An Anonymous Identity Management and Verification Method Supporting Dynamic Changes in User Attributes

The method addresses identity management and verification challenges in blockchain networks by employing attribute-based signatures for decentralized, dynamic identity management, ensuring user privacy and secure transaction verification in distributed environments.

CN113656826BActive Publication Date: 2025-07-15INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010396755.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-05-12
Publication Date
2025-07-15
Estimated Expiration
2040-05-12

AI Technical Summary

Technical Problem

The existing technology is difficult to realize dynamic changes in user attributes and anonymous identity management and verification in blockchain, especially in the lack of distributed and variable attribute functions in consortium chains, resulting in challenges in privacy protection and identity verification.

Method used

The attribute-based signature technology is adopted to generate attribute keys and public keys through attribute institutions, which support dynamic changes in user attributes and anonymous identity management, and use bilinear group parameters and hash functions for signature generation and verification, avoid relying on a single authoritative organization, and realize identity management and verification in a distributed environment.

Benefits of technology

It supports dynamic changes in user attributes on the blockchain, protects user privacy, prevents conspiracy attacks, improves verification efficiency, reduces computing volume and interaction delays, and is suitable for distributed environments of alliance chains.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113656826B_ABST
    Figure CN113656826B_ABST
Patent Text Reader

Abstract

The present invention discloses an anonymous identity management and verification method that supports dynamic changes in user attributes, belonging to the field of blockchain. It mainly includes four steps: system initialization, generation and update of attribute signature keys, generation of signatures, and verification of signatures. This method can effectively solve the problems existing in the prior art. It can not only manage and verify user identities without revealing the user's identity, but also this process does not rely on a central trusted institution, so it is well applicable to distributed scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for anonymous identity management and verification that supports dynamic changes in user attributes, and belongs to the field of blockchain. Background Art

[0002] In recent years, blockchain technology has become a hot research topic. Blockchain refers to a technical solution for collectively maintaining a reliable database in a decentralized and trustless manner. This technical solution allows any number of nodes participating in the system to calculate and record the data of all information exchanges within the system for a period of time into a data block through cryptographic algorithms, and generate a fingerprint of the data block for linking the next data block and verification. All participating nodes in the system jointly determine whether the record is true.

[0003] The four main characteristics of blockchain are:

[0004] (1) Decentralized. There is no centralized hardware or management institution in the entire network. The rights and obligations between any nodes are equal, and the damage or loss of any one node will not affect the operation of the entire system.

[0005] (2) Trustless. Data exchange between each node participating in the entire system does not require mutual trust. The operation rules of the entire system are publicly transparent, and all data contents are also public.

[0006] (3) Collectively Maintain. The data blocks in the system are jointly maintained by all nodes with maintenance functions in the entire system, and anyone can participate in these nodes with maintenance functions.

[0007] (4) Reliable Database. The entire system will be in the form of a distributed database, allowing each participating node to obtain a copy of the complete database. Unless more than 51% of the nodes in the entire system can be controlled simultaneously, the modification of the database on a single node is invalid and cannot affect the data contents on other nodes. Therefore, the more nodes participating in the system and the stronger the computing power, the higher the data security in the system.

[0008] Two other characteristics will be derived from the above four characteristics:

[0009] (1) Open Source: Since the operation rules of the entire system must be publicly transparent, the entire system will necessarily be open source for the program.

[0010] (2) Privacy Protection (Anonymity): Since there is no need for nodes to trust each other, there is no need to disclose identities between nodes, and the privacy of each participating node in the system is protected.

[0011] Blockchains are currently divided into three categories: private blockchains, public blockchains, and consortium blockchains.

[0012] · Public blockchains are the earliest blockchains and are currently the most widely used. They refer to blockchains that are completely decentralized and not controlled by any institution, such as the Bitcoin blockchain. Any individual or group in the world can send transactions, and the transactions can be effectively confirmed by the blockchain. Anyone can participate in its consensus process. The participants in the consensus process maintain the security of the database through cryptographic techniques and built-in economic incentives. Public blockchains have the characteristics of being completely public, uncontrolled, and relying on encryption technology to ensure security.

