Dynamic group time base one-time password method and system with optimized registration strategy
By optimizing the registration strategy and dynamic group time-based one-time password method, anonymity, traceability and lightweight authentication in dynamic groups are achieved, solving the problems of authentication efficiency and resource waste in the prior art, and is suitable for the Internet of Things and edge computing environments.
Patent Information
- Application Number
- CN202510816632.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-08-15
AI Technical Summary
The prior art cannot efficiently generate passwords and verifications in dynamic groups, cannot meet the ability to be interrupted, and cannot maintain the lightweight storage and computing burden of member-sides under dynamic changes. At the same time, it is impossible to avoid the central organization from knowing the actual usage time and purpose of passwords.
The optimized registration strategy is adopted, and the group public key is generated by the registration organization setting security parameters and private keys. The group members generate secret seeds and verification points, and a dynamic group time-based one-time password is generated by the verifier in combination with identity ciphertext and proof. The verifier verifies it without networking, achieving anonymity, traceability and offline verification.
It supports anonymity, traceability and offline verification in dynamic group authentication, reduces resource waste, is suitable for resource-constrained devices, and is suitable for environments such as the Internet of Things, smart terminals and edge computing.
Smart Images

Figure CN120498683A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computers, and in particular to a dynamic group time-based one-time password method and system with an optimized registration strategy. Background Art
[0002] With the rapid development of applications such as the Internet of Things, intelligent transportation, and federated learning, a large number of terminal devices or users in these systems require efficient and privacy-preserving group identity authentication. In this context, time-based one-time passwords (TOTP) have become a widely used authentication mechanism due to their low computational overhead and replay resistance. To meet this need for anonymous group authentication, group time-based one-time passwords (GTOTP) have emerged. By organizing and randomizing multiple users' TOTP instances, they enable authentication without revealing individual identities. They are applicable to scenarios such as anonymous information sharing in intelligent vehicle networks, device authorization collaboration in smart manufacturing, and privacy-preserving authentication in location-based services. In real-world applications, group structures often change dynamically, with devices or members frequently joining and leaving. However, existing authentication mechanisms are unable to achieve both efficient password generation and verification, uninterrupted authentication under dynamic group changes, and minimal storage and computational burden on member terminals. Furthermore, to further protect privacy, the system should prevent central authorities (such as registration authorities) from gaining knowledge of the actual usage time and purpose of passwords. Therefore, realizing a lightweight authentication solution that supports dynamic group management, has high anonymity and traceability has become a common expectation for security authentication systems in many fields. Summary of the Invention
[0003] In order to overcome the above-mentioned defects in the prior art, the object of the present invention is to provide a dynamic group time-based one-time password method and system with an optimized registration strategy.
[0004] To achieve the above-mentioned object of the present invention, the present invention provides a dynamic group time-based one-time password method with an optimized registration strategy, comprising the following steps:
[0005] The registration authority sets security parameters, the maximum number of members, the total number of verification phases, and generates its group public and private keys;
[0006] Group members randomly generate their private keys and use them to generate secret seeds for each verification stage. When registering, they generate a verification point based on the time-based one-time password corresponding to the verification stage to be registered, and send a registration application to the registration authority. The application information includes the group member identity information and the verification point.
[0007] For each registration application received during the verification phase, the registration authority generates the identity ciphertext of the group member applying for registration based on the application information sent by the group member applying for registration, updates the verification point, builds the OTS tree, updates the verification point signature, signs the tree root with SPHINCS+C, generates proof that the group member applying for registration wants to register for the verification phase, and returns it to the corresponding group member applying for registration;
[0008] The group member who applied for registration uses their secret seed and current time, combined with the identity ciphertext and certificate returned by the registration authority to generate a dynamic group time-based one-time password;
[0009] As the prover, the group member sends the generated dynamic group time-based one-time password and the password generation time to the verifier; the verifier updates the verification point, combines the group public key and the OTS public key, and verifies the updated verification point using the SPHINCS+C signature scheme, OTS tree, and proof. If all pass, the dynamic group time-based one-time password verification is successful.
[0010] In this method, group members can generate a dynamic group time-based one-time password containing anonymous identity ciphertext and proof, and the verifier can complete the authentication judgment without the need for an Internet connection, thus achieving the unification of anonymity, traceability, revocability and offline verification capability in dynamic group authentication.
[0011] Optionally, the registration authority's private key is used to generate the group member's identity ciphertext using the following formula:
[0012] in It represents the identity ciphertext of the j-th group member in the i-th verification phase. ASE.Enc() is an encryption algorithm for random authenticated symmetric encryption.
