A Cross-Scene Anonymous Seamless Identity Authentication Method for the Metaverse Based on Dual Blockchains
Through the combination of dual blockchain technology and fuzzy extractor, users' cross-scene anonymous and seamless identity authentication in the metaverse is realized, solving the problems of restricted user experience and privacy leakage among users, and enhancing user experience and privacy protection.
Patent Information
- Application Number
- CN202411804052.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-10
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-12-10
AI Technical Summary
In the metaverse, users' smart wearable devices are limited to specific scenario services, resulting in limited cross-scene experiences, and user privacy information is easily attacked and leaked. It is difficult for the prior art to effectively protect user access control and privacy information in multi-scene services.
The anonymous seamless identity authentication method based on dual blockchain is adopted, and digital credentials and public keys are generated through the registration center, combined with a fuzzy extractor to protect biological information, realize user identity authentication and key exchange in servers in different scenarios, and use interactive data links to store user avatar data to ensure data consistency and privacy protection.
It realizes seamless identity authentication and key exchange for users in different metaverse scenarios, reduces tedious operations, enhances user experience, and effectively protects the integrity and immutability of user privacy data.
Smart Images

Figure CN119299224B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of identity authentication and key exchange, and specifically relates to a cross-scenario anonymous seamless identity authentication method for the metaverse based on dual blockchains. Background Art
[0002] The continuous progress of metaverse technology has promoted the development of many industries, such as gaming, culture and tourism, education, industrial production, etc., providing users with a more immersive experience and enabling users to break free from the limitations of the real world. Users can connect to the virtual world through some mobile intelligent devices or wearable intelligent devices, such as head-mounted glasses, to expand the real world.
[0003] Although metaverse technology has brought new experiences and conveniences to people's lives and work in various aspects, currently, most intelligent wearable devices used to access the metaverse communicate with a server providing specific scenario services through a public channel, which confines the user's intelligent wearable device to a specific scenario service, thus greatly limiting the cross-scenario experience of users. At the same time, due to communication on a public channel, the transmitted information is extremely vulnerable to eavesdropping and interception by attackers, and user personal information, such as photos, transaction records, etc., will be leaked, posing a major challenge to user privacy. Therefore, it is crucial to ensure user access control and the protection of user privacy information while providing multi-scenario services. Summary of the Invention
[0004] In view of the problems existing in the prior art, the present invention provides a cross-scenario anonymous seamless identity authentication method for the metaverse based on dual blockchains, which can effectively protect the privacy data of users. Through the protocol of the present invention, the trouble of users re-entering personal information for login can be saved, and seamless authentication can be achieved. At the same time, due to the particularity of the metaverse environment, users' activities are all realized through avatars. The use of the interactive data chain ensures that although the user's avatars are in different scenario servers, the consistency, confidentiality, and immutability of the user's personalized avatar data can still be guaranteed, thus reducing the cumbersome operations of users creating avatars across scenarios.
[0005] To solve the above technical problems, the present invention provides the following technical solution: A cross-scenario anonymous seamless identity authentication method for the metaverse based on dual blockchains, comprising the following steps:
[0006] S1. Initialization stage: The registration center is initialized to generate a registration center private key and a registration center public key;
[0007] S2. Scenario server registration stage: Before being put into use, each scenario server registers with the registration center RC to obtain a legal identity, obtains a digital certificate, and uploads the digital certificate to the registration blockchain as identity authentication information;
[0008] S3. User registration phase: The user uses a smart device connected to the metaverse to complete registration at the registration center and becomes a legal user;
[0009] S4. User login and avatar creation on the scenario server phase: The legal user inputs user login information and biometric information on the smart device connected to the metaverse. After the smart device successfully verifies the user's identity, it sends a login request to the scenario server, carrying the user's authentication information and avatar information at the same time; After receiving the login authentication request, the scenario server verifies the timestamp of the information. After passing the verification, it will further use the corresponding registration block of the user on the registration blockchain to extract the user's digital certificate and verify whether the digital certificate conforms to the user's authentication information;
[0010] If the verification fails, the program exits. If the verification passes, the scenario server generates a session key between the user and itself, and sends the information digest composed of the key and other parameters and its own authentication information to the user's smart device; The smart device verifies the identity of the scenario server. After passing the verification, it calculates the session key between them, and then verifies whether the information digest is consistent. If so, the mutual identity authentication and key exchange are achieved, otherwise it terminates;
[0011] S5. User cross-scenario server authentication phase: When the user switches scenarios, relevant information of the user avatar is transmitted through the communication between scenario servers to complete the identity authentication and key exchange across scenario servers.
[0012] Further, the aforementioned step S1 is specifically as follows: The registration center RC selects as its private key and calculates the public key Pub RC = k·Q where the global public parameters {E, p, q, G, Q, H} are used in the initialization phase, where E is an elliptic curve over the non-singular finite field F p ,
[0013] E: y 2 = x 3 + ax + b (mod p), p and q are two large prime numbers; G is the elliptic curve additive group composed of the points on the elliptic curve E and the infinite point O, whose order is q, Q is the generator of the G group; H is a collision-resistant one-way hash function that maps {0, 1} * to {0, 1} 1 .
