Identity verification method based on anonymous certificate

By adopting anonymous credentials and fuzzy extractor technology in multi-factor identity authentication, the problem of privacy leakage of biometric data during transmission and storage is solved, and higher authentication security is achieved.

CN120034362APending Publication Date: 2025-05-23XINJIANG DIGITAL CERTIFICATE CERTIFICATION CENT (CO LTD)

Patent Information

Application Number
CN202510084571.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

There is a risk of privacy leakage in the existing multi-factor identity authentication method, and users' biometric data is easily leaked during transmission and storage.

Method used

Anonymous credential-based authentication method is adopted to convert bioprivate data into constant secret values ​​through a fuzzy extractor, and anonymous credential technology is used to ensure that users do not expose additional attributes when generating proofs.

Benefits of technology

It reduces the risk of user privacy data leakage, improves the security of the authentication process, and avoids the risk of privacy leakage caused by directly storing bioprivate data on the device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034362A_ABST
    Figure CN120034362A_ABST
Patent Text Reader

Abstract

The invention provides an identity verification method based on an anonymous certificate, which comprises an initialization step, an identifier generation step, a data acquisition step, a certificate issuing step, a data recovery step and an identity verification step, and designs a multi-factor authentication scheme for protecting user privacy based on a reusable fuzzy extractor and an anonymous certificate method. According to the method, the risk of user privacy data leakage is reduced, an anonymous credential method is adopted to ensure that the user does not expose additional attributes when generating the certification, so that the security of the authentication process is improved, and the privacy leakage risk caused by direct storage of biological privacy data in equipment is avoided by using a reusable fuzzy extractor, so that the user experience is improved. And the privacy security is improved. The method has the advantages that the privacy leakage risk is avoided, and the privacy safety can be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to an identity authentication method based on anonymous credentials. Background Art

[0002] Multi-factor authentication is an identity verification method used to improve system security by combining two or more independent verification factors to confirm the user's identity, thereby enhancing security. Traditional single-factor authentication methods (such as passwords) rely on only one verification factor and are vulnerable to security threats such as weak passwords, social engineering attacks, or credential leaks. Multi-factor authentication can significantly improve security by introducing multiple verification dimensions and is widely used in scenarios that require high security, such as online banking, enterprise networks, cloud services, etc.

[0003] Multi-factor authentication usually combines the following authentication factors: 1. Knowledge factor: information that the user knows, such as a password, PIN code, or answer to a security question. This is the easiest type of factor to break because users often choose simple or easy-to-guess passwords, and passwords may be leaked or cracked by malicious attackers; 2. Possession factor: a physical device owned by the user, such as a mobile phone, smart card, or one-time password generator. This type of factor relies on the user's physical control over a device. Common forms include sending SMS verification codes to the user's mobile phone or generating dynamic passwords through an App; 3. Biometric factor: a user's unique biometric features, such as fingerprints, irises, facial recognition, or voiceprints. This factor is unique and non-replicable, which increases security, but also raises concerns about the privacy leakage of biometric data. In multi-factor authentication, the service provider will only grant the user relevant permissions when all verification factors are passed.

[0004] However, there are still certain potential risks of privacy leakage in the multi-factor identity authentication method: 1. When applying for a service, users need to transmit their attribute information in plain text, which may leak privacy. For example, if a user sends his fingerprint data directly to a service provider, the fingerprint data may be leaked by a malicious service provider or intercepted by a man-in-the-middle attack, resulting in privacy leakage; 2. The biometric factors are stored locally on the user's device, and there is a risk of biometric factor leakage due to theft or attack on the device.

[0005] Anonymous credentials based on BBS+ signatures are a privacy-enhanced identity authentication technology that enables users to prove their identity or specific attributes without disclosing personal information or minimizing the disclosure of information. The BBS+ signature scheme (Boneh-Boyen-Shacham encrypted signature, referred to as BBS+) is an efficient anonymous credential technology, especially suitable for application scenarios that require privacy protection, such as distributed identity systems, digital identity authentication, and data privacy protection.

