Anonymous authentication method capable of asking responsibility based on attribute encryption and block chain technology

By combining attribute encryption and zero-knowledge proof technology on the blockchain, accountable anonymous authentication is achieved, solving the problem of difficulty in tracing malicious behavior in an anonymous environment by traditional identity authentication, and improving the security and efficiency of identity authentication.

CN120034372APending Publication Date: 2025-05-23FUDAN UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510174761.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Traditional identity authentication methods have many challenges in security and privacy protection, especially the problem of malicious behavior being difficult to trace in anonymous environments.

Method used

The accountable anonymous authentication method based on attribute encryption and blockchain technology is adopted to realize user anonymous authentication and malicious user tracking through zero-knowledge proof (zk-SNARKs) and smart contracts, and blacklist information is stored on the blockchain.

Benefits of technology

The dual goals of anonymity and accountability are achieved, ensuring user privacy and security, avoiding single point of failure, improving the security and efficiency of identity authentication, and providing an immutable authentication history.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034372A_ABST
    Figure CN120034372A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of data security and access control, and particularly relates to a responsibility-questionable anonymous authentication method based on attribute encryption and a block chain technology. The invention provides a service access control method with anonymity and responsibility in combination with attribute encryption, a blacklist mechanism, zero-knowledge proof and a block chain technology. The system comprises a user, a service provider, an attribute authority, a tracking group, a block chain platform, an attribute management module, an anonymous authentication module and an accountability processing module. The service provider publishes service information and an access strategy to the block chain platform, the user obtains an attribute key through an attribute authority and generates anonymous authentication, and the block chain platform verifies the anonymous authentication through an intelligent contract; for a malicious user, a service provider can initiate a tracking request, and a tracking group collaboratively obtains the identity of the malicious user and updates a blacklist stored on a chain; the method effectively prevents the malicious user from accessing again while protecting the privacy of the user, and is suitable for decentralized identity management, access control, privacy protection and other scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data security and access control, and specifically relates to an accountable anonymous authentication method based on attribute encryption and blockchain technology. Background Art

[0002] With the rapid development of information technology, identity authentication plays a vital role in network security, data sharing, access control and other fields. Although traditional identity authentication methods such as username-password pairs, digital certificate authentication based on public key infrastructure and biometric recognition are widely used, they still face many challenges in security and privacy protection. For example, password authentication is vulnerable to brute force cracking and password leakage, digital certificate management is complex and has the risk of single point failure, and once biometric data is leaked, it will lead to permanent security risks.

[0003] Anonymous authentication mechanism has received extensive attention in the field of data security. This mechanism allows users to prove that they have certain access rights or meet specific conditions without exposing specific identity information. It is particularly suitable for application scenarios that need to protect user privacy. Attribute-based anonymous authentication further provides fine-grained access control on this basis. This technology authenticates users based on their attribute information without requiring users to directly expose their personal identity information. Accountability mechanism is a further extension of anonymous authentication, which aims to solve the problem that malicious behavior is difficult to trace in an anonymous environment. Traceability is an important part of the accountability mechanism, which can reveal the true identity of malicious users when necessary without affecting the privacy protection of normal users. Blacklist is also a way to implement the accountability mechanism, which prevents malicious users from further accessing protected resources by recording their identity information.

[0004] Zero-knowledge proof is a cryptographic technique that allows a prover to prove the truth of a statement to a verifier without revealing any additional information. Zero-knowledge proofs can be divided into interactive and non-interactive types. Interactive zero-knowledge proofs require multiple rounds of interaction between the prover and the verifier to complete the proof. Non-interactive zero-knowledge proofs allow proofs to be generated and verified in one go without requiring additional interaction. Succinct zero-knowledge proofs (zk-SNARKs) are a special type of non-interactive zero-knowledge proof that further achieves simplicity, has low verification overhead, and has a small proof size, making them suitable for efficient verification scenarios such as blockchain. In the present invention, zk-SNARKs are used to generate anonymous authentication, and users can prove that their attributes comply with access policies and are not on the blacklist without exposing specific information.

