Network security password verification method and system
By generating an anonymous identifier that can be aggregated and linked through an anonymous signature verification method and performing zero-knowledge proof, the problem of identity traceability relying on a centralized administrator in the existing group signature scheme in a decentralized environment is solved, and user privacy protection and efficient identity management are achieved in a quantum computing environment.
Patent Information
- Application Number
- CN202511570862.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-30
- Publication Date
- 2026-02-17
AI Technical Summary
Existing group signature schemes suffer from the problem of relying on centralized administrators for identity tracing in decentralized environments, are unable to resist quantum computing attacks, and cannot effectively protect user privacy or achieve efficient identity management.
An anonymous signature verification method is adopted. By obtaining the revocation list, determining the secret revocation certificate and personal key pair, quantum attack resistant processing is performed to generate an anonymous identifier that can be aggregated and linked. Zero-knowledge proof is then performed to achieve the concealment and revocation detection of group signatures.
In the context of resisting quantum computing attacks, it achieves group signature verification that protects user privacy, effectively identifies and revokes unauthorized signatures, and ensures the legality and security of signatures.
Smart Images

Figure CN121547181A_ABST
Abstract
Description
Technical Field
[0001] This application relates to password verification, and more specifically, to a network security password verification method and system. Background Technology
[0002] Cryptographic verification for cybersecurity is a core technology for ensuring the trustworthiness of digital identities and data privacy, and is widely used in scenarios such as identity authentication, electronic signatures, and blockchain transactions. With the increasing complexity of network environments and the development of quantum computing technology, traditional cryptographic verification mechanisms face severe challenges in terms of security, privacy protection, and scalability. There is an urgent need to build a new cryptographic verification system that can resist quantum attacks while achieving efficient identity management and condition traceability.
[0003] Existing group signature schemes, while an important implementation of cryptographic verification, have significant shortcomings in decentralized environments. Most schemes rely on centralized group administrators for identity verification, violating the decentralized principle. Traditional revocation mechanisms require unrevoked users to update their keys, resulting in high communication and computational overhead. Complete anonymity allows malicious users to sign different messages for the same event without being traceable, while honest users lack effective means of self-verification. Furthermore, existing schemes are generally based on traditional number theory problems such as large integer factorization, making them vulnerable to quantum computing attacks. Therefore, how to achieve group signature verification that protects user privacy while resisting quantum computing attacks has become a major challenge for the industry. Summary of the Invention
[0004] This application provides a network security password verification method and system that can achieve group signature verification that protects user privacy while resisting quantum computing attacks.
[0005] Firstly, this application provides an anonymous signature verification method for use in a network security password verification system to verify anonymous signatures. The method includes the following steps: Retrieve the revocation list when obtaining group member signatures; Determine the secret revocation credential used by each group member when anonymously signing and the personal key pair used when authorizing identity; In response to multiple signature requests from any group of members for multiple event topics, each event topic and the personal key pair are subjected to quantum-resistant processing to obtain an aggregateable, linked anonymous identifier used for identity authorization when the group members sign. The secret revocation credential is quantum-resistant encrypted, and the legality of the anonymous identifier and encryption process is proven based on the encryption form, thereby obtaining a group signature that conceals the identity of the group members. The group signature is revoked based on the anonymous identifier and the revocation list, and the signer identity of the anonymous identifier corresponding to different signed messages under the same event topic is revoked based on the revocation detection result.
[0006] In some embodiments, determining the secret revocation credential for anonymous signing and the personal key pair for identity authorization for each group member specifically includes: Obtain the interactive protocol between group members and group administrators; The personal key pair of each group member is determined during the group registration process through a key generation process resistant to quantum computing attacks; The identity authentication and registration of each group member are completed according to the aforementioned interactive protocol; Based on the results of identity authentication and registration, a secret revocation credential is generated for each group member when anonymous signatures are displayed.
[0007] In some embodiments, in response to multiple signature requests from any group of members for multiple event topics, each event topic and the personal key pair are subjected to quantum-resistant processing to obtain an aggregateable, linked anonymous identifier used for identity authorization when the group members sign. Specifically, this includes: Retrieve multiple signature requests from any group of members on multiple event topics, and select one signature request as the selected signature request; The specific event topic targeted by the selected signature request is confirmed to obtain the target topic to be signed. Quantum-resistant verification is performed based on the target topic corresponding to the selected signature request and the personal key of the group member to obtain the event identifier of the group member under the event topic; Continue to determine the event identifiers of the group members under the remaining event topics; By autonomously linking all event identifiers, an anonymous identifier that can be aggregated and linked when signing the group members is obtained.
