An anonymous identity authentication implementation method and system

An improved scheme for generating keys and auxiliary data on the Galois domain solves the problem of legitimate user key leakage and attacks in multi-authenticator anonymous identity authentication systems, achieving higher security and privacy protection.

CN116545626BActive Publication Date: 2025-12-12SOUTHEAST UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310736972.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-21
Publication Date
2025-12-12
Estimated Expiration
2043-06-21

AI Technical Summary

Technical Problem

In anonymous authentication systems with multiple authenticators, how can we reduce the probability of legitimate user keys being attacked and leaked while satisfying the integrity, robustness, and privacy constraints of anonymous authentication?

Method used

An improved key generation scheme is adopted, which generates keys and auxiliary data for legitimate users and authenticators on the Galois domain GF(q). The authentication phase is conducted through the interaction of encoding and decoding functions, combined with a secret sharing scheme, to ensure that legitimate users can be authenticated and to prevent attackers from impersonating them.

Benefits of technology

It effectively reduces the probability of internal and external attacks on the system, significantly reduces the risk of legitimate user key leakage, and improves the system's security and privacy protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116545626B_ABST
    Figure CN116545626B_ABST
Patent Text Reader

Abstract

The application discloses an anonymous identity authentication implementation method and system. On the basis of an existing interactive anonymous identity authentication model and algorithm, based on (t, n) threshold secret sharing, an improved anonymous identity authentication scheme is provided under the condition of multiple authenticators and a given connection topology. Through careful design of a share allocation function of a legal user and multiple authenticators, on the basis of meeting the integrity, robustness and privacy constraints of the anonymous authentication problem, the attack probability inside and outside the anonymous authentication system is reduced, and the probability of user key leakage is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security, and particularly to an improved anonymous identity authentication method applicable to multiple verifiers, under a given connection topology, and achieving a smaller attack probability. BACKGROUND

[0002] Private Authentication (PA) technology enables legitimate users to pass through server authentication anonymously, and enter a website to use resources or services without revealing their identities. This technology is widely used in wireless body area networks, cloud computing, cryptocurrencies, electronic voting, and other fields. Most research on the problem of anonymous identity authentication is based on cryptographic techniques such as RSA algorithm and ECC algorithm, and achieves computational security. The present application is based on the interactive information theory anonymous identity authentication model proposed by Kazempour et al. in 2019 and the implementable algorithm in the context of multiple verifiers and limited key length. It focuses on the information theory security of the anonymous identity authentication problem, improves the original model, and reduces the attack probability of insiders and outsiders by redesigning the coding scheme, and greatly reduces the probability of user key leakage. SUMMARY

[0003] Technical problem: The technical problem to be solved by the present application is to design a key generation scheme for legitimate users k, k∈[K] and verifiers n, n∈[N] in an anonymous identity authentication system under a given topology structure to generate keys and auxiliary data. On the basis of meeting the integrity, robustness and privacy constraints required by the anonymous identity authentication problem, a smaller attack probability of insiders and outsiders is achieved, and the probability of legitimate user key leakage is reduced.

[0004] Technical solution

[0005] First, consider the problem of anonymous identity authentication in the context of multiple verifiers (as shown in FIG. 1): this problem model includes a Certificate Authority (CA), N verifiers, K legitimate users, and an attacker. The CA is responsible for issuing keys to legitimate users and sending authentication-related data to verifiers. Legitimate users want to pass through the authentication of verifiers with the keys issued by the CA without revealing their identity information. A legitimate user k, k∈[K] may be connected to one or more verifiers, and he can choose any one of them to request authentication at the authentication stage. This part of the verifier constitutes a set Figure 1 The size of the set is ​Attackers attempt to impersonate legitimate users to gain authentication from the authenticator. The authenticator needs to determine whether the entity sending the authentication request is a legitimate user or an attacker. If the requester is a legitimate user, the authenticator allows them access to the system and use the services; otherwise, they deny access. Simultaneously, the authenticator is curious about the identity of the user requesting authentication, hence the term "semi-honest" for the authenticator. Figure 1 As shown, Verifier n, n∈[N] is responsible for authenticating all users connected to it, and these users constitute a set. The cardinality of the set is It can be seen that there are different authentication sets for different Verifier m,n∈[N]. There is an intersection between them. Of course, the intersection may also be empty. Let I denote this intersection. mn The cardinality of the set is |I mn |

[0006] To address the above problems, the technical solution adopted by the present invention is as follows:

[0007] (1) Data distribution phase. In this phase, the CA generates and issues keys to legitimate users k, k∈[K]. Generate and send the data required for subsequent steps for Verifier n, n∈[N].

