Privacy protection autonomous identity management system and method based on block chain under scene of Internet of Things

By designing a blockchain-based privacy protection autonomous identity management system in the Internet of Things scenario, the challenges of traditional identity management systems in terms of security and limited resources are solved, and efficient privacy protection and identity management are achieved.

CN119995887APending Publication Date: 2025-05-13Chinese People's Liberation Army Cyberspace Force Information Engineering University

Patent Information

Application Number
CN202411636338.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-15
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the Internet of Things scenario, traditional identity management systems have challenges in ensuring security and adapting to limited equipment resources, especially the weak privacy protection mechanism and the incomplete identity tracking and revocation mechanism.

Method used

A blockchain-based privacy protection autonomous identity management system is designed to store public-private key pairs and attribute information of autonomous identity locally through IoT devices, and the identity issuer generates multiple unrelated anonymous identities based on a one-way hash chain, and selectively discloses and protects the correlation of identity statements through Merkle tree structure.

Benefits of technology

Decentralized authentication is realized, the portability and privacy protection capabilities of device identity are improved, the privacy of device attribute information and behavior is ensured, and the needs of device privacy protection, non-linkability, traceability and revocation are met.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995887A_ABST
    Figure CN119995887A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of block chain application, in particular to a privacy protection autonomous identity management system and method based on a block chain in an Internet of Things scene, each identity issuer and an identity verification party form an alliance chain, the identity issuer generates system parameters and registers, uploads and revokes an equipment identity, and the identity verification party verifies the equipment identity. The verification party retrieves equipment identity verification and revocation information uploaded to the block chain by the issuer, and constructs a distributed management framework of the Internet of Things equipment identity based on the block chain; an identity issuer generates a plurality of unassociated anonymous identities for equipment based on a one-way hash chain, privacy protection certificateless signature is realized, and one-time anonymous identities are added into leaf nodes based on a Merkle Tree structure to generate verifiable declarations so as to protect association among a plurality of verifiable declarations of the equipment and realize attribute selective disclosure; and the on-chain node realizes management of device identity registration, authentication, tracking and revocation and updating of a full life cycle by using an intelligent contract. According to the invention, the privacy requirement of the Internet of Things equipment can be met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of blockchain application technology, and in particular to a privacy protection autonomous identity management system and method based on blockchain in an Internet of Things scenario. Background Art

[0002] As a new direction of the development of interconnected technology, the Internet of Things (IoT) has greatly promoted the development of smart homes, smart medical care, industrial IoT and other fields. IoT applications have penetrated into all aspects of people's lives and brought great changes to people's production and life. Hundreds of millions of IoT terminal devices and network services constitute a complex IoT network, and digital identity, as the basis of network services, promotes the connection and communication of various entities in IoT. Authentication, access control and data sharing are all based on digital identity. It can be seen that IoT device identity management has become one of the urgent and core tasks today.

[0003] However, the rapid increase in the number of IoT terminal devices has also increased the difficulty of identity management. At present, most identity management systems, such as Kerberos, SAML, OpenID, etc., adopt the traditional identity management model. According to different system architectures, the traditional identity management model can be divided into independent identity management, federated identity management and centralized identity management, but with the promotion of such solutions, their limitations are gradually exposed. Traditional identity management systems all need to centrally store identity information, which is prone to sensitive information leakage and is not conducive to privacy protection. In addition, the storage of identity data at the identity provider causes the device to lose ownership and control of the identity. In short, the traditional identity management model seems to be inadequate in the IoT environment, and it is necessary to seek a more complete identity management method to meet the needs of device information privacy protection and identity self-management.

[0004] Christopher Allen first proposed self-sovereign identity in 2016. Its core is to transfer the control of identity from the identity provider to the user itself, so that the user can fully control the use of identity. In recent years, the rapid development and application of blockchain technology, which uses the underlying distributed architecture, consensus mechanism and cryptographic algorithm as support, has the characteristics of openness, transparency, decentralization and immutability. Decentralized storage and verification can be achieved based on blockchain technology. Blockchain technology provides technical support for the implementation of self-sovereign identity. Self-sovereign identity based on blockchain has become a new paradigm in the field of identity management, but it still faces some challenges. Considering the identity management in the IoT scenario, designing a practical and efficient identity management method mainly faces the following difficulties: on the one hand, the security of the identity management method is difficult to guarantee, the privacy protection mechanism of the device is weak, the identity tracking and revocation mechanism is imperfect, and the cryptographic algorithm relied on by the method has security vulnerabilities, which will affect the security of the system. On the other hand, the computing and storage resources of IoT devices are limited, and some complex identity management methods are not suitable for IoT scenarios, even if they have good security. For this reason, there is an urgent need for a method that can realize the identity management of IoT devices without affecting security and efficiency, so as to expand its actual application scenarios in the IoT. Summary of the invention

[0005] To this end, the present invention provides a privacy-preserving autonomous identity management system and method based on blockchain in an Internet of Things scenario, which solves the problems that the security of existing identity management methods in Internet of Things scenarios is difficult to ensure, and some complex identity management methods are not suitable for Internet of Things devices with limited computing and storage resources.