[0013] Optionally, the registration authority uses the identity ciphertext to bind the verification point of the corresponding group member to generate an updated verification point.
[0014] Optionally, the steps to generate the proof are:
[0015] Sign the root of the OTS tree with SPHINCS+C.Sign() to generate a SPHINCS+C certificate
[0016] Generate an OTS certificate by signing the updated verification point with OTS.Sign() using the selected leaf of the OTS tree And generate a Merkle proof that this leaf is in this OTS tree
[0017] Generated Proof
[0018] Optionally, the steps for group members to generate a dynamic group time-based one-time password are:
[0019] 1) The group member who applied for registration obtains the index of the current verification stage according to the current time;
[0020] 2) determining the secret seed for the current authentication phase according to the index of the current authentication phase, and generating a time-based one-time password based on the secret seed for the current authentication phase and the current time;
[0021] 3) Combine the time-based one-time password with the received identity ciphertext and certificate to form the final dynamic time-based one-time password.
[0022] Optionally, the verifier receives the dynamic group time-based one-time password and password generation time sent by the prover, checks whether the prover has been revoked by using the group management information, and if not, calculates and compares the group public key for verification, and returns the verification result.
[0023] Optional verification steps are:
[0024] The verifier uses the received dynamic group time base one-time password and the current time to calculate the verification point, combines the verification point with the received identity ciphertext to generate an updated verification point, and uses the one-time signed OTS.Verify(), OTS public key and OTS proof Verify updated verification points;
[0025] The verifier generates a tree root based on the published OTS public key and Merkle proof, and uses SPHINCS+C.Verify() signed by SPHINCS+C, SPHINCS+C public key and SPHINCS+C proof Verify this tree root;
[0026] If all the above verification conditions are met, the verification is considered successful.
[0027] Optionally, the registration authority updates the group management information regularly. After receiving the group member identity that needs to be revoked, the registration authority will no longer update the ciphertext of the group member identity to the group management information in the subsequent verification phase.
[0028] Optionally, when a third party requests to reveal the true identity of the generator of a password, the registration authority uses the registration authority private key to recover the identity from the identity ciphertext of the password.
[0029] The present application also proposes a system including: a registration agency, group members and a verifier. The registration agency, group members and verifier communicate with each other and generate and verify a group time-based one-time password according to the above-mentioned dynamic group time-based one-time password method with an optimized registration strategy.
[0030] The beneficial effects of the present invention are:
[0031] The present invention supports anonymous authentication of group members without revealing their identities in scenarios where the verifier is not connected to the Internet; the registration agency can process user registration in a timely manner and complete the registration without affecting the status of registered users and the group public key; it supports dynamic joining and leaving of users, and the overhead of user revocation is very small and almost negligible. At the same time, the present invention can also effectively reduce the resource waste problem caused by the waste of mounting points in existing solutions, while also achieving the security attributes of anonymity and traceability, and can still ensure security under the dynamic group model. In addition, since the present invention has a low computational overhead, it has a lightweight feature and is suitable for resource-constrained devices, especially for application environments such as the Internet of Things, smart terminals, and edge computing that have high requirements for resource constraints and authentication flexibility.
[0032] Compared to the existing DGTOTP mechanism, the present invention effectively avoids redundant mounting, reduces mount point waste, supports offline verification processes, maintains both anonymity and traceability, and is suitable for authentication systems in ubiquitous computing environments that have high requirements for security, privacy, and computing resources. Additional aspects and advantages of the present invention will be provided in part in the following description and will become apparent from the following description or learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments with reference to the accompanying drawings, in which:
[0034] Figure 1 It is a schematic flow diagram of the present invention;
[0035] Figure 2-5 This is a comparison chart of the waste rate of Example 1 and the DGTOTP solution under different numbers of new registrations, where CYN+ represents the existing DGTOTP solution, LW represents Example 1, and l=2, l=3, l=4, and l=5 represent the settings of L values in Example 1. Figures 2 to 5 The expected values β of the number of new registrations each month are 5, 10, 15, and 20 respectively. DETAILED DESCRIPTION
[0036] The following describes embodiments of the present invention in detail. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended only to explain the present invention and are not to be construed as limiting the present invention.
[0037] In the description of the present invention, unless otherwise specified and limited, it should be noted that the terms "installed", "connected" and "connected" should be understood in a broad sense. For example, it can be a mechanical connection or an electrical connection, or it can be the internal communication between two components. It can be a direct connection or an indirect connection through an intermediate medium. For ordinary technicians in this field, the specific meanings of the above terms can be understood according to the specific circumstances.
