A secure and efficient identity authentication method

By adopting polynomial ring encryption and decryption technology in identity authentication, the problem of insufficient security of password authentication in the prior art is solved, efficient and secure identity authentication is achieved, and the system security protection cost is reduced.

CN119496660BActive Publication Date: 2025-06-06HANGZHOU NORMAL UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411688401.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-25
Publication Date
2025-06-06
Estimated Expiration
2044-11-25

AI Technical Summary

Technical Problem

The existing password-based identity authentication scheme has the problem of security-dependent hashing algorithms and salt values, is vulnerable to dictionary attacks, and increases security protection costs and complexity in information systems.

Method used

The polynomial ring encryption and decryption technology is adopted, and the server generates public keys and private keys. The user uses the public key to encrypt the password. The server uses the private key to decrypt and performs authentication calculations to ensure that all password-related operations are carried out in an encrypted state.

Benefits of technology

Improve the security of identity authentication, prevent dictionary attacks and password leakage, reduce system security protection costs, and simplify system installation and operation and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119496660B_ABST
    Figure CN119496660B_ABST
Patent Text Reader

Abstract

The present invention discloses a safe and efficient identity authentication method, which is used to realize the identity authentication of the user end by the server end, including two stages of server end system initialization and user identity authentication: in the server end system initialization stage, the server end generates system operation parameters, and defines the polynomial ring involved in encryption and decryption with the system operation parameters; the polynomial ring is used to randomly form a private key and a public key, the private key is used for decryption of the server end, and the public and private keys are used for encryption of the user end; the user end registration and authentication stage includes user registration and user identity authentication stages; in the user registration stage, the server end stores the plain text of the user ID and the ciphertext of the password, and in the user identity authentication stage, the ciphertext of the password is determined by authentication calculation. The present invention can realize the identity recognition function of the server end to the user end, and has the advantage of high security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a safe and efficient identity authentication method. Background Art

[0002] User identity authentication is the basic module of information system and one of the key means of information system security protection. Among all user identity authentication mechanisms, password-based authentication is the most widely used scheme. This scheme includes two stages: initialization and identity authentication. In the initialization stage, the server stores the user ID, the salted hash value of the password and the salt value used for the salted hash. In the identity authentication stage, the user sends his ID and authentication password to the server. After receiving the user ID and password, the server finds the corresponding salt value and performs salted hash processing on the user password. Then, the hash value is compared with the salted hash value of the user stored by the server. If the two are the same, the authentication is successful, otherwise, the authentication fails. The security of this scheme has the following problems: 1. The security of this method depends on the security of the hash algorithm itself and the length and randomness of the salt value. Irregular use (such as using unsafe algorithms such as MD5 and SHA1, and not using random salt values ​​or the salt value is not random enough) may lead to malicious attacks such as dictionary attacks, thereby greatly reducing the security of the system; 2. The secure transmission of passwords between the user and the server is to establish a secure channel, such as TLS / SSL encrypted channel. This method usually requires the installation of security hardware such as SSLVPN gateway on the server side and the configuration of the corresponding server certificate. This not only increases the cost of information system security protection, but also increases the complexity of system installation, configuration and subsequent operation and maintenance. Summary of the invention

[0003] The purpose of the present invention is to provide a safe and efficient identity authentication method. The present invention can realize the identity recognition function of the service end to the user end, and has the advantage of high security.

[0004] The technical solution of the present invention is a safe and efficient identity authentication method, which is used to implement the identity authentication of the user end by the server end, including two stages: server end system initialization and user end registration authentication:

[0005] The server system initialization phase includes the following steps:

[0006] Step 1: The server generates system operation parameters, and uses the system operation parameters to define the polynomial ring involved in encryption and decryption;

[0007] Step 2: Use the polynomial ring to randomly generate private and public keys. The private key is used for decryption on the server side, and the public and private keys are used for encryption on the user side.

