User equipment factor binding authentication method and system based on user password and equipment identifier

By using the challenge of using a composite order bilinear algorithm in multi-factor identity authentication - response key negotiation step, tightly binding the user password and device identification, solving the problem of unencrypted binding and device identification leakage in the prior art, and achieving high security user equipment factor binding authentication.

CN120185808APending Publication Date: 2025-06-20CHONGQING UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510390522.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

In the existing multi-factor identity authentication technology, user factors and device factors are not encrypted and bound, which poses security risks, and the leakage of device hardware identifiers may lead to the leakage of user privacy information.

Method used

The user equipment factor binding authentication method based on the composite order bilinear algorithm is adopted. Through the challenge-response key negotiation step, the user password and device identification are closely bound, short-term parameters on the user side and the server side are generated, and continuous verification is carried out to ensure the authenticity and freshness of the factors.

Benefits of technology

It realizes the close binding and continuous verification of user factors and device factors, improves security, resists offline password guessing, deterministic device identification, dynamic base number challenges, and ensures forward confidentiality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185808A_ABST
    Figure CN120185808A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of identity authentication, and provides a user equipment factor binding authentication method and system based on a user password and an equipment identifier, and the method comprises the following steps: a challenge-response key negotiation step: a user request sub-step: equipment sends a session starting request to a server; a server challenge sub-step: generating a challenge instruction; a user response sub-step: generating a user side short-term parameter, a user intermediate key and a user authentication code; a server checking sub-step: performing continuous verification on the device identifier and the user password based on the user side short-term parameter, generating a server authentication code, if the server authentication code is consistent with the user authentication code, generating a server session key, and encrypting default information to obtain a ciphertext; a user checking sub-step: generating a user session key and decrypting the ciphertext to obtain decryption information, and if the decryption information is consistent with default information, completing key negotiation; according to the invention, tight binding and continuous verification of the user factor and the equipment factor are realized, and the security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of identity authentication, and particularly to a user device factor binding authentication method and system based on a user password and a device identifier. Background Art

[0002] Although emerging technologies such as fingerprint recognition and facial recognition are becoming increasingly common on smartphones and tablets, password-based methods are still widely used for various devices, especially desktop and laptop computers that may lack standardized biometric sensors. Although the secure storage of passwords does require consideration of hardware conditions (such as full production maintenance TPM or hardware security module HSM), the input of passwords does not require a dedicated device, and employees can input passwords without being affected by the device form factor or environmental limitations. Moreover, organizations have established a large amount of infrastructure and user training for password-based logins. Despite the well-known weaknesses of passwords, such as the risk of reuse, poor complexity, or susceptibility to phishing attacks, it remains a user-friendly fallback method that can function even in traditional and heterogeneous environments.

[0003] In some authentication mechanisms, the server differentiates between different devices by recording device hardware identifiers such as MAC addresses, IMEIs, or chip UIDs. This method is simple and efficient, but it has potential privacy risks. Device hardware identifiers are inherently globally unique, and any third party with access rights or a stealing channel may combine other data for behavioral analysis, resulting in the leakage of information such as user habits and geographical locations.

[0004] Organizations are increasingly relying on multi-factor identity authentication to mitigate the risks brought by stolen passwords or leaked credentials, such as user factors (passwords) and device factors (device identifiers). The core idea behind multi-factor identity authentication is that each factor independently proves identity, thereby reducing the likelihood of successful intrusion if one factor is compromised. However, these factors are not encrypted and bound, and multiple disjoint checks are required. Moreover, attackers may collect individual factors from different sources, or hijack an ongoing session after verifying one factor. Classic man-in-the-middle attacks can also trick users into forwarding valid credentials in real time, posing security risks. Summary of the Invention

[0005] This application aims to at least solve the technical problems existing in the prior art, and provides a user device factor binding authentication method and system based on a user password and a device identifier.

[0006] In a first aspect, the present application provides a user device factor binding authentication method based on a user password and a device identifier, including: a trusted authority initializes system parameters based on a composite-order bilinear algorithm; a server performs registration to obtain a server key pair, and a user performs registration to obtain a user key pair; the user reports device information to the server; a challenge-response key negotiation step is executed, and the challenge-response key negotiation step includes: a user request sub-step: the device sends a session start request to the server; a server challenge sub-step: responds to the session start request and generates a challenge instruction, where the challenge instruction includes server identity, server-side short-term parameters, server random number, random base number, and user salt value; a user response sub-step: the device responds to the challenge instruction, generates user-side short-term parameters based on the user password, device identifier, and user salt value, generates a user intermediate key using the information in the challenge instruction, generates a user authentication code using the shared parameters and the user intermediate key; sends a user response instruction to the server, and the user response instruction includes user identity, user-side short-term parameters, user random number, and user authentication code; where the shared parameters include user identity, server identity, server-side short-term parameters, user-side short-term parameters, server random number, and user random number; a server check sub-step: responds to the user response instruction, continuously verifies the device identifier and the user password based on the user-side short-term parameters, if the continuous verification passes, generates a server intermediate key, generates a server authentication code based on the server intermediate key and the shared parameters, if the server authentication code is the same as the user authentication code, generates a server session key using the server intermediate key and the shared parameters, encrypts the default information using the server session key to obtain a ciphertext, and sends the ciphertext to the device; a user check sub-step: generates a user session key using the shared parameters and the user intermediate key, decrypts the ciphertext using the user session key to obtain decrypted information, if the decrypted information is the same as the default information, the key negotiation is completed.

