Strong non-linkable password-free authentication method supporting global revocation
By adopting deterministic key derivation mechanism and global revocation mechanism in the FIDO2 security model, the problems of privacy protection and key management in the existing technology are solved, efficient key derivation and convenient revocation are achieved, and the security and user experience of the FIDO2 standard are improved.
Patent Information
- Application Number
- CN202510318979.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-06-10
AI Technical Summary
The existing FIDO2 security model does not value privacy and is only applicable tokens that store keys locally. External storage keys lead to privacy and management issues, and the existing key revocation mechanism is inefficient.
The deterministic key derivation mechanism is adopted to form a revocation key through public keys, chain codes and variables, and realize a global revocation mechanism, supporting password-free authentication and multi-factor authentication, and enhancing privacy protection and key management.
It realizes efficient key derivation, complete privacy protection and convenient key revocation, improving the security and user experience of the FIDO2 standard.
Smart Images

Figure CN120128330A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security, and particularly relates to a strong unlinkable passwordless authentication method supporting global revocation. Background Art
[0002] In the digital age, the security and privacy of online authentication are of utmost importance. The FIDO2 standard uses a hardware token for online authentication, and the WebAuthn protocol is responsible for the registration and authentication processes. However, the existing FIDO2 security model has defects, does not pay attention to privacy, and is only applicable to tokens with locally stored keys, while the actual external storage key method (key derivation and encapsulation) brings privacy and management problems.
[0003] In the application of FIDO2, key management and privacy protection are crucial. Although the external storage key solves the storage problem, it brings new risks. For example, key encapsulation may cause user sessions to be associated and privacy to be leaked, and key derivation also has security and privacy risks. At the same time, when the token is lost or stolen, the existing key revocation mechanism requires users to log in to the server one by one, which is inefficient.
[0004] Therefore, researchers introduced the BIP32 deterministic key derivation mechanism in the field of cryptocurrency. BIP32 can compactly store multiple keys and derive new key pairs based on the master key and chain code. Aiming at the problem that the existing such methods can only meet weak unlinkability, the BIP32-SU scheme improved and optimized on this basis adapts to the FIDO2 standard, realizes efficient key derivation, perfect privacy protection, and convenient key revocation, and strongly supports the secure application of the FIDO2 standard. Summary of the Invention
[0005] The purpose of the present invention is to provide a strong unlinkable passwordless authentication method supporting global revocation through technologies such as passwordless authentication, deterministic key derivation mechanism, global revocation mechanism, and multi-factor authentication, aiming to solve the security risks of traditional password authentication and protect user privacy, the lack of a global revocation mechanism in passwordless authentication, and the problem that the existing such methods can only meet weak unlinkability.
[0006] To achieve the above object, the technical solution of the present invention is: A strong unlinkable passwordless authentication method supporting global revocation, which adopts a deterministic derived key mechanism and uses a public key, a chain code, and a variable to form a revocation key. These three values of the public key, the chain code, and the variable can uniquely identify all the credential public keys generated by the token. After the revocation key is published, any server can check whether the stored credentials need to be revoked according to the revocation key, enabling the administrator to immediately revoke the permissions of all sub-keys, i.e., global revocation, through the master key, without the need for step-by-step operations, avoiding the risk diffusion after the key leakage, and achieving strong unlinkability through double encryption and parameter transformation, strict identity authentication and session authentication, and the use of randomization techniques and encryption functions.
[0007] In an embodiment of the present invention, the method includes a registration process, which is specifically as follows:
[0008] The token calls Gen to generate a master key;
[0009] The server calls Rchall to generate a challenge value and a status;
[0010] The client obtains the challenge value from the server and calls Rcomm to generate a message;
[0011] The token obtains the server identifier and the message from the client, calls Rresp to generate a response and a credential identifier, and sends them to the server through the client;
[0012] After the server obtains the response and the credential identifier from the client, it calls Rcheck. If the output is 0, it does not save the credential. Otherwise, the server saves the credential in the registration context.