[0006] Fuzzy Extractor is a cryptographic technique designed to reliably generate consistent keys from imprecise, noisy data. This technique is particularly suitable for biometric data (such as fingerprints, irises, voiceprints, etc.) because these data may vary each time they are read and cannot be guaranteed to be completely consistent. Fuzzy Extractor is able to extract the same key from these slightly different inputs, allowing biometrics to be safely used in authentication and encryption applications without directly exposing the user's biometric information.

[0007] Therefore, there is an urgent need in the art to implement a secure multi-factor authentication method to avoid the risk of privacy leakage caused by the plain text transmission of user factors and the storage of biometric factors on user devices. Currently, no description or report of similar technology to the present invention has been found, and similar materials at home and abroad have not been collected. Summary of the invention

[0008] The present application provides an identity authentication method based on anonymous credentials to solve the problem that the existing identity authentication methods have the risk of privacy leakage and the privacy security cannot be guaranteed.

[0009] The present application provides an identity authentication method based on anonymous credentials, which specifically includes an initialization step, an identifier generation step, a data collection step, a credential issuance step, a data recovery step and an identity authentication step.

[0010] The initialization step is to generate public parameters for issuing and verifying anonymous credentials and a fuzzy extractor for extracting information from biometric privacy data when the network is initialized; the identifier generation step is that during the registration stage, the issuer randomly generates an m-bit first binary string ID for the user as a globally unique identifier; the data collection step is to perform a first collection of the user's biometric privacy data, define the privacy data collected for the first time as the first data, and convert the first data into a constant secret value through the fuzzy extractor; the credential issuance step is to verify the user's attribute set, and after the verification is passed, the issuer uses its own private key to issue an identity credential to the user; the data recovery step is to perform a second collection of the user's biometric privacy data, define the privacy data collected for the second time as the second data, and convert the second data into the secret value through the fuzzy extractor; the identity authentication step is that the verifier proposes an attribute statement, generates a zero-knowledge proof through the secret value and the credential, and determines whether the zero-knowledge proof satisfies the attribute statement. If so, the identity authentication is passed.

[0011] Furthermore, in the initialization step, the public parameters include the identity credential and the elliptic curve group G required for bilinear pairing. 1 ,G 2 ,GT and its generator g 1 ,g 2 ,g T , bilinear pairing For any a,b∈Z P and g∈G 1 ,h∈G 2 , there is e(g a ,h b )=e(g,h) ab , where the number of attributes of the identity credential is no greater than n; from the integer group Z modulo P P Randomly select an element SK and calculate PK = g 2 SK , generate a public-private key pair (PK, SK), from the elliptic curve group G 1 Randomly select n+1 elements from The public key PK and vector Composition of common parameters Broadcast to other nodes, the module P is composed of prime numbers.

[0012] Furthermore, in the initialization step, the fuzzy extractor adopts the BCH code as the error correction code of the fuzzy extractor, and sets a random number seed to initialize the random number generator, wherein the BCH code is an (m, t) error correction code, indicating that when an error not greater than t bits occurs in an m-bit binary string, the error correction code can achieve successful error correction.

[0013] Furthermore, the data collection step specifically includes a first collection step, a first calculation step, a second calculation step and a storage and deletion step.

[0014] The first collection step is to collect the user's biometric privacy data through a physical device, encode it into an m-bit second binary string w, and input the second binary string w into the fuzzy extractor; the first calculation step is to generate a binary string x with a length of m bits by using the random number generator through the fuzzy extractor, and randomly generate a BCH code c with the same length of n bits, and calculate the first XOR result of the binary string x and the error correction code c. The second calculation step is used to calculate the second XOR result of the binary string x and the input second binary string w. Wherein, R represents the secret value; the storage deletion step is to store the binary string (x, s) in the local device and delete the secret value R.

[0015] Furthermore, the certificate issuance step specifically includes an encryption step, a verification step and a certificate acquisition step.

