Identity authentication method, device, terminal and readable storage medium
By generating private and public keys using the non-commutative group of the Michaelis-Hellov subgroup and using conjugate elements for authentication, the security risks of public-key cryptography algorithms in quantum computing environments are resolved, and authentication security against quantum computing is achieved.
Patent Information
- Application Number
- CN202211602679.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-13
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2042-12-13
AI Technical Summary
Public-key cryptography-based authentication methods have security vulnerabilities, especially when facing threats from quantum computing.
Based on the non-commutative group of the Michaelis subgroup, the authentication process is secured by generating replacement elements of the private and public keys and using conjugate elements for identity authentication.
It effectively resists quantum computing attacks, improves the security of identity authentication, prevents private keys from being stolen and spoofed, and enhances the protection capabilities of identity authentication.
Smart Images

Figure CN115840953B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of identity authentication technology, and in particular relates to an identity authentication method, device, terminal and readable storage medium. Background Technology
[0002] Identity authentication generally refers to identity verification, also known as "verification" or "authorization," which means confirming a user's identity through certain means. There are many methods of identity verification, such as identity verification based on public-key cryptography algorithms.
[0003] Public-key cryptography relies on the computational challenges of factorization and discrete logarithm computation to ensure security. However, Shor's famous quantum algorithm, proposed in 1997, can theoretically perform factorization of large integers and computation of discrete logarithms in polynomial time. Furthermore, Google and IBM have both announced the realization or development of quantum computing systems based on Shor's quantum algorithm. This means that authentication methods based on public-key cryptography are no longer secure. Summary of the Invention
[0004] This application provides an identity authentication method, device, terminal, and readable storage medium, which can solve the security risks of identity authentication methods based on public key cryptography algorithms.
[0005] In a first aspect, embodiments of this application provide an identity authentication method applied to an authenticated terminal, the method comprising:
[0006] Obtain the first and second subgroups of the target braid group, wherein the target braid group contains at least two generators, the first and second subgroups are Michael subgroups, and the first and second subgroups are noncommutative groups;
[0007] Select any element from the first subgroup as a private key, and the private key corresponds to a first generator expression;
[0008] Generate a public key based on the target braid group, the second subgroup, and the private key;
[0009] After receiving the first conjugate element corresponding to each generator sent by the authentication terminal, the generator contained in the first generator expression is replaced using the first conjugate element to obtain the first replacement element corresponding to the private key; the first conjugate element is calculated by the authentication terminal based on the public key.
[0010] Based on the private key and the first replacement element, the information to be verified is determined and sent to the authentication terminal. The information to be verified is used to authenticate the identity of the authenticated terminal.
[0011] Secondly, embodiments of this application provide an identity authentication method applied to an authentication terminal, the method comprising:
[0012] Obtain the first and second subgroups of the target braid group, wherein the target braid group contains at least two generators, the first and second subgroups are Michael subgroups, and the first and second subgroups are noncommutative groups;
[0013] Select any element from the first subgroup as a private key, and the private key corresponds to a first generator expression;
[0014] Generate a public key based on the target braid group, the second subgroup, and the private key;
[0015] After receiving the first conjugate element corresponding to each generator sent by the authentication terminal, the generator contained in the first generator expression is replaced using the first conjugate element to obtain the first replacement element corresponding to the private key; the first conjugate element is calculated by the authentication terminal based on the public key.
[0016] Based on the private key and the first replacement element, the information to be verified is determined and sent to the authentication terminal. The information to be verified is used to authenticate the identity of the authenticated terminal.
[0017] Thirdly, embodiments of this application provide an identity authentication device applied to an authenticated terminal, the device comprising:
[0018] The subgroup acquisition module is used to acquire the first subgroup and the second subgroup of the target braid group, wherein the target braid group contains at least two generators, the first subgroup and the second subgroup are Michael subgroups, and the first subgroup and the second subgroup are noncommutative groups.
[0019] The private key acquisition module is used to select any element from the first subgroup as a private key, and the private key corresponds to a first generator expression;
[0020] The public key generation module is used to generate a public key based on the target subgroup, the second subgroup, and the private key;
[0021] The first replacement module is configured to, after receiving the first conjugate element corresponding to each generator element sent by the authentication terminal, use the first conjugate element to replace the generator elements contained in the first generator expression to obtain the first replacement element corresponding to the private key; the first conjugate element is calculated by the authentication terminal based on the public key.
[0022] The first determining module is used to determine the information to be verified based on the private key and the first replacement element, and send the information to be verified to the authentication terminal. The information to be verified is used to authenticate the identity of the authenticated terminal.
[0023] Fourthly, embodiments of this application provide an identity authentication device applied to an authentication terminal, the device comprising:
[0024] The public key acquisition module is used to acquire the public key generated by the authenticated terminal. The public key contains a target braid group and a second subgroup. The target braid group contains at least two generators. The second subgroup is a Michaelis subgroup of the target braid group and is a non-commutative group.