[0013] In an embodiment of the present invention, the method further includes an authentication process, which is specifically as follows:
[0014] The server calls Achall to generate a challenge value and a status;
[0015] The client obtains the challenge value and the credential identifier from the server and calls Acomm to generate a message;
[0016] The token obtains the server identifier, the credential identifier, and the message from the client, calls Aresp to generate a response, and sends it to the server through the client;
[0017] After the server obtains the response from the client, it calls Acheck. If the output is 0, the authentication fails. Otherwise, the server accepts the authentication request.
[0018] In an embodiment of the present invention, the method further includes an execution of the global revocation process, which is specifically as follows:
[0019] The token calls Revoke to generate a revocation key and sends the revocation key to each server;
[0020] After the server obtains the revocation key from the token, it calls CheckCred. If the output is 1, it means that the key corresponding to the credential needs to be revoked; otherwise, it means that the key corresponding to the credential does not need to be revoked.
[0021] In an embodiment of the present invention, the specific implementation steps of the registration process are as follows:
[0022] S1. Master key generation Gen: Taking a key pair (sk 0 , pk 0 ), a chain code ch, a variable lrev, and a seed seed as inputs, and outputting the master key msk of the token = (sk 0 , pk 0 , ch, seed, lrev);
[0023] S2. Random registration challenge generation Rchall: Taking the server identifier id S as an input, and generating a random number and outputting a challenge value c = (id S , rs) and a status st = (id S , rs), indicating random selection;
[0024] S3. Deterministic registration command creation Rcomm: Taking the server identifier id S and the challenge value c as inputs. If id ≠ id S , then terminate, where id is the server identity identifier saved by the client; otherwise, output a message M r = H 0 (rs);
[0025] S4. Random registration response Rresp: Taking the master key msk, the server identifier id S and the message M r as inputs, calculating r = Enc(ch, lrev) and cid = Enc(seed, (id S , r)), setting lrev = r, calculating sk = SRerand(sk 0 , H 1 (pk 0 , ch, r, id S )) and pk = PRerand(pk 0 , H 1 (pk 0 , ch, r, id S )), setting m = (H 0 (id S ), cid, pk, M r), calculate coins = H 1 (seed, m) and σ = Sig(sk, m; coins), output the credential identifier cid and the response R r = (pk, σ); where Enc is a symmetric encryption function, SRerand is a private key re-randomization function, PRerand is a public key re-randomization function, and sig is a signature function;
[0026] S5. Deterministic registration check Rcheck: Take the status st, the credential identifier cid and the response R r as input, let m = (H 0 (id S ), cid, pk, M r ), calculate b = Ver(pk, σ, m), if b = 0, then terminate, otherwise output the registration context rcs S [cid] = pk, where Ver is a signature verification function.
[0027] In an embodiment of the present invention, the authentication process is specifically implemented as follows:
[0028] S6. Random authentication challenge generation Achall: Take the server identifier id S as input, and generate a random number Output the challenge value c = (id S , rs) and the status st = (id S , rs);
[0029] S7. Deterministic authentication command creation Acomm: Take the server identifier id S and the challenge value c as input, if id ≠ id S , then terminate, where id is the server identifier saved by the client, otherwise output the message M a = H 0 (rs), H 0 (·) is a hash function;
[0030] S8. Random authentication response Aresp: Take the master key msk, the server identifier id S , the credential identifier cid and the message M a as input, calculate (id, r) = Dec(cid, seed), compare id and id S , if id ≠ id S , then terminate, otherwise calculate sk = SRerand(sk 0 , H 1 (pk 0 , ch, r, id S )), let m = (H 0(id S ), M a ), compute coins = H 1 (seed, m) and σ = Sig(sk, m; coins), and output the response R a = σ; where Dec is the decryption function and H 1 (·) is the hash function;
[0031] S9, Deterministic authentication check Acheck: Take the state st, the registration context rcs S , the credential identifier cid, and the response R a as inputs, compute pk = rcs S [cid], let m = (H 0 (id S ), M a ), and output b = Ver(pk, σ, m).
[0032] In an embodiment of the present invention, the specific implementation steps of executing the global revocation process are as follows:
[0033] S10, Generate the revocation key Revoke: Take the master key msk as the input, and output the revocation key rk = (pk 0 , ch, lrev);
[0034] S11, Credential check CheckCred: Take the server identifier id S , the credential cred stored on the server, and the revocation key rk as inputs, compute r = Enc(ch, lrev) and pk' = PRerand(pk 0 , H 1 (pk 0 , ch, r, id S ))), if pk' = pk, output 1, indicating that the key corresponding to this credential needs to be revoked, otherwise output 0, indicating that the key corresponding to this credential does not need to be revoked.
