Identity authentication method, system and device in weak network environment
By generating and managing device identification codes on the client, adding salt hash passwords using the Argon2id algorithm, and using the zero-knowledge proof technology to perform identity authentication, the bottlenecks and security risks of identity authentication in weak network environments are solved, and efficient and secure identity authentication and communication are achieved.
Patent Information
- Application Number
- CN202510144254.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-10
AI Technical Summary
In a weak network environment, traditional identity authentication methods rely on centralized server resources, resulting in performance bottlenecks and are vulnerable to password leakage, brute force cracking and social engineering attacks, especially when users reuse passwords across platforms.
By implementing the identity authentication function on the client, generating and managing device identification codes, using the Argon2id algorithm to salt hash the password, and authenticating based on the zero-knowledge proof technology, reducing dependence on the server.
It improves the overall performance and security of the system, reduces the risk of key leakage, enhances the ability to resist man-in-the-middle attacks, and simplifies trust management and key distribution processes.
Smart Images

Figure CN119995861A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and specifically relates to an identity authentication method, system and device in a weak network environment. Background Art
[0002] Identity authentication is an important part of modern network security. It ensures that the user or device of the system is indeed who it claims to be, thereby preventing unauthorized access and operation. Through identity authentication, unauthorized users can be prevented from accessing sensitive data in the system, effectively preventing hackers and malicious users from illegally accessing systems and resources, and ensuring that only authorized users or devices can interpret the transmission content, thereby ensuring the confidentiality and integrity of communications.
[0003] However, in weak network environments or decentralized environments, server resources are limited and clients must undertake more authentication tasks. Traditional identity authentication methods usually rely on centralized server resources, which can easily lead to performance bottlenecks, and password leaks, brute force cracking, and social engineering attacks occur frequently, especially when users reuse passwords across platforms. The risk is even higher, and communication also requires the use of a trusted third-party CA organization to issue digital certificates, which is complex to manage and difficult to implement.
[0004] To this end, an efficient and secure solution is needed to implement identity authentication functions on the client, while reducing dependence on the server and improving the overall performance and security of the system. Summary of the invention
[0005] In view of the above problems, the present invention provides an identity authentication method, system and device in a weak network environment, the main purpose of which is to solve the identity authentication problem when network resources are insufficient and ensure one-to-one correspondence between devices, accounts and users.
[0006] A first aspect of the present invention provides an identity authentication method for use in a weak network environment, specifically comprising the following steps:
[0007] Step 1: Generate and manage device identification codes during the device registration phase;
[0008] During the device registration stage, a unique device identification code is generated based on the device information. This step specifically includes: obtaining the device's hardware feature information, manufacturer information, operating system information, compilation information and application support information; concatenating the hardware feature information, manufacturer information, operating system information, compilation information and application support information in the format of "hardware feature information: manufacturer information: operating system information: compilation information: application support information" to form a set of device feature data; using the SHA3-256 algorithm to perform a hash operation on the device feature data to generate an irreversible hash value of the device identification code; storing the generated hash value of the device identification code in the device's local database to ensure the integrity of the device identification code.
[0009] Step 2: Apply password security enhancement policies during user registration;
[0010] During the user registration stage, the user enters a custom password and processes the password to ensure its security. This step specifically includes: generating a unique random salt value through a secure random number generator, combining the password entered by the user with the generated salt value, and using the Argon2id algorithm to perform a salted hash operation; the generated salt value and the corresponding hash value are interlaced in the order of "one salt, two hashes" and stored in the local database of the device; the software generates multiple pseudo-passwords and their corresponding random salt values, combines the pseudo-passwords with the corresponding salt values, and processes them using the same Argon2id algorithm as the real password, and interlaced the salt value and the generated pseudo-password hash value in the order of "one salt, two hashes", and stores them in the same local database with the salt and hash interlaced values of the real password to form an obfuscated data set; the software stores the index marking the real password in an independent secure data storage.