[0025] An element selection module is used to select any element from the second subgroup as a target element, wherein the target element corresponds to a second generator expression;
[0026] The sending module is used to calculate the first conjugate element corresponding to each generator contained in the target braid group based on the target element, and send the first conjugate element to the authenticated terminal. The first conjugate element is used to obtain the information to be verified.
[0027] The second replacement module is used to replace the generator contained in the second generator expression to obtain the second replacement element corresponding to the target element;
[0028] The second determining module is used to determine target verification information based on the target element and the second replacement element, wherein the target verification information is correct verification information;
[0029] The identity authentication module is used to authenticate the identity of the terminal being authenticated based on the verification information and the target verification information when the terminal being authenticated sends the verification information.
[0030] Fifthly, embodiments of this application provide a terminal, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the authentication methods described in the first and second aspects above.
[0031] Sixthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the authentication methods described in the first and second aspects above.
[0032] In a seventh aspect, embodiments of this application provide a computer program product that, when run on a terminal, causes the terminal to execute the authentication methods described in the first and second aspects above.
[0033] The beneficial effects of this application embodiment compared with the prior art are as follows: In this application, the authenticated terminal obtains a first subgroup and a second subgroup of the target braided group. The target braided group contains at least two generators. The first and second subgroups are Michaelis subgroups and are non-commutative groups. Any element is selected from the first subgroup as a private key, and the private key corresponds to a first generator expression. A public key is generated based on the target braided group, the second subgroup, and the private key. After receiving the first conjugate element corresponding to each generator sent by the authentication terminal, the generators contained in the first generator expression are replaced using the first conjugate element to obtain the first replacement element corresponding to the private key. The first conjugate element is calculated by the authentication terminal based on the public key. Based on the first conjugate element and the first replacement element, the information to be verified is determined, and the information to be verified is sent to the authentication terminal to perform identity authentication on the authenticated terminal based on the information to be verified. Since the membership problem of the Mihailova subgroup introduced in this application is unsolvable, current authentication attack algorithms cannot attack the private key of the authenticated terminal. That is, current authentication attack algorithms cannot crack the private key of the authenticated terminal based on the public key and the first conjugate element, and impersonate the authenticated terminal. This solves the security vulnerability problem of authentication methods based on public key cryptography algorithms. Attached Figure Description
[0034] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0035] Figure 1 This is a flowchart illustrating an identity authentication method provided in one embodiment of this application;
[0036] Figure 2 This is a flowchart illustrating an identity authentication method provided in another embodiment of this application;
[0037] Figure 3 This is a schematic structural block diagram of an identity authentication device provided in one embodiment of this application;
[0038] Figure 4 This is a schematic structural block diagram of an identity authentication device provided in another embodiment of this application;
[0039] Figure 5This is a schematic diagram of the structure of a terminal provided in an embodiment of this application. Detailed Implementation
[0040] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.
[0041] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.
[0042] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0043] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."
[0044] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0045] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0046] Example 1:
[0047] See also Figure 1 , Figure 1 The illustration shows a schematic flow of an authentication method provided in this application. It is provided as an example and not a limitation. This method can be applied to the authenticated terminal.
[0048] Step 101: Obtain the first and second subgroups of the target braided group. The target braided group contains at least two generators. The first and second subgroups are Michaelis subgroups and are noncommutative groups.
[0049] Alternatively, the target braid group can be defined using the following expression, where n is the exponent of the target braid group:
[0050] B n =<σ1,σ2,…,σ n-1 |σ i σ j =σ j σ i , |ij|≥2, σ i σ i+1 σ i =σ i+1 σ i σ i+1 , 1≤i≤n-2>
[0051] B n For the target braid group, B n The elements are all in the set {σ1,σ2,…,σ n-1 The} represents the unique, regular form of the word representation of this element. Where σ1, σ2, ..., σ n-1 Let n be the generator of the target braid group. Optionally, n is a positive number greater than or equal to 6.
[0052] The target braid group contains a subgroup L that is isomorphic to F2×F2. i That is, by σ i 2 ,σ i+1 2 ,σ i+3 2 ,σ i+4 2 The subgroups that are direct product isomorphic to the generated two rank-2 free groups, where F2 denotes a rank-2 free group. Optionally, the subgroup L... i It can be expressed as follows:
[0053]
[0054] For a finite presentation group H whose word problem is unsolvable by two elements, construct L. iA Mihelova subgroup M i M i The 56 generators are shown below:
[0055] S ij T ij j = 1, 2, ..., 27 where S ij Corresponding to 27 generators, T ij Corresponding to 27 generators; the following explains S ij and T ij The corresponding generator expression:
[0056] When i is 1 and j is 1, 2, ..., 27, S 1j The corresponding generator expression is as follows:
[0057]
[0058]
[0059]
[0060]
[0061]
[0062]
[0063]
[0064]
[0065]
[0066]
[0067]
[0068]
[0069]
[0070]
[0071]
[0072]
[0073]
[0074]
[0075]
[0076]
[0077]
[0078]
[0079]
[0080]
[0081]
[0082]
[0083]
[0084] After obtaining S 1j Then, if the value of i is greater than or equal to 2, then S 11j Replace all σ1 in the corresponding generator expression with σ i σ2 is replaced with σ i+1 S can then be obtained. ij For example, when j is 1, S... 1,1 By replacing all instances of σ1 with σ2 and σ2 with σ3 in the corresponding generator expression, we can obtain S. 2,1 When j is 2, S 1,2 By replacing all instances of σ1 with σ2 and σ2 with σ3 in the corresponding generator expression, we can obtain S. 2,2 .
