Method and system for hierarchical multi-authentication access control identity recognition based on secret sharing
By adopting a hierarchical multi-factor authentication method based on secret sharing, the problem of multi-factor authentication in access control systems with multiple users and different user permissions is solved, realizing identity authentication and identity privacy protection for multi-level users and preventing impersonation attacks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-24
- Publication Date
- 2026-03-31
AI Technical Summary
Existing access control systems are unable to effectively achieve multi-level authentication of multiple personnel at different levels in high-security locations such as banks and military facilities, and are also subject to the risk of spoofing attacks.
A hierarchical multi-factor authentication method based on secret sharing is adopted. Through the interaction of identity verification challenge and response sets between the access control server and the mobile identity recognition device, decryption algorithms and signature verification are used, combined with hierarchical secret sharing technology, to ensure the identity verification and level verification of multiple users and prevent impersonation attacks.
This system enables users with multiple access levels to jointly authenticate their identities within the access control system, ensuring the privacy of identities and the security of authentication, and preventing impersonation attacks by attackers.
Smart Images

Figure CN117275127B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to a method and system for hierarchical multi-authentication access control and identity recognition based on secret sharing. Background Technology
[0002] Access control system identity recognition technology, as an important research direction in the field of information security technology, has received widespread academic attention and practical applications. Its research background can be traced back to the need for physical security and resource protection, as well as the understanding of the security vulnerabilities and limitations of traditional access control systems. Traditional access control systems typically use identity authentication methods based on physical keys or magnetic cards, which have several security risks. For example, physical keys can be copied or lost, and magnetic cards can be stolen or misused. Furthermore, traditional access control systems often lack flexibility and scalability, failing to meet the identity authentication requirements of different scenarios and needs. With the rapid development of information technology and the rise of intelligent systems, researchers have begun to explore and develop more secure and reliable access control system identity authentication technologies. Among these, biometric recognition-based identity authentication technology has attracted widespread attention. Biometric recognition technology uses an individual's physiological or behavioral characteristics for identity verification, such as fingerprints, iris scans, facial recognition, and voiceprints. These characteristics are unique to each individual, thus providing highly reliable identity verification.
[0003] In addition, in recent years, identity authentication technologies based on wireless communication have also attracted researchers' attention. For example, identity authentication schemes based on Near Field Communication (NFC) or Bluetooth technologies can achieve convenient identity verification through interaction with smartphones or other portable devices. This technology not only provides higher security but also offers flexibility and scalability, making it suitable for different access control scenarios and application needs. These research efforts aim to improve the security, convenience, and user experience of access control systems, providing better access control management and resource protection methods for various industries and venues. However, for important venues with high security requirements such as banks and military industries, the protection of existing access control authentication systems is far from sufficient. There is a need to design an access control identity recognition system where multiple people at different levels jointly authenticate to provide high-strength security protection for physical resources. Summary of the Invention
[0004] This invention provides a method and system for hierarchical multi-authentication access control identity recognition based on secret sharing. It effectively solves the problem of multi-authentication access control identity recognition in situations with multiple users and different user permissions. This enables different users with multiple levels of permissions to jointly perform identity authentication in the access control system, while ensuring that attackers can prevent impersonation attacks.
[0005] In a first aspect, the present invention provides a hierarchical multi-authentication access control identity recognition method based on secret sharing, applied to an access control server, the method comprising:
[0006] Obtain authentication request information sent by multiple mobile identification devices;
[0007] Based on the authentication request information and the first random number, calculate the identity verification challenge set {z} corresponding to the plurality of mobile identity recognition devices. i ,θ i ,T}, where the identity verification challenge set {z} i ,θ i ,T} includes: identity verification challenge value z i Identity verification challenge value, signature value θ i and the signature value θ of the identity verification challenge value i The corresponding timestamp T;
[0008] The identity verification challenge set {z i ,θ i The information is sent to the corresponding mobile identification device, and the identity verification response set {u} is received. i ,v i ,T i}, wherein the identity verification response set {u i ,v i ,T i This includes: identity verification response information (u i ,v i ) and the current session time (T) i );
[0009] The identity verification response set {u} is processed using a decryption algorithm. i ,v i ,T i The process involves decryption to obtain the plaintext information of the mobile identity recognition device, determining the verified mobile identity recognition device based on the plaintext information, and sending the verification information to the mobile identity recognition device.
[0010] The set of identity verification responses corresponding to the verified mobile identity recognition device {u i ,v i ,T i The information is stored in the verified set. Based on the verified set, it is calculated whether the plurality of mobile identification devices have completed authentication, and the authentication information is sent to the plurality of mobile identification devices.
[0011] In conjunction with the first aspect, in one possible implementation, the step of calculating the identity verification challenge set {z} corresponding to the plurality of mobile identity recognition devices based on the authentication request information and the first random number is as follows: i ,θ i ,T}, specifically includes:
[0012] Select the first random number k i The identity verification challenge value z is calculated according to the formula. i The specific calculation formula is expressed as: z i =k i +B, where B represents the two-way authentication parameter in the access control server;
[0013] The identity verification challenge value z is verified using the signing private key. i Perform a signature to obtain the identity verification challenge signature value θ. i The identity verification challenge value signature value θ i =Sig(z) i (,T), where T is the timestamp;
[0014] The identity verification challenge value z i The identity verification challenge value and signature value θ i Add them to the set to obtain the identity verification challenge set {z}. i ,θ i ,T}.
