A reverse firewall method applicable to identity key negotiation

By deploying reverse firewalls for all participants in the identification key negotiation protocol and using a re-randomization algorithm, privacy leakage problems caused by internal attacks are solved, achieving higher security and leakage resistance.

CN117914482BActive Publication Date: 2025-07-18CHENGDU FANLIAN ZHICUN TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202410078914.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-19
Publication Date
2025-07-18
Estimated Expiration
2044-01-19

AI Technical Summary

Technical Problem

The existing identification key negotiation protocol cannot effectively resist internal attacks, resulting in leakage of user privacy information and is difficult to detect by third-party professional institutions.

Method used

The reverse firewall is deployed for all participants in the identification key negotiation protocol, and the user's session token is processed through a re-randomization algorithm to ensure that even if internal attackers embed the backdoor, privacy information will not be leaked.

Benefits of technology

Enhance the protocol's anti-leakage ability, prevents internal attackers from extracting privacy from user public information, and improves security and resistance to proactive attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117914482B_ABST
    Figure CN117914482B_ABST
Patent Text Reader

Abstract

The present invention discloses a reverse firewall method applicable to identity key negotiation, belonging to the field of information security technology. By deploying reverse firewalls to all parties involved in the protocol, no matter which party in the protocol is subverted by an internal attacker, the method of the present invention can ensure that the privacy of the protocol parties will not be leaked to the internal attacker, thereby realizing the privacy leakage prevention of the overall protocol. Compared with the tag key negotiation method, the present invention enhances security: even if the protocol parties use subverted algorithms, that is, the protocol parties use algorithms tampered with by internal attackers, the present invention can also ensure that the privacy of the protocol parties will not be leaked to the attacker.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and particularly relates to a reverse firewall method applicable to identity-based key negotiation. Background Art

[0002] In a communication network, internal attacks can not only steal a large amount of user privacy, but also are difficult to be detected by third-party professional institutions. At present, scholars have found that such attacks can break all probabilistic cryptographic algorithms, such as encryption, signature, key negotiation, etc., with a non-negligible probability advantage. Identity-based key negotiation also cannot resist such attacks, and internal attackers can easily leak the user's ephemeral session key and long-term session private key.

[0003] In order to successfully resist such attacks, scholars have proposed the concept of "cryptographic reverse firewall". A reverse firewall can not only maintain the security and functionality of the original protocol, but also has the property of preventing leakage. In addition, a reverse firewall is a transparent and "untrusted" third party. "Untrusted" means that a reverse firewall can only process the public incoming and outgoing information of users, but the algorithm of the reverse firewall has not been subverted by internal attackers.

[0004] Identity-based key negotiation can enable two or more parties to establish a session key over an insecure channel and solve the certificate management problem, so it is widely used in fields such as cloud computing, the Internet of Things, and the Internet. Building a reverse firewall applicable to identity-based key negotiation is an extremely important task for both national security and ordinary users.

[0005] In 2015, the literature "Cryptographic reverse firewalls. Advances in Cryptology - EUROCRYPT 2015, Part II, LNCS 9057, pp. 657 - 686, 2015" first proposed the concept of cryptographic reverse firewalls, and gave three properties of a reverse firewall: (1) Maintaining functionality: Whether a reverse firewall exists or not, the protocol function is not damaged; (2) Retaining security: The protocol with a reverse firewall has the same security as the original underlying protocol; (3) Preventing leakage, that is, even if the user's internal algorithm is subverted, due to the re-randomization of the reverse firewall, an attacker cannot extract privacy from the user's public information. In addition, they also constructed a re-randomizable garbled circuit to implement private function computing, and proved that a reverse firewall cannot be subverted. Finally, based on oblivious transfer, they implemented a general structure that can transform any protocol into a protocol that can be successfully deployed with a reverse firewall.

[0006] In 2016, the literature "Message transmission with reverse firewalls - secure communication on corrupted machines. Advances in Cryptology - CRYPTO 2016, Part I, LNCS 9814, pp. 341 - 372, 2016" disclosed a two - round public - key encrypted message transmission protocol with reverse firewalls; it also proposed the definitions of rerandomizability and key malleability respectively: it was proved that a protocol satisfying rerandomizability is chosen - plaintext secure (CPA), and a protocol with key malleability is chosen - ciphertext secure (CCA). In addition, to solve the inefficiency problem of public - key encryption, they also constructed a two - party key - agreement protocol with reverse firewalls. This construction method can achieve three properties of reverse firewalls with only 4 - round interactions and constant - level rerandomization operations. Finally, taking ElGamal as the underlying protocol, they implemented the instantiation of the above - mentioned protocol.

