Web3-oriented distributed identity authentication method and device based on chameleon signature
By using chameleon signature algorithm and blockchain technology in the distributed identity authentication system, the problems of VP non-transferability and high overhead are solved, efficient and secure identity authentication is achieved, and it is in line with the decentralized characteristics of Web3.
Patent Information
- Application Number
- CN202510339256.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-03-21
AI Technical Summary
In the existing distributed identity authentication system, the non-transferability of VPs is difficult to effectively realize, resulting in illegal entities that may impersonate user identity and acquire network resources. In addition, traditional solutions have high communication and storage overhead, and the authentication efficiency is low.
Using the chameleon signature algorithm based on discrete logarithmic assumption, the entity generates a public-private key pair in the registration stage and uploads the mapping of the identification and public key to the blockchain. The certificate issuer uses the private key signature to verify the credentials, the user uses the private key signature to verify the declaration, and the verifier uses the hash verification function to verify the user's identity.
It realizes the non-transferability of certificates, reduces communication and storage overhead, improves authentication efficiency, conforms to the characteristics of Web3 decentralization, and reduces the risk of illegal use of identity.
Smart Images

Figure CN120185886A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular, to a distributed identity authentication method and device based on chameleon signature for Web3. Background Art
[0002] The fifth-generation mobile communication technology (5G) provides a stable and efficient network environment for blockchain applications with its characteristics of high speed, large capacity, and low latency, improving the overall performance of the blockchain network, thus giving birth to Web3. Web3 aims to create an open, decentralized, and user-data-sovereign Internet environment. However, existing identity authentication systems rely on centralized authoritative institutions, which contradicts the decentralized characteristics of Web3. Therefore, decentralized identity (DID) has been proposed. Decentralized identity is based on blockchain technology, is a more robust identity authentication scheme that protects user privacy, and gives users the autonomy to manage their own identities and certificates. The present invention has received extensive attention in the academic and industrial fields.
[0003] A typical distributed identity authentication structure is as Figure 1 shown. In this system, there are three entities, namely the certificate issuer, the user, and the certificate verifier.
[0004] 1) The certificate issuer is generally served by an authoritative institution. In the registration stage, the certificate issuer locally generates an identity identifier (Identifier) id i and a public-private key pair (sk i , pk i ). The public key sk i is saved locally, and the mapping of id i and the public key pk i is published on the blockchain. In the certificate issuance stage, the certificate issuer signs the relevant attribute information with the private key, that is, generates a verifiable credential (VC). The VC is used to prove the user's attributes. For example, the VC proves that a certain user is over 18 years old. After generation, the VC is sent to the corresponding user.
[0005] 2) Similar to the certificate issuer, the user generates an identity identifier id u and a public-private key pair (sk u , pk u ) in the registration stage, and publishes the mapping of id u and pk uThe mapping is published on the blockchain. Subsequently, a verifiable credential can be applied for from the certificate issuer to prove user attributes. After successful application, the certificate is stored locally. During the certificate usage phase, the user uses sk u to sign the VC, generating a Verifiable Presentation (VP) to obtain network resources. The signature can prove ownership of the certificate and ensure that other entities that obtain the VC cannot use the certificate for authentication.
[0006] 3) The verifier is generally a web service. By obtaining the public keys pk i and pk u of the certificate issuer and the user from the blockchain, it verifies the user's certificate. After successful authentication, it provides the corresponding network resources to the user.
[0007] Since the number of certificate issuers and verifiers in the system is small, and the interaction between these two entities and users is frequent, the public keys of these two entities are known to most entities.
[0008] The non - forwardability problem of VP is a key issue in the DID scenario. It requires that even if an illegal entity obtains a user's VP, it cannot use the certificate for identity authentication. The illegal entity that obtains the VP can use it to pass third - party authentication, thus achieving the purpose of impersonating the user's identity. Although the non - transferability problem of certificates generally exists in certificate - based authentication systems, it is particularly prominent in a distributed identity architecture. This is because the DID system gives users autonomous management rights over their identity certificates, and it is difficult to fully control users' behaviors. Therefore, the risk of certificate abuse or transfer increases significantly. This problem has attracted wide attention in the academic and industrial circles.
[0009] Specifically, if an illegal entity can obtain a user's verifiable presentation VP u , since the VP u contains a legitimate signature, this illegal user can claim to be the owner of the certificate and use it for authentication to achieve the purpose of identity impersonation. Specifically, as Figure 2 shown, user id u sends the verifiable presentation VP u to verifier 1. The VP u not only proves the user attributes but also proves the user's ownership of the certificate. And verifier 1 can impersonate the identity of user id u by virtue of the VP u . Specifically, after verifier 1 obtains the VP u , it sends the VP u to verifier 2. Since the VP uLegal. Verifier 2 passes the authentication through VP u and Verifier 1 successfully passes the authentication of Verifier 2 with the identity of id u and illegally obtains the network resources provided by Verifier 2.