[0006] According to the design scheme provided by the present invention, on the one hand, a privacy protection autonomous identity management system based on blockchain in an Internet of Things scenario is provided, comprising:

[0007] An IoT device, wherein the IoT device has multiple unrelated self-determined identities and stores public and private key pairs and attribute information of the self-determined identities locally on the device, wherein the self-determined identities include the real identity of the device and several anonymous identities that are used only once, and the anonymous identities are obtained based on seeds;

[0008] The identity issuer, as a trusted entity, generates multiple unrelated anonymous identities for IoT devices based on a one-way hash chain, and issues a unified identity identifier and verifiable declaration of attribute information for IoT devices. Each identity issuer and the identity verification party form a joint chain and store the verification information on the chain;

[0009] The identity verification party verifies the legitimacy of the IoT device identity based on the information on the chain, and provides services to IoT devices that have passed the identity verification.

[0010] The identity issuer supervises the identity of IoT devices, evaluates the device reputation based on the behavior of IoT devices, and tracks the real identity of malicious IoT devices whose device reputation is below the preset threshold and revokes their identity.

[0011] The privacy protection autonomous identity management system based on blockchain in the Internet of Things scenario of the present invention further comprises the following steps: the identity issuer obtains the attributes of the Internet of Things device and the anonymous identity, organizes the attributes of the Internet of Things device and the anonymous identity into a Merkle tree structure and signs the Merkle tree root, and the signature is a verifiable statement of the Internet of Things device, so as to selectively disclose the attributes of the Internet of Things device by using the verifiable statement and protect the association between multiple verifiable statements of the Internet of Things device.

[0012] As a privacy-preserving autonomous identity management system based on blockchain in the IoT scenario of the present invention, further, the identity verification party reconstructs the Merkle tree based on the required verification attributes and verifiable signature sent by the IoT device, and verifies the IoT device attribute information based on the verifiable signature.

[0013] In another aspect, the present invention further provides a privacy protection autonomous identity management method based on blockchain in an Internet of Things scenario, which is implemented based on the above system, and the implementation process includes:

[0014] The identity issuers and identity authentication parties of each organization serve as nodes and together form a consortium chain. IoT devices send registration requests to the identity issuers.

[0015] The identity issuer generates multiple unrelated anonymous identities for IoT devices based on a one-way hash chain, adds the anonymous identities as leaf nodes to the Merkle tree structure and generates verifiable statements, uploads the verifiable information of registered IoT devices to the blockchain, and stores private information locally on the IoT devices, including the public and private key pairs and attribute information of the device's autonomous identity;

[0016] In response to IoT device identity authentication requests, the identity authentication party obtains the anonymous identity that the IoT device needs to verify and the verifiable credential corresponding to the anonymous identity, verifies the qualifications of the verifiable credential based on the on-chain information, and revokes the IoT device identity based on the revocation list.

[0017] As a privacy protection autonomous identity management method based on blockchain in the IoT scenario of the present invention, further, the identity issuer generates multiple unrelated anonymous identities for the IoT device based on a one-way hash chain, including:

[0018] The IoT device selects several random numbers, uses one of the random numbers as a long-term private key, and uses the random number as a temporary private key. It generates an interaction request with the identity issuer based on the generator in the elliptic curve group and using the random number.

[0019] Based on the interactive request, the identity issuer generates an anonymous identity for the IoT device with the same number of temporary keys using a privacy-preserving certificateless signature algorithm, and sends the anonymous identity to the IoT device through a secure channel.

[0020] As a privacy protection autonomous identity management method based on blockchain in the Internet of Things scenario of the present invention, further, the anonymous identity is added as a leaf node to the Merkle tree structure and a verifiable statement is generated, which also includes:

[0021] The IoT device uses the private key to obtain the anonymous identity signature based on the elliptic curve Schnorr signature algorithm, combines the anonymous identity signature with the anonymous identity to generate a credential application and sends it to the identity issuer;

[0022] The identity issuer checks whether the anonymous identity in the credential application is on the revocation list. If the anonymous identity is not on the revocation list, the anonymous identity signature is verified. If the verification is successful, the seed element of the IoT device is accumulated based on the anonymous identity and a witness is generated. The anonymous identity, witness, version number and seed element accumulation result are used to obtain the identity authentication credential, and the identity authentication credential is sent to the IoT device through a secure channel. If the verification fails, the credential application is rejected.

[0023] As a privacy protection autonomous identity management method based on blockchain in the IoT scenario of the present invention, further, the qualification of the verifiable credentials is verified based on the information on the chain, including:

[0024] The authentication party checks whether the anonymous identity is in the revocation list for the authentication request sent by the IoT device with an anonymous identity. If not, the identity credential is decrypted and the identity contained in the identity credential is checked to see if it is consistent with the anonymous identity in the authentication request. If they are consistent, the authentication is successful, otherwise, the authentication fails.