[0007] In 2016, the literature "Cryptographic reverse firewall via malleable smooth projective hash functions. Advances in Cryptology - ASIACRYPT 2016, Part I, LNCS 10031, pp. 844 - 876, 2016" proposed malleable smooth projective hash functions (MSPHFs). They defined that such functions need to satisfy mapping - key malleability (including key indistinguishability and mapping consistency) and element - rerandomizability (element indistinguishability and rerandomization consistency). And they proposed how to construct such functions using garbled circuits. Finally, they used such functions to construct a key - transmission protocol without keys with reverse firewalls and also constructed a signature - based oblivious - envelope protocol with reverse firewalls. In summary, by means of malleable smooth projective hash functions, they further expanded the scope of protocols applicable to reverse firewalls, making reverse firewalls more general.

[0008] In 2018, Ma et al. proposed a new offline / online attribute-based encryption protocol in the literature "Concessive online / offline attribute based encryption with cryptographic reverse firewalls - secure and efficient fine-grained access control on corrupted machines. Computer Security - ESORICS 2018, LNCS 11099, pp. 507 - 526, 2018". This protocol meets the re-randomization requirements of the reverse firewall. At the same time, they used this protocol as the underlying protocol to construct a reverse firewall protocol suitable for attribute-based encryption. In addition, they proved through game indistinguishability that this protocol not only meets the chosen-plaintext security but also can achieve leakage prevention. Meanwhile, the experimental results show that this protocol not only enhances security but also improves efficiency.

[0009] In 2022, Li et al. proposed a signature scheme for non-interactive password reverse firewalls in the literature "A secure two-factor authentication scheme from password-protected hardware token. IEEE Transactions on Information Forensics and Security, 17: 3525 - 3538, 2022". This signature scheme does not require an increase in communication costs and can also avoid privacy leakage problems caused by communication. In addition, they also proved that this signature scheme meets the existential unforgeability under adaptive chosen-message attacks.

[0010] In 2023, Zhou et al. proposed a password reverse firewall protocol for searchable encryption in cloud storage in the literature "Searchable public-key encryption with cryptographic reverse firewalls for cloud storage. IEEE Transactions on Cloud Computing, 2023, 11(1): 383 - 396". They proved that this protocol can not only prevent privacy leakage but also resist keyword guessing attacks in searchable encryption.

[0011] In addition, the patent application with the publication number CN111404899A proposed a cryptographic reverse firewall method applicable to certificate-free key agreement. This method successfully proved that this protocol can meet the three major properties of the reverse firewall, achieving the purpose of preventing user privacy leakage. In addition, the patent application with the publication number CN111447064A also proposed a cryptographic reverse firewall method applicable to certificate-free encryption. This method mainly deploys a cryptographic reverse firewall between the key generation center and the encrypting party, thereby realizing the privacy leakage prevention property of the protocol. In the field of signatures, the patent application with the publication number CN111404693A constructed a cryptographic reverse firewall applicable to digital signatures by deploying a reverse firewall to the signing party, thus ensuring that the privacy of the signing party is not leaked. Summary of the Invention

[0012] The present invention discloses a reverse firewall method applicable to identity-based key agreement, which constructs reverse firewalls for all parties participating in the protocol, so as to ensure that even if there is an internal attacker and a backdoor is embedded in the processing algorithm, the privacy of all parties will not be leaked.

[0013] The technical solution adopted by the present invention is as follows:

[0014] A reverse firewall method applicable to identity-based key agreement, the method comprising:

[0015] 1. Setup phase:

[0016] (1-1) G1 is a prime order subgroup of the elliptic curve E over the finite field F q and G2 is a subgroup of the finite field both with the order denoted by l. Define k as the smallest number such that l|q k -1, and define a bilinear mapping based on G1 and G2: Define a secure cryptographic hash function H: {0,1} * →G1; define a key derivation function: V: where {0,1} * represents a bit string of arbitrary length; where the superscript "*" of the finite field indicates that the finite field contains 0, and the finite field without the "*" does not contain 0, and the subscript is the modulus (also called the element) of the finite field. For example, F q represents a finite field of order q.