[0008] In some embodiments, quantum-resistant encryption of the secret revocation credential specifically includes: Obtain the group administrator's public key that is resistant to quantum attacks; The secret revocation credential is quantum-resistantly encrypted using the public key to obtain the encrypted form and ciphertext of the secret revocation credential.
[0009] In some embodiments, performing zero-knowledge proofs on the legality of the anonymous identifier and the encryption process based on the encryption method to obtain a group signature that conceals the identity of the group members specifically includes: The group member's proof statement is determined based on the anonymous identifier, the legality of the encryption process, and the validity of the group member's identity; A non-interactive zero-knowledge proof resistant to quantum computing attacks is provided for the proof statement; The group signature that conceals the identities of the group members is determined based on the zero-knowledge proof, the ciphertext of the secret revocation credential, and the anonymous identifier.
[0010] In some embodiments, performing revocation detection on the group signature based on the anonymous identifier and the revocation list specifically includes: The validity of the group signature is verified; The anonymous identifier and the revocation list are compared in relation to each other to obtain preliminary detection results; The detection result is revoked based on the preliminary detection results and the results of the legality verification.
[0011] In some embodiments, revoking the signer identity of the anonymous identifier for different signed messages under the same event topic based on the revocation detection result specifically includes: Perform message consistency checks on any two valid group signatures that have the same anonymous identifier and event subject; If the message consistency check results in different messages, the condition revocation mechanism is triggered; In response to the triggering of the conditional revocation mechanism, a quantum-resistant cryptographic operation is performed on the ciphertext in the two group signatures to recover the secret revocation credential of the violator. The revocation list is updated based on the recovered secret revocation certificate, thus completing the revocation of the signer's identity.
[0012] Secondly, this application provides a network security password verification system, which includes an anonymous signature verification unit, the anonymous signature verification unit comprising: The retrieval module is used to retrieve the revocation list when group members sign in. The processing module is used to determine the secret revocation credential for anonymous signing by each group member and the personal key pair for identity authorization. The processing module is also configured to respond to multiple signature requests from any group of members for multiple event topics, perform quantum attack-resistant processing on each event topic and the personal key pair respectively, and thereby obtain an aggregateable linked anonymous identifier used for identity authorization when the group members sign; The processing module is also used to perform quantum-resistant encryption on the secret revocation certificate, and to perform zero-knowledge proof on the legality of the anonymous identifier and the encryption process based on the encryption form, thereby obtaining a group signature that conceals the identity of the group members. The execution module is used to perform revocation detection on the group signature based on the anonymous identifier and the revocation list, and thereby revoke the signer identity of the anonymous identifier when corresponding to different signed messages under the same event topic based on the revocation detection result.
[0013] Thirdly, this application provides a computer device, the computer device including a memory and a processor, the memory storing code, and the processor being configured to acquire the code and execute the above-described anonymous signature verification method.
[0014] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned anonymous signature verification method.
[0015] The technical solutions provided by the embodiments disclosed in this application have the following beneficial effects: The network security password verification method and system provided in this application first obtains a revocation list of group members' signatures; determines the secret revocation credential and personal key pair for identity authorization when each group member anonymously signs; responds to multiple signature requests from any group member for multiple event topics, performs quantum-resistant processing on each event topic and the personal key pair respectively, thereby obtaining an aggregateable linked anonymous identifier used for identity authorization when the group member signs; performs quantum-resistant encryption on the secret revocation credential, and performs zero-knowledge proof on the legality of the anonymous identifier and the encryption process based on the encryption form, thereby obtaining a group signature that conceals the identity of the group member; performs revocation detection on the group signature according to the anonymous identifier and the revocation list, thereby revoking the signer identity of the anonymous identifier when corresponding to different signature messages under the same event topic based on the revocation detection result.