[0015] In conjunction with the first aspect, in one possible implementation, the use of a decryption algorithm on the identity verification response set (u) i ,v i ,T i The process involves decryption to obtain the plaintext information of the mobile identity recognition device, specifically including:
[0016] According to the identity verification response set {u i ,v i ,T i The identity verification response information (u) in} i ,v i ), calculate the intermediate value for identity verification recovery; the specific calculation is expressed as: Y i =(x i ,y i )=k i v i , where Y i This indicates the intermediate value for restoring identity verification; (x) i ,y i ) represents the coordinates of a point in the elliptic curve point set; k i Represents the first random number; v iThis represents a value in the identity verification response information;
[0017] The decryption algorithm is used to recover the intermediate value of the identity verification and the set of identity verification responses {u}. i ,v i ,T i The corresponding private key is used to calculate the plaintext information of the mobile identity verification device. The specific calculation formula is: Dec SK (u i / f(x i ||y i ||T i ), where u i This represents a value in the identity verification response information.
[0018] In conjunction with the first aspect, in one possible implementation, determining the verified mobile identity recognition device based on the plaintext information specifically includes:
[0019] Obtain the plaintext identity identifier from the plaintext information;
[0020] Determine whether the plaintext identity identifier exists in the plurality of mobile identity recognition devices;
[0021] If yes, the verification passes; otherwise, the verification fails.
[0022] In conjunction with the first aspect, in one possible implementation, the step of calculating whether the plurality of mobile identity verification devices have completed authentication based on the verification through a set specifically includes:
[0023] The verification process involves obtaining multiple mobile identity recognition devices from the set, and then obtaining the level of each mobile identity recognition device and the secret share corresponding to that mobile identity recognition device.
[0024] Using multiple secret shares, multiple general terms are obtained, and the multiple general terms are summed to obtain the verified general term;
[0025] Determine whether the verification formula is equal to the secret verification value stored in the access control server;
[0026] If they are equal, the authentication is complete.
[0027] If they are not equal, authentication fails.
[0028] In conjunction with the first aspect, in one possible implementation, before acquiring the authentication request information sent by multiple mobile identification devices, the access control server is registered. The registration specifically includes:
[0029] The access control server is initialized, and its initialization parameters are determined.
[0030] Select random numbers to construct a polynomial, and calculate the two-way authentication parameters of the access control server based on the polynomial and the random numbers;
[0031] Using a hierarchical secret sharing method, secret shares and secret verification values corresponding to multiple mobile identification devices are determined respectively;
[0032] The authentication set information of the mobile identity recognition device is sent to the mobile identity recognition device respectively, and the authentication set information of the mobile identity recognition device includes: mobile identity recognition device secret information W. i,j σ, the signature value of a mobile identification device i And two-way authentication parameters, wherein the secret information W of the mobile identity recognition device is generated based on the initialization parameters. i,j And based on the two-way authentication parameters, the secret information W of the mobile identity recognition device i,j Perform a signature and determine the signature value σ of the mobile identity recognition device. i .
[0033] In conjunction with the first aspect, in one possible implementation, the method of using hierarchical secret sharing to determine the secret share and secret verification value corresponding to each of the multiple mobile identification devices specifically includes:
[0034] The mobile identity recognition devices in the authentication set are divided into different levels;
[0035] Different thresholds correspond to different levels. The mobile identity recognition device authentication set whose level is less than or equal to the level corresponding to the threshold is divided into a subset.
[0036] Calculate the secret share of each mobile identity recognition device in the subset, and construct a linear regression recursive relationship using the secret share;
[0037] The secret verification value is obtained by summing the linear regression recursive relationships corresponding to the subset and multiple mobile identity recognition devices.
[0038] Secondly, this invention provides a hierarchical multi-authentication access control and identity recognition method based on secret sharing, applied to a mobile identity recognition device, the method comprising:
[0039] Each mobile identification device to be verified sends its authentication request information to the access control server.
[0040] Obtain the identity verification challenge set {z i ,θ i ,T}, where the identity verification challenge set {z} i ,θ i ,T} includes: identity verification challenge value z i Identity verification challenge value, signature value θ i and the signature value θ of the identity verification challenge value i The corresponding timestamp T;
[0041] The identity verification challenge value signature value θ i Perform signature verification and, based on the aforementioned identity verification challenge set {z} i ,θ i ,T} calculate the identity verification response set {u i ,v i ,T i}, and the identity verification response set (u i ,v i ,T i The identity verification response set {u} is sent to the access control server. i ,v i ,T i This includes: identity verification response information (u i ,v i ) and the current session time (T) i );
[0042] Receive the verification information sent by the access control server, and send the next authentication request information to the access control server until there is no mobile identity recognition device to be verified;
[0043] Receive authentication information.
[0044] In conjunction with the second aspect, in one possible implementation, the step of verifying the identity challenge set {z} i ,θ i ,T} calculate the identity verification response set {u i ,v i ,T i Specifically, it includes:
[0045] Calculate the first identity verification intermediate value using the two-way authentication parameters in the access control server;
[0046] Select a second random number, and calculate a second identity verification intermediate value based on the second random number and the first identity verification intermediate value;
[0047] Calculate the identity verification response information (u) based on the second identity verification intermediate value. i ,vi ), thus obtaining the identity verification response set {u i ,v i ,T i}
[0048] Thirdly, this invention provides a hierarchical multi-authentication access control system based on secret sharing, applied to an access control server. The system includes:
[0049] The authentication request information acquisition module is used to acquire authentication request information sent by multiple mobile identity recognition devices.
