Identity authentication method, system, computer device and storage medium
By generating anonymous identity data and regulatory signature information, identity authentication is realized without exposing user attribute information, solving the problem of user privacy and security in traditional identity authentication methods and improving security.
Patent Information
- Application Number
- CN202210809236.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-11
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2042-07-11
AI Technical Summary
The traditional digital certificate identity authentication method will lead to the complete exposure of user attribute information, which will not guarantee the privacy and security of users.
By generating anonymous identity data based on the authentication attributes and the original identity certificate, obtain the supervision signature information generated by the identity supervision device for the anonymous identity data, obtain the anonymous identity certificate, and use it to authenticate.
Without completely exposing the user attribute information, the identity authentication of the target user is completed, improving security.
Smart Images

Figure CN115277010B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to an identity authentication method, system, computer device and storage medium. Background Art
[0002] With the development of computer technology, many important activities of people are now carried out through the Internet, so the security issues that come with it are very important. More and more people use identity authentication technology to establish a "trust" relationship between different entities and conduct reliable network communications.
[0003] In traditional technology, identity authentication is performed through a digital certificate issued by a certificate issuing agency. The verifier uses the public key of the certificate issuing agency to decrypt the digital certificate to obtain the user attribute information in the digital certificate. However, this method will cause the user attribute information to be completely exposed and cannot guarantee the privacy security of the user. Summary of the invention
[0004] Based on this, it is necessary to provide an identity authentication method, system, computer device, computer-readable storage medium and computer program product that can improve security in response to the above technical problems.
[0005] In a first aspect, the present application provides an identity authentication method. The method comprises:
[0006] Generate anonymous identity data based on authentication attributes and the original identity certificate; the authentication attributes are identity attributes that need to be authenticated when the identity authentication device authenticates the target user;
[0007] Obtaining supervision signature information generated by the identity supervision device for the anonymous identity data, so as to obtain an anonymous identity certificate according to the supervision signature information and the anonymous identity data; the identity supervision device is used to supervise the anonymous identity data corresponding to the target user;
[0008] Sending the anonymous identity certificate to an identity authentication device, so that the identity authentication device performs identity authentication on the target user based on the supervision signature information in the anonymous identity certificate and the anonymous identity data;
[0009] After the identity authentication is passed, the authentication authorization information sent by the identity authentication device is obtained.
[0010] In one embodiment, the anonymous identity data includes an anonymous identity public key; and obtaining the supervision signature information generated by the identity supervision device for the anonymous identity data includes:
[0011] Signing the anonymous identity public key to obtain anonymous public key signature information;
[0012] Sending the anonymous public key signature information to an identity supervision device, so that the identity supervision device performs identity validity authentication on the anonymous identity public key based on the anonymous public key signature information;
[0013] After the identity validity authentication is passed, the supervision signature information generated by the identity supervision device for the anonymous identity public key is obtained.
[0014] In one embodiment, sending the anonymous public key signature information to the identity supervision device so that the identity supervision device performs identity validity authentication on the anonymous identity public key based on the anonymous public key signature information includes:
[0015] The anonymous public key signature information is sent to the identity supervision device, so that the identity supervision device determines that the anonymous identity public key belongs to the target user by parsing the anonymous public key signature information, and when it is determined that the anonymous identity public key belongs to the target user and the original identity certificate is valid, determines that the identity validity authentication of the anonymous identity public key is passed.
[0016] In one embodiment, the original identity certificate is a digital certificate generated based on the original identity data of the target user; after the identity validity authentication is passed, obtaining the supervision signature information generated by the identity supervision device for the anonymous identity public key includes:
[0017] After the identity validity authentication is passed, the identity supervision device generates supervision signature information with a validity period for the anonymous identity public key, and stores the anonymous identity public key and the original identity data of the target user in correspondence.
[0018] In one embodiment, the method further includes an identity tracking step for the target user; the identity tracking step includes:
[0019] After receiving the anonymous identity public key and supervision signature information sent by the identity authentication device, the identity supervision device performs signature validity authentication on the supervision signature information, and if the signature validity authentication passes, determines the original identity data stored corresponding to the anonymous identity public key to obtain the identity tracking result for the target user.
[0020] In one embodiment, the anonymous identity data includes zero-knowledge proof data; sending the anonymous identity certificate to an identity authentication device so that the identity authentication device performs identity authentication on the target user based on the supervision signature information in the anonymous identity certificate and the anonymous identity data includes:
[0021] The anonymous identity certificate is sent to the identity authentication device, so that the identity authentication device performs supervision validity authentication on the anonymous identity certificate by locally parsing the supervision signature information in the anonymous identity certificate, and when the supervision validity authentication passes and it is determined based on zero-knowledge proof data that the target user has authentication attributes, it is determined that the identity authentication of the target user is successful.
[0022] In a second aspect, the present application also provides an identity authentication system. The system includes a target device corresponding to a target user, an identity authentication device, and an identity supervision device;
[0023] The target device is used to generate anonymous identity data based on the authentication attribute and the original identity certificate; the authentication attribute is the identity attribute that needs to be authenticated when the identity authentication device authenticates the target user;
[0024] The identity supervision device is used to generate supervision signature information for the anonymous identity data; the identity supervision device is used to supervise the anonymous identity data corresponding to the target user;
[0025] The target device is further used to obtain the supervision signature information to obtain an anonymous identity certificate according to the supervision signature information and the anonymous identity data; and send the anonymous identity certificate to the identity authentication device;
[0026] The identity authentication device is used to authenticate the target user based on the supervision signature information in the anonymous identity certificate and the anonymous identity data; after the identity authentication is passed, the authentication authorization information is sent to the target device;
[0027] The target device is also used to obtain the authentication authorization information sent by the identity authentication device.