[0008] (2) Authentication Phase. Since the person initiating the authentication request could be a legitimate user or an attacker, they are referred to as the request initiator. The interaction between Verifier n and the request initiator in this phase is described below. First, the request initiator sends the key... The key C is input into a specific application (such as his mobile app), which then calculates the request information based on the input key C. It then sends this to the connected Verifier (for example, Verifier n), and simultaneously sends the key C to the CA, which stores the key; next, Verifier n, n∈[N] is based on V n And Q, using encoding functions Generate secret S n and auxiliary data M n S n The identity of the certified person is kept confidential. n This data is sent as supplementary data to the request initiator's program; subsequently, the request initiator's program uses a decoding function. Computational Secret S n ,Right now And send it to Verifier n; finally if Verifier n determines that the requester is a legitimate user and allows them to access the system and use the services; otherwise, it denies the access request.

[0009] (3) Verification Phase. The CA will periodically verify the behavior of the requester. If the CA discovers a key received during the authentication phase... If the key does not belong to any legitimate user, the request initiator will be immediately removed from the system. However, since the identity of the request initiator is unknown, the key can be used again later. Re-entering the system. In this case, the CA will return to the data distribution phase and regenerate the user key C. k The data V required for k∈[K] and Verifier n n If all requesters possess valid keys (i.e., are all legitimate users), but one or more of these users engage in malicious behavior, the CA will hold them accountable, for example, by notifying the appropriate authority. The CA will then return to the data distribution phase to regenerate the user key C. k The data V required for k∈[K] and Verifier n n This is to prevent malicious users from re-entering the site.

[0010] For anonymous authentication protocols with multiple authenticators, detailed function design is required. and space

[0011]

[0012] The data distribution phase includes the following steps:

[0013] The first step is to determine t is greater than the number of users connected to more than two authenticators in the topology. The calculation of this scheme is based on the Galois domain GF(q).

[0014] The second step is to use CA in t-dimensional space (GF(q)). t Remove the vector [1 0…0] from the middle. T After defining Zhang Cheng's linear space, K vectors U1,…,U are uniformly, randomly, and without repetition selected from the remaining vectors. K As part of the legitimate user key.

[0015] The third step is for CA to generate a portion V of its share for Verifier n, n∈[N]. n,1 ,…V n,t-1 The above column vectors should satisfy the following three conditions:

[0016] · ·right There is U i ∈span{[1 0…0] T V n,1 ,…V n,t-1};

[0017] ·right have

[0018] To meet the above conditions, V is generated according to the following steps. n,1 ,…V n,t-1 First, from the t-dimensional space (GF(q)) t Remove [1 0…0] from the middle. T Zhang Cheng's one-dimensional space, then successively removing Each spans a one-dimensional space, and V is uniformly and randomly selected from the remaining vectors. n,1 (must be ensured) Next, from the t-dimensional space (GF(q)) t Remove [1 0…0] from the middle. T and V n,1 Zhang Cheng's two-dimensional space, then successively removing and V n,1 Zhang Cheng's two-dimensional space, and uniformly and randomly selects V from the remaining vectors. n,2 (must be ensured) ); and so on, finally from t-dimensional space (GF(q)) t Remove [1 0…0] from the middle. T V n,1 ,…V n,t-2 Zhang Cheng's t-1 dimensional space, then successively removing and V n,1 ,…V n,t-2 Zhang Cheng's t-1 dimensional space, and uniformly and randomly selects V from the remaining vectors. n,t-1 (must be ensured) From the above, it can be deduced that the order q of the Galois field should satisfy:

