Fine-grained anonymous authentication method for multi-attribute authority system
By using technologies such as attribute private key binding, blind signature and zero-knowledge proof in a multi-attribute authoritative system, the problem of insecure anonymous credentials under the existence of untrusted authority is solved, and the security and privacy protection of fine-grained anonymous authentication is achieved.
Patent Information
- Application Number
- CN202510156034.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-12
AI Technical Summary
The existing multi-attribute authoritative anonymous credential scheme is not secure when the credential issuer contains untrusted authority, and cannot effectively protect user privacy and prevent co-conspiracy risks.
Through technologies such as attribute private key binding, blind signature and zero-knowledge proof, users can realize fine-grained anonymous authentication under the multi-attribute authoritative system to ensure the security and privacy of attribute signatures.
Effectively prevent users from tampering with untrusted attributes and authoritatives to tamper with signed attributes, enhance the security and privacy protection capabilities of the entire system, and support decentralized trust and efficient authentication processes.
Smart Images

Figure CN120017357A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to the technical field of information security, and in particular to a fine-grained anonymous authentication method for a multi-attribute authority system. Background Art
[0002] Anonymous credential technology is a cryptographic technology that verifies the user's authority or qualifications without revealing their real identity. This feature has important application value in privacy protection and digital identity authentication. In particular, attribute-based credential technology focuses on verifying whether the user has specific attributes rather than directly exposing their real identity, thus providing more stringent protection for user privacy.
[0003] The single sign-on (SSO) model allows information service providers to verify user-based privileges through user identity providers, achieving an elegant decoupling of services and identities. Anonymous credential technology can be well applied to the SSO model to complete authentication under the premise of privacy protection, because it only needs to selectively display some attributes during the authentication process.
[0004] With the development of the network environment, decentralized network architecture has been increasingly applied to the commercial field in recent years because it is not restricted by a single point bottleneck. In a more realistic scenario, the attributes of users come from different attribute authorities. At present, although some anonymous credential schemes can realize the joint generation of credentials by multiple issuers, these schemes require service providers to trust all issuers of credentials. In actual situations, service providers should only need to trust the authority associated with the attributes required by the service access policy. For example: the access policy of the video playback service requires that the user has sufficient balance (published by video website T) and the age meets the requirements (published by the birth record authority). In this case, the service provider only needs to trust the video website T and the birth record authority, without considering whether to trust other authorities related to the credential attributes. However, the current multi-attribute authority anonymous credential scheme is not safe when the credential issuer includes an untrusted authority.
[0005] Therefore, there is an urgent need in the art to implement a fine-grained anonymous authentication method for a multi-attribute authority system, which can be used to enable the service provider to perform secure anonymous authentication on the user even when the user credential issuer includes an untrusted authority. Summary of the invention
[0006] In view of the above-mentioned deficiencies in the prior art, the present invention proposes a fine-grained anonymous authentication method for a multi-attribute authoritative system, which achieves a balance between security, privacy, decentralized trust and efficiency through attribute private key binding, blinded signature, zero-knowledge proof and other technologies, solves the collusion risk and privacy leakage problems in the multi-attribute authoritative system, and provides a reliable technical foundation for the next generation of anonymous authentication systems.
[0007] The technical solution of the present invention is as follows:
[0008] A fine-grained anonymous authentication method for a multi-attribute authority system, wherein the multi-system includes a central authority, multiple attribute authorities, N users and M relying parties, and the method includes the following steps:
[0009] Step 1. When the multi-attribute authority system is initialized, the central authority initializes the public parameters and secret values;
[0010] The central authority initializes public parameters and secret values, including:
[0011] Initialize the system, the secret value includes: two private keys γ, y 0 , and the membership value k of N secrets 1 ,…,k N , where N is the maximum number of times the certificate is issued; the public parameters include the public keys corresponding to the two private keys;
[0012] The public keys of the two private keys are Among them, g 2 For a pre-agreed group G 2 The generator on .