[0014] Further, the aforementioned step S2 includes the following sub-steps:
[0015] S2.1. The scenario server SS n uses the unique identification code ID SSn , selects Calculate the public key of the scenario server SS as its private key n which is Then send the registration request information to the registration center RC through a secure channel; where ID SSn is the unique identification code of the scenario server;
[0016] S2.2. After receiving the registration request information, the registration center RC checks the existence and uniqueness of ID SSn in the registration blockchain and the database of the registration center. If ID SSn exists or is not unique, terminate the registration of the scenario server. Otherwise, the registration center RC calculates the digital credential || represents the concatenation operation. Use the transaction <Cert n > to generate a registration block in the registration blockchain. Finally, the registration center RC calculates the information digest and sends to the scenario server SS through a secure channel n , and the scenario server SS n is successfully registered in the registration center RC;
[0017] S2.3. The scenario server SS n calculates to verify whether it holds. If it holds, terminate the process. Otherwise, the scenario server SS n calculates the ciphertext and stores {D1} in its database and stores it in the secure memory.
[0018] Furthermore, the aforementioned step S3 includes the following sub-steps:
[0019] S3.1. The user U i inputs the unique user account password PW i and biometric information Bio i on the intelligent device connecting to the metaverse. The fuzzy extractor in the device encrypts the user's biometric information (δ i , τ i ) = Gen(Bio i ), where δ i is the encrypted value generated by the fuzzy extractor, τ i is the auxiliary parameter, Gen() is the fuzzy extractor. At the same time, select as the private key and calculate the user's public key User identity Send the registration information Send it to the registration center RC through a secure channel;
[0020] S3.2. After the registration center RC receives the authentication information of user U i , it checks the uniqueness of user U i 's in the registration center RC database and the registration blockchain. If the DID i exists or is not unique, the user registration is terminated. Otherwise, the registration center RC calculates and then uses the transaction <Cert i > to generate a registration block in the registration blockchain and saves it in the registration center RC database. Then, it calculates the information digest and sends it to user U through a secure channel i ;
[0021] S3.3. User U i calculates to verify whether it holds. If it does not hold, the user registration is terminated. Otherwise, user U i calculates the ciphertext
[0022]
[0023] where ⊕ is the exclusive-or operation, calculates the information digest and stores {D3, D4, D5, D6} in the database of the smart device, and saves {b i} in the secure memory.
[0024] Furthermore, the aforementioned step S4 includes the following sub-steps:
[0025] S4.1. User U i inputs PW i , Bio i in the smart device accessing the metaverse, calculates δ i = Rep(Bio i , τ i ), verifies whether it holds. If it does not hold, the process termination program is executed. Otherwise, a random number is selected as the temporary secret key, the timestamp T1, and the temporary public key C1 = n1·Q, the temporary symmetric key of the scenario server user public key If the avatar identity of the current scene server is saved in the intelligent device, extract the avatar identity; if not, select a new user avatar, Avat i , calculate the communication digest Encrypt the important information with the temporary symmetric key C2 to generate the communication ciphertext where Info i is the personalized avatar information of the user in the metaverse. The user uses the intelligent device to send {C1, E N1 , T1} to the scene server SS through the public channel n ;
[0026] S4.2. The scene server SS n After receiving the login request from the user U i , first verify the timestamp to ensure the freshness of the data. If it does not hold, return to execute step S4.1; otherwise, calculate Decrypt the communication ciphertext with the calculated temporary symmetric key to obtain Calculate the communication digest Verify If it does not hold, terminate the program; otherwise, the scene server SS n will pass through Retrieve the transaction <Cert i > in its database and the registered blockchain, and verify the digital certificate Whether it holds. If it does not hold, terminate the process; otherwise, save the user's personalized avatar information Info i and retrieve whether there is an avatar identity of the user in the scene server SS according to the user's DID i n If so, extract the avatar; otherwise, create a new avatar, calculate Upload as a transaction record to the data interaction blockchain and generate a data interaction block index After that, select a random number as its temporary secret key, timestamp T2, calculate its temporary public key C3 = n2·Q, and temporary symmetric key Calculate the session key between the user U i and the scene server SS n Communication information digest Encrypt the information {C3, E N2 , T2} with the temporary symmetric key C4 and send it to the user's intelligent device through the public information;
[0027] S4.3. The user Ui Verify the timestamp first after receiving the response information to ensure data freshness. If it does not hold, discard it; otherwise, calculate the temporary symmetric key obtained through calculation to decrypt the communication ciphertext to obtain The user's smart device passes through retrieve the transaction <Cert in the blockchain n (>, verify the digital certificate of the scenario server SS n to see if it holds. If it does not hold, terminate the program; otherwise, calculate the user U and the scenario server SS i between n the
[0028]
[0029] is the data interaction area index block, is the user's avatar identity in the scenario server, is the registration area index block, is the unique identity code of the scenario server; verify If it does not hold, terminate the program; otherwise, complete identity authentication and key exchange.