[0007] In a second aspect, the present application provides a system based on the user device factor binding authentication method based on a user password and a device identifier provided in the first aspect of the present application, including a server and multiple devices communicating with the server, and one or more of the multiple devices belong to a user.

[0008] The beneficial technical effects of the present invention are:

[0009] In the challenge-response key negotiation process between the server and the user, in the user response sub-step, the user password and the device identifier are tightly bound together to generate user-side short-term parameters. In the server check sub-step, the device identifier and the user password are continuously verified directly based on the user-side short-term parameters. On the basis of successful verification of the device identifier, the user password is further verified, realizing the tight binding and continuous verification of user factors and device factors at the cryptography level, and improving security;

[0010] The present invention also realizes dynamic base challenges, specifically manifested in that each time the challenge-response key negotiation step is executed, the server challenge sub-step generates a one-time random element as the random base. In the user response sub-step, the device needs to generate a session-specific user intermediate key based on the random base, which is different each time, ensuring the authenticity and freshness of the device factor;

[0011] In the server verification sub-step, by verifying the consistency between the server authentication code and the user authentication code, it is determined whether both the server and the device have correctly participated in the negotiation process, further improving security;

[0012] In the user verification sub-step, by verifying the consistency between the decrypted information and the default information, it is determined whether both the server and the device have used consistent shared parameters, further improving security. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 is a schematic diagram of the process of the challenge-response key negotiation step in a preferred embodiment of the present invention;

[0014] Figure 2 is a schematic diagram of parameter transfer in the challenge-response key negotiation step in an example;

[0015] Figure 3 is a schematic diagram of the internal connection of the system in a preferred embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0016] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions throughout. The embodiments described below with reference to the drawings are exemplary and are only used to explain the present invention and should not be construed as a limitation of the present invention.

[0017] The hardness of cBDH (Composite Bilinear Diffie-Hellman (cBDH)) supports the security of typical identity-based encryption or signature schemes in composite-order bilinear maps. Intuitively, given an adversary cannot efficiently compute

[0018] Given the group generator one can construct the distribution P(ξ):

[0019] Generate parameters such as bilinear groups based on the composite number N, prime number p, and prime number q:

[0020]

[0021] Select a generator:

[0022]

[0023] wherein, represents a subgroup of prime order p, represents a subgroup of prime order q.

[0024] Select the exponent represents the integer group of order N.

[0025] Construct the "public part"

[0026] Calculate the "challenge value"

[0027] Finally, the distribution P(ξ) is output

[0028] The composite order bilinear Diffie-Hellman (cBDH) problem can be stated as: Given

[0029]

[0030] and an element in one of the following two cases:

[0031] Real scenario:

[0032] Random scenario: where is a subgroup of prime order p within, and D1 is a randomly selected element.

[0033] The algorithm needs to distinguish whether the obtained value is the real value or a random value from The random value.

[0034] The algorithm The advantage when discriminating whether this element is the real value is defined as:

[0035]

[0036] wherein, is generated in the real scenario, while D1 is an element randomly selected from with equal probability in the random scenario. If simply cannot distinguish between real and random, the two probabilities will be approximately equal and the advantage will be close to 0. If can effectively distinguish, then this difference (advantage) will be significantly greater than 0, indicating that it has a non-negligible discrimination ability.

[0037] When, for all polynomial-time algorithms the above advantage can be kept within negligible range, the generator is said to satisfy the composite bilinear Diffie-Hellman (cBDH) assumption. Intuitively, it can be understood that even in a bilinear group of composite order N = pq, given the public part, an adversary still cannot effectively distinguish from a random element in.

[0038] The present invention provides a user device factor binding authentication method based on a user password and a device identifier. In a preferred embodiment, please refer to Appendix Figure 1 and Figure 2 and the method includes:

[0039] First, a system initialization step: A trusted authority initializes system parameters based on a composite order bilinear algorithm, specifically including:

[0040] Using a group generator to generate a multiplicative cyclic group of composite number N N = pq, and the specific generation process is expressed as:

[0041]

[0042] Selecting a first generator g from a subgroup of multiplicative cyclic group whose order is prime number p p , specifically expressed as:

[0043] Selecting a second generator g from a subgroup of multiplicative cyclic group whose order is prime number q q , specifically expressed as:

[0044] Randomly and uniformly selecting a second random parameter α,

[0045] Generating a master secret key msk = (α, p, q) and a master public key

[0046] Releasing public parameters, where the public parameters include the multiplicative cyclic group the first generator g p , the second generator g q , the composite number N, the composite order bilinear mapping the group element mapping function the authentication code hash function H and the session key generation function KDF.

[0047] In this embodiment, is used to map the user identity or the server identity to a group element, H is used for both parties to calculate the authentication code, and KDF is used to derive the final session key. KDF is the abbreviation of Key Derivation Function. Optionally, a set of group elements can also be defined This set of group elements is used to encode the user identity bits and the salted password hash bits as the exponents of the group elements. The identity bits and the salted password hash bits are m bits and n bits respectively.

[0048] Second, the server registration step: The server performs registration to obtain the server key pair. Preferably, it includes:

[0049] The trusted authority generates the server secret key and the server public key according to the server identity and the second random parameter. The server secret key and the server public key form the server key pair. In an example, the server has a unique identity ID S , and the trusted authority uses the second random parameter α to generate the server secret key and the server public key

[0050] After the server obtains the server secret key and the server public key, it performs key correctness verification. Specifically, it verifies whether the equation holds. If it holds, it is confirmed that the server has the correct server secret key. After that, the privacy of the server public key pk S is maintained, and pk S can be published for others to identify.