[0011] Step 3: Record and update the timestamp when the user status changes;
[0012] 31) When the user registration is completed, the software records the registration timestamp and calculates the expiration timestamp of the user identity validity period, and initializes the expiration flag to a non-expired state;
[0013] 32) When a legitimate user logs in, the software dynamically extends the identity validity period according to the current time, updates the expiration timestamp, and resets the expiration flag to a non-expired state;
[0014] 33) When an expired user attempts to log in, the software will update the expiration flag to expired and require the user to re-complete identity authentication to restore the legal identity status;
[0015] 34) When the user is offline, the software records the offline timestamp;
[0016] 35) Timestamps and flags are stored in the local database to ensure data persistence and consistency.
[0017] Step 4: Comparison and verification of device identification code, password and timestamp during login phase;
[0018] 41) During the login phase, the user enters his / her identity information and clicks the login button. The software then reads the expiration timestamp, offline timestamp, expiration flag, device identification code hash value, and the interleaved value of the salt and hash from the database;
[0019] 42) Get the current system time of the device and determine whether the current timestamp is less than the expiration timestamp: if the current timestamp is less than the expiration timestamp, it means that the identity is still valid, otherwise it means that the identity authentication has expired, set the expiration flag to expired and refuse login; check whether the offline timestamp is less than the current timestamp: if the offline timestamp is less than the current timestamp, it means that the device time flow is normal, otherwise it means that the device system time has been tampered with and refuse login;
[0020] 43) Read the current device information, calculate the device identification code according to the method described in step 1, and compare the calculation result with the stored device identification code hash value to confirm the legitimacy of the device;
[0021] 44) Separate the salt value and the hash value, combine the password entered by the user with the salt value, and use the Argon2id algorithm described in step 2 to calculate the hash value; compare the calculated hash value with the stored hash value to verify the correctness of the password: if the verification is successful, the user successfully logs in; if the verification fails and the wrong password is entered k times, the software triggers the security lock mechanism to limit further login attempts;
[0022] 45) If the password entered by the user matches the stored pseudo-password hash value, the software will guide the user into a disguised honeypot account environment. The honeypot account environment records the attack behavior by simulating the behavior and data content of the real account, including the entered password, login time, access path, login IP, and operation records.
[0023] Step 5: Identity-based zero-knowledge proof authentication in the authentication phase;
[0024] 51) The key generation center generates and publishes public parameters. This step specifically includes: selecting elliptic curve parameters to satisfy the following formula:
[0025] y 2 =x 3 +ax+b mod p (1)
[0026] 4a 3 +27b 2 ≠0 (2)
[0027] Where p is a prime number, a and b are elliptic curve parameters, and x and y are points on the elliptic curve;
[0028] Select the base point and its order, generate global parameters and master key, and satisfy the following formula:
[0029] n·G=O (3)
[0030] params=(p,a,b,G,n) (4)
[0031] master_key=Random([1,n-1]) (5)
[0032] Where G is the base point on the elliptic curve, n is the order of the base point G, O is the point at infinity, params is the public parameter, and master_key is the system master key;
[0033] 52) The legitimate user submits the identity to the key generation center through the client software. The key generation center uses the user's identity and the master key master_key to calculate the private key. The formula is as follows:
[0034] SK=H(ID)·master_key mod n (6)
[0035] Where SK is the user's private key, and H(ID) is the identity hash value;
[0036] The key generation center securely distributes SK to users, who encrypt and store it on their local devices.
[0037] 53) The key generation center defines the public key generation function. Any entity only needs to know the user ID and public parameters params to calculate the corresponding user public key. The formula is as follows:
[0038] PK=H(ID)·G (7)
[0039] Among them, PK is the public key, which is used for subsequent identity authentication;
[0040] 54) The prover authenticates the verifier through Schnorr zero-knowledge proof without leaking any information. This step specifically includes: the prover generates a context based on the current timestamp and identity identifier, and generates a proof using the private key and context. The formula is as follows:
[0041] MM=H(T||ID A ) (8)
[0042] R=r·G (9)
[0043] r=Random([1,n-1]) (10)
[0044] c=H(R||M) (11)
[0045] z=r+c·SK A mod n (12)
[0046] π=(R,z) (13)
[0047] Where M is the context, T is the current timestamp, and ID A is the identifier of the prover, H(·) indicates hashing the contents of the brackets, R is a point on the ellipse, r is a random value, c is the challenge, z is the response, and π is the proof;
[0048] The prover sends its own identity, current timestamp and proof to the verifier. The verifier calculates the prover's public key based on the user identity. The formula is as follows:
[0049] PK A =H(ID A )·G (14)
[0050] Among them PK A is the public key of the proving user;
[0051] The verifier checks whether the timestamp is within the allowed time window of m minutes, and rejects the request if it times out;
[0052] The verifier calculates the challenge and verifies whether the following equation holds:
[0053]
[0054] If the equation holds true, the proof is valid and the identity authentication is successful.