[0016] The encryption step is to use the public parameter PP to encrypt the attribute set M d Encrypt to get the attribute set M h , where M d With M h The sum of the number of attributes is n, and the specific process of the encryption step is: for M h Each attribute m in i ,calculate Indicates calculation of power, m i will be converted into an integer. The exponentiation operation is completed on the elliptic curve field. i Represents the elliptic curve G 2 elements on the , and all m i The calculation result is multiplied to get the encrypted result Among them, the attribute set M d Contains the first binary string id; the verification step is to determine the attribute set M by zero-knowledge proof. h Any attribute m i Whether it satisfies m i ∈M h , and verify whether the user has the public attribute set M that he claims d If the verification is successful, the next step is to verify whether the user has the public attribute set M that he claims. d The formula is as follows

[0017] M d =M\M h

[0018] Where M = M 1 ,…,M n , M represents the attribute set held by the user;

[0019] The credential acquisition step is to issue the user identity credential by the issuer using its own private key SK. The calculation formula of the identity credential is:

[0020]

[0021] σ=(A,e,R)

[0022] Among them, e is the issuer randomly selected from group G 1 , σ represents the identity certificate, and e is the random element selected by the issuer from the group G. 1 A random element selected from .

[0023] Furthermore, the data recovery step specifically includes a second acquisition step, a first recovery step, a second recovery step and a third recovery step.

[0024] The second collection step is to collect the user's biometric privacy data through a physical device, encode it into an m-bit third binary string w', and input the third binary string w' into the fuzzy extractor; the first recovery step is to obtain the binary string (x, s) stored locally on the device through the fuzzy extractor, and calculate the third XOR result of the third binary string w' and s. Based on the third XOR result, c is recovered by the fuzzy extracted error correction code, and s represents the first XOR result; the second recovery step is used to calculate the fourth XOR result of s and c Restore the second binary string w; the third recovery step is used to calculate the fifth XOR result of x and w Recover the secret value R.

[0025] Furthermore, the identity authentication step specifically includes a statement submission step, a zero-knowledge proof generation step, and a verification judgment step.

[0026] The claim making step is used by the verifier to make a claim on the attributes in the user's attribute set. If the attribute satisfies the proposed claim, the next step is executed; the zero-knowledge proof generation step is for the user to generate a corresponding zero-knowledge proof based on his own attributes and identity credentials and send it to the verifier. The zero-knowledge proof generation formula is as follows:

[0027] alpha = 1 / a;

[0028] beta = 1 / b;

[0029] A'=A a ;

[0030]

[0031] z alpha =r alpha +c*alpha;

[0032] z beta =r beta +c*beta;

[0033] z e =r e +c*e;

[0034] z b =r b +c*b;

[0035]

[0036] Where H is a hash function; from the integer group Z modulo P P Randomly select elements a, b, r from alpha ,rbeta , r e ,r b , π represents the obtained zero-knowledge proof, A and B are just intermediate variables and have no practical significance; the verification judgment step is that after the verifier receives the proof π, he calculates And further calculate verify as well as Is it true? If so, the user has passed the verification.

[0037] The present application provides an identity authentication method based on anonymous credentials. Based on a reusable fuzzy extractor and an anonymous credential method, a multi-factor authentication scheme for protecting user privacy is designed, which reduces the risk of leakage of user privacy data. The anonymous credential method is used to ensure that the user does not expose additional attributes when generating proofs, thereby improving the security of the authentication process. By using a reusable fuzzy extractor, the risk of privacy leakage caused by directly storing biometric privacy data in the device is avoided, thereby improving privacy security. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0039] Figure 1 is a flow chart of the anonymous credential-based identity authentication method described in this embodiment;

[0040] Figure 2 is a flow chart of the data collection steps described in this embodiment;

[0041] Figure 3 is a flow chart of the steps for issuing a certificate according to the present embodiment;

[0042] Figure 4 is a flow chart of the data recovery steps described in this embodiment;

[0043] Figure 5 It is a flow chart of the identity authentication steps described in this embodiment. DETAILED DESCRIPTION

[0044] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.

