Password-free authentication method and system capable of supporting high security and efficient revocation

Through the combination of deterministic key derivation mechanism and revocation key, the security risks of traditional password authentication and the lack of global revocation mechanism for passwordless authentication are solved, and the high security and efficient global revocation function are achieved, which improves the security and unlinkability of authentication.

CN120128332APending Publication Date: 2025-06-10FUJIAN NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510321981.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

Traditional password authentication has security risks, passwordless authentication lacks a global revocation mechanism, and existing methods can only meet the requirements of weak and unlinkable.

Method used

The deterministic key derivation mechanism is adopted, and the public key, chain code and variables are used to form the revocation key to realize the global revocation function, and the parameter obfuscation processing, key derivation diversity and randomization technology are used to achieve unlinkability.

Benefits of technology

It realizes high security and efficient global revocation function, avoids the spread of risks after key leakage, and improves the security and non-linkability of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128332A_ABST
    Figure CN120128332A_ABST
Patent Text Reader

Abstract

The invention relates to a password-free authentication method and system capable of supporting high security and efficient revocation, and belongs to the technical field of information security. According to the method, a deterministic derived key mechanism is adopted, a public key, a chain code and a variable are utilized to form a revocation key, the public key, the chain code and the variable can uniquely identify all certificate public keys generated by the token, after the revocation key is released, any server can check whether a stored certificate needs to be revoked according to the revocation key, and if yes, the revocation key is released. An administrator can immediately revoke permissions of all the sub-keys through the main key, namely global revocation, step-by-step operation is not needed, and risk diffusion after key leakage is avoided. And the non-linkability is achieved through parameter confusion processing, key derivation diversity and use of a specific randomization technology and an encryption function. According to the password-free authentication method disclosed by the invention, the sub-keys are not required to be disabled one by one or the main key is not required to be replaced, and a specific randomization technology and an encryption function are not required to be adopted; and the password-free authentication method has the characteristics of supporting global revocation, meeting non-linkability and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and particularly relates to a passwordless authentication method and system that support high security and efficient revocation. Background Art

[0002] At present, with the rapid development of information technology, identity authentication is a key link to ensure the security of information systems. Due to many disadvantages such as being easy to forget and being easily cracked, the traditional password authentication method has been difficult to meet the growing security requirements, and the passwordless authentication technology has emerged as the times require. It uses emerging technologies such as biometric recognition and public key cryptography technology to provide users with a more convenient and secure authentication method, which is the major technical background for the emergence of BIP32-MU.

[0003] The public key infrastructure (PKI) technology provides important support for passwordless authentication. PKI ensures identity authentication, data encryption, and integrity protection in network communication through a digital certificate and key management system. Digital certificates are issued by an authoritative certificate authority (CA), which binds the user's identity information with the public key. In passwordless authentication, identity authentication can be achieved based on digital certificates and public key cryptography technology, replacing the traditional password authentication. For example, in the internal networks of some enterprises, employees use smart cards with digital certificates for identity authentication to log in to the enterprise's information systems.

[0004] The multi-factor authentication technology is also one of the important background technologies. It combines multiple authentication factors, such as items owned by users (such as smart cards, USB KEYs), and users' biometric features (such as fingerprints, irises), etc. Through the combined verification of multiple factors, the security and reliability of authentication are improved. For example, when logging in to the mobile client of a bank, in addition to using the account password, secondary verification can also be performed through fingerprint recognition or SMS verification codes. This is the practical application of multi-factor authentication, which provides more technical ideas and implementation means for the passwordless authentication method such as BIP32-MU.

[0005] In addition, with the rapid development of the mobile Internet and the Internet of Things, various smart devices and application scenarios have emerged continuously, putting forward higher requirements for the security, convenience, and scalability of identity authentication. The requirements for interconnection and data sharing between devices are increasing day by day, and a highly efficient, secure, and passwordless authentication method that can adapt to multiple devices and scenarios is needed to ensure the secure operation of the system. This is also an important background factor driving the development of BIP32-MU technology. Summary of the Invention

[0006] The object of the present invention is to provide a passwordless authentication method and system that supports high security and can be efficiently revoked through technologies such as passwordless authentication, deterministic key derivation mechanism, global revocation mechanism, and multi-factor authentication, aiming to solve the security risks of traditional password authentication, protect user privacy, the lack of a global revocation mechanism in passwordless authentication, and the problem that existing such methods can only meet weak unlinkability.