[0085] After obtaining S ij After that, S ij Replace all σ1 in the corresponding generator expression with σ i+3 σ2 is replaced with σ i+4 T can be obtained. ij For example, when both i and j are 1, S... 1,1 Replacing all instances of σ1 with σ4 and σ2 with σ5 in the corresponding generator expression yields T. 1,1 When i is 2 and j is 3, S 2,3 Replacing all instances of σ1 with σ4 and σ2 with σ5 in the corresponding generator expression yields T. 2,3 .
[0086] It should be noted that the target braided group has the following properties: (1) the words representing the elements of the target braided group on the generator set of the target braided group have a unique computable normal form; (2) the product operation and the inversion operation of the group based on the normal form are computable.
[0087] Among them, all Mihelova subgroups M i The membership problem of (i = 1, 2, ..., n-5) is unsolvable. The generalized word problem (gwp) of a subgroup of a group is defined as follows: Given a subgroup H of a group G whose generator set is X, determine whether any element g in G can be represented by a word in X, i.e., determine whether g is an element in H.
[0088] Alternatively, it can be based on all Mihelova subgroups M i Obtain the first and second subgroups.
[0089] Optionally, in step 101 above, it is mentioned that the first and second subgroups are noncommutative groups. A noncommutative group is defined as a group in which the multiplication of two elements a and b is not commutative, i.e., ab is not equal to ba.
[0090] Step 102: Select any element from the first subgroup as the private key, and the private key corresponds to the first generator expression.
[0091] Each element in the first subgroup corresponds to a generator expression. Optionally, an element can be arbitrarily selected from the first subgroup as the private key, and the generator expression corresponding to the private key is determined as the first generator expression.
[0092] The authenticated terminal can send its private key to the authentication terminal for identity verification. However, the private key is easily stolen by a third party during the transmission process, allowing them to impersonate the authenticated terminal. Therefore, this application proposes an identity verification method that makes it difficult for a third party to steal the private key and impersonate the authenticated terminal.
[0093] Step 103: Generate a public key based on the target braid group, the second subgroup, and the private key.
[0094] In an alternative embodiment, the private key may be processed, for example, encrypted, and the target braid group, the second subgroup, and the processed private key may be made public as a public key.
[0095] Step 104: After receiving the first conjugate element corresponding to each generator sent by the authentication terminal, the generator contained in the first generator expression is replaced using the first conjugate element to obtain the first replacement element corresponding to the private key.
[0096] The first conjugate element is calculated by the authentication terminal based on the public key.
[0097] Optionally, since the authentication terminal needs to use the second conjugate element corresponding to the generator when obtaining the first conjugate element corresponding to the generator, and the second conjugate element corresponding to the generator is obtained based on the private key, a public key can be generated based on the target braid group, the second subgroup, and the private key before receiving the first conjugate element corresponding to each generator sent by the authentication terminal. Alternatively, the terminal being authenticated can send the second conjugate element corresponding to each generator to the authentication terminal.
[0098] The process of generating a public key based on the target braid group, the second subgroup, and the private key includes: calculating the second conjugate element corresponding to each generator based on the private key; and generating a public key based on the target braid group, the second subgroup, and the second conjugate element.
[0099] Optionally, based on the private key, the second conjugate element corresponding to each generator is calculated, including: inverting the private key to obtain the inverse element of the private key; and calculating the second conjugate element corresponding to the generator based on the private key, the inverse element of the private key, and the generator.
[0100] Alternatively, the second conjugate element corresponding to the generator can be calculated based on the following formula:
[0101] a I =x -1 σ I x
[0102] a I Let σ be the i-th generator contained in the target braid group. I The corresponding second conjugate element, x, is the private key, x -1 I is the inverse of the private key, and I takes values in the range [1, n-1], where n is the exponent of the target braided group.
[0103] Optionally, the target braid group, the second subgroup, and the second conjugate element corresponding to each generator can be published as a public key.
[0104] Optionally, the generators contained in the first generator expression are replaced using the first conjugate element to obtain the first replacement element corresponding to the private key, including: replacing the generators contained in the first generator expression with the corresponding first conjugate element to obtain the first replacement element.
