Terminal authorization authentication system and method based on anonymous signature
By adopting an anonymous signature-based terminal authorization and authentication in terminal device identity authorization and authentication, and using password collaborative computing and randomized signature mechanism, the problems of insufficient anonymity protection and high security risks in terminal device identity authorization and authentication are solved, and the high credibility and unlinkable security of terminal device identity are achieved.
Patent Information
- Application Number
- CN202311555781.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-21
- Publication Date
- 2025-05-23
AI Technical Summary
The prior art has problems such as insufficient anonymity protection, low credibility of terminal devices and high security risks in terminal devices identity authorization and authentication, especially in emerging application modes such as Web 3.0 and Metauniverse.
The terminal authorization and authentication system based on anonymous signature is adopted, and password collaborative calculations are performed with the terminal device through the authorization service platform, and the device anonymous signature public-private key pair is generated, and anonymous signature verification is used to ensure the anonymity and unlinkability of the terminal device identity.
It enhances the credibility of terminal device identity, realizes the anonymous protection and unlinkable security of terminal device identity, and reduces the risk of illegal linking and tracking.
Smart Images

Figure CN120034339A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer technology and information security technology, and in particular relates to a terminal authorization authentication system and method based on anonymous signature. Background Art
[0002] With the promotion of emerging application models such as Web 3.0 and Metaverse, device identity authorization and authentication services carried out around terminal devices are increasingly becoming the main technical means for autonomous identity management and controllable supervision in IoT application scenarios, and will also become the core driving force for the development of distributed authentication technology. When accessing certain application services of the application party, the terminal device may need to perform necessary identity authentication to have access rights. For example, for a distributed digital identity authentication system with terminal devices as the core, the application party needs to trust the authentication information generated by the terminal device to confirm whether the corresponding application service can be accessed. When supervising, the implementation method generally adopted by the supervisor is to parse the corresponding device information from the data reported by the application party, and use the parsed information to search in the database, so as to trace the relevant device.
[0003] The above application methods have the following defects: (1) There is a security issue that the application party may use public key information to collude to track and illegally connect to terminal devices. (2) The terminal devices participating in the authentication have not obtained trusted access permission. For example, it is difficult for terminal devices without trusted access to provide a secure environment for signing, and many application parties cannot bear the legal risks brought about by terminal authorization authentication. (3) There is a lack of a security mechanism to verify the compliance of the source of information such as assertions, making it difficult to avoid security risks such as impersonation, theft, and tampering.
[0004] To this end, an effective terminal authorization and authentication method based on anonymous signature, verification and supervision is needed to solve the anonymous protection problem of terminal device identity authorization and authentication, effectively enhance the credibility of terminal devices and their output verification results, and achieve the unlinkable security of terminal device identity that changes once. Summary of the invention
[0005] In view of the above analysis, the present invention aims to disclose a terminal authorization and authentication system and method based on anonymous signature, which solves the anonymous protection problem of terminal device authorization and authentication and realizes the unlinkable security of terminal device identity changing once.
[0006] The purpose of the present invention is mainly achieved through the following technical solutions:
[0007] On the one hand, the present invention discloses a terminal authorization and authentication system based on anonymous signature, comprising: an authorization service platform, a terminal device and an application party;
[0008] The authorization service platform is used to perform cryptographic collaborative calculations with the terminal device, generate a device anonymous signature public key on the authorization service platform side, and generate a device anonymous signature public-private key pair on the terminal device side; use the randomized signature private key of the authorization service platform to randomly sign the device anonymous signature public key to obtain a randomized signature value of the device anonymous signature public key;
[0009] The terminal device uses the randomized signature public key of the authorization service platform to verify the randomized signature value, and anonymously signs the authentication information to obtain anonymous signature information;
[0010] The application party is used to verify the anonymous signature information based on the randomized signature public key and the regulatory opening public key of the authorization service platform. If the verification is successful, the terminal device identity is allowed to enter.