[0030] Furthermore, the aforementioned step S5 includes the following sub-steps:
[0031] S5.1. When the user U i switches from the current metaverse scenario service to another service, send a cross-domain request to the target scenario server SS m and select a random number as its temporary secret key, timestamp T3, calculate the temporary public key C5 = n3·Q, and the temporary symmetric key communication information digest Generate a communication ciphertext by encrypting important information with the temporary symmetric key C6: The user uses the smart device to send the communication ciphertext to the target scenario server SS through the public channel m ;
[0032] S5.2. When the target scenario server SS m receives the cross-domain request from the user U i , first verify the timestamp to ensure data freshness. If it does not hold, terminate the cross-domain request of the user U i ; otherwise, calculate the temporary symmetric key obtained through calculation to decrypt the communication ciphertext to obtain communication information digest Verification If it does not hold, terminate the program. Otherwise, the target scenario server SS m Via Retrieve the transaction <Cert in the database and the registered blockchain i (>, discard it if it does not hold, and if it holds, retrieve according to the user's DID i Check whether there is an avatar identity of the user in the target scenario server SS m in the database and authenticate with the scenario server SS n to obtain the user's personalized avatar information Info i ;
[0033] S5.3. The target scenario server SS m Decrypt its registered block index on the registered blockchain Select a random number as its temporary secret key, timestamp T4, calculate the temporary public key C7 = n4·Q, and the temporary symmetric key Communication information digest Encrypt the important information using the temporary symmetric key C8 to generate the communication ciphertext Send the information {C7, E N4 , T4} to the scenario server SS through the public channel n ;
[0034] S5.4. The scenario server SS n After receiving the authentication request from the target scenario server SS m , first verify the timestamp to ensure the freshness of the data. If it does not hold, terminate the program. Otherwise, calculate using the calculated temporary symmetric key Decrypt the communication ciphertext to obtain Verify If it does not hold, terminate the program. Otherwise, the scenario server SS n Retrieve the transaction <Cert in the registered blockchain through the registered block index of the target scenario server SS m >, verify the digital certificate of the target scenario server SS m to check if it holds. If it does not hold, terminate the process. Otherwise, calculate the registered block index of the scenario server SS m to check if it holds. If it does not hold, terminate the process. Otherwise, calculate the registered block index of the scenario server SS n Select a random number as its temporary secret key, timestamp T5, calculate the temporary public key C9 = n5·Q, and the temporary symmetric key Scene Server SS n and the target scene server SS m The session key between them Communication information digest Generate communication ciphertext by encrypting important information with the temporary symmetric key C 10 Send the information {C9, E N5 , T5} to the target scene server SS through the public channel m ;
[0035] S5.5. The target scene server SS m After receiving the response from the scene server SS n First, verify the timestamp Whether it holds to ensure the freshness of the data. If it doesn't hold, terminate the program. Otherwise, calculate the symmetric key Decrypt the communication ciphertext through the calculated temporary symmetric key to obtain Retrieve the transaction <Cert n through the registration block index of the scene server SS on the registration blockchain, and verify the digital certificate n of the scene server SS n Whether it holds. If it doesn't hold, terminate the program. Otherwise, calculate the session key between the target scene server SS m and the scene server SS n Verify Whether it holds. If it doesn't hold, terminate the program. If it holds, complete the authentication between the target scene server SS m and the scene server SS n and establish a secure connection. According to Send the personalized information Info i of the user U in the scene server SS n securely to the target scene server SS i At the same time, the scene server SS m updates the block on the avatar data interaction chain n
[0036] S5.6. After the target scene server SS m successfully obtains the personalized avatar information of the user U i , retrieve whether there is an avatar identity of the user in its database according to the user's DID i in the target scene server SS m Extract the avatar clone if available Create a new avatar identity if not Upload as a transaction record to the data interaction blockchain and generate a data interaction block index Then select a random number as a temporary key, timestamp T6, then select a random number as a temporary key, timestamp T6, calculate the temporary public key C 11 = n6·Q, the temporary symmetric key Calculate the target scenario server SS m and the user U i the session key between Through the temporary symmetric key C 12 Encrypt important information to generate a communication ciphertext Send the information {C11, E N6 , T6} to the user's smart device through public information;
[0037] User U i Receives the information {C 11 , E N6 , T6} and first verifies the timestamp Whether it holds to ensure the freshness of the data. If it doesn't hold, terminate the program. Otherwise, calculate Through the calculated temporary symmetric key Decrypt the communication ciphertext to obtain The user's smart device retrieves the transaction <Cert m through the registration block index of the target scenario server SS > in the registration blockchain and verifies the digital certificate of the target scenario server SS m > Whether it holds. If it doesn't hold, terminate the program. Otherwise, calculate the session key between the user and the target scenario server SS m : Verify Whether it holds. If it doesn't hold, terminate the process. Otherwise, the user completes the identity authentication and key exchange across scenario servers.
[0038] Verify Whether it holds. If it doesn't hold, terminate the process. Otherwise, the user completes the identity authentication and key exchange across scenario servers.
[0039] Compared with the prior art, the beneficial technical effects of the present invention adopting the above technical solutions are as follows:
[0040] In view of the fact that there will be a variety of different interaction scenarios in the metaverse environment, the present invention proposes to set up a server for each different application scenario. By adopting this multi-server mode, not only can the load on the server be reduced, but also the user experience can be enhanced, enabling users to experience the use of multiple scenarios without changing devices. To prevent the leakage of user login information, a fuzzy extractor and blockchain are used to protect the user's biological information. In the traditional metaverse environment, users can usually only experience one scenario on one device. When they want to experience other services, they need to log in to the corresponding server and complete the login process, which is a cumbersome process. The present invention proposes to adopt a dual-blockchain mode, storing each server and user authentication information on the authentication data chain. Since users will be active in different services, the interaction data chain can store the avatar data of users in multi-scenario servers to achieve data consistency. At the same time, the design of the dual-blockchain realizes the isolation of the user's real data and virtual data in the metaverse, effectively protecting the user's privacy data. Through our protocol, the trouble of users having to re-enter personal information for login can be eliminated, achieving seamless authentication. In summary, the present invention can enhance the user experience in the metaverse, connect various metaverse environments together, and enable users to quickly complete identity authentication in the same service scenario or multiple service scenarios through the seamless identity authentication of the dual-blockchain. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 is a flowchart of the present invention.