[0010] The existing research on the non - transferability of VP (Verifiable Presentation) is mainly based on the Challenge mechanism. The specific process is as follows:
[0011] 1) The user initiates an authentication request;
[0012] 2) The verifier generates a 128 - bit random number c locally and sends the random number to the user;
[0013] 3) The user concatenates VC (Verifiable Credential) and c, and uses the user's private key sk i to sign, denoted as Sig I , and VP u = {VC, Sig I}, and sends VP u to the verifier;
[0014] 4) The verifier verifies c and the signature Sig I , and returns the authentication result to the user.
[0015] This scheme can ensure the non - transferability of VP because the probability that the verifier generates the same random number as the challenge is negligible. So even if VP u can be obtained, the authentication will fail due to the incorrect challenge.
[0016] Although the existing methods can achieve the non - transferability of VP, there are problems of high overhead and low efficiency.
[0017] 1) High communication overhead. This is because in the challenge - based authentication scheme, the user and the verifier need to interact multiple times, which will lead to unnecessary communication overhead, especially when the network distance between the user and the verifier is far.
[0018] 2) Large storage overhead. This is because the verifier needs to store the mapping relationship between the user identity and the random number until the end of the authentication process.
[0019] 3) Low authentication efficiency. This is because the user and the verifier interact to transfer the random number. When the number of authentication requests increases, the authentication time is prolonged, reducing the overall efficiency and affecting the scalability of the system. Summary of the Invention
[0020] To solve the technical problems existing in the prior art, the present invention provides a distributed identity authentication method and device based on chameleon signature for Web3, which realizes the non-transferability of certificates while reducing communication overhead, storage overhead, and improving authentication efficiency.
[0021] The present invention provides a distributed identity authentication method based on chameleon signature for Web3, including the following steps:
[0022] Entity registration process: The entity uses the local device to generate a public-private key pair based on the discrete logarithm assumption; the entity includes a certificate issuer, a user, and a verifier.
[0023] Certificate issuance process: The verifier uses the chameleon signature algorithm based on the discrete logarithm assumption to issue a verifiable credential to the user.
[0024] Certificate usage process: The user uses the chameleon signature algorithm based on the discrete logarithm assumption to sign the received verifiable credential to obtain a verifiable statement and send it to the verifier.
[0025] Certificate verification process: After receiving the verifiable statement, the verifier uses the chameleon signature algorithm based on the discrete logarithm assumption to verify the user.
[0026] Preferably, the entity registration process includes the following steps:
[0027] The entity uses the local device to generate a public-private key pair locally based on the discrete logarithm assumption.
[0028] Upload the mapping relationship between the entity's identifier and the public key to the blockchain. The process of the entity managing the private key and the identifier does not require the participation of a trusted third party.
[0029] Preferably, the entity registration process specifically includes the following steps:
[0030] The entity uses the local device to randomly select an element in as the private key sk and calculate the corresponding public key pk = g sk mod p;
[0031] The entity uploads the mapping of id and pk to the blockchain by issuing a transaction.
[0032] Among them, both p and q are prime numbers greater than a preset value and satisfy p mod q = 1, g is an element in representing the generator, represents the multiplicative group modulo q, represents the multiplicative group modulo p.
[0033] Preferably, the certificate issuance process includes the following steps:
[0034] The certificate issuer uses a private key to sign the relevant authentication information based on the discrete logarithm hard problem assumption, and issues the verifiable credential VC u to the user. The relevant authentication information includes the certificate issuer identifier id i and the user identifier id u and the attribute attr. The verifiable credential includes the proofs of each relevant authentication information. This certificate is used for identity authentication and user authorization.
[0035] Preferably, the certificate issuance process specifically includes the following steps:
[0036] The certificate issuer uses the ElGamal signature algorithm based on the discrete logarithm hard assumption, and adopts a hash function to combine the relevant authentication information with the signature Sig of the certificate issuer i to form the verifiable credential VC u , Vc u ={id i , id u , attr, Sig i}. After receiving the certificate, the user stores the certificate using a local device.
[0037] Preferably, the hash function is SHA256.
[0038] Preferably, the certificate usage process includes the following steps:
[0039] When the user wants to use the certificate, the user uses the chameleon hash function, inputs the received verifiable credential VC u , the public key pk of the verifier v and the random number r to obtain the corresponding hash value h, h = Ch_Hash(VC u , pk v ; r). Then the user uses their own private key to sign the hash value h using the signature function to obtain the verifiable statement VP u , and sends the verifiable statement VP u to the verifier.
