An unrevocable authentication method
By introducing the human extractable verification code problem system and human oracle into the remote electronic voting system of DAOs, inalienable identity authentication without relying on complex hardware is achieved, and the problem of difficulty in preventing coercion and bribery in the existing technology is solved, and the fairness of voting is ensured.
Patent Information
- Application Number
- CN202411839220.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-13
AI Technical Summary
The prior art has shortcomings in preventing coercion and bribery in remote electronic voting in DAOs, especially when it is difficult to achieve inalienable identity authentication without relying on complex hardware such as TEE or ASIC.
By introducing a human extractable verification code problem system and a human oracle, the proof party and the verification party will inadvertently transmit the verification code problem, and use the human oracle to generate corresponding proof party solutions to conduct zero-knowledge knowledge proof to ensure the inalienability of identity authentication.
This method does not need to rely on complex hardware. Through linear human extractability and zero-knowledge knowledge proof, it ensures the inalienability of identity authentication, effectively prevents bribery, and ensures the fairness of DAOs.
Smart Images

Figure CN119293778B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of identity authentication, and in particular relates to an inalienable identity authentication method. Background Art
[0002] With the development of blockchain, decentralized autonomous organizations (DAOs) have gradually emerged. The decision-making process of DAOs is voting through smart contracts, and the voting rights of each participant are determined by their shares. However, remote electronic voting in DAOs is vulnerable to coercion and bribery. Existing anti-coercion schemes resist coercion by re-voting or generating fake ballots, but all these anti-coercion voting schemes assume that the authentication procedure is inalienable.
[0003] However, an attack launched by a non-transparent decentralized bribery organization on the blockchain breaks the assumption of inalienable authentication. The attack uses Trusted Execution Environment (TEE) or Secure Multi-Party Computation (MPC) to encrypt keys and attack the identifiable verification of remote electronic voting systems, allowing voters to pass the verification step without knowing their actual keys. This attack makes bribery in DAOs possible, realizes automated bribery, and seriously endangers the governance of DAOs.
[0004] In addition, the current method for the aforementioned attacks is mainly a method called Proof of Complete Knowledge (PoCK). However, this method theoretically assumes that the prover needs to transmit the evidence in plain text on an unencrypted wiretap channel. In addition, when instantiating this scheme, it is necessary to use the hardware assumption of TEE or Application-Specific Integrated Circuit (ASIC).
[0005] "Kelkar, M., Babel, K., Daian, P., Austgen, J., Buterin, V., Juels,A.: Complete knowledge: Preventing encumbrance of cryptographic secrets. Cryptology ePrint Archive, Report 2023 / 044 (2023)" proposes two methods to implement PoCK: one based on TEE and the other based on ASIC. The TEE-based scheme simply uses TEE to prove unrestricted knowledge through remote authentication; while the ASIC-based scheme requires the prover to have ASIC and exploits the performance gap between TEE and ASIC. However, this method theoretically assumes that the prover needs to transmit the evidence in plaintext over an unencrypted eavesdropping channel. So far, not every (public) blockchain participant is equipped with TEE or ASIC, which makes this scheme difficult to deploy in practice. Summary of the invention
[0006] The purpose of the embodiments of the present application is to provide an inalienable identity authentication method to address the problems existing in the prior art.
[0007] According to a first aspect of an embodiment of the present application, an inalienable identity authentication method is provided, which is applied to a proving party, wherein the proving party holds a statement and evidence, and the method comprises:
[0008] Based on the evidence it holds, it obtains part of the captcha puzzle from the verifier through oblivious transmission, and uses a human oracle to generate the corresponding prover’s answer;
[0009] Committing the prover's solution to the evidence and the obtained verification code puzzle, and sending the commitment to the verifier;
[0010] Accepting a verification party ciphertext sent by a verification party and verifying the honesty of the verification party, wherein the verification party ciphertext is generated by the verification party based on the verification party solutions corresponding to all verification code puzzles;
[0011] If the verification is successful, the prover's answer held by the party is encrypted to obtain the prover's answer ciphertext, and the prover's reply ciphertext is calculated based on the evidence, the verifier's ciphertext and the prover's answer ciphertext, and the prover's reply ciphertext is sent to the verifier, so that the verifier verifies the prover's reply ciphertext;
[0012] If the verification is successful, based on the commitment, the verifier proves its honesty to the verifier so that the verifier will disclose all verification code problems after the verification is successful.