[0042] Figure 2 is an interaction block diagram of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0043] In order to better understand the technical content of the present invention, specific embodiments are hereby given and described in conjunction with the accompanying drawings as follows.
[0044] In the present invention, various aspects of the present invention are described with reference to the accompanying drawings, in which many illustrative embodiments are shown. The embodiments of the present invention are not limited to those described in the drawings. It should be understood that the present invention can be implemented by any one of the various concepts and embodiments introduced above, as well as the concepts and embodiments described in detail below, because the concepts and embodiments disclosed in the present invention are not limited to any embodiment. In addition, some aspects disclosed in the present invention can be used alone, or in any appropriate combination with other aspects disclosed in the present invention.
[0045] In the metaverse environment, there will be a variety of different interaction scenarios. Therefore, the present invention proposes to set up a server for each different application scenario. By adopting this multi-server mode, not only can the load on the server be reduced, but also the user experience can be enhanced, enabling users to experience the use of multiple scenarios without changing devices. The method of the present invention is based on a registration center, multiple scenario servers, and users. Among them, the registration center is secure and reliable, responsible for registering users and scenario servers, and storing the registration information on the registration blockchain. After a scenario server completes registration in the registration center, it can provide various metaverse scenario services for users and help users achieve seamless authentication when they need to cross metaverse services. Users are the users of the metaverse. After registering through the registration center, they can experience different services and create avatars on different scenario servers. The use of the interaction data chain is for distributed storage of users' personalized avatar information to protect the privacy security and immutability of users.
[0046] Reference Figure 1 and Figure 2 , the present invention provides a cross-scenario anonymous seamless identity authentication method for the metaverse based on a dual blockchain, including the following steps:
[0047] S1. Initialization stage: The registration center is initialized to generate a registration center private key and a registration center public key.
[0048] S2. Scenario server registration stage: Before being put into use, each scenario server registers in the registration center RC to obtain a legal identity, obtains a digital certificate, and uploads the digital certificate to the registration blockchain as identity authentication information.
[0049] S3. User registration stage: The user uses a smart device connected to the metaverse to complete registration in the registration center and becomes a legal user.
[0050] S4. User login and avatar creation on the scenario server stage: When a legal user enjoys metaverse services, the user enters user login information and biometric information on the smart device connected to the metaverse. After the smart device successfully verifies the user's identity, it sends a login request to the scenario server, and at the same time, it will carry the user's authentication information and avatar information; after receiving the login authentication request, the scenario server verifies the timestamp of the information. After passing, it will further use the corresponding registration block of the user on the registration blockchain to extract the user's digital certificate and verify whether the digital certificate conforms to the user's authentication information.
[0051] If the verification is passed, the scenario server generates a session key between the user and itself, and sends the key and its own authentication information to the user's smart device; the smart device verifies the identity of the scenario server. After passing the verification, it calculates the session key between them, and then verifies whether the information digest is consistent. If it is, the mutual identity authentication and key exchange are achieved, otherwise it terminates.
[0052] S5. User cross-scenario server authentication phase: When the user switches scenarios, relevant information about the user avatar is transmitted through the communication between scenario servers to complete the cross-scenario server identity authentication and key exchange. By interacting with the blockchain, the integrity, confidentiality, and immutability of the user's information in the metaverse are ensured, enabling the user to seamlessly obtain different service experiences across scenario servers.
[0053] Further, as a preferred embodiment of the present invention, the specific steps of the initialization phase in step S1 are as follows: The registration center RC selects as its private key and calculates the public key Pub RC = k·Q. Among them, the global public parameters {E, p, q, G, Q, H} are used in the initialization phase, where E is an elliptic curve over the non-singular finite field F p : y 2 = x 3 + ax + b (mod p), p and q are two large prime numbers; G is an elliptic curve additive group composed of points on the elliptic curve E and the infinite point O, whose order is q, Q is the generator of the G group; H is a collision-resistant one-way hash function that maps {0, 1} * to {0, 1} 1 .
[0054] Further, as a preferred embodiment of the present invention, the scenario server registration phase in step S2 includes the following sub-steps:
[0055] S2.1. The scenario server SS n uses the unique identification code ID SSn to select as its private key and calculates the public key of the scenario server SS n as Then, the registration request information is sent to the registration center RC through a secure channel; among them, ID SSn is the unique identification code of the scenario server.
[0056] S2.2. After receiving the registration request information, the registration center RC checks the existence and uniqueness of ID SSn in the registration blockchain and the database of the registration center. If ID SSn exists or is not unique, the registration of the scenario server is terminated. Otherwise, the registration center RC calculates the digital credential || represents the concatenation operation, and uses the transaction <Cert n > to generate a registration block in the registration blockchain Finally, the registration center RC calculates the information digest and sends to the scenario server SS through a secure channel n, Scenario Server SS n Successfully registered in the Registration Center RC.
[0057] S2.3, Scenario Server SS n Calculate Verify If it holds, terminate the process; otherwise, Scenario Server SS n Calculate the ciphertext And store {D1} in its database, Stored in the secure memory.