[0040] Preferably, the certificate usage process includes the following steps:
[0041] The user retrieves the public key pk of the verifier from the blockchain v ;
[0042] The user encodes the verifiable credential VC u onto the group to obtain m1, and randomly selects a random number r from ;
[0043] With m1, the public key pk of the verifier vUse the random number r as the input of the chameleon hash function, and calculate the hash value h using the following formula:
[0044]
[0045] The user uses the hash value h and the private key sk u as the input, and uses the signature algorithm based on the discrete logarithm assumption to complete the signature operation. The formula is as follows:
[0046] Sig u = sign(sk u , h)
[0047] The user sends the verifiable claim VP u to the verifier in an encrypted communication manner. The verifiable claim VP u includes the verifier's public key, the verifiable credential VC u , the random number r, and the signature Sig u , that is, VP u = {VC u , r, pk v , Sig u};
[0048] Among them, both p and q are prime numbers greater than the preset value, and p mod q = 1. g is an element in, representing the generator, represents the multiplicative group modulo q, represents the multiplicative group modulo p.
[0049] Preferably, after receiving the verifiable claim, the verifier uses the chameleon signature algorithm based on the discrete logarithm assumption to verify the user, which specifically includes the following four aspects of verification:
[0050] 1) Verify whether the proof of the attributes in the verifiable credential VC u meets the requirements of the verifier;
[0051] 2) The verifier checks the trapdoor information: Input the verifiable credential, the verifier's public key, and the random number r, and use the chameleon hash function to calculate the hash value h' = Ch_Hash(VC u , pk v , r), and compare whether the hash value h' is equal to the hash value h;
[0052] 3) Verify the public key consistency: The verifier retrieves the public keys pk u of the user and the verifier from the blockchain i ;
[0053] 4) Verify whether the signatures of the certificate issuer and the user are consistent;
[0054] If all four aspects pass the verification, the verifier considers that the user has passed the authentication.
[0055] Preferably, the verifier's check of the trapdoor information specifically includes:
[0056] The verifier checks whether the verifier's public key pk provided by the user v matches the verifier's own public key.
[0057] If they match, it is considered that the trapdoor information is correct, and the trapdoor information is used to calculate the hash value.
[0058] If they do not match, the verifier's public key pk provided by the user v is further verified.
[0059] If the verifier's public key pk provided by the user v is the public key of another verifier, the verification fails, and it is considered that the verifiable claim VP u has no credibility.
[0060] If the verifier's pk provided by the user v is not the public key of another verifier, the correct public key of the verifier is sent to the user, and the user uses the correct public key to recalculate the hash value and perform a signature operation to generate a new verifiable claim and re - perform the authentication.
[0061] If the trapdoor information check passes, the verifier inputs the verifiable credential VC u , the random number r, the verifier's public key pk v and the hash value h into the hash verification function Ch_Ver().
[0062] The hash verification function Ch_Ver() calculates the hash value h′ of the verifiable credential VC u and compares whether the hash value h′ is equal to the hash value h. If the comparison is successful, it is considered that the verifiable claim VP u has not been tampered with during transmission, outputs 1, and considers the verification successful; otherwise, outputs 0 and considers the verification failed.
[0063] Preferably, the hash verification function Ch_Ver() specifically operates as follows:
[0064] Encode the verifiable credential VC u in the verifiable claim VP u onto the group to obtain m2. Then, based on m2, the verifier's public key pk v and the random number r are used to calculate the hash value h′ using the following formula:
[0065]
[0066] Compare whether the hash value h' is equal to the hash value h. If the comparison is successful, output 1 and consider the verification successful; otherwise, output 0 and consider the verification failed.
[0067] The present invention also provides a distributed identity authentication device for Web3 based on chameleon signature, including a processor, and the processor can execute the steps of the above-mentioned distributed identity authentication method for Web3 based on chameleon signature.
[0068] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0069] 1. The present invention realizes efficient identity authentication and user authorization in the Web3 scenario. On the one hand, in the present invention, the certificate can not only be used to prove the user's identity, but also to prove the user's attributes. On the other hand, in the present invention, the process of the user managing the identity and the certificate does not require the participation of a trusted third party, and this authentication process conforms to the decentralized theme of Web3.
[0070] 2. The present invention realizes efficient non-transferability of verifiable claims. The present invention utilizes the non-transferable characteristic of chameleon signature, and by endowing the verifier with the ability to modify the certificate, the risk that the verifier illegally misuses the user's identity and then steals network resources in an illegal way is reduced.
[0071] 3. Compared with the traditional scheme, the present invention reduces the communication overhead. In the traditional scheme, it is required that the user and the verifier interact multiple times, resulting in a large communication overhead. While in the present invention, it is only required that the user interacts with the adjacent blockchain full node once and with the verifier once, reducing the communication overhead.
[0072] 4. Compared with the traditional scheme, the present invention reduces the storage overhead. In the traditional scheme, it is required that the verifier not only needs to store the verifiable claim being authenticated, but also needs to maintain the mapping of the user identifier and the challenge value until the authentication is completed. While in the present invention, the verifier only needs to store the verifiable claim of the user being authenticated, greatly reducing the storage overhead of the verifier.