[0025] As a privacy protection autonomous identity management method based on blockchain in the IoT scenario of the present invention, further, the IoT device identity is revoked based on a revocation list, including:

[0026] The identity authentication party broadcasts the IoT device identity that has completed qualification verification, so that the on-chain nodes store the broadcasted IoT device identity in the local revocation list to revoke the IoT device identity using the local revocation list.

[0027] As a privacy protection autonomous identity management method based on blockchain in the IoT scenario of the present invention, further, the IoT device identity is revoked based on a revocation list, including:

[0028] For malicious IoT devices, the identity issuer broadcasts the seed selected when generating all anonymous identities of the IoT device, so that the on-chain nodes can obtain all anonymous identities of the IoT device based on the seed and record them in the local revocation list, so as to revoke the identity of the malicious IoT device using the local revocation list.

[0029] As a privacy protection autonomous identity management method based on blockchain in the IoT scenario of the present invention, further, revocation management of IoT device identities is performed based on a revocation list, and further includes:

[0030] The anonymous identity of the IoT device is stored in the anonymous identity pool, and the anonymous identity in the anonymous identity pool is updated according to the identity revocation operation;

[0031] If the number of anonymous identities remaining in the anonymous identity pool of the IoT device does not reach the preset threshold, the process of the IoT device reapplying for an anonymous identity from the identity issuer is triggered.

[0032] Beneficial effects of the present invention:

[0033] The present invention realizes decentralized authentication based on the distributed storage architecture of blockchain, gets rid of the disadvantages of centralized storage in traditional methods. The device only needs to register once to access multiple services, which improves the portability of device identity. The signature algorithm can hide the true identity of the device without complex bilinear operations, and is suitable for Internet of Things scenarios. The attribute selective disclosure mechanism effectively prevents attackers from linking the behavior of devices through anonymous identity identification or verifiable statements, builds a complete device feature portrait, better protects the attribute information and behavior privacy of the device, and makes the autonomous identity management process meet the characteristics of device privacy protection, unlinkability, traceability and revocability, and realizes identity registration, authentication, tracking and revocation, and update management throughout the entire life cycle. It can be applied to identity management scenarios in the Internet of Things environment and can meet the privacy requirements of Internet of Things devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 This is a schematic diagram of the architecture of a privacy-preserving autonomous identity management system based on blockchain in an IoT scenario in an embodiment;

[0035] Figure 2 The figure is a schematic diagram of the process of generating a verifiable claim in an embodiment. DETAILED DESCRIPTION

[0036] In order to make the purpose, technical solutions and advantages of the present invention clearer and more understandable, the present invention is further described in detail below in conjunction with the accompanying drawings and technical solutions.

[0037] In view of the problems that the traditional identity management model has single point failure, poor device identity portability and easy leakage of device privacy, the certificateless signature algorithm cannot protect device privacy and is vulnerable to attack, and the device lacks identity control and is easy to leak device identity privacy in the traditional identity management, the embodiment of the present invention provides a privacy protection autonomous identity management system based on blockchain in the Internet of Things scenario, including:

[0038] An IoT device, wherein the IoT device has multiple unrelated self-determined identities and stores public and private key pairs and attribute information of the self-determined identities locally on the device, wherein the self-determined identities include the real identity of the device and several anonymous identities that are used only once, and the anonymous identities are obtained based on seeds;

[0039] The identity issuer, as a trusted entity, generates multiple unrelated anonymous identities for IoT devices based on a one-way hash chain, and issues a unified identity identifier and verifiable declaration of attribute information for IoT devices. Each identity issuer and the identity verification party form a joint chain and store the verification information on the chain;

[0040] The identity verification party verifies the legitimacy of the IoT device identity based on the information on the chain, and provides services to IoT devices that have passed the identity verification.

[0041] The identity issuer supervises the identity of IoT devices, evaluates the device reputation based on the behavior of IoT devices, and tracks the real identity of malicious IoT devices whose device reputation is below the preset threshold and revokes their identity.

[0042] like Figure 1 As shown in the figure, the IoT device DE can have multiple unrelated autonomous identities at the same time. The device locally stores the public and private key pairs and attribute information of the autonomous identity, and selectively discloses them to the verifier to complete the identity authentication. The identity issuer, as a trusted entity, such as an enterprise or hospital, issues a verifiable statement of a unified identity identifier and attribute information for the device, and uploads the verification information to the blockchain for identity authentication. In addition, the identity issuer can implement supervision functions on malicious devices, track the real identity of malicious devices and revoke them. The identity verification party (Verifier) ​​verifies the legitimacy of the identity through the information on the chain and provides services for the verified devices. The blockchain is a distributed ledger. The issuer uploads its public key and dynamic accumulated value, and the verifier retrieves and uses the information on the chain. By deploying the Register_SC, Query_SC and Revoke_SC smart contracts, the device identity registration, authentication, tracking and revocation, and update management of the entire life cycle are realized.

[0043] Based on the above system, an embodiment of the present invention further provides a privacy protection autonomous identity management method based on blockchain in an Internet of Things scenario, including:

[0044] The identity issuers and identity authentication parties of each organization serve as nodes and together form a consortium chain. IoT devices send registration requests to the identity issuers.