[0007] To achieve the above object, the technical solution of the present invention is: a passwordless authentication method and system that supports high security and can be efficiently revoked, which adopts a deterministic derived key mechanism, uses a public key, a chain code, and a variable to form a revocation key. These three values of the public key, the chain code, and the variable can uniquely identify all the credential public keys generated by the token. After the revocation key is published, any server can check whether the stored credentials need to be revoked according to the revocation key, enabling the administrator to immediately revoke the permissions of all sub-keys, that is, global revocation, through the master key, without the need for step-by-step operations, and avoiding the risk diffusion after the key leakage.

[0008] In an embodiment of the present invention, medium unlinkability is also achieved through parameter obfuscation processing, key derivation diversity, and the use of specific randomization techniques and encryption functions.

[0009] In an embodiment of the present invention, the method includes a registration process, which is specifically as follows:

[0010] The token calls Gen to generate a master private key;

[0011] The server calls Rchall to generate a challenge value and a status;

[0012] The client obtains the challenge value from the server and calls Rcomm to generate a message;

[0013] The token obtains the server identifier and the message from the client, calls Rresp to generate a response and a credential identifier, and sends them to the server through the client;

[0014] After the server obtains the response and the credential identifier from the client, it calls Rcheck. If the output is 0, the credential is not saved. Otherwise, the server saves the credential in the registration context.

[0015] In an embodiment of the present invention, the method further includes an authentication process, which is specifically as follows:

[0016] The server calls Achall to generate a challenge value and a status;

[0017] The client obtains the challenge value and the credential identifier from the server and calls Acomm to generate a message;

[0018] The token obtains the server identifier, the credential identifier, and the message from the client, calls Aresp to generate a response, and sends it to the server through the client;

[0019] After the server obtains the response from the client, it calls Acheck. If the output is 0, the authentication fails; otherwise, the server accepts the authentication request.

[0020] In an embodiment of the present invention, the method further includes performing a global revocation process, which is specifically as follows:

[0021] The token calls Revoke to generate a revocation key and sends the revocation key to each server;

[0022] After the server obtains the revocation key from the token, it calls CheckCred. If the output is 1, it means that the key corresponding to the credential needs to be revoked; otherwise, the output is 0, indicating that the key corresponding to the credential does not need to be revoked.

[0023] In an embodiment of the present invention, the specific implementation steps of the registration process are as follows:

[0024] S1. Master key generation Gen: Taking a key pair (sk 0 , pk 0 ), a chain code ch, a variable lrev, and a seed seed as inputs, and outputting the master key msk of the token = (sk 0 , pk 0 , ch, seed, lerv);

[0025] S2. Random registration challenge generation Rchall: Taking the server identifier id S as an input and generating a random number and outputting a challenge value c = (id S , rs) and a status st = (id S , rs), indicating random selection;

[0026] S3. Deterministic registration command creation Rcomm: Taking the server identifier id S and the challenge value c as inputs. If id ≠ id S , the process terminates, where id is the server identity identifier saved by the client; otherwise, it outputs a message M r = H 0 (rs), where H 0 (·) is a hash function;

[0027] S4. Random registration response Rresp: Taking the master key msk, the server identifier id S and the message M r as inputs, calculating cid = Enc(ch, lrev), setting r = lrev = cid, and calculating sk = SRerand(sk 0 , H1 (pk 0 ,ch,r,id S )) and pk = PRerand(pk 0 ,H 1 (pk 0 ,ch,r,id S )) and let m = (H 0 (id S ),cid,pk,M r ), calculate coins = H 1 (seed,m) and σ = Sig(sk,m;coins), output the credential identifier cid and the response R r = (pk,σ), where Enc is a symmetric encryption function, SRerand is a private key re - randomization function, PRerand is a public key re - randomization function, sig is a signature function, and H 1 (·) is a hash function;

[0028] S5. Deterministic registration check Rcheck: Take the status st, the credential identifier cid and the response R r as inputs, let m = (H 0 (id S ),cid,pk,M r ), calculate b = Ver(pk,σ,m), if b = 0, then terminate, otherwise output the registration context rcs S [cid] = pk, where Ver is a signature verification function.