[0073] 5. Compared with the traditional scheme, the present invention improves the authentication efficiency in the Web3 scenario and reduces the time overhead caused by authentication. This is because in the traditional scheme, the user needs to generate a verifiable claim according to the random number of the verifier, and the generation and transmission of the random number may cause a large time overhead, especially when the verifier needs to process a large number of authentication requests. While in the present invention, the user generates a signature according to the public key of the verifier. Compared with obtaining a random number from the verifier, obtaining the public key from the adjacent full node has a small time overhead, effectively reducing the authentication time and improving the overall authentication efficiency. Description of the Drawings
[0074] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on the structures shown in these drawings.
[0075] Figure 1 It is a schematic diagram of a typical framework for distributed identity authentication in the prior art.
[0076] Figure 2 It is a schematic diagram of an example that breaks the non-transferability of certificates in the prior art.
[0077] Figure 3 It is a schematic diagram of the technical route of the distributed identity authentication method based on chameleon signature for Web3 of the present invention.
[0078] Figure 4 It is a schematic diagram of the present invention using the hash generation algorithm of chameleon signature to generate the hash value h using the verifiable credential VC.
[0079] Figure 5 It is a schematic diagram of the present invention using the hash verification algorithm in chameleon signature to verify the trapdoor information.
[0080] Figure 6 It is a schematic diagram of the present invention using the hash collision algorithm in chameleon signature to modify the certificate.
[0081] Figure 7 It is a flowchart of the distributed identity authentication method based on chameleon signature for Web3 of the present invention. Detailed implementation manners
[0082] The following will make a detailed description of the specific implementation manners of the present invention.
[0083] As Figures 3 - 7 shown, the present invention provides a distributed identity authentication method based on chameleon signature for Web3, including the following steps:
[0084] Entity registration process. Since the Web3 scenario requires users to have the sovereignty to manage their own certificates and identities, in the registration stage, the entity generates a public-private key pair based on the discrete logarithm assumption; the entity includes a certificate issuer, a user, and a verifier;
[0085] Certificate issuance process. The verifier uses the chameleon signature algorithm based on the discrete logarithm assumption to issue the verifiable credential to the user;
[0086] During the certificate usage process, the user uses the chameleon signature algorithm based on the discrete logarithm assumption to sign the received verifiable credential, obtaining a verifiable claim, and sending it to the verifier;
[0087] During the certificate verification process, after receiving the verifiable claim, the verifier uses the chameleon signature algorithm based on the discrete logarithm assumption to verify the user.
[0088] According to a specific implementation of the present invention, the entity registration process includes the following steps:
[0089] The entity uses the local device to generate a public-private key pair locally based on the discrete logarithm assumption;
[0090] Upload the mapping relationship between the entity's identifier and the public key to the blockchain. The process of the entity managing the private key and the identifier does not require the participation of a trusted third party.
[0091] According to a specific implementation of the present invention, the entity registration process specifically includes the following steps:
[0092] The entity uses the local device to randomly select an element in as the private key sk, and calculates the corresponding public key pk = g sk mod p;
[0093] The entity uploads the mapping of id and pk to the blockchain by issuing a transaction;
[0094] Among them, both p and q are prime numbers greater than a preset value, and satisfy p mod q = 1, g is an element in , representing the generator, represents the multiplicative group modulo q, represents the multiplicative group modulo p.
[0095] According to a specific implementation of the present invention, the certificate issuance process includes the following steps:
[0096] The certificate issuer uses the signature algorithm based on the discrete logarithm problem assumption with the private key to sign the relevant authentication information, and issues the verifiable credential VC u to the user. The relevant authentication information includes the certificate issuer identifier id i , the user identifier id u and the attribute attr. The verifiable credential includes the proof of each relevant authentication information. This certificate is used for identity authentication and user authorization.
[0097] According to a specific implementation of the present invention, the certificate issuance process specifically includes the following steps:
[0098] The certificate issuer uses the ElGamal signature algorithm based on the discrete logarithm hard assumption, adopts a hash function, and combines the relevant authentication information with the signature Sig of the certificate issuer i to form a verifiable credential VC u , VC u = {id i , id u , attr, Sig i}. After receiving the certificate, the user stores the certificate using the local device.
[0099] According to a specific implementation of the present invention, the hash function is SHA256.
[0100] According to a specific implementation of the present invention, the process of using the certificate includes the following steps:
[0101] When the user wants to use the certificate, the user uses the chameleon hash function, inputs the received verifiable credential VC u , the public key pk of the verifier v and the random number r to obtain the corresponding hash value h, h = Ch_Hash(VC u , pk v ; r), and then the user uses their own private key to sign the hash value h using the signature function to obtain the verifiable claim VP u , and sends the verifiable claim VP u to the verifier.