[0016] Therefore, in the anonymous signature verification method of this application, firstly, a revocation list of group members' signatures is obtained; then, the secret revocation credential and personal key pair for identity authorization of each group member's anonymous signature are determined; in response to multiple signature requests from any group member for multiple event topics, each event topic and the personal key pair are subjected to quantum attack-resistant processing, thereby obtaining an aggregateable linked anonymous identifier used for identity authorization when the group member signs. The anonymous identifier is a unique identifier associated with the group member's signature, represented by a Merkle root hash value, used to enable the signature to hide the signer's identity while still allowing the verifier to confirm its association with a specific event topic, and to verify... The system first verifies the validity of the signature; secondly, it applies quantum-resistant encryption to the secret revocation credential and performs zero-knowledge proof on the legality of the anonymous identifier and encryption process based on the encryption form, thereby obtaining a group signature that conceals the identity of the group members; it then performs revocation detection on the group signature based on the anonymous identifier and the revocation list, thereby revoking the signer's identity for different signed messages under the same event topic based on the revocation detection result. Here, a group signature is a cryptographic primitive that allows any member of a group to digitally sign a message on behalf of the entire group, providing authentication while protecting the signer's privacy, facilitating subsequent verification and revocation of the signer's identity. This scheme can achieve group signature verification that protects user privacy while resisting quantum computing attacks. Attached Figure Description
[0017] Figure 1 This is an exemplary flowchart of an anonymous signature verification method according to some embodiments of this application; Figure 2 This is an engineering schematic diagram illustrating a response to multiple signature requests for multiple event topics by any group of members, according to some embodiments of this application. Figure 3 This is an exemplary flowchart illustrating the determination of a group signature according to some embodiments of this application; Figure 4 This is a schematic diagram of the structure of an anonymous signature verification unit according to some embodiments of this application; Figure 5 This is a schematic diagram of the structure of a computer device implementing an anonymous signature verification method according to some embodiments of this application. Detailed Implementation
[0018] To better understand the above technical solutions, the following will provide a detailed explanation of the technical solutions in conjunction with the accompanying drawings and specific implementation methods.
[0019] refer to Figure 1The figure is an exemplary flowchart of an anonymous signature verification method according to some embodiments of this application. The anonymous signature verification method mainly includes the following steps: In step 101, the revocation list of group members' signatures is obtained.
[0020] In specific implementation, obtaining the revocation list when obtaining group member signatures can be achieved in the following way: obtain the revocation list when obtaining group member signatures from the anonymous signature verification system, and separately initialize a user registration list for recording group member information; wherein, the revocation list is initially empty, and will be a public, dynamically growing list during the operation of the anonymous signature verification system, changing dynamically as the system runs, used to store the credentials of the revoked group members, thereby realizing the local revocation function of the verifier; other methods can also be used in other embodiments, which are not limited here.
[0021] It should be noted that the aforementioned anonymous signature verification system can simultaneously prepare for the qualification verification of group members during the initialization of the revocation list. Specifically, the anonymous signature verification system first executes an initialization algorithm to generate the system's public parameters. At the same time, it initializes a Merkle tree accumulator based on a collision-resistant hash function on a lattice. This accumulator is used as the membership authentication structure to verify the identity of group members, thereby calculating the initial accumulation value of the Merkle tree accumulator as part of the public parameters. The aforementioned public parameters include at least the dimension, modulus, and Gaussian distribution parameters of the lattice. These parameters are used to provide a unified mathematical domain, security foundation, and algorithm input for quantum-resistant cryptographic operations during subsequent group member registration, anonymous signature generation, and verification processes. Secondly, the anonymous signature verification system initializes the interactive protocol between group members and group administrators.
[0022] In step 102, the secret revocation credential for anonymous signing by each group member and the personal key pair for identity authorization are determined.
[0023] In some embodiments, determining the secret revocation credential for anonymous signing and the personal key pair for identity authorization for each group member can be achieved through the following steps: Obtain the interactive protocol between group members and group administrators; The personal key pair of each group member is determined during the group registration process through a key generation process resistant to quantum computing attacks; The identity authentication and registration of each group member are completed according to the aforementioned interactive protocol; Based on the results of identity authentication and registration, a secret revocation credential is generated for each group member when anonymous signatures are displayed.
[0024] In specific implementation, determining the personal key pair of each group member during group registration through a quantum-resistant key generation process can be achieved in the following way: A quantum-resistant key generation algorithm is used to generate a personal key pair for each group member during group registration. For example, a lattice trapdoor generation algorithm can be used, with common parameters as input parameters. The algorithm then outputs the personal key pair of each group member. Each personal key pair includes a public key matrix and a short private key base. The public key matrix serves as the public key in the group member's personal key pair, while the short base serves as the private key. Other methods can also be used in other embodiments, which are not limited here.
[0025] In specific implementation, the authentication and registration of each group member according to the interactive protocol can be achieved in the following way: the user submits their public key to the group administrator, and the group administrator verifies the legitimacy of the group member's user identity through the interactive protocol and the public key. After the verification is successful, the group administrator assigns a unique identity identifier to each group member. Other methods can also be used in other embodiments, which are not limited here.