[0013] Step 2. The attribute authority generates a secret value for each managed attribute and publishes the public parameter, proving that it holds the secret value through zero-knowledge proof. The specific steps are as follows:
[0014] (2-1) Each attribute authority manages a set of attribute index sets, and the attribute index sets managed by different attribute authorities contain different elements;
[0015] (2-2) For each element of the attribute index set managed by the attribute authority, the attribute authority generates a secret value y k And publish public parameters Among them, g 2 For a pre-agreed group G 2 Generators on ;
[0016] (2-3) The attribute authority proves that it holds the generated secret value y through zero-knowledge proof k ;
[0017] Step 3. When a user joins, he obtains an empty certificate σ from the central authority; the details are as follows:
[0018] The central authority selects a secret value k for the user when the user joins j and the random number v j ∈G 1 , where G 1 For a pre-agreed group;
[0019] Central authority calculates empty certificate (k j ,σ j ) is sent to the user.
[0020] Step 4. The user searches for the attribute authority to sign the certificate in turn, and finally obtains a certificate signed with multiple attributes; the details are as follows:
[0021] (4-1) The user holds a secret (k j ,σ j ), find each attribute authority pair σ in turn j Sign and find the attribute authority A i Before signing, j The signed attribute index set in is
[0022] (4-2) User to attribute authority A i Send the blinded secret and request A i For σ j Perform attribute signing; the blinded secret is:
[0023] The user will j Resolved to σ j =(σ 1 , σ 2 ), select a random number t, and blind the secret held by u (k j , σ j ),generate
[0024]
[0025] Afterwards, the user selects r k , r u and {r s}, s∈I, calculate
[0026]
[0027] Where e is the bilinear pairing map e:G 1 ×G 2 →G T , G 1 , G 2 , GT is a pre-agreed group; I is the attribute index set signed in the user credential. 0 , σ′ is sent to the attribute authority A i These parameters are used by the user to prove to the authority that he has (k j , σ j );
[0028] (4-3) Attribute Authority A i Check the intersection of the signed attribute index set in the user's credential with its own attribute index set Is it empty? If the intersection is not empty, it means that the user's credentials have been j If the signature has been made, no subsequent steps will be performed; if the intersection is empty, the attribute authority A i Send a random challenge c to the user, and the user uses c to prove to the attribute authority that he has (k j , σ j ), and σ j Contains the signed attribute m s , s∈I;
[0029] (4-4) After the proof is completed, the attribute authority A i Prepare a set of attributes to sign to the user Check the attributes into the blinded credentials sent by the user, including: Attribute Authority A i Sign the blinded certificate σ′ sent by the user; attribute authority A i Choose a random number t i , prepare user attribute set Generate New Credentials The user gets a new credential σ, and the attributes contained in σ include finding the attribute authority A i The previously signed attribute m s , s∈I, attribute authority A i Signature attribute set m k , holding (k j ,σ=(σ 1 , σ 2 )).
[0030] Step 5. When the user obtains the service provided by the relying party, if the attributes contained in the credential meet the access control policy of the relying party Then prove to the relying party that it has the required attributes and complete anonymous authentication; the specific steps are as follows:
[0031] (5-1) The access control policy for the service provided by the relying party contains the attribute index set I R For index set I R For some index i, the access policy requires a certain attribute value, using If Indicates this partial index set; for other index values, the access policy provides the allowed range, using I r Represents this partial index set;
[0032] (5-2) For I r The attribute index set represented by the user needs to prove the valid attribute m in the certificate through knowledge proof. i Satisfy the access policy, expressed using a Boolean algorithm:
[0033]
[0034] in, is the access strategy, R is obtained by a specific function f R and blind secret {r i} generated promises, c and {z i} are challenge and response respectively;
[0035] (5-3) The user proves to the relying party through knowledge proof that the certificate σ he holds is signed with the attributes contained in the index set f, and is also signed with I r The index concentrates some attributes to satisfy the access policy specified by the relying party. The user sends the parameters required for knowledge proof to the relying party;
[0036] In the step (5-3), the user sends the parameters required for knowledge proof to the relying party, including:
[0037] The random numbers t, u and σ′ are selected in the same way as in step (4-2);
[0038] User selects r k , r u and calculate
[0039]
[0040] R f =f(r s ∈I r )
[0041] c=H(σ′,R 0 , R f )
[0042] Calculate z k =r k +ck j , z u =r u +cu;
[0043] For all Calculate zs =r s +cm s , (σ′, R 0 , R f ) and the calculated z k , z u and all z s , Sent to the relying party.