[0055] Step 6: Generation and verification of process identification code during the communication phase;
[0056] During the communication phase, a unique process identification code is generated for each message to verify the legitimacy of the communication; the process identification code consists of a user ID, a timestamp and random characters, wherein the random characters are generated based on predefined rules and are arranged as consecutive GBK encoded characters; the generated process identification code is attached to the message to be sent and transmitted to the receiving end along with the message; after receiving the message, the receiving end verifies the legitimacy of the attached process identification code, specifically checking whether the user ID matches, whether the timestamp is within the predefined valid range, and whether the random characters comply with the generation rules; the software adopts a hierarchical storage strategy for the management of process identification codes: short-term storage is used for real-time verification during the session to ensure the integrity and reliability of the message delivery process; long-term storage is used for post-audit and anomaly detection to provide support for the security and traceability of the software.
[0057] The second aspect of the present invention relates to an identity authentication system in a weak network environment, located at a client, and the system is mainly used to implement the identity authentication method in a weak network environment proposed by the present invention. It includes:
[0058] Registration module, used to generate and manage device identification codes during the device registration phase;
[0059] Login module, used to apply password security enhancement policies during the user registration phase;
[0060] Timestamp recording and updating module, used to record and update timestamps when user status changes;
[0061] The device identification code, password and timestamp verification and comparison module is used to compare and verify the device identification code, password and timestamp during the login phase;
[0062] Identity authentication module, used for identity-based zero-knowledge proof authentication in the authentication phase;
[0063] The process identification code generation and verification module is used to generate and verify the process identification code during the communication phase.
[0064] The third aspect of the present invention relates to an identity authentication device in a weak network environment, comprising a memory and one or more processors, wherein the memory stores executable code. When the one or more processors execute the executable code, the identity authentication method in a weak network environment proposed by the present invention can be implemented.
[0065] The beneficial effects of the present invention are as follows:
[0066] 1) The present invention improves the key protection level by entrusting the generation, storage and management of keys to an independent Keystore module, thereby preventing the risk of key leakage caused by device attacks or data leakage.
[0067] 2) The present invention uses the Argon2id algorithm to perform salted hashing on the password to generate a unique secure hash value, and stores the real password mixed with the salt value and hash value of the pseudo password, effectively preventing rainbow table attacks and brute force cracking. At the same time, the pseudo password and honeypot mechanism are used to confuse attackers, further improving the security of password storage.
[0068] 3) The zero-knowledge proof technology based on identity in the present invention can complete authentication without exposing any private information of the user's identity, significantly enhancing the system's ability to resist man-in-the-middle attacks, while simplifying the trust management and key distribution processes and reducing system complexity.
[0069] 4) The design of the present invention fully considers the limitations in a weak network environment, reduces dependence on the server, and utilizes local verification and secure storage mechanisms to achieve efficient and secure identity authentication and communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0070] Figure 1 is a flow chart of the method of the present invention.
[0071] Figure 2 It is a client system framework diagram of the present invention.
[0072] Figure 3 It is a block diagram of an electronic device of the present invention.
[0073] Figure 4 It is a storage format diagram of mixed salt and hash in a preferred embodiment of the present invention.
[0074] Figure 5 It is a message format diagram of the process identification code in the preferred embodiment of the present invention. DETAILED DESCRIPTION
[0075] The present invention is further described below with reference to the accompanying drawings, taking an Android client as an example.