[0011] Furthermore, the authorization service platform includes a terminal anonymous authorization module and a terminal identity opening module;
[0012] The terminal anonymous authorization module is used to generate the device anonymous signature public key, establish and store the binding relationship between the device anonymous signature public key and the terminal device ID, and use the randomized signature private key of the authorization service platform to randomly sign the device anonymous signature public key to obtain the randomized signature value of the device anonymous signature public key;
[0013] The terminal identity opening module calculates and opens the anonymous signature information based on the supervision opening private key to obtain the device anonymous signature public key, and obtains the terminal device ID corresponding to the device anonymous signature public key based on the binding relationship to realize device supervision.
[0014] Furthermore, the terminal anonymous authorization module generates a device anonymous signature public key by the following method:
[0015] The terminal anonymous authorization module generates a randomized signature public-private key pair and a supervision-opening public-private key pair for the authorization service platform;
[0016] receiving a terminal device registration request including a terminal device ID;
[0017] Based on the randomized signature public key of the authorization service platform, cryptographic collaborative calculation is performed with the terminal device to obtain the anonymous signature public key of the device.
[0018] Furthermore, the terminal identity opening module obtains the terminal device ID corresponding to the device anonymous signature public key by the following method:
[0019] The terminal identity opening module receives the anonymous signature information sent by the application party;
[0020] Use the supervision opening public key and the random signature public key of the authorization service platform to verify the anonymous signature information;
[0021] After the signature verification is passed, the anonymous signature information is calculated and opened using the supervisory opening private key to obtain the device anonymous signature public key;
[0022] Based on the device anonymous signature public key, the corresponding binding relationship is retrieved to obtain the corresponding terminal device ID.
[0023] Furthermore, the terminal device includes an anonymous signature module;
[0024] The anonymous signature module generates a device anonymous signature public-private key pair based on the result of cryptographic collaborative calculation; uses the randomized signature public key of the authorization service platform to verify the randomized signature value; securely stores the randomized signature value and the device anonymous signature private key; and uses the device anonymous signature private key, the randomized signature value and public parameters to anonymously sign the authentication information.
[0025] Furthermore, the anonymous signature module calculates in collaboration with the terminal anonymous authorization module password based on the randomized signature public key, the supervision opening public key and the terminal device ID of the authorization service platform to obtain the device anonymous signature private key.
[0026] Furthermore, the application party includes an anonymous signature verification module, which is used to verify the anonymous signature information using the randomized signature public key and the supervisory opening public key of the authorization service platform.
[0027] On the other hand, a terminal authorization authentication method based on anonymous signature is also disclosed, comprising:
[0028] The terminal device sends a device registration request to the authorization service platform and performs cryptographic collaborative calculation with the authorization service platform; the authorization service platform uses the randomized signature private key of the authorization service platform to randomly sign the device anonymous signature public key, obtains the randomized signature value of the device anonymous signature public key and sends it to the terminal device;
[0029] Based on the result of the cryptographic collaborative calculation, the terminal device obtains the device anonymous signature public-private key pair, and the authorization service platform obtains the device anonymous signature public key; the terminal device uses the randomized signature public key of the authorization service platform to verify the randomized signature value, and securely stores the randomized signature value and the device anonymous signature private key;
[0030] The terminal device signs the authentication information using the device anonymous signature private key, the randomized signature value and the public parameters, obtains anonymous signature information and sends it to the application party;
[0031] The application party uses the randomized signature public key and the supervision opening public key of the authorization service platform to verify the anonymous signature information, and provides corresponding services if the verification passes.
[0032] Furthermore, the terminal device and the authorization service platform perform cryptographic collaborative calculation based on the terminal device ID, the randomized signature public key of the authorization service platform, and the supervision opening public key;
[0033] The cryptographic collaborative computing is a secure multi-party computing or a secure two-party computing based on cryptographic technology.