[0051] Third, the user registration step: The user performs registration to obtain the user key pair. Preferably, it includes:

[0052] The trusted authority generates the user secret key and the user public key according to the user identity and the second random parameter. The user secret key and the user public key form the user key pair. In the above example, according to the user identity ID i and the second random parameter α, the user secret key and the user public key

[0053] After the user obtains the user secret key and the user public key through the device, it performs key correctness verification. Specifically, it verifies whether the equation holds. If it holds, the user obtains a legal identity key pair.

[0054] Fourth, password storage and salting steps: The user's holding device sends a password registration request to the server; the server responds to the password registration request, selects a user salt value for the user, and sends the user salt value to the user's holding device; the user's holding device processes the user password and the user salt value together through hashing to obtain a salted password hash, and uploads the salted password hash to the server; the server stores the user salt value, the salted password hash, the user identity, and the user public key in the secure database in the form of a quadruple.

[0055] In the above example, at a certain moment, user ε i must register password P with the server i . The server selects a random salt salt i and passes it to user ε through a secure channel i , and user ε i calculates the verifier i (salted password hash) and passes it through a secure channel:

[0056] verifier i = HashPassword(salt i , P i )

[0057] In practice, HashPassword is salted hashing processing, and memory-hardening functions such as Argon2, scrypt, etc. should be used, or at least a slower function like PBKDF2 should be used to ensure that the cost of offline password cracking is high.

[0058] Finally, the server stores the following quadruple in the secure database : (ID i , pk i , salt i , verifier i ), so that even if the server is compromised, the attacker will only obtain the salted verifier, rather than the plaintext password.

[0059] Fifth, device registration steps: The user reports the device information to the server. Preferably, it includes:

[0060] (1) Bind the user key and the device unique label to generate a device identifier; in the above example, d ij represents the device identifier of the jth device of user ε i , d ij = f(sk i , l j ) = HashToZ N (sk i ‖l j ), lj is the unique tag of the j-th device, such as MAC address, IEMI, chip UID, etc. sk i represents user ε i 's secret key, ‖ represents the concatenation symbol; HashToZ N (·) represents the hash-to-integer function. The j-th device stores internally (pk i , sk i , d ij ), or can re-export d i when sk ij is known.

[0061] (2) The device generates device registration information according to the second generator and the device identifier, and uploads the device registration information to the server; in the above example, the j-th device generates device registration information (the device registration information is M q and the device identifier d ij generates device registration information (the device registration information is M ij or ),

[0062] (3) The server constructs an active device list and stores the device registration information of the devices in the active device list.

[0063] Sixth, perform the challenge-response key negotiation step. The challenge-response key negotiation step includes two rounds of interaction. Among them, the first round of interaction includes the user request sub-step and the server challenge sub-step, and the second round of interaction includes the user response sub-step, the server check sub-step, and the user check sub-step.

[0064] The first round of interaction includes:

[0065] User request sub-step S1: The device sends a session start request to the server.

[0066] In this embodiment, each user can own more than one device. The devices are not limited to laptop computers, desktop computers, terminal devices, smart phones, and tablet computers. The server is not limited to a cloud server or a traditional server, and other devices or software that can provide data, services, and resources. The user sends a session start request to the server through the currently held device (a device owned by the user). Preferably, the session start request includes the server identity and the user identity, or may further include a request indication identifier, and the request indication identifier is not limited to "Request".

[0067] In one example, the i-th user ε i uses the j-th device among the m devices he owns to send a session start request MsgReq to the server:

[0068] MsgReq = (ID i , ID S , “Request”).

[0069] i is the user index, i ∈ [1, num], where num is the total number of users served by the server. j is the index of the device owned by the i-th user ε i , j ∈ [1, M]. ID i represents the unique user identity of user ε i , which is not limited to being in the form of a number. ID S represents the unique server identity of the server, which is not limited to being in the form of a number.

[0070] Server challenge sub-step S2: Respond to the session start request and generate a challenge instruction, which includes the server identity, server-side short-term parameters, server random number, random base, and user salt value.

[0071] In this embodiment, preferably, responding to the session start request and generating a challenge instruction includes:

[0072] Step S21, select a server temporary exponent, and construct server-side short-term parameters, where the server-side short-term parameters are based on the server public key and exponentiated by the server temporary exponent.

[0073] In the above example, the server S extracts the user identity ID from the session start request i , and determines whether ID i is a registered and active user. An active user is not limited to being within the valid registration period of user ε i at the current time. If it is a registered and active user, the server selects a server temporary exponent a, if it is not a registered and active user, stop the first round of interaction. Construct the server-side short-term parameter A based on the construction principle with the server public key pk S as the base and the server temporary exponent a as the exponent:

[0074]

[0075] where, represents mapping the user identity or server identity to a group element of a subgroup of order prime p , represents mapping the server identity to a group element of a subgroup , and the subgroup is a multiplicative cyclic group of order prime q of the subgroup multiplicative cyclic group It is a multiplicative cyclic group of the composite number N generated by a group generator, where N = pq and q is a prime number. A is a short-term Diffie-Hellman parameter that can ensure forward secrecy.

[0076] In step S22, a first random parameter is selected to construct a random base. The random base has a second generator as the base and the first random parameter as the exponent. The second generator is from a prime-order subgroup with order q.

