A Regulatable and Revocable Anonymous Authentication Method

Through an improved anonymous identity authentication method, the non-interactive zero-knowledge proof protocol and improved protocol are used to achieve traceability and revocation of user anonymous identity information on the basis of protecting user identity privacy, solving the problem of user anonymous identity tracking.

CN115277018BActive Publication Date: 2025-05-30HANGZHOU DIANZI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210901834.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-28
Publication Date
2025-05-30
Estimated Expiration
2042-07-28

AI Technical Summary

Technical Problem

On the basis of protecting user identity privacy, how to achieve traceable needs for users’ anonymous identity information, especially when users may engage in illegal activities.

Method used

A supervisory and revocable anonymous identity authentication method is proposed, using a non-interactive zero-knowledge proof protocol to achieve anonymity of user identity, and tracing of anonymous identity through improved protocols. The method includes the initialization phase, the identity registration phase, the proof generation phase, the proof verification phase, the identity tracking phase, and the identity revocation phase.

Benefits of technology

It realizes the function of tracking the user's anonymous identity information while protecting the user's identity privacy, ensuring that the user can track his true identity when he engages in illegal activities, and provides an identity revocation mechanism to enhance the user's ability to self-manage the identity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115277018B_ABST
    Figure CN115277018B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for supervised and revocable anonymous identity authentication, including: an initialization stage, an identity registration stage, a proof generation stage, a proof verification stage, an identity tracing stage, and an identity revocation stage. The present invention uses a non-interactive zero-knowledge proof protocol to achieve the anonymity of user identities, so that the verifier cannot obtain the true information of the user from the anonymous identity. At the same time, we have improved this protocol to enable the traceable nature of the user's anonymous identity. In addition, for the convenience of users' self-management of their identities, we have implemented the revocable nature of the user's identity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and particularly to a traceable and revocable anonymous identity authentication method. Background Art

[0002] In a biometric-based identity authentication scheme, a user needs to register biometric information with a service provider. If the user's biometric information stored at the service provider is leaked, it will have an adverse impact on the user. Therefore, the user does not want their biometric information to be stored at the service provider. At the same time, the user does not want to disclose their true identity information during the identity authentication process. By using anonymous authentication technology, it can be ensured that the user's identity information will not be leaked during the identity authentication process. If the user engages in illegal activities, it will be difficult to hold them accountable. Based on this, how to achieve the traceability requirement for the user's anonymous identity information on the basis of protecting the user's identity privacy has become the focus of attention in the industry. Summary of the Invention

[0003] In response to the need to achieve traceability for the user's anonymous identity information on the basis of protecting the user's identity privacy, the present invention proposes a traceable and revocable anonymous identity authentication method, including the following steps: Step 1 Initialization Phase

[0004] 1.1 The regulatory party constructs a quadratic arithmetic program according to the binary relation R

[0005] where p is a large prime number, and are groups of order p. G is the generator of and H is the generator of and e is the generator of .

[0006] 1.2 The regulatory party calculates the polynomials s i (X,Y) and s m+j (X,Y). Where

[0007] s i (X,Y) = w i (X)Y 2 + u i (X)Y 3 + v i (X)Y 4 , i = 0,.., m, s m+j (X,Y) = t(X)Y j+1 , j = 1, 2, 3.

[0008] 1.3 The regulatory party calculates the polynomials n 1 (X,Y),..., n3d-m+l (X, Y) such that

[0009] For i = {l + 1,..., m + 3} and k = {1,..., 3d - m + l}, we have s i (X, Y) · n k (X, Y) with respect to X d Y 4 the coefficients on are all 0;

[0010] For all there exists k ∈ {1,..., 3d - m + l} such that p(X, Y) · Y 2 · n k (X, Y) in X d Y 4 the coefficients on are all non - zero.