[0008] The user-side registration and authentication includes user registration and user identity authentication stages;

[0009] The user registration phase includes the following steps:

[0010] Step 1: The client sends a registration request to the server and obtains the server's public key;

[0011] Step 2: The user end encodes the user ID and password to obtain a corresponding digital string;

[0012] Step 3: The server uses the public key to encrypt each integer in the user ID and password to obtain the corresponding ciphertext, and then sends the ciphertext to the server;

[0013] Step 4: The server uses the private key to decrypt the ciphertext. After decryption, the server stores the plain text of the user ID and the ciphertext of the password. The user identity authentication stage includes the following steps:

[0014] Step a: The client encrypts the user ID with the public key to obtain a ciphertext, and sends the ciphertext to the server. At the same time, the client encodes the password;

[0015] Step b: After receiving the ciphertext of the user ID, the server uses the private key to decrypt it to obtain the plaintext of the user ID, and then finds the ciphertext of the password stored in the server based on the plaintext of the user ID;

[0016] Step c: The server randomly selects a polynomial in the polynomial ring to perform a first authentication calculation on a portion of the ciphertext of the password, and sends the result to the user after the first authentication calculation;

[0017] Step d: The user terminal performs a second authentication calculation on the result of the first authentication calculation, and sends the result to the server terminal after the second authentication calculation;

[0018] Step e: The server performs a third authentication calculation on the result of the second authentication calculation, and then combines the result of the third authentication calculation with another part of the password ciphertext to form a new ciphertext;

[0019] Step f: The server uses the private key to decrypt the new ciphertext. If the obtained plaintext is the same as the designed value, the authentication is successful, otherwise the authentication fails.

[0020] In the above-mentioned secure and efficient identity authentication method, in step 1, the system operating parameters include an integer k greater than 100, a prime number p greater than 1000, and an integer power of 2 n, where k is used to ensure the correctness of data decryption, and p and n are used to define the polynomial ring involved in encryption and decryption:

[0021] R p =F p [X] / (X n +1);

[0022] In the formula, R pis the ring of algebraic polynomials with prime numbers p as coefficients; F p is the integer field of prime number p; X is the indefinite quantity in the algebraic polynomial;

[0023] The elements in the polynomial ring are:

[0024] {a n-1 X n-1 +a n-2 X n-2 +…+a 1 X+a 0 :a i ∈Z p};

[0025] The small elements in the polynomial ring are:

[0026] {a n-1 X n-1 +a n-2 X n-2 +…+a 1 X+a 0 :a i ∈{0, 1, -1}}.

[0027] In the above-mentioned secure and efficient identity authentication method, in step 2, the private key is a random small element in the polynomial ring, represented by S; the public key is represented by (a, b), where a is a random element in the polynomial ring, b=as+e, and e is another random small element in the polynomial ring.

[0028] In the above-mentioned secure and efficient identity authentication method, in the encryption process, for the integer m to be encrypted, the ciphertext obtained after encryption is expressed as (v, w), where:

[0029] v=ar+e 1 ;

[0030] w=br+e 2 +km;

[0031] In the formula, r, e 1 and e 2 are three random small elements in the polynomial ring, (a, b) represents the public key;

[0032] After receiving the ciphertext (v, w), the decryption process is as follows:

[0033] Calculate x=w-vs, then take the number y that is an integer multiple of k closest to x, and then divide y by k to get the corresponding plaintext m.

[0034] In the aforementioned secure and efficient identity authentication method, the encoding and decoding of the user-side registration authentication adopts ASCII code.

[0035] In the above-mentioned secure and efficient identity authentication method, in step c, the ciphertext of the password is represented as (v 1 , w 1 ),…,(v n , w n );

[0036] Select the w in the ciphertext of the password i Perform the first authentication calculation:

[0037] w′ i =w i -r a ;

[0038] Where: r a is a random polynomial in the polynomial ring, the highest degree of the polynomial is no greater than n, and the coefficient of each term in the polynomial is a random number in the set {1,2,...,n-1};

[0039] The result of the first authentication calculation is expressed as (w′ 1 , ..., w′ n ).

[0040] In the above-mentioned secure and efficient identity authentication method, in step d, the second authentication calculation is as follows:

[0041] w″ i =w′ i -km i ;

[0042] Where: k is a common parameter of the system, that is, an integer greater than 100; m i Yes i The corresponding plaintext;

[0043] The result of the second authentication calculation is expressed as (w″′ i ,…w″′ n ).

[0044] In the above-mentioned secure and efficient identity authentication method, in step e, the third authentication calculation is as follows:

[0045] w″′ i =w″ i -ra;

[0046] The result of the third authentication calculation is expressed as (w″′ i ,…w″′ n );

[0047] Then the result of the third authentication calculation and the other part of the password ciphertext form a new ciphertext represented as (v i ,w″′i ), and finally use the private key S to encrypt the new ciphertext (v i ,w″′ i ) line to decrypt. If the obtained plaintext is all 0, the authentication is successful, otherwise the authentication fails.

