronic equipment and storage medium

Through the authentication mechanism of ring signature and non-interactive zero-knowledge proof, ring signatures are generated and identity authentication is combined with timestamp identifiers, which solves the problem of identity authentication in the prior art that is susceptible to security attacks and information leakage, and realizes the security and reliability of anonymous identity authentication.

CN120474719AActive Publication Date: 2025-08-12TRAVELSKY TECHNOLOGY LIMITED

Patent Information

Application Number
CN202510675726.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-08-12
Estimated Expiration
2045-05-23

AI Technical Summary

Technical Problem

Existing identity authentication technology is prone to security attacks, resulting in information leakage and unreliable authentication, which in turn leads to identity authentication failure.

Method used

The authentication mechanism of ring signature and non-interactive zero-knowledge proof is adopted. The ring signature is generated by obtaining the set of trusted user public keys licensed by the authentication system and the local private key, and the identity authentication is combined with the timestamp identifier to ensure user anonymity and authentication security.

Benefits of technology

Without revealing the specific identity information of users, efficient anonymous identity authentication is achieved, ensuring the high security and reliability of identity authentication, preventing information leakage and replay attacks, and improving user privacy protection level and user experience of online services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474719A_ABST
    Figure CN120474719A_ABST
Patent Text Reader

Abstract

The invention discloses an anonymous identity authentication method and device, electronic equipment and a storage medium, and relates to the technical field of anonymous identity authentication or other related fields, and the method comprises the steps: obtaining a public key set containing a trusted user public key, and extracting a local private key of a target anonymous user; a ring signature is generated based on the public key set and the private key, certification information is generated based on the private key and the ring signature, the ring signature is used for certifying that the target anonymous user belongs to one of trusted users, and the certification information is used for certifying that the ring signature is legal; packaging the ring signature, the certification information and the timestamp identifier into an authentication request, submitting the authentication request to an authentication system, and returning an authentication result; and obtaining an identity authentication token indicating that authentication passes in the authentication result, and logging in the authentication system based on the identity authentication token. According to the method and the device, the technical problem of identity authentication failure caused by information leakage and unreliable authentication due to the fact that security attacks are easily encountered in the identity authentication process in related technologies is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of anonymous identity authentication, and in particular to an anonymous identity authentication method and device, electronic equipment, and a storage medium. Background Art

[0002] In the digital age, internet services have become deeply integrated into our lives, but this has also brought with it an increased risk of identity and privacy breaches. The personal information required to register and log in to online platforms—including sensitive data such as ID number, name, phone number, and email address—can be easily intercepted during transmission, leading to privacy breaches and security threats.

[0003] Despite rapid technological advancements, the authentication process still faces two core challenges: information leakage caused by security attacks, and the unreliability of the authentication mechanism itself. These two factors together constitute key factors in authentication failure. Given the serious consequences of private data leakage and users' growing demand for privacy protection, the limitations of existing authentication technology are becoming increasingly apparent. The authentication process is vulnerable to security attacks, resulting in information leakage and unreliable authentication, which in turn leads to authentication failure.

[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention

[0005] The embodiments of the present invention provide an anonymous identity authentication method and device, an electronic device, and a storage medium to at least solve the technical problem in related technologies that the identity authentication process is prone to security attacks, resulting in information leakage and unreliable authentication, thereby leading to identity authentication failure.

[0006] According to one aspect of an embodiment of the present invention, an anonymous identity authentication method is provided, wherein the user terminal for a target anonymous user includes: obtaining a public key set including N public keys of trusted users authorized by an authentication system, and extracting a private key locally stored by the target anonymous user, wherein N is a positive integer greater than or equal to 2; generating a ring signature based on the public key set and the private key, and generating proof information based on the private key and the ring signature, wherein the ring signature is used to prove that the target anonymous user belongs to one of the N trusted users, and the proof information is used to prove that the ring signature is legal; encapsulating the ring signature, the proof information and a timestamp identifier into an authentication request initiated by the target anonymous user, and submitting the authentication request to the authentication system, wherein the authentication system performs identity authentication based on the ring signature, the proof information and the timestamp identifier to generate and return an authentication result; obtaining an identity authentication token indicating that the authentication is passed in the authentication result, and logging into the authentication system based on the identity authentication token.

[0007] Furthermore, the step of generating a ring signature based on the public key set and the private key includes: obtaining challenge string information, wherein the challenge string information is a random challenge value generated by the authentication system according to a random timestamp in the current time period; obtaining a unique random number generated by a random number generator for the target anonymous user based on elliptic curve cryptography, and a set of random numbers generated for N-1 other trusted users other than the target anonymous user, wherein the random number set contains N-1 random numbers corresponding to the other N-1 trusted users, and each of the random numbers conforms to a preset elliptic curve. The method comprises the following steps: calculating a true intermediate value corresponding to the target anonymous user based on the unique random number, and constructing N-1 disguised intermediate values corresponding to other N-1 trusted users based on the random number set and the public key set; calculating N hash values based on the true intermediate value and the N-1 disguised intermediate values, and calculating a unique disguised random number corresponding to the target anonymous user based on the principle that the N hash values can form a closed hash chain; placing the unique disguised random number into the random number set, and arranging the new random number set and the closed hash chain according to a preset structure to obtain the ring signature.

[0008] Furthermore, the step of generating proof information based on the private key and the ring signature includes: performing hash calculation on the private key to obtain an anonymous user commitment, wherein the anonymous user commitment is a public commitment value used to prove that the user holds the private key but does not disclose the private key value; performing hash calculation on challenge string information, the public key set, the ring signature and the anonymous user commitment to obtain a challenge value; encrypting the challenge value using the private key to obtain a response value; and encapsulating the challenge value and the response value to obtain the proof information.

[0009] Furthermore, after receiving the authentication request, the authentication system authenticates the ring signature, including: extracting the ring signature in the authentication request, and calculating N verification intermediate values based on N random numbers and corresponding N hash values in the ring signature; verifying whether the N hash values can form a closed hash chain based on the N verification intermediate values and challenge string information, to obtain a verification result; and when the hash chain is verified to be closed, determining that the ring signature is authentic, and that the target anonymous user is one of the trusted users.

[0010] Furthermore, after receiving the authentication request, the authentication system performs a step of authenticating the proof information, including: performing a hash calculation using the challenge string information, the public key set, the closed hash chain, and the public anonymous user commitment to obtain a verification challenge value; extracting the proof information in the authentication request, and if the verification challenge value is consistent with the challenge value in the proof information, determining that the challenge value submitted by the target anonymous user is true.

[0011] Furthermore, after receiving the authentication request, the authentication system performs a step of authenticating the proof information, further comprising: upon determining that the challenge value submitted by the target anonymous user is authentic, performing a mathematical relationship verification on the verification challenge value and the response value in the proof information to obtain a verification result; and upon the verification result indicating that the verification challenge value and the response value conform to a preset mathematical relationship, determining that the proof information is reliable and that the ring signature is legal.

[0012] Furthermore, after receiving the authentication request, the authentication system performs a step of authenticating the timestamp identifier, including: querying the system identification library using the timestamp identifier as a query identifier to obtain a query result; if the query result indicates that the query identifier is not repeated with any historical identifier, determining that the timestamp authentication is successful; if the ring signature, the proof information and the timestamp identifier are all authenticated, generating an identity authentication token for the target anonymous user, wherein the identity authentication token is used to log in to the authentication system; if any of the ring signature, the proof information and the timestamp identifier fails to be authenticated, rejecting the authentication request of the target anonymous user and marking the timestamp identifier as invalid.

[0013] According to another aspect of an embodiment of the present invention, an anonymous identity authentication device is also provided, which is arranged at a user terminal of a target anonymous user and includes: an acquisition unit, used to obtain a public key set including N public keys of trusted users permitted by an authentication system, and extract a private key locally stored by the target anonymous user, wherein N is a positive integer greater than or equal to 2; a generation unit, used to generate a ring signature based on the public key set and the private key, and generate proof information based on the private key and the ring signature, wherein the ring signature is used to prove that the target anonymous user belongs to one of the N trusted users, and the proof information is used to prove that the ring signature is legal; a submission unit, used to encapsulate the ring signature, the proof information and the timestamp identifier into an authentication request initiated by the target anonymous user, and submit the authentication request to the authentication system, wherein the authentication system performs identity authentication based on the ring signature, the proof information and the timestamp identifier to generate and return an authentication result; a login unit, used to obtain an identity authentication token indicating that the authentication is passed in the authentication result, and log in to the authentication system based on the identity authentication token.