[0044] (5-4) The relying party verifies whether the user credential attributes satisfy the access policy. If so, the user can access the service normally.
[0045] Compared with the prior art, the technical effects of the present invention are as follows:
[0046] The attribute authority selects a private key for each managed attribute and publishes a public key, thereby preventing the signature attribute from being tampered with. Compared with existing authentication schemes, the present invention has greatly improved security and privacy protection.
[0047] First, the attribute authority will be responsible for issuing attribute-based credentials, and this process does not require the participation of a central authority. The attribute authority will select a private key for each attribute it manages and publish public parameters, proving that it holds the private key through zero-knowledge proof. In the existing multi-attribute authority anonymous authentication scheme, the attribute authority will not select a private key for the attribute, and the attributes it publishes will be directly signed in the credential in the form of discrete logarithms, which can lead to users colluding with untrusted attribute authorities to obtain the private key without modifying the signed attribute m. i In the case of i , and anonymous authentication can be successfully completed, and the entire credential is no longer credible. In our proposed scheme, in the credential issued by the attribute authority, the signed attribute m i Binding to the attribute private key prevents users from colluding with untrusted attribute authorities to transfer the signed attribute m i Claimed as attribute m′ i , enhancing the security of the entire solution.
[0048] In terms of privacy protection, due to the use of anonymous credential technology, users only need to prove that they have certain attributes when authenticating, without having to show their real identity and other irrelevant attributes, which effectively protects user privacy. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 It is a schematic diagram of a multi-attribute authoritative anonymous authentication system.
[0050] Figure 2 It is a flow chart of the fine-grained anonymous authentication method for a multi-attribute authority system.
[0051] Figure 3 It is a schematic diagram of a user searching for each attribute authority to sign the credential in turn.
[0052] Figure 4 It is a diagram showing the degree of trust a service provider has in the attributes contained in a user's credentials when performing anonymous authentication. DETAILED DESCRIPTION
[0053] The present invention is further explained below in conjunction with the accompanying drawings and embodiments, but the protection scope of the present invention should not be limited thereto.
[0054] like Figure 1 The multi-attribute authority anonymous authentication system shown in the figure includes a central authority, multiple attribute authorities, N users and M relying parties. The central authority and each attribute authority are the credential issuers, and the relying parties are the service providers. Users obtain anonymous credentials signed with attributes from the credential issuers, and can anonymously authenticate with the service providers and obtain services.
[0055] like Figure 2 As shown, the overall anonymous authentication process is divided into 5 steps:
[0056] Step 1. When the multi-attribute authority system is initialized, the central authority initializes the public parameters and secret values.
[0057] The secret value includes: two private keys γ, y 0 , and the membership value k of N secrets 1 ,…,k N , where N is the maximum number of times the certificate is issued, which is also the maximum number of users that the authentication system can include, secret γ and secret y 0 Used together to issue user credentials.
[0058] The public parameters include the public keys corresponding to the two private keys Among them, g 2 For a pre-agreed group G 2 The generator on .
[0059] Step 2. The attribute authority joins the system, generates secret values for each managed attribute and publishes public parameters, and proves that it holds the secret value through zero-knowledge proof. The specific process is as follows:
[0060] (2-1) Each attribute authority manages a set of attribute indexes The attribute index sets managed by different attribute authorities contain different elements.
[0061] (2-2) For each element of the attribute index set managed by the attribute authority The attribute authority generates a secret value y k And publish public parameters Among them, g2 For a pre-agreed group G 2 The generator on the secret value y k Used to prevent users from colluding with other attribute authorities to claim attribute m k For other attributes.