[0050] The identity verification challenge set calculation module is used to calculate the identity verification challenge set {z} corresponding to the plurality of mobile identity recognition devices based on the authentication request information and the first random number. i ,θ i ,T}, where the identity verification challenge set {z} i ,θ i ,T} includes: identity verification challenge value z i Identity verification challenge value, signature value θ i and the signature value θ of the identity verification challenge value i The corresponding timestamp T;
[0051] The identity verification response set acquisition module is used to retrieve the identity verification challenge set {z}. i ,θ i The information is sent to the corresponding mobile identification device, and the identity verification response set {u} is received. i ,v i ,T i}, wherein the identity verification response set {u i ,v i ,T i This includes: identity verification response information (u i ,v i ) and the current session time (T) i );
[0052] The identity verification response set verification module is used to verify the identity verification response set {u} using a decryption algorithm. i ,v i ,T i The process involves decryption to obtain the plaintext information of the mobile identity recognition device, determining the verified mobile identity recognition device based on the plaintext information, and sending the verification information to the mobile identity recognition device.
[0053] The authentication module is used to process the set of identity verification responses corresponding to the verified mobile identity recognition device {ui ,v i ,T i The information is stored in the verified set. Based on the verified set, it is calculated whether the plurality of mobile identification devices have completed authentication, and the authentication information is sent to the plurality of mobile identification devices.
[0054] One or more technical solutions provided in this invention have at least the following technical effects or advantages:
[0055] This invention employs a hierarchical multi-authentication access control identity recognition method and system based on secret sharing, applied to an access control server. The method includes: acquiring authentication request information sent by multiple mobile identity recognition devices; calculating identity verification challenge sets corresponding to the multiple mobile identity recognition devices based on the authentication request information and a first random number, wherein the identity verification challenge set includes: an identity verification challenge value, an identity verification challenge value signature value, and a timestamp corresponding to the identity verification challenge value signature value;
[0056] The system sends an identity verification challenge set to the corresponding mobile identity recognition device and receives an identity verification response set, which includes the identity verification response information and the current session time. During the registration phase, the user's identity identifier, level, and allocated share are encrypted and stored in the mobile identity recognition device. Attackers cannot obtain this information during communication, thus ensuring privacy while verifying the validity of individual user identities. The identity verification response set is decrypted using a decryption algorithm to obtain the plaintext information of the mobile identity recognition device. Based on this plaintext information, the verified mobile identity recognition device is determined, and the verification information is sent to it. The server verifies the signature message using its own and the client's share. It can jointly calculate relevant parameters to complete two-way authentication, preventing attackers from impersonating others. It stores the set of identity verification responses corresponding to verified mobile identification devices in a verification pass set. Based on the verification pass set, it calculates whether multiple mobile identification devices have completed authentication and sends the authentication information to multiple mobile identification devices. It collects and calculates the secret share of multiple levels of users who meet the threshold, and compares it with the secret verification value stored on the server to verify the validity of the number and level of users, preventing malicious interference. It effectively solves the problem of multi-authentication access control identity recognition in situations with multiple users and unequal user permissions, thus enabling different users with multiple levels of permissions to jointly authenticate the access control system while ensuring that attackers can prevent impersonation attacks. Attached Figure Description
[0057] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments of the present invention or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0058] Figure 1 A flowchart of a hierarchical multi-authentication access control identity recognition method based on secret sharing provided in an embodiment of the present invention;
[0059] Figure 2 This is a schematic diagram of the registration stage provided in an embodiment of the present invention;
[0060] Figure 3 This is a schematic diagram of the authentication stage provided in an embodiment of the present invention. Detailed Implementation
[0061] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0062] In the embodiments provided by the present invention, the access control server is registered before step S101, and the registration specifically includes the following steps S201 to S204.
[0063] S201, initialize the access control server and determine its initialization parameters. Assume the access control server has its own encryption and decryption public / private key pair; the encryption and decryption algorithms can be, but are not limited to, the Chinese national cryptographic standard SM2 encryption and decryption algorithm; it also has its own signature and verification public / private key pair; the signature and verification algorithms can be, but are not limited to, the Chinese national cryptographic standard SM2 signature and verification algorithm. In a specific embodiment of this invention, the initialization operation of the encryption and decryption public / private keys using the Chinese national cryptographic standard SM2 public key algorithm is as follows: The access control server determines the elliptic curve parameter ecc(F) based on the security parameter λ. p ,E(F p ),G,n), where E(F p Let G = (x1, y1) be the point set of an elliptic curve, and let E(F) be the point set of the curve. p Let d be a base point on G, and n be the order of G. Randomly select a point d∈[1,n-1] as the server's private key SK, and calculate the corresponding public key PK = [d]G∈E(F). p Select a one-way hash function f, and use ecc, f, and PK as public parameters, while SK is secretly stored by the access control server.
[0064] S202, select random numbers to construct a polynomial, and calculate the two-way authentication parameters of the access control server based on the polynomial and the random numbers. This invention uses a Shamir secret sharing method based on a Lagrange interpolation polynomial, with the following specific steps:
[0065] (1) The access control server selects two random integers S and r, and then uses S and r and the access control server's identity ID. Server Construct a polynomial F(x) = (xS)[x-(ID)] Server -r) / S]+r, such that F(S)=r, F(0)=ID Server .
[0066] (2) The access control server continues to select two random integers a and b, where a and b ≠ S, and then uses polynomials to calculate A and B respectively. F(a) represents the value of polynomial F(x) at integer a; F(b) represents the value of polynomial F(x) at integer b.
[0067] S203, using a hierarchical secret sharing method, determines the secret share and secret verification value corresponding to multiple mobile identification devices respectively.