[0011] 1.4 The regulator calculates the polynomial

[0012] 1.5 The regulator randomly selects parameters (x, y, z), calculates the common reference string crs according to QAP QAP and publishes it to the whole network. crs QAP is as follows:

[0013]

[0014] 1.6 The regulator generates random numbers (y 1 ,..., y n , O) according to the binary relation R, which we regard as the verification key of the service provider. For convenience, we use the symbol u = (a 1 ,..., a l ) to represent it. When receiving the registration request from the service provider, after the regulator approves it, it will provide the verification key for it to provide anonymous identity authentication services for users.

[0015] Step 2 Identity registration phase

[0016] 2.1 User identity registration

[0017] Before the user conducts anonymous identity authentication with the service provider, the user needs to register their identity information with the regulator.

[0018] The regulator needs to collect the user's biometric information, the password pw and H entered by the user R , where R is a value randomly generated by the user. In this scheme, the user's fingerprint image is used as their biometric information.

[0019] 2.1.1 Image pre - processing

[0020] After obtaining the user's fingerprint image, the supervisor first performs grayscale processing on the image to convert the color image into a grayscale image. Secondly, noise reduction processing is performed on the image to remove the influence of noise interference from the imaging device and the external environment during the acquisition process. Finally, histogram equalization processing is performed on the image to increase the local contrast of the image.

[0021] 2.1.2 Feature Extraction

[0022] The supervisor uses the FingerCode feature extraction mechanism to represent the features extracted from the processed user fingerprint image as Γ=(x 1 ,...,x n ). Where x i is an 8-bit integer, 0 < i < n.

[0023] 2.1.3 Calculate the Identity Identifier

[0024] The supervisor uses the extracted fingerprint features and the password entered by the user to calculate the user's identity identifier. Note: This identity identifier can only be known by the user. Once the identity identifier is leaked, the user's identity information will be exploited by lawbreakers.

[0025] The calculation process of the identity identifier is as follows:

[0026] x 1 y 1 +x 2 y 2 +...+x n y n +pw + v′ = O mod p

[0027] Where p is a large prime number generated in the initialization phase, (y 1 ,...,y n ,O) is the verification key randomly selected by the supervisor, (x 1 ,...,x n ) is the feature information extracted from the user fingerprint image, pw is the password entered by the user, and v′ is the difference.

[0028] Finally, the user's identity identifier (x 1 ,...,x n ,pw,v′,x 1 ·y 1 ,...,x n ·y n ) is obtained. For convenience, we represent the user's identity identifier as w=(a l+1 ,...,a m ).

[0029] 2.1.4 Generate Identity Tags and Store Identity Information

[0030] The regulatory party generates a unique identity tag U for the user i , and calculates using crs and the user identity identifier w Finally, the regulatory party stores the user's identity tag U i , H R , and locally. Sends the user identity tag U i and the user identity identifier w and the verification key u to the user.

[0031] 2.2 Service Provider Identity Registration

[0032] Before providing anonymous identity authentication services for users, the service provider must register its identity information with the regulatory party. The service provider sends identity information such as name, address, and email to the regulatory party. After the regulatory party's review and approval, it stores the information locally and sends the verification key u = (a 1 ,..., a l ) to the service provider. The service provider can use the verification key to verify whether the anonymous identity sent by the user is legal. At the same time, the service provider cannot find the user's real identity information from the identity proof sent by the user.

[0033] Step 3 Proof Generation Phase

[0034] 3.1 The user parses the identity identifier (a l+1 ,..., a m ) ← w and the verification key (a 1 ,..., a l ) ← u generated by the regulatory party. And set a 0 = 1.

[0035] 3.2 The user calculates the polynomial q(x) according to the above information and the QAP publicly available by the regulatory party. Where the polynomial

[0036] 3.3 The user uses crs QAP and q(x) to calculate the parameter G q(x)y . Sends G q(x)y and U i to the regulatory party. The regulatory party stores G q(x)y in the local information corresponding to U i .