[0028] In one of the embodiments, the anonymous identity data includes an anonymous identity public key; the target device is also used to sign the anonymous identity public key to obtain anonymous public key signature information; and send the anonymous public key signature information to an identity supervision device; the identity supervision device is also used to perform identity validity authentication on the anonymous identity public key based on the anonymous public key signature information; the target device is also used to obtain the supervision signature information generated by the identity supervision device for the anonymous identity public key after the identity validity authentication is passed.
[0029] In one of the embodiments, the target device is further used to send the anonymous public key signature information to the identity supervision device; the identity supervision device is further used to determine that the anonymous identity public key belongs to the target user by parsing the anonymous public key signature information, and when it is determined that the anonymous identity public key belongs to the target user and the original identity certificate is valid, determine that the identity validity authentication of the anonymous identity public key has passed.
[0030] In one of the embodiments, the original identity certificate is a digital certificate generated based on the original identity data of the target user; after the identity validity authentication is passed, the identity supervision device is also used to generate supervision signature information with a validity period for the anonymous identity public key, and store the anonymous identity public key and the original identity data of the target user in correspondence.
[0031] In one of the embodiments, the identity supervision device is also used to perform signature validity authentication on the supervision signature information after receiving the anonymous identity public key and supervision signature information sent by the identity authentication device, and if the signature validity authentication passes, determine the original identity data stored corresponding to the anonymous identity public key to obtain the identity tracking result for the target user.
[0032] In one of the embodiments, the anonymous identity data includes zero-knowledge proof data; the target device is further used to send the anonymous identity certificate to the identity authentication device; the identity authentication device is further used to perform regulatory validity authentication on the anonymous identity certificate by locally parsing the regulatory signature information in the anonymous identity certificate, and when the regulatory validity authentication passes and it is determined based on the zero-knowledge proof data that the target user has the authentication attribute, determine that the identity authentication of the target user is passed.
[0033] In a third aspect, the present application further provides a computer device, wherein the computer device comprises a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps in each embodiment of the method described in the present application are implemented.
[0034] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps in each embodiment of the method described in the present application are implemented.
[0035] In a fifth aspect, the present application further provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, the steps in each embodiment of the method described in the present application are implemented.
[0036] The above-mentioned identity authentication method, system, computer device, storage medium and computer program product generate anonymous identity data based on authentication attributes and original identity certificates; authentication attributes are identity attributes that need to be authenticated when the identity authentication device authenticates the target user; obtains the supervision signature information generated by the identity supervision device for the anonymous identity data, so as to obtain the anonymous identity certificate based on the supervision signature information and the anonymous identity data; the identity supervision device is used to supervise the anonymous identity data corresponding to the target user; sends the anonymous identity certificate to the identity authentication device, so that the identity authentication device authenticates the target user based on the supervision signature information and anonymous identity data in the anonymous identity certificate; after the identity authentication is passed, obtains the authentication authorization information sent by the identity authentication device. The anonymous identity data corresponding to the target user is signed by the identity supervision device to obtain the supervision signature information, and the identity authentication device can authenticate the target user based on the supervision signature information and anonymous identity data in the anonymous identity certificate, so that the identity authentication of the target user can be completed without completely exposing the user attribute information, thereby improving security. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 is an application environment diagram of an identity authentication method in an embodiment;
[0038] Figure 2 A schematic diagram of a flow chart of an identity authentication method in an embodiment;
[0039] Figure 3 A simplified flowchart of an identity authentication method in one embodiment;
[0040] Figure 4 is a timing diagram of identity authentication in one embodiment;
[0041] Figure 5 is a structural block diagram of an identity authentication system in an embodiment;
[0042] Figure 6 is an internal structure diagram of a computer device in one embodiment;
[0043] Figure 7 FIG. 4 is a diagram showing the internal structure of a computer device in another embodiment. DETAILED DESCRIPTION
[0044] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0045] The identity authentication method provided in the embodiment of the present application can be applied to Figure 1In the application environment shown. Among them, the target device 102, the identity authentication device 104 and the identity supervision device 106 communicate through the blockchain network. The target device 102 can generate anonymous identity data based on the authentication attribute and the original identity certificate; the authentication attribute is the identity attribute that needs to be authenticated when the identity authentication device authenticates the target user; the target device 102 can obtain the supervision signature information generated by the identity supervision device 106 for the anonymous identity data, so as to obtain the anonymous identity certificate according to the supervision signature information and the anonymous identity data; the identity supervision device is used to supervise the anonymous identity data corresponding to the target user; the target device 102 can send the anonymous identity certificate to the identity authentication device 104, so that the identity authentication device 104 authenticates the target user based on the supervision signature information and the anonymous identity data in the anonymous identity certificate; after the identity authentication is passed, the target device 102 obtains the authentication authorization information sent by the identity authentication device 104.
[0046] Among them, the target device 102, the identity authentication device 104 and the identity supervision device 106 are computer devices in the blockchain network. The computer device can be a terminal or a server. The server can be implemented as an independent server or a server cluster composed of multiple servers.
[0047] In one embodiment, Figure 2 As shown, an identity authentication method is provided, which is implemented through interaction between a target device, an identity authentication device and an identity supervision device, and includes the following steps:
[0048] Step 202: Generate anonymous identity data based on the authentication attributes and the original identity certificate.
[0049] Among them, the authentication attribute is the identity attribute that needs to be authenticated when the identity authentication device authenticates the target user. The identity attribute is used to indicate the identity characteristics of the target user. The original identity certificate is a digital certificate generated based on the original identity data of the target user, which is used to prove the original identity of the target user. The original identity certificate includes the original identity attributes of the target user. The original identity attribute is the identity attribute of the target user itself, which has not been modified and is a real identity attribute. It can be understood that the target user itself has the original identity data, and the original identity data includes all the original identity attributes of the target user. The original identity data corresponds to the target user one by one. Anonymous identity data is used to selectively prove that the target user has authentication attributes and hide other original identity attributes that are not necessary for identity authentication. It can be understood that anonymous identity data is essentially pseudonymous identity data used for identity authentication. The target user can correspond to multiple anonymous identity data, that is, the target user can have multiple pseudonymous identities.