[0005] Blockchain technology is widely used in the field of data security due to its decentralized, tamper-proof and transparent characteristics. As a distributed ledger technology, blockchain ensures the integrity and transparency of information by maintaining and verifying data through multiple parties. Its decentralized architecture eliminates the reliance on a single trusted institution, making data storage and management safer and more reliable. All transaction records are stored in a chain in chronological order, and cryptographic mechanisms are used to ensure that they cannot be tampered with, ensuring the authenticity and traceability of the data. In the identity authentication scenario, blockchain can be used to store and manage public keys, authentication records and blacklist information, and realize automated verification through smart contracts. The present invention constructs an accountable anonymous authentication method based on blockchain, so that service providers can set access policies, and users can only obtain corresponding services if their attributes meet the access policies, while also providing accountability capabilities. Summary of the invention

[0006] The purpose of the present invention is to provide an accountable anonymous authentication method based on attribute encryption and blockchain technology, which can protect user privacy while providing accountability for malicious users. The present invention allows users to prove the legitimacy of their own attributes through zero-knowledge proofs (zk-SNARKs) while maintaining anonymity, and to track and blacklist malicious users when malicious behavior occurs, thereby achieving a secure, reliable, anonymous and accountable identity authentication and access control system.

[0007] The present invention proposes an accountable anonymous authentication method based on attribute encryption and blockchain technology. The accountable anonymous authentication method is implemented by an accountable anonymous authentication system. The system includes a user, an attribute authority, an attribute management module, an anonymous authentication module, a blockchain, a tracking group, a service provider and an accountability processing module; the user is bidirectionally connected to the attribute authority, the output end of the attribute authority is connected to the input end of the attribute management module, the output end of the user-generated anonymous authentication is connected to the input end of the anonymous authentication module, the input end of the blockchain is respectively connected to the user, the attribute authority, the tracking group and the service provider, the output end of the blockchain is connected to the anonymous authentication module and the accountability processing module, and the output end of the tracking group is connected to the accountability processing module; wherein: As the access subject of the service provider, the user assumes the role of the access requester. First, the user submits the application attribute to the attribute authority, and obtains the corresponding attribute key after the attribute authority reviews it. Then, the user uses the attribute key and his own secret value to generate an anonymous authentication through the anonymous authentication module, and uploads it to the blockchain for evidence storage and verification. If the anonymous authentication verification passes, it means that the user's attributes meet the access policy, and the user will obtain the permission to access the corresponding service provider, otherwise the access request will be rejected. As a resource provider, the service provider is responsible for setting access policies and publishing the requirements for accessing the service provider to the blockchain. The access policy defines the attribute conditions that users need to meet. Only users who have attributes that meet the access policy and are not blacklisted by the accountability processing module can obtain access rights. The attribute authority is a trusted institution responsible for managing user attributes in the accountable anonymous authentication system. There can be several independent attribute authorities in the accountable anonymous authentication system. Each attribute authority generates corresponding attribute public and private keys through its own attribute management module and publishes the corresponding attribute public key to the blockchain. The attribute authority is responsible for reviewing the user's application attributes and issuing attribute keys to qualified users. The tracking group is composed of several independent members. Its main function is to track the real identity of a user through collaboration when the user is identified as having malicious behavior. The tracking group adopts the threshold secret sharing method. Under normal circumstances, the identity of the user remains anonymous. Only when abuse or attack occurs can the identity information be revealed through collaboration. After the tracking is completed, the identity information of the malicious user will be added to the blacklist to restrict its further access to the service provider's resources and trigger additional accountability mechanisms when necessary. As a decentralized data storage and management platform, blockchain is mainly responsible for storing public keys, blacklists, access records, and anonymous authentication submitted by users, and verifies anonymous authentication, manages blacklists, and processes tracking requests through smart contracts. Blockchain provides an unalterable, open, and transparent storage environment to ensure the security and credibility of identity authentication and accountability processes. At the same time, by using blockchain smart contracts, the accountable anonymous authentication system can automatically perform anonymous authentication verification and blacklist updates, reducing human intervention and improving efficiency and security. The attribute management module adopts a multi-authority center attribute encryption algorithm, is responsible for generating the public and private keys and attribute keys of the attribute authority, and provides an attribute authority initialization and attribute key generation interface for the attribute authority to call, so as to support flexible management of user attributes; The main function of the anonymous authentication module is to ensure that users can prove that their attributes meet the access policy and are not blacklisted without revealing their identity information. Based on zero-knowledge proof technology, the anonymous authentication module allows users to generate anonymous authentication to prove that they have access rights while avoiding exposing any sensitive information. The accountability processing module is used for blacklist management and tracking operations to ensure that malicious users can be identified and restricted from accessing resources again. When abnormal behavior is found, the service provider initiates a tracking request, and the tracking group reveals the identity of the malicious user through the tracking execution interface. After the tracking is successful, the smart contract records the identity of the malicious user into the blacklist stored on the blockchain through the blacklist update interface to prevent the malicious user from accessing resources again.

[0008] In the present invention, the anonymous authentication module provides an anonymous authentication initialization interface, an anonymous authentication generation interface and an anonymous authentication verification interface.