[0017] (1-2) The Key Generate Center (KGC) selects a master private key s ∈ {1,..., l-1}, randomly selects a generator P ∈ G1, and calculates the partial public parameter P KGS = sP;

[0018] (1-3) The reverse firewall W of the KGC KGCReceive parameters {P, P KGS}, W KGC Select a random number Re-randomize the public parameter P 1 = xP, P KGS 1 = xP KGS , and send the re-randomized public parameters {P 1 , P KGS 1} to the KGC, and the KGC publishes the public parameters Among them, the finite field

[0019] 2. Registration phase:

[0020] (2-1) User 1 (Alice) submits the identity information ID A to the key generation center for identity registration; User 2 (Bob) submits the identity information ID B to the key generation center for identity registration, where User 1 and User 2 are the two parties for key negotiation.

[0021] (2-2) The KGC receives ID A , calculates the parameter Q A = H(ID A ), the private key S A = sQ A , and the KGC sends S A to Alice; The KGC receives ID B , calculates the parameter Q B = H(ID B ), the private key S B = sQ B ; The KGC sends S B to Bob.

[0022] 3. Key negotiation:

[0023] (3-1) Alice selects a temporary private key calculates T A = aP 1 , Q A = H(ID A ), and sends {T A , Q A} to Bob; Bob selects a temporary private key calculates T B = bP 1 , Q B = H(ID B ), and sends {T B , Q B} to Alice;

[0024] (3-2) Alice's Reverse Firewall W A Select a random number W A Receive {T A , Q A}, calculate Q A 1 =x a Q A , T A 1 =T A , and send {T A 1 , Q A 1} to Bob; W A Receive {T B 1 , Q B 1}, calculate T B 2 =x a T B 1 , Q B 2 =Q B 1 , and send {T B 2 , Q B 2} to Alice;

[0025] (3-3) Bob's Reverse Firewall W B Select a random number W B Receive {T B , Q B}, calculate Q B 1 =x b Q B , T B 1 =T B , W B Send {T B 1 , Q B 1} to Alice; W B Receive {T A 1 , Q A 1}, calculate T A 2 =x b T A 1 , QA 2 = Q A 1 , W B Send {T A 2 , Q A 2}} to Bob;

[0026] (3 - 4) Alice receives {T B 2 , Q B 2} and then calculates Bob receives {T A 2 , Q A 2} and then calculates

[0027] (3 - 5) Verify whether k A = k B holds. If it holds, the identity authentication is successful and the key negotiation is completed; otherwise, it fails;

[0028] (3 - 6) Calculate the session key K = V(k A ) = V(k B ).

[0029] The technical solution provided by the present invention has at least the following beneficial effects:

[0030] Due to the above - mentioned technical solution, the beneficial effect of the present invention is that the present invention deploys reverse firewalls for each participant of the protocol applicable to identity - based key negotiation, enhancing the ability to resist active attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following - described drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0032] Figure 1 It is a schematic diagram of the system model when the embodiment of the present invention is implemented;

[0033] Figure 2 It is a processing flow chart of the setup phase of the embodiment of the present invention;

[0034] Figure 3 It is a processing flow chart of the registration phase of the embodiment of the present invention;

[0035] Figure 4This is the processing flowchart of the key negotiation phase in the embodiments of the present invention, where the red numbers are the re-randomization algorithms of Party Alice, and the black numbers are the re-randomization algorithms of Party Bob. Detailed implementation manners

[0036] To make the objectives, technical solutions and advantages of the present invention clearer, the following will further describe the embodiments of the present invention in detail with reference to the accompanying drawings.