[0050] Specifically, the target device can trigger the identity authentication device to authenticate the target user. The identity authentication device can determine the identity attribute that needs to be authenticated and obtain the authentication attribute. The target device can obtain the authentication attribute sent by the identity authentication device, generate zero-knowledge proof data of the authentication attribute based on the original identity attribute in the original identity certificate, and obtain anonymous identity data including the zero-knowledge proof data of the authentication attribute. It can be understood that the zero-knowledge proof data of the authentication attribute can enable the identity authentication device to confirm that the target user has the authentication attribute without the target device sending the authentication attribute to the identity authentication device.
[0051] In one embodiment, the target device can be a business user, and the identity authentication device can be a business verifier. In the process of business transactions, the target device can trigger the identity authentication device to determine the authentication attributes and challenge values; the target device can use the original identity private key in the original identity data to sign the challenge value, and obtain the challenge value signature information to obtain anonymous identity data including the challenge value signature information and the zero-knowledge proof data of the authentication attributes. It can be understood that the challenge value signature information is used to enable the identity authentication device to determine that the target user undergoing identity authentication is consistent with the user who triggered the identity authentication, that is, the target device is the correct communication object. In one embodiment, during the identity authentication process, the target device can use a knowledge proof mechanism (Schnorr mechanism) based on the discrete logarithm problem, and combine the heuristic transformation (Fiat-Shamir) to convert the interactive zero-knowledge proof into a non-interactive zero-knowledge proof, and cooperate with the identity authentication device to complete the identity authentication.
[0052] In one embodiment, the anonymous identity data includes an anonymous identity key pair. The target device can derive the anonymous identity key pair from the original identity key pair. For example, the target device can use the original identity key pair as an input to a key derivation function, and output the anonymous identity private key and the anonymous identity public key through the key derivation function to obtain the anonymous identity key pair.
[0053] In one embodiment, the anonymous identity data may include zero-knowledge proof data of the original identity certificate. The target device may obtain the authentication attributes sent by the identity authentication device, and generate zero-knowledge proof data of the original identity certificate and the authentication attributes using the identity mixer. It can be understood that the zero-knowledge proof data of the original identity certificate can enable the identity authentication device to confirm that the target user has an authorized original identity certificate when the target device does not send the original identity certificate to the identity authentication device. The original identity certificate is actually a digital certificate generated for the authorization of the original identity data. Only the target device with the original identity certificate can communicate with each other in the blockchain network. Among them, the identity mixer is an anonymous authentication method that is different from the traditional public key infrastructure (PKI) real-name certificate. It has an efficient zero-knowledge proof and a verifiable encryption algorithm. It can prove that the signer has certain attributes without opening the signature, and can achieve the purpose of authentication while hiding some of the user's attributes. In one embodiment, the target device can send the original identity data to the identity authorization device. The identity authorization device can authorize the original identity data and generate authorization signature information to obtain the original identity certificate including the original identity data and the authorization signature information. Among them, the identity authorization device is used to issue the original identity certificate, which is equivalent to the certification authority (CA), that is, the communication authorization agency in the blockchain network. It can be understood that the identity authorization device has an identity authorization certificate including an identity authorization public key and an identity authorization private key. When the identity authorization certificate including the identity authorization public key of the identity authorization device is obtained, the identity authorization public key can be used to verify the original identity certificate issued by the identity authorization device.
[0054] In one embodiment, the identity authorization device can generate an identity authorization key pair of the identity authorization device and an identity supervision key pair of the identity supervision device by agreeing on the authentication strategy and selecting the algorithm public parameters, and obtain an identity authorization certificate of the identity authorization device. It can be understood that the identity authorization key pair includes an identity authorization public key and an identity authorization private key. The identity supervision key pair includes an identity supervision public key and an identity supervision private key. The identity authorization device and the identity supervision device can correspond to the same blockchain node, that is, the steps performed by the identity authorization device and the identity supervision device can be performed by the same device.
[0055] In one embodiment, the identity authorization device can generate an identity authorization key pair (CSK, CPK) and an identity supervision key pair (MSK, MPK) based on the input security parameter λ and the key generation algorithm. Among them, CSK is the identity authorization private key, CPK is the identity authorization public key, MSK is the identity supervision private key, and MPK is the identity supervision public key. It can be understood that the identity authorization key pair is used to generate and verify the original identity certificate. The identity supervision key pair is used to generate and verify anonymous identity certificates. It can be understood that the identity supervision device and the identity authorization device can be deployed separately or jointly according to the business scenario.
[0056] In one embodiment, the identity authorization device can synchronize the identity authorization public key and the identity supervision public key to any device in the same blockchain network.
[0057] In one embodiment, the identity authorization device and the identity supervision device may correspond to different blockchain nodes, and the identity authorization device may generate an identity authorization certificate including an identity authorization key pair. The identity supervision device may apply to the identity authorization device for an identity supervision certificate, and after the application is approved, obtain an identity supervision certificate including an identity supervision key pair. It is understood that the identity authorization device may also directly generate an identity supervision certificate including an identity supervision key pair, and synchronize the identity supervision certificate to the identity supervision device.
[0058] In one embodiment, the identity authorization device can synchronize the identity authorization public key to any device in the same blockchain network. The identity authorization device can also synchronize the identity supervision public key to any device in the same blockchain network. It is understood that the identity supervision device can synchronize the identity supervision public key to any device in the same blockchain network.