[0037] 3.4 When required for identity authentication, the user selects a random number and calculates the anonymous identity proof B ← H b(x,y)and C←G c(x,y,z) Among them,

[0038]

[0039]

[0040]

[0041]

[0042] 3.5 The user sends the anonymous identity proof π=(A 1 , A 2 , B, C) to the service provider.

[0043] Step 4: Proof verification stage

[0044] 4.1 When the service provider receives the verification key (a 1 ,..., a l )←u generated by the regulatory party and the anonymous identity proof π=(A 1 , A 2 , B, C) sent by the user, set the parameter a 0 =1.

[0045] 4.2 The service provider first determines whether the equation e(A 1 ·A 2 , H)=e(G, B) holds. If it does not hold, the verification fails and an authentication failure message is returned to the user. Otherwise, proceed to the next step.

[0046] 4.3 The service provider determines whether the following equations hold,

[0047]

[0048] If the equations hold, the verification is successful and an authentication success message is returned to the user; otherwise, an authentication failure message is returned.

[0049] Step 5: Identity tracing stage

[0050] If the user engages in illegal activities, the service provider can send part of the information A 2 of the anonymous identity proof sent by the user to the regulatory party. The regulatory party can find the user's real identity based on this information.

[0051] The regulatory party uses the information G q(x)y stored locally and the A 2 sent by the service provider for calculation to obtain Φ.

[0052] Among them

[0053]

[0054] Finally, the regulatory party combines Φ with the local G q(x)y corresponding for comparison. If they are the same, the record is determined to be the user's identity information; otherwise, the next record is calculated.

[0055] Step 6: Identity revocation phase

[0056] If the user wants to revoke the identity information registered with the regulatory party, the user can submit an identity revocation application to the regulatory party.

[0057] 6.1 The user uses a biometric scanning device to obtain their fingerprint image and uses the FingerCode feature extraction mechanism to extract the feature information (y 1 ,..., y n ) of the fingerprint.

[0058] 6.2 The user uses the generators G and H of and in the publicly available QAP of the regulatory party to encrypt the extracted fingerprint feature information to obtain the parameter s. Where r i is a random number selected by the user, 1 ≤ i ≤ n + 1, and r 1 +... + r n + r n+1 = R / 2. (x 1 ,..., x n ) is part of the user identity identifier and is also the fingerprint feature information extracted when the user registered their identity. Finally, the user sends the identity tag U i and the parameter s to the regulatory party.

[0059] 6.3 After receiving the identity revocation application sent by the user, the regulatory party will find the corresponding parameters i and H in the local database based on the user identity identifier U R . Finally, the parameter G γ is calculated, where

[0060]

[0061] 6.4 The regulatory party determines whether G γ is within the set . If it exists, it is determined that the user's identity information is genuine and the identity information stored locally is revoked. Otherwise, a verification failure is returned to the user and revocation is not possible. Where Δ is the threshold for determining whether two fingerprints are similar.

[0062] The substantial feature of the present invention lies in: using a non-interactive zero-knowledge proof protocol to achieve the anonymity of user identities, so that the verifier cannot obtain the real information of the user from the anonymous identity. At the same time, we have improved this protocol to enable the traceable property of the anonymous identity of the user. In addition, to facilitate the user's self-management of the identity, we have implemented the revocable property of the user's identity. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 The timing diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0064] Embodiment 1

[0065] To better understand the purpose, structure and function of the present invention, the following further details the method for a supervisable and revocable anonymous identity authentication of the present invention with reference to the attached Figure 1 drawings.

[0066] Step 1 Initialization phase

[0067] 1.1 The supervisor constructs a quadratic arithmetic program according to the binary relation R

[0068] where p is a large prime number, and are groups of order p. G is the generator of , H is the generator of , and e is the generator of .

[0069] 1.2 The supervisor calculates the polynomials s i (X,Y) and s m+j (X,Y). Where

[0070] s i (X,Y) = w i (X)Y 2 + u i (X)Y 3 + v i (X)Y 4 , i = 0,.., m, s m+j (X,Y) = t(X)Y j+1 , j = 1, 2, 3.