[0105] Optionally, the first generator expression corresponding to the private key can be F1(σ1,σ2,…,σ n-1 ), that is, x=F1(σ1,σ2,…,σ n-1 Using the first conjugate element, after replacing the generators contained in the first generator expression, the resulting generator expression with the first replacement element is F1(b1,b2,…,b…).n-1 (where b1, b2, ..., b) n-1 These are the first conjugate elements corresponding to each generator. Step 105: Based on the private key and the first replacement element, determine the information to be verified and send the information to be verified to the authentication terminal. The information to be verified is used to authenticate the identity of the authenticated terminal.
[0106] Optionally, the information to be verified is determined based on the private key and the first replacement element, including: inverting the private key to obtain the inverse element of the private key; and hashing the inverse element of the private key and the first replacement element to obtain the information to be verified.
[0107] Alternatively, the information to be verified can be obtained based on the following formula:
[0108] z′=H(x -1 (F1(b1,b2,…,b n-1 )))
[0109] z′ represents the information to be verified, H is the hash function, and x -1 Let F1(b1,b2,…,b) be the inverse of the private key. n-1 ) is the generator expression for the first replacement element.
[0110] Optionally, the hash function can be included in the public key; if the public key does not contain a hash function, the hash function can be sent to the authentication terminal.
[0111] A hash function can take any number of bytes as input and output bytes of fixed length, and be collision-resistant. As an example, and not a limitation, the output of a hash function can be a string of 0s and 1s, where the fixed length can be a sufficiently large, fixed natural number.
[0112] The security of the authentication method provided in this application relies on the unsolvability of the corresponding decision problem, rather than the computational difficulty of the corresponding decision problem. Therefore, the authentication method of this invention can resist all known attacks, including quantum computing attacks.
[0113] In this application, the authenticated terminal obtains a first subgroup and a second subgroup of a target braided group. The target braided group contains at least two generators. The first and second subgroups are Michaelis subgroups and are non-commutative groups. Any element is selected from the first subgroup as a private key, and the private key corresponds to a first generator expression. A public key is generated based on the target braided group, the second subgroup, and the private key. After receiving the first conjugate element corresponding to each generator sent by the authentication terminal, the generators contained in the first generator expression are replaced using the first conjugate element to obtain the first replacement element corresponding to the private key. The first conjugate element is calculated by the authentication terminal based on the public key. Based on the first conjugate element and the first replacement element, the information to be verified is determined, and the information to be verified is sent to the authentication terminal to perform identity authentication based on the information to be verified. Since the membership problem of the Michaelis-Hellov subgroup introduced in this application is unsolvable, current authentication attack algorithms cannot attack the private key of the authenticated terminal. That is, current authentication attack algorithms cannot crack the private key of the authenticated terminal based on the public key and the first conjugate element, and impersonate the authenticated terminal. This solves the security vulnerability problem of authentication methods based on public key cryptography algorithms.
[0114] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0115] Example 2:
[0116] See also Figure 2 , Figure 2 The illustration shows a schematic flow of an authentication method provided in this application. This is an example, not a limitation, and can be applied to authentication terminals.
[0117] Step 201: Obtain the public key generated by the authenticated terminal. The public key contains the target braid group and the second subgroup. The target braid group contains at least two generators. The second subgroup is the Michaelis-Hellov subgroup of the target braid group and is a non-commutative group.
[0118] Optionally, the public key of the authenticated terminal is public, so the authenticator can obtain the public key of the authenticated terminal.
[0119] Step 202: Select any element from the second subgroup as the target element, and the target element corresponds to a second generator expression.
[0120] Optionally, each element in the second subgroup corresponds to a generator expression, and the generator expression corresponding to any element selected from the second subgroup can be determined as the second generator expression.
[0121] Step 203: Based on the target element, calculate the first conjugate element corresponding to each generator contained in the target braid group, and send the first conjugate element to the authenticated terminal. The first conjugate element is used to obtain the information to be verified.
[0122] Optionally, based on the target element, the first conjugate element corresponding to each generator contained in the target braid group is calculated, including: inverting the target element to obtain the inverse element of the target element; and calculating the first conjugate element corresponding to the generator based on the target element, the inverse element of the target element, and the generator.
[0123] Alternatively, the first conjugate element corresponding to the generator can be calculated based on the following formula:
[0124] b I = -1 σ I y
[0125] b I For the i-th generator σ I The corresponding first conjugate element, y is the target element, y -1 Let I be the inverse of the target element, and let I take values in the range [1, n-1], where n is the exponent of the target braid group.
[0126] Step 204: Replace the generators contained in the second generator expression to obtain the second replacement element corresponding to the target element.
[0127] Optionally, the generators contained in the second generator expression can be replaced using the second conjugate element corresponding to the generator. The second conjugate element corresponding to the generator is obtained by the authenticated terminal based on the private key and the generator.