[0048] Compared with the prior art, the present invention has the following beneficial effects:

[0049] 1. Confidentiality protection of user passwords: During the entire identity authentication process, user passwords are transmitted in ciphertext and stored in ciphertext on the server. All communication and operations on passwords are completed in an encrypted state, ensuring the confidentiality of user passwords. The protocol data exchange of the present invention can be run in an unsecured channel, and there is no need to deploy hardware security devices such as SSLVPN gateways, which reduces implementation costs and improves system reliability.

[0050] 2. Anti-offline dictionary attack: User passwords are encrypted and stored on the server, avoiding the risk of user passwords being leaked due to offline dictionary attacks when the server is compromised.

[0051] 3. Innovative application of fully homomorphic encryption scheme: By adopting fully homomorphic encryption (FHE) technology, on the one hand, the user side can use the ciphertext generated by the server to perform calculations without generating and managing its own public and private key pairs; on the other hand, the server side does not need to decrypt the user password plaintext during the entire process of the protocol operation, thus preventing the leakage of the user password during the operation of the protocol.

[0052] 4. Anti-replay attack: The present invention adopts a challenge-response mechanism. The server generates random challenges during each protocol operation, and the client must make new responses according to different challenges. Therefore, the attacker cannot replay any response from the client to deceive the server. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 It is a schematic diagram of the user terminal registration process of the present invention;

[0054] Figure 2 It is a schematic diagram of the user end identity authentication process of the present invention. DETAILED DESCRIPTION

[0055] The present invention is further described below in conjunction with the accompanying drawings and embodiments, but they are not intended to limit the present invention.

[0056] Embodiment: A safe and efficient identity authentication method is used to implement identity authentication of a user end by a server end, including two stages: server end system initialization and user end registration authentication:

[0057] The server system initialization phase includes the following steps:

[0058] Step 1: The server generates system operation parameters, and uses the system operation parameters to define the polynomial ring involved in encryption and decryption;

[0059] In this step, the system operation parameters include an integer k greater than 100, a prime number p greater than 1000, and an integer power of 2 n, where k is used to ensure the correctness of data decryption, and p and n are used to define the polynomial ring involved in encryption and decryption:

[0060] R p =F p [X] / (X n +1);

[0061] In the formula, R p is the ring of algebraic polynomials with prime numbers p as coefficients; F p is the integer field of prime number p; X is an indeterminate in the algebraic polynomial;

[0062] The elements in the polynomial ring are:

[0063] {a n-1 X n-1 +a n-2 X n-2 +…+a 1 X+a 0 :a i ∈Z p};

[0064] The small elements in the polynomial ring are:

[0065] {a n-1 X n-1 +a n-2 X n-2 +…+a 1 X+a 0 :a i ∈{0, 1, -1}}.

[0066] Step 2: Use the polynomial ring to randomly generate private and public keys. The private key is used for decryption on the server side, and the public and private keys are used for encryption on the user side.

[0067] In this step, after the system operating parameters are determined, the server randomly selects a small element in the polynomial ring as the private key, denoted as S; at the same time, it randomly selects an element a and a small element e in the polynomial ring, calculates b=as+e, and obtains the public key corresponding to the private key s, denoted as (a, b); during the user registration and authentication process, the user uses the public key (a, b) for encryption, and the server uses the private key S for decryption.

[0068] In this embodiment, for an integer m to be encrypted (0<m<p / k), the encryption process at the user end is described as follows:

[0069] 1. The user randomly selects three small elements r and e in the polynomial ring 1 and e 2 ;

[0070] 2. The user side calculates v and w according to the following formulas respectively;

[0071] v=ar+e 1 ;

[0072] w=br+e 2 +km;

[0073] In the formula, (a, b) represents the public key;

[0074] After encryption, the ciphertext of the integer m is represented as (v, w). After encryption is completed, the user end can discard the small elements r and e 1 and e 2 ;

[0075] After receiving the ciphertext (v, w), the server uses the corresponding private key S to decrypt it:

[0076] 1. Calculate x = w - vs;

[0077] 2. Then take the number y that is the closest integer multiple of k to x;

[0078] 3. Divide y by k to get the corresponding plaintext m.