[0077] In the above example, the server selects a first random parameter r, and and constructs the random base h as:

[0078]

[0079] where g q is the second generator; is a prime-order subgroup with order q and is also a subgroup of the multiplicative cyclic group with order q The multiplicative cyclic group is the multiplicative cyclic group of the composite number N generated by a group generator, where N = pq. The random base h is used to challenge the device identifier, forcing the device to perform an exponential operation on h, i.e., a power function operation, to obtain the short-term parameter third intermediate term Ψ ij (see the description later). ij (Please refer to the description later).

[0080] In step S23, a server random number is selected, and the user salt value is extracted from the secure database.

[0081] In the above example, the server selects a random number as the server random number n S , and this random number n S is also used by the user as a shared parameter to ensure session freshness. The server extracts the user salt value salt i corresponding to the user ε i . The user salt value salt i is stored in the secure database in a quadruple form together with the salted password hash verifier i , the user identity ID i and the user public key pk i when the user password is stored in advance. The user can be verified whether they truly hold the user password through the user salt value.

[0082] In step S24, the server identity, the server-side short-term parameter, the server random number, the random base, and the user salt value are combined to obtain a challenge instruction.

[0083] In the above example, the challenge instruction MsgChal is:

[0084] MsgChal = (ID S , A, n S , salt i , h)

[0085] The second-round interaction includes:

[0086] User response sub-step S3: The device responds to the challenge instruction, generates short-term parameters on the user side based on the user password, device identifier, and user salt value, generates an intermediate user key using the information in the challenge instruction, and generates a user authentication code using the shared parameters and the intermediate user key; sends a user response instruction to the server, and the user response instruction includes the user identity, short-term parameters on the user side, user random number, and user authentication code; wherein, the shared parameters include the user identity, server identity, short-term parameters on the server side, short-term parameters on the user side, server random number, and user random number.

[0087] In this embodiment, in user response sub-step S3, generating short-term parameters on the user side based on the user password, device identifier, and user salt value includes:

[0088] Step S3a1, select a user temporary exponent, and construct the first intermediate term of the short-term parameter. The first intermediate term of the short-term parameter has the user public key as the base and the user temporary exponent as the exponent.

[0089] In the above example, user ε i selects the user temporary exponent b, and constructs the first intermediate term pk of the short-term parameter in the manner of taking the user public key pk i as the base and the user temporary exponent b as the exponent: i b :

[0090]

[0091] Among them, represents mapping the user identity ID i to a group element of a subgroup of order prime p . pk i b is the core of the short-term parameters on the user side, ensuring forward secrecy.

[0092] Step S3a2, hash the user password and the user salt value together to obtain the salted password hash.

[0093] In the above example, user ε i 's salted password hash verifier i , also called the user's verifier:

[0094] verifier i= HashPassword(salt i , P i )

[0095] Among them, HashPassword(,) represents a hash function, preferably but not limited to the memory-hardened hash functions Argon2, scrypt, PBKDF2, preferably a slower memory-hardened hash function, so as to ensure a higher cost for offline password cracking.

[0096] Step S3a3, encode the user identity bits and the salted password hash bits into a second intermediate term of the short-term parameter, and the second intermediate term of the short-term parameter is a subgroup of prime order p. An element in the group.

[0097] In the above example, the trusted authority defines a set of group elements Among them, m represents the number of bits of the user identity ID i , n represents the number of bits of the salted password hash, and the {u l} in the group element group is used to encode the identity bits of the user identity ID i , and the identity bits of the user identity ID i are (I1, I2,..., I l ,..., I m ), I l ∈{0, 1}, l ∈ [1, m], and the {v l} in the group element group is used to encode the bits of the salted password hash (P’1, P’2,..., P’ w ,..., P’ n ), P’ w ∈{0, 1}, w ∈ [1, n]. Therefore, the user identity bits and the salted password hash bits are encoded into the second intermediate term Φ i of the short-term parameter:

[0098]

[0099] Step S3a4, construct a third intermediate term of the short-term parameter, where the third intermediate term of the short-term parameter has a random base and the device identifier as the exponent.

[0100] In the above example, the constructed third intermediate term Ψ ij of the short-term parameter is:

[0101]

[0102] Among them, d ij represents the device identifier of the jth device of the user ε i , d ij = f(sk i,l j ) = HashToZ N (sk i ‖l j ), l j is the unique tag of the j-th device, such as MAC address, IEMI, chip UID, etc. sk i represents the key of user ε i , ‖ represents the concatenation symbol; HashToZ N (·) represents the hash-to-integer function. The device identifier d ij obtained in this way can ensure that: the device identifier is stable, jointly determined by the user's private key sk i and the device tag l j , and the user cannot regenerate the device identifier to avoid revocation or tracking.

[0103] Step S3a5, construct the fourth intermediate term of the short-term parameter. The fourth intermediate term of the short-term parameter takes the product of the second intermediate term and the third intermediate term of the short-term parameter as the base, and the server random number as the exponent.

[0104] In the above example, the fourth intermediate term of the short-term parameter constructed by the j-th device of user ε i is such that the product of the second intermediate term Φ and the third intermediate term Ψ i of the short-term parameter is taken as the base, and the server random number n ij is taken as the exponent. Taking the server random number n S as the power can ensure session freshness. S i

[0105] Step S3a6, take the product of the first intermediate term and the fourth intermediate term of the short-term parameter as the user-side short-term parameter.

[0106] In the above example, the product of the first intermediate term pk i and the fourth intermediate term i b of the short-term parameter constructed by the j-th device of user ε is taken as the user-side short-term parameter B:

[0107]

[0108] The user-side short-term parameter B is a short-term Diffie-Hellman parameter, which ensures both forward secrecy and continuous multi-factor authentication.