[0013] Furthermore, based on the evidence in their possession, they obtain part of the verification code from the verification party through inadvertent transmission, specifically:
[0014] For the verifier CAPTCHA Puzzles , using each bit of the evidence, from a pair of CAPTCHA puzzles Among them, one is selected through oblivious transfer, and we get CAPTCHA Puzzles ,in The length of the evidence.
[0015] Furthermore, the proving party replies with the ciphertext ,in To solve the ciphertext for the prover, each bit of evidence , To verify the ciphertext, The length of the evidence.
[0016] Furthermore, based on the commitment, the honesty of the party is proved to the verifier, including:
[0017] A standard zero-knowledge proof of knowledge protocol is run with the verifier to prove to the verifier that the commitment key used to generate the commitment is honestly generated, that the prover's reply ciphertext is honestly calculated based on the evidence corresponding to the commitment and the prover's answer, and that the evidence satisfies a binary relationship with the statement.
[0018] According to a second aspect of an embodiment of the present application, there is provided an inalienable identity authentication method, which is applied to a verification party, wherein the verification party holds a statement, and the method comprises:
[0019] Generate a captcha puzzle and a corresponding verifier solution, so that the prover, based on the evidence it holds, obtains part of the captcha puzzle from the verifier through oblivious transmission, obtains the corresponding prover solution using a human oracle, and commits to the evidence and the obtained prover solution to the captcha puzzle, and sends the commitment to the verifier;
[0020] Generate a verifier ciphertext based on all verifier answers, send the verifier ciphertext to the prover and prove its own honesty to the prover, so that the prover encrypts the prover answer held by itself to obtain the prover answer ciphertext after the verification is passed, calculate the prover reply ciphertext based on the evidence, the verifier ciphertext and the prover answer ciphertext, and send the prover reply ciphertext to the verifier;
[0021] The ciphertext replied by the prover is verified. If the verification is successful, the honesty of the prover is verified based on the commitment. If the verification is successful, all verification code puzzles are made public.
[0022] Further, generating a verification party ciphertext based on all verification party answers, sending the verification party ciphertext to the proving party and proving the proving party's own honesty, including:
[0023] Generate an additively homomorphic encryption key pair , and the public key Sent to the proving party, where sk is the private key;
[0024] The opposite of all verifiers' answers , encrypted to get the ciphertext ,in for the length of the evidence;
[0025] Ciphertext Send to the proving party;
[0026] Ciphertext , run a standard zero-knowledge proof protocol with the prover to prove to the prover that the public key pk it sent was honestly generated, and that the verification code puzzles and the corresponding solutions used for inadvertent transmission and encryption are honestly generated.
[0027] Furthermore, the ciphertext replied by the proving party is verified, specifically:
[0028] Decrypt the ciphertexts replied by all the proving parties. If the decrypted ciphertexts replied by all the proving parties are 0, the verification is successful.
[0029] According to a third aspect of an embodiment of the present application, a computer program product is provided, comprising a computer program / instruction, which, when executed by a processor, implements the method described in the first aspect or the second aspect.
[0030] According to a fourth aspect of an embodiment of the present application, there is provided an electronic device, including:
[0031] one or more processors;
[0032] A memory for storing one or more programs;
[0033] When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in the first aspect or the second aspect.
[0034] According to a fifth aspect of an embodiment of the present application, a computer-readable storage medium is provided, on which computer instructions are stored. When the instructions are executed by a processor, the steps of the method described in the first aspect or the second aspect are implemented.