[0035] The present invention also provides an electronic device, which includes a processor and a memory. Among them, the memory stores a computer program. When the computer program is executed by the processor, the processor is caused to execute the method steps as described in any one of the above.
[0036] The present invention also provides a strong unlinkable passwordless authentication system supporting global revocation, including a memory, a processor, and computer program instructions stored on the memory and capable of being run by the processor. When the processor runs the computer program instructions, the method steps as described in any one of the above can be implemented.
[0037] The present invention also provides a computer-readable storage medium, on which computer program instructions capable of being run by a processor are stored. When the processor runs the computer program instructions, the method steps as described in any of the above can be implemented.
[0038] Compared with the prior art, the present invention has the following beneficial effects:
[0039] In the traditional solution, when revoking a user's permission, it is necessary to disable sub-keys one by one or replace the master key, which is cumbersome to operate and may affect other users. There is a mathematical relationship between the sub-keys generated by hierarchical derivation, and the on-chain analysis tool can identify the transactions of the same user through the address pattern, resulting in privacy leakage (such as Bitcoin address clustering attack).
[0040] The present invention adopts a deterministic derived key mechanism, using the public key pk0, the chain code ch, and the variable lrev to form a revocation key. These three values can uniquely identify all the credential public keys generated by the token. After the revocation key is published, any server can check whether the stored credentials need to be revoked according to the revocation key. Therefore, the administrator can immediately revoke the permissions of all sub-keys (global revocation) through the master key, without the need for step-by-step operations, avoiding the risk diffusion after the key leakage. And through double encryption and parameter transformation, strict identity authentication and session authentication, and the use of specific randomization techniques and encryption functions, strong unlinkability is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 It is a flowchart of an implementation when registering for the present invention, including three entities: a token, a client, and a server
[0042] Figure 2 It is a flowchart of an implementation when authenticating and performing global revocation for the present invention, including three entities: a token, a client, and a server. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0043] The following describes the present solution in detail in combination with embodiments and the accompanying drawings. The following implementation embodiments only represent one possible implementation manner of the present invention, not all possible implementation embodiments, and do not limit the present invention.
[0044] The present invention provides a strong unlinkable passwordless authentication method supporting global revocation. It adopts a deterministic derived key mechanism, uses a public key, a chain code, and a variable to form a revocation key. These three values, namely the public key, the chain code, and the variable, can uniquely identify all the credential public keys generated by the token. After the revocation key is released, any server can check whether the stored credentials need to be revoked based on the revocation key, enabling the administrator to immediately revoke the permissions of all sub-keys through the master key, i.e., global revocation, without the need for step-by-step operations, avoiding the risk diffusion after key leakage. Moreover, through double encryption and parameter transformation, strict identity authentication and session authentication, and the use of randomization techniques and encryption functions, strong unlinkability is achieved.
[0045] The following is the specific implementation process of the present invention.
[0046] 1. Symbols and Definitions
[0047] p: Large prime number.
[0048] Z p : Finite field containing p elements, i.e., the set {0, 1, 2,..., p - 1}.
[0049] sk 0 : Private key randomly selected from the non-zero elements of the finite field Z p , where p is the order of the elliptic curve.
[0050] pk 0 : Corresponding public key, obtained through the generator g of the elliptic curve and the point multiplication operation on the elliptic curve, i.e.,
[0051] ch: Chain code, a value randomly selected from {0, 1} λ , used for key derivation and subsequent global revocation.
[0052] lrev: Component of the revocation key, used to generate the credential identifier and subsequent global revocation.
[0053] seed: Seed, a value randomly selected from {0, 1} λ , making the signature random.
[0054] r: Intermediate variable, temporarily saving the credential identifier and the variable lrev.
[0055] Randomly and uniformly selected from the set.
[0056] H 0 (·): Hash function, converting the server identifier id S and the variable rs into a hash value of a fixed length, used to construct the message m.
[0057] H1 (·): A hash function used to generate a key or signature random number.
[0058] Enc(·): The symmetric encryption of a message by an encryptor.