[0037] The embodiments of the present invention provide a reverse firewall method applicable to identity key negotiation. Figure 1 This is the schematic diagram of the system model when the embodiments of the present invention are implemented. It can be seen from Figure 1 that the key generation center KGC selects a generator P and sets a master private key s for generating a master public key P KGS ; the re-randomization system parameter of the reverse firewall of KGC is P 1 , P KGS 1 , and sends {P 1 , P KGS 1} to the participating parties (including KGC); the user submits the identity information ID to KGC, and KGC generates the user's long-term private key S according to the submitted identity information ID of the user and the master private key ID . Even if KGC uses a backdoored setting and key extraction algorithm, the re-randomization of the reverse firewall of KGC makes it impossible for an attacker to distinguish between the honest behavior and the subversive behavior of KGC, let alone extract privacy from it. In addition, Figure 1 also shows the operation mechanism of the cryptographic reverse firewall of both communication parties. W A re-randomizes the session token generated by Alice and the received Bob session token. Similarly, W B re-randomizes the incoming and outgoing session tokens of Bob. Due to the re-randomization of the cryptographic reverse firewall, this ensures that even if Alice and Bob use a backdoored random number generator or a backdoored session key generation algorithm, an internal attacker cannot extract privacy information from the re-randomized messages.

[0038] The above comprehensive description of the cryptographic reverse firewall shows that the method of the present invention has anti-leakage properties. Even if any party in the method is embedded with a backdoor, the privacy information in the protocol will not be leaked.

[0039] Refer to Figure 2 , Figures 3 and 4. The execution steps include three phases: a setup phase, registration, and key negotiation, which are specifically described as follows:

[0040] (1) Setup phase:

[0041] (1.1) G1 is the elliptic curve E over F qA prime-order subgroup of, G2 is a subgroup of, and the orders are all represented by l. Define k as the smallest number such that l|q k -1, and define a bilinear mapping based on G1 and G2: Define a secure cryptographic hash function H: {0, 1} * →G1; Define a key derivation function: V: where {0, 1} * represents bit strings of arbitrary length.

[0042] (1.2) The Key Generate Center (KGC) selects a master private key s ∈ {1,..., l - 1}, randomly selects a generator P ∈ G1, and calculates P KGS = sP and publishes the system parameters.

[0043] (1.3) The reverse firewall W of the KGC KGC receives the parameters {P, P KGS}, and W KGC selects a random number to re-randomize the public parameter P 1 = xP, P KGS 1 = xP KGS , and sends the re-randomized public parameters {P 1 , P KGS 1} to the KGC. The KGC publishes the public parameters

[0044] (2) Registration phase:

[0045] (2.1) Alice submits her identity information ID A to the key generate center for identity registration; Bob submits his identity information ID B to the key generate center for identity registration.

[0046] (2.2) The KGC receives ID A , calculates Q A = H(ID A ), S A = sQ A , and the KGC sends S A to Alice; The KGC receives ID B , calculates Q B = H(ID B ), S B = sQ B ; The KGC sends S B to Bob.

[0047] (3) Key agreement:

[0048] (3.1) Alice selects a temporary private key Calculate T A = aP 1 , Q A = H(ID A ), and send {T A , Q A} to Bob;

[0049] (3.2) Bob selects a temporary private key Calculate T B = bP 1 , Q B = H(ID B ), and send {T B , Q B} to Alice;

[0050] (3.3) Alice's reverse firewall W A selects a random number Bob's reverse firewall W B selects a random number

[0051] (3.4) W A receives {T A , Q A}, calculates T A 1 = T A , Q A 1 = x a Q A , and sends {T A 1 , Q A 1} to Bob; W B receives {T B , Q B}, calculates Q B 1 = x b Q B , T B 1 = T B , and sends {T B 1 , Q B 1} to Alice;

[0052] (3.5) Alice's reverse firewall W A receives {T B 1 , QB 1 , calculate T B 2 = x a T B 1 , Q B 2 = Q B 1 Then send {T B 2 , Q B 2} to Alice; Bob's reverse firewall W B Receives {T A 1 , Q A 1 , calculate T A 2 = x b T A 1 , Q A 2 = Q A 1 Then send {T A 2 , Q A 2} to Bob;

[0053] (3.6) Alice receives {T B 2 , Q B 2} and then calculates Bob receives {T A 2 , Q A 2} and then calculates

[0054] (3.7) Verify if k A = k B holds. If it holds, the identity authentication is successful and the key negotiation is completed; otherwise, it fails;

[0055] (3.8) Calculate the session key K = V(k A ) = V(k B ).