[0038] Example 1
[0039] like Figure 1 As shown, the present invention provides a dynamic group time-based one-time password method with an optimized registration strategy. The method includes seven steps: initialization of the authentication system, user initialization, user registration, password generation, password verification, user revocation, and user identity tracing. When a user joins a group, they become a group member.
[0040] Before introducing this embodiment in detail, the following description is given:
[0041] In this embodiment, [n] = {1, ..., n} is used to represent all positive integers between 1 and n. Assume that X is a set, It means randomly selecting an element x from the set X.
[0042] The protocol of the present invention uses the SPHINCS+C and OTS (specifically using the WOTS+C signature in SPHINCS+C) signature scheme (KeyGen, Sign, Verify), which are specifically defined as follows:
[0043] 1)(sk,pk)∈ R KeyGen(1 κ ): Key generation algorithm, which inputs a security parameter 1 κ , output the private key sk and the corresponding public key pk.
[0044] 2)sig∈ R Sign(sk, m): encryption algorithm, input private key sk and message m, output signature sig.
[0045] 3) {0, 1}←Verify(pk, sig): decryption algorithm, input public key pk and signature σ, output {0, 1}.
[0046] The specific steps are as follows:
[0047] Step 1, system initialization: The registration authority sets the security parameter k, sets the system time start and end time, the password generation interval, the maximum number of group members U, and presets E verification stages. k, U, and E are all positive integers. The registration authority generates a random private key k RA, and use the existing SPHINCS+C signature scheme, call (sk SPHINCS+C , pk SPHINCS+C )∈ R SPHINCS+C.KeyGen(1 κ )Generate a SPHINCS+C public key (as a group public key) and a private key.
[0048] User initialization: Group members randomly generate private keys and use them to generate secret seeds for each verification phase. This embodiment generates them in the following way:
[0049] in is the secret seed of the j-th group member in the i-th verification phase, i is the verification phase index, i∈[1,E], F(·) is a pseudo-random function, || represents the connection symbol, Indicates the ID of the jth group member j The private key.
[0050] In step 2, when a group member registers, they generate a verification point for the time-based one-time password corresponding to the verification phase they wish to register for and submit a registration application to the registration authority. The application includes the group member's identity information and the verification point. During each verification phase, a group member generates a batch of time-based one-time passwords and a verification point for each time-based one-time password. The verification point is used to verify these passwords. This embodiment generates verification points for each verification phase in the following manner: It is the verification point of the j-th group member in the i-th verification phase. TOTP.MInit() represents the initialization function of the TOTP protocol.
[0051] Step 3: For each registration received during the verification phase, the registration authority generates the identity ciphertext of the group member applying for registration based on the group member identity information and verification point sent by the group member applying for registration, updates the verification point, builds an OTS tree, updates the verification point signature, signs the tree root with SPHINCS+C, generates proof that the group member applying for registration wants to register for the verification phase, and returns it to the corresponding group member applying for registration.
[0052] The specific steps are as follows:
[0053] 1) Use the registration authority's private key to generate the identity ciphertext of the group member applying for registration: in It represents the identity ciphertext of the j-th group member in the i-th verification phase. ASE.Enc() is an encryption algorithm for random authenticated symmetric encryption.
[0054] 2) Use the identity ciphertext to bind the corresponding group member verification point to generate the updated verification point: is the updated verification point of the jth group member in the i-th verification phase, H is the collision-resistant hash function, is the verification point of the j-th group member in the i-th verification phase.
[0055] 3) Build an OTS tree, sign the updated verification point, and use SPHINCS+C to sign the root of the tree to generate proof that group members need to register for the verification phase. The specific steps are:
[0056] One-time signature (OTS) is used. Its specific implementation uses WOTS+C in SPHINCS+C. Since each group member has a registration order, the registration agency will assign an identifier to it, map the group members to {1,…,U} and shuffle them, and divide each L group into a group. The L OTS instances generated are determined according to the divided groups, and then the OTS public key is determined to be signed according to the position in the group to which the user is mapped; call L times (sk OTS , pk OTS )∈ R OTS.KeyGen() generates L OTS public key and private key pairs, uses these L OTS public keys to build an OTS tree, and signs its root with SPHINCS+C.Sign() and the SPHINCS+C private key to generate a SPHINCS+C certificate Use the leaf of the selected OTS tree (since the group members are grouped for every L, the selected here means that the group members divided into the same group will use the same OTS-tree) to sign the updated verification point using OTS.Sign() and the OTS private key to generate an OTS certificate Generate a Merkle proof that this leaf is in this OTS tree
[0057] Finally it will be proved Combination and identity ciphertext Returned to the group member who applied for registration for use in the i-th verification phase.