[0109] In this embodiment, further preferably, in the user response sub-step S3, generating a user intermediate key using the information in the challenge instruction includes:

[0110] In the user response sub-step, generate a user intermediate key using the information in the challenge instruction, including:

[0111] Step S3b1, construct the first intermediate value of the user intermediate key, where the first intermediate value of the user intermediate key has the server public key as the base and the user temporary exponent as the exponent.

[0112] In the above example, for user ε i the first intermediate value of the user intermediate key constructed by the j-th device is which has the server public key pk S as the base and the user temporary exponent b as the exponent.

[0113] Step S3b2, multiply the first intermediate value of the user intermediate key by the server-side short-term parameter to obtain the second intermediate value of the user intermediate key.

[0114] In the above example, for user ε i the first intermediate value of the user intermediate key constructed by the j-th device is and multiply it by the server-side short-term parameter A in the challenge instruction to obtain the second intermediate value of the user intermediate key

[0115] Step S3b3, process the user key and the second intermediate value of the user intermediate key through a composite-order bilinear mapping to obtain the user intermediate key. The user intermediate key is a key intermediate value in the entire key negotiation process and is used to derive the final session key.

[0116] In the above example, for user ε i the user key sk i and the second intermediate value of the user intermediate key are processed through a composite-order bilinear mapping to obtain the user intermediate key σ i :

[0117]

[0118] In this embodiment, further preferably, in the user response sub-step S3, generate a user authentication code using the shared parameter and the user intermediate key, including:

[0119] Select a user random number, and use the authentication code hash function to process the shared parameter and the user intermediate key to generate the user authentication code. The user random number is also used by the server side to ensure session freshness. The user authentication code can be used to verify whether the other party (server side) has correctly participated in the key negotiation process.

[0120] In the above example, for user ε i , the shared parameter includes the user identity ID i , the server identity IDS User-side short-term parameter B, server-side short-term parameter A, user random number n i and server random number n S Then the user authentication code τ i is:

[0121] τ i = H(ID i , ID S , B, A, n i , n S , σ i ).

[0122] Wherein, H(·) represents the authentication code hash function.

[0123] In the above example, the user response instruction MsgRes generated by the device is:

[0124] MsgRes = (ID i , B, n i , τ i ).

[0125] Server check sub-step S4: In response to the user response instruction, based on the user-side short-term parameter, perform continuous verification of the device identifier and the user password. If the continuous verification passes, generate a server-side intermediate key, generate a server-side authentication code based on the server-side intermediate key and the shared parameter. If the server-side authentication code is consistent with the user authentication code, generate a server-side session key using the server-side intermediate key and the shared parameter, encrypt the default information using the server-side session key to obtain the ciphertext, and send the ciphertext to the device.

[0126] In this embodiment, preferably, in the server check sub-step S4, the continuous verification of the device identifier and the user password based on the user-side short-term parameter includes:

[0127] Step a1, process the user-side short-term parameter and the second generator through a composite order bilinear mapping to obtain the device identifier information to be verified.

[0128] In the above example, for user ε i , the server processes the user-side short-term parameter B and the second generator g q through a composite order bilinear mapping to obtain the device identifier information to be verified

[0129]

[0130] Since the following equation holds:

[0131]

[0132] Furthermore, the following equation holds:

[0133]

[0134] where the device registration information of the j-th device of user ε i is M ij or Therefore, in the device registration step of device j, device j can share the device registration information with the server.

[0135] Step a2: Traverse the active device list. If the default verification information of a device in the active device list matches the device identifier to be verified information, it is considered that the device identifier verification is passed, and step a3 is entered; otherwise, the challenge-response key negotiation step is ended.

[0136] In the above example, the server stores an active device list, and each device's device registration information (M ij or ) is stored in this list. The default verification information of each device in the active device list can be calculated in advance using the first random parameter r Therefore, traverse the active device list to determine the device identifier to be verified information of each device whether it matches the default verification information ( or (M ij )) r ) (i.e., equality). If they are equal, it is considered that the device identifier verification of the currently traversed device is passed, and step a3 is entered. If they are not equal, the default verification information of the next device is traversed. If no matching device appears after traversing the entire active device list, the challenge-response key negotiation step is ended and the session is aborted.

[0137] In this embodiment, further preferably, when no matching device appears after traversing the entire active device list, the device tracking step is started. The device tracking step is: Traverse the illegal devices in the illegal device list of the server. If an illegal device can be matched according to the above matching method, the session participated by the illegal device is blocked or the legitimate user of the illegal device is notified.

[0138] Step a3: The server extracts the salted password hash corresponding to the user from the security database, generates a short-term parameter second intermediate term reference value using the extracted salted password hash and the user identity, and verifies the correctness of the user password and the server random number in the user-side short-term parameters through the short-term parameter second intermediate term reference value. If the user password and the server random number are verified to be passed, the device identifier and the user password are continuously verified to be passed; otherwise, the challenge-response key negotiation step is ended.

[0139] In this embodiment, the salted password hash corresponding to each user is stored in the security database in the form of a quadruple.

[0140] In the above example, the salted password hash verifier is stored in the security database in the form of a quadruple (ID i , pk i , salt i , verifier i ). Using the extracted salted password hash verifier i and the user identity ID i to generate a reference value for the second intermediate term of the short-term parameter (generate the second intermediate term Φ of the short-term parameter according to the method in step S3a3 executed by the terminal i , and call this second intermediate term Φ of the short-term parameter i the reference value Φ i ' of the second intermediate term of the short-term parameter). i ).