[0013] · Private blockchains refer to blockchains with certain centralized control. Only the general ledger technology of blockchains is used for accounting. It can be a company or an individual, and only they have the write permission to this blockchain. This blockchain is not much different from other distributed storage solutions. The only participating node is the user himself, and there is strict permission management for data access and use. Since consortium blockchains have certain centralized control, they can also be considered to belong to the category of private blockchains. Since in private blockchains, everything is decided by the user, the data does not have the property of being immutable, and there is not much guarantee for third parties. It is generally used for internal audits.

[0014] · Consortium blockchains designate multiple preselected nodes as bookkeepers within a certain group. The generation of each block is jointly determined by all the preselected nodes. Other connected nodes can participate in transactions but do not interfere in the accounting process. The nodes participating in the blockchain are preselected in advance, and there is likely to be a good network connection between the nodes. Other consensus algorithms other than proof-of-work can be adopted on such blockchains. For example, if a blockchain is established among 100 financial institutions, it is stipulated that more than 67 institutions must agree to reach a consensus. Consortium blockchains can achieve good connections between nodes, can be maintained at very low cost, provide rapid transaction processing and low transaction fees, have good scalability, but the scalability will decrease as the number of nodes increases. The data can ensure a certain degree of privacy, and at the same time, the application scope of this blockchain is limited.

[0015] With the development of blockchain technology, more and more projects are being deployed on the blockchain. However, the privacy protection issue of the blockchain cannot be ignored. Taking the blockchain of electronic transactions as an example, in an electronic trading system, there is no longer a need for a third-party platform as an intermediary between users, and users can directly conduct transactions with each other, helping to improve the current situation of information asymmetry between buyers and sellers. In such a scenario, a more common example is to assign corresponding credit values to users based on their behaviors, and this credit value represents the honesty degree of the users. Generally speaking, both buyers and sellers hope to conduct transactions with users with high credit, and the transaction information is stored on the blockchain, which is immutable and permanent. However, due to the publicly accessible nature of the data on the blockchain, it inevitably brings threats to privacy. First of all, at the network layer, there may be a situation where the data is tampered with during the transmission of these transaction information. Secondly, at the transaction layer, during the generation, verification, storage, and use of transactions, there are also threats of transaction information leakage and user identity privacy leakage. In addition, at the application layer, when using these transaction data, privacy risks will also be faced. Therefore, in practical applications, not only the privacy protection of these on-chain transaction data needs to be considered, but also the user identity privacy needs to be considered, that is, an anonymous identity management and verification method is required.

[0016] One of the solutions to the problem of the use of transaction data is to perform access control on the identity of users accessing the data. However, most of the existing identity management systems rely on central institutions such as PKI and CA, so it is difficult to be applied in the distributed blockchain scenario. Regarding the problem of user identity privacy, most of the current methods are pseudo-anonymous methods, but through mathematical analysis, there are still problems of identity linking. Regarding the problem that users rely on credit values to independently select trading parties, no researchers have conducted research yet.

[0017] Considering the above problems, combined with cryptographic techniques, when abstracting the credit value as an attribute, the use of attribute-based signatures can help solve the above problems. Because in an attribute-based signature scheme, the identity of the user is characterized by attributes. On the one hand, it avoids the leakage of the user's real identity. On the other hand, through the verification of the attribute signature, it can help to implement the access control function, so that only users who meet the corresponding conditions can have the ability to access the data. However, the current research on attribute-based signature schemes cannot be directly applied because the functions are not perfect and lack distributed or attribute-variable functions. Therefore, it is a problem to be solved to improve the attribute-based signature to have distributed and variable attribute functions to achieve anonymous identity management and verification.

[0018] Considering the actual scenario of use, the required signature control scheme needs to meet the following requirements:

[0019] (1) Validity. User identity management and verification can be achieved through attribute management and verification.