[0068] In step S203, the hierarchical secret sharing method is used to determine the secret share and secret verification value corresponding to multiple mobile identification devices, which specifically includes the following steps.
[0069] (1) Divide the mobile identity recognition devices in the mobile identity recognition device authentication set into different levels.
[0070] (2) Different thresholds correspond to different levels. The mobile identity recognition device authentication set whose level is less than or equal to the level corresponding to the threshold is divided into a subset.
[0071] (3) Calculate the secret share of the mobile identification device in the subset respectively, and use the secret share to construct a linear regression recursive relationship.
[0072] (4) The linear regression recursive relationships corresponding to multiple mobile identification devices in the subset are summed to obtain the secret verification value.
[0073] In a specific embodiment of this invention, a hierarchical secret sharing method based on linear regression recursion (LHR) is used to obtain the secret share and the secret verification value. Specifically, this includes:
[0074] 1) Assume the set of mobile identification devices in the system is P = {P1, P2, ..., P}n This set corresponds one-to-one with a user. The access control server divides the set into m disjoint subsets γ1, γ2, ..., γm. m , where γ i Compared to γ i+1 Higher rank, more privileges. A set of mobile identification devices qualified to pass through an access control identification system should simultaneously satisfy the following m conditions: at least k1 mobile identification devices with valid identities exist in γ1; at least k2 mobile identification devices with valid identities exist in γ1∪γ2; There are at least k in the middle m A mobile identity verification device with valid identity. That is, for each set... Its corresponding threshold region is Where k j It is a set The recovery threshold The number of mobile identification devices in this set satisfies Finally, the access control server randomly selects m different one-way functions f1(x), f2(x), ... f m (x), for example, f(x) = 2 x +1 (mod 19).
[0075] 2) Let N j =n1+n2+...+n j Represents a set The number of mobile identification devices in the access control server is initially set as γ. j The i-th mobile identification device randomly selects the secret share of the current mobile identification device. Next, randomly select m distinct integers α1, α2, ..., α... m , where m is the number of user levels in the entire system.
[0076] 3) For 1≤j≤m, 1≤i≤N j Located at the level (set) The share of the i-th participant is Specifically, N0 = 0, N m =n, further calculate the secret share used to construct the LHR polynomial.
[0077] 4) For 1≤j≤m, let Then the access control server uses k j Construct the j-th LHR relation using initial values.
[0078]
[0079] And calculate the remaining values excluding the initial values.
[0080] 5) The access control server calculates and stores the secret verification value. This serves as a secret verification value to confirm whether the number of mobile identity recognition devices has reached a specified threshold and whether their secret shares are valid.
[0081] S204, the mobile identification device authentication set information is sent to the mobile identification device respectively. The mobile identification device authentication set information includes: mobile identification device secret information W. i,j σ, the signature value of a mobile identification device i And two-way authentication parameters, including generating mobile identification device secret information W based on initialization parameters. i,j And based on the two-way authentication parameters, the secret information W of the mobile identity recognition device i,j Perform a signature and determine the signature value σ of the mobile identification device. i .
[0082] Suppose there are n mobile identification devices P = {P1, P2, ..., Pn} n Its mobile device identification is id. i The level information is l i For any 1 ≤ i ≤ n, the access control server uses its own public key to calculate the user's secret information by running the SM2 encryption algorithm. Where 1≤j≤l i .
[0083] The access control server uses its own signing private key to run the SM2 signature algorithm to verify (W) i,j A) Obtain the user information signature value by signing. And collect user authentication information Secretly sent to the i-th mobile identification device, and (B,h) n It is stored locally as a secret verification message.
[0084] like Figure 2 The diagram shown is a specific registration embodiment provided in conjunction with steps S201 to S204.
[0085] First, server initialization: determine the elliptic parameter ecc(F). p ,E(F p ),G,n), select d as the server private key SK to calculate the corresponding public key PK=[d]G∈E(F p );
[0086] Then calculate the two-way authentication parameters: select random numbers S and r and construct a polynomial F(x), select random numbers a and b, and calculate A and B;
[0087] Then calculate the multi-factor authentication share: classify user levels, determine threshold values, and calculate the user's secret share. Verification value h with server n ;
[0088] Then, user information is generated: the user information is encrypted using the SM2 algorithm. Generate signature And the identity verification challenge set {z i ,θ i The value z is sent to a mobile identity verification device. i Identity verification challenge value, signature value θ i and the signature value θ of the identity verification challenge value i The corresponding timestamp T;
[0089] Preserve server information: Save (B,h) n Local authentication verification information.
[0090] By registering the access control server and using the national cryptographic SM2 algorithm, the personnel identification, level, and allocated share in the hierarchical system are encrypted and stored in the mobile identification device during the registration phase, thus achieving privacy protection of user identity.
[0091] This invention provides a method and system for hierarchical multi-authentication access control identity recognition based on secret sharing, applicable to access control servers, such as... Figure 1 The method shown includes the following steps S101 to S105.
[0092] In a specific embodiment of the present invention, before executing step S101, it is assumed that there is a set of mobile identity recognition devices at this time. To access a system for identity authentication, and for that system to be an authorized set, i.e., if and only if it contains at least k... m A user with a valid identity, and k m At least k of the users m-1 One from the set k m-2 One from the set And so on. Each mobile identification device P i Each ∈A will initiate an identity authentication request with the access control server through the access control identification device and submit valid authentication share information.
[0093] S101, respectively obtain authentication request information sent by multiple mobile identity recognition devices.