[0141] In the above example, the correctness of the user password P i in the user-side short-term parameter B and the server random number n i is verified through the reference value Φ S ' of the second intermediate term of the short-term parameter. Specifically:

[0142] Calculate the password verification reference value Calculate the verification value Φ ' of the second intermediate term of the short-term parameter according to the calculation formula. The server divides the user-side short-term parameter B in the user response instruction by the verification value Φ i ' of the second intermediate term of the short-term parameter to obtain the actual password verification value, and determines whether the password verification reference value is equal to the actual password verification value. If they are equal, it is considered that the user password P i in the user-side short-term parameter B and the server random number n i are correct. If they are not equal, it is considered that the user password P i in the user-side short-term parameter B and / or the server random number n S are incorrect. It can be seen that if the user does not use the correct password or the server random number n S , subsequent verification will fail. i

[0143] In this embodiment, preferably, in the server check sub-step S4, generating the server intermediate key includes:

[0144] Step S4a1, constructing the first intermediate value of the server intermediate key. The first intermediate value of the server intermediate key takes the user public key as the base and the server temporary exponent as the exponent.

[0145] In the above example, the first intermediate value of the server intermediate key is which takes the user's public key pk i as the base and the server's temporary exponent a as the exponent.

[0146] Step S4a2: Multiply the short-term parameters on the user side and the first intermediate value of the server intermediate key to obtain the second intermediate value of the server intermediate key.

[0147] In the above example, multiply the short-term parameter B on the user side in the user response instruction and the first intermediate value of the server intermediate key to obtain the second intermediate value of the server intermediate key

[0148] Step S4a3: Construct the third intermediate value of the server intermediate key. The third intermediate value of the server intermediate key takes the second intermediate term of the short-term parameter as the base and the server random number as the exponent.

[0149] In the above example, the third intermediate value of the server intermediate key takes the second intermediate term Φ i of the short-term parameter as the base and the server random number n S as the exponent.

[0150] Step S4a4: Divide the second intermediate value of the server intermediate key by the third intermediate value of the server intermediate key to obtain the fourth intermediate value of the server intermediate key.

[0151] In the above example, divide the second intermediate value of the server intermediate key by the third intermediate value of the server intermediate key to obtain the fourth intermediate value of the server intermediate key

[0152] Step S4a5: Process the server key and the fourth intermediate value of the server intermediate key through a composite-order bilinear map to obtain the server intermediate key.

[0153] In the above example, process the server key sk S and the fourth intermediate value of the server intermediate key through a composite-order bilinear map to obtain the server intermediate key σ S :

[0154]

[0155] In this embodiment, because subgroup orthogonality ensures that the relevant elements are mapped to the identity element, that is, the device identifier d ij for the composite-order bilinear map The result makes no contribution.

[0156] In this embodiment, preferably, in the server check sub-step S4, the server authentication code is generated based on the server intermediate key and the shared parameters. In the above example, the server uses the shared parameter user identity ID i , server identity ID S , user-side short-term parameter B, server-side short-term parameter A, user random number n i and server random number n S , and the server intermediate key σ S The server authentication code τ is generated by using the authentication code hash function H(·) S as:

[0157] τ S = H(ID i , ID S , B, A, n i , n S , σ S ).

[0158] In this embodiment, preferably, in the server check sub-step S4, if the server authentication code and the user authentication code are consistent, the server session key is generated by using the server intermediate key and the shared parameters, and the default information is encrypted with the server session key to obtain the ciphertext, and the ciphertext is sent to the device. This process specifically includes in the above example:

[0159] If τ S = τ i , it is considered that the server authentication code and the user authentication code are consistent, and the server session key K S is generated by using the server intermediate key σ S = KDF(ID i , ID S , B, A, n i , n S , σ S ), the default information is encrypted with K S to obtain the ciphertext CT, and then the ciphertext is returned to the device j in the form of MsgFin = (ID S , CT); if τ S ≠ τ i , it is considered that the server authentication code and the user authentication code are inconsistent, and the session is aborted. The default information can be any string negotiated by both parties concatenated with the user random number n i , such as the default information is "Finished" ‖ n i , and "Finished" is the string negotiated by both parties. CT = Enc("Finished" ‖ n i , K S)。Enc(,) represents the encryption function. Through the verification of the consistency between the server authentication code and the user authentication code, it can be verified whether both parties have correctly participated in the key negotiation process.

[0160] User check sub-step S5: Generate the user session key using the shared parameters and the user intermediate key, decrypt the ciphertext using the user session key to obtain the decryption information. If the decryption information is consistent with the default information, the key negotiation is completed.

[0161] In the above example, the user check sub-step S5 specifically includes:

[0162] Step S51, user ε i Calculate the user session key K through device j i :

[0163] K i = KDF(ID i , ID S , B, A, n i , n S , σ i ).

[0164] If the shared information used by the user and the server is consistent, then K i = K S .

[0165] Step S52, user ε i Use the negotiated user session key K through device j i Decrypt the ciphertext CT to obtain the decryption information Dec(CT, K i ), and check whether the result meets the expectation Dec(,) represents the decryption function. If the decryption information Dec(CT, K i ) is consistent with the default information, the key negotiation is completed, and user ε i trusts the user session key K i . If the decryption information Dec(CT, K i ) is not the default information "Finished", the key negotiation fails. The correctness of this method lies in ensuring that σ i = σ S , and the proof process mainly uses bilinearity, subgroup orthogonality, and symmetry:

[0166]

[0167] In a preferred embodiment, it further includes: Device revocation step: The user-held device sends a revocation request to the server, where the revocation request carries the device registration information of the device to be revoked; The server responds to the revocation request and deletes the device registration information of the device to be revoked from the active device list.

