Identity information protection authentication method based on homomorphic password
By using homomorphic password algorithms to generate ciphertexts in identity authentication, the problem of user identity information leakage in the existing technology is solved, and the full protection and privacy security of user identity information are realized.
Patent Information
- Application Number
- CN202510384637.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-06-17
AI Technical Summary
Existing digital certificate-based identity authentication technology may disclose user identity information when processing in the authentication center, and cannot fully protect user privacy.
Identity information protection authentication method based on homomorphic passwords is adopted, and identity authentication information ciphertext is generated through homomorphic password algorithm to ensure that user identity information is authenticated in the entire encrypted state, and avoid the authentication center from obtaining plaintext data.
It realizes full protection of user identity information, prevents the authenticator from leaking and abusing user identity information, and ensures user privacy and security.
Smart Images

Figure CN120165834A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an identity information protection and authentication method based on homomorphic cryptography, belonging to the technical field of data communication and information security. Background Art
[0002] In the Internet, the premise of communication between two parties is identity authentication. To achieve reliable identity authentication, users not only need to provide necessary information to prove their true identities, but also need to avoid exposing too much information during the authentication process to cause privacy leakage.
[0003] Over the years, the main means of identity authentication has been "digital certificates". During the identity authentication process, the strategy is to minimize the exposure of user attribute information. The PKI technology is used to issue digital certificates by a digital certificate center, and users present these certificates for identity authentication. However, the method of exchanging identity authentication with "digital certificates" can only minimize the information that needs to be exposed during the authentication process and cannot fully protect user privacy. That is, the existing authentication technology based on digital certificates can obtain the plaintext data of user identity information when processed by the authentication center, which may lead to the leakage of user identity information. Summary of the Invention
[0004] The technical problem to be solved by the present invention is: to overcome the deficiencies of the prior art and provide an identity information protection and authentication method based on homomorphic cryptography, which can protect user identity authentication information throughout the process while realizing user identity authentication.
[0005] The technical solution of the present invention is: In the first aspect, an identity information protection and authentication method based on homomorphic cryptography is provided, including:
[0006] Step 1: The user selects a suitable homomorphic cryptography algorithm at the user side and generates the ciphertext of identity authentication information based on the user identity information by using the homomorphic cryptography algorithm;
[0007] Step 2: The user sends a registration request to the user trusted registration center, including the ciphertext of the user identity authentication information. The user trusted registration center generates a unique identifier for the user, sends it to the user, and enters the ciphertext of the user identity authentication information and the unique identifier into the user identity authentication information ciphertext library;
[0008] Step 3: The user trusted registration center establishes a communication connection with the authentication center of the service provider, synchronously updates the user identity authentication information ciphertext library to the authentication center, and the authentication center stores the received ciphertext of the user identity authentication information in the identity authentication information ciphertext memory of the service provider;
[0009] Step 4: The user sends an authentication request to the authentication center. The authentication center performs homomorphic addition on ciphertexts based on the authentication request and then sends the result to the user. After receiving the result of the homomorphic addition of ciphertexts, the user decrypts it and sends the decryption result to the authentication center. The authentication center determines whether the identity authentication is successful based on the decryption result.
[0010] Preferably, after the user selects a suitable homomorphic cryptography algorithm at the user side, a key pair including a public key and a private key is generated using a homomorphic cryptography key generation algorithm.
[0011] Preferably, the user identity information ID is the number assigned to the current user by the system;
[0012] The ciphertext C of the user identity authentication information is the ciphertext encrypted by the public key generated based on the homomorphic cryptography key generation algorithm, that is, C = Enc pk (ID), where Enc() refers to the encryption algorithm and pk refers to the public key.
[0013] Preferably, the unique identifier UID generated by the user trusted registration center for the user is: a random number generated by the user trusted registration center based on a random number generator.
[0014] Preferably, in Step 4, when the user sends an authentication request to the authentication center, the authentication request sent includes: the user unique identifier UID and the new ciphertext C';
[0015] The new ciphertext C' is the ciphertext generated by using the public key again based on the user identity information, that is, C' = Enc pk (ID), where Enc() refers to the encryption algorithm and pk refers to the public key.