[0019] Fourth step, CA determines the vector a for Verifier n, n∈[N]. n =[a n,0 a n,1 …a n,t-1 ] T This step depends on the connection topology (e.g., Figure 1 (As shown). First, satisfy... A pair of certifiers m and n is defined as an ordered pair (m, n), and the set of all ordered pairs is denoted as . For each ordered pair Make vector α mn =a m -a n And satisfy the following requirements: α mn T ⊥span{Ui i∈I mn}. In order to have the above formula for all ordered pairs, one can make all α mn satisfy In fact, the bracket is the union of all U i s held by users who are connected to more than two authenticators. In order to guarantee the existence of such a vector α mn , one requires that t is greater than the number of users in the topology who are connected to more than two authenticators. Then, assuming that all the authenticators involved in the ordered pairs share N I , one can generate the corresponding vectors a as follows: randomly select N I -1 ordered pairs (m, n) and the corresponding α mn , and randomly determine the vector a corresponding to a certain authenticator, then the vectors a corresponding to these authenticators can be determined. The remaining α mn s are redundant information. For the authenticators not involved in the ordered pairs, i.e. the authenticators in the topology that do not have an intersection with the authentication set of other authenticators, one can randomly and independently generate the corresponding vectors a for them. After the vectors a corresponding to all authenticators are generated, the identity authentication agency (CA) can determine B k = a n T U k , n can take any element in the set .

[0020] Step 5, the CA issues the private key C k = (U k , B k ) for the user k∈[K], and the key length is t+1 symbols, i.e. The CA also sends V n = (a n,0 , V n,1 ,..., V n,t-1 , a n T V n,1 ,..., a n T V n,t-1 ) to the Verifier n∈[N], and the key length is t 2 symbols, i.e.

[0021] The steps involved in the authentication phase are as follows:

[0022] Step 1, the request initiator inputs the key into the application.

[0023] Second step, the program outputs a request message Q e GF(q) independent of the key C (for example, Q = 1). The program chooses a suitable verifier n, n e [N] to request authentication and sends Q to the verifier n, prompting it to send the auxiliary data. At the same time, the program sends the key C to the CA, and the CA stores the key.

[0024] Third step, after receiving the request message Q, the verifier n sends the auxiliary data

[0025] M = (V n n,1 ,…V n,t-1 ,a n T V n,1 ,…,a n T V n,t-1 to the request initiator while keeping the secret S n = a n,0 secret.

[0026] Fourth step, after receiving the auxiliary data M n , the request initiator calculates as follows:

[0027]

[0028] The request initiator then sends the first element of , i.e. , to the verifier n.

[0029] Fifth step, if holds, the verifier n allows the request initiator to enter the system and use the service; otherwise, it is rejected.

[0030] Explanation of symbols:

[0031] For each authenticator n, n e [N], the key to the identity authentication scheme is whether the secret a n,0 recovered by the request initiator is correct. If it is correct, it is authenticated, otherwise it is rejected. The secret a n,0 is split into shares by the secret sharing scheme. Each share contains a t-dimensional vector and a scalar. Among them, t-1 shares are given to the authenticator n, which is also given to the user by the authenticator n as auxiliary data; the remaining shares are given to each user as a key, so that the user can correctly recover the secret a n,0 based on the t-1 auxiliary data of the authenticator n and his own key, while an illegal user cannot recover the secret without the key. Therefore, the vector a n ​Mid a n,0 Indicates a secret, a n,1 ,… a n,t-1 Is a random noise to protect the secret; V n,1 ,…, V n,t-1 Indicates a t-dimensional vector in t-1 shares allocated to authenticator n, Indicates a t-dimensional vector allocated to User, and a n T V n,1 ,…, a n T V n,t-1 Is a scalar in t-1 shares allocated to authenticator n, Is a scalar in allocated to User.

[0032] The application also provides a controller, comprising: a memory; and a processor coupled to the memory, the processor being configured to execute the above-mentioned anonymous identity authentication implementation method based on instructions stored in the memory.

[0033] The application also provides an anonymous identity authentication implementation system, comprising:

[0034] The above-mentioned controller;

[0035] A terminal configured to send an authentication message to the controller before accessing a service system;

[0036] An access gateway configured to open a port according to a port opening control policy sent by the controller; and

[0037] A service system configured to establish a connection with the terminal through the port opened by the access gateway.