[0058] Step 4, password generation: When the E verification phases are running, the group member who applied for registration uses their secret seed and current time, combined with the identity ciphertext and proof returned by the registration authority to generate a dynamic group time-based one-time password. The specific steps are as follows:
[0059] 1) Group members who apply for registration obtain the index of the current verification stage based on the current time Among them, T current Refers to the current time, T s is the start time of E verification phases, Δ υp Is the duration of a verification phase, Is the ceiling symbol.
[0060] 2) Determine the secret seed for the current verification phase based on the index of the current verification phase, and generate a time-based one-time password based on the secret seed for the current verification phase and the current time:
[0061] in, is the time-based one-time password of the j-th group member in the i-th verification phase, is the secret seed of the j-th group member in the i-th verification phase. TOTP.PGen() is the function of the TOTP protocol to generate a time-based one-time password. z represents the number of the time-based one-time password in the current verification phase, and z is a positive integer.
[0062] 3) Combine the time-based one-time password with the received identity ciphertext and proof to form the final dynamic time-based one-time password: is the identity ciphertext of the j-th group member in the i-th stage.
[0063] In step 5, the group member, acting as the prover, sends the generated dynamic group time-based one-time password and the password generation time to the verifier. After receiving the dynamic group time-based one-time password and password generation time from the prover, the verifier uses the group management information to check whether the prover has been revoked. If not, it verifies the received password and returns the verification result. The verification process is as follows:
[0064] 1) The verifier uses the received dynamic group time-based one-time password and the current time to calculate the verification point, and combines the verification point with the received identity ciphertext to generate an updated verification point And use the one-time signed OTS.Verify(), OTS public key and OTS proof Verify updated verification points;
[0065] 2) Generate the root of the tree based on the published OTS public key and Merkle proof, and use SPHINCS+C.Verify(), SPHINCS+C public key and SPHINCS+C proof signed by SPHINCS+C Verify the root.
[0066] The verification result is returned by Verify, and a return of 1 indicates a pass. If all the above verification conditions are met, the verification is considered passed.
[0067] In this embodiment, the registration agency will require group members to register all verification points within a period of time (multiple verification stages, such as one month or one year, etc.) at one time, and update the group management information at regular intervals to achieve verification without the verifier being online. This is because the group management information can be manually updated offline for the verifier at regular intervals. After the registration agency receives the group member identity that needs to be revoked, it will no longer update the group member identity ciphertext to the group management information in the subsequent verification stages. When a third party (such as a judicial or regulatory agency) requests to reveal the true identity of the generator of a password, the registration agency uses the registration agency's private key to restore the identity from the password's identity ciphertext. The key step is ASE.Dec() refers to the decryption algorithm of random authenticated symmetric encryption, k RA Is the registration authority private key.
[0068] Performance Analysis
[0069] Due to the low storage and computational overhead of the protocol and hash calculation involved in this embodiment, it is lightweight and suitable for resource-constrained devices. The following comparison with the DGTOTP solution will more vividly demonstrate the performance advantages of the present invention.
[0070] Since the maximum number of users U, the total number of verification stages E, the size of a single OTS tree L, and the actual number of registered people will affect the waste rate of the present invention, the actual number of registered people is modeled as a Poisson distribution. Figure 2-Figure 5 As shown, it shows the comparison of the waste rate of this embodiment with the existing DGTOTP solution under different L values when the maximum number of users is 500, α users have registered initially, and the number of new registrations each month follows a Poisson distribution with an expectation of β.
[0071] As can be seen, the smaller the value of L, the lower the waste rate in this embodiment compared to the existing solution. In a real-world scenario (with 209 initial registrations, an average of 20 monthly registrations, and L = 2), the waste rate decreased by 10.2% compared to the existing solution, demonstrating a significant effect in reducing the waste rate.
[0072] Example 2
[0073] The present invention also provides an embodiment of a system, which includes: a registration agency, group members and a verifier. The registration agency, group members and verifier communicate with each other and generate and verify a group time-based one-time password according to the dynamic group time-based one-time password method with an optimized registration strategy described in Example 1.