[0076] Example 1
[0077] Reference Figure 1 , an identity authentication method in a weak network environment, comprising the following steps:
[0078] Step 1: Generate and manage device identification codes during the device registration phase;
[0079] During the device registration phase, the device hardware feature information, manufacturer information, operating system information, compilation information, and application support information of the mobile phone are first read. The optional information list is shown in Table 1 below:
[0080] Table 1
[0081]
[0082]
[0083] The device brand, device hardware name, version number, device manufacturer, and build timestamp are selected and concatenated into the device feature information "Redmi:mt6768:SP1A.210812.016:Xiaomi:1689573760000". Subsequently, the SHA3-256 hash function is called to calculate the device feature information and generate a 256-bit hash value as the device identification code. Finally, the generated device identification code is stored in the local database SQLite.
[0084] Step 2: Apply password security enhancement policies during user registration;
[0085] During the user registration stage, the user enters the password "123456". The software first generates a unique random salt value of 16 bytes in length by calling the secure random number generation method SecureRandom. Subsequently, the password entered by the user is combined with the generated salt value, and the Argon2id algorithm is used for salted hash calculation to generate a hash value of 32 bytes in length. The recommended Argon2id algorithm parameter configuration is: 4 iterations, 96MB of memory cost, and 2 parallelism. On devices with stronger hardware performance, the number of iterations and memory cost can be appropriately increased, and the degree of parallelism can be adjusted to be consistent with the number of CPU cores of the device to achieve a balance between security and performance. Finally, refer to Figure 4 , the generated salt value and hash value are interlaced and merged according to the rule of "one salt, two hashes" to form mixed data with a total length of 48 bytes. The mixed data is stored in the local database SQLite to ensure the security of the password data.
[0086] At the same time, in order to enhance the anti-attack capability of the software, multiple pseudo passwords and their corresponding random salt values are generated in the process of processing user passwords. Pseudo passwords are generated in various ways, for example: replacing characters in user passwords to generate pseudo passwords in the form of "123678"; appending suffixes to passwords to generate pseudo passwords in the form of "123456Bob"; completely randomly generated pseudo passwords in the form of "f5tG846Dh". After each pseudo password is combined with its corresponding random salt value, the salted hashing process is performed using the same Argon2id algorithm and parameter configuration as the real password to generate the corresponding pseudo password hash value. After the pseudo password hash value and its salt value are processed according to the same interleaving rule, they are stored in the same database table together with the mixed data of the real password to form an obfuscated data set. The serial number information of the real password is stored in an independent index database to mark and identify the correct password. This design effectively improves the anti-attack capability of the data, reduces the possibility of cracking the real password through data analysis, and ensures the password management security and privacy protection capabilities of the system in a weak network environment.
[0087] Step 3: Record and update the timestamp when the user status changes;
[0088] 31) When the user completes the registration, the software initializes the expiration flag of the user identity to "not expired" and records the timestamp of the registration time 1732591137562 as the initial login timestamp. This timestamp is used to identify the time node of the user's first registration.
[0089] 32) When a legitimate user logs in, the software will update the login timestamp, dynamically extend the validity period of the user's identity according to the preset identity validity period, and reset the expiration flag to "not expired". The login timestamp, such as 1732591204547, will also be recorded in the software as a reference for subsequent verification.
[0090] 33) When an expired user logs in, the software will update the expiration flag to "expired" and require the user to re-complete identity authentication to restore the legal identity status.
[0091] 34) When the user completes the communication and enters the offline state, the software will record the offline timestamp, such as 1732591426765, and combine it with the set identity validity period, such as 12 hours, to calculate the new expiration timestamp 1732634591000.
[0092] 35) Flags and timestamps are stored in the SQLite local database to ensure data reliability and consistency. The timestamp recording mechanism can effectively support the software's dynamic management of user identity status, ensure the security of user identity authentication, and improve the stability and practicality of the software in a weak network environment.
[0093] Step 4: Comparison and verification of device identification code, password and timestamp during login phase;
[0094] 41) During the login phase, the user enters the ID number 64001 obtained during registration and the initial password 123456 set. After clicking the login button, the software will extract user-related information from the SQLite database, including expiration timestamp, offline timestamp, expiration flag, device identification code hash value, and an interleaved data set of salt and hash value to verify the user's identity validity and the legitimacy of the device.