[0038] The application also provides a non-transitory computer-readable storage medium having computer program instructions stored thereon, the instructions being executed by a processor to implement the above-mentioned anonymous identity authentication implementation method.

[0039] Advantages: the prior art uses a secret sharing scheme based on polynomial interpolation, essentially taking the Vandermonde matrix as the encoding matrix, and has low design freedom and low security; the application innovatively generates random elements of the encoding matrix, improves the design space while meeting the requirements, and improves the security of the system. The advantages are that the scheme realizes smaller internal and external attack probabilities than the original scheme on the basis of meeting the integrity, robustness and privacy constraints of the anonymous identity authentication problem, and greatly reduces the probability of leakage of the legal user key. BRIEF DESCRIPTION OF DRAWINGS

[0040] Figure 1A schematic diagram of an anonymous identity authentication model with multiple authenticators.

[0041] Figure 2 This is a schematic diagram of an anonymous identity authentication model with two authenticators.

[0042] Figure 3 This is a schematic diagram of an anonymous identity authentication model with three authenticators. Detailed Implementation

[0043] The technical solution of the present invention will be described in detail below, but the scope of protection of the present invention is not limited to the embodiments described.

[0044] This invention proposes an improved anonymous identity authentication scheme for multiple authenticators. Examples of anonymous identity authentication systems with two authenticators and three authenticators are given below.

[0045] Example 1: Anonymous Authentication Scheme with Two Authenticators

[0046] A connection topology in the case of two authenticators, such as Figure 2 As shown, the implementation of the anonymous authentication scheme for this embodiment includes the following data distribution stage, authentication stage, and inspection stage.

[0047] The first step, the data distribution phase, includes the following steps:

[0048] (1) Determine based on topology All calculations are based on the Galois domain GF(q).

[0049] (2) CA from t-dimensional space (GF(q)) t Remove the vector [1 0…0] from the middle. T After Zhang Cheng's linear space, five vectors U1, ..., U5 are selected uniformly, randomly, and without repetition from the remaining vectors as part of the legitimate user key.

[0050] (3) CA first generates a portion of its share, V, for Verifier 1. 1,1 ,…V 1,t-1 First, from the t-dimensional space (GF(q)) t Remove [1 0…0] from the middle. T The one-dimensional space spanned by U1, U2, U3, and U4 is then removed sequentially, and V is selected uniformly and randomly from the remaining vectors. 1,1 Next, from the t-dimensional space (GF(q)) t Remove [1 0…0] from the middle. T and V 1,1 Zhang Cheng's two-dimensional space, then successively removing U1, U2, U3, U4 and V1,1 Zhang Cheng's two-dimensional space, and uniformly and randomly selects V from the remaining vectors. 1,2 And so on, finally from t-dimensional space (GF(q)) t Remove [1 0…0] from the middle. T V 1,1 ,…V 1,t-2 Zhang Cheng's t-1 dimensional space, then successively removing U1, U2, U3, U4 and V 1,1 ,…V 1,t-2 Zhang Cheng's t-1 dimensional space, and uniformly and randomly selects V from the remaining vectors. 1,t-1 Following the above approach, CA generates a portion of its share, V, for Verifier 2. 2,1 ,…V 2,t-1 Note that in the above steps, U1, U2, U3, U4 should be replaced with U3, U4, U5.

[0051] (4) CA is the Verifier n, n = 1, 2, which determines the vector a. n =[a n,0 a n,1 …a n,t-1 ] T This step depends on the connection topology. Figure 2 In the context, the intersection I of the authentication sets of Verifier 1 and Verifier 2 is... 1,2 ={User 3,User 4},|I 1,2 |=2. For User 3, the following equation holds:

[0052]

[0053] Subtracting the two equations, we get:

[0054] (a1-a2) T U3=0

[0055] Similarly, the same applies to User 4:

[0056] (a1-a2) T U4=0

[0057] Therefore, a can be generated by following these steps. n n = 1, 2: make α 12 =a1-a2, and determine α. 12 T ⊥span{U3,U4}; then randomly determine a1, and we can get a2=a1-α 12 Once a1 and a2 are determined, B can be determined. 1,2,3,4 =a1 T U 1,2,3,4 B5 = a2T U5.