[0020] (2) Anonymity. During the signature verification process, no third party can obtain the user's true identity from the message and the message's signature.

[0021] (3) Unforgeability. No user member can forge a false reputation value and generate a valid signature.

[0022] In addition, considering that the user's attributes are dynamically changing in the actual application process, how to efficiently deal with the dynamic changes of the user's attributes is an important issue that needs to be solved urgently. The system should not only support the distributed system architecture, realize the distribution of keys without relying on a single authority, but also support the dynamic changes of attributes. Therefore, how to achieve efficient decentralized key distribution and update of dynamic attributes is a problem worth studying. Currently, there is no existing method or system that can solve the above problems in the alliance chain, so further research is needed.

[0023] Blockchain involves access structure and linear key sharing scheme, which are briefly described as follows:

[0024] The access structure is a logical structure that describes the access policy. Its original idea comes from the threshold key sharing scheme. The access structure implements access control to data by distinguishing the participant sets, that is, defining the authorized set that can reconstruct the key and the unauthorized set that cannot reconstruct the key. The specific definition is as follows:

[0025] Access Structure) Let {P1,P2,...,P n} represents a set of n participants, and Γ represents a subset of the participant set. If Γ is a monotone access structure, then Γ satisfies: for all subsets A, B, if A∈Γ, and Then we can conclude that B∈Γ. And if D∈Γ, then D is an authorized set, otherwise it is an unauthorized set.

[0026] A secret sharing scheme Π on a set of participants P is called Z if it satisfies the following conditions: p A linear secret sharing scheme on (denoting a group over prime numbers p):

[0027] 1. Each entity’s secret share constitutes Z p A vector on .

[0028] 2. For the secret sharing scheme Π, there exists a generator matrix M l×n, for each row \(i = 1, 2, \ldots, l\) of matrix \(M\), the mapping \(\rho:\{1, 2, \ldots, l\} \to P\) maps it to the set of participants \(P\). Let the vector where \(s \in Z\) p is the shared secret key, and \(r_2, r_3, \ldots, r\) n are random parameters used to hide \(s\), and \(\mathbf{y}\) is a vector composed of \(l\) secret shares. Then, denotes the secret share assigned to participant \(\rho\) i . Summary of the Invention

[0029] The object of the present invention is to provide an anonymous identity management and verification method that supports dynamic changes of user attributes, which can effectively solve the problems existing in the prior art, not only support dynamic changes of attributes, well adapt to distributed scenarios, but also perfectly implement identity management and verification.

[0030] To solve the above technical problems, the present invention adopts the following technical solutions:

[0031] An anonymous identity management and verification method that supports dynamic changes of user attributes, which is used for a blockchain network system. The system includes users, an attribute institution, and a blockchain service provider; the attribute institution is responsible for maintaining an attribute set, generating an attribute key and a public key, and generating an attribute signature key for users. Different institutions are responsible for different attributes, and a user is given one or more corresponding attributes, and identity management and verification of the user are realized through management and verification of these attributes; the blockchain service provider provides a public platform for transactions between users, and all transaction information is stored on the blockchain. The method includes the following steps:

[0032] S1. System initialization: Initialize system parameters, generate global parameters of the system, and initialize the attribute institution according to the global parameters to generate an attribute key for each attribute;

[0033] S2. Generation and update of attribute keys: A user applies to the corresponding attribute institution for an attribute key, and the attribute institution responsible for the corresponding attribute distributes the attribute key to the user. In the process of generating the attribute key, not only the user identity but also the time node is considered to cope with the subsequent key update process;

[0034] S3. Signature generation: The user generates access information \(M\), signs the access information \(M\) using the attribute key, and then broadcasts and sends the access information \(M\) and the signature;

[0035] S4. Signature verification: Other users verify the access information \(M\) and the signature. If the verification passes, the request is processed.