[0035] The technical solution provided by the embodiments of the present application may have the following beneficial effects:
[0036] This application abandons the framework in the full knowledge proof PoCK scheme, and no longer requires the assumption that "evidence is transmitted in plain text on an unencrypted wiretap channel". It introduces a human-extractable verification code puzzle system and a human oracle, which can be completed only through the interaction between computer programs and humans during instantiation, without relying on complex hardware assumptions such as TEE / ASIC, and is a more convenient and effective solution.
[0037] This method has linear human extractability, which ensures the inalienability of knowledge in the zero-knowledge knowledge proof process; applied to the electronic voting authentication system on the blockchain, it can effectively prevent vote-buying and ensure the fairness of DAOs; compared with the previous full knowledge proof method, this method has fewer assumptions and does not rely on complex hardware assumptions during the instantiation process, but can complete the execution of the protocol by introducing computer programs and human interaction. When both the prover and the verifier are honest, the method can be executed normally. In the case of a malicious prover or a malicious verifier, the method will detect the existence of the malicious participant and allow the verifier or the prover to exit the protocol.
[0038] "Straight-line human extractability" means that when the prover and the verifier only execute the zero-knowledge proof protocol once (single execution means straight-line), there is an extractor that can extract the prover's evidence by accessing the corresponding interaction records and the access records to the oracle.
[0039] "Inalienability" means that in a proof process, if a provers possesses evidence w, and completes the proof through the evidence w in the execution of a zero-knowledge proof of knowledge protocol, then the person who executes the proof process must be the prover himself.
[0040] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0042] Figure 1 The figure is a schematic diagram of an inalienable identity authentication method according to an exemplary embodiment.
[0043] Figure 2 The present invention is a flowchart of an inalienable identity authentication method (applied to a prover) according to an exemplary embodiment.
[0044] Figure 3The present invention is a flowchart of an inalienable identity authentication method (applied to a verification party) according to an exemplary embodiment.
[0045] Figure 4 The present invention is a block diagram showing an inalienable identity authentication device (applied to a prover) according to an exemplary embodiment.
[0046] Figure 5 The present invention is a block diagram showing an inalienable identity authentication device (applied to a verification party) according to an exemplary embodiment.
[0047] Figure 6 The diagram is a schematic diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION
[0048] Here, exemplary embodiments are described in detail, and examples thereof are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application.
[0049] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms of "a", "said" and "the" used in this application and the appended claims are also intended to include plural forms unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.
[0050] It should be understood that although the terms first, second, third, etc. may be used in the present application to describe various information, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0051] This application provides an inalienable identity authentication method that can be used for blockchain voting authentication. In this case, the proving party is the voting client held by the user, and the verifier is the authentication server of the voting system. Assuming that the human-extractable zero-knowledge knowledge proof system is applied to a certain NP binary relation R, the proving party's input is a statement x (the proving party's blockchain public key) and a piece of evidence w (the proving party's blockchain private key), and the verifier's input is a statement x. The length of evidence w is , Right now This method can prove that statement x and evidence w satisfy a certain NP binary relation R. In one embodiment, , It is a generator on the multiplicative cyclic group in the key generation algorithm used to generate the blockchain public and private keys (i.e. x and w) of the prover.
[0052] The following combination Figure 1 The method is explained.
[0053] Step S1: The verifier generates a verification code puzzle and a corresponding verification solution;
[0054] In this phase, the verifier randomly selects random numbers, and use these random numbers to generate Answers to verification code problems and corresponding verification parties ,in For verification code puzzles, Solve the problem for the corresponding verifier. In a specific implementation, the verifier can use a public (human-extractable) captcha puzzle system To generate verification code problems and corresponding verification party solutions.
[0055] Specifically, a captcha puzzle system It consists of two parts, is a verification code generation algorithm, which uses the random number and security parameters As input, a verification code puzzle can be randomly generated And its corresponding answer . Oracle is a family of functions that can efficiently solve CAPTCHA problems in polynomial time, that is, for any function given by Generated verification code puzzles and solutions , satisfy CAPTCHA puzzles are easy for humans to solve, but difficult for computer programs. Suppose that for a computer program without H access rights, it is possible to solve the problem in polynomial time. Answer The probability of is negligible.