[0071] 1.3 The supervisor calculates the polynomials n 1 (X,Y),..., n 3d-m+l (X,Y) such that

[0072] For i = {l + 1,..., m + 3} and k = {1,..., 3d - m + l}, we have s i(X,Y)·n k (X,Y) with respect to X d Y 4 The coefficients on are all 0;

[0073] For all There exists k ∈ {1,..., 3d - m + l} such that p(X,Y)·Y 2 ·n k (X,Y) on X d Y 4 The coefficients on are all non - zero.

[0074] 1.4 The supervisor calculates the polynomial

[0075] 1.5 The supervisor randomly selects the parameters (x, y, z), calculates the common reference string crs according to QAP QAP and publishes it to the whole network. crs QAP is as follows:

[0076]

[0077] 1.6 The supervisor generates random numbers (y 1 ,..., y n , O) according to the binary relation R, which we regard as the verification key of the service provider. For convenience, we use the symbol u = (a 1 ,..., a l ) to represent. When receiving the registration request from the service provider, after the supervisor approves it, it will provide the verification key for it to provide anonymous identity authentication services for users.

[0078] Step 2 Identity registration phase

[0079] 2.1 User identity registration

[0080] Before the user conducts anonymous identity authentication with the service provider, the user needs to register his / her identity information with the supervisor.

[0081] The supervisor needs to collect the user's biometric information, the password pw and H input by the user R , where R is a value randomly generated by the user. In this scheme, the user's fingerprint image is used as his / her biometric information.

[0082] 2.1.1 Image pre - processing

[0083] After obtaining the user's fingerprint image, the supervisor first performs grayscale processing on the image, converting the color image into a grayscale image. Secondly, the supervisor performs noise reduction processing on the image to remove the influence of noise interference from the imaging device and the external environment during the acquisition process. Finally, the supervisor performs histogram equalization processing on the image to increase the local contrast of the image.

[0084] 2.1.2 Feature Extraction

[0085] The regulatory party uses the FingerCode feature extraction mechanism to represent the features extracted from the processed user fingerprint image as Γ=(x 1 ,...,x n ). Where x i is an 8-bit integer, 0 < i < n.

[0086] 2.1.3 Calculate the Identity Identifier

[0087] The regulatory party uses the extracted fingerprint features and the password entered by the user to calculate the user's identity identifier. Note: Only the user can know this identity identifier. Once the identity identifier is leaked, the user's identity information will be exploited by criminals.

[0088] The calculation process of the identity identifier is as follows:

[0089] x 1 y 1 +x 2 y 2 +...+x n y n +pw + v′ = O mod p

[0090] Where p is a large prime number generated in the initialization phase, (y 1 ,...,y n ,O) is a verification key randomly selected by the regulatory party, (x 1 ,...,x n ) is the feature information extracted from the user fingerprint image, pw is the password entered by the user, and v′ is the difference.

[0091] Finally, the user's identity identifier (x 1 ,...,x n ,pw,v′,x 1 ·y 1 ,...,x n ·y n ) is obtained. For convenience, we represent the user's identity identifier as w=(a l+1 ,...,a m ).

[0092] 2.1.4 Generate Identity Tags and Store Identity Information

[0093] The regulatory party generates a unique identity tag U i for the user, and calculates using crs and the user identity identifier w Finally, the regulatory party stores the user's identity tag Ui , H R , and are stored locally. The user identity tag U i and the user identity identifier w and the verification key u are sent to the user.

[0094] 2.2 Service Provider Identity Registration

[0095] Before providing anonymous identity authentication services to users, the service provider must register its identity information with the regulatory party. The service provider sends identity information such as name, address, and email to the regulatory party. After the regulatory party approves the review, it stores the information locally and sends the verification key u = (a 1 ,..., a l ) to the service provider. The service provider can use the verification key to verify whether the anonymous identity sent by the user is legal. At the same time, the service provider cannot find the real identity information of the user from the identity proof sent by the user.