[0029] In an embodiment of the present invention, the authentication process is specifically implemented as follows:

[0030] S6. Random authentication challenge generation Achall: Take the server identifier id S as an input and generate a random number Output the challenge value c = (id S ,rs) and the status st = (id S ,rs);

[0031] S7. Deterministic authentication command creation Acomm: Take the server identifier id S and the challenge value c as inputs, if id ≠ id S , then terminate, where id is the server identifier saved by the client, otherwise output the message M a = H 0 (rs);

[0032] S8. Random authentication response Aresp: Take the master secret key msk, the server identifier id S , the credential identifier cid and the message Ma As input, let r = cid, and compute sk = SRerand(sk 0 ,H 1 (pk 0 ,ch,r,id S ))). Let m = (H 0 (id S ),M a ). Compute coins = H 1 (seed,m) and σ = Sig(sk,m;coins), and output the response R a = σ;

[0033] S9, Deterministic authentication check Acheck: Taking the state st, the registration context rcs S , the credential identifier cid and the response R a as input, compute pk = rcs S [cid]. Let m = (H 0 (id S ),M a ). Output b = Ver(pk,σ,m).

[0034] In an embodiment of the present invention, the specific implementation steps of performing the global revocation process are as follows:

[0035] S10, Generate revocation key Revoke: Taking the master key msk as input, output the revocation key rk = (pk 0 ,ch,lrev);

[0036] S11, Credential check CheckCred: Taking the server identifier id S , the credential cred stored on the server and the revocation key rk as input, compute r = Enc(ch,lrev) and pk' = PRerand(pk 0 ,H 1 (pk 0 ,ch,r,id S ))). If pk' = pk, output 1, indicating that the key corresponding to this credential needs to be revoked; otherwise, output 0, indicating that the key corresponding to this credential does not need to be revoked.

[0037] The present invention also provides a passwordless authentication system supporting high security and efficient revocation, including a memory, a processor, and computer program instructions stored on the memory and executable by the processor. When the processor runs the computer program instructions, the method steps described above can be implemented.

[0038] The present invention also provides a computer-readable storage medium, on which computer program instructions capable of being run by a processor are stored. When the processor runs the computer program instructions, the method steps described in any of the above can be implemented.

[0039] Compared with the prior art, the present invention has the following beneficial effects:

[0040] In the traditional solution, when revoking a user's permission, it is necessary to disable sub-keys one by one or replace the master key, which is cumbersome and may affect other users. Moreover, there is a mathematical relationship between the sub-keys generated by hierarchical derivation, and the on-chain analysis tool can identify the transactions of the same user through the address pattern, resulting in privacy leakage (such as Bitcoin address clustering attack).

[0041] The present invention adopts a deterministic derived key mechanism, using the public key pk0, the chain code ch, and the variable lrev to form a revocation key. These three values can uniquely identify all the credential public keys generated by the token. After the revocation key is published, any server can check whether the stored credentials need to be revoked according to the revocation key. Therefore, the administrator can immediately revoke the permissions of all sub-keys (global revocation) through the master key, without the need for step-by-step operations, avoiding the risk diffusion after the key leakage. And through parameter confusion processing, key derivation diversity, and the use of specific randomization techniques and encryption functions, unlinkability is achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 It is a flowchart of an implementation when registering for the present invention, including three entities: a token, a client, and a server.

[0043] Figure 2 It is a flowchart of an implementation when authenticating and performing global revocation for the present invention, including three entities: a token, a client, and a server. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0044] The following describes the present solution in detail in combination with embodiments and the drawings. The following embodiments only represent one possible implementation manner of the present invention, not all possible implementation manners, and do not limit the present invention.

[0045] The present invention provides a passwordless authentication method and system that support high security and can be efficiently revoked. It adopts a deterministic derived key mechanism, using a public key, a chain code, and a variable to form a revocation key. These three values of the public key, the chain code, and the variable can uniquely identify all the credential public keys generated by the token. After the revocation key is published, any server can check whether the stored credentials need to be revoked according to the revocation key, enabling the administrator to immediately revoke the permissions of all sub-keys, that is, global revocation, through the master key, without the need for step-by-step operations, avoiding the risk diffusion after the key leakage. And through parameter confusion processing, key derivation diversity, and the use of specific randomization techniques and encryption functions, unlinkability is achieved.

[0046] The following is the specific implementation process of the present invention.

[0047] 1. Symbols and Definitions

[0048] p: Large prime number.

[0049] Z p : Finite field containing p elements, i.e., the set {0, 1, 2,..., p - 1}.