[0009] In the present invention, the accountability processing module includes a tracking group initialization interface, a blacklist initialization interface, a tracking execution interface and a blacklist update interface.

[0010] In the present invention, the attribute management module provides an attribute authority initialization interface and an attribute key generation interface.

[0011] The workflow of the authentication method proposed by the present invention is as follows: (1) Initialize the accountable anonymous authentication system, complete the blockchain node joining and smart contract deployment, and use the anonymous authentication module and accountability processing module to perform initialization operations, and execute the anonymous authentication and blacklist initialization algorithms; (2) User initialization: the user generates a secret value and a unique identity for subsequent identity authentication; (3) The attribute authority completes initialization through the attribute management module, generates attribute public and private keys, and uploads the attribute public keys to the chain; (4) The tracking group performs tracking group initialization through the accountability processing module. Several independent members form the tracking group. Each member holds part of the tracking group private key and uploads the tracking group public key to the chain. (5) The user submits an attribute application to the attribute authority. After verifying the user's qualifications, the attribute authority generates the corresponding attribute key through the attribute management module and issues it to the user; (6) The service provider publishes service information on the blockchain, including basic service information and access policies, so that users can apply for relevant attributes and generate certification based on the access policies; (7) The user uses his own secret value, unique identifier and attribute key to execute the anonymous authentication generation algorithm through the anonymous authentication module, and uploads the generated anonymous authentication to the blockchain; (8) The blockchain platform verifies the validity of the anonymous authentication submitted by the user through a smart contract. Users with valid authentication can obtain access rights, otherwise access is denied; (9) For malicious users, the service provider submits a tracking request to the blockchain. The tracking group members perform tracking operations through the accountability processing module. After obtaining the identity of the malicious user, they call the blacklist management interface to add the malicious user to the blacklist stored in the blockchain to prevent subsequent access.

[0012] The beneficial effects of the present invention are as follows: the present invention combines attribute encryption, zero-knowledge proof, blacklist and blockchain technology to achieve the dual goals of anonymity and accountability. Using zero-knowledge proof technology, users can perform identity authentication without exposing their identities, ensuring user privacy and security; through blockchain technology and multi-attribute authority architecture, single point failures are avoided, and stability and security are improved; when malicious behavior is discovered, the tracking group can track the real identity of malicious users through collaboration and update the blacklist to prevent them from accessing the service again; using smart contracts to implement anonymous authentication verification and blacklist management, the efficiency of authentication is improved and the cost of manual intervention is reduced; all public keys, blacklists and authentication information are stored in the blockchain to ensure that the data cannot be tampered with and provide a traceable authentication history. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 It is a diagram of the system architecture of the present invention.

[0014] Figure 2 The figure is a diagram of the working process of the system of the present invention. DETAILED DESCRIPTION

[0015] The present invention proposes an accountable anonymous authentication method based on attribute encryption and blockchain technology. The following is a further introduction to the system of the present invention through a specific example: Embodiment 1: The blockchain is responsible for receiving information such as public keys, service access policies, anonymous authentication, and blacklists, and storing them on the chain. At the same time, the legality of anonymous authentication is verified through smart contracts, and blacklist updates are performed. The anonymous authentication, attribute management, and accountability processing modules are installed as clients in the local environments of users, attribute authorities, and tracking groups, respectively, while the verification service of the anonymous authentication module and the blacklist update service of the accountability processing module are called by smart contracts on the blockchain.

[0016] like Figure 1 As shown in the figure, the attribute authority generates the attribute public and private keys through the attribute management module, the user applies to the attribute authority to obtain the attribute key, and uses the attribute key to generate an anonymous authentication through the anonymous authentication module and submit it to the blockchain for verification. The smart contract on the blockchain verifies whether the anonymous authentication meets the access policy published on the chain by the service provider through the anonymous authentication module. If the verification is passed, the user can access the service. When the user has malicious behavior, the service provider initiates a request to track the malicious user to the blockchain. The tracking group generates tracking clues through the accountability processing module, collaborates to restore the identity of the malicious user and submits the tracking results to the blockchain. The smart contract executes the operation of updating the blacklist through the accountability processing module.

[0017] like Figure 2As shown, the present invention involves users, service providers, attribute authorities and tracking groups. The workflow of the method of the present invention can be divided into eight main links, and the specific steps are as follows: (1) Global initialization At the system startup stage, the blockchain network is first deployed, and the smart contract is installed and instantiated. Subsequently, the system generates global parameters and executes anonymous authentication and blacklist initialization algorithms. The anonymous authentication initialization algorithm mainly executes the initial setting algorithm of zero-knowledge proof, while the blacklist initialization algorithm mainly builds an accumulator for managing the blacklist to efficiently store and update malicious user information.