[0026] In specific implementation, the secret revocation credential generated for anonymous signatures of each group member based on the results of identity authentication and registration can be implemented in the following way: The group member's public key, Gaussian parameters, and the group member's identity identifier (derived as a target vector) are used as inputs to the lattice preimage sampling algorithm. The group administrator then runs the lattice preimage sampling algorithm to obtain a short vector, which serves as the secret revocation credential uniquely bound to the group member's identity identifier. Next, the group administrator updates the Merkle tree accumulator, calculates the cryptographic commitment value of each group member using a collision-resistant hash function on the public key and the secret revocation credential, adds the group member's public key to the accumulator, and records the commitment value in the user registration list, completing the registration update. Other methods can also be used in other embodiments, which are not limited here.
[0027] It should be noted that the secret revocation credential in this application is a revocation credential generated by the group administrator for each group member and uniquely bound to their identity. It is used to control the anonymity of the group member when revoking a signature. It can identify and reject the signature of the revoked member locally in real time and efficiently, which facilitates the subsequent verification and conditional revocation of the group member's signature.
[0028] In step 103, in response to multiple signature requests from any group of members for multiple event topics, each event topic and the personal key pair are subjected to quantum attack-resistant processing to obtain an aggregateable linked anonymous identifier used for identity authorization when the group members sign.
[0029] In some embodiments, in response to multiple signature requests from any group of members for multiple event topics, each event topic and the personal key pair are subjected to quantum-resistant processing to obtain an aggregateable, linked anonymous identifier used for identity authorization when the group members sign. This can be achieved through the following steps: Retrieve multiple signature requests from any group of members on multiple event topics, and select one signature request as the selected signature request; The specific event topic targeted by the selected signature request is confirmed to obtain the target topic to be signed. Quantum-resistant verification is performed based on the target topic corresponding to the selected signature request and the personal key of the group member to obtain the event identifier of the group member under the event topic; Continue to determine the event identifiers of the group members under the remaining event topics; By autonomously linking all event identifiers, an anonymous identifier that can be aggregated and linked when signing the group members is obtained.
[0030] In practice, confirming the specific event topic targeted by the selected signature request to obtain the current target topic to be signed can be achieved in the following way: (Refer to...) Figure 2 As shown in the figure, this is an engineering schematic diagram illustrating how the system responds to multiple signature requests for multiple event topics from any group of members in some embodiments of this application. The system can receive multiple signature requests for different event topics initiated by any group of members through a concurrent signature request queue, thereby parsing the metadata of the selected signature request, extracting the event subject field, and calculating a fixed-length topic digest for the topic field. This topic digest is then used as the target topic of the selected signature request. The topic field can be calculated using a collision-resistant hash function. Other methods can also be used in other embodiments, which are not limited here.
[0031] In specific implementation, quantum-resistant verification is performed based on the target topic corresponding to the selected signature request and the personal key of the group member to obtain the event identifier of the group member under the event topic. This can be achieved in the following way: the private key of the target topic corresponding to the selected signature request and the personal key of the group member are used as input, and then a quantum-resistant cryptographic algorithm is used to perform the operation and output a short vector as the anonymous event identifier of the target topic corresponding to the selected signature request. Here, one event of a group member corresponds to only one anonymous event identifier. Other methods can also be used in other embodiments, which are not limited here.
[0032] It should be noted that the quantum-safe cryptographic algorithms in the above process can employ lattice-verifiable random functions or other algorithms with pseudo-randomness, uniqueness, and verifiability, thereby ensuring their security in the post-quantum era (i.e., resistance to quantum attacks). Anonymous identifiers are constant for the same topic event among the same group of members. When the system detects that the same event identifier has been validly signed for two different messages under the same event topic, it can be identified as a violation (such as a double-spending attack) and the revocation mechanism can be triggered.
[0033] In specific implementation, the anonymous identifiers that can be aggregated and linked when signing the group member are autonomously linked can be achieved in the following way: Construct a Merkle tree based on all event identifiers. For example, use all the obtained event identifiers as leaf nodes, and then use a quantum-resistant function (such as a lattice-based collision-resistant hash function) to recursively hash the parent node of each leaf node (recursively from bottom to top) until the hash value of the root of the Merkle tree is obtained, thus constructing a Merkle tree; use the hash value of the root of the Merkle tree as the anonymous identifier that can be aggregated and linked when signing the group member; secondly, generate a zero-knowledge proof for the group member using a zero-knowledge proof protocol (such as the Stern-type protocol). This zero-knowledge proof proves that the group member knows a valid Merkle path from a certain leaf node (i.e., a certain specific event identifier) to the Merkle root, and that the path corresponds to the group member's private key and the corresponding event topic; other methods can also be used in other embodiments, which are not limited here.