[0096] Step 3 Proof Generation Phase

[0097] 3.1 The user parses the identity identifier (a l+1 ,..., a m ) ← w and the verification key (a 1 ,..., a l ) ← u generated by the regulatory party. And set a 0 = 1.

[0098] 3.2 The user calculates the polynomial q(x) according to the above information and the QAP publicly disclosed by the regulatory party. Among them, the polynomial

[0099] 3.3 The user uses crs QAP and q(x) to calculate the parameter G q(x)y . Send G q(x)y and U i to the regulatory party. The regulatory party stores G q(x)y in the corresponding information of local U i .

[0100] 3.4 When requested for identity authentication, the user selects a random number and calculates the anonymous identity proof B ← H b(x,y) and C ← G c(x,y,z) . Among them,

[0101]

[0102]

[0103]

[0104]

[0105] 3.5 The user sends the anonymous identity proof π = (A 1 , A 2 , B, C) to the service provider.

[0106] Step 4: Proof verification phase

[0107] 4.1 When the service provider receives the verification key (a 1 ,..., a l ) ← u generated by the supervisor and the anonymous identity proof π = (A 1 , A 2 , B, C) sent by the user, set the parameter a 0 = 1.

[0108] 4.2 The service provider first determines whether the equation e(A 1 ·A 2 , H) = e(G, B) holds. If it does not hold, the verification fails and an authentication failure message is returned to the user. Otherwise, proceed to the next step.

[0109] 4.3 The service provider determines whether the following equations hold.

[0110]

[0111] If the equations hold, the verification is successful and an authentication success message is returned to the user; otherwise, an authentication failure message is returned.

[0112] Step 5: Identity tracing phase

[0113] If the user engages in illegal activities, the service provider can send part of the information A 2 of the anonymous identity proof sent by the user to the supervisor. The supervisor can find the user's real identity based on this information.

[0114] The supervisor uses the information G q(x)y stored locally and A 2 sent by the service provider for calculation to obtain Φ.

[0115] Where

[0116]

[0117] Finally, the supervisor compares Φ with the corresponding q(x)y local G If they are the same, the record is determined to be the user's identity information; otherwise, calculate the next record.

[0118] Step 6: Identity revocation phase

[0119] If a user wants to revoke his or her registered identity information to the regulator, the user can submit an identity revocation application to the regulator.

[0120] 6.1 The user uses a biometric scanning device to obtain his fingerprint image and uses the FingerCode feature extraction mechanism to extract the fingerprint feature information (y 1 ,...,y n ).

[0121] 6.2 User use of the QAP published by the supervisor and The generators G and H of encrypt the extracted fingerprint feature information to obtain the parameter s. r i is a random number selected by the user, 1≤i≤n+1, and r 1 +...+r n +r n+1 =R / 2. (x 1 ,...,x n ) is part of the user's identity identifier and is also the fingerprint feature information extracted when the user registers his / her identity. Finally, the user sets the identity tag U i and parameter s are sent to the supervisor.

[0122] 6.3 After receiving the identity revocation application from the user, the supervisor will i Find the corresponding parameters in the local database and H R Finally, calculate the parameter G γ ,in

[0123]

[0124] 6.4 Supervisory Judgment G γ Is it in the collection If it exists, the user's identity information is determined to be authentic and the locally stored identity information is revoked. Otherwise, the user is returned a verification failure and cannot be revoked. Δ is the threshold for determining whether two fingerprints are similar.