[0095] 42) Get the current system time of the device and determine whether the current timestamp is less than the expiration timestamp: If the current timestamp is less than the expiration timestamp, it means that the identity is still valid, otherwise it means that the identity authentication has expired, set the expiration flag to the expired state and refuse login; check whether the offline timestamp is less than the current timestamp: If the offline timestamp is less than the current timestamp, it means that the device time flow is normal, otherwise it means that the device system time may be tampered with and refuse login.
[0096] 43) Read the current device hardware feature information, manufacturer information, operating system information, compilation information and application support information. Select the device brand, device hardware name, version number, device manufacturer and build timestamp, and splice them in the format of "brand: hardware name: version number: manufacturer: build timestamp" to generate device feature information, such as "Redmi:mt6768:SP1A.210812.016:Xiaomi:1689573760000". Then, use the SHA3-256 hash function to hash the device feature information, generate a 256-bit device identification code hash value, and compare it with the stored device identification code. If they are equal, it means that the device is legal, otherwise it is an illegal device and the user's login request is rejected.
[0097] 44) Separate the salt value from the hash value, combine the password entered by the user with the salt value, call the Argon2id algorithm to calculate the hash value, and compare the generated hash value with the stored hash value. If the hash values are equal, the password is correct, otherwise the password is wrong. If the verification fails and the wrong password is entered three times, the software triggers the security lock mechanism to limit further login attempts and prevent brute force cracking and database collision attacks.
[0098] 45) If the password entered by the user matches the stored pseudo-password hash value, the software will guide the user into a disguised honeypot account environment. The honeypot account environment records the attack behavior by simulating the behavior and data content of the real account, including the entered password, login timestamp, access path, login IP, and operation records. For example, an attack record may show that the entered password is "123678", the login timestamp is 1732604513897, the access path is " / storage / emulated / 0 / Download", and the login IP is "192.168.20.133". These records are stored in log files, providing important data support for the design and optimization of subsequent security policies.
[0099] Step 5: Identity-based zero-knowledge proof authentication in the authentication phase;
[0100] 51) The key generation center initializes system parameters and selects appropriate elliptic curve parameters to meet the following conditions:
[0101] y 2 =x 3 +ax+b mod p (1)
[0102] 4a 3 +27b 2 ≠0 (2)
[0103] Where p is a prime number, a and b are elliptic curve parameters, and x and y are points on the elliptic curve;
[0104] Select a base point and its order, generate global public parameters (p, a, b, G, n), and publish them through a secure channel. At the same time, randomly select a master key master_key that satisfies the following formula:
[0105] n·G=O (3)
[0106] params=(p,a,b,G,n) (4)
[0107] master_key=Random([1,n-1]) (5)
[0108] Where G is the base point on the elliptic curve, n is the order of the base point G, O is the point at infinity, params is the public parameter, and master_key is the system master key, which is only stored in the key generation center;
[0109] 52) The legitimate user submits the identity to the key generation center through the client software. The key generation center uses the user's identity and the master key master_key to calculate the private key. The formula is as follows:
[0110] SK=H(ID)·master_key mod n (6)
[0111] Where SK is the user's private key, and H(ID) is the identity hash value;
[0112] The key generation center securely distributes SK to users, who encrypt and store it on their local devices.
[0113] 53) The key generation center defines the public key generation function. Any entity only needs to know the user identity and public parameters params to calculate the corresponding user public key. The formula is as follows:
[0114] PK=H(ID)·G (7)
[0115] Among them, PK is the public key, which is used for subsequent identity authentication;
[0116] 54) For example, if Alice, the prover, wants to authenticate Bob, the verifier, through Schnorr zero-knowledge proof without leaking any information, she first generates the context using the current timestamp and her own identity identifier, selects a random number, calculates the random point, and then calculates the challenge value based on the context and the random point. Finally, she calculates the response value and constructs the proof. The formula is as follows:
[0117] M=H(T||ID A ) (8)
[0118] R=r·G (9)
[0119] r=Random([1,n-1]) (10)
[0120] c=H(R||M) (11)
[0121] z=r+c·SK A mod n (12)
[0122] π=(R,z) (13)
[0123] Where M is the context, T is the current timestamp, and ID A is the user ID of the prover Alice, H(·) indicates the hash calculation inside the bracket, R is the point on the ellipse, r is the random value, c is the challenge, z is the response, and π is the proof;
[0124] The proving party Alice sends her user ID, current timestamp and proof to the verifying party Bob. The verifying party calculates Alice's public key based on the user ID. The formula is as follows:
[0125] PK A =H(ID A )·G (14)
[0126] Among them PK A is the public key of user Alice;
[0127] The authenticator checks whether the timestamp is within the allowed time window, for example, within 5 minutes. If it times out, the authentication request is rejected.