[0056] A human-extractable CAPTCHA system is a CAPTCHA system, but it needs to satisfy another property, namely "human extractability". , you must visit Then we know that for The access records will include verification code problems Suppose a computer program is given two CAPTCHA puzzles one of the as input and in Successfully got the answer with the help of , then there will be a Access rights extractor, through which the program Access records and As input, the corresponding bit information can be extracted In other words, a computer program can There is an efficient extractor for access records that can effectively distinguish the two captcha puzzles.
[0057] It should be noted that the verifier does not hold the evidence, but the length of the evidence can be made public in advance. In the blockchain voting system, the blockchain private key is usually 256 bits, which is the length of the evidence.
[0058] Step S2: The prover obtains part of the verification code puzzle from the verifier through oblivious transmission based on the evidence it holds, and generates the corresponding prover solution using the human oracle;
[0059] 1) At this stage, for each bit of information, , the prover uses Two verification code problems from the verification side Among them, one is selected through inadvertent transfer, and finally CAPTCHA Puzzles .
[0060] 2) The prover obtains After the verification code puzzle, the human oracle H is queried and the result is The corresponding prover answers .
[0061] Combined with the above, we can see that to a human oracle Query a captcha puzzle , what you get is Generated , that is, the generated prover solution is the same as the corresponding verifier solution.
[0062] Step S3: the prover makes a commitment to the evidence and the prover's solution corresponding to the obtained verification code puzzle, and sends the commitment to the verifier;
[0063] The prover generates a commitment key , and will Sent to the verification party. , the prover selects a random number , and for , , Make a commitment. Eventually the commitment value Sent to the verifier.
[0064] Step S4: The verifier generates a verifier ciphertext based on all verifier answers, sends the verifier ciphertext to the prover and proves its own honesty to the prover.
[0065] Generate an additively homomorphic encryption key pair , and the public key Sent to the proving party, where sk is the private key;
[0066] for , Authenticator Encryption Get the ciphertext Finally, the verifier will ciphertext Sent to the prover.
[0067] Ciphertext , the verifier and the prover run a standard zero-knowledge proof protocol. At this time, the verifier plays the role of the prover P in the protocol, and the prover plays the role of the verifier V in the sub-protocol. P needs to prove to V the public key he has sent It is honestly generated, and the inputs to the oblivious transfer protocol and the inputs during encryption use honestly generated captcha puzzles and solutions.
[0068] If P (the verifier) fails to pass the zero-knowledge proof protocol, the prover exits.
[0069] Step S5: the prover encrypts the prover's answer held by itself to obtain the prover's answer ciphertext, calculates the prover's reply ciphertext based on the evidence, the verifier's ciphertext and the prover's answer ciphertext, and sends the prover's reply ciphertext to the verifier;
[0070] for , the prover will solve the verification code he holds Use random numbers Encrypted as , and calculate the ciphertext The final proof will be Ciphertext Sent to the verifier.
[0071] Step S6: the verifier verifies the ciphertext replied by the prover, and if the verification is successful, the prover's honesty is verified based on the commitment, and if the verification is successful, all verification code puzzles are made public;
[0072] The verifier uses the private key sk Ciphertext Decryption is performed only when all ciphertexts are decrypted to The verifier will continue to execute the following protocol only when the verification is successful, otherwise the verifier will exit.
[0073] After the verification of the ciphertext replied by the prover is passed, the prover and the verifier run a standard zero-knowledge proof protocol. At this time, the prover plays the role of prover P in the sub-protocol, and the verifier plays the role of verifier V in the sub-protocol. The prover P needs to prove the commitment key he sent to is generated honestly, and for , the ciphertext it sends All with promises In , , Honest calculation, in addition to the concatenated string satisfy , Represents statement x and evidence Satisfy the binary relationship that needs to be proved .
[0074] If P (i.e. the prover) fails to pass the zero-knowledge proof protocol, the verifier exits.
[0075] When the verification is successful and the verifier accepts the zero-knowledge proof, the verifier will CAPTCHA Puzzles Make it public.