[0094] S102, based on the authentication request information and the first random number k i Calculate the identity verification challenge set {z} corresponding to multiple mobile identity recognition devices respectively. i ,θ i ,T}, where the identity verification challenge set {z} i ,θ i ,T} includes: identity verification challenge value z i Identity verification challenge value, signature value θ i and the signature value θ related to the identity verification challenge value i The corresponding timestamp T.
[0095] In step S102, based on the authentication request information and the first random number, the identity verification challenge set {z} corresponding to multiple mobile identity recognition devices is calculated respectively. i ,θ i The specific steps include: ,T}.
[0096] (1) Select the first random number k i Calculate the identity verification challenge value z according to the formula. i The specific calculation formula is expressed as: z i =k i +B, where B represents the two-way authentication parameter in the access control server.
[0097] (2) Use the signature private key to verify the identity challenge value z. i Perform a signature to obtain the identity verification challenge value signature value θ. i Identity verification challenge value, signature value θ i =Sig(z) i ,T), where T is the timestamp.
[0098] (3) The identity verification challenge value z i Identity verification challenge value signature value θ i Add them to the set to obtain the identity verification challenge set {z} i ,θ i ,T}.
[0099] S103, the identity verification challenge set {z i ,θ i The message ,T} is sent to the corresponding mobile identification device, and the identity verification response set {u} is received. i ,v i ,T i}, where the identity verification response set {u i ,v i ,T i This includes: identity verification response information (u i ,vi ) and the current session time (T) i ).
[0100] S104, using a decryption algorithm to process the identity verification response set {u i ,v i ,T i The device is decrypted to obtain the plaintext information of the mobile identification device. Based on the plaintext information, the verified mobile identification device is identified, and the verification information is sent to the mobile identification device.
[0101] In step S104, the identity verification response set {u} is processed using a decryption algorithm. i ,v i ,T i The process involves decryption to obtain the plaintext information of the mobile identification device, specifically including the following steps.
[0102] (1) Based on the identity verification response set {u i ,v i ,T i The identity verification response information in} i ,v i ), calculate the intermediate value for identity verification recovery; the specific calculation is expressed as: Y i =(x i ,y i )=k i v i , where Y i This indicates restoring the intermediate value for identity verification; (x i ,y i ) represents the coordinates of a point in the elliptic curve point set; v i This represents a value in the identity verification response information.
[0103] (2) Use the decryption algorithm to recover the intermediate value of identity verification and the set of identity verification responses {u i ,v i ,T i The corresponding private key is used to calculate the plaintext information of the mobile identity verification device. The specific calculation formula is: Dec SK (u i / f(x i ||y i ||T i ), where u i This represents a value in the identity verification response information.
[0104] S105, the set of identity verification responses corresponding to the verified mobile identification device {u i ,v i ,T iThe authentication information is stored in the verified set. Based on the verified set, it is calculated whether multiple mobile identification devices have completed authentication, and the authentication information is sent to the multiple mobile identification devices.
[0105] In step S105, the verification process is performed to determine whether multiple mobile identification devices have completed authentication, which includes the following steps.
[0106] (1) Obtain verification through multiple mobile identity recognition devices in the set, and obtain the level of each mobile identity recognition device and the secret share corresponding to the mobile identity recognition device.
[0107] (2) Using multiple secret shares, multiple general terms are obtained, and the multiple general terms are accumulated to obtain the verified general term.
[0108] (2.1) Utilize the authorization set A consisting of k1 mobile identification devices from set γ1 (1) The corresponding k1 secret shares Generate k1 points The k1-1 order polynomial p can be calculated using Lagrange interpolation. (1) (x): The first-order LHR general term can then be calculated.
[0109] (2.2) Then utilize the authorization set A composed of k2 mobile identification devices from the set γ1∪γ2. (2) For the corresponding k2 secret shares, calculate the corresponding second-level LHR general term.
[0110] (2.3) Repeat the above operation until the result comes from the set. k m An authorization set A consisting of mobile identification devices (m) The corresponding share recovered the m-th level LHR general term. Then, add these m LHR general terms together to obtain
[0111] (3) Determine if the verification formula is equal to the secret verification value stored in the access control server. If they are equal, authentication is complete; otherwise, authentication fails. The access control server uses h i Calculate the nth value h n ′, and compare h n ′=h n Whether it is true or not, where h nThis is a secret verification value stored internally on the server. If they match, authentication is successful, and the server sends an authentication success message to the access control device; otherwise, it sends an authentication failure message.
[0112] The national cryptographic algorithm SM2 and Shamir's threshold secret sharing scheme are used to generate relevant shares and signature messages, ensuring bidirectional authentication during the identity authentication process.
[0113] In a specific embodiment provided by the present invention, such as Figure 3 As shown, in the access control server, the authentication request from the mobile identification device is first received, and then a random number k is selected. i Calculate z i =k i +B, and sign it θ i =Sig(z) i ,T), and {z i ,θ i ,T} is sent to the mobile identification device;
[0114] Then receive the {u} returned by the mobile identification device i ,v i ,T i}, and according to {u i ,v i ,T i}, calculate Y i =(x i ,y i )=k i v i Decrypt Dec using SM2 SK (u i / f(x i ||y i ||T i Get id i It then determines whether the identification is correct and valid, obtains the result, and sends it to the mobile identification device.
[0115] If invalid, return to receive the next authentication request; if valid, extract the level l of the mobile identification device. i and all secret shares 1≤j≤l i .
[0116] Using the collected secret shares, recover m LHR general terms, and add them together to obtain Calculate h n ′=h n Whether it is valid or not, and based on the judgment result, to the mobile identity recognition device.