[0034] Furthermore, it also includes terminal equipment supervision, including:
[0035] During the terminal device registration phase, a binding relationship between the device anonymous signature public key and the terminal device ID is established through the authorization service platform and stored;
[0036] The anonymous signature information is sent to the authorization service platform through the application party;
[0037] Use the supervision opening public key and the random signature public key of the authorization service platform to verify the anonymous signature information;
[0038] After the signature verification is passed, the anonymous signature information is calculated and opened using the supervisory opening private key to obtain the device anonymous signature public key;
[0039] Use the device's anonymous signature public key to obtain the binding relationship corresponding to the public key, obtain the terminal device ID, and realize traceability supervision of the device.
[0040] The present invention can achieve at least one of the following beneficial effects:
[0041] 1. The authorization service platform registers the real identity of the terminal device, and generates an anonymous identity and corresponding private key based on the randomized signature value for the terminal device through cryptographic collaborative calculation and randomized signature, thus ensuring the anonymity of the terminal device identity and enhancing the security of identity non-disclosure;
[0042] 2. During the identity verification of the terminal device, the application uses the randomized signature public key and other parameters of the authorization service platform to perform anonymous signature verification to realize the authorization and authentication of the terminal device identity, and ensure the security of the unlinkability of the terminal device identity that changes once;
[0043] 3. When the terminal device identity is opened, the authorization service platform uses the supervisory opening private key to calculate the anonymous signature value and obtain the device anonymous signature public key, thereby realizing the traceability of the device's true identity. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] The accompanying drawings are only used for the purpose of illustrating specific embodiments and are not to be considered as limiting the present invention. In the entire drawings, the same reference symbols represent the same components;
[0045] Figure 1 It is a block diagram of a terminal authorization and authentication system based on anonymous signature in an embodiment of the present invention;
[0046] Figure 2 The present invention is a flowchart of a terminal authorization and authentication method based on anonymous signature in an embodiment of the present invention. DETAILED DESCRIPTION
[0047] The preferred embodiments of the present invention will be described in detail below in conjunction with the accompanying drawings, wherein the accompanying drawings constitute a part of this application and are used to illustrate the principles of the present invention together with the embodiments of the present invention.
[0048] Embodiment 1:
[0049] The embodiment of the present invention discloses a terminal authorization and authentication system based on anonymous signature, such as Figure 1 As shown, the system includes: an authorization service platform, a terminal device and an application party;
[0050] The authorization service platform includes a terminal anonymous authorization module and a terminal identity opening module, which are used to perform cryptographic collaborative calculations with the terminal device, generate a device anonymous signature public key on the authorization service platform side, and generate a device anonymous signature public-private key pair on the terminal device side; use the randomized signature private key of the authorization service platform to randomly sign the device anonymous signature public key to obtain the randomized signature value of the device anonymous signature public key; and use it to supervise and open the terminal device identity; among them,
[0051] The terminal anonymous authorization module is used to generate the device anonymous signature public key, and establish and store the binding relationship between the device anonymous signature public key and the terminal device ID, and use the randomized signature private key of the authorization service platform to randomly sign the device anonymous signature public key to obtain the randomized signature value of the device anonymous signature public key; the terminal identity opening module calculates and opens the anonymous signature information based on the supervision opening private key to obtain the device anonymous signature public key, and obtains the terminal device ID corresponding to the device anonymous signature public key based on the binding relationship to realize device supervision.
[0052] Specifically, the terminal anonymous authorization module generates the device anonymous signature public key through the following method:
[0053] First, the terminal anonymous authorization module generates a randomized signature public-private key pair for the authorization service platform and a supervisory opening public-private key pair; in particular, during the system establishment phase, public parameters are provided to the authorization service platform, terminal devices and application parties; the public parameters include bilinear group parameters and hash functions required for zero-knowledge proof; the authorization service platform generates a randomized signature public-private key pair for the authorization service platform and a supervisory opening public-private key pair (i.e., a de-anonymization public-private key pair) based on the public parameters; and the public keys of the two public-private key pairs are disclosed to the terminal devices and application parties.