[0059] Dec(·): The symmetric decryption of a ciphertext by a decryptor.
[0060] SRerand(·): A function for private key re-randomization.
[0061] PRerand(·): A function for public key re-randomization.
[0062] sig(·): The signature of a message by a signer.
[0063] Ver(·): Verify the signature of a message.
[0064] 2. A Strong Unlinkable Passwordless Authentication Method Supporting Global Revocation
[0065] Figure 1 This is a flowchart of an implementation during the registration of the present invention, including three entities: a token, a client, and a server. First, the token calls Gen to generate a master key. Then, the server calls Rchall to generate a challenge value and a status. Next, the client obtains the challenge value from the server and calls Rcomm to generate a message. Then, the token obtains the server identifier and the message from the client, calls Rresp to generate a response and a credential identifier, and sends them to the server through the client. Finally, after the server obtains the response and the credential identifier from the client, it calls Rcheck. If the output is 0, the credential is not saved; otherwise, the server saves the credential in the registration context.
[0066] Figure 2 This is a flowchart of an implementation during the authentication and global revocation execution of the present invention. It includes three entities: a token, a client, and a server. First, the server calls Achall to generate a challenge value and a status. Next, the client obtains the challenge value and the credential identifier from the server and calls Acomm to generate a message. Then, the token obtains the server identifier, the credential identifier, and the message from the client, calls Aresp to generate a response, and sends it to the server through the client. Finally, after the server obtains the response from the client, it calls Acheck. If the output is 0, the authentication fails; otherwise, the server accepts the authentication request. During the global revocation execution, first, the token calls Revoke to generate a revocation key and sends the revocation key to each server. Then, after the server obtains the revocation key from the token, it calls CheckCred. If the output is 1, it means the key corresponding to this credential needs to be revoked; otherwise, the output is 0, indicating that the key corresponding to this credential does not need to be revoked.
[0067] A strong unlinkable passwordless authentication method supporting global revocation in this example mainly includes 11 parts: master key generation (Gen), random registration challenge generation (Rchall), deterministic registration command creation (Rcomm), random registration response (Rresp), deterministic registration check (Rcheck), random authentication challenge generation (Achall), deterministic authentication command creation (Acomm), random authentication response (Aresp), deterministic authentication check (Acheck), revocation key generation (Revoke), and credential check (CheckCred). Specifically as follows:
[0068] S1. Master key generation (Gen): Taking a key pair (sk 0 , pk 0 ), a chain code ch, a variable lrev, and a seed seed as inputs, and outputting the master key msk of the token = (sk 0 , pk 0 , ch, seed, lrev).
[0069] S2. Random registration challenge generation (Rchall): Taking the server identifier id S as an input, and generating a random number and outputting the challenge value c = (id S , rs) and the status st = (id S , rs).
[0070] S3. Deterministic registration command creation (Rcomm): Taking the server identifier id S and the challenge value c as inputs, if id ≠ id S , then terminate, where id is the server identity identifier saved by the client, otherwise output the message M r = H 0 (rs).
[0071] S4. Random registration response (Rresp): Taking the master key msk, the server identifier id S and the message M r as inputs, calculating r = Enc(ch, lrev) and cid = Enc(seed, (id S , r)), making lrev = r, calculating sk = SRerand(sk 0 , H 1 (pk 0 , ch, r, id S )) and pk = PRerand(pk 0 , H 1 (pk 0 , ch, r, idS ), let m = (H 0 (id S ), cid, pk, M r ), compute coins = H 1 (seed, m) and σ = Sig(sk, m; coins), output the credential identifier cid and the response R r = (pk, σ).
[0072] S5. Deterministic registration check (Rcheck): Take the state st, the credential identifier cid and the response R r as input, let m = (H 0 (id S ), cid, pk, M r ), compute b = Ver(pk, σ, m), if b = 0, then terminate, otherwise output the registration context rcs S [cid] = pk.
[0073] S6. Random authentication challenge generation (Achall): Take the server identifier id S as input, and generate a random number Output the challenge value c = (id S , rs) and the state st = (id S , rs).
[0074] S7. Deterministic authentication command creation (Acomm): Take the server identifier id S and the challenge value c as input, if id ≠ id S , then terminate, where id is the server identifier saved by the client, otherwise output the message M a = H 0 (rs).