[0050] sk 0 : Private key randomly selected from the non - zero elements of the finite field Z p , where p is the order of the elliptic curve.

[0051] pk 0 : Corresponding public key, obtained through the generator g of the elliptic curve and the point multiplication operation on the elliptic curve, i.e.,

[0052] ch: Chain code, a value randomly selected from {0, 1} λ , used for key derivation and subsequent global revocation.

[0053] lrev: Component of the revocation key, used to generate the credential identifier and subsequent global revocation.

[0054] seed: Seed, a value randomly selected from {0, 1} λ , making the signature random.

[0055] r: Intermediate variable, temporarily storing the credential identifier and the variable lrev.

[0056] Randomly and uniformly selected from the set.

[0057] H 0 (·): Hash function, converting the server identifier id S and the variable rs into a hash value of fixed length, used to construct the message m.

[0058] H 1 (·): Hash function, used to generate keys or signature random numbers.

[0059] Enc(·): Symmetric encryption of the message by the encryptor.

[0060] SRerand(·): A function for private key re - randomization.

[0061] PRerand(·): A function for public key re - randomization.

[0062] sig(·): Signature of the message by the signer.

[0063] Ver(·): Verify the signature of the message.

[0064] 2. A passwordless authentication method and system supporting high security and efficient revocation

[0065] Figure 1 This is an implementation flowchart during the registration of the present invention, including three entities: a token, a client, and a server. First, the token calls Gen to generate the master private key. Then, the server calls Rchall to generate a challenge value and a status. Next, the client obtains the challenge value from the server and calls Rcomm to generate a message. Then, the token obtains the server identifier and the message from the client, calls Rresp to generate a response and a credential identifier, and sends them to the server through the client. Finally, after the server obtains the response and the credential identifier from the client, it calls Rcheck. If the output is 0, the credential is not saved; otherwise, the server saves the credential in the registration context.

[0066] Figure 2 This is an implementation flowchart during the authentication and global revocation of the present invention. It includes three entities: a token, a client, and a server. First, the server calls Achall to generate a challenge value and a status. Next, the client obtains the challenge value and the credential identifier from the server and calls Acomm to generate a message. Then, the token obtains the server identifier, the credential identifier, and the message from the client, calls Aresp to generate a response, and sends it to the server through the client. Finally, after the server obtains the response from the client, it calls Acheck. If the output is 0, the authentication fails; otherwise, the server accepts the authentication request. During the global revocation, first, the token calls Revoke to generate a revocation key and sends the revocation key to each server. Then, after the server obtains the revocation key from the token, it calls CheckCred. If the output is 1, it means that the key corresponding to the credential needs to be revoked; otherwise, the output is 0, indicating that the key corresponding to the credential does not need to be revoked.

[0067] A passwordless authentication method supporting high security and efficient revocation in this example mainly includes 11 parts: master private key generation (Gen), random registration challenge generation (Rchall), deterministic registration command creation (Rcomm), random registration response (Rresp), deterministic registration check (Rcheck), random authentication challenge generation (Achall), deterministic authentication command creation (Acomm), random authentication response (Aresp), deterministic authentication check (Acheck), revocation key generation (Revoke), and credential check (CheckCred). Specifically as follows:

[0068] S1. Master key generation (Gen): Generate a key pair (sk 0 , pk0 ) With a chain code ch, a variable lrev, and a seed seed as inputs, the master secret key msk of the output token is = (sk 0 , pk 0 , ch, seed, lrev).

[0069] S2. Random registration challenge generation (Rchall): Using the server identifier id S as an input, and generating a random number rs Output the challenge value c = (id S , rs) and the state st = (id S , rs).

[0070] S3. Deterministic registration command creation (Rcomm): Using the server identifier id S and the challenge value c as inputs, if id ≠ id S , then terminate, where id is the server identity identifier saved by the client, otherwise output the message M r = H 0 (rs).

[0071] S4. Random registration response (Rresp): Using the master secret key msk, the server identifier id S and the message M r as inputs, calculate cid = Enc(ch, lrev), let r = lrev = cid, calculate sk = SRerand(sk 0 , H 1 (pk 0 , ch, r, id S )) and pk = PRerand(pk 0 , H 1 (pk 0 , ch, r, id S ))), let m = (H 0 (id S ), cid, pk, M r ), calculate coins = H 1 (seed, m) and σ = Sig(sk, m; coins), output the credential identifier cid and the response R r = (pk, σ).