[0045] The present application provides an identity authentication method based on anonymous credentials, and the system includes three nodes, namely, issuer, user and verifier. The issuer is responsible for user registration and credential issuance steps. When the user registers, a globally unique identifier is returned to the user for identifying the user's role in the system. When the credential is issued, the user is issued an anonymous credential after verifying the legitimacy of the user's attributes. After the user applies for the anonymous credential from the issuer, the user uses the credential to generate a zero-knowledge proof to prove the correctness of the declaration of the specific attribute, while ensuring that the privacy of other attributes is not leaked. The verifier is responsible for making declarations on certain attributes of the user, receiving the zero-knowledge proof provided by the user, and then verifying the validity of the proof.

[0046] like Figure 1 As shown, the anonymous credential-based identity authentication method specifically includes step S1) an initialization step, step S2) an identifier generation step, step S3) a data collection step, step S4) a credential issuance step, step S5) a data recovery step, and step S6) an identity authentication step.

[0047] Step S1) Initialization step: when the network is initialized, public parameters for issuing and verifying anonymous credentials and a fuzzy extractor for extracting information from biometric privacy data are generated. In this embodiment, during the system initialization phase, the issuer generates a pair of public and private keys (PK, SK) for issuing anonymous credentials, and generates a set of public parameters, which are broadcast to other nodes in the system. The user initializes the fuzzy extractor locally for subsequent privacy data collection and recovery processes.

[0048] In step S1) of initialization, the public parameters include the identity certificate and the elliptic curve group G required for bilinear pairing. 1 ,G 2 ,G T and its generator g 1 ,g 2 ,g T , bilinear pairing For any a,b∈Z P and g∈G 1 ,h∈G 2 , there is e(g a ,h b)=e(g,h) ab , wherein the number of attributes of the identity credential is not greater than n;

[0049] From the integer group Z modulo P P Randomly select an element SK and calculate PK = g 2 SK , generate a public-private key pair (PK, SK), from the elliptic curve group G 1 Randomly select n+1 elements from The public key PK and vector Composition of common parameters Broadcast to other nodes, the module P is composed of prime numbers.

[0050] In step S1) of initialization, the fuzzy extractor uses the BCH code as the error correction code of the fuzzy extractor, and sets a random number seed to initialize the random number generator, wherein the BCH code is an (m, t) error correction code, indicating that when an error not greater than t bits occurs in an m-bit binary string, the error correction code can achieve successful error correction.

[0051] Step S2) Identifier generation step: During the registration phase, the issuer randomly generates an m-bit first binary string ID for the user as a globally unique identifier. In this embodiment, after the system is initialized, the user registers with the issuer and obtains a globally unique identifier for identifying its role in the system. The identifier is used for communication between the user and other nodes in the system.

[0052] Step S3) Data collection step, first collect the user's biometric privacy data, define the privacy data collected for the first time as the first data, and convert the first data into a constant secret value through the fuzzy extractor. In this embodiment, the user inputs his biometric data (such as fingerprint, iris, etc.) through the fuzzy extractor to reduce the privacy leakage risk caused by directly storing the biometric data on the device. The biometric data is encoded to form a binary string w with a length of m bits. After being processed by the reusable fuzzy extractor, only two binary strings (x, s) with a length of m bits need to be stored on the device, and the generated secret value R is not retained in the device after use, thereby further enhancing privacy protection.

[0053] like Figure 2 As shown, step S3) the data collection step specifically includes step S31) a first collection step, step S32) a first calculation step, step S33) a second calculation step and step S34) a storage and deletion step.

[0054] Step S31) In the first collection step, after collecting the user's biometric privacy data through a physical device, the data is encoded into an m-bit second binary string w, and the second binary string w is input into the fuzzy extractor.

[0055] Step S32) A first calculation step is to generate a binary string x with a length of m bits by using the random number generator through the fuzzy extractor, and randomly generate a BCH code c with the same length of n bits, and calculate the first XOR result of the binary string x and the error correction code c.

[0056] Step S33) A second calculation step is to calculate a second XOR result of the binary string x and the second binary string w inputted. Wherein, R represents the secret value.

[0057] Step S34) Storage deletion step, storing the binary string (x, s) in a local device and deleting the secret value R, wherein the local device is a physical device such as a computer.

[0058] Step S4) Certificate issuance step, verifying the user's attribute set. After the verification is passed, the issuer uses its own private key to issue an identity certificate to the user.