[0075] S8. Random authentication response (Aresp): Take the master secret key msk, the server identifier id S , the credential identifier cid and the message M a as input, compute (id, r) = Dec(cid, seed), compare id and id S , if id ≠ id S , then terminate, otherwise compute sk = SRerand(sk 0 , H 1 (pk 0 , ch, r, id S )), let m = (H 0 (id S ), M a ), compute coins = H1 (seed, m) and σ = Sig(sk, m; coins), output the response R a = σ.
[0076] S9. Deterministic authentication check (Acheck): Take the state st, the registration context rcs S , the credential identifier cid and the response R a as inputs, calculate pk = rcs S [cid], let m = (H 0 (id S ), M a ), and output b = Ver(pk, σ, m).
[0077] S10. Generate revocation key (Revoke): Take the master secret key msk as an input, and output the revocation key rk = (pk 0 , ch, lrev).
[0078] S11. Credential check (CheckCred): Take the server identifier id S , the credential cred stored on the server and the revocation key rk as inputs, calculate r = Enc(ch, lrev) and pk ‘ = PRerand(pk 0 , H 1 (pk 0 , ch, r, id S ))), if pk' = pk, output 1, indicating that the key corresponding to this credential needs to be revoked, otherwise output 0, indicating that the key corresponding to this credential does not need to be revoked.
[0079] The present invention also provides an electronic device, which includes a processor and a memory. Among them, the memory stores a computer program. When the computer program is executed by the processor, the processor is caused to execute the method steps as described in any one of the above.
[0080] The present invention also provides a strong unlinkable passwordless authentication system supporting global revocation, including a memory, a processor, and computer program instructions stored on the memory and capable of being run by the processor. When the processor runs the computer program instructions, the method steps as described in any one of the above can be implemented.
[0081] The present invention also provides a computer-readable storage medium, on which computer program instructions capable of being run by a processor are stored. When the processor runs the computer program instructions, the method steps as described in any one of the above can be implemented.
[0082] The above are the preferred embodiments of the present invention. All changes made according to the technical solution of the present invention, as long as the functions and effects produced do not exceed the scope of the technical solution of the present invention, fall within the protection scope of the present invention.
Claims
1. A strong unlinkable passwordless authentication method supporting global revocation, characterized in that: A deterministic derived key mechanism is adopted, and the revocation key is composed of public key, chain code and variables. The three values of public key, chain code and variable can uniquely identify all credential public keys generated by the token. After the revocation key is released, any server can check whether the stored credentials need to be revoked based on the revocation key, so that the administrator can immediately revoke the permissions of all subkeys through the master key, that is, global revocation, without the need for step-by-step operations, avoiding the risk spread after key leakage, and achieving strong unlinkability through double encryption and parameter transformation, strict identity authentication and session authentication, and the use of randomization technology and encryption functions.
2. A strong unlinkable passwordless authentication method supporting global revocation according to claim 1, characterized in that: Including the registration process, as follows: The token calls Gen to generate the master key; The server calls Rchall to generate the challenge value and status; The client obtains the challenge value from the server and calls Rcomm to generate a message; The token obtains the server identifier and message from the client, calls Rresp to generate a response and credential identifier, and sends it to the server through the client; After the server receives the response and credential identifier from the client, it calls Rcheck. If the output is 0, the credential is not saved. Otherwise, the server saves the credential in the registration context.
3. A strong unlinkable passwordless authentication method supporting global revocation according to claim 2, characterized in that: It also includes the certification process, as follows: The server calls Achall to generate the challenge value and status; The client obtains the challenge value and credential identifier from the server and calls Acomm to generate a message; The token obtains the server identifier, credential identifier, and message from the client, calls Aresp to generate a response, and sends it to the server through the client; After the server receives a response from the client, it calls Acheck. If the output is 0, the authentication fails. Otherwise, the server accepts the authentication request.
4. A strong unlinkable passwordless authentication method supporting global revocation according to claim 3, characterized in that: It also includes executing the global undo process, as follows: The token calls Revoke to generate a revocation key and sends the revocation key to each server; After the server obtains the revocation key from the token, it calls CheckCred. If the output is 1, it means that the key corresponding to the credential needs to be revoked. Otherwise, it means that the key corresponding to the credential does not need to be revoked.