[0014] Furthermore, the generation unit includes: a first acquisition module for acquiring challenge string information, wherein the challenge string information is a random challenge value generated by the authentication system according to a random timestamp in the current time period; a second acquisition module for acquiring, based on elliptic curve cryptography, a unique random number generated by a random number generator for the target anonymous user, and a set of random numbers generated for N-1 other trusted users other than the target anonymous user, wherein the random number set includes N-1 random numbers corresponding to the other N-1 trusted users, and each of the random numbers conforms to the value range specified by the preset elliptic curve; a first calculation module for obtaining a unique random number generated by a random number generator for the target anonymous user according to elliptic curve cryptography, and a set of random numbers generated for N-1 other trusted users other than the target anonymous user, wherein the random number set includes N-1 random numbers corresponding to the other N-1 trusted users, and each of the random numbers conforms to the value range specified by the preset elliptic curve; A module is configured to calculate a true intermediate value corresponding to the target anonymous user based on the unique random number, and to construct N-1 disguised intermediate values corresponding to other N-1 trusted users based on the random number set and the public key set; a second calculation module is configured to calculate N hash values based on the true intermediate value and the N-1 disguised intermediate values, and to calculate a unique disguised random number corresponding to the target anonymous user based on the principle that the N hash values can form a closed hash chain; an arrangement module is configured to place the unique disguised random number into the random number set, and to arrange the new random number set and the closed hash chain according to a preset structure to obtain the ring signature.

[0015] Furthermore, the generation unit also includes: a third calculation module, used to perform hash calculation on the private key to obtain an anonymous user commitment, wherein the anonymous user commitment is a public commitment value used to prove that the user holds the private key but does not disclose the private key value; a fourth calculation module, used to perform hash calculation on the challenge string information, the public key set, the ring signature and the anonymous user commitment to obtain a challenge value; an encryption module, used to encrypt the challenge value using the private key to obtain a response value; and an encapsulation module, used to encapsulate the challenge value and the response value to obtain the proof information.

[0016] Furthermore, the anonymous identity authentication device also includes a first authentication unit in the authentication system, which is used to perform the step of authenticating the ring signature after the authentication system receives the authentication request. The first authentication unit includes: a fifth calculation module, which is used to extract the ring signature in the authentication request and calculate N verification intermediate values based on the N random numbers and corresponding N hash values in the ring signature; a verification module, which is used to verify whether the N hash values can form a closed hash chain based on the N verification intermediate values and challenge string information to obtain a verification result; and a first identification module, which is used to determine that the ring signature is authentic and that the target anonymous user is one of the trusted users when the hash chain is verified to be closed.

[0017] Furthermore, the anonymous identity authentication device also includes a second authentication unit in the authentication system, which is used to perform the step of authenticating the proof information after the authentication system receives the authentication request, and the second authentication unit includes: a sixth calculation module, which is used to use the challenge string information, the public key set, the closed hash chain and the public anonymous user commitment to perform hash calculation to obtain a verification challenge value; a second identification module, which is used to extract the proof information in the authentication request, and when the verification challenge value is consistent with the challenge value in the proof information, identify the challenge value submitted by the target anonymous user as true.

[0018] Furthermore, the second authentication unit also includes: a verification module for, upon determining that the challenge value submitted by the target anonymous user is authentic, performing a mathematical relationship verification on the verification challenge value and the response value in the proof information to obtain a verification result; and a third recognition module for, upon the verification result indicating that the verification challenge value and the response value conform to a preset mathematical relationship, determining that the proof information is reliable and that the ring signature is legal.

[0019] Furthermore, the anonymous identity authentication device also includes a third authentication unit in the authentication system, which is used to perform the step of authenticating the timestamp identifier after the authentication system receives the authentication request, and the third authentication unit includes: a query module, which is used to query the system identification library with the timestamp identifier as the query identifier to obtain the query result; a fourth identification module, which is used to determine that the timestamp authentication is successful when the query result indicates that the query identifier is not repeated with any historical identifier; a generation module, which is used to generate the identity authentication token of the target anonymous user when the ring signature, the proof information and the timestamp identifier are all authenticated, wherein the identity authentication token is used to log in to the authentication system; a rejection module, which is used to reject the authentication request of the target anonymous user and mark the timestamp identifier as invalid when any one of the ring signature, the proof information and the timestamp identifier fails to be authenticated.

[0020] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is further provided, wherein the computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute any of the above-mentioned anonymous identity authentication methods.

[0021] According to another aspect of an embodiment of the present invention, an electronic device is also provided, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement any one of the above-mentioned anonymous identity authentication methods.

[0022] In the present invention, an anonymous identity authentication method is proposed, which is used for the user terminal of a target anonymous user. First, a public key set containing N public keys of trusted users authorized by an authentication system is obtained, and a private key locally stored by the target anonymous user is extracted, wherein N is a positive integer greater than or equal to 2. Then, a ring signature is generated based on the public key set and the private key, and proof information is generated based on the private key and the ring signature. The ring signature is used to prove that the target anonymous user belongs to one of the N trusted users, and the proof information is used to prove that the ring signature is legal. Then, the ring signature, the proof information, and the timestamp identifier are encapsulated into an authentication request initiated by the target anonymous user, and the authentication request is submitted to the authentication system. The authentication system performs identity authentication based on the ring signature, the proof information, and the timestamp identifier to generate and return an authentication result. Finally, an identity authentication token indicating that the authentication is passed is obtained in the authentication result, and the authentication system is logged in based on the identity authentication token.

[0023] This invention uses an authentication mechanism that integrates ring signatures and non-interactive zero-knowledge proofs. Through cryptographic operations, it achieves efficient anonymous identity authentication without exposing the user's specific identity information. This ensures highly secure and reliable identity authentication while protecting user privacy.

[0024] Specifically, the target anonymous user first obtains a public key set containing multiple trusted user public keys authorized by the authentication system, and generates a ring signature based on the locally stored private key to prove that he or she is a member of the trusted user group, rather than directly exposing his or her specific identity. Then, based on the private key and the ring signature, proof information is generated to verify the legitimacy of the ring signature, ensuring that the signature is indeed generated by the private key held by the user, which can prove the authenticity and validity of the user's identity in an anonymous state; then a timestamp identifier is introduced to ensure the immediate uniqueness of each authentication request, which can prevent replay attacks. The ring signature, proof information and timestamp identifier are encapsulated into the authentication request and submitted to the authentication system by the target anonymous user. After receiving the request, the authentication system performs a comprehensive evaluation based on the above information to generate an authentication result; the identity authentication token issued after the final user successfully passes the authentication allows the user to log in to the authentication system without leaking any sensitive information, and enjoy secure and anonymous online services;

[0025] The present invention thoroughly improves the vulnerability of identity authentication in related technologies through the above-mentioned means, effectively avoids security attacks in the authentication process, reduces the risk of information leakage, and also enhances the reliability of authentication, significantly improving the level of user privacy protection and the user experience of online services, thereby solving the technical problems in related technologies that the identity authentication process is prone to security attacks, resulting in information leakage and unreliable authentication, which leads to identity authentication failure. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0027] Figure 1 is a flow chart of an optional anonymous identity authentication method according to an embodiment of the present invention;

[0028] Figure 2 is a model diagram of an optional anonymous authentication system according to an embodiment of the present invention;

[0029] Figure 3 is a flow chart of an optional anonymous authentication and anonymous login method according to an embodiment of the present invention;

[0030] Figure 4 is a schematic diagram of an optional anonymous identity authentication device according to an embodiment of the present invention;

[0031] Figure 5 The present invention is a block diagram of an electronic device for performing an anonymous identity authentication method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0032] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0033] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0034] To facilitate those skilled in the art to understand the present invention, some of the terms or nouns involved in the embodiments of the present invention are explained below:

[0035] Ring Signature, a special digital signature scheme, allows the signer of a message to conceal their identity from a group of signers (the "ring"). Ring signatures rely on the public keys of all members of the ring and the signer's own private key. When verifying a signature, the verifier only knows that the signer is a member of the ring, but cannot determine the specific member. This feature protects user privacy while ensuring the authenticity and legitimacy of authentication.