[0076] It should be noted that those skilled in the art should be aware that zero-knowledge means that no information about the evidence is disclosed in the process of proving that a statement is true, that is, zero-knowledge proof of knowledge means that no information about the knowledge is disclosed in the process of proving the knowledge, which is not equivalent to zero-knowledge proof.
[0077] In blockchain voting authentication, the input of the voting client held by the prover is its blockchain private key, and the input of the verification party, the authentication server of the voting system, is the corresponding blockchain public key. The user entity corresponding to the blockchain private key plays the role of human oracle H to assist in completing the authentication. After the prover and the verifier run the above method, the authentication server of the voting system will publish all the generated verification code puzzles on the voting bulletin board.
[0078] Using this method to authenticate voting on the blockchain can ensure that even if the user does not have TEE / ASIC, attacks such as vote-buying and coercion can still be eliminated. Assuming that a non-transparent decentralized vote-buying organization on a blockchain attempts to bribe a blockchain user, then according to this method, during the authentication process, the access record of the human oracle H will be leaked to the decentralized vote-buying organization, and then the entire private key of the blockchain user will be leaked. Therefore, it can be asserted that any user who sells votes will leak his private key. Therefore, completing the identity authentication of the voting client by this method can effectively resist the vote-buying attack of the decentralized vote-buying organization.
[0079] Based on this, the present application provides an inalienable identity authentication method, which is applied to a proving party, wherein the proving party holds statements and evidence, such as Figure 2 As shown, the method may include:
[0080] S11: Based on the evidence it holds, it obtains part of the captcha puzzle from the verifier through oblivious transmission, and uses the human oracle to generate the corresponding prover’s answer;
[0081] S12: Committing the prover's solution corresponding to the evidence and the obtained verification code puzzle, and sending the commitment to the verifier;
[0082] S13: accepting the verification party ciphertext sent by the verification party and verifying the honesty of the verification party, wherein the verification party ciphertext is generated by the verification party based on the verification party solutions corresponding to all verification code puzzles;
[0083] S14: If the verification is successful, the prover's answer held by the prover is encrypted to obtain a prover answer ciphertext, a prover reply ciphertext is calculated based on the evidence, the verifier ciphertext and the prover answer ciphertext, and the prover reply ciphertext is sent to the verifier, so that the verifier verifies the prover reply ciphertext;
[0084] S15: If the verification is successful, then based on the commitment, prove its honesty to the verifier, so that the verifier will disclose all verification code problems after the verification is successful.
[0085] The present application also provides an inalienable identity authentication method, which is applied to a verification party, wherein the verification party holds a statement such as Figure 3 As shown, the method may include:
[0086] S21: Generate a verification code puzzle and a corresponding verification party solution, so that the prover obtains part of the verification code puzzle from the verification party through oblivious transmission based on the evidence held by the prover, obtains the corresponding verification party solution by using a human oracle, and commits to the evidence and the verification party solution corresponding to the obtained verification code puzzle, and sends the commitment to the verification party;
[0087] S22: generating a verifier ciphertext based on all verifier answers, sending the verifier ciphertext to the prover and proving its own honesty to the prover, so that the prover encrypts the prover answer it holds to obtain the prover answer ciphertext after the verification is passed, calculating the prover reply ciphertext based on the evidence, the verifier ciphertext and the prover answer ciphertext, and sending the prover reply ciphertext to the verifier;
[0088] S23: verifying the ciphertext replied by the prover, and if the verification is successful, verifying the honesty of the prover based on the commitment, and if the verification is successful, making all verification code puzzles public.
[0089] Corresponding to the aforementioned embodiment of the inalienable identity authentication method, the present application also provides an embodiment of an inalienable identity authentication device.