[0016] Preferably, after the authentication center performs homomorphic addition on ciphertexts based on the authentication request and sends the result to the user, specifically:
[0017] After receiving the authentication request, the authentication center retrieves the ciphertext C of the identity authentication information from the ciphertext memory of the identity authentication information based on the user unique identifier UID, and generates a random number Nonce based on a random number generator;
[0018] The authentication center performs homomorphic addition on ciphertexts by combining the ciphertext C sent during user registration, the random number, and the new ciphertext C': J = C ′ +Nonce - C, and sends the encryption result J to the user.
[0019] Preferably, after the user receives the result of the homomorphic addition of ciphertexts, the user decrypts it and sends the decryption result to the authentication center, specifically:
[0020] The user decrypts the result sent by the authentication center using the private key to obtain Nonce ′ , and the decryption result Nonce ′Sent to the authentication center; where Nonce′ = Dec sk (C ′ + Nonce - C), Dec() refers to the decryption algorithm, and sk refers to the private key.
[0021] Preferably, the authentication center determines whether the identity authentication is successful based on the decryption result. Specifically:
[0022] The authentication center determines whether Nonce and Nonce ′ are equal: if they are equal, the identity authentication is successful; if not, the identity authentication fails.
[0023] Preferably, the user can select suitable homomorphic cryptography algorithms, including: semi - homomorphic cryptography algorithms, quasi - homomorphic cryptography algorithms, and fully - homomorphic cryptography algorithms.
[0024] In a second aspect, a homomorphic - cryptography - based identity information protection authentication system is provided, including: a user - side and a server - side. Among them, the user - side includes a user interaction interface and a user trusted registration center; the server - side includes an authentication center and a ciphertext memory for identity authentication information. Specifically:
[0025] The user interaction interface provides suitable homomorphic cryptography algorithms for the user to select, can generate the ciphertext of identity authentication information based on the user's identity information using the homomorphic cryptography algorithm. When the user sends a registration request to the user trusted registration center, it sends the user's identity information and the ciphertext of identity authentication information to the user trusted registration center, and receives the user's unique identifier generated by the user trusted registration center; when the user sends an authentication request, it regenerates a new ciphertext based on the user's identity information, sends the new ciphertext and the user's unique identifier to the authentication center, and receives the operation result after homomorphic addition of the ciphertext based on the authentication request and decrypts the operation result;
[0026] The user trusted registration center is a management end trusted by the user. It receives the registration request sent by the user interaction interface, generates the user's unique identifier for the currently registered user, stores the ciphertext of identity authentication information and the user's unique identifier into the user identity authentication information library, and can simultaneously synchronize and update the ciphertext of identity authentication information and the user's unique identifier of the user to the ciphertext memory for identity authentication information on the server - side;
[0027] The authentication center can receive the ciphertext of the user's identity authentication information and the user's unique identifier provided by the user trusted registration center, and store them in the ciphertext memory of the identity authentication information; when receiving an authentication request from the user, it receives the new ciphertext and the user's unique identifier sent by the user interaction interface, retrieves the ciphertext memory of the identity authentication information based on the user's unique identifier, obtains the ciphertext of the identity authentication information sent by the user during registration, generates a random number, performs a ciphertext homomorphic addition operation using the new ciphertext, the random number, and the ciphertext of the identity authentication information sent by the user during registration, and then sends the operation result to the user interaction interface; it receives the decryption result sent back by the user interaction interface and determines whether the identity authentication is successful based on the decryption result;
[0028] The ciphertext memory of the identity authentication information receives the ciphertext of the user's identity authentication information and the user's unique identifier that are synchronously updated by the user trusted registration center.