[0058] (5) CA issues a private key Ck for user k, k e [1, 2, 3, 4, 5] k = (U k , B k ), U k and B k are generated as in steps (2) and (4). The key length is t + 1 symbols, i.e. CA sends to Verifier n = 1, 2 simultaneously V n = (a n,0 , V n,1 ,... V n,t-1 , a n T V n,1 ,..., a n T V n,t-1 ), the key length is t symbols, i.e. 2

[0059] The second step, authentication phase, includes the following steps:

[0060] (1) The request initiator inputs the key Ck into the application program.

[0061] (2) The program outputs a request information Q e GF(q) (for example, Q = 1) independent of the key C. The program selects the Verifier connected to the user (for example, user 3 can request authentication from Verifier 1 or Verifier 2) and sends Q to the selected Verifier, prompting it to send the auxiliary data. At the same time, the program sends the key C to the CA, which stores the key.

[0062] (3) After receiving the request information Q, the Verifier n = 1, 2 sends the auxiliary data

[0063] M n = (V n,1 ,... V n,t-1 , a n T V n,1 ,..., a n T V n,t-1 ) to the request initiator while keeping the secret S n = a n,0 secret.

[0064] (4) After receiving the auxiliary data M n , the request initiator calculates as follows:​​

[0065]

[0066] The request initiator will then The first element, namely Send to Verifier n.

[0067] (5) If there is If true, Verifier n allows the requester to access the system and use the service; otherwise, it denies access.

[0068] The third step, the inspection phase, is as described in the technical solution section.

[0069] Example 2: Anonymous Identity Authentication Scheme with Three Authenticators

[0070] A connection topology in the case of three authenticators, such as Figure 3 As shown, the implementation of the anonymous authentication scheme for this embodiment still includes the following data distribution stage, authentication stage, and inspection stage.

[0071] (1) Determine based on topology All calculations are based on the Galois domain GF(q).

[0072] (2) CA from t-dimensional space (GF(q)) t Remove the vector [1 0…0] from the middle. T After Zhang Cheng's linear space, five vectors U1, ..., U5 are selected uniformly, randomly, and without repetition from the remaining vectors as part of the legitimate user key.

[0073] (3) CA first generates a portion of its share, V, for Verifier 1. 1,1 ,…V 1,t-1 First, from the t-dimensional space (GF(q)) t Remove [1 0…0] from the middle. T The one-dimensional space spanned by U1, U2, and U3 is then removed sequentially, and V is selected uniformly and randomly from the remaining vectors. 1,1 Next, from the t-dimensional space (GF(q)) t Remove [1 0…0] from the middle. T and V 1,1 Zhang Cheng's two-dimensional space, then successively removing U1, U2, U3 and V 1,1 Zhang Cheng's two-dimensional space, and uniformly and randomly selects V from the remaining vectors. 1,2 And so on, finally from t-dimensional space (GF(q)) t Remove [1 0…0] from the middle. T V 1,1 ,…V1,k-2 t-1 dimensional space, and then successively remove U1, U2, U3 and V 1,1 ,…V 1,t-2 t-1 dimensional space, and then uniformly and randomly select V from the remaining vectors 1,t-1 CA generates a part of the share V held by Verifier 2 according to the above idea 2,1 ,…V 2,t-1 Note that U1, U2, U3 in the above steps are replaced by U2, U3, U4; CA generates a part of the share V held by Verifier 3 according to the above idea 3,1 ,…V 3,t-1 U1, U2, U3 are replaced by U3, U4, U5.

[0074] (4) CA determines the vector a for Verifier n, n = 1, 2, 3 n = [a n,0 a n,1 …a n,t-1 ] T This step depends on the connection topology. Details are as follows.