[0062] (2-3) The attribute authority proves that it holds the generated secret value y through zero-knowledge proof k , the zero-knowledge proof process is as follows:
[0063] Prove that you have y k , the public parameters are
[0064] 1: Select R = g r
[0065] 2: According to the secure hash function, R is used as input to obtain
[0066] 3: z = cy k +r
[0067] 4: Output (R, c, z)
[0068] Where R is a random commitment, c is a challenge, and z is the response to challenge c. Other parties can verify Y k c R = g z , to verify whether the private key selected by the attribute authority for this attribute is y k .
[0069] The user obtains an empty certificate from the central authority, and then searches for each attribute authority to sign the certificate attributes in turn. Figure 3 shown.
[0070] Step 3. When a user joins, he obtains an empty credential σ from the central authority.
[0071] The central authority selects a secret value k for the user when the user joins j and random v j ∈G 1 , where G 1 For a pre-arranged group.
[0072] Central authority calculates empty certificate (k j , σ j ) is sent to the user.
[0073] Step 4. The user searches for the attribute authority to sign the certificate in turn, and finally obtains a certificate signed with multiple attributes. The specific process is as follows:
[0074] (4-1) The user holds a secret (k j , σ j ), find each attribute authority pair σ in turn j Sign and find the attribute authority A i Before signing, j The signed attribute index set in is
[0075] (4-2) User to attribute authority A i Send the blinded secret and request A i For σ j Perform attribute signature. The details are as follows:
[0076] In search of attribute authority A i Before, the user has visited some other authorities and signed several attributes m in the certificate s , s∈I. The user is currently looking for attribute authority A i Sign the new attributes of the credential.
[0077] First, the user proves to the attribute authority that he has (k j , σ j ), and σ j Resolved to σ j =(σ 1 , σ 2 ), select a random number t, and blind the secret held by u (k j , σ j ),generate
[0078]
[0079] Afterwards, the user selects r k , r u and (r s ), s∈I, calculate
[0080]
[0081] Where e is the bilinear pairing map e:G 1 ×G 2 →G T , G 1 , G 2 , G T is a pre-agreed group; I is the attribute index set signed in the user credential. 0 , σ′ is sent to the attribute authority A i .
[0082] (4-3) Attribute Authority A iCheck the intersection of the signed attribute index set in the user's credential with its own attribute index set Is it empty? If the intersection is not empty, it means that the user's credentials have been j If the signature has been made, no subsequent steps will be performed; if the intersection is empty, the attribute authority A i Send a random challenge c to the user, and the user uses c to prove to the attribute authority that he has (k j , σ j ), and σ j Contains the signed attribute m s , s∈I. The details are as follows:
[0083] After the user receives c, calculate
[0084] z k =r k +ck j , z u =r u +cu
[0085] And for each s∈I, calculate z s =r s +cm s , and send the calculation results to the attribute authority A i .
[0086] Attribute Authority A i Resolve σ′ as σ′=(σ 1 ′,σ 2 '),examine:
[0087]
[0088] If the equation holds, the proof is successful, and the user has successfully proved to the attribute authority that he has (k j , σ j ).
[0089] (4-4) After the proof is completed, the attribute authority A i Prepare a set of attributes to sign to the user The attributes are signed into the blinded credential sent by the user, and the user obtains a new credential σ. The attributes contained in σ include finding the attribute authority A i The previously signed attribute m s , s∈I, attribute authority A i Signature attribute set m k The details are as follows:
[0090] Attribute Authority A i First select a random number Prepare a set of attributes to sign to the user Among them, the random number ti Used to blind attributes and the private key corresponding to the attributes. Attribute Authority A i Generate new credentials and send to the user:
[0091]
[0092] The user gets a new credential σ, and the attributes contained in σ include finding the attribute authority A i The previously signed attribute m s , s∈I, and the attribute authority A i Signature Properties The user now holds the secret (k j , σ).