[0090] Figure 4 is a block diagram of an inalienable identity authentication device according to an exemplary embodiment. Figure 4 , the device is applied to a proving party, the proving party holds a statement and evidence, and the device may include:
[0091] A prover solution generation module 11 is used to obtain part of the captcha puzzle from the verifier through oblivious transmission based on the evidence it holds, and generate a corresponding prover solution using a human oracle;
[0092] A commitment module 12, configured to make a commitment to the prover's solution corresponding to the evidence and the obtained verification code puzzle, and send the commitment to the verifier;
[0093] A verifier honesty verification module 13, configured to receive a verifier ciphertext sent by a verifier and verify the verifier's honesty, wherein the verifier ciphertext is generated by the verifier based on the verifier's answers corresponding to all verification code puzzles;
[0094] The ciphertext generation module 14 may also encrypt the prover's answer held by itself to obtain the prover's answer ciphertext if the verification is passed, calculate the prover's reply ciphertext based on the evidence, the verifier's ciphertext and the prover's answer ciphertext, and send the prover's reply ciphertext to the verifier, so that the verifier verifies the prover's reply ciphertext;
[0095] The prover's honesty proof module 15 is used to prove its own honesty to the verifier based on the commitment if the verification is successful, so that the verifier will disclose all verification code puzzles after the verification is successful.
[0096] Figure 5 FIG. 1 is a block diagram of an inalienable identity authentication device according to an exemplary embodiment. Figure 5, the device is applied to a verification party, the verification party holds a statement, and the device may include:
[0097] The verifier solution generation module 21 is used to generate a verification code problem and a corresponding verification party solution, so that the prover obtains part of the verification code problem from the verifier through oblivious transmission based on the evidence held by the prover, obtains the corresponding prover solution by using the human oracle, and commits to the prover solution corresponding to the evidence and the obtained verification code problem, and sends the commitment to the verifier;
[0098] The verifier honesty proof module 22 is used to generate a verifier ciphertext based on all verifier answers, send the verifier ciphertext to the prover and prove its own honesty to the prover, so that the prover encrypts the prover answer held by itself to obtain the prover answer ciphertext after the verification is passed, calculate the prover reply ciphertext based on the evidence, the verifier ciphertext and the prover answer ciphertext, and send the prover reply ciphertext to the verifier;
[0099] The prover honesty verification module 23 is used to verify the prover's reply ciphertext. If the verification is successful, the prover's honesty is verified based on the commitment. If the verification is successful, all verification code problems are disclosed.
[0100] Regarding the device in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0101] For the device embodiment, since it basically corresponds to the method embodiment, the relevant parts can refer to the partial description of the method embodiment. The device embodiment described above is only schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present application scheme. A person of ordinary skill in the art can understand and implement it without paying any creative work.
[0102] Accordingly, the present application also provides a computer program product, including a computer program / instruction, which implements the above-mentioned inalienable identity authentication method when executed by a processor.
[0103] Accordingly, the present application also provides an electronic device, comprising: one or more processors; a memory for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the above-mentioned inalienable identity authentication method. Figure 6As shown, a hardware structure diagram of an inalienable identity authentication device provided by an embodiment of the present invention is provided in any device with data processing capability, except Figure 6 In addition to the processor, memory and network interface shown, any device with data processing capability in which the apparatus in the embodiment is located may also include other hardware, generally based on the actual functions of the device with data processing capability, which will not be described in detail.
[0104] Accordingly, the present application also provides a computer-readable storage medium on which computer instructions are stored, and when the instructions are executed by a processor, the inalienable identity authentication method as described above is implemented. The computer-readable storage medium can be an internal storage unit of any device with data processing capabilities described in any of the aforementioned embodiments, such as a hard disk or a memory. The computer-readable storage medium can also be an external storage device, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), an SD card, a flash card (Flash Card), etc. equipped on the device. Furthermore, the computer-readable storage medium can also include both an internal storage unit and an external storage device of any device with data processing capabilities. The computer-readable storage medium is used to store the computer program and other programs and data required by any device with data processing capabilities, and can also be used to temporarily store data that has been output or is to be output.
[0105] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the contents disclosed herein. The present application is intended to cover any variations, uses or adaptations of the present application, which follow the general principles of the present application and include common knowledge or customary technical means in the art that are not disclosed in the present application.
[0106] It should be understood that the present application is not limited to the exact construction that has been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof.