[0072] S5. Deterministic registration check (Rcheck): Using the state st, the credential identifier cid, and the response R r as inputs, let m = (H 0 (id S ), cid, pk, M r), compute \(b = Ver(pk, \sigma, m)\). If \(b = 0\), terminate; otherwise, output the registration context \(rcs\). S [cid] = pk.

[0073] S6. Random authentication challenge generation (Achall): Take the server identifier id S as input and generate a random number Output the challenge value \(c=(id S , rs)\) and the state \(st=(id S , rs)\).

[0074] S7. Deterministic authentication command creation (Acomm): Take the server identifier id S and the challenge value \(c\) as input. If \(id eq id S \), terminate, where \(id\) is the server identifier saved by the client; otherwise, output the message \(M a = H 0 (rs).

[0075] S8. Random authentication response (Aresp): Take the master secret key \(msk\), the server identifier \(id S \), the credential identifier \(cid\), and the message \(M a as input. Let \(r = cid\), compute \(sk = SRerand(sk 0 , H 1 (pk 0 , ch, r, id S ))\). Let \(m=(H 0 (id S ), M a )\), compute \(coins = H 1 (seed, m)\) and \(\sigma = Sig(sk, m; coins)\). Output the response \(R a =\sigma\).

[0076] S9. Deterministic authentication check (Acheck): Take the state \(st\), the registration context \(rcs S \), the credential identifier \(cid\), and the response \(R a as input. Compute \(pk = rcs S [cid]\). Let \(m=(H 0 (id S ), M a )\). Output \(b = Ver(pk, \sigma, m)\).

[0077] S10. Generate revocation key (Revoke): Take the master secret key \(msk\) as input and output the revocation key \(rk=(pk 0 , ch, lrev)\).

[0078] S11, Credential Check (CheckCred): Take the server identifier id S , the credential cred and the revocation key rk stored on the server as inputs, calculate r = Enc(ch, lrev) and pk ‘ = PRerand(pk 0 , H 1 (pk 0 , ch, r, id S ). If pk' = pk, output 1, indicating that the key corresponding to this credential needs to be revoked; otherwise, output 0, indicating that the key corresponding to this credential does not need to be revoked.

[0079] The present invention also provides a passwordless authentication system that supports high security and efficient revocation, including a memory, a processor, and computer program instructions stored on the memory and executable by the processor. When the processor runs the computer program instructions, the method steps described in any of the above can be implemented.

[0080] The present invention also provides a computer-readable storage medium, on which computer program instructions executable by the processor are stored. When the processor runs the computer program instructions, the method steps described in any of the above can be implemented.

[0081] The above are the preferred embodiments of the present invention. All changes made according to the technical solution of the present invention, as long as the functions and effects produced do not exceed the scope of the technical solution of the present invention, fall within the protection scope of the present invention.

Claims

1. A password-free authentication method that supports high security and can be efficiently revoked, characterized in that: A deterministic derived key mechanism is adopted, and the revocation key is composed of the public key, chain code and variables. The three values ​​of the public key, chain code and variable can uniquely identify all the credential public keys generated by the token. After the revocation key is released, any server can check whether the stored credentials need to be revoked based on the revocation key, so that the administrator can immediately revoke the permissions of all subkeys through the master key, that is, global revocation, without the need for step-by-step operations, avoiding the spread of risks after key leakage.

2. A highly secure and efficiently revocable password-free authentication method according to claim 1, characterized in that: Unlinkability is also achieved through parameter obfuscation, key derivation diversity, and the use of specific randomization techniques and encryption functions.

3. A highly secure and efficiently revocable password-free authentication method according to claim 2, characterized in that: Including the registration process, as follows: The token calls Gen to generate the master private key; The server calls Rchall to generate the challenge value and status; The client obtains the challenge value from the server and calls Rcomm to generate a message; The token obtains the server identifier and message from the client, calls Rresp to generate a response and credential identifier, and sends it to the server through the client; After the server receives the response and credential identifier from the client, it calls Rcheck. If the output is 0, the credential is not saved. Otherwise, the server saves the credential in the registration context.

4. A highly secure and efficiently revocable password-free authentication method according to claim 3, characterized in that: It also includes the certification process, as follows: The server calls Achall to generate the challenge value and status; The client obtains the challenge value and credential identifier from the server and calls Acomm to generate a message; The token obtains the server identifier, credential identifier, and message from the client, calls Aresp to generate a response, and sends it to the server through the client; After the server receives a response from the client, it calls Acheck. If the output is 0, the authentication fails. Otherwise, the server accepts the authentication request.