[0059] like Figure 3 As shown, step S4) the certificate issuance step specifically includes step S41) an encryption step, step S42) a verification step and step S43) a certificate acquisition step.

[0060] Step S41) Encryption step, using the public parameter PP to encrypt the attribute set M d Encrypt to get the attribute set M h , where M d With M h The sum of the number of attributes is n, and the specific process of the encryption step is: for M h Each attribute m in i ,calculate Indicates calculation of power, m i will be converted into an integer. The exponentiation operation is completed on the elliptic curve field. i Represents the elliptic curve G 2 elements on the , and all m i The calculation result is multiplied to get the encrypted result Among them, the attribute set M d Contains the first binary string id, attribute set M hIncluding the secret value R generated by the fuzzy extractor, to avoid privacy leakage, the user will not transmit this data directly to the issuer. Instead, the user adopts blind issuance technology to ensure that the issuer cannot know M h After verifying all the attributes declared by the user, the issuer uses the private key SK to issue the corresponding certificate to the user through the BBS+ signature scheme.

[0061] Step S42) Verification step, through zero-knowledge proof, determine the attribute set M h Any attribute m i Whether it satisfies m i ∈M h , and verify whether the user has the public attribute set M that he claims d If the verification is successful, the next step is to verify whether the user has the public attribute set M that he claims. d The formula is as follows

[0062] M d =M\M h

[0063] Where M = M 1 ,…,M n , M represents the attribute set held by the user;

[0064] Step S43) Credential acquisition step, the issuer uses its own private key SK to issue the user identity credential, and the calculation formula of the identity credential is:

[0065]

[0066] σ=(A,e,R)

[0067] Among them, e is the issuer randomly selected from group G 1 , σ represents the identity certificate, and e is the random element selected by the issuer from the group G. 1 A random element selected from .

[0068] In this embodiment, zero-knowledge proof is essentially a protocol involving two or more parties, that is, a series of steps that two or more parties need to take to complete a task. The prover proves to the verifier and makes him believe that he knows or has a certain message, but the proof process cannot leak any information about the proven message to the verifier. A large number of facts have proved that zero-knowledge proof is very useful in cryptography. If zero-knowledge proof can be used for verification, it will effectively solve many problems. Zero-knowledge proof is a mature existing technology, and the specific proof process will not be described in detail.

[0069] Step S5) Data recovery step, collect the user's biometric privacy data for the second time, define the privacy data collected for the second time as the second data, and convert the second data into the secret value through the fuzzy extractor. In this embodiment, when the user inputs his biometric privacy data again, the encoding generates a binary string w' with a length of m bits. Since there may be errors in the collection process of biometric data such as fingerprints and irises, there may be differences between w' and the original binary string w. The user uses w' and the public value (x, s) stored in the fuzzy extractor to restore the original secret value R through the fuzzy extractor.

[0070] like Figure 4 As shown, step S5) the data recovery step specifically includes step S51) a second acquisition step, step S52) a first recovery step, step S53) a second recovery step and step S54) a third recovery step.

[0071] Step S51) In the second collection step, after collecting the user's biometric privacy data through a physical device, the data is encoded into an m-bit third binary string w', and the third binary string w' is input into the fuzzy extractor.

[0072] Step S52) The first recovery step is to obtain the binary string (x, s) stored locally in the device through the fuzzy extractor, and calculate the third XOR result of the third binary string w' and s Based on the third XOR result, c is recovered by the fuzzy extraction error correction code, and s represents the first XOR result. In this embodiment, the BCH code is used as the error correction code of the fuzzy extractor. The function of the BCH code is to recover the third XOR result. Restoring to c is a technical means well known to those skilled in the art and will not be described in detail here.

[0073] Step S53) The second recovery step is to calculate the fourth XOR result of s and c Recover the second binary string w;

[0074] Step S54) The third recovery step is to calculate the fifth XOR result of x and w. Recover the secret value R.

[0075] Step S6) Identity verification step: the verifier makes an attribute claim, generates a zero-knowledge proof through the secret value and the credential, and determines whether the zero-knowledge proof satisfies the attribute claim. If so, the identity verification is successful.

