Method for authenticating fault-tolerant passwords and negotiating keys
By using the two-layer secret sharing algorithm to check the Hamming distance between the user's input password and the registration password, the problem of difficult to balance password security and availability in the prior art is solved, and the authentication and key negotiation of fault-tolerant passwords are realized, and the user experience is improved.
Patent Information
- Application Number
- CN202211722770.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-30
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-12-30
AI Technical Summary
The prior art is difficult to improve the availability of user input passwords while ensuring password security, especially for passwords containing a small number of typos.
A two-layer secret sharing algorithm is used to check whether the Hamming distance between the user input password and the registration password is less than the predetermined threshold. If it is less than the threshold, the session key will be reconstructed, otherwise the random number will be reconstructed.
While ensuring password security, users are allowed to use passwords with a small number of misspelled passwords for authentication and key negotiation, improving user experience and usability.
Smart Images

Figure CN116232573B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to password authentication key negotiation technology, and particularly to authentication and key negotiation technology for fault-tolerant passwords. Background Art
[0002] In password-based authentication key negotiation, a user needs to first register with a password on the server side. When the user requests a service from the server, the server can verify the user's identity through the registered password. If the verification passes, the user and the server can negotiate a session key through the password to protect subsequent communications.
[0003] From the perspective of security, the server is vulnerable to attacks by adversaries. Once an adversary breaks into the server's database, the user passwords stored in the server will be leaked. The adversary can use the leaked passwords to impersonate legitimate users, which poses a serious threat to the privacy and security of users. To protect user passwords, the most common method is to store the one-way hash value of the user password instead of the user password on the server side. In this case, even if an adversary breaks into the server and steals the hash value of the user password, it still takes additional time to crack the hash value of the password. In addition, to further improve the security of passwords, many websites such as Google, Amazon, JD.com, Taobao, etc. will evaluate the strength of the passwords selected by users when setting passwords, forcing users to set longer and more complex passwords.
[0004] From the perspective of usability, when users input passwords, input errors often occur. For example, forgetting to switch the case, or mistyping a letter as its adjacent letter. This situation is more frequent for more complex and difficult-to-remember passwords. To input a completely correct password, users need to tap the keyboard again and again, which seriously affects the user experience. Therefore, while ensuring the security of passwords, a small number of spelling mistakes in the passwords input by users should be tolerated.
[0005] Currently, there is no password-based authentication and key negotiation scheme that can ensure both security and usability. The present invention aims to design an authentication and key negotiation method for fault-tolerant passwords, which allows the user and the server to authenticate each other's identities and negotiate a session key as long as the Hamming distance between the password input by the user and the registered password is within a predetermined threshold range. This method improves usability while ensuring security. Summary of the Invention
[0006] The problem to be solved by the present invention is to provide a method that allows users to use passwords containing a small number of spelling mistakes to pass the server's authentication and complete key negotiation with the server.
[0007] The technical solution adopted by the present invention to solve the above problems is an authentication and key negotiation method for fault-tolerant passwords. This method uses a two-layer secret sharing algorithm to check whether the Hamming distance between the user's input password and the registered password is less than a predetermined threshold. If the distance is less than the predetermined threshold, the user can use the two-layer secret sharing algorithm to reconstruct the session key. Otherwise, the user uses the two-layer secret sharing algorithm to reconstruct a random number. Specifically, it includes the following steps:
[0008] System initialization phase:
[0009] Perform system initialization according to security parameters to determine the public parameters of the system; initialize any symmetric encryption scheme, oblivious transfer scheme, two-layer secret sharing algorithm, and pseudorandom function.
[0010] Registration phase:
[0011] 1. The user sends the password to the server through a secure channel;
[0012] 2. The server selects two random numbers, one of which is used to blind the user's password and the other is used to generate the symmetric key;
[0013] 3. The server invokes the two-layer secret sharing algorithm to share the symmetric key. The specific steps are as follows:
[0014] 3.1. The server performs the first-layer secret sharing on the symmetric key to generate several secrets;
[0015] 3.2. The server performs the second-layer secret sharing on each of the secrets generated by the first-layer sharing to generate several sub-secrets.