5. A highly secure and efficiently revocable password-free authentication method according to claim 4, characterized in that: It also includes executing the global undo process, as follows: The token calls Revoke to generate a revocation key and sends the revocation key to each server; After the server obtains the revocation key from the token, it calls CheckCred. If the output is 1, it means that the key corresponding to the credential needs to be revoked. Otherwise, it outputs 0, which means that the key corresponding to the credential does not need to be revoked.

6. A highly secure and efficiently revocable password-free authentication method according to claim 5, characterized in that: The specific steps of the registration process are as follows: S1. Master key generation Gen: takes a key pair (sk0, pk0), a chain code ch, a variable lrev and a seed seed as input, and outputs the master key of the token msk = (sk0, pk0, ch, seed, lrev); S2, random registration challenge generation Rchall: server identifier id S As input, and generate a random number Output challenge value c = (id S ,rs) and state st=(id S ,rs), Indicates random selection; S3, deterministic registration command creates Rcomm: server identifier id S and challenge value c as input, if id≠id S , then terminate, where id is the server identity identifier saved by the client, otherwise output message M r =H0(rs), H0(·) is the hash function; S4, random registration response Rresp: the master key msk, server identifier id S and message M r As input, calculate cid = Enc (ch, lrev), let r = lrev = cid, calculate sk = SRerand (sk0, H1 (pk0, ch, r, id S )) and pk=PRerand(pk0,H1(pk0,ch,r,id S )), let m=(H0(id S ),cid,pk,M r ), calculate coins = H1(seed, m) and σ = Sig(sk, m; coins), output the credential identifier cid and the response R r =(pk,σ), where Enc is a symmetric encryption function, SRerand is a private key re-randomization function, PRerand is a public key re-randomization function, sig is a signature function, and H1(·) is a hash function; S5, deterministic registration check Rcheck: the state st, credential identifier cid and response R r As input, let m = (H0 (id S ),cid,pk,M r ), calculate b = Ver (pk, σ, m), if b = 0, then terminate, otherwise output the registration context rcs S [cid]=pk, where Ver is the verification signature function.

7. A highly secure and efficiently revocable password-free authentication method according to claim 6, characterized in that: The specific steps of the authentication process are as follows: S6, random authentication challenge generation Achall: server identifier id S As input, and generate a random number Output challenge value c = (id S ,rs) and state st=(id S ,rs); S7, deterministic authentication command creates Acomm: server identifier id S and challenge value c as input, if id≠id S , then terminate, where id is the server identifier saved by the client, otherwise output message M a =H0(rs); S8, random authentication response Aresp: the master key msk, server identifier id S , credential identifier cid and message M a As input, let r = cid and calculate sk = SRerand(sk0,H1(pk0,ch,r,id S )), let m=(H0(id S ),M a ), calculate coins = H1 (seed, m) and σ = Sig (sk, m; coins), and output the response R a =σ; S9, deterministic authentication check Acheck: set the state st, registration context rcs S , credential identifier cid and response R a As input, calculate pk=rcs S [cid], let m = (H0 (id S ),M a ), output b = Ver(pk,σ,m).

8. A highly secure and efficiently revocable password-free authentication method according to claim 7, characterized in that: The specific steps to implement the global revocation process are as follows: S10, generate revocation key Revoke: take the master key msk as input, and output revocation key rk = (pk0, ch, lrev); S11, credential check CheckCred: server identifier id S , the server stored credentials cred and revocation key rk as input, calculate r = Enc (ch, lrev) and pk' = PRerand (pk0, H1 (pk0, ch, r, id S )), if pk'=pk, then output 1, indicating that the key corresponding to the certificate needs to be revoked, otherwise output 0, indicating that the key corresponding to the certificate does not need to be revoked.

9. A highly secure and efficiently revocable password-free authentication system, characterized in that: The method comprises a memory, a processor and computer program instructions stored in the memory and capable of being executed by the processor. When the processor executes the computer program instructions, the method steps as claimed in any one of claims 1 to 8 can be implemented.

10. A computer-readable storage medium having stored thereon computer program instructions that can be executed by a processor, and when the processor executes the computer program instructions, the method steps according to any one of claims 1 to 8 can be implemented.