[0058] Furthermore, as a preferred embodiment of the present invention, step S3, the user registration phase includes the following sub-steps:
[0059] S3.1, User U i Input the unique user account Password PW i , Biometric information Bio i into the intelligent device connected to the metaverse. The fuzzy extractor in the device encrypts the user's biometric information (δ i , τ i ) = Gen(Bio i ), where δ i is the encrypted value generated by the fuzzy extractor, τ i is the auxiliary parameter, Gen() is the fuzzy extractor. At the same time, select as the private key, as the secret value, and calculate the user's public key User identity Send the registration information to the Registration Center RC through the secure channel.
[0060] S3.2, After receiving the authentication information of User U i , the Registration Center RC checks the uniqueness of User U i in the Registration Center RC database and the registration blockchain. If DID exists or is not unique, terminate the user registration; otherwise, the Registration Center RC calculates i and then uses the transaction <Cert > to generate a registration block i in the registration blockchain and saves it in the Registration Center RC database. Then calculate the information digest and send to User U i through the secure channel.
[0061] S3.3, User U i Calculate Verify Whether it holds. If not, terminate the user registration; otherwise, user U i Calculate the ciphertext
[0062] Is an exclusive OR operation, calculate the message digest And store {D3, D4, D5, D6} in the database of the intelligent device, {b i} is saved in the secure memory
[0063] Furthermore, as a preferred embodiment of the present invention, step S4 where the user logs in and creates an avatar at the scene server includes the following sub-steps:
[0064] S4.1. User U i Input in the intelligent device accessing the metaverse Calculate δ i = Rep(Bio i , τ i ), Verify Whether it holds. If not, terminate the program; otherwise, select a random number As the temporary secret key, timestamp T1, calculate the temporary public key C1 = n1·Q, the temporary symmetric key of the scene server User public key If the avatar identity of the current scene server is saved in the intelligent device, extract the avatar identity; if not, select a new user avatar Avat i , calculate the communication digest Encrypt the important information through the temporary symmetric key C2 to generate the communication ciphertext Where Info i Is the personalized avatar information of the user in the metaverse. The user uses the intelligent device to send {C1, E N1 , T1} to the scene server SS through the public channel n ;
[0065] S4.2. Scene server SS n After receiving the login request of user U i , first verify the timestamp To ensure the freshness of the data. If not, return to execute step S4.1; otherwise, calculate Decrypt the communication ciphertext through the calculated temporary symmetric key To obtain Calculate the communication digest Verify If it does not hold, terminate the program; otherwise, the scenario server SS n will retrieve the transaction <Cert in its database and the registered blockchain i >, and verify the digital certificate to check if it holds. If it does not hold, terminate the process; otherwise, save the user's personalized avatar information Info i and retrieve from the database whether there exists the user's avatar identity in the scenario server SS i based on the user's DID n ; if so, extract the avatar; otherwise, create a new avatar and calculate Upload as a transaction record to the data interaction blockchain and generate a data interaction block index After that, select a random number as its temporary secret key, timestamp T2, and calculate its temporary public key C3 = n2·Q, the temporary symmetric key Calculate for user U and the session key between the scenario server SS i and the scenario server SS n ; communication information digest Send the information {C3, E N2 , T2} to the user's smart device through the public information using the temporary symmetric key C4;
[0066] S4.3. After the user U i receives the response information, first verify the timestamp to ensure the freshness of the data. If it does not hold, discard it; otherwise, calculate Decrypt the communication ciphertext through the calculated temporary symmetric key to obtain The user's smart device retrieves the transaction <Cert in the blockchain n > and verify the digital certificate of the scenario server SS n ; if it does not hold, terminate the program; otherwise, calculate between the user U and the scenario server SS i ; n ;
[0067]
[0068] is the data interaction area index block, is the user's avatar identity in the scenario server, is the registration area index block, is the unique identity code of the scenario server; verify If it does not hold, terminate the program; otherwise, complete the identity authentication and key exchange.
[0069] Further, as a preferred embodiment of the present invention, step S5 is the user cross-scenario server authentication phase:
[0070] S5.1. When user U i switches from the current metaverse scene service to another service, send a cross-domain request to the target scene server SS m and select a random number as its temporary secret key, timestamp T3, calculate the temporary public key C5 = n3·Q, and the temporary symmetric key communication information digest Generate a communication ciphertext by encrypting important information with the temporary symmetric key C6: The user uses the smart device to send the communication ciphertext to the target scene server SS through the public channel m ;
[0071] S5.2. When the target scene server SS m receives the cross-domain request from user U i , first verify whether the timestamp holds to ensure the freshness of the data. If it does not hold, terminate the cross-domain request of user U i . Otherwise, calculate Decrypt the communication ciphertext with the calculated temporary symmetric key to obtain the communication information digest Verify If it does not hold, terminate the program. Otherwise, the target scene server SS m Retrieve the transaction <Cert > in the database and the registered blockchain. If it does not hold, discard it. If it holds, retrieve whether there is an avatar identity of the user in the target scene server SS according to the user's DID i > and authenticate with the scene server SS i to obtain the personalized avatar information Info of the user m ; and n the scene server SS i ;
[0072] S5.3. The target scene server SS m Decrypt its own registered block index on the registered blockchain Select a random number as its temporary secret key, timestamp T4, calculate the temporary public key C7 = n4·Q, and the temporary symmetric key communication information digest Encrypt the important information using the temporary symmetric key C8 to generate the communication ciphertext Send the information {C7, E N4 , T4} to the scenario server SS through the public channel n ;
[0073] S5.4. The scenario server SS n After receiving the authentication request from the target scenario server SS m , first verify whether the timestamp is valid to ensure the freshness of the data. If it is not valid, terminate the program. Otherwise, calculate Decrypt the communication ciphertext using the calculated temporary symmetric key to obtain