[0045] The identity issuer generates multiple unrelated anonymous identities for IoT devices based on a one-way hash chain, adds the anonymous identities as leaf nodes to the Merkle tree structure and generates verifiable statements, uploads the verifiable information of registered IoT devices to the blockchain, and stores private information locally on the IoT devices, including the public and private key pairs and attribute information of the device's autonomous identity;

[0046] In response to IoT device identity authentication requests, the identity authentication party obtains the anonymous identity that the IoT device needs to verify and the verifiable credential corresponding to the anonymous identity, verifies the qualifications of the verifiable credential based on the on-chain information, and revokes the IoT device identity based on the revocation list.

[0047] like Figure 1 The system architecture shown, the overall workflow may include: system initialization, Verifier registration, registration, anonymous identity credential generation, identity authentication, attribute selective disclosure, anonymous identity revocation and update.

[0048] 1) System initialization: Issuer performs system initialization, given a security parameter, generates a set of system parameters and publishes the public parameters on the blockchain.

[0049] 2) Verifier registration: This step is carried out between the Issuer and the Verifier, and the Issuer generates a public-private key pair for the Verifier.

[0050] 3)DE Registration

[0051] 3-1) Issuer generates an anonymous identity and a corresponding part of the public and private key pair for DE;

[0052] 3-2) Issuer uploads the device authentication information generated based on dynamic accumulator technology to the blockchain.

[0053] 4) Anonymous identity credential generation: Issuer generates a corresponding identity credential for an anonymous identity of DE.

[0054] Authentication

[0055] 4-1) Verifier retrieves device verification information on the chain;

[0056] 4-2) Verifier verifies identity credentials based on dynamic accumulator technology.

[0057] 5) Selective disclosure of attributes: Issuer adds a one-time anonymous identity to the leaf node of the Merkle Tree to generate a verifiable statement for DE to achieve selective disclosure of attributes and protect the association between multiple verifiable statements of the device.

[0058] 6) Revocation and update of anonymous identities: The revocation part is divided into normal revocation and revocation of malicious devices. The anonymous identities that have completed authentication are revoked in the form of a revocation list, and the anonymous identity generation parameters of malicious devices are broadcast on the chain to revoke all their anonymous identities. When there are not many identities left in the anonymous identity pool, you can reapply for an anonymous identity from the Issuer.

[0059] Combining the principle of autonomous identity and the need for privacy protection, this solution can achieve decentralized storage and get rid of the reliance on central authorities in the traditional identity management model. Device information can only be accessed with the permission of the device, and the device can autonomously control the disclosure of identity information. The identity issuer can track the real identity of malicious devices and revoke them. Attackers cannot obtain system services by impersonating other entities, ensuring system security. The identity management method can protect the real identity of the device and comply with the principle of minimum disclosure of attributes. At the same time, effective measures can be taken to prevent the behavior of devices from being linked through anonymous identity identification or identity credentials to achieve the purpose of privacy protection.

[0060] Among them, the identity issuer generates multiple unrelated anonymous identities for IoT devices based on a one-way hash chain, which may include:

[0061] The IoT device selects several random numbers, uses one of the random numbers as a long-term private key, and uses the random number as a temporary private key. It generates an interaction request with the identity issuer based on the generator in the elliptic curve group and using the random number.

[0062] Based on the interactive request, the identity issuer generates an anonymous identity for the IoT device with the same number of temporary keys using a privacy-preserving certificateless signature algorithm, and sends the anonymous identity to the IoT device through a secure channel.

[0063] The IoT device uses the elliptic curve Schnorr signature algorithm and the private key to obtain the anonymous identity signature, combines the anonymous identity signature with the anonymous identity to generate a credential application and sends it to the identity issuer; the identity issuer checks whether the anonymous identity in the credential application is on the revocation list. If the anonymous identity is not on the revocation list, the anonymous identity signature is verified. If the verification is successful, the seed element of the IoT device is accumulated based on the anonymous identity and a witness is generated. The anonymous identity, witness, version number and seed element accumulation result are used to obtain the identity authentication credential, and the identity authentication credential is sent to the IoT device through a secure channel. If the verification fails, the credential application is rejected.

[0064] The authentication party checks whether the anonymous identity is in the revocation list for the authentication request sent by the IoT device with an anonymous identity. If not, the identity credential is decrypted and the identity contained in the identity credential is checked to see if it is consistent with the anonymous identity in the authentication request. If they are consistent, the authentication is successful, otherwise, the authentication fails.

[0065] The identity authentication party broadcasts the IoT device identity that has completed qualification verification, so that the on-chain nodes store the broadcasted IoT device identity in the local revocation list to revoke the IoT device identity using the local revocation list.

[0066] For malicious IoT devices, the identity issuer broadcasts the seed selected when generating all anonymous identities of the IoT device, so that the on-chain nodes can obtain all anonymous identities of the IoT device based on the seed and record them in the local revocation list, so as to revoke the identity of the malicious IoT device using the local revocation list.