[0128] In an optional embodiment, if the public key also includes a second conjugate element corresponding to each generator contained in the target braided group, then replacing the generator contained in the second generator expression includes: obtaining the second conjugate element corresponding to each generator contained in the public key, and using the second conjugate element to replace the corresponding generator in the second generator expression.
[0129] In another optional embodiment, if the public key does not include the second conjugate element corresponding to each generator contained in the target braid group, then before replacing the generator contained in the second generator expression, the method further includes: receiving the second conjugate element corresponding to each generator sent by the authenticated terminal.
[0130] Optionally, the generators in the second generator expression are replaced using the second conjugate element, including replacing the generators contained in the second generator expression with the corresponding second conjugate element to obtain the second replacement element.
[0131] Optionally, the second generator expression corresponding to the target element can be F2(σ1,σ2,…,σ n-1 ), that is, y=F2(σ1,σ2,…,σ n-1 Using the second conjugate element, after replacing the generators contained in the second generator expression, the resulting generator expression of the second replacement element is F2(a1,a2,…,a…). n-1 ), a1, a2, ..., a n-1 These are the second conjugate elements corresponding to each generator.
[0132] Step 205: Based on the target element and the second replacement element, determine the target verification information, which is the correct verification information.
[0133] Optionally, the target verification information is determined based on the target element and the second replacement element, including: inverting the target element to obtain the inverse element of the target element; and performing hash processing on the inverse element of the target element and the second replacement element to obtain the target verification information.
[0134] Alternatively, the target verification information can be obtained based on the following formula:
[0135] z=H((y -1 (F2(a1,a2,…,a n-1 ))) -1 )
[0136] z represents the target verification information, H represents the hash function, and y represents the target verification information. -1 F2(a1,a2,…,a) is the inverse of the target element. n-1 ) is the generator expression for the second replacement element, a1, a2, ..., a n-1 These are the second conjugate elements corresponding to each generator.
[0137] Alternatively, the hash function can be obtained based on the public key, or the hash function can be received from the authenticated terminal.
[0138] Step 206: Upon receiving the verification information sent by the terminal to be authenticated, perform identity authentication on the terminal to be authenticated based on the verification information and the target verification information.
[0139] After receiving the information to be verified, the information to be verified can be compared with the target verification information. If the information to be verified is the same as the target verification information, the identity of the terminal being authenticated is recognized; otherwise, the identity of the terminal being authenticated is rejected.
[0140] This application obtains a public key generated by the terminal being authenticated. The public key contains a target braided group and a second subgroup. The target braided group contains at least two generators, and the second subgroup is a Michaelis subgroup of the target braided group and is a non-commutative group. Any element is selected from the second subgroup as a target element, and the target element corresponds to a second generator expression. The generators contained in the second generator expression are substituted to obtain a second substitution element corresponding to the target element. Based on the second substitution element, a first conjugate element corresponding to each generator contained in the target braided group is calculated and sent to the terminal being authenticated. The first conjugate element is used to obtain the information to be verified. The target verification information is determined, and the target verification information is correct. Upon receiving the information to be verified sent by the terminal being authenticated, the terminal is authenticated based on the information to be verified and the target verification information. This application authenticates the terminal based on the information to be verified and the target verification information, without needing to obtain the terminal's private key, thus avoiding the theft of the private key during the acquisition process.
[0141] Alternatively, if the authentication method provided in this application is used, the specific authentication principle can be explained in the following ways.
[0142] For the information z′ to be verified:
[0143] z′=H(x -1 (F1(b1,b2,…,b n-1 )))
[0144] =H(x) -1 (F1(y -1 σ1y,y -1 σ2y,…,y -1 σ2y)))
[0145] =H(x) -1 y -1 (F1(σ1,σ2,…,σ n-1 ))y)
[0146] =H(x) -1 y -1 xy)
[0147] For the target verification information z:
[0148] z=H((y -1 (F2(a1,a2,…,a n-1 ))) -1 )
[0149] =H((y) -1 (F2(x -1 σ1x,x -1 σ²x,…,x-1 σ n-1 x))) -1 )
[0150] =H((y) -1 x -1 (F2(σ1,σ2,…,σ n-1 ))x) -1 )
[0151] =H((y) -1 x -1 yx) -1 )=H(x -1 y -1 xy)
[0152] Therefore, it can be seen that the information to be verified z′ and the target verification information z obtained according to the identity authentication method provided in this application are the same.