[0036] NIZK, short for Non-interactive Zero-Knowledge Proof, is a proof mechanism that allows a prover (i.e., a user) to prove the correctness of a statement or piece of knowledge without directly interacting with a verifier (e.g., an authentication system). In this invention, users use NIZK to prove that their private key is legitimate and can generate a valid ring signature, without revealing any specific information about the private key.

[0037] The following embodiments of the present invention can be applied to various systems, applications, and devices requiring anonymous identity authentication and secure login, enabling efficient and secure identity authentication and login without exposing personal privacy. This invention uses a ring signature algorithm for anonymous identity verification and generates proof information based on a non-interactive zero-knowledge proof. This can better ensure the legitimacy of the ring signature while protecting the privacy of the user's private key and preventing information leakage and replay attacks.

[0038] Through this innovative anonymous authentication process, even in highly sensitive environments such as financial transactions, online government affairs or personal data management platforms, users can successfully complete identity authentication and access required services while ensuring their own privacy, significantly improving the security of user data and the convenience of the authentication process.

[0039] The present invention will be described in detail below with reference to various embodiments.

[0040] Example 1

[0041] According to an embodiment of the present invention, an embodiment of an anonymous identity authentication method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0042] The present invention is implemented as follows Figure 1 The anonymous identity authentication method shown in the figure can be implemented by the user terminal of the target anonymous user interacting with the authentication system. It combines ring signatures with non-interactive zero-knowledge proof technology and is used in anonymous identity authentication scenarios, especially to address the problems of user privacy leakage and identity forgery. Through the anonymous identity authentication process means: obtaining a public key set, generating a ring signature and proof information, encapsulating an authentication request, verifying the validity of the ring signature and proof information, generating and returning an identity authentication token, etc., it can achieve high security and reliability of identity authentication while protecting user privacy.

[0043] Figure 1 is a flow chart of an optional anonymous identity authentication method according to an embodiment of the present invention, such as Figure 1 As shown, the method includes the following steps:

[0044] Step S101: obtain a public key set including N public keys of trusted users permitted by the authentication system, and extract a private key stored locally by a target anonymous user, where N is a positive integer greater than or equal to 2.

[0045] It's important to note that the authentication system is the central hub responsible for managing, verifying, and authorizing user identities. Its primary responsibilities include, but are not limited to, user management, key management, identity verification, and the issuance of authentication tokens. A trusted user is one who has registered with the authentication system and passed verification, whose identity is recognized by the system and who possesses the corresponding public-private key pair. The public key is publicly available, while the private key is controlled by the user.

[0046] The public keys of all trusted users form a public key set. This public key set can be used to generate a ring signature, allowing individual users to prove their membership in the set without revealing their personal identity. A private key is a key stored locally on a user's device. It is paired with a public key in the public key set and directly impacts the user's identity security and privacy. Any disclosure of this private key increases the risk of identity impersonation. In this embodiment of the present invention, only users with the correct private key can generate a valid ring signature, proving their membership in the set of trusted users permitted by the authentication system.

[0047] The target anonymous user in the embodiment of the present invention refers to a user who wishes to authenticate his / her identity through an authentication system without disclosing his / her personal identity information. For example, in scenarios such as financial services, online shopping, and social media, the user wishes to avoid leaking his / her personal information while enjoying the services.

[0048] Another important point to note is that key pairs are pre-generated during the registration phase. The registration process involves the authentication system generating a public-private key pair for each successfully registered user, handing the private key over to the registered user for private storage, and making the public key public. The registration phase is the foundation of the anonymous identity authentication system. Generating a public-private key pair for each user ensures that each user has a unique and secure identity. For example, during system registration, the SM2 algorithm (elliptic curve public key algorithm) is used to generate a public-private key pair for each user. The private key is kept private by the user, while the public key is made public and serves as the basis for generating ring signatures and ZKPs (zero-knowledge proofs).

[0049] In a specific embodiment, the public and private key generation process of SM2 relies on the basic operations of elliptic curves and the mathematical model of key generation, randomly selects two multiplicative cyclic groups G1 and G2 with prime order q, and a bilinear mapping function e:G1×G1→G2, and selects a generator g∈G1.

[0050] The private key generation process includes: randomly selecting a large integer sk as the user's private key, where the value range of sk is: 1≤sk≤q. The private key is confidential and is generated by a random number generator in the key generation mechanism to ensure its randomness and unpredictability. At the same time, the private key is kept solely by the user.

[0051] The public key generation includes: calculating by multiplying the private key sk and the generator g, that is: pk = sk·g.

[0052] Furthermore, in the user registration phase, it is assumed that the legal user set of the service system has n legal users, which can be expressed as: {P1, P2, ..., P n}, the authentication system registers all users in the legal user set, and generates a unique public and private key pair for each user in the legal user set through the key generation agency using the SM2 algorithm, namely: {(pk1,sk1),(pk2,sk2),...,(pk n ,sk n )}, where each public-private key pair corresponds to a user one-to-one. After a public-private key pair is generated for a user in the legal user set, the private key is given to the user in the legal user set for private safekeeping, and the public key is made public.

[0053] The authentication system provides challenge string information M to all users in the set of legitimate users within a fixed time period. The challenge string information M is a random challenge value randomly generated by the authentication system. Users use the challenge string information M to generate authentication requests to prevent replay attacks and prove the legitimacy of their identity in an anonymous manner.

[0054] The challenge string information M in the embodiment of the present invention can use a timestamp or a random number, or a value generated by combining a timestamp and a random number. When a user wants to log in to the authentication system anonymously, a ring signature and a zero-knowledge proof are required for identity authentication.

[0055] Step S102: Generate a ring signature based on the public key set and the private key, and generate proof information based on the private key and the ring signature. The ring signature is used to prove that the target anonymous user belongs to one of N trusted users, and the proof information is used to prove that the ring signature is legitimate.

[0056] It should be noted that a ring signature is a digital signature scheme that allows a signer to anonymously prove their membership in a specified set of users (the trusted user set) without revealing their exact identity. The set of public keys of this trusted user set is called a "ring." For example, if a ring consists of the public keys of five trusted users, when one of them signs anonymously, the recipient can only verify through the ring signature that the signature is signed by one of the five trusted users, but cannot determine which trusted user it is.

[0057] The proof information is data generated through non-interactive zero-knowledge proof technology to ensure the legitimacy of the ring signature and the actual ownership of the private key by the target anonymous user, ensuring that the legitimacy of the signature and the authenticity of the user's identity can be confirmed even in an anonymous state.

[0058] Optionally, the step of generating a ring signature based on a public key set and a private key includes: obtaining challenge string information, wherein the challenge string information is a random challenge value generated by an authentication system according to a random timestamp within a current time period; obtaining a unique random number generated by a random number generator for a target anonymous user based on elliptic curve cryptography, and a set of random numbers generated for N-1 other trusted users other than the target anonymous user, wherein the random number set includes N-1 random numbers corresponding one-to-one to the other N-1 trusted users, and each random number conforms to a value range specified by a preset elliptic curve; calculating a true intermediate value corresponding to the target anonymous user based on the unique random number, and constructing N-1 disguised intermediate values corresponding to the other N-1 trusted users based on the random number set and the public key set; calculating N hash values based on the true intermediate value and the N-1 disguised intermediate values, and calculating a unique disguised random number corresponding to the target anonymous user based on the principle that the N hash values can form a closed hash chain; placing the unique disguised random number into the random number set, and arranging the new random number set and the closed hash chain according to a preset structure to obtain a ring signature.

[0059] In a specific embodiment, for n users in the legal user set: {P1, P2, ..., P n}, assuming user P s is a member of the legal user set and wants to log in to the authentication system anonymously while ensuring the privacy of personal data, where s is the corresponding index in the legal user set (1≤s≤n), then user P s First, a random number k needs to be selected through a random number generator, and the random number k is calculated with the generator g to generate a random number belonging to the legitimate user P. s The middle value, that is, the true middle value: L s =k·g, where k∈Z q , q is the order of the elliptic curve, Z q It is a set of integers modulo q, that is, all integers satisfying 0≤k≤q. Since k in the present invention represents the user serial number, it is not 0.