[0067] The anonymous identity of the IoT device can be stored in the anonymous identity pool, and the anonymous identity in the anonymous identity pool can be updated according to the identity revocation operation; if the number of anonymous identities remaining in the anonymous identity pool of the IoT device does not reach the preset threshold, the process of the IoT device reapplying for an anonymous identity from the identity issuer is triggered.

[0068] In this embodiment, the privacy-preserving certificateless signature algorithm is used to realize anonymous identity generation and signature. The privacy-preserving certificateless signature algorithm mainly consists of the following eight parts:

[0069] 1) Setup: System initialization is completed by each identity issuer. Taking issuer I1 as an example, I1 selects a large prime number q with a length greater than k, where k is a security parameter. G is an elliptic curve group of order q, and P is its generator.

[0070] is a secure hash function. Randomly selected And calculate the public key Ipub1=s1P, where the master key Isk1=s1 is kept secret. Release the public parameters params=(q,G,P,Ipub1,H1,H2).

[0071] 2) Set the secret value (SetSecValue): Identity is ID U1 Device DE1 randomly selects m+1 random numbers As a way to generate long-term private keys and m A temporary private key, DE1 calculates X 1k =x 1k P, sends {ID U1 ,X 10 ,X 11 ,…,X1m}.

[0072] 3) Generate anonymous identity (PseudoIdGen): I1 selects two random seeds SD U1 and SD U2 , m anonymous identities are generated by the two one-way hash chains in formula (1) And send it to DE1 through a secure channel.

[0073]

[0074] This method can generate multiple unrelated anonymous identities, and for any anonymous identity, I1 can use the private key to restore the real identity of the device and realize the function of tracing malicious devices.

[0075] 4) Generate partial private key (PartialPskGen): For anonymous identity I1 Random Selection calculate Generate a partial private key Will It is sent to DE1 through a secure channel. DE1 can verify Is it established to verify The partial private key of the real identity is generated in the same way.

[0076] 5) Generate a complete private key (SetSecKey): DE1 settings The complete private key is

[0077] 6) Generate a complete public key (SetPubKey): DE1 settings The complete public key is

[0078] 7) Signature: DE1 is based on anonymous identity For message M∈{0,1} * The signature is as follows: Randomly select Calculate β1=w1P, γ=H1(β1||M), Output

[0079] Verify signature: I1 receives a message from DE1 After that, calculate γ'=H1(β1||M), Verify whether η1P=β1+γ'δ holds.

[0080] In the attribute selective disclosure mechanism, the Issuer obtains the attributes of the IoT device {a1, a2, …, a n}, and issue verifiable claims for these attributes to prove their authenticity. The specific method is as follows: I1 organizes the attributes and anonymous identities into the form of a Merkel Tree, signs the calculated Merkel root, and the resulting signature is the verifiable claim of the attribute. These verifiable claims are stored locally by DE1. The anonymity contained in the leaf nodes of the Merkel Tree ensures that the verifiable claims of different anonymous identities of the same device cannot be linked.

[0081] To meet the minimum disclosure principle, DE only needs to send the required attribute values ​​and hash values ​​of other attributes to Verifier, as follows: Figure 2 For example, when attr3 needs to be verified, the device will H(L), attr3 and verifiable claims The verifier reconstructs the Merkel Tree based on the above information. Complete device attribute verification. A one-time anonymous identity is added to the leaf node of the Merkle Tree to generate a verifiable statement for DE. From the generation process of the verifiable statement, it can be seen that this mechanism realizes the selective disclosure of attributes and protects the association between multiple verifiable statements of the device. Attackers cannot collect the attributes disclosed by the device in different sessions and build a complete device attribute feature.

[0082] In the embodiment of this case, privacy-preserving autonomous identity management based on blockchain is implemented, device registration and verification are achieved through a privacy-preserving certificateless signature algorithm, and identity credentials are issued to devices that have passed the verification; at the same time, dynamic accumulator technology is introduced to achieve membership authentication and reduce on-chain storage overhead; finally, sensitive attributes of the device are protected based on the attribute selective disclosure mechanism.

[0083] The blockchain-based privacy-preserving self-sovereign identity management algorithm can be composed of the following six parts:

[0084] (1) System initialization

[0085] The system is initialized by each identity issuer. Taking I1 as an example, I1 selects a security parameter k and outputs I1’s public parameters (p1, q, G1, G T1 ,G,e1,g1,pk acc ,P,Ipub1,H1,H2), where the bilinear map e1:G1×G1→G T1 , g1 is the generator of group G1, and the large prime number p1 is the sum of groups G1 and G T1The order of the dynamic accumulator public and private key pair The tuple (q, G, P, H1, H2) is the unified parameter pre-selected by each identity issuer, where the order of a generator P of the elliptic curve group G is is a large prime number with a length greater than k, the private key of I1 Public key Ipub1 = s1P, A secure hash function.

[0086] To initialize the blockchain, I1 will accumulate value transactions Published on the blockchain, where did I1 is the identifier of I1, v is the version number, This is the signature of I1 to ATX.