[0059] In one embodiment, the target device may generate an original identity certificate request (CertQuest) by registering the original identity attributes of the target user. The target device may send the original identity certificate request to the identity authorization device so that the identity authorization device verifies the original identity certificate request. After the verification is passed, the original identity attributes of the target user are saved and an original identity certificate is generated. It is understandable that the target device may generate an original identity certificate request including information such as the original identity public key based on the registered original identity private key and original identity attributes, as well as the random value sent by the identity authorization device. If the original identity certificate request is not legal, the identity authorization device may reject the request.
[0060] In one embodiment, the original identity certificate request includes the original signature information generated by the target device using the original identity private key, and the identity authorization device can use the original identity public key to verify the original signature information in the original identity certificate request. It can be understood that the original signature information is generated by the target device using the original identity private key, and is used to instruct the identity authorization device to determine the target user corresponding to the original identity request. After the verification is passed, the identity authorization device can generate the original identity certificate based on the identity authorization key pair (CSK, CPK), the original identity certificate request (CertQuest), and the original identity attributes, and send it to the target device.
[0061] In one embodiment, the target device can use the identity authorization public key to verify the received original identity certificate, and after determining that the original identity certificate is issued by the identity authorization device, save the original identity certificate, otherwise apply for the original identity certificate from the identity authorization device again.
[0062] Step 204: Obtain supervision signature information generated by the identity supervision device for the anonymous identity data, so as to obtain an anonymous identity certificate according to the supervision signature information and the anonymous identity data.
[0063] The identity supervision device is used to supervise the anonymous identity data corresponding to the target user. The supervision signature information is used to indicate that the anonymous identity data has been supervised by the identity supervision device.
[0064] Specifically, the target device may send the anonymous identity public key to the identity supervision device, so that the identity supervision device generates supervision signature information for the anonymous identity public key. The target device may obtain an anonymous identity certificate including the supervision signature information and the anonymous identity data.
[0065] Step 206, sending the anonymous identity certificate to the identity authentication device, so that the identity authentication device authenticates the target user based on the supervision signature information and anonymous identity data in the anonymous identity certificate; after the identity authentication is passed, obtaining the authentication authorization information sent by the identity authentication device.
[0066] The authentication authorization information is used to indicate that the identity authentication of the target user has passed.
[0067] Specifically, the target device may send an anonymous identity certificate to the identity authentication device. The identity authentication device may perform regulatory validity authentication on the anonymous identity certificate based on the regulatory signature information in the anonymous identity certificate, and determine whether the target user has the authentication attribute based on the anonymous identity data. If the regulatory validity is passed and the target user has the authentication attribute, it is determined that the identity authentication of the target user is passed. After the identity authentication is passed, the identity authentication device generates authentication authorization information. The target device may obtain the authentication authorization information sent by the identity authentication device.
[0068] In the above-mentioned identity authentication method, anonymous identity data is generated based on authentication attributes and the original identity certificate; authentication attributes are identity attributes that need to be authenticated when the identity authentication device authenticates the target user; the supervision signature information generated by the identity supervision device for the anonymous identity data is obtained to obtain an anonymous identity certificate based on the supervision signature information and the anonymous identity data; the identity supervision device is used to supervise the anonymous identity data corresponding to the target user; the anonymous identity certificate is sent to the identity authentication device so that the identity authentication device authenticates the target user based on the supervision signature information and the anonymous identity data in the anonymous identity certificate; after the identity authentication is passed, the authentication authorization information sent by the identity authentication device is obtained. The anonymous identity data corresponding to the target user is signed by the identity supervision device to obtain the supervision signature information. The identity authentication device can authenticate the target user based on the supervision signature information and the anonymous identity data in the anonymous identity certificate, thereby completing the identity authentication of the target user without completely exposing the user attribute information, thereby improving security.
[0069] In addition, although the identity mixer can convert the certificate into a valid mark of any pseudonym of the user, these marks only contain the authentication attributes in the original certificate, and the converted marks can still be verified under the identity authorization public key (CA public key), this method will make the pseudonym identity unable to be effectively supervised. Supervising anonymous identity information through identity supervision equipment can further improve security.
[0070] In one embodiment, the anonymous identity data includes an anonymous identity public key; obtaining the supervision signature information generated by the identity supervision device for the anonymous identity data includes: signing the anonymous identity public key to obtain anonymous public key signature information; sending the anonymous public key signature information to the identity supervision device, so that the identity supervision device performs identity validity authentication on the anonymous identity public key based on the anonymous public key signature information; after the identity validity authentication is passed, obtaining the supervision signature information generated by the identity supervision device for the anonymous identity public key.
[0071] The anonymous public key signature information is used to indicate that the anonymous identity public key belongs to the target user.
[0072] Specifically, the target device can use the original identity private key to sign the anonymous identity public key to obtain anonymous public key signature information. The target device can send anonymous public key signature information and anonymous identity public key to the identity supervision device. The identity supervision device can use the original identity public key to parse the anonymous public key signature information, and perform identity validity authentication on the anonymous identity public key by comparing the parsed supervision signature information and the anonymous identity public key. After the identity validity authentication is passed, the target device can obtain the supervision signature information generated by the identity supervision device for the anonymous identity public key.
[0073] In one embodiment, the identity supervision device may determine that the anonymous identity public key belongs to the target user when determining that the parsed supervision signature information is consistent with the anonymous identity public key, so as to perform identity validity authentication on the anonymous identity public key.
[0074] In one embodiment, after the identity validity authentication is passed, the identity supervision device may use the identity supervision public key to sign the anonymous identity public key to generate supervision signature information.