[0060] Then, the legitimate user P s Generate the disguised intermediate value L of other legitimate users i (i≠s), used to obfuscate the signer's identity information. The specific method is as follows: a random number generator is used to generate a one-to-one random number for all users in the set of legal users except the signer, that is, {r1, r2, ..., r s-1 ,r s+1 ,...,r n}, where r i ∈Z q (i≠s), and then use the public key of other users to calculate and generate their own disguised intermediate values, namely: Li =r i ·g+c i ·pk i , where c i The challenge value of the previous user;

[0061] Regarding the challenge value, it should be noted that the real signature user P s In generating the real intermediate value L s Afterwards, the hash value obtained by using the SM3 hash algorithm combined with the challenge string information M is used as the challenge value corresponding to the user, that is: c s =H(M||L s-1 ), and for other users whose identities are obfuscated by the user, the hash calculation formula of the challenge value is: i+1 =H(M||L i ), so far, we have obtained N challenge values corresponding to N trusted users and N-1 random numbers corresponding to N-1 other users;

[0062] Based on the design requirement that the ring signature must be completely closed from beginning to end, for user P s Calculate a unique pseudo-random number r s , that is: r s =(kc s ·sk s )mod q, insert {r1,r2,...,r s-1 ,r s+1 ,...,r n} in the collection;

[0063] The final ring signature is formed as follows: σ=(c1,c2,...,c n ,r1,r2,...,r n ), where c1, c2, ..., c n are the challenge values of N trusted users, r1, r2, ..., r n is a random number of N trusted users.

[0064] Optionally, the step of generating proof information based on the private key and the ring signature includes: performing hash calculation on the private key to obtain an anonymous user commitment, wherein the anonymous user commitment is a public commitment value used to prove that the user holds the private key but does not disclose the private key value; performing hash calculation on the challenge string information, the public key set, the ring signature, and the anonymous user commitment to obtain a challenge value; encrypting the challenge value using the private key to obtain a response value; and encapsulating the challenge value and the response value to obtain proof information.

[0065] In a specific embodiment, user P sAfter receiving the challenge string information M and generating a ring signature, in order to ensure the legitimacy of one's own identity and prevent malicious users from forging the ring signature, it is necessary to generate a zero-knowledge proof of the ring signature to prove that one can generate a legal ring signature without exposing any private information about oneself.

[0066] First, user P s By using your own private key sk s Generate a commitment to ensure that the private key is not leaked. The commitment is generated using the SM3 hash algorithm, that is: C = H (sk s ), the commitment value is public and will not reveal the private key itself; then, in order to ensure the non-interactive nature of zero-knowledge proof, the challenge value challenge needs to be obtained through the public challenge string information M, user P s The public key, ring signature, and commitment are generated by combining the SM3 hash algorithm, namely: challenge = H(M,pk s ,σ,C); Then, through the encryption algorithm function f, the challenge value challenge and its own private key sk s Generate a certificate that can prove that user P s The response of holding a legal private key, the response generation formula is: response = f(sk s ,challenge); Finally, the challenge value and response value are encapsulated to form a zero-knowledge proof, that is: π s =(challenge,response).

[0067] In step S103, the ring signature, proof information, and timestamp identifier are encapsulated into an authentication request initiated by the target anonymous user, and the authentication request is submitted to the authentication system. The authentication system performs identity authentication based on the ring signature, proof information, and timestamp identifier to generate and return an authentication result.

[0068] User P s Before sending the authentication request, the timestamp identifier Timestamp is generated using the current timestamp and submitted to the authentication system together with the ring signature, zero-knowledge proof, and unique identifier as the authentication request. The authentication request can be expressed as {σ,π s ,Timestamp}.

[0069] It should be noted that appending a timestamp identifier (Timestamp) to the authentication request can prevent replay attacks; after the authentication system receives the authentication request, it compares the Timestamp with the timestamp list stored internally by the authentication system to detect reuse; and after successful authentication, the authentication system records the Timestamp to ensure the uniqueness of the authentication credentials, which can prevent double-spending attacks.

[0070] After receiving the authentication request, the authentication system will perform a series of verification processes based on the ring signature, the proof information, and the timestamp identifier to confirm the identity of the target anonymous user. The authentication results may include the following two situations.

[0071] 1. Authentication passed: If the authentication system confirms that the ring signature is valid, the proof information is correct, and the timestamp identifier appears for the first time and is within the valid range, an authentication token or identity authorization is generated as a sign of authentication passed. The user who initiated the request can use this authentication token to log in to the system and enjoy related services or permissions.

[0072] 2. Authentication failure: If any one or more of the ring signature, proof information, or timestamp identifier does not meet the expected verification criteria, the authentication system will reject the authentication request and record the failed timestamp identifier as invalid for comparison in future requests to prevent malicious retries or replay attacks.

[0073] Optionally, after receiving the authentication request, the authentication system performs the steps of authenticating the ring signature, including: extracting the ring signature in the authentication request, and calculating N verification intermediate values based on N random numbers and corresponding N hash values in the ring signature; verifying whether the N hash values can form a closed hash chain based on the N verification intermediate values and the challenge string information, and obtaining a verification result; when the hash chain is verified to be closed, determining that the ring signature is authentic, and that the target anonymous user is one of the trusted users.

[0074] Alternatively, when the hash chain is verified to be non-closed, the ring signature is deemed to be unauthentic, and the target anonymous user is deemed to be an untrustworthy user.

[0075] In a specific embodiment, after receiving the authentication request sent by the target anonymous user, the authentication system first performs ring signature verification, and calculates each user P using the challenge value and random number given in the submitted ring signature σ. i (i=1,2,...,n), that is: L i =r i ·g+c i ·pk i ; Then, the authentication system verifies whether the following conditions are met for each user, namely: c i+1 =H(M||L i ); Finally, verify whether c1 satisfies the loop closure condition, that is: c1=H(M||L n ), where L n is the median value of the last user.

[0076] If all the above conditions are met, the ring signature is proven to be valid, the target anonymous user who submitted the request is identified as a legitimate user without revealing personal information, and the ring signature does come from a member of the key ring.

[0077] Optionally, after receiving the authentication request, the authentication system performs steps to authenticate the proof information, including: performing hash calculation using the challenge string information, the public key set, the closed hash chain, and the public anonymous user commitment to obtain a verification challenge value; extracting the proof information in the authentication request, and when the verification challenge value is consistent with the challenge value in the proof information, determining that the challenge value submitted by the target anonymous user is authentic.

[0078] Alternatively, when the verification challenge value is inconsistent with the challenge value in the certification information, it is determined that the challenge value submitted by the target anonymous user is not authentic.

[0079] In a specific embodiment, when the ring signature authentication is passed, the authentication system continues to perform the non-interactive zero-knowledge proof π s Verification is performed to ensure that the target anonymous user actually has the correct private key and can legally generate a ring signature σ. The specific verification is as follows:

[0080] The authentication system administrator uses the same public information (public challenge string information M, public key set, ring signature σ, commitment C) to recalculate the challenge value, that is, verify the challenge value challenge new =H((M,pk s ,σ,C), if the recalculated verification challenge value challenge new If the challenge value is consistent with the challenge value challenge submitted by the target anonymous user, it means that the challenge value is generated correctly.

[0081] Optionally, after receiving the authentication request, the authentication system performs a step of authenticating the proof information, further comprising: when it is determined that the challenge value submitted by the target anonymous user is authentic, using the verification challenge value and the response value in the proof information to perform a mathematical relationship verification to obtain a verification result; when the verification result indicates that the verification challenge value and the response value conform to a preset mathematical relationship, determining that the proof information is reliable and that the ring signature is legal.

[0082] Alternatively, if the verification result indicates that the verification challenge value and the response value do not conform to a preset mathematical relationship, the certification information is deemed unreliable and the ring signature is deemed illegal.

[0083] In a specific embodiment, when verifying that the challenge value is generated correctly, the authentication system uses the calculated challenge value challenge newVerify(response,challenge) new ,pk s ,σ)=True; If the above equation holds, it can be verified that the target anonymous user has legally generated a ring signature without leaking the private key.

[0084] Optionally, after receiving the authentication request, the authentication system performs a step of authenticating the timestamp identifier, including: querying the system identification library using the timestamp identifier as the query identifier to obtain the query result; if the query result indicates that the query identifier does not repeat with any historical identifier, determining that the timestamp authentication is passed; if the query result indicates that there is a historical identifier that is repeated with the query identifier, determining that the timestamp authentication is failed.