[0087] (2) Identity verification party registration

[0088] Assume that at this stage, Issuer and Verifier use a secure channel to transmit secret data. The following takes the registration of Verifier V1 as an example to introduce the registration process. V1 sends its real identity ID V1 Request registration to I1, I1 checks whether the device has been registered, if it has been registered, stop registration, otherwise do the following: Randomly select Calculate R V1 =r V1 P, private key Vsk1 = r V1 +H1(ID V1 ||R V1 )·s1, public key Vpub1=Vsk1·P, I1 will {R V1 ,Vsk1,Vpub1} to V1. After receiving the message, V1 verifies R V1 +H1(ID V1 ||R V1 )Is Ipub1 = Vpub1 true? If so, save the private key locally and make the public key public; otherwise, reapply.

[0089] (3) System initialization

[0090] At this stage, Issuer generates multiple anonymous identities for DE and uses a certificateless cryptographic algorithm to generate a public-private key pair for each anonymous identity to ensure DE's control over the identity. Afterwards, the device authentication information is uploaded to the blockchain in combination with the dynamic accumulator. Taking I1 as DE1 registration as an example, the registration process is as follows:

[0091] According to the privacy protection certificateless signature algorithm, the real identity is ID U1 Device DE1 interacts with I1 to obtain an anonymous identity j∈[1,m] and its corresponding complete private key With public key In order to track the real identity of the malicious device and update the anonymous identity of the device, (ID U1 ,P U1 ,SD U1 ,SD U2 ) is saved in the local database, where SD U1 and SD U2 A random seed for generating an anonymous device identity.

[0092] I1 calculates the accumulated element β of the device U1 =H1(ID U1 ||SD U1 ||SD U2 ), call the Register_SC smart contract to calculate the new accumulated value In order to U1 Recorded in the accumulation set. I1 trades the new accumulation value Broadcast to blockchain nodes, and after consensus is reached using the Byzantine Fault Tolerance (PBFT) algorithm, the transaction will be saved in the blockchain ledger. v' is the updated version number. The signature of I1 on the accumulated value transaction. Compared with directly storing all the anonymous information of the device, accumulating the identity information of the device into one value can effectively reduce the storage overhead on the chain.

[0093]

[0094] (4) Anonymous identity credential generation

[0095] To pass the authentication of the authentication party, the IoT device needs to obtain the authentication credentials of the anonymous identity from the Issuer in advance. i For example, DE1 sends an anonymous identity to identity provider I1. Application for certificate in is the public key corresponding to the anonymous identity, Utilize private key for device based on elliptic curve Schnorr signature algorithm get The specific calculation method is as follows: DE1 randomly selects Calculate β1=w1P,

[0096] After receiving the identity credential request, I1 checks the identity Is it in the revocation list? If not, verify the signature. The specific verification method is as follows: Calculate Verify whether η1P=β1+γ'δ holds. If the verification fails, the request is rejected; otherwise, calculate Accumulate element β U1 =H1(ID U1 ||SD U1 ||SD U2 ), generate a witness Compute authentication credentials in v is the version number, Vpub i For authentication party V i and returns the authentication credential to DE1.

[0097] (5) Identity verification

[0098] DE1 anonymous To V i Sending an authentication request in is the public key corresponding to the identity, did I1 is the identity identifier of the identity provider I1, s 1,j is the message hash value. i Check identity Is it in the revocation list? If not, decrypt the identity certificate μ, check whether the identity contained in the certificate is consistent with the verification request, check the hash value to verify the message integrity, and then check the identity certificate to verify the identity of the verification request. I1 and the version number in the identity certificate v , call Algorithm 2 to retrieve I1's information on the chain and verify Is it true? If so, it means that the accumulated element of DE1 is in the accumulated set and the authentication is successful; otherwise, the authentication fails.

[0099]

[0100] (6) Revoking and updating anonymous identity

[0101] 1) Normal cancellation

[0102] Revoking Anonymity with V1 For example, when V1 is After completing identity authentication, broadcast the cancellation transaction on the chain The node on the chain will pid 1,j,1 Save the revocation list locally.

[0103] Each anonymous identity is used only once, which helps to achieve the unlinkability of device behavior. 1,j,1 Generated by two seeds, just need to pid 1,j,1 Anonymous identities can be revoked by saving to a local revocation list Compared to preserving the complete anonymous identity (pid 1,j,1 ,pid 1,j,2 ), reducing storage overhead.

[0104] 2) Revoking the identity of malicious devices

[0105] The device reputation value can be calculated based on the device's behavior or by evaluating the information provided by the device. When the reputation value is lower than a predetermined threshold, the device is determined to be a malicious device. For example, when I1 discovers the anonymous identity When malicious behavior occurs, Get the real identity and query the local database to obtain the seed SD of the device U1 , SD U2 , calculate the corresponding cumulative element, and call contract algorithm 3 to calculate the new cumulative value The updated accumulated value will be traded Write it into the blockchain ledger. Other nodes will use the SD in ATX' U1 and SD U2 As the parameters of formula (1), all anonymous identities of malicious devices are calculated and added to the revocation list. During the revocation process, only the new accumulated value and seed need to be uploaded to revoke all anonymous identities of malicious devices, which reduces the communication overhead.