[0168] In a preferred embodiment, it further includes: a device tracking step: the server checks whether all devices participating in the session are illegal devices in the illegal device list. If the device participating in the session is an illegal device, the session participated by the illegal device is blocked or the legal user of the illegal device is notified.

[0169] The present invention also discloses a system based on the above user equipment factor binding authentication method based on user password and device identifier. Please see the appendix Figure 3 The system includes a server and multiple devices communicating with the server. One or more devices among the multiple devices belong to a user.

[0170] The user equipment factor binding authentication method and system provided by the present invention have the following advantages:

[0171] (1) Resisting offline password guessing. The user password is never directly transmitted in plain text, but is embedded in the subgroup after being salted and hashed for verification. Specifically, the server stores a random user salt value for each user. During authentication, the user password and the user salt value are hashed through a one-way hash (a memory-hardened hash function can be selected) to obtain the salted password hash, and then encoded as an exponent by a group of group elements to participate in subsequent calculations.

[0172] (2) Deterministic device identifier. The device label j First, an irreversible combination operation is performed through the user's private key to generate the device identifier d used inside the method ij , and the latter only appears in the authentication message in the form of group elements. In other words, the real device label is never directly transmitted on the network, and all interactions are encrypted-mapped identifiers. External observers cannot extract the original device hardware identifier from it, thus protecting the privacy of the user equipment.

[0173] (3) Dynamic base challenge. To further ensure the authenticity and freshness of the device factor, the method introduces a dynamic random base challenge mechanism in each authentication. Specifically, the server generates a one-time random element as a new base during the challenge phase and requires the device to calculate a response to it. This means that the device must perform a power operation on different random bases provided by the server using its own identity identifier to generate a session-specific response value. In the second-round user response, the proof of the device factor is reflected in the calculation result, which is different each time.

[0174] (4) Continuous user and device factor authentication. The remarkable feature of this method is that it realizes the tight binding and continuous verification of user factors and device factors at the cryptographic level. Different from the traditional method of separately verifying multiple factors independently, this method combines the two factors into a single cryptographic proof and gradually verifies them, which benefits from the subgroup orthogonality of composite order bilinear groups.

[0175] (5) Forward secrecy. The method achieves forward secrecy by introducing Diffie-Hellman ephemeral key exchange. In each session, the user device and the server each select a one-time use secret ephemeral exponent, and these ephemeral values participate in the negotiation of the session key. The finally generated session key is the result of jointly calculating the existing long-term credentials user password and device identifier with the ephemeral exponent.

[0176] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "example", "specific example", "one implementation manner", "one preferred implementation manner" or "some examples", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0177] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the claims and their equivalents.

Claims

1. A user device factor binding authentication method based on a user password and a device identifier, characterized in that: include: A trusted authority initializes system parameters based on a composite-order bilinear algorithm; The server registers to obtain the server key pair, and the user registers to obtain the user key pair; The user reports device information to the server; Performing a challenge-response key negotiation step, the challenge-response key negotiation step comprising: User request sub-step: the device sends a session start request to the server; Server challenge sub-step: respond to the session start request and generate a challenge instruction, which includes the server identity, server-side short-term parameters, server random number, random base number and user salt value; User response sub-step: the device responds to the challenge instruction, generates the user-side short-term parameters based on the user password, device identification and user salt value, generates the user intermediate key using the information in the challenge instruction, and generates the user authentication code using the shared parameters and the user intermediate key; sends the user response instruction to the server, the user response instruction includes the user identity, the user-side short-term parameters, the user random number and the user authentication code; wherein the shared parameters include the user identity, the server identity, the server-side short-term parameters, the user-side short-term parameters, the server random number and the user random number; The server check sub-step: respond to the user response instruction, perform continuous verification of the device identification and user password based on the user-side short-term parameters, if the continuous verification passes, generate a server intermediate key, generate a server authentication code based on the server intermediate key and the shared parameters, if the server authentication code is consistent with the user authentication code, generate a server session key using the server intermediate key and the shared parameters, encrypt the default information using the server session key to obtain the ciphertext, and send the ciphertext to the device; User checking sub-step: Generate a user session key using the shared parameters and the user intermediate key, and use the user session key to decrypt the ciphertext to obtain the decrypted information. If the decrypted information is consistent with the default information, key negotiation is completed.

2. The user device factor binding authentication method based on user password and device identification as claimed in claim 1, characterized in that: In the server-side challenge sub-step, responding to the session initiation request and generating a challenge instruction includes: Select the server temporary index and construct the server-side short-term parameters, where the server-side short-term parameters use the server public key as the base and the server temporary index as the exponent; Selecting a first random parameter, constructing a random base, wherein the random base has a second generator as a base and the first random parameter as an exponent, and the second generator is derived from a prime-order subgroup whose order is a prime number q; Select the server random number and extract the user salt value from the security database; The challenge instruction is obtained by combining the server identity, server-side short-term parameters, server random number, random base number and user salt value.