[0036] Furthermore, the steps for initializing system parameters include:

[0037] (1) Given a security parameter k, run the bilinear pairing generation algorithm to obtain bilinear group parameters, which include p, G, G T , e, g1, where p is the order of group G, g1 is the generator of group G respectively, and e is the mapping e: G1×G1→G T ;

[0038] (2) Generate three hash functions H0: {0, 1} * →Z p , H1: {0, 1} * →G, h: {0, 1} * →G;

[0039] (3) Obtain the global parameters from the bilinear group parameters and the hash functions: GP = (G, G T , e, p, g1, H0, H1, h)

[0040] Furthermore, the steps for initializing the attribute authority include:

[0041] (1) According to the global parameter GP, each attribute authority selects two random numbers as the attribute private keys α, y ∈ Z for each attribute it is responsible for p ;

[0042] (2) The attribute authority calculates the corresponding attribute public keys for each attribute: apk (1) = e(g1, g1) α , apk (2) = g1 y ; where the attribute private key of attribute i is ask i = {α i , y i}, and the attribute public key is:

[0043] Furthermore, the steps for the attribute authority responsible for the corresponding attribute to distribute the attribute key to the user include:

[0044] (1) The attribute authority receives the attribute key request of attribute i of user GID, obtains the current time t, and generates the attribute key of user GID at time t for attribute i:

[0045] (2) The attribute authority sends the attribute key requested by the user to user GID.

[0046] Further, the method for obtaining the current time t is: obtaining the timestamp of the last confirmed block in the current blockchain as the current moment.

[0047] Further, define the access policy as a matrix A, and the user uses this matrix, the global parameter GP, the identity information GID, and the attribute key and the access information M to perform signature.

[0048] Further, the steps for the user to sign the access information M include:

[0049] (1) The user randomly selects a random number s ∈ Z p and vectors and vectors Set s ∈ Z p as the first element of the vector while the first element of the vector is set to 0;

[0050] (2) Let v x represent A x ·v, and w x represent A x ·w, where A x represents the x-th row of the matrix A;

[0051] (3) The user selects a random number r x ∈ Z x for each row A p of the matrix A, and then performs the following calculations:

[0052] σ0 = e(g1,g1) sh(M)

[0053]

[0054]

[0055] (4) The signature generated for the access information M is σ = (σ0, σ 1,x .σ 2,x ).

[0056] Further, the steps for verifying the access information M and the signature include:

[0057] (1) For the matrix A composed of the access policy, calculate a set of c x that satisfy the equation: ∑c x A x = (1, 0,..., 0);

[0058] (2) Use the hash function h to hash the message to obtain h(M), get the timestamp of the latest block, and calculate H0(t);

[0059] (3) Perform the following calculations:

[0060]

[0061] (4) If this equation holds, then the verification passes; otherwise, the verification fails.

[0062] Compared with the prior art, the present invention has the following advantages:

[0063] (1) The present invention formulates an anonymous identity management and verification method that supports dynamic changes in user attributes. This method utilizes attribute-based signature technology to grant legitimate users corresponding attributes and attribute keys. Through the management of attributes, anonymous management of user identities is achieved. Users can generate signatures for authentication during the interaction process, and if the signature verification passes, the identity verification is successful. This indicates that user identity verification can be completed through the verification of attribute signatures. Attribute-based signature technology characterizes user identities through attributes, thus protecting the privacy of user identities. The attribute keys granted to users embed the user's identity and time nodes, thus enabling prevention of collusion attacks and problems of key update and abuse.

[0064] (2) The authentication process of the present invention can be independent of a single authoritative institution and is applicable to the distributed environment of the blockchain. Although an attribute institution is introduced during system initialization, the attribute institution does not participate in the signature verification process, and only the corresponding public key of the attribute institution needs to be obtained for the signature verification process, without the need to interact with the attribute institution.

[0065] (3) The present invention supports direct identity verification between users and can achieve identity management. Through the verification of attribute signatures, users can verify the identity of the other party without relying on a central institution, thereby achieving identity management and verification.