[0076] like Figure 5 As shown, step S6) the identity authentication step specifically includes step S61) the statement submission step, step S62) the zero-knowledge proof generation step and step S63) the verification judgment step.

[0077] Step S61) Statement submission step, the verifier submits a statement on the attributes in the user's attribute set. If the attribute satisfies the statement, the next step is executed. In this embodiment, whether the attribute in the user's attribute set satisfies the satisfaction condition of the statement is determined according to the requirements, for example, statement 1 =(m 1 =c 1 ,m 2 =c 2 ), specifically, for example, gender: male, age: 18 years old, etc.

[0078] Step S62) Zero-knowledge proof: The user generates a corresponding zero-knowledge proof based on his / her own attributes and identity credentials and sends it to the verifier. The zero-knowledge proof generation formula is as follows:

[0079] alpha = 1 / a;

[0080] beta = 1 / b;

[0081] A'=A a ;

[0082]

[0083] z alpha =r alpha +c*alpha;

[0084] z beta =r beta +c*beta;

[0085] z e =r e +c*e;

[0086] z b =r b +c*b;

[0087]

[0088] Where H is a hash function; from the integer group Z modulo P P Randomly select elements a, b, r from alpha ,r beta , r e ,r b , π represents the obtained zero-knowledge proof, A and B are just intermediate variables and have no practical significance;

[0089] Step S63) Verification and judgment step: after receiving the proof π, the verifier calculates And further calculate verify as well as Is it true? If so, the user has passed the verification.

[0090] The present application provides an identity authentication method based on anonymous credentials. Based on a reusable fuzzy extractor and an anonymous credential method, a multi-factor authentication scheme for protecting user privacy is designed, which reduces the risk of leakage of user privacy data. The anonymous credential method is used to ensure that the user does not expose additional attributes when generating proofs, thereby improving the security of the authentication process. By using a reusable fuzzy extractor, the risk of privacy leakage caused by directly storing biometric privacy data in the device is avoided, thereby improving privacy security.

[0091] The above is a detailed introduction to the identity authentication method based on anonymous credentials provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for general technical personnel in this field, according to the idea of ​​the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. An identity authentication method based on anonymous credentials, characterized in that: The specific steps include: Initialization step, when the network is initialized, public parameters for issuing and verifying anonymous credentials and fuzzy extractors for extracting information from biometric privacy data are generated; Identifier generation step: During the registration phase, the issuer randomly generates an m-bit first binary string id for the user as a globally unique identifier; A data collection step, first collecting the user's biometric privacy data, defining the privacy data collected for the first time as first data, and converting the first data into a constant secret value through the fuzzy extractor; The certificate issuance step verifies the user's attribute set. After the verification is passed, the issuer uses its own private key to issue an identity certificate to the user; A data recovery step, performing a second collection of the user's biometric privacy data, defining the second collected privacy data as second data, and converting the second data into the secret value through the fuzzy extractor; as well as In the identity authentication step, the verifier makes an attribute statement, generates a zero-knowledge proof through the secret value and the credential, and determines whether the zero-knowledge proof satisfies the attribute statement. If so, the identity authentication is passed.

2. The anonymous credential-based identity authentication method according to claim 1, wherein: In the initialization step, the public parameters include: The elliptic curve groups G1, G2, G required for the identity certificate and bilinear pairing T and its generators g1,g2,g T , bilinear pairing For any a,b∈Z P and g∈G1,h∈G2, we have e(g a ,h b )=e(g,h) ab , wherein the number of attributes of the identity credential is not greater than n; From the integer group Z modulo P P Randomly select an element SK from the equation and calculate PK=g2 SK , generate a public and private key pair (PK, SK), randomly select n+1 elements from the elliptic curve group G1 The public key PK and vector Composition of common parameters Broadcast to other nodes, the module P is composed of prime numbers.

3. The anonymous credential-based identity authentication method according to claim 1, wherein: In the initialization step, the fuzzy extractor uses the BCH code as the error correction code of the fuzzy extractor, and sets a random number seed to initialize the random number generator, wherein the BCH code is an (m, t) error correction code, which means that when an error not greater than t bits occurs in an m-bit binary string, the error correction code can achieve successful error correction.