[0128] The verifier calculates the challenge and verifies whether the following equation holds:
[0129]
[0130] If the equation holds, the authentication succeeds; otherwise, the authentication fails.
[0131] Through the design and implementation of the above zero-knowledge proof, the system effectively ensures the security and privacy of identity authentication without the need to directly transmit user private keys or other sensitive information.
[0132] Step 6: Generate and verify the process identification code during the communication phase;
[0133] During the communication process, the software generates a unique process identification code for each message to ensure that the identification code cannot be reused to effectively prevent forgery and replay attacks. The rules for process identification codes are as follows: Figure 5, with a length of 16 bytes, including 4 bytes of user ID, 8 bytes of timestamp, and 4 bytes of random characters. The random characters consist of two consecutive GBK-encoded Chinese characters. For example, the Chinese characters "独读" corresponding to 0xB6C0 and 0XB6C1. Before sending the message, the sender reads the user ID and fills it into the first 4 bytes of the process identification code, obtains the current system timestamp and fills it into the middle part of the identification code, and generates a 4-byte random character to fill the end of the process identification code. The generated process identification code will be combined with the message to be sent and then sent to the receiver.
[0134] The receiver receives the message, parses the part of the process identification code, and verifies whether the process identification code conforms to the rules, including: whether the user ID matches the current communication object; whether the timestamp is within the allowed gap range with the timestamp of the previous message, such as 5 minutes, to prevent the replay of expired messages; whether the random characters conform to the predefined generation rules.
[0135] The software manages the process identification code in a hierarchical manner: during the valid session, the process identification code is stored in short-term storage for real-time verification of the legality of communication; to meet the auditing requirements and anomaly detection, the software stores all used process identification codes in long-term storage, recording information such as the process identification code, generation time, and associated messages. For example, through auditing, it can be detected whether there are reused or forged process identification codes, providing data support for optimizing communication security policies.
[0136] This embodiment includes generating and managing device identification codes in the device registration stage, applying password security enhancement strategies in the user registration stage, recording and updating timestamps when the user status changes, comparing and verifying device identification codes, passwords, and timestamps in the login stage, identity-based zero-knowledge proof authentication in the authentication stage, and generating and verifying process identification codes in the communication stage. Specifically, it includes: generating a unique device identification code through the SHA3-256 algorithm; salting and hashing the password and storing the obfuscated data in combination with the Argon2id algorithm; recording and dynamically updating timestamps to manage the identity validity period; using multiple mechanisms to verify device identification codes, passwords, and timestamps; based on elliptic curve cryptography technology, using zero-knowledge proof to achieve identity authentication; verifying the legality through process identification codes during the communication process. The present invention combines high efficiency and security, reduces the dependence on the server, and adapts to the identity authentication and communication requirements in a weak network environment.
[0137] Embodiment 2
[0138] Referring to Figure 2 , this embodiment relates to an identity authentication system based on a weak network environment. Located on the client side, it is divided into a registration module, a login module, a communication module, and a storage module. The storage module further includes a database module and a Keystore module. The system is used to implement the identity authentication method for a weak network environment in Embodiment 1.
[0139] Example 3
[0140] Reference Figure 3 This embodiment relates to an identity authentication device based on a weak network environment. It includes a memory and one or more processors, wherein the memory stores executable code, and when the one or more processors execute the executable code, it is used to implement the identity authentication method for a weak network environment of embodiment 1.
[0141] The contents described in the embodiments of this specification are merely enumerations of implementation forms of the inventive concept and are for illustrative purposes only. The protection scope of the present invention should not be considered to be limited to the specific forms described in this embodiment, and the protection scope of the present invention also extends to equivalent technical means that can be thought of by ordinary technicians in this field based on the inventive concept.