3. The user device factor binding authentication method based on user password and device identification as claimed in claim 1, characterized in that: In the user response sub-step, generating user-side short-term parameters based on the user password, device identification and user salt value includes: Select the user's temporary index and construct the first intermediate term of the short-term parameter. The first intermediate term of the short-term parameter takes the user's public key as the base and the user's temporary index as the exponent; Hash the user password and the user salt value together to obtain the salted password hash; Encode the user identity bit and the salted password hash bit into a short-term parameter second intermediate term, the short-term parameter second intermediate term being a group element in a prime-order subgroup whose order is a prime number p; Constructing a short-term parameter third intermediate term, the short-term parameter third intermediate term having a random base as a base and a device identifier as an exponent; Construct the fourth intermediate term of the short-term parameter, which takes the product of the second intermediate term of the short-term parameter and the third intermediate term of the short-term parameter as the base and takes the random number of the server as the exponent; The product of the first intermediate term of the short-term parameter and the fourth intermediate term of the short-term parameter is used as the user-side short-term parameter.

4. The user device factor binding authentication method based on user password and device identification as claimed in claim 3, characterized in that: In the user response sub-step, generating a user intermediate key using information in the challenge instruction includes: Constructing a first intermediate value of a user intermediate key, wherein the first intermediate value of the user intermediate key has a server public key as a base and a user temporary index as an exponent; Multiplying the first intermediate value of the user intermediate key by the short-term parameter on the server side to obtain a second intermediate value of the user intermediate key; The user key and the second intermediate value of the user intermediate key are processed by composite-order bilinear mapping to obtain the user intermediate key.

5. The user device factor binding authentication method based on user password and device identification as claimed in claim 2, characterized in that: In the server-side checking sub-step, the device identification and user password continuous verification based on the user-side short-term parameters includes: Step a1, the user-side short-term parameter and the second generator are processed by composite-order bilinear mapping to obtain the device identification information to be verified; Step a2, traverse the active device list. If there is a device in the active device list whose default verification information matches the device identification information to be verified, it is considered that the device identification verification is successful, and proceed to step a3. Otherwise, the challenge-response key negotiation step is terminated. In step a3, the server extracts the salted password hash corresponding to the user from the security database, generates the second intermediate item reference value of the short-term parameter using the extracted salted password hash and the user identity, and verifies the correctness of the user password and the random number of the server in the short-term parameter on the user side through the second intermediate item reference value of the short-term parameter. If the user password and the random number of the server are verified, the device identification and the user password are verified continuously, otherwise the challenge-response key negotiation step is terminated.

6. The user device factor binding authentication method based on user password and device identification as claimed in claim 5, characterized in that: In the server-side checking sub-step, generating a server-side intermediate key includes: Constructing a first intermediate value of a server intermediate key, wherein the first intermediate value of the server intermediate key has a user public key as a base and a server temporary index as an exponent; Multiply the user-side short-term parameter and the server-side intermediate key first intermediate value to obtain the server-side intermediate key second intermediate value; Constructing a third intermediate value of the server intermediate key, wherein the third intermediate value of the server intermediate key has the second intermediate term of the short-term parameter as a base and the server random number as an exponent; Dividing the second intermediate value of the server intermediate key by the third intermediate value of the server intermediate key to obtain a fourth intermediate value of the server intermediate key; The server key and the fourth intermediate value of the server intermediate key are processed by composite-order bilinear mapping to obtain the server intermediate key.

7. The user device factor binding authentication method based on user password and device identification as claimed in claim 5, characterized in that: The trusted authority initializes system parameters based on a composite-order bilinear algorithm, including: Generate a multiplicative cyclic group of a composite number N using a group generator N = pq; From the multiplicative cyclic group The subgroup of the prime number p Select the first generator g p ; From the multiplicative cyclic group The subgroup of the prime number q Select the second generator g q ; The second random parameter α is selected uniformly at random; Generate a master key and a master public key; Public parameters are published, including a multiplication cyclic group The first generator g p , the second generator g q , composite number N, composite order bilinear mapping Group element mapping function Authentication code hash function H and session key generation function KDF.

8. The user device factor binding authentication method based on user password and device identification as claimed in claim 7, characterized in that: The server registers to obtain a server key pair, including: a trusted authority generates a server key and a server public key according to the server identity and a second random parameter; after the server obtains the server key and the server public key, it verifies the correctness of the key, and the server key and the server public key form a server key pair; And / or, the user registering to obtain a user key pair includes: a trusted authority generates a user key and a user public key according to the user identity and a second random parameter; the user obtains the user key and the user public key through a device and then verifies the correctness of the key; the user key and the user public key form a user key pair; And / or, password storage and salting steps: the user's device initiates a password registration request to the server; the server selects a user salt value for the user in response to the password registration request, and sends the user salt value to the user's device; the user's device hashes the user password and the user salt value together to obtain a salted password hash, and uploads the salted password hash to the server; the server stores the user salt value, the salted password hash, the user identity and the user public key in a security database in the form of a four-tuple; And / or, the user reports device information to the server, including: binding the user key and the device unique tag to generate a device identifier; the device generates device reporting information based on the second generator and the device identifier, and uploads the device reporting information to the server; the server builds an active device list and stores the device reporting information of the device in the active device list.

9. The user device factor binding authentication method based on user password and device identification as claimed in claim 8, characterized in that: The method further comprises: Device revocation step: the user holds the device and sends a revocation request to the server, wherein the revocation request carries the device registration information of the device to be revoked; the server responds to the revocation request and deletes the device registration information of the device to be revoked from the active device list; and / or, Device tracking step: The server checks whether all devices participating in the session are illegal devices in the illegal device list. If the device participating in the session is an illegal device, the session in which the illegal device participates is blocked or the legal user of the illegal device is notified.

10. A system based on the user device factor binding authentication method based on user password and device identification according to any one of claims 1 to 9, characterized in that: It includes a server and multiple devices communicating with the server, and more than one of the multiple devices belongs to one user.