[0054] Preferably, the process of generating the randomized signature public-private key pair of the authorization service platform is: x←Z n * , y←Z n * , X = x·P, Private key sk = (y, X), public key Make the public key pk public;
[0055] The process of generating a public-private key pair for supervision (de-anonymization of public-private key pair) is: z←Z n * , Z = z·P, z is the supervisory opening of the private key, Z is the supervisory opening of the public key, and the public key Z is made public;
[0056] Where n is the order of the n-torsion subgroup of the elliptic curve, is a prime number, Zn* is the set of non-zero elements in Zn, Zn is a modulo n integer ring, (G1,+) is an n-order additive cyclic group, (G2,+) is an n-order additive cyclic group, P is the generator of (G1,+) P = (xP, yP), P ≠ O, is the generator of (G2,+)
[0057] receiving a terminal device registration request including a terminal device ID;
[0058] Based on the terminal device ID and the randomized signature public key and the supervision opening public key of the authorization service platform, the anonymous signature public key of the device is calculated in coordination with the terminal device password. Specifically, the terminal device sends the interaction information to the authorization service platform, where the interaction information includes the secret commitment message generated based on the elliptic curve and the corresponding zero-knowledge proof. The authorization service platform verifies the validity of the interaction information. After the verification is passed, the authorization service platform obtains the anonymous signature public key of the device through a secure two-party operation based on the obtained interaction information, and establishes a binding relationship between the anonymous signature public key of the device and the terminal device ID;
[0059] Furthermore, the terminal identity opening module obtains the corresponding terminal device ID based on the device anonymous signature public key, including:
[0060] The terminal identity opening module receives the anonymous signature information sent by the application; uses the regulatory opening public key and the randomized signature public key of the authorization service platform to verify the anonymous signature information; after the verification, uses the regulatory opening private key to calculate and open the anonymous signature information to obtain the device anonymous signature public key; based on the device anonymous signature public key, retrieves the binding relationship of the device and obtains the corresponding terminal device ID.
[0061] Furthermore, the terminal device includes an anonymous signature module for anonymously signing the authentication information based on the device anonymous signature private key, the randomized signature value and the public parameter to obtain anonymous signature information;
[0062] The anonymous signature module generates a device anonymous signature public-private key pair based on the result of cryptographic collaborative calculation, and uses the device anonymous signature private key, randomized signature value and public parameters to sign the authentication information to generate anonymous signature information;
[0063] The anonymous signature module performs cryptographic collaborative calculations with the terminal anonymous authorization module based on the randomized signature public key, the supervisory opening public key and the terminal device ID of the authorization service platform to obtain the device anonymous signature private key. During the cryptographic collaborative calculation process, the authorization service platform sends the verified interactive information to the terminal device. After the terminal device verifies the validity of the interactive information, it calculates the device anonymous signature private key based on the obtained interactive information and its own information.
[0064] Furthermore, the application includes an anonymous signature verification module, which is used to verify the anonymous signature information using the randomized signature public key and the regulatory opening public key of the authorization service platform. If the verification is passed, the terminal device identity is allowed to enter.
[0065] Specifically, the application party usually refers to Internet application service providers, telecom operators, etc. The application party includes an anonymous signature verification module, which is mainly responsible for verifying the signature information and accepting the authentication information.
[0066] During the stage when the application party verifies the anonymous signature information provided by the terminal device, the application party uses the authorization service platform to randomize the signature public key and the supervisory open public key to verify the anonymous signature information submitted by the terminal device. Only after the verification is passed can the corresponding application service be provided.