[0066] (4) The signature method involved in the present invention requires less computational effort compared to previous signature methods. At the same time, in this method, the identity verification process does not need to interact with a third party, avoiding information delay caused by interaction, thereby accelerating the verification processing speed. Description of the Drawings

[0067] Figure 1 It is a schematic structural diagram of a blockchain network system.

[0068] Figure 2 It is a flowchart of an anonymous identity management and verification method that supports dynamic changes in user attributes.

[0069] Figure 3 It is a schematic diagram of the generation process of time nodes. Specific implementation manners

[0070] To make the technical solutions of the present invention more obvious and understandable, specific embodiments are given and described in detail below in conjunction with the accompanying drawings.

[0071] This embodiment proposes a distributed anonymous authentication method applicable to consortium blockchains that supports traceability, which is applied to a blockchain network system, such as Figure 1 As shown, the system includes users, attribute institutions, and blockchain service providers. The attribute institutions are responsible for maintaining their attribute sets, generating attribute keys and public keys, and generating attribute signature keys for users. Different institutions are responsible for different attributes. Users are assigned corresponding attributes, which may be one or more. The management and verification of these attributes are used to implement the management and verification of user identities. The blockchain service provider provides a public platform for transactions between users. All transaction information is stored on the blockchain; the method is as Figure 2 shown, and specifically includes the following steps:

[0072] S1. System initialization: System initialization includes the initialization of system parameters and the initialization of attribute institutions.

[0073] In step S1, the public parameters and corresponding secret parameters are generated through the following steps:

[0074] The generation process of system parameters is:

[0075] (1) Given a security parameter k, run the bilinear pairing generation algorithm to obtain bilinear group parameters, which include p, G, G T , e, g1, where p is the order of group G, g1 are the generators of group G respectively, and e is the mapping e: G1×G1→G T .

[0076] (2) Three hash functions H0: {0,1} * →Z p , H1: {0,1} * →G, h: {0,1} * →G.

[0077] (3) The global parameters are: GP = (G, G T , e, p, g1, H0, H1, h).

[0078] The parameter generation process of the attribute institution is:

[0079] (1) Given the global parameter GP, each attribute institution selects two random numbers as the attribute private keys α, y∈Z p .

[0080] (2) The attribute authority calculates the corresponding attribute public key for each attribute: apk (1) = e(g1, g1) α , apk (2) = g1 y ;

[0081] The attribute private key of attribute i is ask i = {α i , y i} and the attribute public key is:

[0082] S2. Generation and update of attribute keys: The user applies to the corresponding attribute authority for an attribute key. The attribute authority responsible for the corresponding attribute distributes the key to the user. In the process of generating the attribute key, not only the user identity but also the time node is considered to cope with the subsequent key update process.

[0083] In step S2, the generation and update steps of the attribute signature key are performed as follows:

[0084] (1) The attribute authority receives the attribute key request of attribute i for user GID, obtains the current time t, and generates the attribute key of user GID for attribute i at time t:

[0085] (2) The generation process at time t is: Take the timestamp of the last confirmed block in the current blockchain as the current time, as Figure 3 shown.

[0086] (4) The attribute authority sends the attribute key requested by the user to user GID.

[0087] S3. Signature generation: The user generates access information M and signs the access information M using the attribute key. The user broadcasts the access information M and the signature.

[0088] In step S3, the signature generation is performed through the following steps:

[0089] (1) Define the access policy as a matrix A, and the user uses this matrix, global parameters GP, identity information GID, attribute signature key and access information M to generate the signature.

[0090] (2) The user randomly selects a random number s ∈ Z p , vector and vector Set s ∈ Z p as the first element of vector while vector The first element of

[0091] (3) Let v x represent A x ·v, w x represent A x ·w, where A x represents the x-th row of matrix A.

[0092] (4) The user selects a random number r x for each row A x ∈Z p of matrix A, and then performs the following calculations:

[0093] σ0 = e(g1, g1) sh(M)

[0094]

[0095]

[0096] (5) The signature generated for the access information M is σ = (σ0, σ 1,x .σ 2,x ).