5. A strong unlinkable password-free authentication method supporting global revocation according to claim 4, characterized in that: The specific steps of the registration process are as follows: S1. Master key generation Gen: takes a key pair (sk0, pk0), a chain code ch, a variable lrev and a seed seed as input, and outputs the master key of the token msk = (sk0, pk0, ch, seed, lrev); S2, random registration challenge generation Rchall: server identifier id S As input, and generate a random number Output challenge value c = (id S ,rs) and state st=(id S ,rs), Indicates random selection; S3, deterministic registration command creates Rcomm: server identifier id S and challenge value c as input, if id≠id S , then terminate, where id is the server identity identifier saved by the client, otherwise output message M r =H0(rs); S4, random registration response Rresp: the master key msk, server identifier id S and message M r As input, calculate r = Enc (ch, lrev) and cid = Enc (seed, (id S ,r)), let lrev=r, calculate sk=SRerand(sk0,H1(pk0,ch,r,id S )) and pk=PRerand(pk0,H1(pk0,ch,r,id S )), let m=(H0(id S ),cid,pk,M r ), calculate coins = H1(seed, m) and σ = Sig(sk, m; coins), output the credential identifier cid and the response R r =(pk,σ); where Enc is the symmetric encryption function, SRerand is the private key re-randomization function, PRerand is the public key re-randomization function, and sig is the signature function; S5, deterministic registration check Rcheck: the state st, credential identifier cid and response R r As input, let m = (H0 (id S ),cid,pk,M r ), calculate b = Ver (pk, σ, m), if b = 0, then terminate, otherwise output the registration context rcs S [cid]=pk, where Ver is the verification signature function.
6. A strong unlinkable passwordless authentication method supporting global revocation according to claim 5, characterized in that: The specific steps of the authentication process are as follows: S6, random authentication challenge generation Achall: server identifier id S As input, and generate a random number Output challenge value c = (id S ,rs) and state st=(id S ,rs); S7, deterministic authentication command creates Acomm: server identifier id S and challenge value c as input, if id≠id S , then terminate, where id is the server identifier saved by the client, otherwise output message M a =H0(rs), H0(·) is the hash function; S8, random authentication response Aresp: the master key msk, server identifier id S , credential identifier cid and message M a As input, calculate (id, r) = Dec(cid, seed), compare id and id S , if id≠id S , then terminate, otherwise calculate sk=SRerand(sk0,H1(pk0,ch,r,id S )), let m=(H0(id S ),M a ), calculate coins = H1 (seed, m) and σ = Sig (sk, m; coins), and output the response R a =σ; Dec is the decryption function and H1(·) is the hash function; S9, deterministic authentication check Acheck: set the state st, registration context rcs S , credential identifier cid and response R a As input, calculate pk=rcs S [cid], let m = (H0 (id S ),M a ), output b = Ver(pk,σ,m).
7. A strong unlinkable passwordless authentication method supporting global revocation according to claim 6, characterized in that: The specific steps to implement the global revocation process are as follows: S10, generate revocation key Revoke: take the master key msk as input, and output revocation key rk = (pk0, ch, lrev); S11, credential check CheckCred: server identifier id S , the server stored credentials cred and revocation key rk as input, calculate r = Enc (ch, lrev) and pk' = PRerand (pk0, H1 (pk0, ch, r, id S )), if pk′=pk, then output 1, indicating that the key corresponding to the certificate needs to be revoked, otherwise output 0, indicating that the key corresponding to the certificate does not need to be revoked.
8. An electronic device comprising a processor and a memory, wherein: The memory stores a computer program, and when the computer program is executed by the processor, the processor executes the method steps according to any one of claims 1 to 7.
9. A strong unlinkable passwordless authentication system supporting global revocation, characterized in that: The method comprises a memory, a processor, and computer program instructions stored in the memory and executable by the processor. When the processor executes the computer program instructions, the method steps as claimed in any one of claims 1 to 7 can be implemented.
10. A computer-readable storage medium storing computer program instructions that can be executed by a processor, wherein when the processor executes the computer program instructions, the method steps according to any one of claims 1 to 7 can be implemented.