[0153] The following demonstrates that the authentication method of this invention can resist all known attacks, including quantum computing attacks:
[0154] If a third party attempts to attack this agreement, it can only do so through publicly available information shared by both parties to the agreement. n ,Q,H,a1,a2,…,a n-1}(a I = -1 σ I x, I = 1, ..., n-1) and {b1, b2, ..., b} obtained through the channel n-1}(b I = -1 σ I An attack is launched on y, I = 1, ..., n-1, where Q is the second subgroup. If a third party can obtain B n The elements s and t make
[0155] s -1 σ I s=y -1 σ I y, t -1 σ I t = x -1 σ I x, I = 1, 2, ..., n-1,
[0156] Let s = cy, t = dx (where c and d are B) n If a certain element is given, then we have
[0157] s -1 σ I s = (cy) -1 σ I cy = y -1 c-1 σ I cy = y -1 σ I y, I = 1, 2, ..., n-1
[0158] Therefore,
[0159] c -1 σ I c = σ I I = 1, 2, ..., n-1
[0160] That is, c and each σ I Multiplication is commutative. Because B n From σ1,σ2,…,σ n-1 The generated c is B n The central element. And B n The center is formed by Δ 2 The generated infinite cyclic subgroup <Δ 2 >, among which
[0161] Δ=σ1σ2…σ n-1 σ1σ2…σ n-2 …σ1σ2σ3σ1σ2σ1
[0162] Therefore, c is <Δ 2 > is an element. Similarly, d is also an element of <Δ. 2 The element >. Because <Δ 2 >Is B n The center of , and σ I 2 <Δ 2 >,σ I+1 2 <Δ 2 >,σ I+3 2 <Δ 2 > and σ I+4 2 <Δ 2 >Generated business group B n / <Δ 2 > subgroups and σ I 2 , σ I+1 2 , σ I+3 2 and σ I+4 2 Generate B n The subgroups of are isomorphic, and therefore are also free groups of rank 2. Hence, the subquotient group (M) I <Δ 2 >) / <Δ 2 Also a business group B n / <Δ 2>The Mihelova subgroup. Therefore (M I <Δ 2 >) / <Δ 2 The subgroup membership problem is also unsolvable. Therefore, if an attacker can obtain B... n The elements s and t make
[0163] s -1 σ I s=y -1 σ I y, t -1 σ I t = x -1 σ I x, I = 1, 2, ..., n-1,
[0164] Then s = cy, t = dx, and c, d ∈ < Δ 2 >, therefore in quotient group B n / <Δ 2 > contains s<Δ 2 >= y < Δ 2 > and t<Δ 2 >=x<Δ 2 >. That is, the attacker is in business group B. n / <Δ 2 > The Mhelowa subgroup must be found in > I <Δ 2 >) / <Δ 2 > element y < Δ 2 > and x<Δ 2 >. Due to (M) I <Δ 2 >) / <Δ 2 The subgroup membership problem of y < Δ is unsolvable; therefore, there is no algorithm that allows an attacker to successfully obtain y < Δ. 2 > and x<Δ 2 Therefore, there is no algorithm that would allow an attacker to successfully obtain the required s and t.
[0165] Example 3:
[0166] See also Figure 3 , Figure 3 The diagram illustrates a schematic structure of an authentication device provided in this application. It is provided as an example and not a limitation, and can be applied to the terminal being authenticated. For ease of explanation, only the parts relevant to the embodiments of this application are shown in the figure.
[0167] Reference Figure 3 The device includes a subgroup acquisition module 31, a private key acquisition module 32, a public key generation module 33, a first replacement module 34, and a first determination module 35; the specific functions of each module are as follows:
[0168] Subgroup acquisition module 31 is used to acquire the first subgroup and the second subgroup of the target braid group. The target braid group contains at least two generators. The first subgroup and the second subgroup are Michaelis subgroups and are noncommutative groups.
[0169] The private key acquisition module 32 is used to select any element from the first subgroup as a private key, and the private key corresponds to a first generator expression;
[0170] Public key generation module 33 is used to generate a public key based on the target braid group, the second subgroup and the private key;
[0171] The first replacement module 34 is used to replace the generators contained in the first generator expression with the first conjugate element after receiving the first conjugate element corresponding to each generator sent by the authentication terminal, so as to obtain the first replacement element corresponding to the private key; the first conjugate element is calculated by the authentication terminal based on the public key;
[0172] The first determining module 35 is used to determine the information to be verified based on the private key and the first replacement element, and send the information to be verified to the authentication terminal. The information to be verified is used to authenticate the identity of the terminal being authenticated.
[0173] Optionally, the public key generation module 33 is specifically used to: calculate the second conjugate element corresponding to each generator based on the private key; and generate a public key based on the target braid group, the second subgroup, and the second conjugate element.
[0174] Optionally, the public key generation module 33 is specifically used for: inverting the private key to obtain the inverse element of the private key; and calculating the second conjugate element corresponding to the generator based on the private key, the inverse element of the private key, and the generator.
[0175] Optionally, the first determining module 35 is specifically used for: inverting the private key to obtain the inverse element of the private key; performing hash processing on the inverse element of the private key and the first replacement element to obtain the information to be verified.