[0102] According to a specific implementation of the present invention, the process of using the certificate includes the following steps:
[0103] The user retrieves the public key pk of the verifier from the blockchain v ;
[0104] The user encodes the verifiable credential VC u onto the group to obtain m1, and randomly selects a random number r from ;
[0105] Taking m1, the public key pk of the verifier v and the random number r as the input of the chameleon hash function, calculate the hash value h using the following formula:
[0106]
[0107] The user uses the hash value h and the private key sk u as the input, and completes the signature operation using the signature algorithm based on the discrete logarithm assumption. The formula is as follows:
[0108] Sig u = sign(sku , h)
[0109] The user sends the verifiable presentation VP u to the verifier in an encrypted communication manner. The verifiable presentation VP u includes the verifier's public key, the verifiable credential VC u , a random number r, and a signature Sig u , that is, VP u = {VC u , r, pj v , Sig u};
[0110] Among them, both p and q are prime numbers greater than a preset value, and p mod q = 1. g is an element in, representing a generator, represents the multiplicative group modulo q, represents the multiplicative group modulo p.
[0111] According to a specific implementation of the present invention, after receiving the verifiable presentation, the verifier uses the chameleon signature algorithm based on the discrete logarithm assumption to verify the user, which specifically includes the following four aspects of verification:
[0112] 1) Verify whether the proof of the attributes in the verifiable credential VC u meets the requirements of the verifier;
[0113] 2) The verifier checks the trapdoor information: Input the verifiable credential, the verifier's public key, and the random number r, and use the chameleon hash function to calculate the hash value h' = Ch_Hash(VC u , pk v , r), and compare whether the hash value h' is equal to the hash value h;
[0114] 3) Verify the public key consistency: The verifier retrieves the public keys pk u of the user and the verifier from the blockchain i ;
[0115] 4) Verify whether the signatures of the certificate issuer and the user are consistent;
[0116] If all four aspects pass the verification, the verifier considers that the user passes the authentication.
[0117] According to a specific implementation of the present invention, the verifier's checking of the trapdoor information specifically includes:
[0118] The verifier checks whether the verifier's public key pk v provided by the user matches the verifier's own public key,
[0119] If a match is found, the trapdoor information is considered correct, and the trapdoor information is used to calculate the hash value.
[0120] If there is no match, the verifier public key pk provided by the user v is further verified.
[0121] If the verifier public key pk provided by the user v is the public key of another verifier, the verification fails, and the verifiable claim VP u is considered not credible.
[0122] If the verifier pk provided by the user v is not the public key of another verifier, the correct public key of the verifier is sent to the user. The user uses the correct public key to recalculate the hash value and perform a signature operation to generate a new verifiable claim and re - authenticate.
[0123] If the trapdoor information check passes, the verifier inputs the verifiable credential VC u , the random number r, the verifier public key pk v and the hash value h into the hash verification function Ch_Ver().
[0124] The hash verification function Ch_Ver() calculates the hash value h′ of the verifiable credential VC u , and compares whether the hash value h′ is equal to the hash value h. If the comparison is successful, the verifiable claim VP u is considered not tampered with during transmission, outputs 1, indicating successful verification, otherwise outputs 0, indicating failed verification.
[0125] According to a specific implementation of the present invention, the hash verification function Ch_Ver() specifically operates as follows:
[0126] Encode the verifiable credential VC u in the verifiable claim VP u onto the group to obtain m2. Then, based on m2, the public key pk of the verifier v and the random number r are used to calculate the hash value h′ using the following formula:
[0127]
[0128] Compare whether the hash value h′ is equal to the hash value h. If the comparison is successful, output 1, indicating successful verification, otherwise output 0, indicating failed verification.
[0129] The present invention also provides a distributed identity authentication device based on chameleon signature, including a processor, and the processor can execute the steps of the above - mentioned distributed identity authentication method based on chameleon signature for Web3.
[0130] Example 1
[0131] As Figures 3 - 7 shown, the present invention provides a distributed identity authentication method based on chameleon signatures for Web3, including the following steps:
[0132] Entity registration process, where an entity generates a public-private key pair based on the discrete logarithm assumption; the entity includes a certificate issuer, a user, and a verifier;
[0133] Certificate issuance process, where a verifier uses a chameleon signature algorithm based on the discrete logarithm assumption to issue a verifiable credential to a user;
[0134] Certificate usage process, where a user uses a chameleon signature algorithm based on the discrete logarithm assumption to sign the received verifiable credential to obtain a verifiable claim and send it to the verifier;
[0135] Certificate verification process, where after receiving the verifiable claim, the verifier uses a chameleon signature algorithm based on the discrete logarithm assumption to verify the user.