4. The anonymous credential-based identity authentication method according to claim 1, wherein: The data collection step specifically includes the following steps: In the first collection step, after collecting the user's biometric privacy data through a physical device, the data is encoded into an m-bit second binary string w, and the second binary string w is input into a fuzzy extractor; In the first calculation step, the fuzzy extractor generates a binary string x with a length of m bits using the random number generator, and randomly generates a BCH code c with the same length of n bits, and calculates the first XOR result of the binary string x and the error correction code c. The second calculation step is to calculate the second XOR result of the binary string x and the second binary string w input Wherein, R represents the secret value; as well as The storage deletion step stores the binary string (x, s) in the local device and deletes the secret value R.

5. The anonymous credential-based identity authentication method according to claim 1, wherein: The certificate issuance step specifically includes the following steps: Encryption step: using the public parameter PP to encrypt the attribute set M d Encrypt to get the attribute set M h , where M d With M h The sum of the number of attributes is n, and the specific process of the encryption step is: for M h Each attribute m in i ,calculate Indicates calculation of power, m i will be converted into an integer. The exponentiation operation is completed on the elliptic curve field. i Represents the elements on the elliptic curve G2, and all m i The encrypted result is obtained by multiplying the calculation result of Among them, the attribute set M d Contains the first binary string id; Verification step, through zero-knowledge proof, judge the attribute set M h Any attribute m i Whether it satisfies m i ∈M h , and verify whether the user has the public attribute set M that he claims d If the verification is successful, the next step is to verify whether the user has the public attribute set M that he claims. d The formula is as follows M d =M\M h Where M=M1,…,M n , M represents the set of attributes held by the user; and The certificate acquisition step, the issuer uses its own private key SK to issue the user identity certificate, the calculation formula of the identity certificate is: σ=(A,e,R) Among them, e is a random element randomly selected by the issuer from the group G1, σ represents the identity credential, and e is a random element randomly selected by the issuer from the group G1.

6. The anonymous credential-based identity authentication method according to claim 1, wherein: The data recovery step specifically includes the following steps: In the second collection step, after collecting the user's biometric privacy data through a physical device, encode it into an m-bit third binary string w', and input the third binary string w' into a fuzzy extractor; The first recovery step is to obtain the binary string (x, s) stored locally on the device through the fuzzy extractor, and calculate the third XOR result of the third binary string w' and s Based on the third XOR result, c is recovered by using the fuzzy extracted error correction code, and s represents the first XOR result; The second recovery step is to calculate the fourth XOR result of s and c. Recover the second binary string w; The third recovery step is to calculate the fifth XOR result of x and w. Recover the secret value R.

7. The anonymous credential-based identity authentication method according to claim 1, wherein: The identity verification step specifically includes the following steps: In the claim making step, the verifier makes a claim about an attribute in the user's attribute set. If the attribute satisfies the claim, the next step is executed. Zero-knowledge proof generation step: The user generates the corresponding zero-knowledge proof based on his / her own attributes and identity credentials and sends it to the verifier. The zero-knowledge proof generation formula is as follows: alpha = 1 / a; beta = 1 / b; A′=A a ; z alpha =r alpha +c*alpha; from beta =r beta +c*beta; z e =r e +c*e; z b =r b +c*b; Where H is a hash function; from the integer group Z modulo P P Randomly select elements from Indicates the obtained zero-knowledge proof, A and B are just intermediate variables and have no practical significance; as well as Verification step: After receiving the proof π, the verifier calculates And further calculate verify as well as Is it true? If so, the user has passed the verification.

Citation Information

Patent Citations

  • User-centered multi-factor authentication method for multi-IDP aggregation

    CN114866255A

  • Internet of Things equipment authentication method and device based on zero-knowledge proof

    CN116707956A

  • System and method to integrate secure and privacy-preserving biometrics with identification, authentication, and online credential systems

    US10523654B1

Cited By

  • Personnel data verification method and system based on zero-knowledge proof

    CN121396490A