[0034] It should be noted that the anonymous identifier in this application refers to a unique identifier associated with a group member's signature, represented by the hash value of the Merkle tree root. This identifier allows the signature to conceal the signer's identity while still being verifiable by the verifier to confirm its relevance to a specific event topic and verify its validity. In group signature scenarios, signers wish to sign multiple event topics without revealing their own identity. The anonymous identifier generated by the Merkle tree can represent multiple event topics and hides the specific identity information of group members. Furthermore, the use of quantum-resistant functions to construct the Merkle tree ensures that the entire signature system remains secure even in a quantum computing environment. Secondly, the existence of zero-knowledge proofs allows the verifier to confirm that a group member indeed possesses a valid path from the specific event identifier to the anonymous identifier, and that this path is associated with the group member's private key, thereby guaranteeing the legitimacy and credibility of the signature.
[0035] In step 104, the secret revocation credential is quantum-resistant encrypted, and the legality of the anonymous identifier and the encryption process is proven using zero-knowledge proof based on the encryption form, thereby obtaining a group signature that conceals the identity of the group members.
[0036] In some embodiments, quantum-resistant encryption of the secret revocation credential can be achieved using the following steps: Obtain the group administrator's public key that is resistant to quantum attacks; The secret revocation credential is quantum-resistantly encrypted using the public key to obtain the encrypted form and ciphertext of the secret revocation credential.
[0037] In specific implementation, the secret revocation credential is quantum-resistant encrypted using the public key to obtain the encrypted form and ciphertext of the secret revocation credential. This can be achieved in the following way: the secret revocation credential is encrypted using a quantum-resistant public key encryption algorithm combined with the public key. First, the secret revocation credential is used as the message to be encrypted, and a cryptographically secure pseudo-random number generator is called from the system to generate a random vector and noise for the group members. Then, the random vector, noise, and secret revocation credential are subjected to matrix operations using a quantum-resistant public key encryption algorithm (such as the double Regev encryption scheme) to output the ciphertext of the group member's secret revocation credential. Other methods can also be used in other embodiments, which are not limited here.
[0038] In some embodiments, reference Figure 3 As shown, this diagram is an exemplary flowchart for determining a group signature in some embodiments of this application. In this embodiment, the group signature that conceals the identities of the group members can be obtained by performing zero-knowledge proof on the legality of the anonymous identifier and the encryption process based on the encryption form using the following steps: First, in step 1041, the proof statement of the group member is determined based on the anonymous identifier, the legality of the encryption process, and the validity of the group member's identity; Secondly, in step 1042, a non-interactive zero-knowledge proof resistant to quantum computing attacks is performed on the proof statement; Finally, in step 1043, a group signature that conceals the identity of the group members is determined based on the zero-knowledge proof, the ciphertext of the secret revocation credential, and the anonymous identifier.
[0039] In specific implementation, the group member proof statement can be determined based on the anonymous identifier, the legality of the encryption process, and the validity of the group member's identity in the following ways: First, the path of the group member's public key in the Merkle tree is used as proof of the validity of the group member's identity, the anonymous identifier of the group member is used as proof of the anonymous identifier of the group member, and the ciphertext components and noise constraints generated during the double Regev encryption process are used as proof of the correctness of the encryption process; Second, all the above proofs are integrated into a unified proof statement through an extension protocol (such as an extension protocol based on Stern); Other methods can also be used in other embodiments, which are not limited here.
[0040] It should be noted that the proof statement in this application refers to a composite proof statement that can simultaneously verify membership, anonymous identifier generation, and encryption correctness. The core of this proof statement is to transform multiple constraints satisfied by all secret witnesses (including member private keys, revocation credentials, Merkle tree path nodes, etc.) into a standardized form suitable for zero-knowledge proofs on lattices by introducing appropriate slack variables and random masks.
[0041] In specific implementation, the non-interactive zero-knowledge proof resistant to quantum computing attacks on the proof statement can be implemented as follows: The non-interactive proof is generated using the Stern protocol through the following steps: First, a corresponding commitment value is generated for each constraint in the composite proof statement, including commitments to the secret witness vector, slack variables, and random masks; second, a quantum-resistant hash function (such as a lattice-based hash function) is used to calculate all commitment values and public parameters to generate a hash value (i.e., a challenge value) simulating a verifier challenge; then, the response value for the corresponding verifier challenge is calculated based on the challenge value, including the linear combination of the secret vector, the disclosure of error terms, and proof of the correctness of the commitments; finally, the multi-round interactive process of Stern's extended protocol (i.e., Stern's extended protocol) is converted into a single non-interactive proof through the Fiat-Shamir transformation, outputting a zero-knowledge proof containing a sequence of commitment-challenge-response triples. Other methods can also be used in other embodiments, which are not limited here.