[0136] Example 2
[0137] As Figures 3 - 7 shown, the present invention provides a distributed identity authentication method based on chameleon signatures for Web3, including the following steps:
[0138] The present invention provides a distributed identity authentication method based on chameleon signatures for Web3, including the following steps:
[0139] Entity registration process, where an entity generates a public-private key pair based on the discrete logarithm assumption; the entity includes a certificate issuer, a user, and a verifier;
[0140] Different from the traditional scheme, in this embodiment, the entity of the present invention uses a local device to generate a public-private key pair (sk, pk) based on the discrete logarithm assumption and uploads the mapping of the identifier and the public key to the blockchain. The process of the entity managing the private key and the identifier does not require the participation of a trusted third party. The entity here includes a certificate issuer, a user, and a verifier.
[0141] The present invention first gives some definitions of public parameters. Both p and q are large prime numbers, greater than a preset value, and satisfy p mod q = 1. g is an element of representing the multiplicative group modulo q, representing the multiplicative group modulo p.
[0142] The entity first locally generates an identifier id and a public-private key pair, and then uploads the mapping of id and the public key pk to the blockchain.
[0143] Specifically, in this embodiment, first, the entity randomly selects an element in as the private key sk using the local device, and calculates the corresponding public key pk = g sk mod p. After that, the entity uploads the mapping of id and pk to the blockchain by issuing a transaction. In the present invention, the user's identifier and public-private key pair are denoted as (id u , sk u , pk u ), the verifier's identifier public-private key pair is denoted as (id v , sk v , pk v ), and the certificate issuer's public-private key pair is denoted as (id i , sk i , pk i ).
[0144] In the certificate issuance process, the verifier uses the chameleon signature algorithm based on the discrete logarithm assumption to issue a verifiable credential to the user, and this certificate is used for identity authentication and user authorization.
[0145] Similar to the traditional scheme, the certificate issuer signs the relevant authentication information using the private key. The relevant authentication information includes the certificate issuer identifier id i , the certificate holder (i.e., the user) identifier id u and the attribute attr.
[0146] Different from the traditional scheme, in this embodiment, in the certificate issuance process of the present invention, only the signature algorithm based on the discrete logarithm hard assumption can be used, such as the ElGamal signature algorithm. In the certificate issuance stage, the certificate issuer can adopt any hash function, such as SHA256. The relevant authentication information and the signature Sig i of the certificate issuer together form the verifiable credential VC u , VC u = {id i , id u , attr, Sig i}. After receiving the certificate, the user stores the certificate using the local device.
[0147] In the certificate usage process, the user uses the chameleon signature algorithm based on the discrete logarithm assumption to sign the received verifiable credential to obtain a verifiable statement, and sends it to the verifier; the present invention designs a certificate usage mechanism based on chameleon signature to achieve the non-transferability of the certificate, as shown in the certificate usage mechanism part of Algorithm 1.
[0148] In this embodiment, the certificate signature operation mainly includes the following four steps.
[0149] 1) The user retrieves the public key pk of the verifier from the blockchain v . Note that this does not incur a large communication overhead because the blockchain is a distributed ledger jointly maintained by many full nodes, and the user can choose a nearby full node to retrieve pk v .
[0150] 2) The user encodes the verifiable credential VC u onto a group to obtain m1, and randomly selects a random number r from . Then, using the message m1, the public key pk of the verifier v , and the random number r as inputs, calculates a hash value, as shown in Figure 4 .
[0151]
[0152] In this embodiment, a chameleon hash function is used here. The trapdoor information of this chameleon hash is held by the verifier, that is, the certificate verifier can generally find a hash collision, thus ensuring that after the verifier receives the verifiable statement VP, it cannot use the VP to authenticate to other verifiers because the verifier holds the trapdoor information and can modify the certificate content to make the signature valid. For example, originally attr represents that the age is equal to 12, and the verifier can find a hash collision and change the attr part to the age is equal to 19, while the hash value remains unchanged and the signature is still valid. So even if the verifier sends the VP to other entities, this certificate is not credible.
[0153] 3) The user takes the hash value h and the user's private key sk u as inputs to complete the signature operation. Note that here a signature algorithm based on the discrete logarithm assumption is required, such as signature algorithms like ElGamal, that is
[0154] Sig u = sign(sk u , h)
[0155] 4) The user sends the verifiable statement VP u to the verifier in an encrypted communication manner. VP u includes the verifiable credential VC u , the random number r, the verifier's public key, and the signature Sig u , that is, VP u = {VC u , r, pk v , Sig u}.
[0156] Certificate verification process. After receiving the verifiable claim, the verifier uses the chameleon signature algorithm based on the discrete logarithm assumption to verify the user.
[0157] To achieve efficient non-transferability of VPs, the present invention designs a certificate verification mechanism based on chameleon signatures. When the verifier receives the verifiable claim VP u afterwards, perform a verification operation on VP u The verification operation mainly includes the following four steps, as shown in the certificate verification mechanism part of Algorithm 1.
[0158] 1) Check the attribute attr; 2) Check the threshold information and calculate the hash value; 3) Retrieve the public keys of the certificate issuer and the user; 4) Verify the signatures of the certificate issuer and the user.