[0029] The present invention has the following advantages compared with the prior art:
[0030] (1) By utilizing the feature that homomorphic cryptography can directly operate on encrypted data, the present invention realizes identity authentication in the full ciphertext state of user identity information, and solves the problem that the authentication center may leak user identity information during the authentication process;
[0031] (2) The present invention can be realized by using the homomorphic addition operation of homomorphic cryptography. The selectable algorithms include the partially homomorphic encryption (PHE) algorithm, the somewhat homomorphic encryption (SHE) algorithm, and the fully homomorphic encryption (FHE) algorithm that only support homomorphic addition operation. The algorithm selection range is relatively wide; in addition, the homomorphic addition operation is efficient, does not cause rapid growth of noise, has low requirements for the algorithm's software and hardware implementation resources, and has strong feasibility;
[0032] (3) The present invention can solve the identity authentication problem in the scenario where the user is unwilling to provide plaintext identity information to the authenticator. Description of the Drawings
[0033] Figure 1 It is a schematic diagram of the interaction model among the user, the user trusted registration center, and the authentication center of the present invention;
[0034] Figure 2 It is a schematic diagram of the interaction model during the registration stage of the present invention: the interaction between the user and the registration center;
[0035] Figure 3 It is a schematic diagram of the interaction model between the registration center and the user center of the present invention;
[0036] Figure 4 It is a schematic diagram of the interaction model during the authentication stage of the present invention: the interaction between the user and the authentication center. Detailed Embodiments
[0037] The present invention proposes an identity information protection and authentication method based on homomorphic cryptography, which solves the problem of exposure of user identity and other information caused by the use of digital certificates during the identity authentication process. While realizing user identity authentication, it can protect user identity authentication information throughout the process, preventing both the authenticator from obtaining, leaking, and misusing user identity information, and preventing the leakage of user authentication information, achieving the purpose of protecting the privacy of user identity information and the confidentiality of user authentication information.
[0038] It mainly includes three participants: the user, the user trusted registration center, and the authentication center. As Figure 1 shown, the user interacts with the user trusted registration center to complete user registration, interacts with the authentication center for identity authentication, and the user trusted registration center interacts with the authentication center to complete the synchronization of the identity authentication information cipher library. In this example, the specific implementation process is as follows:
[0039] Step 1: User initialization phase: The user selects a suitable homomorphic cryptography algorithm at the user side, and the user side uses the homomorphic cryptography key generation algorithm to generate a key pair (i.e., public key and private key).
[0040] Step 2: Registration phase: The user interacts with the user trusted registration center, and the user trusted registration center verifies the user identity information; the specific process of this interaction is as Figure 2 shown; the user trusted registration center here is established at the user side and is a trusted management side of the user, which verifies, maintains, and supervises the user's identity.
[0041] Step 3: User identity authentication information synchronization phase: The user trusted registration center establishes a communication connection with the authentication center of the service provider, synchronizes and updates the user identity authentication information cipher library to the authentication center, and the authentication center stores the received user identity authentication information ciphertext in the identity authentication information ciphertext storage of the service provider; the specific process of this interaction is as Figure 3 shown;
[0042] Step 4: Authentication phase: The user interacts with the authentication center, and the authentication center authenticates the user identity and feeds back the identity authentication result to the user; if it passes, the identity authentication is successful, otherwise the authentication fails; the specific process of this interaction is as Figure 4 shown;
[0043] In the above implementation process, taking user A as an example; in the user initialization phase, the user selects a suitable homomorphic cryptography algorithm and generates a key pair based on the homomorphic cryptography key generation algorithm, where the public key is denoted as pk and the private key is denoted as sk; the encryption algorithm is denoted as Enc(), and the decryption algorithm is denoted as Dec().
[0044] In the step 2 registration phase described in the present invention, the interaction between the user and the registration center specifically includes the following steps:
[0045] Step 2-1: The user submits a registration application to the user trusted registration center. The request sent contains: user identity information and the ciphertext C of the user identity authentication information encrypted with the public key in the homomorphic cipher.
[0046] Step 2-2: The user trusted registration center verifies the user identity information and completes two operations:
[0047] Step 2-2-1: The user trusted registration center generates a random number based on the random number generator as the unique user identifier UID and issues it to the user.