[0018] (2) User initialization When a user first joins the system, they need to complete initialization. The user generates a unique identity through the anonymous authentication module and creates a secret value related to their identity. The user's unique identity is used for anonymous authentication and tracking operations, while the secret value is used as a private credential and is only held by the user to ensure the security and non-repudiation of the authentication process.

[0019] (3) Initialization of attribute authority The attribute authority is the core organization that manages user attributes. It adopts a distributed architecture, and users can apply for corresponding attribute keys from different attribute authorities. During initialization, the attribute authority generates public and private keys and publishes the attribute public key to the blockchain for users and service providers to query.

[0020] (4) Tracking group initialization The tracking group is composed of multiple independent members, whose responsibility is to track the identity of users when they are found to have malicious behavior. In the initialization phase, the tracking group members jointly generate the tracking group public key, and each holds a part of the tracking group private key to ensure the fairness and security of the tracking process. The tracking group public key is stored in the blockchain.

[0021] (5) User application attributes After completing the initialization, the user submits an attribute application to the attribute authority. The attribute authority reviews the information submitted by the user and, after confirming that the conditions are met, generates the corresponding attribute key through the attribute management module and issues it to the user. The attribute key is the key credential for the user to prove the compliance of his or her attributes in the subsequent anonymous authentication process.

[0022] (6) Service providers publish access requirements As a resource provider, the service provider is responsible for setting access policies and publishing service access requirements to the blockchain. All users can query the access conditions of the service on the blockchain and determine whether they meet the policy requirements.

[0023] (7) User anonymous authentication generation and submission When a user wants to access a service, he needs to use parameters such as secret values, unique identifiers, and attribute keys to generate an anonymous authentication using zero-knowledge proof technology. This anonymous authentication proves that the user meets the attribute requirements of the access policy and is not on the blacklist, while not exposing his real identity information. The user then uploads the anonymous authentication to the blockchain for verification.

[0024] (8) Blockchain verification and anonymous authentication The blockchain platform runs smart contracts to verify the anonymous authentication submitted by the user. The smart contract checks whether the user's anonymous authentication complies with the access policy and confirms that the user is not blacklisted. After successful verification, the blockchain returns the verification result to the service provider, who decides whether to allow the user to access the corresponding resources based on it.

[0025] (9) Accountability of Malicious Users and Blacklist Management During the process of user access to the service, if malicious behavior is detected in the user, the service provider can initiate a tracking request, notify the tracking group members through the smart contract, and track the malicious user. During the tracking process, multiple tracking group members need to collaborate to calculate to restore the real identity of the malicious user. The identity of the malicious user will only be restored when the trackers exceeding the threshold agree to reveal their identities to ensure the fairness of accountability. After the tracking is successful, the tracking group submits the identity information of the malicious user to the blockchain, and the smart contract automatically executes the blacklist update operation to prevent the user from continuing to access resources. The blacklist information can be used as a reference for all service providers to decide whether to restrict the user's access rights to other services. Depending on the severity of the malicious behavior, the service provider can further take additional accountability measures, such as prohibiting the user from applying for new attribute keys.