[0016] 4. The server stores all the sub-secrets in a binary tuple set. Among them, the storage positions of these sub-secrets are determined by the password bits of the user, and the remaining positions of the set are filled with random numbers selected by the server;
[0017] 5. The server generates and stores a password file for the user. This file includes the symmetric key generated by the server, the blinded password, the random number used for blinding the password, and a binary tuple set.
[0018] Authentication and key negotiation phase:
[0019] 1. The server selects a new random number and uses this random number to update the password file, that is, to update the symmetric key and the binary tuple set included in the password file;
[0020] 2. The server invokes the encryption algorithm to encrypt the random number, the blinded password, and the updated binary tuple set in the password file, and sends the ciphertext to the user, where the encryption key is the updated symmetric key;
[0021] 3. The server calculates the pseudo-random function value of the symmetric key and sets it as its own session key;
[0022] 4. After receiving the ciphertext, the user and the server execute an oblivious transfer protocol, where the user inputs the password and the server inputs the updated set of binary tuples. This protocol uses the password bits of the user to retrieve the values stored at the corresponding positions in the set of binary tuples and returns the retrieval results to the user. In particular, if and only if the Hamming distance between the user's password and the registered password is less than a predetermined threshold, the user can retrieve enough sub-secrets from the set of binary tuples;
[0023] 5. The user calls a two-layer secret sharing algorithm to reconstruct the retrieved results and recover the symmetric key. The specific steps are as follows:
[0024] 5.1. The user groups the retrieved results and performs the first-layer reconstruction on each group separately;
[0025] 5.2. The user performs the second-layer reconstruction on the results of the first-layer reconstruction. If the retrieved results contain sub-secrets that meet the reconstruction quantity, the two-layer secret contribution algorithm can reconstruct the symmetric key. Otherwise, the algorithm reconstructs a random number.
[0026] 6. The user calls a decryption algorithm to decrypt the ciphertext and obtains the random number, the blinded password, and the set of binary tuples in the password file, where the decryption key is the symmetric key or random number reconstructed by the two-layer secret sharing algorithm;
[0027] 7. The user verifies whether there exists a password such that the Hamming distance between this password and the user's used password is less than a predetermined threshold and is consistent with the decrypted blinded password. In addition, the user verifies whether the part retrieved from the set of binary tuples is consistent with the corresponding part in the decrypted binary tuples. If the above verifications pass, it means that the Hamming distance between the user's password and the registered password is less than a predetermined threshold, and the user successfully reconstructs the symmetric key through the two-layer secret sharing algorithm; the user calculates the pseudo-random function value of the symmetric key and sets it as its own session key, and the key negotiation is successful. Otherwise, the user selects a random number, calculates its pseudo-random function value, and sets it as its own session key, and the key negotiation fails.
[0028] The present invention uses a two-layer secret sharing algorithm to measure the Hamming distance between the password input by the user and the registered password. When it is less than a predetermined threshold, the present invention allows the user to reconstruct the symmetric key through the two-layer secret sharing algorithm and further calculate the session key, enabling the user to successfully complete authentication and key negotiation with the server.
[0029] The beneficial effects of the present invention are:
[0030] 1. Design an authentication and key agreement method for fault-tolerant passwords, which allows a user and a server to authenticate each other's identities and negotiate a session key if and only if the Hamming distance between the password entered by the user and the registered password is within a predetermined threshold range.
[0031] 2. This method improves usability while ensuring password security. Brief Description of the Drawings
[0032] Figure 1 Schematic diagram of the registration phase for the embodiment;
[0033] Figure 2 Schematic diagram of the authentication and key agreement phase for the embodiment. Detailed Implementation Manner
[0034] The present invention will be further described below with reference to the accompanying drawings.
[0035] System initialization phase:
[0036] Determine the public parameters PP = {q, g, G, Z q , n, m, l, t, r} according to the security parameter λ. Where q is a large prime number, g is a generator of the cyclic group G of order q, Z q is the residue class ring modulo q, n is the bit length of the password, m is the character length of the password, l is the bit length of the character, and t, r are the thresholds of the double-layer secret sharing algorithm. Initialize the symmetric encryption scheme Π = {Enc(·), Dec(·)}, the oblivious transfer scheme OT, the double-layer secret sharing algorithm DLSS, and the pseudorandom function PRG.