[0048] Step 2-2-2: Enter the unique identifier UID of the currently registered user and the ciphertext C of the identity authentication information into the identity authentication information cipher library.
[0049] In the above implementation process, the user identity information is denoted as ID, which is the number assigned to the user by the system. The ciphertext C = Enc pk (ID) is generated by encrypting with the public key based on the user identity information. In Step 2-1, the user sends (ID, C) to the user trusted registration center, and the user trusted registration center generates the unique identifier UID and sends it to the user. At the same time, the user trusted registration center stores the user A in the form of (UID, C) in the identity authentication information cipher library of the user trusted registration center. It should be emphasized that the homomorphic cipher algorithm is a probabilistic cipher algorithm, and different random numbers are used in each encryption process, resulting in different ciphertexts.
[0050] In the authentication phase of Step 4 of the present invention, the interaction between the user and the authentication center specifically includes the following steps:
[0051] Step 4-1: The user sends an authentication request to the authentication center. The request sent contains: the user unique identifier UID and the new ciphertext C' generated by encrypting with the homomorphic cipher based on the user identity information ID.
[0052] Step 4-2: After receiving the authentication request, the authentication center completes two operations:
[0053] Step 4-2-1: Based on the user unique identifier UID, retrieve the identity authentication information cipher memory to obtain the ciphertext C sent by the user during registration.
[0054] Step 4-2-2: Generate a random number Nonce based on the random number generator.
[0055] Step 4-3: The authentication center performs the homomorphic addition operation of ciphertext (C ′ + Nonce - C), and sends the operation result to the user.
[0056] Step 4-4: The user decrypts the result sent by the authentication center in Step 4-3 to obtain Nonce ′ , and the decryption result Nonce′ Sent to the authentication center;
[0057] Step 4-5: The authentication center determines whether Nonce is equal to Nonce ′ Are they equal? Yes, the identity authentication is successful; No, the identity authentication fails;
[0058] In the above implementation process, the user sends (UID, C') to the authentication center, where C' is the ciphertext generated by reusing the public key of homomorphic encryption based on the user identity information, C' = Enc pk (ID); After receiving the authentication request of user A, the authentication center retrieves the corresponding registered ciphertext C from the identity authentication information ciphertext library using the UID of user A, and at the same time generates Nonce using a random number generator, and obtains the value of C ′ + Nonce - C through homomorphic addition operation, and sends the operation result to user A; User A decrypts using the private key to obtain: Nonce' = Dec sk (C ′ + Nonce - C), and returns the result to the authentication center; The authentication center makes a comparison. When Nonce' = Nonce, it feeds back to user A that the identity authentication is successful; Otherwise, the authentication fails;
[0059] The principle of identity authentication is: Using the homomorphic cryptography characteristics, after performing specific algebraic operations on the ciphertext (such as: step 4-3), the obtained is still the encrypted ciphertext. The result Dec sk (C ′ + Nonce - C) obtained after decrypting it is the same as the result of performing the same operation on the plaintext Enc pk (0 + Nonce); That is to say: C ′ - C is the ciphertext encrypted by user A for 0, C ′ - C = Enc pk (0).