[0085] Furthermore, after authenticating the timestamp identifier, the method further includes: if the ring signature, the proof information, and the timestamp identifier are all authenticated successfully, generating an identity authentication token for the target anonymous user, wherein the identity authentication token is used to log in to the authentication system; if any one of the ring signature, the proof information, and the timestamp identifier fails to be authenticated successfully, rejecting the authentication request of the target anonymous user and marking the timestamp identifier as invalid.

[0086] In a specific embodiment, the authentication system records the unique identifier Timestamp sent by the target anonymous user in the authentication request and checks whether the authentication request has been processed. If it is found that the same identifier has been processed, the duplicate request is rejected.

[0087] Furthermore, if the authentication system passes all the verifications of the ring signature, zero-knowledge proof and unique identity identifier Timestamp sent to the target anonymous user, the authentication system will confirm that the user's identity is legitimate and issue a P s Return a valid authentication token, namely: AuthenticationResult(P s )=Authorized; If any one or more of the verifications fail, the authentication system rejects the authentication request and marks the currently sent unique identifier Timestamp as invalid in the database, and never passes any authentication request carrying this identifier, i.e.: AuthenticationResult(P s )=Unauthorized.

[0088] Step S104: obtaining an identity authentication token indicating that the authentication is successful in the authentication result, and logging into the authentication system based on the identity authentication token.

[0089] In an optional embodiment, the target anonymous user P s After receiving the identity authentication token sent back from the authentication system, the user can use the token to apply for login to the authentication system and service system without revealing any personal information. After verifying that the authentication token is correct, the authentication system allows login. s Anonymous authentication and login succeeded.

[0090] Through the above steps S101 to S104, a public key set including the public keys of N trusted users authorized by the authentication system can be obtained first, and the private key locally stored by the target anonymous user can be extracted, where N is a positive integer greater than or equal to 2. A ring signature is then generated based on the public key set and the private key, and proof information is generated based on the private key and the ring signature, where the ring signature is used to prove that the target anonymous user belongs to one of the N trusted users, and the proof information is used to prove that the ring signature is legal. The ring signature, proof information and timestamp identifier are then encapsulated into an authentication request initiated by the target anonymous user, and the authentication request is submitted to the authentication system, where the authentication system performs identity authentication based on the ring signature, proof information and timestamp identifier to generate and return an authentication result. Finally, an identity authentication token indicating that the authentication is successful is obtained in the authentication result, and the authentication system is logged in based on the identity authentication token.

[0091] In this embodiment of the present invention, an authentication mechanism that integrates ring signatures and non-interactive zero-knowledge proofs is adopted. Through cryptographic operations, efficient anonymous identity authentication is achieved without exposing the user's specific identity information. This achieves the technical effect of ensuring highly secure and reliable identity authentication while protecting user privacy.

[0092] Specifically, the target anonymous user first obtains a public key set containing multiple trusted user public keys authorized by the authentication system, and generates a ring signature based on the locally stored private key to prove that he or she is a member of the trusted user group, rather than directly exposing his or her specific identity. Then, based on the private key and the ring signature, proof information is generated to verify the legitimacy of the ring signature, ensuring that the signature is indeed generated by the private key held by the user, which can prove the authenticity and validity of the user's identity in an anonymous state; then a timestamp identifier is introduced to ensure the immediate uniqueness of each authentication request, which can prevent replay attacks. The ring signature, proof information and timestamp identifier are encapsulated into the authentication request and submitted to the authentication system by the target anonymous user. After receiving the request, the authentication system performs a comprehensive evaluation based on the above information to generate an authentication result; the identity authentication token issued after the final user successfully passes the authentication allows the user to log in to the authentication system without leaking any sensitive information, and enjoy secure and anonymous online services;

[0093] The embodiments of the present invention thoroughly improve the vulnerability of identity authentication in related technologies through the above-mentioned means, effectively avoid security attacks in the authentication process, reduce the risk of information leakage, and at the same time enhance the reliability of authentication, significantly improve the level of user privacy protection and the user experience of online services, thereby solving the technical problem that the identity authentication process in related technologies is prone to security attacks, resulting in information leakage and unreliable authentication, which leads to identity authentication failure.

[0094] The present invention will be described below in conjunction with another specific embodiment.

[0095] The application background involved in the implementation mode of the present invention is: in the scenario of anonymous identity authentication, the authentication system provides a legal user set for the legal users of the website. Users in the set can log in, otherwise they are not allowed; if external users want to log in to the authentication system, they need to register and join the legal user set before they can use it.

[0096] Figure 2 is a model diagram of an optional anonymous authentication system according to an embodiment of the present invention, such as Figure 2 As shown, the model works as follows:

[0097] First, the authentication system administrator submits a key application to the key management center based on all users in the legal user set. The key management center generates a public-private key pair for each user using the SM2 algorithm and sends the generated public-private key pair to all users.

[0098] Suppose user U in the set of legitimate users wants to log in to the authentication system without revealing personal information. User U needs to use his personal private key and all public keys of users in the set of legitimate users to generate a ring signature to prove that he is a member of the legitimate users. Then, he needs to generate a non-interactive zero-knowledge proof for the ring signature to prove that the private key is indeed owned by him and can generate a valid ring signature to prevent external attackers from tampering with the information. After generating the above information, user U submits the ring signature, non-interactive zero-knowledge proof and unique identity identifier to the authentication system for verification by the authentication system administrator.

[0099] After receiving the information uploaded by user U, the authentication system administrator uses the ring signature verification formula to prove whether the ring signature is valid. If the verification passes, it proves that user U is a legitimate member of the set of legitimate users, otherwise it is considered illegal. Then, the authentication system administrator verifies whether the non-interactive zero-knowledge proof is valid. If the verification passes, it proves that the ring signature generated by user U is legitimate and that user U does have the private key paired with its public key, otherwise it is considered illegal.

[0100] If the ring signature and zero-knowledge proof verified by the authentication system administrator are all successful and the request is not repeated, the authentication system confirms the legitimacy of the user's identity and sends an authentication token or identity authorization within a certain period of time. If the verification fails, the authentication request is rejected. After receiving the authentication token or identity authorization, the legitimate user who has successfully verified the authentication will log in to the authentication system.

[0101] Figure 3 : is a flow chart of an optional anonymous authentication and anonymous login method according to an embodiment of the present invention. Figure 3 As shown, the method includes the following steps: system initialization, legitimate user registration, submission of anonymous authentication request, anonymous identity verification by the authentication system, authentication return, and user login. The following is an introduction based on the specific steps.

[0102] Step 1: System initialization.

[0103] The system model is shown in the figure Figure 2 As shown, the model diagram contains four entities: key generation system, authentication system, legal user set, and authentication system administrator, which are introduced one by one.

[0104] Key generation system: Generates public and private key pairs for users in the legal user set through SM2, and distributes the public and private key pairs to each user through the certified system administrator;

[0105] Authentication system administrator: Serves as a bridge between the key generation system, the set of legitimate users, and the authentication system. This administrator generates corresponding key pairs for the set of legitimate users in the key generation system. At the same time, he verifies the information sent by users whose identity privacy is protected, proves that the user is legitimate, and returns an authentication token to legitimate users, allowing them to log in to the authentication system.

[0106] Legal user set: a set of legal users who have successfully registered with the authentication system, but the users in the set want to log in to the authentication system without revealing their personal identities;

[0107] Authentication system: Similar to online service platforms, authentication system websites only allow registered users or members to enjoy related services and discounts.

[0108] During the initialization process, it is necessary to introduce that the bilinear map is a universal mathematical structure, usually expressed as: e:G1×G1→G2, where G1 and G2 are two multiplication cyclic groups. The bilinear map needs to satisfy the following three properties: a. Bilinearity: for any a, b∈Z q and R,S∈G1, both have e(R a ,S b )=e(R,S) ab; b. Non-degeneracy: there exist R, S∈G1 such that: e(R, S)≠1; c. Computability: there exists an efficient algorithm that can calculate the value of e(R, S) for any R, S∈G1.

[0109] The public and private key generation process of SM2 relies on the basic operations of elliptic curves and the mathematical model of key generation. It randomly selects two cyclic groups G1 and G2 with prime order q, as well as a bilinear mapping function e:G1×G1→G2, and selects a generator g∈G1.

[0110] Furthermore, private key generation: a large integer sk is randomly selected as the user's private key, where the value range of sk is: 1≤sk≤q. The private key is confidential and is generated by a random number generator in the key generation mechanism to ensure its randomness and unpredictability. At the same time, the private key is kept solely by the user; public key generation: the public key pk is calculated by multiplying the private key sk and the generator g, that is, pk = sk·g.