[0037] Registration phase, as Figure 1 shown:
[0038] 1. User U selects a password pw and sends it to server S through a secure channel;
[0039] 2. After receiving the password pw sent by U, S selects a random number and calculates the symmetric key K = g s , and blinds the user password P = g pw+r′ , where K is the key of the symmetric encryption algorithm;
[0040] 3. S uses the double-layer secret sharing algorithm DLSS to share the random number s, and the specific steps are as follows:
[0041] 3.1. S selects a random number and constructs a polynomial f(x) of degree t - 1 = s + a 1 x + a 2 x 2 + … + a t-1 x t-1 modulo p, where f(0) = s, k ∈ {1, 2, …, t - 1};
[0042] 3.2. S performs the first - layer secret sharing on the random number s, calculates f(i) = s i , and generates the first - layer secrets {s 1 , s 2 , …, s m}, where i ∈ {1, 2, …, m};
[0043] 3.3. For each s i , S selects a random number to construct a polynomial h i (x) = s i + b i,1 x + b i,2 x 2 + … + b i,l-1 x l-1 modulo p, where h i (0) = s i , k ∈ {1, 2, …, l - 1};
[0044] 3.4. S performs the second - layer secret sharing on each s i , calculates h i (j) = s i,j , and generates the second - layer sub - secrets where i ∈ {1, 2, …, m}, j ∈ {1, 2, …, l};
[0045] 4. S stores the second - layer sub - secrets in the set of tuples . The storage location of the sub - secrets is determined by the password bits of the user, that is where pw i,j ∈ {0, 1}, {i, j} represents the j - th bit of the i - th character of the user's password;
[0046] 5. S selects a random number r i,j , calculates and uses it to fill the empty positions of A, that is
[0047] 6. S generates and stores the password file F = {A, P, K, r ′}, and deletes pw, s, {r i,j}.
[0048] Authentication and key agreement phase, as Figure 2 shown:
[0049] 1. S randomly selects and calculates
[0050] 2. The S invokes an encryption algorithm to encrypt {A ′ , P, r ′}, and sends the ciphertext C = Enc K′ (A′, P, r ′ ) to U, where the encryption key is K ′ ;
[0051] 3. S calculates the session key K S = PRG(K′);
[0052] 4. After receiving the ciphertext C sent by S, U executes an oblivious transfer protocol with S, where U inputs the password pw′ and S inputs A ′ , and U uses the password pw′ to retrieve the second-layer sub-secret from A ′ If the password pw′ input by the user contains errors, the retrieval result will contain some random numbers;
[0053] 5. U uses the double-layer secret sharing algorithm DLSS to reconstruct the retrieval result B to generate a symmetric key The specific steps are as follows:
[0054] 5.1. U divides B into m subsets according to the subscripts and performs the first-layer reconstruction for each subset B i U calculates where
[0055] 5.2. Given the set U performs the second-layer reconstruction and calculates The specific steps are as follows:
[0056] 5.2.1. U randomly selects a subset and calculates where
[0057] 5.2.2. For each element in the set E, U verifies whether holds. If at most m - r values fail to be verified, then U calculates
[0058] 5.2.3. If the above verification fails, U repeats steps 5.2.1 and 5.2.2 until U calculates If the Hamming distance between the user's password pw′ and the registered password pw is less than a predetermined threshold, the user can reconstruct Otherwise, the user reconstructs a random number;
[0059] 6. U invokes the decryption algorithm to decrypt the ciphertext C and obtains the plaintext where the decryption key is
[0060] 7. U checks whether there exists a pw such that the Hamming distance d(pw, pw ′ ) < ε and where ε is a predetermined threshold; U checks whether there exists which is used to determine whether the retrieved set B part is consistent with the set of binary tuples generated using pw. If the verification passes, it indicates that the Hamming distance between the user's password and the registered password is less than the predetermined threshold, and the user successfully reconstructs the symmetric key through the double-layer secret sharing algorithm;
[0061] 8. If the above verification passes, the user calculates The key negotiation is successful; otherwise, the user selects a random number, calculates its pseudo-random function value, and sets it as their session key, and the key negotiation fails.