[0060] The present invention also provides an identity information protection authentication system based on homomorphic cryptography. The system includes: a user side and a service side. Among them, the user side includes a user interaction interface and a user trusted registration center; The service side includes an authentication center and an identity authentication information ciphertext storage; Specifically:
[0061] The user interaction interface provides suitable homomorphic encryption algorithms for users to select, and can generate ciphertext of identity authentication information using a homomorphic encryption algorithm based on the user's identity information. When the user sends a registration request to the user trusted registration center, the user's identity information and the ciphertext of the identity authentication information are sent to the user trusted registration center, and the user's unique identifier generated by the user trusted registration center is received; when the user sends an authentication request, a new ciphertext is regenerated based on the user's identity information, the new ciphertext and the user's unique identifier are sent to the authentication center, and the operation result after homomorphic addition of the ciphertext is received from the authentication center and the operation result is decrypted;
[0062] The user trusted registration center is a management end trusted by users. It receives the registration request sent by the user interaction interface, generates the user's unique identifier for the currently registered user, stores the ciphertext of the identity authentication information and the user's unique identifier in the user identity authentication information ciphertext library, and can simultaneously synchronize and update the ciphertext of the user's identity authentication information and the user's unique identifier to the identity authentication information ciphertext storage in the server;
[0063] The authentication center can receive the ciphertext of the user's identity authentication information and the user's unique identifier provided by the user trusted registration center and store them in the identity authentication information ciphertext storage; when the user sends an authentication request, it receives the new ciphertext and the user's unique identifier sent by the user interaction interface, retrieves the identity authentication information ciphertext storage based on the user's unique identifier to obtain the ciphertext of the identity authentication information sent during the user's registration, generates a random number, performs a homomorphic addition operation on the new ciphertext, the random number, and the ciphertext of the identity authentication information sent during the user's registration, and then sends the operation result to the user interaction interface; receives the decryption result sent back by the user interaction interface and determines whether the identity authentication is successful based on the decryption result;
[0064] The identity authentication information ciphertext storage receives the ciphertext of the user's identity authentication information and the user's unique identifier synchronized and updated by the user trusted registration center.
[0065] Although the present invention has been disclosed above with preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make possible changes and modifications to the technical solution of the present invention using the methods and technical contents disclosed above without departing from the spirit and scope of the present invention. Therefore, any simple modifications, equivalent changes, and decorations made to the above embodiments based on the technical essence of the present invention without departing from the content of the technical solution of the present invention all belong to the protection scope of the technical solution of the present invention.
[0066] The content not detailedly described in the specification of the present invention belongs to the known prior art of those skilled in the art.
Claims
1. An identity information protection authentication method based on homomorphic encryption, characterized in that include: Step 1: The user selects a suitable homomorphic cryptographic algorithm on the user side, and uses the homomorphic cryptographic algorithm to generate identity authentication information ciphertext based on the user identity information; Step 2: The user sends a registration request to the user trusted registration center, which includes the user identity authentication information ciphertext. The user trusted registration center generates a unique identifier for the user, sends it to the user, and enters the user identity information ciphertext and the unique identifier into the user identity authentication information ciphertext library; Step 3: The user trusted registration center establishes a communication connection with the authentication center of the service provider, and synchronously updates the user identity authentication information ciphertext library to the authentication center. The authentication center stores the received user identity authentication information ciphertext in the identity authentication information ciphertext storage of the service provider; Step 4: The user sends an authentication request to the authentication center. The authentication center performs a ciphertext homomorphic addition operation based on the authentication request and sends the result to the user. The user decrypts the ciphertext homomorphic addition result after receiving it and sends the decrypted result to the authentication center. The authentication center determines whether the identity authentication is successful based on the decryption result.
2. According to claim 1, the identity information protection authentication method based on homomorphic encryption is characterized in that: After the user selects a suitable homomorphic cryptographic algorithm on the user side, the homomorphic cryptographic key generation algorithm is used to generate a key pair, including a public key and a private key.
3. According to claim 2, the identity information protection authentication method based on homomorphic encryption is characterized in that: User identity information ID is the number assigned by the system to the current user; The user authentication information ciphertext C is the ciphertext encrypted by the public key generated based on the homomorphic cryptographic key generation algorithm, that is, C = Enc pk (ID), Enc() refers to the encryption algorithm, and pk refers to the public key.
4. According to claim 1, the identity information protection authentication method based on homomorphic encryption is characterized in that: The unique identifier UID generated by the user trusted registration center for the user is: a random number generated by the user trusted registration center based on a random number generator.