[0176] The identity authentication device provided in this application embodiment can be applied in the aforementioned method embodiment one. For details, please refer to the description of the aforementioned method embodiment one, which will not be repeated here.
[0177] Example 4:
[0178] See also Figure 4 , Figure 4 The figure illustrates a schematic structure of an identity authentication device provided in this application. This is an example, not a limitation, and can be applied to authentication terminals. For ease of explanation, only the parts relevant to the embodiments of this application are shown in the figure.
[0179] Reference Figure 4The device includes a public key acquisition module 41, an element selection module 42, a sending module 43, a second replacement module 44, a second determination module 45, and an identity authentication module 46; the specific functions of each module are as follows:
[0180] The public key acquisition module 41 is used to acquire the public key generated by the authenticated terminal. The public key contains a target braid group and a second subgroup. The target braid group contains at least two generators. The second subgroup is the Michaelis-Hellov subgroup of the target braid group and is a non-commutative group.
[0181] The element selection module 42 is used to select any element from the second subgroup as the target element, and the target element corresponds to a second generator expression;
[0182] The sending module 43 is used to calculate the first conjugate element corresponding to each generator contained in the target braid group based on the target element, and send the first conjugate element to the authenticated terminal. The first conjugate element is used to obtain the information to be verified.
[0183] The second replacement module 44 is used to replace the generators contained in the second generator expression to obtain the second replacement element corresponding to the target element;
[0184] The second determining module 45 is used to determine target verification information based on the target element and the second replacement element, wherein the target verification information is correct verification information.
[0185] The identity authentication module 46 is used to authenticate the identity of the terminal being authenticated based on the information to be verified and the target verification information when it receives the information to be verified sent by the terminal being authenticated.
[0186] Optionally, the public key also includes a second conjugate element corresponding to each generator contained in the target braid group, and the second replacement module 44 is specifically used to: replace the corresponding generator in the second generator expression using the second conjugate element.
[0187] Optionally, the second determining module 45 is specifically used for: inverting the target element to obtain the inverse element of the target element; performing hash processing on the inverse element of the target element and the second replacement element to obtain target verification information.
[0188] Optionally, the sending module 43 is specifically used for: inverting the target element to obtain the inverse element of the target element; and calculating the first conjugate element corresponding to the generator based on the target element, the inverse element of the target element, and the generator.
[0189] The identity authentication device provided in this application embodiment can be applied in the aforementioned method embodiment two. For details, please refer to the description of the aforementioned method embodiment two, which will not be repeated here.
[0190] Example 5:
[0191] See also Figure 5 , Figure 5 A schematic structure of a terminal provided in an embodiment of this application is shown. The terminal 5 of this embodiment includes: at least one processor 50 ( Figure 5 The at least one processor 50 is shown in the diagram, along with a memory 51 and a computer program 52 stored in the memory 51 and executable on the at least one processor 50. When the processor 50 executes the computer program 52, it implements the steps of the authentication methods described in Embodiments 1 and 2 above.
[0192] The terminal 5 can be a computing device such as a desktop computer, laptop, handheld computer, or cloud server. The terminal 5 may include, but is not limited to, a processor 50 and a memory 51. Those skilled in the art will understand that... Figure 5 This is merely an example of terminal 5 and does not constitute a limitation on terminal 5. It may include more or fewer components than shown in the figure, or combine certain components, or different components, such as input / output devices, network access devices, etc.
[0193] The processor 50 may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0194] In some embodiments, the memory 51 may be an internal storage unit of the terminal 5, such as a hard disk or memory of the terminal 5. In other embodiments, the memory 51 may be an external storage device of the terminal 5, such as a plug-in hard disk, smart memory card (SMC), secure digital card (SD) card, flash card, etc., equipped on the terminal 5. Furthermore, the memory 51 may include both internal storage units and external storage devices of the terminal 5. The memory 51 is used to store the operating system, applications, bootloader, data, and other programs, such as the program code of the computer program. The memory 51 can also be used to temporarily store data that has been output or will be output.
[0195] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.
[0196] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0197] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps described in the various method embodiments above.
[0198] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a terminal, a recording medium, a computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunication signals.
[0199] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0200] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0201] In the embodiments provided in this application, it should be understood that the disclosed devices / terminals and methods can be implemented in other ways. For example, the device / terminal embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling or direct coupling or communication connection may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0202] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0203] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. An identity authentication method, characterized in that, Applied to the authenticated terminal, the method includes: Obtain the first and second subgroups of the target braid group, wherein the target braid group contains at least two generators, the first and second subgroups are Michael subgroups, and the first and second subgroups are noncommutative groups; Select any element from the first subgroup as a private key, and the private key corresponds to a first generator expression; Generate a public key based on the target braid group, the second subgroup, and the private key; After receiving the first conjugate element corresponding to each generator sent by the authentication terminal, the generator contained in the first generator expression is replaced using the first conjugate element to obtain the first replacement element corresponding to the private key; the first conjugate element is calculated by the authentication terminal based on the public key. Based on the private key and the first replacement element, the information to be verified is determined and sent to the authentication terminal. The information to be verified is used to authenticate the identity of the authenticated terminal.