[0159] In this embodiment, it specifically includes the following steps:
[0160] 1) Verify whether the attribute attr proven in VP u complies with the rules of the verifier.
[0161] For example, if the verifier requires proof that the age is greater than 18 years old, the verifier needs to verify whether the age field in attr is greater than 18.
[0162] 2) Check the threshold information and calculate the hash value.
[0163] The verifier first checks whether the public key pk v provided by the user matches the verifier's own public key. If it matches, it is considered that the threshold information is correct, and then the hash value is calculated using this threshold information. If it does not match, the public key pk v provided by the user is further verified. If the public key pk v provided by the user is the public key of another verifier, the verification fails, and it is considered that the verifiable claim VP u is not credible; if the public key pk v provided by the user is not the public key of another verifier, the correct public key of the verifier is sent to the user, and the user recalculates the hash and signature operations to generate a new verifiable claim and re-perform the authentication. Because in this case, due to reasons such as transmission errors or untimely blockchain updates, the user may obtain the wrong pk v , resulting in authentication errors.
[0164] If the threshold information check passes, the verifier needs to input VC u , the random number r, the verifier's public key pk v and the hash value h into the Ch_Ver() function. Ch_Ver() is a hash verification function that will first calculate VC uThe hash value h' of it, and compare whether h' is equal to h. If the comparison is successful, it is considered that VP u has not been tampered with during the transmission, output 1, otherwise output 0, as Figure 5 shown. Specifically, the verifier first encodes the verifiable credential VC u in the verifiable claim VP u onto the group to obtain m2, and then calculate the hash value h'. The inputs for calculating the hash value h' are m2, the public key pk v of the verifier, and the random number r, that is
[0165]
[0166] Then compare whether h is equal to h'. If they are not equal, it is considered that the verification fails.
[0167] 3) The verifier retrieves the public keys of the certificate issuer and the user from the blockchain.
[0168] The verifier uses the identity identifiers id i , id u of the user and the certificate issuer to obtain the corresponding pk I and pk u from the nearest full node.
[0169] 4) Verify whether the signatures of the user and the certificate issuer are correct and valid.
[0170] After that, the verifier verifies the signature sig u of the user and the signature sig i of the verifier respectively according to the retrieved public keys pk u and pk i . The formula is expressed as
[0171] result u = vrfy1(pk u , sig u , h)
[0172] result i = vrfy2(pk i , sig i , id i , id u , attr)
[0173] result = result u ∧ result i
[0174] where vrfy1() and vrfy2() represent the corresponding signature verification functions. result uWith result i They are respectively the results of verifying the signatures of the user and the certificate issuer, which are boolean data with values of True or False. True represents successful verification, while False represents failed verification. ∧ represents the AND logical operation, that is, if result u and result i are both equal to True, it is considered that the signature authentication is successful. If result u or result i is False or both are equal to False, it is considered that the signature verification fails, and the verifier refuses to provide the corresponding network resources for the user.
[0175] If all of the above four steps are verified successfully, the verifier considers that the user has provided the correct certificate, that is, the authentication is passed, and the verifier can provide the corresponding network resources for the user.
[0176] In the present invention, even if the verifier knows that it holds the correct verifiable claim, the verifier cannot use the verifiable claim VP u to other verifiers to achieve the purpose of impersonating the user's identity and obtaining illegal network resources. This is because the verifier holds the trapdoor information and can generally find a hash collision, that is, while ensuring the validity of the hash value and the signature value, modify the content in VP u . For example, originally attr represents that the age is equal to 12, and the verifier can find a hash collision and change the attr part to the age equal to 19, while the hash value remains unchanged and the signature still holds. As Figure 6 shown, if the verifier wants to change m1 to m3, the verifier can input its own private key sk v , random number r, m1, and m3 into the function Ch_Cld(). This function is a hash collision function and will output a new random number r′ such that Ch_Hash(m1, pk v ; r) = Ch_Hash(m3, pk v ; r′). From the chameleon hash function,
[0177]
[0178]
[0179] if the two are equal, then we can get Therefore, the verifier with the trapdoor information can change the content in VP u at will, thus reducing the risk of its impersonating the user's identity.
[0180] The following is the pseudocode of the authentication mechanism of this embodiment:
[0181]
[0182]
[0183] In view of the problem that under the DID architecture, the risk of certificate abuse or transfer is significantly increased compared with traditional authentication schemes, the present invention proposes a distributed identity authentication method based on chameleon signatures for Web3. By using chameleon signatures, verifiers in DID can generally find hash collisions, thereby achieving efficient non-transferability of certificates with relatively small communication and storage overheads.
[0184] The present invention designs a certificate usage process based on chameleon signatures. During the certificate usage process, the user of DID uses a chameleon signature, which takes a verifiable credential, the user's private key, and the public key of the DID verifier as inputs. While proving the user's ownership of the verifiable claim, it grants the verifier the permission to modify the certificate. In addition, the present invention modifies the certificate verification mechanism. During the certificate verification process, the verifier can correctly and efficiently verify the legality of the verifiable claim. At the same time, the DID verifier has trapdoor information and thus has the ability to modify the verifiable claim. This ability effectively prevents the verifier from illegally misusing the user's identity and obtaining network resources in an illegal manner.