[0075] In this embodiment, by signing the anonymous public key, anonymous public key signature information is obtained, and the identity supervision device performs identity validity authentication on the anonymous public key based on the anonymous public key signature information, so that after the identity validity authentication is passed, the supervision signature information generated by the identity supervision device for the anonymous public key can be obtained, thereby realizing the supervision of the anonymous public key and improving security. And it is convenient for the identity authentication device to perform identity authentication locally based on the supervision signature information in the future.
[0076] In one embodiment, sending anonymous public key signature information to an identity supervision device so that the identity supervision device performs identity validity authentication on the anonymous identity public key based on the anonymous public key signature information includes: sending anonymous public key signature information to the identity supervision device so that the identity supervision device determines that the anonymous identity public key belongs to the target user by parsing the anonymous public key signature information, and when it is determined that the anonymous identity public key belongs to the target user and the original identity certificate is valid, determining that the identity validity authentication of the anonymous identity public key has passed.
[0077] The validity of the original identity certificate means that the target user has not revoked the original identity certificate when the authorization of the original identity certificate by the identity authorization device is valid.
[0078] Specifically, the target device can send anonymous public key signature information and anonymous identity public key to the identity supervision device. The identity supervision device can use the original identity public key of the target user to parse the anonymous public key signature information, and when it is determined that the parsed anonymous public key signature information is consistent with the anonymous identity public key, it is determined that the anonymous identity public key belongs to the target user. When it is determined that the anonymous identity public key belongs to the target user, the identity supervision device can verify whether the original identity certificate of the target user has been revoked, that is, whether the authorization of the original identity certificate is valid. If the original identity certificate has not been revoked, the identity supervision device can determine that the original identity certificate is valid to determine that the identity validity authentication of the anonymous identity public key has passed.
[0079] In this embodiment, anonymous public key signature information is sent to the identity supervision device, so that the identity supervision device determines that the anonymous identity public key belongs to the target user by parsing the anonymous public key signature information, and when it is determined that the anonymous identity public key belongs to the target user and the original identity certificate is valid, the identity validity authentication of the anonymous identity public key is determined to be passed, and subsequently supervision signature information is generated for the anonymous identity public key to supervise the anonymous identity public key, thereby improving security.
[0080] In one embodiment, the original identity certificate is a digital certificate generated based on the original identity data of the target user; after the identity validity authentication is passed, obtaining the supervision signature information generated by the identity supervision device for the anonymous identity public key includes: after the identity validity authentication is passed, the identity supervision device generates supervision signature information with a validity period for the anonymous identity public key, and stores the anonymous identity public key and the original identity data of the target user in correspondence.
[0081] Specifically, after the identity validity authentication is passed, the identity supervision device can use the identity supervision private key to sign the anonymous identity public key to generate supervision signature information with an expiration date. The identity supervision device can store the anonymous identity public key and the original identity data of the target user in correspondence. It can be understood that the supervision signature information is accompanied by an expiration date, which allows the identity authentication device to perform offline identity authentication on the target user within the validity period of the supervision signature information.
[0082] In one embodiment, the original identity data may correspond to an identity identifier. It is understood that the identity management device may store the identity identifier and the original identity data in correspondence. The identity management device may store the anonymous identity public key and the corresponding identity identifier in correspondence.
[0083] In one embodiment, the identity authorization device may store the identity identifier and the original identity data in correspondence. The identity supervision device may only store the identity identifier without storing the original identity data. It is understood that the identity supervision device may send the identity identifier to the identity authorization device to obtain the corresponding original identity data.
[0084] In this embodiment, after the identity validity authentication is passed, the identity supervision device generates supervision signature information with a validity period for the anonymous identity public key, and stores the anonymous identity public key and the original identity data of the target user in correspondence, so that the identity authentication device performs offline identity authentication on the target user within the validity period of the supervision signature information, without the need for cooperation and verification of the identity supervision device, and decoupling identity supervision and identity authentication, thereby improving adaptability.
[0085] In one embodiment, the method also includes an identity tracking step for the target user; the identity tracking step includes: after the identity supervision device receives the anonymous identity public key and supervision signature information sent by the identity authentication device, the identity supervision device performs signature validity authentication on the supervision signature information, and when the signature validity authentication passes, determines the original identity data stored corresponding to the anonymous identity public key to obtain the identity tracking result for the target user.
[0086] Specifically, the identity authentication device can send an anonymous identity public key and supervision signature information to the supervision device, triggering the identity supervision device to track the identity of the target user. It can be understood that the target device uses the target user's anonymous identity certificate to obtain authentication authorization information from the identity authentication device. When a dispute occurs later, the identity supervision device is required to track the original identity data of the target user. The identity supervision device can use the identity supervision private key to parse the supervision signature information, and perform signature validity authentication on the supervision signature information by comparing the parsed supervision signature information with the anonymous identity public key. It can be understood that when the parsed supervision signature information is consistent with the anonymous identity public key, the identity supervision device can determine that the signature validity authentication is passed. When the signature validity authentication is passed, the identity supervision device can determine the original identity data stored corresponding to the anonymous identity public key to obtain the identity tracking result for the target user.
[0087] In one embodiment, the identity supervision device may use the identity supervision public key to parse the supervision signature information to obtain the parsed supervision signature information.
[0088] In one embodiment, after receiving the anonymous identity public key and supervision signature information sent by the identity authentication device, the identity supervision device sends a tracking code to the identity authentication device. After receiving the tracking code, the identity authentication device determines that the identity supervision device has accepted the identity tracking for the target user. It can be understood that the subsequent identity authentication device can obtain the tracking result of the identity supervision device for the target user based on the tracking code to determine the true identity of the target user based on the tracking result.