[0093] Figure 4 Shows the degree of trust that the service provider has in the attributes contained in the user's credentials when performing anonymous authentication. The service requires the attribute m 1 , m 2 , m 4 , the authority trusted by the relying party is AA 1 , A.A. 3 , A.A. 4 , is the attribute m 1 , m 2 , m 4 During authentication, the user claims and proves that the credential contains attribute m 1 , m 2 , m 4 The credential attributes also include m 3 , which is issued by AA 3 , is not in the trust domain of the relying party. The present invention can complete secure user authentication in this case, ensuring that the attribute m contained in the user's claimed credential 1 , m 2 , m 4 The existing anonymous authentication schemes of other multi-attribute authority systems cannot do this.
[0094] Step 5. When the user obtains the service provided by the relying party, if the attributes contained in the credential meet the access control policy of the relying party Then prove to the relying party that it has the required attributes, complete anonymous authentication, and obtain services. The specific steps are as follows:
[0095] (5-1) The access control policy for the service provided by the relying party contains the attribute index set I R For index set I R For some index i, the access policy requires a certain attribute value, using I f Indicates this part of the attribute index set; for other index values, the access policy provides an allowed range, and the user attribute only needs to meet this range.r Represents this partial attribute index set.
[0096] (5-2) For I r The attribute index set represented by the user needs to prove the valid attribute m in the certificate through knowledge proof. i Satisfy the access policy, expressed using a Boolean algorithm:
[0097]
[0098] in, is the access strategy, R is obtained by a specific function f R and blind secret {r i} generated promises, c and {z i} are challenge and response respectively.
[0099] (5-3) The user proves to the relying party through knowledge proof that the certificate σ he holds is signed by I f The attributes included in the index set are also signed with I r The index concentrates some attributes to meet the access policy specified by the relying party. The user sends the parameters required for knowledge proof to the relying party. The details are as follows:
[0100] The user selects a random number t,u in the same way as step (4-2) and calculates σ′;
[0101] User selects r k , r u and {r s}, calculate:
[0102]
[0103] R f =f(r s ∈I r )
[0104] c=H(σ′,R 0 , R f )
[0105] Calculate z k =r k +ck j , z u =r u +cu;
[0106] For all Calculate z s =r s +cm s , (σ′, R 0 , R f) and the calculated z k , z u and all z s , Sent to the relying party. User calculates z s =r s +cm s , Because the certificate contains I f In addition to the attributes in the certificate, it also contains other attributes. The user needs to cooperate with the relying party to prove that the certificate contains I f The attributes in .
[0107] (5-4) The relying party verifies whether the user credential attributes meet the access policy. If they do, the user can access the service normally. The details are as follows:
[0108] After receiving the user authentication message, the relying party verifies whether the user attributes meet the access policy and checks the following equation:
[0109]
[0110] If the above equations are true, the user completes the knowledge proof and the relying party confirms that the user's credentials contain the access policy. The required attributes are met, anonymous authentication succeeds, and the user can access the service normally.
[0111] All matters not covered in the above embodiments of the present invention are well known in the art.
[0112] The present invention generates an independent private key for each attribute authority that it manages, and proves to the system that it holds the private key through zero-knowledge proof. When signing an attribute, the attribute value is bound to the private key to generate a mathematically associated credential. When a user requests an attribute signature, the attribute authority checks whether the user's credential already contains the attributes it manages (verified by the intersection of the index set) to prevent duplicate signatures or attribute tampering, thereby ensuring that the user cannot collude with an untrusted attribute authority to tamper with the signed attributes. The attribute sets managed by different attribute authorities do not intersect with each other, and the private keys are generated independently. Even if some attribute authorities are compromised, the security of other attributes cannot be affected.
[0113] When a user requests a signature from an attribute authority, a random number is used to blind the empty credential, generate a temporary credential, and hide the associated information of the original credential, ensuring that different signature sessions cannot be associated with the same user, preventing the attribute authority or relying party from tracking user behavior. When a user proves to a relying party that an attribute satisfies the access policy, the existence and scope of the attribute are only proved through mathematical commitment and challenge-response mechanism, without revealing specific attribute values or identity information.
[0114] The verification mechanism based on bilinear pairing reduces exponential operations and modular inverse calculations while ensuring security, and is suitable for resource-constrained Internet of Things (IoT) devices. Attribute authorities can be dynamically added to the system, and new attributes do not require reconstruction of global parameters, supporting high-concurrency user and attribute management.