[0079] The user-side registration and authentication includes user registration and user identity authentication stages;

[0080] like Figure 1 As shown, the user registration stage includes the following steps:

[0081] Step 1: The client sends a registration request to the server, and the server sends the public key (a, b) to the client for encryption;

[0082] Step 2: The user end encodes the user ID and password (ASCII code) to obtain a corresponding digital string; In this step, the user ID and password are encoded with ASCII code to obtain a corresponding decimal digital string, which is represented by m i Indicates the i-th decimal digit after the password is encoded, such as:

[0083] Username: HilsWang;

[0084] Password: kieS87Dq#t;

[0085] The corresponding ASCII decimal string is:

[0086] Username: 721051081158797110103;

[0087] Password: 1071051018356556811335116;

[0088] Step 3: The server uses the public key (a, b) to encrypt each integer in the user ID and password to obtain the corresponding ciphertext, and then sends the ciphertext to the server;

[0089] In this step, the ciphertext of the user ID is as follows:

[0090] (uv 1 , uw 1 ),…,(uv m , uw m );

[0091] The ciphertext of the password is as follows:

[0092] (v 1 , w 1 ),…,(v n , w n );

[0093] Step 4: After receiving the ciphertext, the server uses the private key S to decrypt the ciphertext, obtains the decimal digit string corresponding to the ASCII code of the user name, decodes the user ID after decryption, and stores the plain text of the user ID and the ciphertext of the password after decoding;

[0094] like Figure 2 As shown, the user identity authentication stage includes the following steps:

[0095] Step a: The user end encrypts the user ID with the public key (a, b) to obtain the ciphertext (uv 1 , uw 1 ),...,(uv m , uw m ), and sends the ciphertext to the server. At the same time, the user encodes the password, and the encoded value is used in the identity authentication process (and the password ciphertext sent by the server) for calculation;

[0096] In this step, since the encryption algorithm is a probabilistic encryption algorithm, the ciphertext is different from the user ID ciphertext sent by the user end during the registration phase;

[0097] Step b: After receiving the ciphertext of the user ID, the server uses the private key S to decrypt it to obtain the plaintext of the user ID, and then finds the ciphertext of the password stored on the server based on the plaintext of the user ID:

[0098] (v 1 ,w1 ),…,(v n ,w n );

[0099] Step c: The server randomly selects a polynomial in the polynomial ring to perform a first authentication calculation on a portion of the ciphertext of the password, and sends the result to the user after the first authentication calculation;

[0100] In this step, select the w in the ciphertext of the password. i Perform the first authentication calculation:

[0101] w′ i =w i -r a ;

[0102] Where: ra is a random polynomial in the polynomial ring;

[0103] The result of the first authentication calculation is expressed as (w′ 1 ,…,w′ n ).

[0104] Step d: The user terminal performs a second authentication calculation on the result of the first authentication calculation, and sends the result to the server terminal after the second authentication calculation;

[0105] In this step, the second authentication is calculated as follows:

[0106] w″ i =w′ i -km i ;

[0107] Where: k is a common parameter of the system, that is, an integer greater than 100; m i Yes i The corresponding plain text (the i-th digit in the decimal string of the password ASCII code);

[0108] The result of the second authentication calculation is expressed as (w″ 1 ,...,w″ n ).

[0109] Step e: The server performs a third authentication calculation on the result of the second authentication calculation, and then combines the result of the third authentication calculation with another part of the password ciphertext to form a new ciphertext;

[0110] In this step, the third authentication is calculated as follows:

[0111] w″′ i =w″ i -r a ;

[0112] The result of the third authentication calculation is expressed as (w″ i ,...,w″ n );

[0113] Then the result of the third authentication calculation and the other part of the password ciphertext form a new ciphertext represented as (v i ,w″′ i ),

[0114] Step f: The server uses the private key S to encrypt the new ciphertext (v i , w i ″′) for decryption. If the obtained plaintext is the same as the designed value (that is, the obtained plaintext is all 0), the authentication is successful, otherwise the authentication fails.

[0115] In summary, the present invention adopts a fully homomorphic encryption scheme to ensure that the communication and calculation about the password are performed in an encrypted state, thereby improving security. The user password of the present invention is stored in an encrypted form to prevent the password from being leaked when the server is compromised. The present invention adopts a challenge-response mechanism to ensure the uniqueness of each user response data and prevent attackers from replaying information. Therefore, the present invention can realize the identity recognition function of the server to the user end, and has the advantage of high security.