[0111] Step 2: Register as a legitimate user.

[0112] Assume that the service system has n legal users, represented as: {P1,P2,...,P n}, the authentication system registers all users in the legal user set, and generates a unique public and private key pair for each user in the legal user set through the key generation agency using the SM2 algorithm, namely: {(pk1,sk1),(pk2,sk2),...,(pk n ,sk n )}, where each public-private key pair corresponds to a user one-to-one.

[0113] After the authentication system administrator generates a public-private key pair for a user in the valid user set, they hand over the private key to the user in the valid user set for personal safekeeping and make the public key public. The authentication system then provides a challenge string M to all users in the valid user set within a fixed timeframe. Users use the challenge string to generate authentication information, anonymously proving the legitimacy of their identity.

[0114] Step 3: Submit an anonymous authentication request.

[0115] When a user wants to log in to the authentication system for identity authentication, he needs to use ring signatures and non-interactive zero-knowledge proof to confirm the legitimacy of his identity.

[0116] 1. Ring signature generation:

[0117] For n users in the legal user set: {P1,P2,...,P n}, assuming user P sis a member of the legal user set and wants to log in to the authentication system anonymously while ensuring the privacy of personal data, where s is the corresponding index in the legal user set and 1≤s≤n. User P s Choose a random number k, where k∈Z q , q is the order of the elliptic curve, and the random number k is calculated with the generator g to generate a s The middle value, that is: L s =k·g; then, user P s Use the SM3 hash algorithm to generate the intermediate value L s Perform hash calculation on the challenge string information M to generate the signature value, namely: c s =H(M||L s ).

[0118] Then, the legitimate user P s Generate the intermediate value L of other legitimate users i (i≠s), used to obfuscate the identity information of the signer, the legitimate user P s Generate random values one by one for all users in the legal user set except themselves, that is, {r1,r2,...,r s-1 ,r s+1 ,...,r n}, where r i ∈Z q (i≠s), and then generate the intermediate value for disguise by using the public key of other users, namely: L i =r i ·g+c i ·pk i , where c i is the challenge value of the previous user, i.e. c i+1 =H(M||L i ). Finally, for the legitimate user P s , calculate the disguised random number so that the entire ring signature can be completely closed, that is: r s =kc s ·sk s modq.

[0119] Finally, the generated ring signature is: σ=(c1,c2,...,c n ,r1,r2,...,r n ), where c1, c2, ..., c n is the challenge value of each user, r1,r2,...,r n is a random number for each user.

[0120] 2. Non-interactive zero-knowledge proof generation:

[0121] User P s After receiving the challenge string information M and generating a ring signature, in order to ensure the legitimacy of one's own identity and prevent malicious users from forging the ring signature, it is necessary to generate a zero-knowledge proof of the ring signature to prove that one can generate a legitimate ring signature without exposing any private information about oneself.

[0122] First, user P s By using your own private key sk s Generate a commitment to ensure that the private key is not leaked. The commitment is generated using the SM3 national secret hash algorithm, namely: C = H (sk s ), the commitment value is public and will not reveal the private key itself. Then, in order to ensure the non-interactive nature of zero-knowledge proof, the challenge value challenge needs to be obtained through the public challenge string information M, user P s The public key, ring signature, and commitment are generated by the SM3 national secret hash algorithm, namely: challenge = H(M,pk s ,σ,C).

[0123] User P s According to the challenge value challenge and its own private key sk s Generate a response that can prove that the user holds a legitimate private key through the encryption algorithm function f. The response generation formula is: response = f(sk s ,challenge), after generating the response, the user encapsulates the challenge value and the response value to form a zero-knowledge proof, that is: π s =(challenge,response).

[0124] 3. Submit authentication request: User P s Before sending the request, a unique identifier (current timestamp) Timestamp is generated. After the generation, the ring signature, zero-knowledge proof, and unique identifier are submitted to the authentication system together, namely: {σ,π s ,Timestamp}.

[0125] Step 4: Authentication system anonymous identity authentication.

[0126] After receiving the authentication system administrator s After the authentication request is sent, the ring signature verification is first performed, and each user P is calculated by the submitted challenge value and random number. i (i=1,2,...,n), that is: L i =r i ·g+c i ·pk i,Then, the authentication system administrator verifies whether the following conditions are met for each user in the legal user set: c i+1 =H(M||L i ), finally, verify whether c1 satisfies the loop closure condition, namely: c1=H(M||L n ), where L n is the median value of the last user.

[0127] If all the above conditions are met, the signature is proven to be valid and the legitimate user P s Without revealing personal information, the user is still identified as a legitimate user, and the ring signature is indeed from a member of the key ring.

[0128] Next, the certified system administrator performs a non-interactive zero-knowledge proof π s Verify to ensure that user P s Indeed, UFIDA private key sk s And it can legally generate a ring signature σ. The specific verification is as follows: the authentication system administrator uses the same public information (public challenge string information M, user P s public key, ring signature, commitment) to recalculate the challenge value, that is, challenge new =H((M,pk s ,σ,C); if the recalculated challenge value is consistent with the challenge value challenge submitted by the user, it means that the generation of the challenge value is correct.

[0129] The authentication system administrator uses the calculated challenge value challenge new and user P s The provided response value response is checked to see if the response conforms to the mathematical relationship of the predetermined encryption algorithm function, namely:

[0130] Verify(response,challenge new ,pk s ,σ)=True;

[0131] If the above equation holds, it is guaranteed that user P s Ring signatures can be generated legally without leaking the private key.

[0132] After verifying the above information, the authentication system administrator will record the unique identifier Timestamp sent by the requester and check whether the request has been processed. If it is found that the same identifier has been processed, the duplicate request will be rejected.

[0133] Step 5: Authentication return.

[0134] If the authentication system administrator authenticates user P s If the ring signature, zero-knowledge proof and unique identity identifier Timestamp are all verified, the authentication system will confirm the legitimacy of the user's identity and issue a P s Send a valid authentication token, ie: AuthenticationResult(P s )=Authorized;

[0135] If the authentication system administrator authenticates user P s If the request sent fails to be verified, the authentication request is rejected and the currently sent unique identifier Timestamp is marked as invalid in the database, that is: AuthenticationResult(P s )=Unauthorized.

[0136] Step 6: User login.

[0137] User P s After receiving the legal authentication token sent by the authentication system administrator, the user can apply to the authentication system administrator to log in to the authentication system through the authentication token without revealing any personal information. After verifying that the authentication token is correct, the authentication system administrator allows the user to log in. s Login successful.

[0138] The embodiments of the present invention have the following beneficial effects:

[0139] 1. To achieve the anonymity of the login user's identity, the ring signature algorithm is used to allow the user to prove that he or she is a member of the legitimate user group without revealing his or her specific identity. At the same time, the legitimacy of the user's identity is ensured by introducing a non-interactive zero-knowledge proof method, that is, proving that the user does indeed possess a specific private key and that the signature is legally generated. Through the above methods, the privacy of the user to be logged in, the legitimacy of the identity, and the security of the authentication are guaranteed.

[0140] 2. To prevent malicious users from forging ring signatures to bypass the authentication system and log in, a non-interactive zero-knowledge proof is used. This allows the authentication process to be completed without any interaction between the user and the authentication system, making the authentication process more efficient while avoiding possible privacy leaks during the interaction process.

[0141] 3. In the process of users sending requests, a unique request identifier is introduced, and the identifier is added to each authentication request to resist replay attacks. At the same time, after successful authentication, the unique identifier of the received authentication request will be recorded to ensure that each person's authentication credentials can only be used once. The unique identifier is associated with the user's current authentication request and marked as "authenticated" to prevent double-spending attacks.

[0142] 4. When using the ring signature algorithm, the SM2 and SM3 algorithms are used to perform symmetric encryption and hashing on the plaintext data used in the process, making it resistant to quantum attacks and effectively preventing the leakage of sensitive information. At the same time, it can effectively resist malicious tampering and improper theft by external attackers, ensuring the security and privacy of user data.

[0143] The present invention is described below in conjunction with another optional embodiment.

[0144] Example 2

[0145] An anonymous identity authentication device provided in this embodiment includes multiple implementation units, each implementation unit corresponding to each implementation step in the above-mentioned embodiment 1.