[0067] Embodiment 2
[0068] The embodiment of the present invention discloses a terminal authorization authentication method based on anonymous signature, such as Figure 2 As shown, the following steps are included:
[0069] Step S1: The terminal device sends a device registration request to the authorization service platform, and performs cryptographic collaborative computing with the authorization service platform; specifically, the terminal device and the authorization service platform perform cryptographic collaborative computing based on the terminal device ID and the authorization service platform's randomized signature public key and the supervisory opening public key pre-generated by the authorization service platform; the cryptographic collaborative computing is a secure multi-party computing or secure two-party computing based on cryptographic technology;
[0070] In the initialization stage of this embodiment, the authorization service platform generates a randomized public-private key pair for the authorization service platform, and stores the randomized private key for the authorization service platform, which is used for the password collaborative calculation during device registration and for randomizing the device anonymous signature public key; at the same time, it generates a supervision opening public-private key pair, and stores the supervision opening private key;
[0071] When registering a device, the terminal device sends a device registration request to the authorization service platform. After receiving the request, the authorization service platform performs cryptographic collaborative calculations with the terminal device, calculates the device anonymous signature public key based on the result of the cryptographic collaborative calculation, and establishes a binding relationship between the device anonymous signature public key and the terminal device ID. At the same time, the device anonymous signature public key is randomly signed based on the randomized signature private key of the authorization service platform to obtain the randomized signature value of the device anonymous signature public key; the terminal device side generates a device anonymous signature private key.
[0072] After cryptographic collaborative calculations are performed by the authorized service platform and the terminal device, the device anonymous signature public key and the device anonymous signature private key are obtained respectively. There is no need to transmit key information. The required key information can be calculated based only on the public parameter information and the interaction data of both parties, which has higher security.
[0073] Step S2: Based on the result of the cryptographic collaborative calculation, the terminal device obtains the device anonymous signature private key, and the authorization service platform obtains the device anonymous signature public key;
[0074] Specifically, the device anonymous signature private key is stored in the terminal device. The generation of the device anonymous signature private key indicates that the authorization service platform has completed the trusted authorization of the terminal device, and constrains that only authorized terminal devices can effectively sign the authentication information.
[0075] Step S3: The terminal device uses the device anonymous signature private key, randomized signature value and public parameters to anonymously sign the authentication information, obtains anonymous signature information and sends it to the application party;
[0076] Specifically, to ensure that the authentication information is secure, authentic, and reliable, when the terminal device accesses the application service of the application party, it uses the device's anonymous signature private key, randomized signature value, and public parameters to anonymously sign the authentication information to form anonymous signature information. The anonymous signature information generated on the terminal device side is submitted to the application party for authentication.
[0077] The anti-linking anonymous signature mechanism of this embodiment provides a safer and more reliable signing environment for the terminal device, effectively avoiding the problem of illegal linking and tracking of the terminal device by the application party using public key information, and realizes the anonymization of the terminal device authorization and authentication process.
[0078] Step S4: The application party uses the randomized signature public key and the supervisory opening public key pre-generated by the authorization service platform to verify the anonymous signature information. If the verification is passed, the corresponding service is provided.
[0079] Specifically, after the application parses the received anonymous signature information, the anonymous signature verification module uses the randomized signature public key and the supervisory open public key of the authorization service platform to verify the signature information. The signature verification process mainly uses the randomized signature public key and the supervisory open public key of the authorization service platform. The signature verification process is completed by the application party to confirm the issuance source of the signature information.
[0080] The application party uses the authorization service platform to randomize the signature public key and supervise the opening of the public key to verify the anonymous signature information. If the verification passes, it means that the identity of the terminal device has been approved. At the same time, the application party cannot perform homology linking to the terminal device based on the public key information.
[0081] According to the anonymous signature information submitted by the terminal device, the application party uses the authorization service platform to randomize the signature public key and supervise the opening public key to verify the anonymous signature information. After the signature verification is passed, the application party can believe that the anonymous signature information is generated by a trusted authorized device. On the basis of passing the signature verification, the application party provides application services to users.