[0056] The correctness verification is as follows:

[0057]

[0058]

[0059] A reverse firewall method applicable to identity key negotiation provided by an embodiment of the present invention deploys reverse firewalls for all parties (key generation center, Alice, Bob) participating in the protocol. No matter which party participating in the protocol is subverted by an internal attacker, the method of the present invention can ensure that the privacy of the protocol participants will not be leaked to the internal attacker, thereby realizing the privacy leakage prevention of the overall protocol. This method enhances the security compared with the previous tag key negotiation method: even if the protocol participants use subverted algorithms (algorithms tampered with by internal attackers), the privacy of the protocol participants will not be leaked to the attacker.

[0060] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

[0061] The above are only some embodiments of the present invention. For those of ordinary skill in the art, without departing from the inventive concept of the present invention, several deformations and improvements can still be made, and these all belong to the protection scope of the present invention.

Claims

1. A reverse firewall method applicable to identity key negotiation, characterized in that, Including the following steps:

1. Setup phase: (1-1) Define \(G_1\) as the subgroup of prime order of the elliptic curve \(E\) over the finite field \(\mathbb{F}\). q Let \(G_2\) be a subgroup of the finite field both with orders denoted by \(l\). Define \(k\) as the smallest number such that \(l\mid q k - 1, and define a bilinear map based on \(G_1\) and \(G_2\): Define a secure cryptographic hash function \(H:\{0,1\} * \to G_1\); define a key derivation function where {0, 1} * represents a bit string of arbitrary length, a finite field with superscript "*" means it contains 0, without superscript "*" means it does not contain 0, and the subscript is the modulus of the finite field; (1-2) The Key Generation Center KGC selects a master private key s ∈ {1,..., l - 1}, randomly selects a generator P ∈ G1, and calculates the partial public parameter P KGS = sP; (1-3) Reverse firewall W of KGC KGC Receives the parameters {P, P KGS}, W KGC Selects a random number x from the finite field and re-randomizes the public parameter P 1 = xP, P KGS 1 = xP KGS , and sends the re-randomized public parameters {P 1 , P KGS 1} to KGC, and KGC publishes the public parameters 2. Registration phase: (2-1) User 1 submits the identity information ID A to the key generation center for identity registration; User 2 submits the identity information ID B to the key generation center for identity registration, where User 1 and User 2 are the two parties for key negotiation; (2-2) KGC receives the ID A , calculates the parameter Q A = H(ID A ), the private key S A = sQ A , KGC sends S A to User One; KGC receives the ID B , calculates the parameter Q B = H(ID B ), the private key S B = sQ B ; KGC sends S B to User Two; 3. Key negotiation: (3-1) User 1 selects a temporary private key Calculate parameter T A = aP 1 , parameter Q A = H(ID A ), send {T A , Q A} to User 2; User 2 selects a temporary private key Calculate parameter T B = bP 1 , parameter Q B = H(ID B ), send {T B , Q B} to User 1; (3-2) Reverse Firewall W of User 1 A Select a random number W A Receive {T A , Q A}, and calculate parameter Q A 1 = x a Q A , parameter T A 1 = T A , and send {T A 1 , Q A 1} to User 2; W A After receiving {T B 1 , Q B 1}, calculate parameter T B 2 = x a T B 1 , parameter Q B 2 = Q B 1 , and send {T B 2 , Q B 2} to User 1; (3-3) Reverse Firewall W of User 2 B Select a random number W B Receive {T B , Q B}, and calculate parameter Q B 1 = x b Q B , parameter T B 1 = T B , W B Send {T B 1 , Q B 1}} to User 1; W B After receiving {T A 1 , Q A 1}, calculate parameter T A 2 = x b T A 1 , parameter Q A 2 = Q A 1 , W B Send {T A 2 , Q A 2} to User Two; (3-4) After User 1 receives {T B 2 , Q B 2}, calculate the parameters After User 2 receives {T A 2 , Q A 2}, calculate the parameters (3 - 5) Verify k A = k B If it holds, the identity authentication is successful and the key negotiation is completed; otherwise, it fails. (3-6) Calculate the session key K = V(k A ) = V(k B ).

Citation Information

Patent Citations

  • Password reverse firewall method suitable for digital signature

    CN111404693A

  • Password reverse firewall method suitable for one-round three-party key negotiation

    CN111404899A

  • Password reverse firewall method suitable for certificateless encryption

    CN111447064A

  • Dynamic application address conversion method and gateway system

    CN104378363A

  • Password reverse firewall method suitable for proxy re-encryption

    CN111277413A