[0075] Figure 3 The intersection I of the authentication sets of Verifier 1 and Verifier 2 is 1,2 = {User 2, User 3}, |I 1,2 | = 2. Obviously, the following is true for User 2 and User 3:

[0076] (a1-a2) T U2 = 0

[0077] (a1-a2) T U3 = 0

[0078] The intersection I of the authentication sets of Verifier 2 and Verifier 3 is 2,3 = {User 3, User 4}, |I 2,3 | = 2. Then we have:

[0079] (a2-a3) T U3 = 0

[0080] (a2-a3) T U4 = 0

[0081] Finally, for Verifier 1 and Verifier 3, the intersection I of the authentication sets is 1,3 = {User 3}, |I 1,3 | = 1. Obviously we have:

[0082] (a1-a3) T U3=0

[0083] If α 12 = a1-a2, α 23 = a2-a3, α 13 = a1-a3, then the following must be satisfied:

[0084] α 12 T ⊥span{U2,U3}, α 23 T ⊥span{U3,U4}, α 13 T ⊥span{U3}, and to satisfy the above requirements, we make α 12 T , α 23 T , α 13 T ⊥span{U2,U3,U4}, and choose N I -1=2, for example α 12 T and α 13 T are alternatives. In this case, α1is determined randomly, and α2and α3are calculated according to α 12 and α 13 . After α1, a2and a3are determined, B 1,2,3 = a1 T U 1,2,3 , B 4,5 = a3 T U 4,5 are determined.

[0085] (5) CA issues a private key C k = (U k , B k ) for user k, k∈[1,2,3,4,5], and the generation of U k and B k is seen in steps (2) and (4). The key length is t+1 symbols, i.e. c=GF t+1 (q). CA sends V n = (a n,0 , V n,1 ,…V n,t-1 , a n T V n,1 ,…, a n T V n,t-1 ) to Verifier n = 1,2,3, and the key length is t 2a symbol, i.e.

[0086] The second step, authentication phase, includes the following steps:

[0087] (1) The request initiator sends the key to the application program.

[0088] (2) The program outputs the request information Q∈GF(q) (for example, Q=1) independent of the key C. The program selects the Verifier connected with the user to request authentication (for example, the user 3 can request the authentication of the Verifier 1, Verifier 2 and Verifier 3) and sends Q to the selected Verifier to prompt it to send the auxiliary data. At the same time, the program sends the key C to the CA, and the CA stores the key.

[0089] (3) After receiving the request information Q, the Verifier n=n, 2, 3 sends the auxiliary data

[0090] M n =(V n,1 ,…V n,t-1 ,a n T V n,1 ,…,a n T V n,t-1 ) to the request initiator while keeping the secret S n =a n,0 secret.

[0091] (4) After receiving the auxiliary data M n , the request initiator calculates as follows:

[0092]

[0093] The request initiator then sends the first element of , i.e. to the Verifier n.

[0094] (5) If is true, the Verifier n allows the request initiator to enter the system and use the service; otherwise, it is rejected.

[0095] The third step, the checking phase, is as described in the technical solution part.

[0096] In the above scheme, as long as the legal user selects the authenticator in the set to request authentication, and ensures that C =U k ,B C =a TU k , must have So the legitimate user can be authenticated by the verifier, ensuring the integrity of the anonymous identity authentication problem. If the attacker sends an authentication request to the verifier, he cannot correctly recover S n = a n,0 The probability is only Where q is the order of the Galois field, which has a large value, so the probability can be ignored, ensuring the robustness of the anonymous identity authentication problem. In addition, for each verifier, all legitimate users in the authentication set calculate the same Therefore, the verifier cannot identify the difference between users in the authentication set, meeting the privacy constraints of the anonymous identity authentication problem.

[0097] The application also provides a controller, comprising: a memory; and a processor coupled to the memory, the processor being configured to execute the above-mentioned anonymous identity authentication implementation method based on instructions stored in the memory.

[0098] The application also provides an anonymous identity authentication implementation system, comprising:

[0099] The above-mentioned controller;

[0100] A terminal configured to send an authentication message to the controller before accessing the service system;

[0101] An access gateway configured to open a port according to the port opening control policy sent by the controller; and

[0102] A service system configured to establish a connection with the terminal through the port opened by the access gateway.

[0103] The application also provides a non-transitory computer-readable storage medium having computer program instructions stored thereon, the instructions being executed by a processor to implement the above-mentioned anonymous identity authentication implementation method.