Claims

1. A regulatory and revocable anonymous identity authentication method, characterized in that, it includes the following steps: Step 1, initialize and generate a verification key; Step 1.1, the regulator constructs a quadratic arithmetic program according to the binary relation R: where p is a large prime number, and is a group of order p; G is a generator of, H is a generator of, and e is a generator of; Step 1.2, the supervisor calculates the polynomial s i (X, Y) and s m+j (X, Y); where s i (X,Y) = w i (X)Y 2 + u i (X)Y 3 + v i (X)Y 4 , i = 0,.., m, s m+j (X,Y) = t(X)Y j+1 , j = 1, 2, 3; Step 1.3, the regulatory party calculates the polynomial: n 1 (X,Y),…,n 3d-m+l (X,Y), such that for \(i = \{l + 1,\ldots,m + 3\}\) and \(k=\{1,\ldots,3d - m + l\}\), there is \(s\ i (X,Y)\cdot n k (X,Y)\) with respect to \(X\ d Y 4 the coefficients on are all \(0\); For all there exists a \(k\in\{1,\ldots,3d - m + l\}\) such that \(p(X,Y)\cdot Y 2 \(\cdot n k (X,Y)\) has non-zero coefficients in \(X d Y 4 and the coefficients of \(Y\) are all non-zero; Step 1.4, the regulatory party calculates the polynomial: Step 1.5, the supervisor randomly selects parameters (x, y, z) and calculates the common reference string crs according to QAP QAP and announces it to the entire network; crs QAP as follows: Step 1.6, the regulator generates a random number (y 1 , …, y n , O) according to the binary relation R, and regards it as the verification key of the service provider; use the symbol u = (a 1 , …, a l ) to represent; when receiving the registration request of the service provider, after the regulator reviews and approves it, it will provide the verification key for it to provide anonymous identity authentication services for users; Step 2, extract the registered identity features, generate the identity label, and complete the anonymous identity registration; Step 2.1.0, before the user conducts anonymous identity authentication with the service provider, the user first registers their identity information with the regulator; The regulatory party collects the user's biometric information, the password pw and H input by the user R , where R is a value randomly generated by the user; Step 2.1.1, image preprocessing: After obtaining the biometric information image of the user, the regulator first performs grayscale processing on the image to convert the color image into a grayscale image; secondly, performs noise reduction processing on the image to remove the influence of noise interference from the imaging device and the external environment during the acquisition process; finally, performs histogram equalization processing on the image to increase the local contrast of the image; Step 2.1.2, feature extraction: The regulatory party uses the FingerCode feature extraction mechanism to represent the features extracted from the processed user biometric information image as Γ = (x 1 , …, x n ); where x i is an 8-bit integer, 0 < i < n; Step 2.1.3, calculate the identity identifier: The regulator uses the extracted biometric information features and the password input by the user to calculate the user's identity identifier; the calculation process of the identity identifier is as follows: x 1 y 1 +x 2 y 2 +…+x n y n +pw + v' ≡ 0 mod p where p is a large prime number generated in the initialization stage, (y 1 , …, y n , O) is the verification key randomly selected by the supervisor, (x 1 , …, x n ) is the feature information extracted from the user's fingerprint image, pw is the password input by the user, and v' is the difference; the user's identity identifier (x 1 , …, x n , pw, v', x 1 ·y 1 , …, x n ·y n ) is obtained, and the identity identifier is represented as w = (a l+1 , …, a m ); Step 2.1.4, generate an identity tag and store the identity information The regulator generates a unique identity tag U for the user i and calculates using crs and the user identity identifier w Finally, the regulator locally stores the user's identity tag U i , H R , and ; sends the user identity tag U i and the user identity identifier w and the verification key u to the user; Step 2.2, service provider identity registration; Before providing anonymous identity authentication services to users, the service provider registers its identity information with the regulatory authority; the service provider sends identity information such as name, address, and email to the regulatory authority; after the regulatory authority approves the verification, it stores the information locally and sends the verification key u = (a 1 ,…,a l ) to the service provider; the service provider can use the verification key to verify whether the anonymous identity sent by the user is legal; at the same time, the service provider cannot find the true identity information of the user from the identity certificate sent by the user; Step 3, complete the regulator's identification of the user according to the identity tag and the verification key; Step 3.1, the user parses the identity identifiers (a l+1 , …, a m ) ← w and the verification key (a 1 , …, a l ) ← u; and set a 0 = 1; Step 3.2 The user calculates the polynomial q(x) based on the above information and the QAP publicly disclosed by the regulatory party; where the polynomial Step 3.3, the user uses crs QAP and q(x) to calculate the parameter G q(x)y ; Send G q(x)y and U i to the supervisor; The supervisor stores G q(x)y in the corresponding information of the local U i ; Step 3.4, when requested for identity authentication, the user selects a random number and calculates the anonymous identity proof B ← H b(x,y) and C ← G c(x,y,z) ; where Step 3.5, the user sends an anonymous identity proof π = (A 1 , A 2 , B, C); Step 4, verify the identification result of Step 3; Step 4.1, when the service provider receives the verification key (a 1 , …, a l ) ← u generated by the supervisor and the anonymous identity proof π = (A 1 , A 2 , B, C) sent by the user, set the parameter a 0 = 1; Step 4.2, the service provider first determines whether the equation e(A 1 ·A 2 , H) = e(G, B) holds; if it does not hold, the verification fails and an authentication failure message is returned to the user; otherwise, the next step is executed; Step 4.3, the service provider determines whether the following equation holds, If the equation holds, the verification is successful and the service provider returns an authentication success message to the user, otherwise it returns an authentication failure message; Step 5, if the user engages in illegal activities, the regulator traces the anonymous user according to Steps 3 and 4; Step 6, if the user wants to revoke the registered information, the user submits an identity revocation application to the regulator.