[0097] S4. Signature verification: Verify the access information M and the signature. If the verification passes, the request is processed.

[0098] In step S4, the signature verification is carried out through the following steps:

[0099] (1) For the matrix A formed by the access policy, the verifier calculates a set of c x that satisfies the equation: ∑c x A x = (1, 0,..., 0).

[0100] (2) The verifier uses the hash function h to hash the message to obtain h(M), gets the timestamp of the latest block, and calculates H0(t).

[0101] (3) The verifier performs the following calculations:

[0102]

[0103] (4) If the equation holds, the verification passes; otherwise, the verification fails.

[0104] The above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit them. Those of ordinary skill in the art can modify or equivalently replace the technical solutions of the present invention. The protection scope of the present invention shall be subject to the claims.

Claims

1. An anonymous identity management and verification method supporting dynamic changes of user attributes, which is used for a blockchain network system. The system includes users, attribute institutions, and blockchain service providers, and is characterized in that The method includes the following steps: Initialize the system parameters to generate the global parameters GP of the system. The steps for initializing the system parameters include: According to a security parameter, obtain the bilinear group parameters through the bilinear pairing generation algorithm. These parameters include p, G, G T , e, g1, where p is the order of the group G and is a prime number; g1 is the generator of the group G; e is the mapping e: G1×G1→G T ; Generate the hash functions H0, H1, h based on the bilinear group parameters. The method for generating the hash functions is: H0: {0, 1} * →Z p , Z p is a group over p, H1: {0, 1} * →G, h: {0, 1} * →G; Obtain the global parameters GP = (G, G T , e, p, g1, H0, H1, h) from the bilinear group parameters and the hash functions; Initialize the attribute authority according to the global parameter GP to generate an attribute key for each attribute; the steps for initializing the attribute authority include: according to the global parameter GP, each attribute authority selects two random numbers as the attribute private keys α, y ∈ Z for each attribute it is responsible for p ; the attribute authority calculates the corresponding attribute public key apk for each attribute (1) = e(g1, g1) α , apk (2) = g1 y ; the attribute private key of attribute i is ask i = {α i , y i}, and the attribute public key is The user applies to the corresponding attribute institution for an attribute key, and the attribute institution responsible for the corresponding attribute distributes the attribute key to the user. The method is as follows: when the attribute institution receives the attribute key request for the user's attribute i, it obtains the current time t and generates an attribute key for the user regarding attribute i at time t and sends it to the user; The user generates access information M, signs the access information M according to the matrix A, global parameters GP, identity information GID, and attribute key pair formed by the access policy, and broadcasts the access information M and the signature; the method for the user to sign the access information M is: the user randomly selects a random number s ∈ Z p , vector and vector Set s ∈ Z p as the first element of vector , and set the first element of vector to 0; let v x represent A x ·v, w x represent A x ·w, where A x represents the x-th row of matrix A; the user selects a random number r x for each row A x ∈ Z p , and then performs the following calculations: Generate the signature σ=(σ0,σ 1,x .σ 2,x ) of the access information M; Other users verify the access information M and the signature. If the verification passes, the request is processed.

2. The method according to claim 1, wherein The method for obtaining the current time t is: obtaining the timestamp of the last confirmed block in the current blockchain as the current moment.

3. The method according to claim 1, characterized in that, The steps for verifying the access information M and the signature include: for the matrix A formed by the access policy, calculating a set of c x ; Using the hash function h, hash the message to obtain h(M), obtain the timestamp of the latest block, and calculate H0(t); Perform the following calculations: If the equation holds, the verification passes; otherwise, the verification fails.

4. The method according to claim 3, characterized in that, c x satisfies the equation: ∑c x A x = (1, 0,..., 0).

Citation Information

Patent Citations

  • Attribute-based network ring signing method for distributed authorization

    CN107342990A

  • Privacy protection method for storing shared data in mobile cloud

    CN107968780A