Claims

1. An anonymous identity authentication implementation method, characterized by, The method comprises the following steps: The CA generates and issues a key for a legitimate user, and generates and sends data required for the subsequent steps for the Verifier; A request initiator, including a user or an attacker, initiates an authentication request, and the interaction between the Verifier and the request initiator is as follows: the request initiator inputs the key into a specific application program, the program calculates request information based on the input key and sends it to the connected Verifier, and the program sends the key to the CA, which stores the key; the Verifier generates a secret and auxiliary data using an encoding function, wherein the secret is kept secret by the Verifier, and the auxiliary data is sent to the program of the request initiator; then the program of the request initiator calculates the secret using a decoding function and sends it to the Verifier; if the decoded secret is the same as the secret before decoding, the Verifier considers that the request initiator is a legitimate user and allows it to enter the system to use services; otherwise, the access request of the request initiator is rejected; CA is A legitimate user generates and issues a key, and for Each verifier generates and sends the data required for subsequent steps, which include: determining the dimension and the number of elements in the Galois field according to the connection topology between the authenticators and the users wherein, , , is greater than the number of users connecting more than two authenticators in the topology, denotes the set of all legitimate users responsible for authentication by the Verifier . CA from dimensional space vectors spanned by the remaining vectors, uniformly, randomly, and without repetition, select vectors as part of the legitimate user key; CA is the Verifier Generates a fraction of its share The latter represents the fraction of the share given to the Verifier of the vector; CA is the Verifier determining a vector and for the user determining , taking any element from the set vector in denotes a secret, is random noise protecting the secret; CA is the user issues a private key , with a key length of symbols, i.e. ; CA also sends to Verifier , with a key length of symbols, i.e. .​ 2. The anonymous identity authentication implementation method according to claim 1, characterized in that, Generate according to the following steps First from 3D space Remove from middle Zhang Cheng's one-dimensional space, then successively removing Each spans a one-dimensional space, and then uniformly and randomly selects from the remaining vectors. Next, from 3D space Remove from middle and Zhang Cheng's two-dimensional space, then successively removing and Zhang Cheng's two-dimensional space, and uniformly and randomly selects from the remaining vectors. And so on, finally from 3D space Remove from middle , Zhang Cheng 1-dimensional space, then remove them one by one. and Zhang Cheng dimensional space, and uniformly and randomly select from the remaining vectors. .

3. The anonymous identity authentication implementation method according to claim 1, characterized in that, CA is the verifier determining vector The step includes: the authentication of satisfying the verifier , the authentication of Combination is defined as an ordered pair , all ordered sets are recorded as ; For each ordered pair , the vector , and meet the following requirements: , the bracket is the union of all the users held by the authentication of connecting two or more authentication ; All ordered pairs involving authentication of the corresponding vector As follows: randomly select ordered pair and the corresponding , randomly determine the vector corresponding to a certain authentication , the vector corresponding to the authentication can be determined; The remaining is redundant information; For authentication not involved in the ordered pair, randomly and independently for them to generate the corresponding vector .

4. The anonymous identity authentication implementation method according to claim 1, characterized in that, The method further comprises a checking stage; the CA will check the behavior of the request initiator from time to time; If the CA finds that the key received in the authentication stage does not belong to any legitimate user, the request initiator corresponding to the key will be immediately removed from the system; if the request initiator re-enters the system using the key again, the CA will return to the data distribution stage to re-generate the key of the user and the data required for the Verifier; If all request initiators hold valid keys, but one or more of these users are malicious, the CA will be held responsible; the CA will return to the data distribution phase, re-generating user keys and Verifier Data required to prevent re-entry of malicious users.

5. A controller comprising: a memory; and a processor coupled to the memory, the processor being configured to execute the instructions stored in the memory to implement the anonymous identity authentication implementation method according to any one of claims 1 to 4.

6. An anonymous identity authentication implementation system, comprising: the controller of claim 5; a terminal configured to send an authentication message to the controller before accessing a service system; an access gateway configured to open a port according to a port opening control policy sent by the controller; and a service system configured to establish a connection with the terminal through the port opened by the access gateway.

7. A non-transitory computer readable storage medium having computer program instructions stored thereon, the instructions being executed by a processor to implement the anonymous identity authentication implementation method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Improved anonymous identity authentication implementation method based on secret sharing

    CN115603991A