[0089] In one embodiment, Figure 3As shown, a simple flow chart of the identity authentication method is provided. The identity supervision device and the identity authorization device can be devices located at the same blockchain node. First, the identity authorization device creates an identity authorization key pair, and the target device sends an original identity certificate request to the identity authorization device. The original identity certificate request can carry the original identity attributes of the target user and the original signature information obtained by signing with the original identity private key. The identity authorization device can verify whether the original identity certificate request is legal by parsing the original signature information using the original identity public key. If it is legal, the original identity certificate is issued to the target device according to the original identity attributes, and the original identity attributes are saved. It can be understood that the identity authorization device can generate an identity identifier of the target user, and store the identity identifier and the original identity attributes in correspondence. The target device can verify whether the original identity certificate is legal by parsing the authorization signature information in the original identity certificate using the identity authorization public key.
[0090] During a business transaction, the target device can generate anonymous identity data, and after obtaining the regulatory signature information generated by the identity supervision device, generate an anonymous identity certificate. The identity authentication device can authenticate the target user based on the regulatory signature information and anonymous identity data in the anonymous identity certificate. If the identity authentication is successful, the authentication authorization information is sent to the target device. It can be understood that the authentication authorization information can be a business authorization token corresponding to this business transaction, and the business authorization token is used to indicate that the target user has the authority to use the corresponding business. When there is a need to track the identity of an anonymous identity certificate due to business disputes or other reasons, the identity supervision device can determine the original identity data of the target user based on the regulatory signature information and anonymous identity public key sent by the identity authentication device to achieve identity tracking of the target user.
[0091] In this embodiment, after receiving the anonymous identity public key and supervision signature information sent by the identity authentication device, the identity supervision device performs signature validity authentication on the supervision signature information, and if the signature validity authentication passes, determines the original identity data stored corresponding to the anonymous identity public key to obtain the identity tracking result for the target user, thereby realizing identity tracking of the target user. Through prior supervision and post-tracking, the security of identity authentication can be improved.
[0092] In one embodiment, the anonymous identity data includes zero-knowledge proof data; sending an anonymous identity certificate to an identity authentication device so that the identity authentication device performs identity authentication on a target user based on the regulatory signature information and the anonymous identity data in the anonymous identity certificate includes: sending an anonymous identity certificate to the identity authentication device so that the identity authentication device performs regulatory validity authentication on the anonymous identity certificate by locally parsing the regulatory signature information in the anonymous identity certificate, and when the regulatory validity authentication passes and it is determined based on the zero-knowledge proof data that the target user has authentication attributes, the identity authentication of the target user is determined to pass.
[0093] Among them, zero-knowledge proof data is used to enable the identity authentication device to believe that a certain assertion is correct without providing any useful information to the identity authentication device.
[0094] Specifically, the target device can send an anonymous identity certificate and challenge value signature information to the identity authentication device. The anonymous identity data includes zero-knowledge proof data of the authentication attribute, regulatory signature information, and the anonymous identity public key. The identity authentication device can verify the identity consistency of the target user by parsing the challenge value signature information. After the identity consistency verification, the identity authentication device can use the identity regulatory public key locally to parse the regulatory signature information in the anonymous identity certificate. When the parsed regulatory signature information is consistent with the anonymous identity public key, it is determined that the regulatory validity authentication of the anonymous identity certificate has passed. When the regulatory validity authentication has passed, the identity authentication device can verify the zero-knowledge proof data of the authentication attribute to determine that the target user has the authentication attribute, thereby determining that the identity authentication of the target user has passed.
[0095] In one embodiment, the anonymous identity data includes the original identity certificate and zero-knowledge proof data of the authentication attribute. The identity authentication device can determine that the original identity certificate of the target user is valid by verifying the zero-knowledge proof data, that is, the target user has the authority granted by the identity authorization device, and the target user has the authentication attribute. When the identity consistency verification passes, the supervision validity authentication passes, the original identity certificate of the target user is valid, and the target user has the authentication attribute, it is determined that the identity authentication of the target user passes.
[0096] In one embodiment, the identity authentication device can use the anonymous identity public key to parse the challenge value signature information, and by comparing whether the parsed challenge value signature information is consistent with the challenge value, determine that the target device that sends the anonymous identity certificate is the device of the target user to be authenticated. When the parsed challenge value signature information is consistent with the challenge value, it is determined that the identity consistency verification of the target user has passed. It can be understood that the anonymous identity key pair is derived from the original identity key pair, and the anonymous identity public key can parse the signature information obtained by signing with the original identity private key.
[0097] In one embodiment, the identity authentication device can perform identity authentication on multiple target users at the same time. The identity authentication device can determine multiple anonymous identity certificates corresponding to the multiple target users, and obtain aggregate signature information corresponding to the multiple anonymous identity certificates by aggregating the regulatory signature information in the multiple anonymous identity certificates. The identity authentication device can perform regulatory validity authentication on multiple anonymous identity certificates at the same time by parsing the aggregate signature. Compared with the method of parsing each regulatory signature information separately, computing resources can be saved.
[0098] In one embodiment, the identity authentication device can use an aggregate signature algorithm to aggregate the regulatory signature information in multiple anonymous identity certificates to generate aggregate signature information. The aggregate signature algorithm (Boneh-Lynn-Shacham signature algorithm) is an algorithm that can realize signature aggregation and key aggregation, that is, multiple keys can be aggregated into one key, and multiple signatures can be aggregated into one signature. The aggregate signature algorithm is a short signature scheme constructed based on bilinear mapping, and one of its characteristics is that it can be used to construct aggregate signatures. Bilinear mapping is a binary mapping. As a construction tool for cryptographic algorithms, it is widely used in various blockchain platforms. For example, technical solutions such as zero-knowledge proofs and aggregate signatures are mostly constructed based on bilinear pairings.