[0106]

[0107] 3) Anonymous identity update

[0108] When the number of identities left in the anonymous identity pool of device DE1 does not exceed L (L is a pre-defined threshold), the device can re-apply for an anonymous identity from I1. The process is similar to that of DE1 registration, but the registration request is encrypted with I1's public key. I1 decrypts the message after receiving it, and uses X based on elliptic curve cryptography to obtain the anonymous identity. 10 Send the generated anonymous encryption to DE1.

[0109] To verify the effectiveness of this solution, the following is a further explanation based on the security theory analysis:

[0110] (1) Privacy protection

[0111] The solution in this case protects device privacy from multiple aspects (anonymity, selective disclosure of attributes, anonymous identity identifiers, and unlinkability of verifiable statements): ① During the use of the identity, the anonymous identity hides the true identity of the device, and any entity other than the identity issuer cannot restore the true identity of the device. ② Based on the Merkle Tree method, the principle of minimum disclosure is met when providing attributes to the verifier. ③ Use a one-way hash chain to generate multiple unrelated anonymous identities for the device, and generate verifiable statements by adding a one-time anonymous identity to the leaf node of the Merkle Tree to hide the association between multiple statements of the device. According to the anonymous identity and verifiable statement generation process, it can be seen that the solution in this case can effectively prevent attackers from linking the behavior of devices through anonymous identity identifiers or verifiable statements to build a complete device feature portrait.

[0112] (2) Other attributes

[0113] 1) Decentralization: This system implements decentralized authentication based on the distributed storage architecture of blockchain, getting rid of the drawbacks of centralized storage in traditional methods. In this solution, authentication information and revocation transactions are stored on the chain, while the real identity and attributes of the device are stored locally by the device, and the device information will not be leaked.

[0114] 2) System scalability: The verifier completes membership authentication by looking up the accumulated value on the chain. Authentication does not rely on a central authority. Compared with traditional identity management methods, this solution is more suitable for large-scale identity management and authentication. In addition, devices only need to register once to access multiple services, which improves the portability of device identities.

[0115] 3) Identity control: In this solution, the device identity and attribute information are securely stored by the device itself. The device can control the creation, use and update of the identity, hide the real identity and selectively disclose attribute information. Other entities can access the device attributes only after obtaining permission from the device.

[0116] 4) Supervisory control: Although the solution in this case generates multiple anonymous identities for the device to protect the privacy of the device, for malicious devices that damage the system security, the identity issuer can use its own private key to restore the real identity of the device and revoke all anonymous identities of the device for punishment.

[0117] Based on the above analysis, it can be shown that this solution can strengthen the privacy protection of IoT devices from multiple aspects. At the same time, the authoritative agency can exercise regulatory power to track and revoke the identity of anonymous malicious devices. It has good application prospects in the field of anomaly detection of IoT devices.

[0118] Unless otherwise specifically stated, the relative steps, numerical expressions and values ​​of the components and steps set forth in these embodiments do not limit the scope of the present invention.

[0119] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the system disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0120] The units and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. A person of ordinary skill in the art may use different methods to implement the described functions for each specific application, but such implementation is not considered to be beyond the scope of the present invention.

[0121] Finally, it should be noted that the above-described embodiments are only specific implementations of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The protection scope of the present invention is not limited thereto. Although the present invention is described in detail with reference to the above-described embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-described embodiments within the technical scope disclosed by the present invention, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A privacy-preserving autonomous identity management system based on blockchain in the Internet of Things scenario, characterized in that: Include: An IoT device, wherein the IoT device has multiple unrelated self-determined identities and stores public and private key pairs and attribute information of the self-determined identities locally on the device, wherein the self-determined identities include the real identity of the device and several anonymous identities that are used only once, and the anonymous identities are obtained based on seeds; The identity issuer, as a trusted entity, generates multiple unrelated anonymous identities for IoT devices based on a one-way hash chain, and issues a unified identity identifier and verifiable declaration of attribute information for IoT devices. Each identity issuer and the identity verification party form a joint chain and store the verification information on the chain; The identity verification party verifies the legitimacy of the IoT device identity based on the information on the chain, and provides services to IoT devices that have passed the identity verification. The identity issuer supervises the identity of IoT devices, evaluates the device reputation based on the behavior of IoT devices, and tracks the real identity of malicious IoT devices whose device reputation is below the preset threshold and revokes their identity.

2. According to claim 1, the privacy protection autonomous identity management system based on blockchain in the Internet of Things scenario is characterized in that: The identity issuer obtains the IoT device attributes and anonymous identity, organizes the IoT device attributes and anonymous identity into a Merkle tree structure and signs the Merkle tree root. The signature is a verifiable statement of the IoT device, so as to selectively disclose the IoT device attributes using the verifiable statement and protect the association between multiple verifiable statements of the IoT device.