Claims
1. An identity authentication method in a weak network environment, characterized in that: The following steps are involved: Step 1: Generate and manage device identification codes during the device registration phase; Step 2: Apply password security enhancement policies during user registration; Step 3: Record and update timestamp when user status changes; Step 4: Compare and verify the device identification code, password and timestamp during the login phase; Step 5: Identity-based zero-knowledge proof authentication in the authentication phase; Step 6: Generate and verify the process identification code during the communication phase.
2. The identity authentication method in a weak network environment according to claim 1, characterized in that: Step 1 includes: 11) During the device registration phase, a unique device identification code is generated based on the device information, specifically including: obtaining the device's hardware feature information, manufacturer information, operating system information, compilation information, and application support information; splicing the hardware feature information, manufacturer information, operating system information, compilation information, and application support information in the format of "hardware feature information: manufacturer information: operating system information: compilation information: application support information" to form a set of device feature data; 12) Using the SHA3-256 algorithm to perform a hash operation on the device feature data to generate an irreversible hash value of the device identification code; 13) The generated hash value of the device identification code is stored in a local database of the device to ensure the integrity of the device identification code.
3. The identity authentication method in a weak network environment according to claim 2, characterized in that: Step 2 includes: During the user registration phase, the user enters a custom password and the password is processed to ensure its security, including: 21) Generate a unique random salt value through a secure random number generator, combine the password entered by the user with the generated salt value, and perform a salted hash operation using the Argon2id algorithm; 22) The generated salt value and the corresponding hash value are arranged in an interleaved order of "one salt, two hashes" and stored in the local database of the device; 23) The software generates multiple pseudo passwords and their corresponding random salt values. After combining the pseudo passwords with the corresponding salt values, the pseudo passwords are processed using the same Argon2id algorithm as the real passwords. The salt values and the generated pseudo password hash values are interleaved in the order of "one salt, two hashes" and stored in the same local database as the real password salt and hash interleaved values to form an obfuscated data set. 24) The software stores an index of the actual password in a separate secure data store.
4. The identity authentication method in a weak network environment according to claim 3, characterized in that: Step 3 includes: 31) When the user registration is completed, the software records the registration timestamp and calculates the expiration timestamp of the user identity validity period, and initializes the expiration flag to a non-expired state; 32) When a legitimate user logs in, the software dynamically extends the identity validity period according to the current time, updates the expiration timestamp, and resets the expiration flag to a non-expired state; 33) When an expired user attempts to log in, the software will update the expiration flag to expired and require the user to re-complete identity authentication to restore the legal identity status; 34) When the user is offline, the software records the offline timestamp; 35) Timestamps and flags are stored in the local database to ensure data persistence and consistency.
5. The identity authentication method in a weak network environment according to claim 4, characterized in that: Step 4 includes: 41) During the login phase, the user enters his / her identity information and clicks the login button. The software then reads the expiration timestamp, offline timestamp, expiration flag, device identification code hash value, and the interleaved value of the salt and hash from the database; 42) Get the current system time of the device and determine whether the current timestamp is less than the expiration timestamp: if the current timestamp is less than the expiration timestamp, it means that the identity is still valid, otherwise it means that the identity authentication has expired, set the expiration flag to expired and refuse login; check whether the offline timestamp is less than the current timestamp: if the offline timestamp is less than the current timestamp, it means that the device time flow is normal, otherwise it means that the device system time has been tampered with and refuse login; 43) Read the current device information, calculate the device identification code, and compare the calculation result with the stored device identification code hash value to confirm the legitimacy of the device; 44) Separate the salt value and the hash value, combine the password entered by the user with the salt value, and calculate the hash value; compare the calculated hash value with the stored hash value to verify the correctness of the password: if the verification is successful, the user successfully logs in; if the verification fails and the wrong password is entered k times, the software triggers the security lock mechanism to limit further login attempts; 45) If the password entered by the user matches the stored pseudo-password hash value, the software will guide the user into a disguised honeypot account environment. The honeypot account environment records the attack behavior by simulating the behavior and data content of the real account, including the entered password, login time, access path, login IP, and operation records.