[0117] The system combines the national cryptographic SM2 encryption algorithm, the Shamir threshold secret sharing algorithm, and the LHR-based multi-level secret sharing scheme to implement the access control authentication process for important locations when multiple people are present and their identities are at different levels. It uses a unique user identifier to verify the validity of user identities and uses the recovery process of multi-level share information stored in the user's mobile identification device to verify the validity of the common identity when multiple users are present at the same time, thereby improving the security of the access control system authentication.
[0118] This invention provides a hierarchical multi-authentication access control identification method based on secret sharing, which is applied to a mobile identification device. The method includes the following steps S301 to S305.
[0119] S301 sends authentication request information for the mobile identity recognition device to be verified to the access control server.
[0120] S302, Obtain the identity verification challenge set {z i ,θ i ,T}, where the identity verification challenge set {z} i ,θ i ,T} includes: identity verification challenge value z i Identity verification challenge value, signature value θ i and the signature value θ related to the identity verification challenge value i The corresponding timestamp T.
[0121] S303, Signing the identity verification challenge value θ i Verify the signature and challenge the identity verification set {z}. i ,θ i ,T} calculate the identity verification response set {u i ,v i ,T i}, and the identity verification response set {u i ,v i ,T i} is sent to the access control server, where the identity verification response set {u i ,v i ,T i This includes: identity verification response information (u i ,v i ) and the current session time (T) i ).
[0122] In step S303, based on the identity verification challenge set {z} i ,θ i ,T} calculate the identity verification response set {u i ,v i ,Ti The specific steps include:
[0123] (1) Calculate the first identity verification intermediate value using the two-way authentication parameters in the access control server. The first identity verification intermediate value is specifically represented as: c i =z i +A-ID Server , where z i Indicates the identity verification challenge value; A represents; ID Server This indicates the identity identifier of the access control server.
[0124] (2) Select the second random number t i And based on the second random number t i Intermediate value c of the first identity verification i Calculate the intermediate value for the second identity verification, which is specifically represented as: X i =(x 2i ,y 2i ) = c i t i G, where (x 2i ,y 2i ) represents the coordinates of the second point on the point set of the circular curve; c i Indicates the intermediate value of the first identity verification; t i This represents the second random number; G = (x1, y1) is the base point on the elliptic curve point set.
[0125] (3) Based on the intermediate value X of the second identity verification i Calculate identity verification response information (u i ,v i ), thus obtaining the identity verification response set {u i ,v i ,T i}
[0126] Identity verification response information (u i ,v i Specifically, it is expressed as: Among them, (x 2i ,y 2i ) represents the coordinates of the second point on the point set of the circular curve; T i Indicates the current session time; t i W represents the second random number; i This indicates confidential information from a mobile identification device.
[0127] S304 receives the verification information sent by the access control server and sends the next authentication request information to the access control server until there is no more mobile identification device to be verified.
[0128] S305 receives authentication information.
[0129] This invention does not remain at the theoretical level, but proposes a design for the application implementation of a hierarchical multi-authentication access control and identity recognition system for important locations, from registration to actual authentication processes, and has strong practicality.
[0130] This invention provides a hierarchical multi-authentication access control and identity recognition system based on secret sharing, applied to an access control server. The system includes an authentication request information acquisition module, an identity verification challenge set calculation module, an identity verification response set acquisition module, an identity verification response set verification module, and an authentication module.
[0131] The authentication request information acquisition module is used to acquire authentication request information sent by multiple mobile identity recognition devices.
[0132] The identity verification challenge set calculation module is used to calculate the identity verification challenge set {z} corresponding to multiple mobile identity recognition devices based on the authentication request information and the first random number. i ,θ i ,T}, where the identity verification challenge set {z} i ,θ i ,T} includes: identity verification challenge value z i Identity verification challenge value, signature value θ i and the signature value θ related to the identity verification challenge value i The corresponding timestamp T;
[0133] The identity verification response set acquisition module is used to retrieve the identity verification challenge set {z}. i ,θ i The message ,T} is sent to the corresponding mobile identification device, and the identity verification response set {u} is received. i ,v i ,T i}, where the identity verification response set {u i ,v i ,T i This includes: identity verification response information (u i ,v i ) and the current session time (T) i );
[0134] The identity verification response set verification module is used to verify the identity verification response set {u} using a decryption algorithm. i ,v i ,T i The process involves decryption to obtain the plaintext information of the mobile identification device, identifying the verified mobile identification device based on the plaintext information, and sending the verification information to the mobile identification device.
[0135] The authentication module is used to process the set of identity verification responses corresponding to verified mobile identification devices {u i ,v i ,T i The authentication information is stored in the verified set. Based on the verified set, it is calculated whether multiple mobile identification devices have completed authentication, and the authentication information is sent to the multiple mobile identification devices.
[0136] This invention proposes a hierarchical multi-factor authentication access control identification method comprising two phases: a registration phase and an authentication phase, involving two entities: a server and a user (a mobile identity recognition system). In the registration phase, the server uses public-key encryption algorithms, including but not limited to the national cryptographic standard SM2, to encrypt sensitive information distributed to the mobile identity recognition system, such as user identification, user level, and the secret share required for authentication, and then secretly distributes the relevant parameters to the mobile identity recognition system. In the authentication phase, multiple mobile identity recognition systems sequentially communicate with the server through the access control device for authentication. Access control identification only succeeds when all levels of personnel meet the thresholds set for the access control system, all personnel identities are verified, and the final secret recovery value from the server is verified to be correct and valid. Otherwise, authentication fails, and access is blocked. The proposed protocol also solves the problems of one-way authentication and privacy protection by achieving two-way authentication in the authentication phase through digital signature technology and secret sharing technology, preventing attackers from impersonating the server for malicious behavior. Furthermore, during communication, attackers cannot obtain the user's privacy information related to the mobile identity recognition system except through the server.