Claims
1. An inalienable identity authentication method, characterized in that: Applied to a proving party, the proving party having a statement and evidence, the method comprises: Based on the evidence it holds, it obtains part of the captcha puzzle from the verifier through oblivious transmission, and uses a human oracle to generate the corresponding prover’s answer; Committing the prover's solution to the evidence and the obtained verification code puzzle, and sending the commitment to the verifier; Accepting a verification party ciphertext sent by a verification party and verifying the honesty of the verification party, wherein the verification party ciphertext is generated by the verification party based on the verification party solutions corresponding to all verification code puzzles; If the verification is successful, the prover's answer held by the party is encrypted to obtain the prover's answer ciphertext, and the prover's reply ciphertext is calculated based on the evidence, the verifier's ciphertext and the prover's answer ciphertext, and the prover's reply ciphertext is sent to the verifier, so that the verifier verifies the prover's reply ciphertext; If the verification is successful, based on the commitment, the verifier proves its honesty to the verifier so that the verifier will disclose all verification code problems after the verification is successful.
2. The method according to claim 1, characterized in that Based on the evidence in their possession, they can obtain part of the verification code from the verifier through inadvertent transmission. The specific problem is: For the verifier CAPTCHA Puzzles , using each bit of the evidence, from a pair of CAPTCHA puzzles Among them, one is selected through oblivious transfer, and we get CAPTCHA Puzzles ,in The length of the evidence.
3. The method according to claim 1, characterized in that The prover replies with the ciphertext ,in To solve the ciphertext for the prover, each bit of evidence , To verify the ciphertext, The length of the evidence.
4. The method according to claim 3, characterized in that Based on the above commitment, prove its honesty to the verifier, including: A standard zero-knowledge proof of knowledge protocol is run with the verifier to prove to the verifier that the commitment key used to generate the commitment is honestly generated, that the prover's reply ciphertext is honestly calculated based on the evidence corresponding to the commitment and the prover's answer, and that the evidence satisfies a binary relationship with the statement.
5. An inalienable identity authentication method, characterized in that: Applied to a verifying party, the verifying party being in possession of a statement, the method comprises: Generate a captcha puzzle and a corresponding verifier solution, so that the prover, based on the evidence it holds, obtains part of the captcha puzzle from the verifier through oblivious transmission, obtains the corresponding prover solution using a human oracle, and commits to the evidence and the obtained prover solution to the captcha puzzle, and sends the commitment to the verifier; Generate a verifier ciphertext based on all verifier answers, send the verifier ciphertext to the prover and prove its own honesty to the prover, so that the prover encrypts the prover answer held by itself to obtain the prover answer ciphertext after the verification is passed, calculate the prover reply ciphertext based on the evidence, the verifier ciphertext and the prover answer ciphertext, and send the prover reply ciphertext to the verifier; The ciphertext replied by the prover is verified. If the verification is successful, the honesty of the prover is verified based on the commitment. If the verification is successful, all verification code puzzles are made public.
6. The method according to claim 5, characterized in that Generate a verifier ciphertext based on all verifier answers, send the verifier ciphertext to the prover and prove its own honesty to the prover, including: Generate an additively homomorphic encryption key pair , and the public key Sent to the proving party, where sk is the private key; The opposite of all verifiers' answers , encrypted to get the ciphertext ,in for the length of the evidence; Ciphertext Send to the proving party; Ciphertext , run a standard zero-knowledge proof protocol with the prover to prove to the prover that the public key pk it sent was honestly generated, and that the verification code puzzles and the corresponding solutions used for inadvertent transmission and encryption are honestly generated.
7. The method according to claim 5, characterized in that Verify the ciphertext replied by the proving party, specifically: Decrypt the ciphertexts replied by all the proving parties. If the decrypted ciphertexts replied by all the proving parties are 0, the verification is successful.
8. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the method according to any one of claims 1 to 7 is implemented.
9. An electronic device, characterized in that: include: one or more processors; A memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Retrieval ciphertext detectable method and device based on accumulative commitment verification
CN117134993A
Transaction verification method based on non-interactive zero-knowledge proof of specified verifier
CN118537017A