5. According to claim 2, the identity information protection authentication method based on homomorphic encryption is characterized in that: In step 4, when the user sends an authentication request to the authentication center, the authentication request sent includes: the user's unique identifier UID and the new ciphertext C'; The new ciphertext C' is the ciphertext generated by using the public key again based on the user identity information, that is, C' = Enc pk (ID), Enc() refers to the encryption algorithm, and pk refers to the public key.
6. According to claim 5, the identity information protection authentication method based on homomorphic encryption is characterized in that: The authentication center performs a homomorphic addition operation on the ciphertext based on the authentication request and sends the result to the user. Specifically: After receiving the authentication request, the authentication center retrieves the identity authentication information ciphertext storage based on the user's unique identifier UID, obtains the ciphertext C sent by the user when registering, and generates a random number Nonce based on the random number generator; The authentication center combines the ciphertext C sent by the user during registration, the random number, and the new ciphertext C′ to perform a ciphertext homomorphic addition operation: J = C ′ +Nonce-C, send the encrypted result J to the user.
7. According to claim 6, a method for identity information protection authentication based on homomorphic encryption is characterized in that: After receiving the ciphertext homomorphic addition operation result, the user decrypts it and sends the decryption result to the authentication center. Specifically: The user uses the private key to decrypt the result sent by the authentication center to obtain Nonce ′ , and the decryption result Nonce ′ Sent to the authentication center; where Nonce′=Dec sk (C ′ +Nonce-C), Dec() refers to the decryption algorithm, and sk refers to the private key.
8. According to claim 7, a method for identity information protection authentication based on homomorphic encryption is characterized in that: The authentication center determines whether the identity authentication is successful based on the decryption result, specifically: The authentication center determines the Nonce and Nonce ′ Are they equal? If they are equal, the authentication succeeds; if they are not equal, the authentication fails.
9. According to claim 1, the identity information protection authentication method based on homomorphic encryption is characterized in that: Users can choose suitable homomorphic encryption algorithms including semi-homomorphic encryption algorithms, quasi-homomorphic encryption algorithms and fully homomorphic encryption algorithms.
10. An identity information protection authentication system based on homomorphic encryption, characterized in that The method according to any one of claims 1 to 9 is implemented, comprising: a user end and a server end, wherein the user end comprises a user interaction interface and a user trusted registration center; the server end comprises an authentication center and an identity authentication information ciphertext storage device; specifically: The user interaction interface provides a suitable homomorphic cryptographic algorithm for the user to choose, and can generate identity authentication information ciphertext based on the user identity information using the homomorphic cryptographic algorithm. When the user sends a registration request to the user trusted registration center, the user identity information and the identity authentication information ciphertext are sent to the user trusted registration center, and the user unique identifier generated by the user trusted registration center is received; when the user sends an authentication request, a new ciphertext is regenerated based on the user identity information, the new ciphertext and the user unique identifier are sent to the authentication center, and the authentication center receives the calculation result of the homomorphic addition of the ciphertext based on the authentication request and decrypts the calculation result; The user trusted registration center is the management end trusted by users. It receives the registration request sent by the user interaction interface, generates the user unique identifier of the current registered user, stores the identity authentication information ciphertext and the user unique identifier in the user identity authentication information ciphertext library, and can simultaneously update the user's identity authentication information ciphertext and the user unique identifier to the server's identity authentication information ciphertext storage; The authentication center can receive the user's identity authentication information ciphertext and user unique identifier provided by the user trusted registration center, and store them in the identity authentication information ciphertext storage; when the user issues an authentication request, it receives the new ciphertext and user unique identifier issued by the user interaction interface, retrieves the identity authentication information ciphertext storage based on the user unique identifier, obtains the identity authentication information ciphertext sent by the user when registering, generates a random number, performs ciphertext homomorphic addition operation using the new ciphertext, the random number and the identity authentication information ciphertext sent by the user when registering, and sends the operation result to the user interaction interface; receives the decryption result sent back by the user interaction interface, and determines whether the identity authentication is successful based on the decryption result; The identity authentication information ciphertext storage receives the identity authentication information ciphertext and the user unique identifier of the user synchronously updated by the user trusted registration center.