[0099] In this embodiment, an anonymous identity certificate is sent to the identity authentication device, so that the identity authentication device performs regulatory validity authentication on the anonymous identity certificate by locally parsing the regulatory signature information in the anonymous identity certificate, and when the regulatory validity authentication passes and it is determined based on zero-knowledge proof data that the target user has the authentication attribute, the identity authentication of the target user is determined to be successful. This enables the identity authentication device to locally and individually authenticate the target user within the validity period of the regulatory signature information, thereby improving adaptability.
[0100] In one embodiment, Figure 4 As shown, a timing diagram of identity authentication is provided. The identity supervision device and the identity authorization device are located at trusted nodes in the blockchain network. The identity authorization device can generate an identity authorization key pair of the identity authorization device and an identity supervision key pair of the identity supervision device by agreeing on the authentication strategy and selecting the algorithm public parameters, and issue an identity authorization certificate. The identity authorization device can synchronize the identity authorization certificate including the identity authorization public key to the identity supervision device, the identity authentication device and the target device.
[0101] The target user can register the original identity attribute through the target device and generate an original identity certificate request. The identity authorization device can verify the original identity certificate request and generate an original identity certificate after the verification is successful. The target device can verify the original identity certificate sent by the identity authorization device and resend the original identity certificate request if the verification fails.
[0102] During a business transaction, the target device triggers the identity authentication device to authenticate the target user. The identity authentication device can determine the authentication attributes and generate a challenge value. The target device can generate an anonymous identity public key, and use the original identity private key to sign the anonymous identity public key to generate anonymous public key signature information. The target device can use the original identity private key to sign the challenge value to generate challenge value signature information. The anonymous public key signature information is used to instruct the identity supervision device to determine the target user corresponding to the anonymous identity public key. The challenge value signature information is used to indicate to the identity authentication device that the target device is the device of the target user. The target device can send the anonymous identity public key and the anonymous public key signature information to the identity supervision device to apply to the identity supervision device to generate supervision signature information for the anonymous identity public key.
[0103] The identity supervision device can use the original identity public key to parse the anonymous public key signature information to determine that the anonymous identity public key corresponds to the target user, and then use the identity supervision private key to sign the anonymous identity public key to generate supervision signature information. The target device can obtain an anonymous identity certificate including supervision signature information and anonymous identity data.
[0104] The target device can send the anonymous identity certificate and the challenge value signature information to the identity authentication device, and the identity authentication device can authenticate the target user based on the anonymous identity certificate. After the identity authentication is passed, the identity authentication device can send authentication authorization information to the target device. It can be understood that the identity authentication device can aggregate multiple supervision signature information to obtain aggregate signature information to simultaneously authenticate the supervision validity of multiple anonymous identity certificates.
[0105] When a business dispute occurs, the identity authentication device can send the supervision signature information and the anonymous identity public key to the identity supervision device to initiate an identity tracking request for the target user. The identity supervision device can perform signature validity authentication by parsing the supervision signature information, and if the signature validity authentication passes, query the original identity attribute corresponding to the anonymous identity public key, thereby determining the original identity of the target user, that is, the real identity, and obtaining the identity tracking result. The identity supervision device can return the identity tracking result to the identity authentication device. It can be understood that the identity tracking result includes the original identity data of the target user. For example, the identity tracking result includes the original identity certificate of the target user.
[0106] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0107] Based on the same inventive concept, the embodiment of the present application also provides an identity authentication system for implementing the identity authentication method involved above. The implementation scheme for solving the problem provided by the system is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more identity authentication system embodiments provided below can refer to the limitations on the identity authentication method above, and will not be repeated here.
[0108] In one embodiment, Figure 5 As shown, an identity authentication system 500 is provided, including: a target device 502 corresponding to a target user, an identity authentication device 504 and an identity supervision device 506, wherein:
[0109] The target device 502 is used to generate anonymous identity data based on the authentication attribute and the original identity certificate; the authentication attribute is the identity attribute that needs to be authenticated when the identity authentication device 504 authenticates the target user;
[0110] The identity supervision device 506 is used to supervise the signature information generated for the anonymous identity data; the identity supervision device 506 is used to supervise the anonymous identity data corresponding to the target user;
[0111] The target device 502 is also used to obtain the supervision signature information to obtain the anonymous identity certificate according to the supervision signature information and the anonymous identity data; and send the anonymous identity certificate to the identity authentication device 504;
[0112] The identity authentication device 504 is used to authenticate the target user based on the supervision signature information and anonymous identity data in the anonymous identity certificate; after the identity authentication is passed, the authentication authorization information is sent to the target device 502;
[0113] The target device 502 is also used to obtain the authentication authorization information sent by the identity authentication device 504.
[0114] In one of the embodiments, the anonymous identity data includes an anonymous identity public key; the target device 502 is also used to sign the anonymous identity public key to obtain anonymous public key signature information; and send the anonymous public key signature information to the identity supervision device 506; the identity supervision device 506 is also used to authenticate the validity of the anonymous identity public key based on the anonymous public key signature information; the target device 502 is also used to obtain the supervision signature information generated by the identity supervision device 506 for the anonymous identity public key after the identity validity authentication is passed.
[0115] In one of the embodiments, the target device 502 is further used to send anonymous public key signature information to the identity supervision device 506; the identity supervision device 506 is further used to determine that the anonymous identity public key belongs to the target user by parsing the anonymous public key signature information, and when it is determined that the anonymous identity public key belongs to the target user and the original identity certificate is valid, determine that the identity validity authentication of the anonymous identity public key has passed.
[0116] In one of the embodiments, the original identity certificate is a digital certificate generated based on the original identity data of the target user; after the identity validity authentication is passed, the identity supervision device 506 is also used to generate supervision signature information with a validity period for the anonymous identity public key, and store the anonymous identity public key and the original identity data of the target user in correspondence.