2. A regulatory and revocable anonymous identity authentication method according to claim 1, characterized in that, the said Step 5 includes the following sub-steps: If the user engages in illegal activities, the service provider will send part of the information A of the anonymous identity certificate sent by the user 2 to the regulatory authorities; The regulator can find the true identity of the user based on this information; The regulator uses the locally stored information G q(x)y and A sent by the service provider 2 to perform calculations and obtain Φ; where: Finally, the regulatory authority will compare Φ with the local G q(x)y corresponding for comparison. If they are the same, the user's identity information U is determined i Otherwise, compare with the next user information stored locally.

3. A regulatory and revocable anonymous identity authentication method according to claim 1, characterized in that, the said Step 6 includes the following sub-steps: If the user wants to revoke the identity information they registered with the regulator, then use it to submit an identity revocation application to the regulator; Step 6.1, the user uses a biometric scanning device to obtain an image of their biometric information, and uses the FingerCode feature extraction mechanism to extract the feature information (y 1 ,…,y n ) of the biometric information image; Step 6.2, the user uses the generators G and H in the QAP publicly disclosed by the regulatory party to encrypt the extracted fingerprint feature information to obtain the parameter s; and of the generator G and H to encrypt the extracted fingerprint feature information to obtain the parameter s; wherein r i is a random number selected by the user, 1 ≤ i ≤ n + 1, and r 1 + … + r n + r n+1 = R / 2; (x 1 , …, x n ) is partial information of the user identity identifier; finally, the user sends the identity tag U i and the parameter s to the supervisor; Step 6.3, after the supervisor receives the identity revocation application sent by the user, it will find the corresponding parameters i in the local database according to the user's identity identifier U and H R ; finally, calculate the parameter G γ , where Step 6.4, the supervisor determines whether G γ is within the set . If it exists, it is determined that the user's identity information is true and the locally stored identity information is revoked; otherwise, a verification failure is returned to the user and revocation cannot be performed; where Δ is the threshold for determining whether two fingerprints are similar.

Citation Information

Patent Citations

  • Anonymous revocation ring signature based on public chain and generation and revocation method of anonymous revocation ring signature

    CN110190970A

  • Traceable anonymous authentication method and traceable anonymous authentication system

    CN110225023A