[0137] The physical states and communication methods of the identification devices during implementation include, but are not limited to, the following: UKEY, connected to the access control device via a USB interface or cable; Bluetooth KEY, connected to the access control device via Bluetooth; IC key card, connected to the access control device via an IC card reader; Infrared KEY, connected to the access control device via infrared; NFC key card, connected to the access control device via NFC. Relevant identity verification information can be stored in these convenient storage media, improving portability. The confidentiality and verifiability of user identification, level, and secret share information in the portable identification device enhance the security and effectiveness of the hierarchical multi-level authentication process of the access control system.
[0138] The apparatus or module described in the above embodiments can be implemented by a computer chip or physical entity, or by a product with a certain function. For ease of description, the above apparatus is described by dividing it into various modules according to their functions. In implementing this invention, the functions of each module can be implemented in one or more software and / or hardware. Of course, a module that implements a certain function can also be implemented by combining multiple sub-modules or sub-units.
[0139] The various embodiments described in this specification are presented in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on its differences from other embodiments. All or part of this invention can be used in numerous general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, mobile communication terminals, multiprocessor systems, microprocessor-based systems, programmable electronic devices, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices, etc.
[0140] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the present invention.
Claims
1. A method for hierarchical multi-authentication access control identity recognition based on secret sharing, applied to an access control server, characterized in that, The method comprises the steps of: respectively acquiring authentication request information sent by a plurality of mobile identity recognition devices; According to the authentication request information and the first random number, a set of identity verification challenges corresponding to the plurality of movable identity recognition devices is calculated respectively , wherein the set of identity verification challenges comprises an identity verification challenge value , an identity verification challenge value signature value , and a timestamp corresponding to the identity verification challenge value signature value ; Set of identity verification challenges are sent to the corresponding mobile identity device and a set of identity verification responses are received Set of identity verification challenges are sent to the corresponding mobile identity device and a set of identity verification responses are received The set of identity verification responses Include identity verification response information And the current session time decrypting the identity verification response set using a decryption algorithm to obtain plaintext information of the mobile identity recognition device, determining the mobile identity recognition device that passes the verification according to the plaintext information, and sending verification information to the mobile identity recognition device; wherein the decryption algorithm is used to decrypt the identity verification response set to obtain the plaintext information of the mobile identity recognition device, and the mobile identity recognition device that passes the verification is determined according to the plaintext information, and verification information is sent to the mobile identity recognition device; wherein the decryption algorithm is used to decrypt the identity verification response set to obtain the plaintext information of the mobile identity recognition device, and the mobile identity recognition device that passes the verification is determined according to the plaintext information, and verification information is sent to the mobile identity recognition device; wherein the decryption algorithm is used to decrypt the identity verification response set , and the identity verification response information in the identity verification response set is used to calculate a recovered identity verification intermediate value; the specific calculation is represented as: , wherein represents the recovered identity verification intermediate value; represents a point coordinate in an elliptic curve point set; represents a first random number; represents a value in the identity verification response information; the identity verification response set corresponding private key is used to calculate the plaintext information of the mobile identity recognition device using a decryption algorithm, and the specific calculation formula is: , wherein represents a value in the identity verification response information; The identity verification response set corresponding to the mobile identity recognition device that passes the verification The authentication information is sent to the plurality of mobile identity recognition devices after it is determined that the plurality of mobile identity recognition devices complete authentication according to the verification pass set. 2.The method of hierarchical multi-authentication access control identity recognition based on secret sharing of claim 1, applied to an access control server, characterized in that, The authentication request information and a first random number are used to calculate a set of identity verification challenges corresponding to the plurality of mobile identity recognition devices respectively , and specifically comprises: selecting the first random number , calculating the identity verification challenge value according to a calculation formula , and the specific calculation formula is represented as: , , wherein the bidirectional authentication parameter in the access control server is represented. using a signature private key performing a signature to obtain a signature value of the identity-check challenge value , the signature value of the identity-check challenge value wherein is a timestamp; placing the identity check challenge value signing the identity check challenge value placing the identity check challenge value in a set, resulting in the identity check challenge set . 3.The method of hierarchical multi-authentication access control identity recognition based on secret sharing of claim 1, applied to an access control server, characterized in that, determining the mobile identity recognition device that passes the verification according to the plaintext information, and specifically comprising the steps of: acquiring a plaintext identity identifier in the plaintext information; judging whether the plaintext identity identifier exists in the plurality of mobile identity recognition devices; if yes, the verification is passed, and if no, the verification is failed. 4.The method of hierarchical multi-authentication access control identity recognition based on secret sharing of claim 1, applied to an access control server, characterized in that, calculating whether the plurality of mobile identity recognition devices complete the authentication according to the verification passing set, and specifically comprising the steps of: acquiring a plurality of mobile identity recognition devices in the verification passing set, and respectively acquiring the level of the mobile identity recognition device and the secret share corresponding to the mobile identity recognition device; obtaining a plurality of general polynomials by using a plurality of secret shares, and accumulating the plurality of general polynomials to obtain a verification passing general polynomial; judging whether the verification passing general polynomial is equal to the secret check value saved in the access control server; if yes, the authentication is completed; if no, the authentication is failed. 5.The method of hierarchical multi-authentication access control identity recognition based on secret sharing of claim 1, applied to an access control server, characterized in that, Before respectively acquiring the authentication request information sent by the plurality of mobile identity recognition devices, the method further comprises registering the access control server, and the registration specifically comprises the steps of: initializing the access control server, and determining the initialization parameter of the access control server; selecting a random number to construct a polynomial, and calculating the two-way authentication parameter of the access control server according to the polynomial and the random number; determining the secret share corresponding to each of the plurality of mobile identity recognition devices and the secret check value by using a hierarchical secret sharing method; The authentication set information of the mobile identity recognition device is respectively sent to the mobile identity recognition device, and the authentication set information of the mobile identity recognition device includes: mobile identity recognition device secret information , mobile identity recognition device signature value , and two-way authentication parameters, wherein the mobile identity recognition device secret information is generated according to the initialization parameters , and the mobile identity recognition device secret information is signed according to the two-way authentication parameters to determine the mobile identity recognition device signature value .