Claims

1. A safe and efficient identity authentication method, characterized by: It includes two stages: server system initialization and user registration and authentication: The server system initialization phase includes the following steps: Step 1: The server generates system operation parameters, and uses the system operation parameters to define the polynomial ring involved in encryption and decryption; Step 2: Use the polynomial ring to randomly generate private keys and public keys. The private key is used for decryption on the server side, and the public key is used for encryption on the user side. The user-side registration and authentication phase includes two phases: user registration and user identity authentication; The user registration phase includes the following steps: Step 1: The client sends a registration request to the server and obtains the server's public key; Step 2: The user end encodes the user ID and password to obtain a corresponding digital string; Step 3: The client uses the public key to encrypt each integer in the user ID and password to obtain the corresponding ciphertext, and then sends the ciphertext to the server; Step 4: The server uses the private key to decrypt the ciphertext. After decryption, the server stores the plaintext of the user ID and the ciphertext of the password. The user identity authentication stage includes the following steps: Step a: The client encrypts the user ID with the public key to obtain a ciphertext, and sends the ciphertext to the server. At the same time, the client encodes the password; Step b: After receiving the ciphertext of the user ID, the server uses the private key to decrypt it to obtain the plaintext of the user ID, and then finds the ciphertext of the password stored in the server based on the plaintext of the user ID; Step c: The server randomly selects a polynomial in the polynomial ring to perform a first authentication calculation on a portion of the ciphertext of the password, and sends the result to the user after the first authentication calculation; Step d: The user terminal performs a second authentication calculation on the result of the first authentication calculation, and sends the result to the server terminal after the second authentication calculation; Step e: The server performs a third authentication calculation on the result of the second authentication calculation, and then combines the result of the third authentication calculation with another part of the password ciphertext to form a new ciphertext; Step f: The server uses the private key to decrypt the new ciphertext. If the obtained plaintext is the same as the designed value, the authentication is successful, otherwise the authentication fails. In step c, the ciphertext of the password is represented by (v1, w1),…,(v n ,w n ); Select the w in the ciphertext of the password i Perform the first authentication calculation: w′ i =w i -r a ; Where: r a is a random polynomial in the polynomial ring, the highest degree of the polynomial is not greater than the integer power n of 2, and the coefficient of each term in the polynomial is a random number in the set {1,2,...,n-1}; The result of the first authentication calculation is expressed as (w′1,...,w′ n ); In step d, the second authentication is calculated as follows: In" i =in′ i -km i ; Where: k is an integer greater than 100; m i It is W i The corresponding plaintext; The result of the second authentication calculation is expressed as (w″1, ..., w″ n ); In step e, the third authentication is calculated as follows: w″′ i =w″ i -r a ; The result of the third authentication calculation is expressed as (w″′ i ,…w″′ n ); Then the result of the third authentication calculation and the other part of the password ciphertext form a new ciphertext represented as (v i , w″′ i ), and finally use the private key s to encrypt the new ciphertext (v i , w″′ i ) is used for decryption. If the obtained plaintext is all 0, the authentication is successful, otherwise the authentication fails.

2. The safe and efficient identity authentication method according to claim 1, characterized in that: In step 1, the system operating parameters include an integer k greater than 100, a prime number p greater than 1000, and an integer power of 2 n, where k is used to ensure the correctness of data decryption, and p and n are used to define the polynomial ring involved in encryption and decryption: R p =F p [X] / (X n +1); In the formula, R p is the ring of algebraic polynomials with prime numbers p as coefficients; F p is the integer field of prime number p; X is the indefinite quantity in the algebraic polynomial; The elements in the polynomial ring are: {a n-1 X n-1 +a n-2 X n-2 +…+a1X+a0:a i ∈Z p }; The small elements in the polynomial ring are: {a n-1 X n-1 +a n-2 X n-2 +…+a1X+a0:a i ∈{0,1,-1}}。 3. The safe and efficient identity authentication method according to claim 2, characterized in that: In step 2, the private key is a random small element in the polynomial ring, represented by s; the public key is represented by (a, b), where a is a random element in the polynomial ring, b=as+e, and e is another random small element in the polynomial ring.

4. The safe and efficient identity authentication method according to claim 3, characterized in that: During the encryption process on the user side, for the integer m to be encrypted, the ciphertext obtained after encryption is expressed as (v, w), where: v = ar + e1; w=br+e2+km: Wherein, r, e1 and e2 are three random small elements in the polynomial ring, and (a, b) represents the public key; After receiving the ciphertext (v, w), the server decryption process is as follows: Calculate x=w-vs, then take the number y that is an integer multiple of k closest to x, and then divide y by k to get the corresponding plaintext m.

5. The safe and efficient identity authentication method according to claim 1, characterized in that: The encoding and decoding of the user terminal registration authentication adopts ASCII code.

Citation Information

Patent Citations

  • Image comparison method and device based on privacy protection

    CN115001652A

  • Method and system for homomorphicly randomizing an input

    US20150215123A1