[0115] The above describes the specific embodiments of the present invention. It should be understood that the present invention is not limited to the above specific embodiments, and those skilled in the art may make various modifications or variations within the scope of the claims, which do not affect the essence of the present invention.
Claims
1. A fine-grained anonymous authentication method for a multi-attribute authority system, characterized in that: The multi-system includes a central authority, multiple attribute authorities, N users and M relying parties, and the method includes the following steps: Step 1. During the system initialization phase, the central authority generates public parameters and secret values, including: Select bilinear pairing groups G1, G2, G T , g1 is a generator on the group G1, g2 is a generator on the group G2, that is, g1∈G1 and g2∈G2; Generate a private key And calculate the corresponding public key Generate N secret member values k1,…,k N , used to uniquely identify the user's credential, where N is the maximum number of times the credential can be issued; Step 2. Each attribute authority manages a unique set of attribute indexes And for each property do the following: For each element of the attribute index set managed by each attribute authority, generate a private key y k , and publish the public key Prove to the system that it holds the private key y through zero-knowledge proof k ; Step 3. When a user registers, the central authority assigns a secret value k to the user j and the random number v j ∈G1, generate an empty certificate And the secret (k j ,σ j ) sent to the user; Step 4. The user sequentially requests multiple attribute authorities to sign the empty certificate, thereby obtaining a certificate signed with multiple attributes, specifically including: User to attribute authority A i Sending blinded credentials in, is the random blinding factor; Attribute Authority A i Verify that the user's credentials do not contain a self-managed attribute set And verify the user's secret (k j ,σ j ) is legally held, and σ j Contains the signed attribute m s ,s∈I; After verification, the attribute authority A i Use the private key to sign the blinded certificate σ′ and generate a new certificate The user gets a new credential σ and holds (k j ,σ=(σ1,σ2)); Step 5. When the user requests a service from the relying party, if the credential attributes satisfy the relying party’s access control policy Anonymous authentication is completed through zero-knowledge proof, including: The relying party specifies the access control policy for the service provided Contains a set of identified attribute indexes I f and range attribute index set I r ; User Generated Commitment and R f =f(r s ∈I r ), and generate the challenge c = H(σ′, R0, R f ); The user calculates the response and sends it to the relying party, who verifies the following equation: and After verification, service permissions are granted.
2. The fine-grained anonymous authentication method for a multi-attribute authoritative system according to claim 1, characterized in that: The zero-knowledge proof in step 2 also includes: The verifier checks Y k c R = g z , to verify the attribute authority for the private key y k holdings.
3. The fine-grained anonymous authentication method for a multi-attribute authoritative system according to claim 1, characterized in that: The step 4 also includes: -The blinded credential generation process satisfies: Each time a user requests a signature, an independent random number is used Empty Certificates j Blinding is performed to ensure that different signing sessions cannot be correlated; -The attribute authority signs the blinded credential, including the introduction of random numbers Used to blind attribute signatures to prevent signatures from being tracked.
4. The fine-grained anonymous authentication method for a multi-attribute authoritative system according to claim 1, characterized in that: In step 5, the range attribute index set I r Verification of the promise associated with the scope R is constructed by the user f , and based on the Boolean algorithm Prove that the attribute value satisfies the access policy 5. The fine-grained anonymous authentication method for a multi-attribute authoritative system according to claim 1, characterized in that: The bilinear pairing map e:G1×G2→G T is an asymmetric bilinear pairing, and the groups G1, G2, G T The order of is a prime number p.
6. The fine-grained anonymous authentication method for a multi-attribute authoritative system according to claim 1, characterized in that: The user has empty credentials σ j The generation of meets the following conditions: Among them, v j ∈G1 is a random number, k j A unique secret value for the user.
Citation Information
Patent Citations
Anonymous trusted access control method based on verifiable credentials and zero-knowledge proof
CN115694838A
Traceable anonymous authentication method and system
CN116582275A
Privacy preserving authorisation in pervasive environments
US20130117824A1