[0074] Verify If it is not valid, terminate the program. Otherwise, the scenario server SS n Retrieve the transaction <Cert m from the registration blockchain through the registration block index of the target scenario server SS >, and verify whether the digital certificate m of the target scenario server SS m is valid. If it is not valid, terminate the process. Otherwise, calculate the registration block index of the scenario server SS n Select a random number as its temporary secret key, timestamp T5, calculate the temporary public key C9 = n5·Q, and the temporary symmetric key The session key between the scenario server SS n and the target scenario server SS m Calculate the communication information digest Encrypt the important information using the temporary symmetric key C to generate the communication ciphertext 10 Send the information {C9, E , T5} to the target scenario server SS through the public channel N5 ; m ;
[0075] S5.5. The target scenario server SS m After receiving the response from the scenario server SS n , first verify whether the timestamp is valid to ensure the freshness of the data. If it is not valid, terminate the program. Otherwise, calculate the symmetric key Decrypt the communication ciphertext using the calculated temporary symmetric key to obtain Through the scenario server SSn Registered block index Retrieve transactions from the registry blockchain <Cert n >, verify the scene server SS n Digital certificate Is it true? If not, terminate the program. Otherwise, calculate the target scene server SS. m and scene server SS n The session key between verify Is it true? If not, terminate the program. If true, complete the target scenario server SS m and scene server SS n Authentication and secure connection between User U i In the scene server SS n Personalized avatar information in Info i Safely transmitted to the target scene server SS m , while the scene server SS n Update the block on the avatar data interaction chain
[0076] S5.6, target scene server SS m Successfully obtained user U i After the personalized avatar data is obtained, the DID of the user i Check whether the user exists in the target scenario server SS in its database m The avatar identity If there is, extract the avatar clone If not, create a new avatar identity Will Uploaded to the data interaction blockchain as a transaction record and generate a data interaction block index Then choose a random number As a temporary key, timestamp T6, then choose a random number As the temporary key, timestamp T6, calculate the temporary public key C 11 =n6·Q, temporary symmetric key Calculate the target scene server SS m and user U i The session key between Through the temporary symmetric key C 12 Encrypt important information to generate communication ciphertext The information {C11, E N6 , T6} is sent to the user’s smart device via public information;
[0077] User U i After receiving the information {C 11 , E N6 , T6}, first verify the timestamp to check if it holds, in order to ensure the freshness of the data. If it doesn't hold, terminate the program. Otherwise, calculate the temporary symmetric key obtained through the calculation to decrypt the communication ciphertext to obtain The intelligent device of the user retrieves the transaction <Cert m from the registration block index of the target scenario server SS in the registration blockchain, and verifies the digital certificate of the target scenario server SS m to check if it holds. If it doesn't hold, terminate the program. Otherwise, calculate the session key between the user and the target scenario server SS m : to check if it holds. If it doesn't hold, terminate the process. Otherwise, the user completes the cross-scenario server identity authentication and key exchange. m
[0078] Verify to check if it holds. If it doesn't hold, terminate the process. Otherwise, the user completes the cross-scenario server identity authentication and key exchange.
[0079] Although the present invention has been described above with preferred embodiments, it is not intended to limit the present invention. Those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and refinements without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention shall be subject to what is defined by the claims.
Claims
1. A cross-scenario anonymous seamless identity authentication method for the metaverse based on dual blockchains, characterized in that, It includes the following steps: S1. Initialization of the registration center; S2. Upload the digital certificates of each scene server obtained by registering the scene server in the registration center to the registration blockchain; S3. Upload the digital certificates of users obtained by registering the intelligent devices used by users to connect to the metaverse in the registration center to the registration blockchain; S4. The user sends a login request carrying the avatar information of the user in the metaverse to the scene server through the intelligent device. When the avatar identity of the user in the scene server does not exist in the scene server, a new avatar identity of the user in the scene server is created according to the avatar information and uploaded to the data interaction blockchain; S5. Cross-scene server authentication for users: Target scenario server SS m After receiving a cross-domain request from a user, obtain the user's digital certificate by registering on the blockchain; After the user's digital certificate is verified, the current scenario server SS n obtains the digital certificate of SS m by registering with the blockchain; SS m After the digital certificate of SS m is verified, SS n obtains the digital certificate of SS SS n After the digital certificate of SS n is verified, SS m establishes a secure connection and sends the avatar information corresponding to the avatar identity of the user in the data interaction blockchain to SS n where the avatar is located, m , SS m Extract the avatar identity of the user in SS when it exists, and create a new avatar identity of the user in SS according to the corresponding avatar information and upload it to the data interaction blockchain when it does not exist; m Extract the avatar identity of the user in SS when it exists, and create a new avatar identity of the user in SS according to the corresponding avatar information and upload it to the data interaction blockchain when it does not exist; m Extract the avatar identity of the user in SS when it exists, and create a new avatar identity of the user in SS according to the corresponding avatar information and upload it to the data interaction blockchain when it does not exist; SS m According to the user's digital certificate, the digital certificate of SS m and the avatar identity of the user in SS m calculate the session key, and then calculate the communication information digest based on the above three and the session key; the smart device verifies the communication information digest to complete cross-scenario identity authentication.