2. The method as described in claim 1, characterized in that, The step of generating a public key based on the target braid group, the second subgroup, and the private key includes: Based on the private key, calculate the second conjugate element corresponding to each generator; The public key is generated based on the target braid group, the second subgroup, and the second conjugate element.
3. The method as described in claim 2, characterized in that, The step of calculating the second conjugate element corresponding to each generator based on the private key includes: Invert the private key to obtain its inverse element; Based on the private key, the inverse element of the private key, and the generator, calculate the second conjugate element corresponding to the generator.
4. The method according to any one of claims 1 to 3, characterized in that, The step of determining the information to be verified based on the private key and the first replacement element includes: Invert the private key to obtain its inverse element; The inverse element of the private key and the first replacement element are hashed to obtain the information to be verified.
5. An identity authentication method, characterized in that, Applied to an authentication terminal, the method includes: Obtain the public key generated by the authenticated terminal. The public key contains a target braid group and a second subgroup. The target braid group contains at least two generators. The second subgroup is a Michaelis subgroup of the target braid group and is a non-commutative group. Select any element from the second subgroup as the target element, and the target element corresponds to a second generator expression; Based on the target element, calculate the first conjugate element corresponding to each generator element contained in the target braid group, and send the first conjugate element to the authenticated terminal. The first conjugate element is used to obtain the information to be verified. The generators contained in the second generator expression are replaced to obtain the second replacement element corresponding to the target element; Based on the target element and the second replacement element, target verification information is determined, and the target verification information is correct verification information; Upon receiving the verification information sent by the authenticated terminal, the authenticated terminal is authenticated based on the verification information and the target verification information.
6. The method as described in claim 5, characterized in that, The public key also includes a second conjugate element corresponding to each generator contained in the target braided group, and the substitution of the generator contained in the second generator expression includes: The corresponding generator in the second generator expression is replaced using the second conjugate element.
7. The method as described in claim 5, characterized in that, The step of determining the target verification information based on the target element and the second replacement element includes: Invert the target element to obtain its inverse element; The target verification information is obtained by hashing the inverse element of the target element and the second replacement element.
8. The method according to any one of claims 5-7, characterized in that, The step of calculating the first conjugate element corresponding to each generator in the target braid group based on the target element includes: Invert the target element to obtain its inverse element; Based on the target element, the inverse element of the target element, and the generator, calculate the first conjugate element corresponding to the generator.
9. An identity authentication device, characterized in that, The device, applied to the authenticated terminal, includes: The subgroup acquisition module is used to acquire the first subgroup and the second subgroup of the target braid group, wherein the target braid group contains at least two generators, the first subgroup and the second subgroup are Michael subgroups, and the first subgroup and the second subgroup are noncommutative groups. The private key acquisition module is used to select any element from the first subgroup as a private key, and the private key corresponds to a first generator expression; The public key generation module is used to generate a public key based on the target subgroup, the second subgroup, and the private key; The first replacement module is configured to, after receiving the first conjugate element corresponding to each generator element sent by the authentication terminal, use the first conjugate element to replace the generator elements contained in the first generator expression to obtain the first replacement element corresponding to the private key; the first conjugate element is calculated by the authentication terminal based on the public key. The first determining module is used to determine the information to be verified based on the private key and the first replacement element, and send the information to be verified to the authentication terminal. The information to be verified is used to authenticate the identity of the authenticated terminal.
10. An identity authentication device, characterized in that, The device, used in authentication terminals, includes: The public key acquisition module is used to acquire the public key generated by the authenticated terminal. The public key contains a target braid group and a second subgroup. The target braid group contains at least two generators. The second subgroup is a Michaelis subgroup of the target braid group and is a non-commutative group. An element selection module is used to select any element from the second subgroup as a target element, wherein the target element corresponds to a second generator expression; The sending module is used to calculate the first conjugate element corresponding to each generator contained in the target braid group based on the target element, and send the first conjugate element to the authenticated terminal. The first conjugate element is used to obtain the information to be verified. The second replacement module is used to replace the generator contained in the second generator expression to obtain the second replacement element corresponding to the target element; The second determining module is used to determine target verification information based on the target element and the second replacement element, wherein the target verification information is correct verification information; The identity authentication module is used to authenticate the identity of the terminal being authenticated based on the verification information and the target verification information when the terminal being authenticated sends the verification information.
11. A terminal, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1 to 4 or 5 to 8.
12. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 4 or 5 to 8.
Citation Information
Patent Citations
Method for establishing public key cryptogram against quantum computing attack
CN105393488A
Method for establishing public key cryptogram against quantum computing attack
CN107911209A