[0117] In one of the embodiments, the identity supervision device 506 is also used to perform signature validity authentication on the supervision signature information after receiving the anonymous identity public key and supervision signature information sent by the identity authentication device 504, and when the signature validity authentication passes, determine the original identity data stored corresponding to the anonymous identity public key to obtain the identity tracking result for the target user.
[0118] In one of the embodiments, the anonymous identity data includes zero-knowledge proof data; the target device 502 is further used to send an anonymous identity certificate to the identity authentication device 504; the identity authentication device 504 is further used to perform regulatory validity authentication on the anonymous identity certificate by locally parsing the regulatory signature information in the anonymous identity certificate, and when the regulatory validity authentication passes and it is determined based on the zero-knowledge proof data that the target user has the authentication attribute, it is determined that the identity authentication of the target user is passed.
[0119] Each device in the above identity authentication system can be implemented in whole or in part by software, hardware, or a combination thereof. Each device can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute the operations corresponding to each device above.
[0120] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 6 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store anonymous identity data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, an identity authentication method is implemented.
[0121] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 7 As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected via a system bus, and the communication interface, the display unit and the input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, an identity authentication method is implemented. The display unit of the computer device is used to form a visually visible image, and can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covered on the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse, etc.
[0122] Those skilled in the art will understand that Figure 6 and Figure 7The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0123] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above-mentioned method embodiments when executing the computer program.
[0124] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0125] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0126] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.
[0127] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.
[0128] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0129] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. An identity authentication method, It is characterized in that The method is performed by a target device, and includes: Generate anonymous identity data based on authentication attributes and the original identity certificate; the authentication attributes are identity attributes that need to be authenticated when the identity authentication device authenticates the target user; Obtaining supervision signature information generated by the identity supervision device for the anonymous identity data, so as to obtain an anonymous identity certificate according to the supervision signature information and the anonymous identity data; the identity supervision device is used to supervise the anonymous identity data corresponding to the target user; Sending the anonymous identity certificate to an identity authentication device, so that the identity authentication device performs identity authentication on the target user based on the supervision signature information in the anonymous identity certificate and the anonymous identity data; After the identity authentication is passed, the authentication authorization information sent by the identity authentication device is obtained.
2. The method according to claim 1, It is characterized in that The anonymous identity data includes an anonymous identity public key; the supervision signature information generated by the identity supervision device for the anonymous identity data includes: Signing the anonymous identity public key to obtain anonymous public key signature information; Sending the anonymous public key signature information to an identity supervision device, so that the identity supervision device performs identity validity authentication on the anonymous identity public key based on the anonymous public key signature information; After the identity validity authentication is passed, the supervision signature information generated by the identity supervision device for the anonymous identity public key is obtained.
3. The method according to claim 2, It is characterized in that The sending of the anonymous public key signature information to the identity supervision device so that the identity supervision device performs identity validity authentication on the anonymous identity public key based on the anonymous public key signature information includes: The anonymous public key signature information is sent to the identity supervision device, so that the identity supervision device determines that the anonymous identity public key belongs to the target user by parsing the anonymous public key signature information, and when it is determined that the anonymous identity public key belongs to the target user and the original identity certificate is valid, determines that the identity validity authentication of the anonymous identity public key is passed.
4. The method according to claim 2, It is characterized in that The original identity certificate is a digital certificate generated based on the original identity data of the target user; After the identity validity authentication is passed, obtaining the supervision signature information generated by the identity supervision device for the anonymous identity public key includes: After the identity validity authentication is passed, the identity supervision device generates supervision signature information with a validity period for the anonymous identity public key, and stores the anonymous identity public key and the original identity data of the target user in correspondence.
5. The method according to claim 4, It is characterized in that The method further comprises an identity tracking step for the target user; the identity tracking step comprises: After receiving the anonymous identity public key and supervision signature information sent by the identity authentication device, the identity supervision device performs signature validity authentication on the supervision signature information, and if the signature validity authentication passes, determines the original identity data stored corresponding to the anonymous identity public key to obtain the identity tracking result for the target user.
6. The method according to any one of claims 1 to 5, It is characterized in that The anonymous identity data includes zero-knowledge proof data; sending the anonymous identity certificate to the identity authentication device so that the identity authentication device performs identity authentication on the target user based on the supervision signature information in the anonymous identity certificate and the anonymous identity data includes: The anonymous identity certificate is sent to the identity authentication device, so that the identity authentication device performs supervision validity authentication on the anonymous identity certificate by locally parsing the supervision signature information in the anonymous identity certificate, and when the supervision validity authentication passes and it is determined based on zero-knowledge proof data that the target user has authentication attributes, it is determined that the identity authentication of the target user is successful.
7. An identity authentication system, It is characterized in that The system includes a target device, an identity authentication device and an identity supervision device corresponding to the target user; The target device is used to generate anonymous identity data based on the authentication attribute and the original identity certificate; The authentication attribute is an identity attribute that needs to be authenticated when the identity authentication device authenticates the target user; The identity supervision device is used to generate supervision signature information for the anonymous identity data; the identity supervision device is used to supervise the anonymous identity data corresponding to the target user; The target device is further used to obtain the supervision signature information to obtain an anonymous identity certificate according to the supervision signature information and the anonymous identity data; and send the anonymous identity certificate to the identity authentication device; The identity authentication device is used to authenticate the target user based on the supervision signature information in the anonymous identity certificate and the anonymous identity data; after the identity authentication is passed, the authentication authorization information is sent to the target device; The target device is also used to obtain the authentication authorization information sent by the identity authentication device.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program. It is characterized in that When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, It is characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product comprising a computer program, It is characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Traceable attribute signature method without trusted center
CN105812144A
Supervisable anonymous authentication method based on zero knowledge proof
CN109450645A