[0146] Figure 4 is a schematic diagram of an optional anonymous identity authentication device according to an embodiment of the present invention, such as Figure 4 As shown, the device may include: an acquisition unit 41, a generation unit 42, a submission unit 43, and a login unit 44.

[0147] The acquisition unit 41 is configured to acquire a public key set including N public keys of trusted users permitted by the authentication system, and extract a private key stored locally by a target anonymous user, where N is a positive integer greater than or equal to 2.

[0148] The generation unit 42 is configured to generate a ring signature based on the public key set and the private key, and to generate certification information based on the private key and the ring signature, wherein the ring signature is used to prove that the target anonymous user belongs to one of the N trusted users, and the certification information is used to prove that the ring signature is legitimate.

[0149] The submitting unit 43 is configured to encapsulate the ring signature, the proof information, and the timestamp identifier into an authentication request initiated by the target anonymous user, and submit the authentication request to the authentication system. The authentication system performs identity authentication based on the ring signature, the proof information, and the timestamp identifier to generate and return an authentication result.

[0150] The login unit 44 is configured to obtain an identity authentication token indicating that the authentication is successful in the authentication result, and log in to the authentication system based on the identity authentication token.

[0151] The above-mentioned anonymous identity authentication device can first obtain a public key set including N public keys of trusted users authorized by the authentication system through the acquisition unit 41, and extract the private key locally stored by the target anonymous user, where N is a positive integer greater than or equal to 2, and then generate a ring signature based on the public key set and the private key through the generation unit 42, and generate proof information based on the private key and the ring signature, wherein the ring signature is used to prove that the target anonymous user belongs to one of the N trusted users, and the proof information is used to prove that the ring signature is legal, and then encapsulate the ring signature, proof information and timestamp identifier into the authentication request initiated by the target anonymous user through the submission unit 43, and submit the authentication request to the authentication system, wherein the authentication system performs identity authentication based on the ring signature, proof information and timestamp identifier to generate and return an authentication result, and finally obtain an identity authentication token indicating that the authentication is successful in the authentication result through the login unit 44, and log in to the authentication system based on the identity authentication token.

[0152] In this embodiment of the present invention, an authentication mechanism that integrates ring signatures and non-interactive zero-knowledge proofs is adopted. Through cryptographic operations, efficient anonymous identity authentication is achieved without exposing the user's specific identity information. This achieves the technical effect of ensuring highly secure and reliable identity authentication while protecting user privacy.

[0153] Specifically, the target anonymous user first obtains a public key set containing multiple trusted user public keys authorized by the authentication system, and generates a ring signature based on the locally stored private key to prove that he or she is a member of the trusted user group, rather than directly exposing his or her specific identity. Then, based on the private key and the ring signature, proof information is generated to verify the legitimacy of the ring signature, ensuring that the signature is indeed generated by the private key held by the user, which can prove the authenticity and validity of the user's identity in an anonymous state; then a timestamp identifier is introduced to ensure the immediate uniqueness of each authentication request, which can prevent replay attacks. The ring signature, proof information and timestamp identifier are encapsulated into the authentication request and submitted to the authentication system by the target anonymous user. After receiving the request, the authentication system performs a comprehensive evaluation based on the above information to generate an authentication result; the identity authentication token issued after the final user successfully passes the authentication allows the user to log in to the authentication system without leaking any sensitive information, and enjoy secure and anonymous online services;

[0154] The embodiments of the present invention thoroughly improve the vulnerability of identity authentication in related technologies through the above-mentioned means, effectively avoid security attacks in the authentication process, reduce the risk of information leakage, and at the same time enhance the reliability of authentication, significantly improve the level of user privacy protection and the user experience of online services, thereby solving the technical problem that the identity authentication process in related technologies is prone to security attacks, resulting in information leakage and unreliable authentication, which leads to identity authentication failure.

[0155] The anonymous identity authentication device may further include a processor and a memory. The acquisition unit 41, generation unit 42, submission unit 43, login unit 44, etc. are all stored in the memory as program units, and the processor executes the program units stored in the memory to implement corresponding functions.

[0156] Optionally, the generation unit includes: a first acquisition module for acquiring challenge string information, wherein the challenge string information is a random challenge value generated by the authentication system based on a random timestamp within a current time period; a second acquisition module for acquiring, based on elliptic curve cryptography, a unique random number generated by a random number generator for a target anonymous user, and a set of random numbers generated for N-1 other trusted users other than the target anonymous user, wherein the random number set includes N-1 random numbers corresponding one-to-one to the other N-1 trusted users, and each random number conforms to a value range specified by a preset elliptic curve; a first calculation module for calculating a true intermediate value corresponding to the target anonymous user based on the unique random number, and constructing N-1 disguised intermediate values corresponding to the other N-1 trusted users based on the random number set and the public key set; a second calculation module for calculating N hash values based on the true intermediate value and the N-1 disguised intermediate values, and calculating a unique disguised random number corresponding to the target anonymous user based on the principle that the N hash values can form a closed hash chain; and an arrangement module for placing the unique disguised random number into the random number set, and arranging the new random number set and the closed hash chain according to a preset structure to obtain a ring signature.

[0157] Optionally, the generation unit also includes: a third calculation module, used to perform hash calculation on the private key to obtain an anonymous user commitment, wherein the anonymous user commitment is a public commitment value used to prove that the user holds the private key but does not disclose the private key value; a fourth calculation module, used to perform hash calculation on the challenge string information, the public key set, the ring signature and the anonymous user commitment to obtain a challenge value; an encryption module, used to encrypt the challenge value using the private key to obtain a response value; and an encapsulation module, used to encapsulate the challenge value and the response value to obtain proof information.

[0158] Optionally, the anonymous identity authentication device further includes a first authentication unit in the authentication system, which is used to perform the step of authenticating the ring signature after the authentication system receives the authentication request. The first authentication unit includes: a fifth calculation module, which is used to extract the ring signature in the authentication request and calculate N verification intermediate values based on the N random numbers and corresponding N hash values in the ring signature; a verification module, which is used to verify whether the N hash values can form a closed hash chain based on the N verification intermediate values and the challenge string information to obtain a verification result; and a first identification module, which is used to determine that the ring signature is authentic and that the target anonymous user is one of the trusted users when verifying that the hash chain is closed.

[0159] Optionally, the anonymous identity authentication device further includes a second authentication unit in the authentication system, which is used to perform a step of authenticating the proof information after the authentication system receives the authentication request. The second authentication unit includes: a sixth calculation module, which is used to use the challenge string information, the public key set, the closed hash chain and the public anonymous user commitment to perform hash calculation to obtain a verification challenge value; a second identification module, which is used to extract the proof information in the authentication request, and when the verification challenge value is consistent with the challenge value in the proof information, identify the challenge value submitted by the target anonymous user as true.

[0160] Optionally, the second authentication unit further includes: a verification module for performing a mathematical relationship verification on the challenge value and the response value in the proof information when the challenge value submitted by the target anonymous user is determined to be true, and obtaining a verification result; a third recognition module for determining that the proof information is reliable and that the ring signature is legal when the verification result indicates that the verification challenge value and the response value conform to a preset mathematical relationship.

[0161] Optionally, the anonymous identity authentication device further includes a third authentication unit in the authentication system, which is used to perform the step of authenticating the timestamp identifier after the authentication system receives the authentication request, and the third authentication unit includes: a query module, which is used to query the system identification library with the timestamp identifier as the query identifier to obtain the query result; a fourth identification module, which is used to determine that the timestamp authentication is passed when the query result indicates that the query identifier is not repeated with any historical identifier; a generation module, which is used to generate an identity authentication token of the target anonymous user when the ring signature, proof information and timestamp identifier are all authenticated, wherein the identity authentication token is used to log in to the authentication system; a rejection module, which is used to reject the authentication request of the target anonymous user and mark the timestamp identifier as invalid when any of the ring signature, proof information and timestamp identifier fails to be authenticated.

[0162] The processor includes a kernel that retrieves corresponding program units from memory. One or more kernels can be configured to encapsulate a ring signature, proof information, and a timestamp identifier into an authentication request initiated by a target anonymous user by adjusting kernel parameters. The authentication request is then submitted to an authentication system. The authentication system then performs identity authentication based on the ring signature, proof information, and timestamp identifier to generate and return an authentication result. The authentication system then obtains an authentication token indicating successful authentication from the authentication result and logs into the authentication system using the authentication token.