3. The privacy protection autonomous identity management system based on blockchain in the Internet of Things scenario according to claim 2 is characterized in that: The identity verification party rebuilds the Merkle tree based on the required verification attributes and verifiable signature sent by the IoT device, and verifies the IoT device attribute information based on the verifiable signature.

4. A privacy-preserving autonomous identity management method based on blockchain in an Internet of Things scenario, characterized in that: Based on the system implementation described in claim 1, the implementation process includes the following contents: The identity issuers and identity authentication parties of each organization serve as nodes and together form a consortium chain. IoT devices send registration requests to the identity issuers. The identity issuer generates multiple unrelated anonymous identities for IoT devices based on a one-way hash chain, adds the anonymous identities as leaf nodes to the Merkle tree structure and generates verifiable statements, uploads the verifiable information of registered IoT devices to the blockchain, and stores private information locally on the IoT devices, including the public and private key pairs and attribute information of the device's autonomous identity; In response to IoT device identity authentication requests, the identity authentication party obtains the anonymous identity that the IoT device needs to verify and the verifiable credential corresponding to the anonymous identity, verifies the qualifications of the verifiable credential based on the on-chain information, and revokes the IoT device identity based on the revocation list.

5. The privacy protection autonomous identity management method based on blockchain in the Internet of Things scenario according to claim 4 is characterized in that: The identity issuer generates multiple unrelated anonymous identities for IoT devices based on a one-way hash chain, including: The IoT device selects several random numbers, uses one of the random numbers as a long-term private key, and uses the random number as a temporary private key. It generates an interaction request with the identity issuer based on the generator in the elliptic curve group and using the random number. Based on the interactive request, the identity issuer generates an anonymous identity for the IoT device with the same number of temporary keys using a privacy-preserving certificateless signature algorithm, and sends the anonymous identity to the IoT device through a secure channel.

6. The privacy protection autonomous identity management method based on blockchain in the Internet of Things scenario according to claim 4 is characterized in that: Add the anonymous identity as a leaf node to the Merkle tree structure and generate a verifiable statement, which also includes: The IoT device uses the private key to obtain the anonymous identity signature based on the elliptic curve Schnorr signature algorithm, combines the anonymous identity signature with the anonymous identity to generate a credential application and sends it to the identity issuer; The identity issuer checks whether the anonymous identity in the credential application is on the revocation list. If the anonymous identity is not on the revocation list, the anonymous identity signature is verified. If the verification is successful, the seed element of the IoT device is accumulated based on the anonymous identity and a witness is generated. The anonymous identity, witness, version number and seed element accumulation result are used to obtain the identity authentication credential, and the identity authentication credential is sent to the IoT device through a secure channel. If the verification fails, the credential application is rejected.

7. The privacy protection autonomous identity management method based on blockchain in the Internet of Things scenario according to claim 4 is characterized in that: Verify the eligibility of verifiable credentials based on on-chain information, including: The authentication party checks whether the anonymous identity is in the revocation list for the authentication request sent by the IoT device with an anonymous identity. If not, the identity credential is decrypted and the identity contained in the identity credential is checked to see if it is consistent with the anonymous identity in the authentication request. If they are consistent, the authentication is successful, otherwise, the authentication fails.

8. The privacy protection autonomous identity management method based on blockchain in the Internet of Things scenario according to claim 4 is characterized in that: Revocation management of IoT device identities based on revocation lists, including: The identity authentication party broadcasts the IoT device identity that has completed qualification verification, so that the on-chain nodes store the broadcasted IoT device identity in the local revocation list to revoke the IoT device identity using the local revocation list.

9. The privacy protection autonomous identity management method based on blockchain in the Internet of Things scenario according to claim 4 or 8 is characterized in that: Revocation management of IoT device identities based on revocation lists, including: For malicious IoT devices, the identity issuer broadcasts the seed selected when generating all anonymous identities of the IoT device, so that the on-chain nodes can obtain all anonymous identities of the IoT device based on the seed and record them in the local revocation list, so as to revoke the identity of the malicious IoT device using the local revocation list.

10. The method for privacy protection and autonomous identity management based on blockchain in the Internet of Things scenario according to claim 4 is characterized in that: Revocation management of IoT device identities based on revocation lists also includes: The anonymous identity of the IoT device is stored in the anonymous identity pool, and the anonymous identity in the anonymous identity pool is updated according to the identity revocation operation; If the number of anonymous identities remaining in the anonymous identity pool of the IoT device does not reach the preset threshold, the process of the IoT device reapplying for an anonymous identity from the identity issuer is triggered.

Citation Information

Patent Citations

  • Internet of Things anonymous identity authentication method and device based on block chain

    CN115842657A

  • Vehicle privacy protection method based on cloud storage block chain in Internet of Vehicles

    CN116760619A

  • Vehicle-mounted network continuous authentication method with privacy protection based on reputation management

    CN117768877A

  • Anonymous identity authentication method, system and product based on group signature and block chain

    CN118764212A

Cited By

  • An Internet of Things-based device master data automatic binding method, device and medium

    CN122554245A