[0042] In specific implementation, the group signature that conceals the identity of the group member, based on the zero-knowledge proof, the ciphertext of the secret revocation credential, and the anonymous identifier, can be implemented in the following way: the zero-knowledge proof, the ciphertext of the secret revocation credential, and the anonymous identifier generated by a lattice-verifiable random function are structurally combined. Specifically, firstly, the ciphertext of the zero-knowledge proof, the secret revocation credential, and the anonymous identifier are standardized and serialized according to a preset encoding rule, and then all the serialized numbers are concatenated to finally output the group signature that conceals the identity of the group member. Other methods can also be used in other embodiments, which are not limited here.
[0043] It should be noted that the group signature in this application refers to a cryptographic primitive that allows any member of a group to digitally sign a message on behalf of the entire group. That is, the verifier can be sure that the signature comes from a legitimate member of the group, but cannot determine which member it is. It is used to provide identity authentication while protecting the privacy of the signer and facilitating subsequent verification and revocation of the signer's identity. The preset encoding format can adopt the "Type-Length-Value" encoding format.
[0044] In step 105, the group signature is revoked based on the anonymous identifier and the revocation list, and the signer identity of the anonymous identifier corresponding to different signed messages under the same event topic is revoked based on the revocation detection result.
[0045] In some embodiments, revocation detection of the group signature based on the anonymous identifier and the revocation list can be achieved by the following steps: The validity of the group signature is verified; The anonymous identifier and the revocation list are compared in relation to each other to obtain preliminary detection results; The detection result is revoked based on the preliminary detection results and the results of the legality verification.
[0046] In specific implementation, the legitimacy verification of the group signature can be achieved in the following way: adopting a verification process based on the Stern protocol, reconstructing the challenge value through the Fiat-Shamir transformation, and checking whether the responses provided by the group members conform to the commitment-challenge-response relationship, thereby obtaining the legitimacy verification result of the group signature; wherein, the same hash function and common parameters as when the group signature was generated are used in the verification process to ensure the consistency of the verification process; other methods can also be used in other embodiments, which are not limited here.
[0047] In specific implementation, the preliminary detection result can be obtained by comparing the anonymous identifier and the revocation list in relation to each other. Specifically, for each secret revocation credential in the revocation list, the verifier calculates the revocation verification parameters of each secret revocation credential and the verification parameters in the group signature. Then, all the revocation verification parameters are compared with the verification parameters in the group signature. If they match, it is determined that the group signature comes from a revoked group member, and the preliminary detection result is set to match. Otherwise, the preliminary detection result is set to unmatched, thus obtaining the preliminary detection result. The revocation detection result can be obtained based on the preliminary detection result and the result of the legality verification. Specifically, when the result of the legality verification is legal and the preliminary detection result is unmatched, the final revocation detection result is set to pass verification; otherwise, the final revocation detection result is set to fail. Other methods can also be used in other embodiments, which are not limited here.
[0048] In some embodiments, revoking the signer identity of the anonymous identifier for different signed messages under the same event topic based on the revocation detection result can be achieved by the following steps: Perform message consistency checks on any two valid group signatures that have the same anonymous identifier and event subject; If the message consistency check results in different messages, the condition revocation mechanism is triggered; In response to the triggering of the conditional revocation mechanism, a quantum-resistant cryptographic operation is performed on the ciphertext in the two group signatures to recover the secret revocation credential of the violator. The revocation list is updated based on the recovered secret revocation certificate, thus completing the revocation of the signer's identity.
[0049] In specific implementation, message consistency detection for any two valid group signatures with the same anonymous identifier and event topic can be achieved in the following way: continuously monitor all verified group signatures, and when two valid group signatures are found to have the same anonymous identifier and corresponding event topic, trigger message consistency detection. Specifically, compare the message fields in the two valid group signatures. If the two message fields are not equal, it is determined that there is a signature conflict, and the result of the message consistency detection is marked as different messages. Other methods can also be used in other embodiments, which are not limited here.