[0062] The above has introduced in detail the authentication and key negotiation method for the fault-tolerant password provided by the present invention, and has elaborated on the principle and implementation manner of the present invention. The description of the above examples is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of the present invention, several improvements and modifications can still be made to the present invention, and these improvements and modifications also fall within the protection scope of the claims of the present invention.
Claims
1. Authentication and Key Agreement Method for Fault-Tolerant Passwords Characterized in that It includes the following steps System Initialization Phase: Initialize the system according to security parameters, determine the public parameters of the system, initialize any symmetric encryption scheme, oblivious transfer scheme, and pseudorandom function Registration Phase 1) The user sends the password to the server through a secure channel 2) After receiving the user's password, the server selects two random numbers, one of which is used to blind the user's password and the other is used to generate a symmetric key 3) The server shares the symmetric key using the double-layer secret sharing algorithm, generates several sub-secrets, and stores the sub-secrets and the random numbers together in a binary tuple set 4) The server generates and stores a password file for the user, and the password file includes the symmetric key generated by the server, the blinded password, the random number used for blinding the password, and a binary tuple set Authentication and Key Agreement Phase 1) The server selects a new random number and updates the symmetric key in the password file and the elements in the binary tuple set using the new random number 2) The server calls the encryption algorithm to encrypt the random number, blinded password, and updated binary tuple set in the password file to obtain the ciphertext, and sends the ciphertext to the user, where the encryption key is the updated symmetric key 3) The server calculates the pseudorandom function value of the updated symmetric key and sets it as its own session key 4) After receiving the ciphertext, the user and the server execute the oblivious transfer protocol to retrieve the sub-secrets from the server's binary tuple set 5) The user reconstructs the retrieved sub-secrets using the double-layer secret sharing algorithm to generate a symmetric key 6) The user calls the decryption algorithm to decrypt the ciphertext to obtain the random number, blinded password, and binary tuple set in the password file, where the decryption key is the reconstructed symmetric key 7) The user verifies whether there is a password such that the Hamming distance between this password and the user-entered password is less than a predetermined threshold and is consistent with the decrypted blinded password In addition, the user verifies whether the retrieved sub-secret part from the binary tuple set is consistent with the corresponding part in the decrypted binary tuple; if the above verification passes, it means that the Hamming distance between the user's password and the registered password is less than the predetermined threshold, and the user successfully reconstructs the symmetric key through the double-layer secret sharing algorithm. The user calculates the pseudorandom function value of the symmetric key and sets it as its own session key, and the key agreement is successful; otherwise, the user selects a random number, calculates its pseudorandom function value, and sets it as its own session key, and the key agreement fails Among them, in step 3) of the registration phase, the server first performs the first-layer secret sharing on the symmetric key to generate several secrets; secondly, the server performs the second-layer secret sharing on each secret respectively to generate several sub-secrets; the server stores the sub-secrets in a binary tuple set, and their storage positions are determined by the bits in the user's password, and the remaining positions in the binary tuple set are filled with random numbers selected by the server In step 4) of the authentication and key negotiation phase, when executing the oblivious transfer protocol, the user inputs a password, and the server inputs a set of binary tuples. The user uses the password to retrieve the values stored at the corresponding positions from the set of binary tuples, and the values include sub-secrets and random numbers; If and only if the Hamming distance between the user's password and the registered password is less than a predetermined threshold, the user can retrieve the sub-secrets that meet the reconstruction quantity from the set of binary tuples; In step 5) of the authentication and key negotiation phase, the user first groups the retrieved results and performs the first-layer reconstruction on each group respectively; secondly, the user performs the second-layer reconstruction on the results of the first-layer reconstruction; If and only if the results retrieved by the user from the set of binary tuples contain sub-secrets that meet the reconstruction quantity, the user can reconstruct the symmetric key using the double-layer secret contribution algorithm.