[0163] The above-mentioned memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0164] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing an initialization program having the following method steps: obtaining a public key set containing N public keys of trusted users authorized by the authentication system, and extracting a private key locally stored by a target anonymous user, wherein N is a positive integer greater than or equal to 2; generating a ring signature based on the public key set and the private key, and generating proof information based on the private key and the ring signature, wherein the ring signature is used to prove that the target anonymous user belongs to one of the N trusted users, and the proof information is used to prove that the ring signature is legal; encapsulating the ring signature, the proof information, and the timestamp identifier into an authentication request initiated by the target anonymous user, and submitting the authentication request to the authentication system, wherein the authentication system performs identity authentication based on the ring signature, the proof information, and the timestamp identifier to generate and return an authentication result; obtaining an identity authentication token indicating that the authentication is passed in the authentication result, and logging into the authentication system based on the identity authentication token.

[0165] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is further provided. The computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the anonymous identity authentication method of any one of the above-mentioned embodiments.

[0166] According to another aspect of an embodiment of the present invention, an electronic device is also provided, including one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors implement the anonymous identity authentication method of any one of the above-mentioned embodiments.

[0167] Figure 5 is a structural block diagram of an electronic device for executing an anonymous identity authentication method according to an embodiment of the present invention. Figure 5 As shown, the electronic device may include: one or more ( Figure 5 Only one is shown) processor 502, memory 504, storage controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module and display.

[0168] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the anonymous identity authentication method and device in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizing the above-mentioned anonymous identity authentication method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely located relative to the processor, and these remote memories can be connected to the terminal via a network. Examples of the above-mentioned network include but are not limited to the Internet, corporate intranet, local area network, mobile communication network and combinations thereof.

[0169] It can be understood by those skilled in the art that Figure 5 The structure shown is for illustration only, and the electronic device may also be a terminal device such as a smart phone, a tablet computer, a PDA, a mobile Internet device (MID), or a PAD. Figure 5 It does not limit the structure of the above electronic device. For example, the electronic device may also include Figure 5 More or fewer components (such as network interfaces, display devices, etc.) shown in, or with Figure 5 Different configurations shown.

[0170] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.

[0171] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0172] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0173] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0174] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0175] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc. Various media that can store program codes.

[0176] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. An anonymous identity authentication method, characterized in that: Clients for targeting anonymous users, including: Obtain a public key set containing N public keys of trusted users permitted by the authentication system, and extract the private key stored locally by the target anonymous user, where N is a positive integer greater than or equal to 2; Generate a ring signature based on the public key set and the private key, and generate certification information based on the private key and the ring signature, wherein the ring signature is used to prove that the target anonymous user belongs to one of N trusted users, and the certification information is used to prove that the ring signature is legitimate; Encapsulating the ring signature, the proof information, and the timestamp identifier into an authentication request initiated by the target anonymous user, and submitting the authentication request to an authentication system, wherein the authentication system performs identity authentication based on the ring signature, the proof information, and the timestamp identifier to generate and return an authentication result; Obtain an identity authentication token indicating that the authentication is successful in the authentication result, and log in to the authentication system based on the identity authentication token.

2. The anonymous identity authentication method according to claim 1, characterized in that: The step of generating a ring signature based on the public key set and the private key includes: Acquire challenge string information, wherein the challenge string information is a random challenge value generated by the authentication system according to a random timestamp within a current time period; Based on elliptic curve cryptography, obtain a unique random number generated by a random number generator for the target anonymous user, and a set of random numbers generated for N-1 other trusted users other than the target anonymous user, wherein the set of random numbers includes N-1 random numbers corresponding one-to-one to the other N-1 trusted users, and each of the random numbers conforms to a value range specified by a preset elliptic curve; Calculate the true intermediate value corresponding to the target anonymous user based on the unique random number, and construct N-1 disguised intermediate values corresponding to other N-1 trusted users based on the random number set and the public key set; Calculating N hash values based on the true intermediate value and N-1 disguised intermediate values, and calculating a unique disguised random number corresponding to the target anonymous user based on the principle that the N hash values can form a closed hash chain; The unique disguised random number is placed into the random number set, and the new random number set and the closed hash chain are arranged according to a preset structure to obtain the ring signature.

3. The anonymous identity authentication method according to claim 1, characterized in that: The step of generating certification information based on the private key and the ring signature includes: Performing a hash calculation on the private key to obtain an anonymous user commitment, wherein the anonymous user commitment is a public commitment value used to prove that the user holds the private key without revealing the private key value; Performing a hash calculation on the challenge string information, the public key set, the ring signature, and the anonymous user commitment to obtain a challenge value; Encrypt the challenge value using the private key to obtain a response value; The challenge value and the response value are encapsulated to obtain the certification information.

4. The anonymous identity authentication method according to claim 1, characterized in that: After receiving the authentication request, the authentication system performs the steps of authenticating the ring signature, including: Extracting the ring signature from the authentication request, and calculating N verification intermediate values based on N random numbers and corresponding N hash values in the ring signature; Verify whether the N hash values can form a closed hash chain based on the N verification intermediate values and the challenge string information, and obtain a verification result; When the hash chain is verified to be closed, the ring signature is deemed to be authentic, and the target anonymous user is deemed to be one of the trusted users.

5. The anonymous identity authentication method according to claim 4, characterized in that: After receiving the authentication request, the authentication system performs the following steps on the certification information: Performing a hash calculation using the challenge string information, the public key set, the closed hash chain, and the public anonymous user commitment to obtain a verification challenge value; The certification information in the authentication request is extracted, and when the verification challenge value is consistent with the challenge value in the certification information, the challenge value submitted by the target anonymous user is determined to be authentic.

6. The anonymous identity authentication method according to claim 5, characterized in that: After receiving the authentication request, the authentication system further performs the step of authenticating the certification information: When the challenge value submitted by the target anonymous user is determined to be true, performing a mathematical relationship verification on the verification challenge value and the response value in the certification information to obtain a verification result; If the verification result indicates that the verification challenge value and the response value conform to a preset mathematical relationship, the certification information is deemed reliable and the ring signature is deemed legal.

7. The anonymous identity authentication method according to claim 6, characterized in that: After receiving the authentication request, the authentication system performs the step of authenticating the timestamp identifier, including: Using the timestamp identifier as a query identifier to query a system identification library to obtain a query result; If the query result indicates that the query identifier is not repeated with any historical identifier, it is determined that the timestamp authentication is successful; If the ring signature, the certification information, and the timestamp identifier are all authenticated, generating an identity authentication token for the target anonymous user, wherein the identity authentication token is used to log in to the authentication system; If any one of the ring signature, the certification information, and the timestamp identifier fails authentication, the authentication request of the target anonymous user is rejected, and the timestamp identifier is marked as invalid.

8. An anonymous identity authentication device, characterized in that: The settings on the target anonymous user's client include: an acquisition unit, configured to acquire a public key set including N public keys of trusted users permitted by the authentication system, and extract a private key stored locally by a target anonymous user, where N is a positive integer greater than or equal to 2; a generating unit, configured to generate a ring signature based on the public key set and the private key, and generate certification information based on the private key and the ring signature, wherein the ring signature is used to prove that the target anonymous user belongs to one of N trusted users, and the certification information is used to prove that the ring signature is legitimate; a submitting unit, configured to encapsulate the ring signature, the proof information, and the timestamp identifier into an authentication request initiated by the target anonymous user, and submit the authentication request to an authentication system, wherein the authentication system performs identity authentication based on the ring signature, the proof information, and the timestamp identifier to generate and return an authentication result; The login unit is used to obtain the identity authentication token indicating that the authentication is successful in the authentication result, and log in to the authentication system based on the identity authentication token.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the anonymous identity authentication method according to any one of claims 1 to 7.

10. An electronic device, characterized in that: The method comprises one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the anonymous identity authentication method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • IOT identity authentication method based on non-interactive zero knowledge proof

    CN112636922A

  • Alliance chain cross-chain identity authentication method and system based on traceable ring signature

    CN117614634A

  • Hybrid encryption authentication method, device and equipment for resisting quantum computing

    CN119814279A

Cited By

  • Anonymous certificate registration method, anonymous authentication method and electronic equipment

    CN121530595A

  • Identity verification system and method, electronic equipment and readable storage medium

    CN121530753A

  • An identity verification system, method, electronic device and readable storage medium

    CN121530753B

  • Identity attribute authentication method and device and storage medium

    CN121792163A