[0050] In specific implementation, in response to the triggering of the conditional revocation mechanism, quantum-resistant cryptographic operations are performed on the ciphertexts of the two conflicting group signatures to recover the secret revocation credential of the violator. This can be achieved in the following way: when the message consistency check result is that the messages are different, the system performs a credential recovery operation. Specifically, the inverse operation of the homomorphic trapdoor function is used to perform quantum-resistant cryptographic operations (such as lattice operations) on the ciphertexts of the two conflicting group signatures. The calculated ciphertext difference and the trapdoor information obtained by applying the homomorphic trapdoor function are used to recover the violator's secret revocation credential. The recovered secret revocation credential is then added to the revocation list, and the leaf node corresponding to the revoked member in the Merkle tree accumulator is marked as invalid. At the same time, the revocation update information is broadcast so that all verifiers can obtain the latest revocation status, ensuring that all signatures generated by the revoked member cannot pass subsequent verification. Other methods can also be used in other embodiments, which are not limited here.
[0051] Furthermore, in another aspect of this application, in some embodiments, this application provides a network security password verification system, which includes an anonymous signature verification unit, referencing... Figure 4 The figure is a schematic diagram of the structure of an anonymous signature verification unit according to some embodiments of this application. The anonymous signature verification unit includes: an acquisition module 401, a processing module 402, and an execution module 403, which are described below: The acquisition module 401 in this application is mainly used to obtain the revocation list when group members sign in; Processing module 402, in this application, is used to determine the secret revocation credential for anonymous signing by each group member and the personal key pair for identity authorization; It should be noted that the processing module 402 in this application is also used to respond to multiple signature requests from any group of members for multiple event topics, and to perform quantum attack-resistant processing on each event topic and the personal key pair respectively, thereby obtaining an aggregateable anonymous identifier used for identity authorization when the group members sign. Additionally, it should be noted that the processing module 402 in this application is also used to perform quantum-resistant encryption on the secret revocation certificate, and to perform zero-knowledge proof on the legality of the anonymous identifier and the encryption process based on the encryption form, thereby obtaining a group signature that conceals the identity of the group members. The execution module 403 in this application is mainly used to perform revocation detection on the group signature based on the anonymous identifier and the revocation list, and thereby revoke the signer identity of the anonymous identifier when corresponding to different signature messages under the same event topic based on the revocation detection result.
[0052] In addition, this application also provides a computer device, the computer device including a memory and a processor, the memory storing code, and the processor being configured to acquire the code and execute the above-described anonymous signature verification method.
[0053] In some embodiments, reference Figure 5 The figure is a schematic diagram of the structure of a computer device implementing an anonymous signature verification method according to some embodiments of this application. The anonymous signature verification method in the above embodiments can be implemented through... Figure 5 The computer device shown is used to implement this, and the computer device includes at least one processor 501, a communication bus 502, a memory 503, and at least one communication interface 504.
[0054] Processor 501 can be a general-purpose central processing unit (CPU) or an application-specific integrated circuit (ASIC).
[0055] The communication bus 502 can be used to transmit information between the aforementioned components.
[0056] Memory 503 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CDROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital versatile optical discs, Blu-ray discs, etc.), magnetic disks or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. Memory 503 may exist independently and be connected to processor 501 via communication bus 502. Memory 503 may also be integrated with processor 501.
[0057] The memory 503 stores program code for executing the scheme of this application, and its execution is controlled by the processor 501. The processor 501 executes the program code stored in the memory 503. The program code may include one or more software modules. The method used in the above embodiments can be implemented by the processor 501 and one or more software modules in the program code in the memory 503.
[0058] Communication interface 504 uses any transceiver-like device to communicate with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc.
[0059] In a specific implementation, as one example, a computer device may include multiple processors, each of which may be a single-core (single CPU) processor or a multi-core (multi CPU) processor. Here, a processor may refer to one or more devices, circuits, and / or processing cores used to process data (e.g., computer program instructions).
[0060] The aforementioned computer device can be a general-purpose computer device or a special-purpose computer device. In specific implementations, the computer device can be a desktop computer, a portable computer, a network server, a handheld digital assistant (PDA), a mobile phone, a tablet computer, a wireless terminal device, a communication device, or an embedded device. This application does not limit the type of computer device.
[0061] In addition, this application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described anonymous signature verification method.
[0062] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0063] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for verifying anonymous signatures for a network security password verification system, the method comprising: receiving a request for a password verification; receiving a password verification request from a user; receiving a password verification response from the user; and verifying the password verification response. The method comprises the following steps: Obtain the revocation list when the group members sign; Determine the secret revocation credential and the personal key pair for identity authorization when each group member anonymously signs; In response to multiple signature requests of any group member on multiple event topics, respectively perform anti-quantum attack processing on each event topic and the personal key pair, and then obtain the anonymous identifier of the group member signature for identity authorization in the form of an aggregatable link; Perform anti-quantum encryption on the secret revocation credential, and perform zero-knowledge proof on the legality of the anonymous identifier and the encryption process based on the encrypted form, and then obtain the group signature that hides the identity of the group member; According to the anonymous identifier and the revocation list, the group signature is revoked, and the identity of the signer of the anonymous identifier corresponding to different signature messages under the same event topic is revoked based on the revocation detection result.