[0082] The verification method of this embodiment improves the credibility of authentication information, while also ensuring the unlinkability of the terminal device; when verifying the signature information, the application party only uses the randomized signature public key and the regulatory opening public key of the authorization service platform, but does not use the device anonymous signature public key. This method allows the application party to verify the signature information submitted by the terminal device, but cannot obtain relevant information of the terminal device, avoiding the conventional practice of the application party using the public key information generated by the terminal to verify the signature, which may lead to security issues such as the application party using the device anonymous signature public key to collude to track the terminal device.
[0083] Furthermore, the method of this embodiment also includes terminal device supervision, including:
[0084] During the terminal device registration phase, a binding relationship between the device anonymous signature public key and the terminal device ID is established through the authorization service platform and stored;
[0085] The anonymous signature information is sent to the authorization service platform through the application party;
[0086] Use the supervision opening public key and the random signature public key of the authorization service platform to verify the anonymous signature information;
[0087] After the signature verification is passed, the anonymous signature information is calculated and opened using the supervisory opening private key to obtain the device anonymous signature public key;
[0088] Use the device's anonymous signature public key to obtain the binding relationship corresponding to the public key, obtain the terminal device ID, and realize traceability supervision of the device.
[0089] In summary, the present invention provides a terminal authorization and authentication system and method based on anonymous signature, which realizes the identity authorization registration of the terminal device, the anonymous signature of the authentication information by the terminal device, the public verification of the signature information by the third-party application, and the opening and tracing of the anonymous signature information by the supervisor through the authorization service platform, thereby solving the problem of illegal linking of the terminal device by the application party. The anonymous signature process ensures that the terminal device cannot be linked, and enhances the security of the terminal device signature. The cryptographic collaborative calculation generates the device anonymous signature key information without the need for key transmission. The device anonymous signature private key signing process ensures the credibility of the verification result, and realizes the anonymous protection of the terminal device authorization and authentication based on the trusted authorization signature of the terminal device, the trusted verification of the third party, and the trusted traceability of the supervisor.
[0090] Those skilled in the art will appreciate that all or part of the process of the method in the above embodiment can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium, wherein the computer-readable storage medium is a disk, an optical disk, a read-only storage memory, or a random access memory, etc.
[0091] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by any technician familiar with the technical field within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.
Claims
1. A terminal authorization and authentication system based on anonymous signature, It is characterized in that include: Authorized service platforms, terminal devices and application parties; The authorization service platform is used to perform cryptographic collaborative calculations with the terminal device, generate a device anonymous signature public key on the authorization service platform side, and generate a device anonymous signature public-private key pair on the terminal device side; use the randomized signature private key of the authorization service platform to randomly sign the device anonymous signature public key to obtain a randomized signature value of the device anonymous signature public key; The terminal device uses the randomized signature public key of the authorization service platform to verify the randomized signature value, and anonymously signs the authentication information to obtain anonymous signature information; The application party is used to verify the anonymous signature information based on the randomized signature public key and the regulatory opening public key of the authorization service platform. If the verification is successful, the terminal device identity is allowed to enter.
2. According to claim 1, the terminal authorization and authentication system based on anonymous signature, It is characterized in that The authorization service platform includes a terminal anonymous authorization module and a terminal identity opening module; The terminal anonymous authorization module is used to generate the device anonymous signature public key, establish and store the binding relationship between the device anonymous signature public key and the terminal device ID, and use the randomized signature private key of the authorization service platform to randomly sign the device anonymous signature public key to obtain the randomized signature value of the device anonymous signature public key; The terminal identity opening module calculates and opens the anonymous signature information based on the supervision opening private key to obtain the device anonymous signature public key, and obtains the terminal device ID corresponding to the device anonymous signature public key based on the binding relationship to realize device supervision.