6. The identity authentication method in a weak network environment according to claim 1, characterized in that: Step 5 includes: 51) The key generation center generates and publishes public parameters, including: selecting elliptic curve parameters to satisfy the following formula: y 2 =x 3 +ax+b mod p (1) 4a 3 +27b 2 ≠0 (2) Where p is a prime number, a and b are elliptic curve parameters, and x and y are points on the elliptic curve; Select the base point and its order, generate global parameters and master key, and satisfy the following formula: n·G=O (3) params=(p,a,b,G,n) (4) master_key=Random([1,n-1]) (5) Where G is the base point on the elliptic curve, n is the order of the base point G, O is the point at infinity, params is the public parameter, and master_key is the system master key; 52) The legitimate user submits the identity to the key generation center through the client software. The key generation center uses the user's identity and the master key master_key to calculate the private key. The formula is as follows: SK=H(ID)·master_key mod n (6) Where SK is the user's private key, and H(ID) is the identity hash value; The key generation center securely distributes SK to users, who encrypt and store it on their local devices. 53) The key generation center defines the public key generation function. Any entity only needs to know the user ID and public parameters params to calculate the corresponding user public key. The formula is as follows: PK=H(ID)·G (7) Among them, PK is the public key, which is used for subsequent identity authentication; 54) The prover authenticates the verifier through Schnorr zero-knowledge proof without leaking any information. This step specifically includes: the prover generates a context based on the current timestamp and identity identifier, and generates a proof using the private key and context. The formula is as follows: M=H(T||ID A ) (8) R=r·G (9) r=Random([1,n-1]) (10) c=H(R||M) (11) z=r+c·SK A mod n (12) π=(R,z) (13) Where M is the context, T is the current timestamp, and ID A is the identifier of the prover, H(·) indicates hashing the contents of the brackets, R is a point on the ellipse, r is a random value, c is the challenge, z is the response, and π is the proof; The prover sends its own identity, current timestamp and proof to the verifier. The verifier calculates the prover's public key based on the user identity. The formula is as follows: PK A =H(ID A )·G (14) Among them PK A is the public key of the proving user; The verifier checks whether the timestamp is within the allowed time window of m minutes, and rejects the request if it times out; The verifier calculates the challenge and verifies whether the following equation holds: If the equation holds true, the proof is valid and the identity authentication is successful.
7. The identity authentication method in a weak network environment according to claim 1, characterized in that: Step 6 includes: During the communication phase, a unique process identification code is generated for each message to verify the legitimacy of the communication; the process identification code consists of a user ID, a timestamp and random characters, wherein the random characters are generated based on predefined rules and are arranged as consecutive GBK encoded characters; the generated process identification code is attached to the message to be sent and transmitted to the receiving end along with the message; after receiving the message, the receiving end verifies the legitimacy of the attached process identification code, specifically checking whether the user ID matches, whether the timestamp is within the predefined valid range, and whether the random characters comply with the generation rules; the software adopts a hierarchical storage strategy for the management of process identification codes: short-term storage is used for real-time verification during the session to ensure the integrity and reliability of the message delivery process; long-term storage is used for post-audit and anomaly detection to provide support for the security and traceability of the software.
8. An identity authentication system in a weak network environment, characterized in that: Located on the client side, including: Registration module, used to generate and manage device identification codes during the device registration phase; Login module, used to apply password security enhancement policies during the user registration phase; Timestamp recording and updating module, used to record and update timestamps when user status changes; The device identification code, password and timestamp verification and comparison module is used to compare and verify the device identification code, password and timestamp during the login phase; Identity authentication module, used for identity-based zero-knowledge proof authentication in the authentication phase; The process identification code generation and verification module is used to generate and verify the process identification code during the communication phase.
9. An identity authentication device in a weak network environment, characterized in that: It includes a memory and one or more processors, wherein the memory stores executable code, and when the one or more processors execute the executable code, it is used to implement the identity authentication method in a weak network environment described in any one of claims 1-7.
Citation Information
Patent Citations
Certificateless multi-factor zero-knowledge certification authentication method based on elliptic curve
CN116170145A
Data transmission method and system in Internet of Things
CN116614239A
Mobile terminal equipment credibility authentication method and system based on Internet of Things
CN118631570A
Multi-factor authentication method based on homomorphic encryption
CN118740365A
Password mutual authentication system and method for u-healthcare environment
KR1020150069416A