2. The method for cross-scenario anonymous seamless identity authentication in the metaverse based on dual blockchains according to claim 1, wherein Step S1 is specifically as follows: The registration center RC selects as its private key and calculates the public key Pub RC = k·Q; where the global public parameters {E, p, q, G, Q, H} are used in the initialization phase, where E is an elliptic curve over the non-singular finite field F p on which, E: y 2 = x 3 + ax + b (mod p), p and q are two large prime numbers; G is an elliptic curve additive group composed of the points on the elliptic curve E and the infinite point O, whose order is q, Q is the generator of the G group; H is a collision-resistant one-way hash function that maps {0, 1} * to {0, 1} l .
3. A method for cross-scenario anonymous seamless identity authentication in the metaverse based on dual blockchains according to claim 2, characterized in that, Step S2 includes the following sub-steps: S2.
1. Scenario Server SS n Using the unique identification code ID SSn , select as its private key, and calculate the public key of the scenario server SS n as Then send the registration request information to the registration center RC through a secure channel; where ID SSn is the unique identification code of the scenario server; S2.
2. After the registration center RC receives the registration request information, it checks the existence and uniqueness of the ID in the registration blockchain and the database of the registration center. If the ID SSn exists or is not unique, the registration of the scenario server is terminated. Otherwise, the registration center RC calculates the digital certificate SSn || represents the connection operation. Using the transaction <Cert n > to generate a registration block index in the registration blockchain Finally, the registration center RC calculates the information digest and sends it to the scenario server SS through a secure channel n , and the scenario server SS n is successfully registered in the registration center RC; S2.
3. Scenario Server SS n Calculate Verify If it holds, terminate the process; otherwise, the Scenario Server SS n Calculate the ciphertext And store {D1} in its database, Store it in the secure memory, which is an exclusive OR operation.
4. A method for cross-scenario anonymous seamless identity authentication in the metaverse based on dual blockchains according to claim 3, characterized in that, Step S3 includes the following sub-steps: S3.
1. User U i Input the unique user account into the intelligent device connected to the metaverse Password PW i and biometric information Bio i . The fuzzy extractor in the device encrypts the user's biometric information (δ i , τ i ) = Gen(Bio i ), where δ i is the encrypted value generated by the fuzzy extractor, τ i is the auxiliary parameter, Gen() is the fuzzy extractor. At the same time, select as the private key as the secret value, and calculate the user's public key User identity Send the registration information to the registration center RC through a secure channel; S3.
2. After the registration center RC receives the registration information of user U i , it checks the uniqueness of the DID of user U i in the RC database of the registration center and on the registration blockchain. If the DID i exists or is not unique, the user registration is terminated. Otherwise, the registration center RC calculates the digital certificate i and then uses the transaction <Cert > to generate a registration block in the registration blockchain i and saves it in the RC database of the registration center. Then it calculates the information digest and sends to user U through a secure channel i ; S3.3, User U i Calculate Verify If it does not hold, terminate user registration; otherwise, User U i Calculate the ciphertext Is an exclusive OR operation, calculate the message digest And store {D3, D4, D5, D6} in the database of the intelligent device, and store {b i} in the secure memory.
5. A method for cross-scenario anonymous seamless identity authentication in the metaverse based on dual blockchains according to claim 4, characterized in that, Step S4 includes the following sub-steps: S4.
1. User U i Input PW i and Bio i into the intelligent device accessing the metaverse, and calculate δ i = Rep(Bio i , τ i ). Verify whether it holds. If it does not hold, terminate the program. Otherwise, select a random number as the temporary secret key, timestamp T1, calculate the temporary public key C1 = n1·Q, and the temporary symmetric key of the scenario server User public key If the avatar identity of the current scenario server is saved in the intelligent device, extract the avatar identity. If the avatar identity of the current scenario server is not saved, select a new user avatar Avat i and calculate the communication digest Encrypt the important information with the temporary symmetric key C2 to generate the communication ciphertext where Info i is the avatar information of the user in the metaverse. The user uses the intelligent device to send {C1, E N1 , T1} to the scenario server SS n through the public channel; this avatar information is the user's personalized avatar information; S4.
2. Scene Server SS n After receiving the login request from user U i , first verify whether the timestamp is valid to ensure the freshness of the data. If it is not valid, return to execute step S4.
1. Otherwise, calculate Decrypt the communication ciphertext through the calculated temporary symmetric key to obtain Calculate the communication digest Verify whether it is valid. If it is not valid, terminate the program. Otherwise, the scene server SS n will pass Retrieve the transaction <Cert i > in its database and the registered blockchain, and verify the digital certificate whether it is valid. If it is not valid, terminate the process. Otherwise, save the personalized avatar information Info of the user in the metaverse i , and retrieve whether there is an avatar identity of the user in the scene server SS i according to the user's DID n If so, extract the avatar. Otherwise, create a new avatar and calculate Upload as a transaction record to the data interaction blockchain and generate a data interaction block index After that, select a random number as its temporary secret key, timestamp T2, calculate its temporary public key C3 = n2·Q, and temporary symmetric key Calculate the session key i between user U n and scene server SS Communication information digest Send the information {C3, E N2 , T2} to the user's smart device through the public information using the temporary symmetric key C4; E N2 is the communication ciphertext; S4.3, User U i After receiving the response message, first verify the timestamp to ensure the freshness of the data. If it does not hold, discard it. Otherwise, calculate Obtain the decrypted communication ciphertext through the calculated temporary symmetric key The smart device of the user retrieves the transaction <Cert through the registration block index in the blockchain and verifies the digital certificate of SS n >. If it does not hold, terminate the process. Otherwise, calculate the n between User U and the scenario server SS i ; verify n between them is the data interaction block index, is the avatar identity of the user in the scenario server, is the registration block index, is the unique identity code of the scenario server; verify If it does not hold, terminate the program. Otherwise, complete the identity authentication and key exchange.