[0074] Throughout this specification, reference to terms such as "one embodiment," "some embodiments," "examples," "specific examples," or "some examples" means that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.
[0075] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to the embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the claims and their equivalents.
Claims
1. A dynamic group time-based one-time password method with an optimized registration strategy, characterized in that: The following steps are involved: The registration authority sets security parameters, the maximum number of members, the total number of verification phases, and generates its group public and private keys; Group members randomly generate their private keys and use them to generate secret seeds for each verification stage. When registering, they generate a verification point based on the time-based one-time password corresponding to the verification stage to be registered, and send a registration application to the registration authority. The application information includes the group member identity information and the verification point. For each registration application received during the verification phase, the registration authority generates the identity ciphertext of the group member applying for registration based on the application information sent by the group member applying for registration, updates the verification point, builds the OTS tree, updates the verification point signature, signs the tree root with SPHINCS+C, generates proof that the group member applying for registration wants to register for the verification phase, and returns it to the corresponding group member applying for registration; The group member who applied for registration uses their secret seed and current time, combined with the identity ciphertext and certificate returned by the registration authority to generate a dynamic group time-based one-time password; As the prover, the group member sends the generated dynamic group time-based one-time password and the password generation time to the verifier; the verifier updates the verification point, combines the group public key and the OTS public key, and verifies the updated verification point using the SPHINCS+C signature scheme, OTS tree, and proof. If all pass, the dynamic group time-based one-time password verification is successful.
2. The dynamic group time-based one-time password method with optimized registration strategy according to claim 1, characterized in that: The private key of the registration authority is used to generate the identity ciphertext of the group members using the following formula: in It represents the identity ciphertext of the j-th group member in the i-th verification phase. ASE.Enc() is an encryption algorithm for random authenticated symmetric encryption.
3. The dynamic group time-based one-time password method with optimized registration strategy according to claim 1, characterized in that: The registration authority uses the identity ciphertext to bind the verification point of the corresponding group member to generate an updated verification point.
4. The dynamic group time-based one-time password method with optimized registration strategy according to claim 1, characterized in that: The steps to generate the proof are: Sign the root of the OTS tree with SPHINCS+C.Sign() to generate a SPHINCS+C certificate Generate an OTS certificate by signing the updated verification point with OTS.Sign() using the selected leaf of the OTS tree And generate a Merkle proof that this leaf is in this OTS tree Generated Proof 5. The dynamic group time-based one-time password method with optimized registration strategy according to claim 1, characterized in that: The steps for group members to generate a dynamic group time-based one-time password are: 1) The group member who applied for registration obtains the index of the current verification stage according to the current time; 2) determining the secret seed for the current authentication phase according to the index of the current authentication phase, and generating a time-based one-time password based on the secret seed for the current authentication phase and the current time; 3) Combine the time-based one-time password with the received identity ciphertext and certificate to form the final dynamic time-based one-time password.
6. The dynamic group time-based one-time password method with optimized registration strategy according to claim 1, characterized in that: The verifier receives the dynamic group time-based one-time password and password generation time sent by the prover, checks whether the prover has been revoked by using the group management information, and if not, calculates and compares the group public key for verification, and returns the verification result.
7. The dynamic group time-based one-time password method with optimized registration strategy according to claim 4, characterized in that: The verification steps are: The verifier uses the received dynamic group time base one-time password and the current time to calculate the verification point, combines the verification point with the received identity ciphertext to generate an updated verification point, and uses the one-time signed OTS.Verify(), OTS public key and OTS proof Verify updated verification points; The verifier generates a tree root based on the published OTS public key and Merkle proof, and uses SPHINCS+C.Verify() signed by SPHINCS+C, SPHINCS+C public key and SPHINCS+C proof Verify this tree root; If all the above verification conditions are met, the verification is considered successful.
8. The dynamic group time-based one-time password method with optimized registration strategy according to claim 1, characterized in that: The registration authority updates the group management information regularly. After receiving the group member identity that needs to be revoked, the registration authority will no longer update the ciphertext of this group member identity to the group management information in the subsequent verification stage.
9. The dynamic group time-based one-time password method with optimized registration strategy according to claim 1, characterized in that: When a third party requests to reveal the true identity of the generator of a password, the registration authority uses the registration authority private key to recover the identity from the password's identity ciphertext.
10. A system, characterized in that: include: A registration authority, group members and verifier communicate with each other and generate and verify a group time-based one-time password according to the dynamic group time-based one-time password method with optimized registration strategy according to any one of claims 1 to 10.