3. According to claim 2, the terminal authorization and authentication system based on anonymous signature, It is characterized in that The terminal anonymous authorization module generates the device anonymous signature public key by the following method: The terminal anonymous authorization module generates a randomized signature public-private key pair and a supervision-opening public-private key pair for the authorization service platform; receiving a terminal device registration request including a terminal device ID; Based on the randomized signature public key of the authorization service platform, cryptographic collaborative calculation is performed with the terminal device to obtain the anonymous signature public key of the device.
4. According to claim 2, the terminal authorization and authentication system based on anonymous signature, It is characterized in that The terminal identity opening module obtains the terminal device ID corresponding to the device anonymous signature public key by the following method: The terminal identity opening module receives the anonymous signature information sent by the application party; Use the supervision opening public key and the random signature public key of the authorization service platform to verify the anonymous signature information; After the signature verification is passed, the anonymous signature information is calculated and opened using the supervisory opening private key to obtain the device anonymous signature public key; Based on the device anonymous signature public key, the corresponding binding relationship is retrieved to obtain the corresponding terminal device ID.
5. According to claim 2, the terminal authorization and authentication system based on anonymous signature, It is characterized in that The terminal device includes an anonymous signature module; The anonymous signature module generates a device anonymous signature public-private key pair based on the cryptographic collaborative calculation result; and uses the randomized signature public key of the authorization service platform to verify the randomized signature value; Safely store the randomized signature value and the device anonymous signature private key; The authentication information is anonymously signed using the device's anonymous signature private key, randomized signature value, and public parameters.
6. The terminal authorization and authentication system based on anonymous signature according to claim 5, It is characterized in that The anonymous signature module calculates in collaboration with the terminal anonymous authorization module password based on the randomized signature public key, the supervision opening public key and the terminal device ID of the authorization service platform to obtain the device anonymous signature private key.
7. The terminal authorization and authentication system based on anonymous signature according to claim 1, It is characterized in that The application side includes an anonymous signature verification module; which is used to verify the anonymous signature information using the randomized signature public key and the supervisory opening public key of the authorization service platform.
8. A terminal authorization authentication method based on anonymous signature, It is characterized in that include: The terminal device sends a device registration request to the authorization service platform and performs cryptographic collaborative calculation with the authorization service platform; The authorization service platform uses the randomized signature private key of the authorization service platform to perform randomized signature on the device anonymous signature public key, obtains the randomized signature value of the device anonymous signature public key and sends it to the terminal device; Based on the result of the cryptographic collaborative calculation, the terminal device obtains the device anonymous signature public and private key pair, and the authorization service platform obtains the device anonymous signature public key; The terminal device verifies the randomized signature value using the randomized signature public key of the authorization service platform, and securely stores the randomized signature value and the device anonymous signature private key; The terminal device signs the authentication information using the device anonymous signature private key, the randomized signature value and the public parameters, obtains anonymous signature information and sends it to the application party; The application party uses the randomized signature public key and the supervision opening public key of the authorization service platform to verify the anonymous signature information, and provides corresponding services if the verification passes.
9. The terminal authorization authentication method based on anonymous signature according to claim 8, It is characterized in that The terminal device and the authorization service platform perform cryptographic collaborative calculation based on the terminal device ID, the authorization service platform randomized signature public key and the supervision opening public key; The cryptographic collaborative computing is a secure multi-party computing or a secure two-party computing based on cryptographic technology.
10. The terminal authorization authentication method based on anonymous signature according to claim 8, It is characterized in that It also includes terminal equipment supervision, including: During the terminal device registration phase, a binding relationship between the device anonymous signature public key and the terminal device ID is established through the authorization service platform and stored; The anonymous signature information is sent to the authorization service platform through the application party; Use the supervision opening public key and the random signature public key of the authorization service platform to verify the anonymous signature information; After the signature verification is passed, the anonymous signature information is calculated and opened using the supervisory opening private key to obtain the device anonymous signature public key; Use the device's anonymous signature public key to obtain the binding relationship corresponding to the public key, obtain the terminal device ID, and realize traceability supervision of the device.