2. The method of claim 1, wherein, Determine the secret revocation credential and the personal key pair for identity authorization when each group member anonymously signs, specifically comprising: Obtain the interactive protocol between the group members and the group administrator; Determine the personal key pair of each group member during group registration through a key generation process resistant to quantum computing attacks; Complete the identity authentication and registration of each group member according to the interactive protocol; Generate secret revocation credentials for anonymous signature of each group member based on the results of identity authentication and registration.
3. The method of claim 1, wherein, In response to multiple signature requests of any group member on multiple event topics, respectively perform anti-quantum attack processing on each event topic and the personal key pair, and then obtain the anonymous identifier of the group member signature for identity authorization in the form of an aggregatable link, specifically comprising: Obtain multiple signature requests of any group member on multiple event topics, and select one signature request as a selected signature request; Confirm the specific event topic corresponding to the selected signature request to obtain the target topic to be signed; Perform anti-quantum verification on the personal key of the group member corresponding to the target topic of the selected signature request to obtain the event identifier of the group member under the event topic; Continue to determine the event identifier of the group member under the remaining event topics; Autonomously link all event identifiers to obtain the anonymous identifier of the group member signature in the form of an aggregatable link.
4. The method of claim 1, wherein, Perform anti-quantum encryption on the secret revocation credential, specifically comprising: Obtain the public key of the group administrator resistant to quantum attacks; Perform anti-quantum encryption on the secret revocation credential through the public key to obtain the encrypted form and ciphertext of the secret revocation credential.
5. The method of claim 1, wherein, Perform zero-knowledge proof on the legality of the anonymous identifier and the encryption process based on the encrypted form, and then obtain the group signature that hides the identity of the group member, specifically comprising: Determine the proof statement of the group member according to the anonymous identifier, the legality of the encryption process, and the validity of the group member identity; Perform non-interactive zero-knowledge proof of the proof statement resistant to quantum computing attacks; Determine the group signature that hides the identity of the group member based on the zero-knowledge proof, the ciphertext of the secret revocation credential, and the anonymous identifier.
6. The method of claim 1, wherein, According to the anonymous identifier and the revocation list, the group signature is revoked, specifically comprising: Verify the legality of the group signature; correlate the anonymous identifier and the revocation list to obtain a preliminary detection result; obtain a revocation detection result based on the preliminary detection result and the result of the legitimacy verification.
7. The method of claim 1, wherein, The revocation of the signer identity of the anonymous identifier corresponding to different signed messages under the same event subject based on the revocation detection result specifically includes: performing message consistency detection on any two valid group signatures with the same anonymous identifier and event subject; if the result of the message consistency detection is that the messages are different, triggering a conditional revocation mechanism; in response to the triggering of the conditional revocation mechanism, performing an anti-quantum-computing-attack-resistant cryptographic operation on the ciphertext in the two group signatures to recover the secret revocation credential of the violator; updating the revocation list according to the recovered secret revocation credential to complete the revocation of the signer identity.
8. A network security password verification system comprising an anonymous signature verification unit, characterized by, The anonymous signature verification unit includes: an acquisition module configured to acquire a revocation list when a group member signs; a processing module configured to determine a secret revocation credential and a personal key pair for identity authorization when each group member signs anonymously; the processing module is further configured to, in response to a plurality of signature requests of any group member on a plurality of event subjects, perform anti-quantum-attack-resistant processing on each event subject and the personal key pair, and then obtain an aggregatable linkable anonymous identifier for identity authorization when the group member signs; the processing module is further configured to perform anti-quantum-encryption on the secret revocation credential, and perform zero-knowledge proof on the legitimacy of the anonymous identifier and the encryption process based on the encrypted form, and then obtain a group signature that hides the identity of the group member; an execution module configured to perform revocation detection on the group signature based on the anonymous identifier and the revocation list, and thereby revoke the signer identity of the anonymous identifier corresponding to different signed messages under the same event subject based on the revocation detection result.
9. A computer device, comprising: The computer device includes a memory and a processor, the memory stores code, and the processor is configured to acquire the code and execute the anonymous signature verification method according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, the computer program comprising instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1-9. The computer program is executed by the processor to implement the anonymous signature verification method according to any one of claims 1 to 7.