6. The method for cross-scenario anonymous seamless identity authentication in the metaverse based on a dual blockchain according to claim 1, wherein Step S5 includes the following sub-steps: S5.1, User U i When switching from the current metaverse scene service to another service, send a cross-domain request to the target scene server SS m and select a random number as its temporary secret key, timestamp T3, calculate the temporary public key C5 = n3·Q, and the temporary symmetric key communication information digest Encrypt the important information with the temporary symmetric key C6 to generate a communication ciphertext: The user uses a smart device to send the communication ciphertext to the target scenario server SS through a public channel m ; S5.
2. Target Scenario Server SS m Upon receiving a cross - domain request from user U i , first verify whether the timestamp is valid to ensure data freshness. If it is not valid, discard it. Otherwise, calculate where a m is the private key of the target scenario server SS m . Decrypt the communication ciphertext through the calculated temporary symmetric key to obtain the communication information digest Verify whether it holds. If it does not hold, terminate the program. Otherwise, the target scenario server SS m retrieves the transaction <Cert > in the database and the registered blockchain. According to the user's DID i , retrieve the user's avatar identity on the target scenario server SS i in the database m and authenticate with the scenario server SS to obtain the user's personalized avatar information Info n in the meta - universe i ; S5.3, Target Scenario Server SS m Decrypt the registration block index on the registration blockchain that belongs to itself is the encrypted information stored in the target scenario server; select a random number as its temporary secret key, timestamp T4, calculate the temporary public key C7 = n4·Q, and the temporary symmetric key Communication information digest Use the temporary symmetric key C8 to encrypt the important information to generate communication ciphertext Send the information {C7, E N4 , T4} to the scenario server SS through the public channel n ; S5.4, Scenario Server SS n After receiving the authentication request from the target scenario server SS m , first verify whether the timestamp is valid to ensure the freshness of the data. If it is not valid, terminate the program. Otherwise, calculate Decrypt the communication ciphertext through the calculated temporary symmetric key to obtain Verify Whether it is valid. If it is not valid, terminate the program. Otherwise, the scenario server SS n Retrieve the transaction <Cert m > in the registration blockchain through the registration block index of the target scenario server SS , and verify the digital certificate m of the target scenario server SS m Whether it is valid. If it is not valid, terminate the process. Otherwise, calculate the registration block index of the scenario server SS n , select a random number as its temporary secret key, timestamp T5, calculate the temporary public key C9 = n5·Q, and the temporary symmetric key The session key between the scenario server SS n and the target scenario server SS m Calculate the communication information digest through the temporary symmetric key C Encrypt the important information through the temporary symmetric key C 10 to generate the communication ciphertext Send the information {C9, E N5 , T5} to the target scenario server SS through the public channel m ; S5.5, Target Scenario Server SS m After receiving the response from Scenario Server SS n first verify the timestamp to ensure the freshness of the data. If it does not hold, terminate the program. Otherwise, calculate the symmetric key Decrypt the communication ciphertext using the calculated temporary symmetric key to obtain Retrieve the transaction <Cert n from the registration blockchain using the registration block index of Scenario Server SS Verify the digital certificate of Scenario Server SS n > If it does not hold, terminate the program. Otherwise, calculate the session key n between the target scenario server SS and Scenario Server SS m n verify Is it true? If not, terminate the program. If true, complete the target scenario server SS m and scene server SS n Authentication and secure connection between User U i In the scene server SS n Personalized information in Info i Safely transmitted to the target scene server SS m , S5.6, target scene server SS m Successfully obtained user U i After the personalized avatar information is obtained, the user's DID i Check whether the user exists in the target scenario server SS in its database m Avatar identity If yes, extract the avatar identity If not, create a new avatar identity Will Uploaded to the data interaction blockchain as a transaction record and generate a data interaction block index Then choose a random number As the temporary key, timestamp T6, calculate the temporary public key C 11 =n6·Q, temporary symmetric key Calculate the target scene server SS m and user U i The session key between communication summary Through the temporary symmetric key C 12 Encrypt important information to generate communication ciphertext The information 11 , E N6 , T6} is sent to the user’s smart device via public information; S5.7, User U i receives the information {C 11 , E N6 , T6}, and first verifies the timestamp to ensure data freshness. If it does not hold, the program is terminated. Otherwise, calculate the temporary symmetric key obtained through calculation to decrypt the communication ciphertext to obtain The user's smart device retrieves the transaction <Cert m from the registration block index of the target scenario server SS in the registration blockchain, and verifies the digital certificate of the target scenario server SS m > m . If it does not hold, the program is terminated. Otherwise, calculate the session key between the user and the target scenario server SS Verify 1. A cross-scenario anonymous seamless identity authentication method for the metaverse based on dual blockchains, characterized in that, It includes the following steps: whether it holds. If it does not hold, the process is terminated. Otherwise, the user completes the cross-scenario server identity authentication and key exchange.
Citation Information
Patent Citations
Data processing method, device and equipment, blockchain system and storage medium
CN111353175A
Multi-universe identity mutual recognition and information transmission system and method thereof
CN117411640A