Claims

1. An accountable anonymous authentication method based on attribute encryption and blockchain technology, characterized in that The accountable anonymous authentication method is implemented by an accountable anonymous authentication system, which includes a user, an attribute authority, an attribute management module, an anonymous authentication module, a blockchain, a tracking group, a service provider, and an accountability processing module; the user is bidirectionally connected to the attribute authority, the output end of the attribute authority is connected to the input end of the attribute management module, the output end of the user-generated anonymous authentication is connected to the input end of the anonymous authentication module, the input end of the blockchain is respectively connected to the user, the attribute authority, the tracking group, and the service provider, the output end of the blockchain is respectively connected to the anonymous authentication module and the accountability processing module, and the output end of the tracking group is connected to the accountability processing module; wherein: As the access subject of the service provider, the user assumes the role of the access requester. First, the user submits the application attribute to the attribute authority, and obtains the corresponding attribute key after the attribute authority reviews it. Then, the user uses the attribute key and his own secret value to generate an anonymous authentication through the anonymous authentication module, and uploads it to the blockchain for evidence storage and verification. If the anonymous authentication verification passes, it means that the user's attributes meet the access policy, and the user will obtain the permission to access the corresponding service provider, otherwise the access request will be rejected. As a resource provider, the service provider is responsible for setting access policies and publishing the requirements for accessing the service provider to the blockchain. The access policy defines the attribute conditions that users need to meet. Only users who have attributes that meet the access policy and are not blacklisted by the accountability processing module can obtain access rights. The attribute authority is a trusted institution responsible for managing user attributes in the accountable anonymous authentication system. There can be several independent attribute authorities in the accountable anonymous authentication system. Each attribute authority generates corresponding attribute public and private keys through its own attribute management module and publishes the corresponding attribute public key to the blockchain. The attribute authority is responsible for reviewing the user's application attributes and issuing attribute keys to qualified users. The tracking group is composed of several independent members. Its main function is to track the real identity of a user through collaboration when the user is identified as having malicious behavior. The tracking group adopts the threshold secret sharing method. Under normal circumstances, the identity of the user remains anonymous. Only when abuse or attack occurs can the identity information be revealed through collaboration. After the tracking is completed, the identity information of the malicious user will be added to the blacklist to restrict its further access to the service provider's resources and trigger additional accountability mechanisms when necessary. As a decentralized data storage and management platform, blockchain is mainly responsible for storing public keys, blacklists, access records, and anonymous authentication submitted by users, and verifies anonymous authentication, manages blacklists, and processes tracking requests through smart contracts. Blockchain provides an unalterable, open, and transparent storage environment to ensure the security and credibility of identity authentication and accountability processes. At the same time, by using blockchain smart contracts, the accountable anonymous authentication system can automatically perform anonymous authentication verification and blacklist updates, reducing human intervention and improving efficiency and security. The attribute management module adopts a multi-authority center attribute encryption algorithm, is responsible for generating the public and private keys and attribute keys of the attribute authority, and provides attribute authority initialization and attribute key generation interfaces for attribute authority to call, so as to support flexible management of user attributes; The main function of the anonymous authentication module is to ensure that users can prove that their attributes meet the access policy and are not blacklisted without revealing their identity information. Based on zero-knowledge proof technology, the anonymous authentication module allows users to generate anonymous authentication to prove that they have access rights while avoiding exposing any sensitive information. The accountability processing module is used for blacklist management and tracking operations to ensure that malicious users can be identified and restricted from accessing resources again. When abnormal behavior is found, the service provider initiates a tracking request, and the tracking group reveals the identity of the malicious user through the tracking execution interface. After the tracking is successful, the smart contract records the identity of the malicious user into the blacklist stored on the blockchain through the blacklist update interface to prevent the malicious user from accessing resources again.

2. According to claim 1, a method for accountable anonymous authentication based on attribute encryption and blockchain technology is characterized in that The anonymous authentication module provides anonymous authentication initialization interface, anonymous authentication generation interface and anonymous authentication verification interface.

3. According to claim 1, a method for accountable anonymous authentication based on attribute encryption and blockchain technology is characterized in that The accountability processing module includes the tracking group initialization interface, the blacklist initialization interface, the tracking execution interface and the blacklist update interface.

4. According to claim 1, a method for accountable anonymous authentication based on attribute encryption and blockchain technology is characterized in that The attribute management module provides an attribute authority initialization interface and an attribute key generation interface.

5. According to claim 1, the accountable anonymous authentication method based on attribute encryption and blockchain technology is characterized in that: The workflow of this authentication method is as follows: (1) Initialize the accountable anonymous authentication system, complete the blockchain node joining and smart contract deployment, and use the anonymous authentication module and accountability processing module to perform initialization operations, and execute the anonymous authentication and blacklist initialization algorithms; (2) User initialization: the user generates a secret value and a unique identity for subsequent identity authentication; (3) The attribute authority completes initialization through the attribute management module, generates attribute public and private keys, and uploads the attribute public keys to the chain; (4) The tracking group performs tracking group initialization through the accountability processing module. Several independent members form the tracking group. Each member holds part of the tracking group private key and uploads the tracking group public key to the chain. (5) The user submits an attribute application to the attribute authority. After verifying the user's qualifications, the attribute authority generates the corresponding attribute key through the attribute management module and issues it to the user; (6) The service provider publishes service information on the blockchain, including basic service information and access policies, so that users can apply for relevant attributes and generate certification based on the access policies; (7) The user uses his own secret value, unique identifier and attribute key to execute the anonymous authentication generation algorithm through the anonymous authentication module, and uploads the generated anonymous authentication to the blockchain; (8) The blockchain platform verifies the validity of the anonymous authentication submitted by the user through a smart contract. Users with valid authentication can obtain access rights, otherwise access is denied; (9) For malicious users, the service provider submits a tracking request to the blockchain. The tracking group members perform tracking operations through the accountability processing module. After obtaining the identity of the malicious user, they call the blacklist management interface to add the malicious user to the blacklist stored in the blockchain to prevent subsequent access.