6. The method of hierarchical multi-authentication access control identity recognition based on secret sharing according to claim 5, applied to an access control server, characterized in that, the method of determining the secret share corresponding to each of the plurality of mobile identity recognition devices and the secret check value by using the hierarchical secret sharing method specifically comprises the steps of: dividing the mobile identity recognition devices in the mobile identity recognition device authentication set into different levels; different threshold values correspond to different levels, and the mobile identity recognition device authentication set with a level less than or equal to the level corresponding to the threshold value is divided into a subset; calculating the secret share of the mobile identity recognition device in the subset, and constructing a linear regression recursive relationship by using the secret share; accumulating the linear regression recursive relationship corresponding to the plurality of mobile identity recognition devices in the subset to obtain the secret check value.
7. A method for hierarchical multi-authentication access control identity recognition based on secret sharing, applied to a mobile identity recognition device, characterized in that, The method comprises the steps of: respectively sending the authentication request information of the mobile identity recognition device to be verified to the access control server; Acquiring identity verification challenge set Wherein the identity verification challenge set Comprise: identity verification challenge value Identity verification challenge value signature value And the identity verification challenge value signature value Corresponding timestamp ; signing the identity verification challenge value performing signature verification, and calculating the identity verification response set according to the identity verification challenge set performing signature verification, and calculating the identity verification response set according to the identity verification challenge set sending the identity verification response set to the access control server performing signature verification, and calculating the identity verification response set according to the identity verification challenge set the identity verification response set comprises identity verification response information and current session time performing signature verification, and calculating the identity verification response set according to the identity verification challenge set performing signature verification, and calculating the identity verification response set according to the identity verification challenge set performing signature verification, and calculating the identity verification response set according to the identity verification challenge set calculating a first identity check intermediate value by using the two-way authentication parameter in the access control server; selecting a second random number, and calculating a second identity check intermediate value according to the second random number and the first identity check intermediate value; calculating the identity verification response information according to the second identity verification intermediate value , obtaining the identity verification response set ; receiving the verification information sent by the access control server, and sending the next authentication request information to the access control server until there is no mobile identity recognition device to be verified; receiving the authentication information.
8. A secret sharing-based hierarchical multi-authentication access control identity recognition system applied to an access control server, characterized in that, The method comprises the steps of: an authentication request information acquisition module, configured to respectively acquire authentication request information sent by a plurality of mobile identity recognition devices; The identity verification challenge set calculation module is configured to calculate identity verification challenge sets corresponding to the plurality of mobile identity recognition devices respectively according to the authentication request information and the first random number , wherein the identity verification challenge set comprises an identity verification challenge value , an identity verification challenge value signature value , and a timestamp corresponding to the identity verification challenge value signature value ; Identity verification response set obtaining module, configured to send the identity verification challenge set to the corresponding movable identity recognition device, and receive an identity verification response set Identity verification response set obtaining module, configured to send the identity verification challenge set to the corresponding movable identity recognition device, and receive an identity verification response set Identity verification response set obtaining module, configured to send the identity verification challenge set to the corresponding movable identity recognition device, and receive an identity verification response set Identity verification response set obtaining module, configured to send the identity verification challenge set to the corresponding movable identity recognition device, and receive an identity verification response set Identity verification response set obtaining module, configured to send the identity verification challenge set to the corresponding movable identity recognition device, and receive an identity verification response set Identity verification response set obtaining module, configured to send the identity The identity verification response set verification module is used to verify the identity verification response set using a decryption algorithm. Decryption is performed to obtain the plaintext information of the mobile identity verification device. Based on the plaintext information, the verified mobile identity verification device is determined, and the verification information is sent to the mobile identity verification device. The step of using a decryption algorithm to analyze the identity verification response set... Decryption is performed to obtain the plaintext information of the mobile identity verification device, specifically including: based on the identity verification response set. The identity verification response information in Calculate the intermediate value for identity verification; the specific calculation is as follows: ,in, This represents the intermediate value for restoring identity verification; Represents the coordinates of a point in the elliptic curve point set; Represents the first random number; This represents a value in the identity verification response information; the decryption algorithm is used to recover the intermediate identity verification value and the identity verification response set. The corresponding private key is used to calculate the plaintext information of the mobile identity verification device. The specific calculation formula is as follows: ,in, This represents a value in the identity verification response information; An authentication module is configured to check the identity of the mobile identification device that passes the verification The authentication information is sent to the plurality of mobile identification devices based on the verification pass set.
Citation Information
Patent Citations
Bullet warehouse protection door management method capable of being remotely authorized and managed
CN114373253A
Method for secure contactless communication of a smart card and a point of sale terminal
US20140289129A1