[0185] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention are included within the protection scope of the present invention.
Claims
1. A distributed identity authentication method based on chameleon signature for Web3, characterized in that: The steps include: During the entity registration process, the entity generates a public-private key pair based on the discrete logarithm hypothesis; the entity includes a certificate issuer, a user, and a verifier; During the certificate issuance process, the verifier uses the Chameleon signature algorithm based on the discrete logarithm assumption to issue a verifiable credential to the user; During the certificate usage process, the user uses the Chameleon signature algorithm based on the discrete logarithm hypothesis to sign the received verifiable credential, obtain a verifiable statement, and send it to the verifier; Certificate verification process,After receiving the verifiable claim, the verifier uses the Chameleon signature algorithm based on the discrete logarithm assumption to verify the user.
2. According to claim 1, the distributed identity authentication method based on chameleon signature for Web3 is characterized in that: The entity registration process includes the following steps: The entity generates a public-private key pair locally using a local device based on a discrete logarithm assumption; Upload the mapping relationship between the entity's identity and public key to the blockchain.
3. According to claim 2, the distributed identity authentication method based on chameleon signature for Web3 is characterized in that: The entity registration process specifically includes the following steps: Entity uses local device to Randomly select an element as the private key sk and calculate the corresponding public key pk = g sk modp; The entity uploads the mapping between id and pk to the blockchain by publishing transactions; Where p and q are both prime numbers greater than a preset value and satisfy p mod q = 1, and g is The elements in represent generators, represents the multiplicative group modulo q, represents the multiplicative group modulo p.
4. According to claim 3, the distributed identity authentication method based on chameleon signature for Web3 is characterized in that: The certificate issuance process includes the following steps: The certificate issuer uses the private key to sign the relevant authentication information based on the signature algorithm assumed by the discrete logarithm problem, and the verifiable certificate VC u Issued to the user, the relevant authentication information includes the certificate issuer ID i , user ID u With the attribute attr, it is possible to verify that the credential includes relevant authentication information.
5. According to claim 4, the distributed identity authentication method based on chameleon signature for Web3 is characterized in that: The certificate issuance process includes the following steps: The certificate issuer uses the ElGamal signature algorithm based on the discrete logarithm difficulty assumption and a hash function to combine the relevant authentication information with the certificate issuer's signature Sig i Together we form a verifiable credential VC u , VC u ={id i ,id u ,attr,Sig i }, after receiving the certificate, the user uses the local device to store the certificate.
6. The distributed identity authentication method based on chameleon signature for Web3 according to claim 4 is characterized in that: The certificate usage process includes the following steps: When the user wants to use the certificate, the user uses the Chameleon hash function and inputs the received verifiable credential VC u , the public key pk of the verifier v The hash value h corresponding to the random number r is obtained, h = Ch_Hash (VC u ,pk v ; r), then the user uses his own private key to sign the hash value h using the signature function to obtain a verifiable statement VP u , and will verifiably declare VP u Sent to the validator.
7. The distributed identity authentication method based on chameleon signature for Web3 according to claim 6 is characterized in that: The certificate usage process includes the following steps: The user retrieves the validator’s public key pk from the blockchain v ; Users will be able to verify the VC u Encode to On the group, we get m1, from Randomly select a random number r in; Take m1 and the public key pk of the verifier v The random number r is used as the input of the Chameleon hash function, and the hash value h is calculated using the following formula: The user uses the hash value h and the private key sk u As input, the signature operation is completed using the signature algorithm based on the discrete logarithm assumption. The formula is as follows: Say u =sign(sk u ,h); The user will verify the declaration of the VP in an encrypted communication u Sent to the verifier to verify the VP statement u Including the verifier public key, verifiable certificate VC u , random number r and signature Sig u , namely VP u = {VC u ,r,pk v ,Sig u }; Where p and q are both prime numbers greater than a preset value and satisfy p mod q = 1, and g is The elements in represent generators, represents the multiplicative group modulo q, represents the multiplicative group modulo p.
8. The distributed identity authentication method based on chameleon signature for Web3 according to claim 7 is characterized in that: After receiving the verifiable statement, the verifier uses the Chameleon signature algorithm based on the discrete logarithm hypothesis to verify the user, including the following four aspects of verification: 1) Verify the Verifiable Credentials VC u Whether the proof of the attributes in the test meets the verifier's requirements; 2) The verifier checks the trapdoor information: input the verifiable credential, the verifier public key and the random number r, and uses the Chameleon hash function to calculate the hash value h′=Ch_Hash(VC u ,pk v ,r), compare the hash value h ′ Is it equal to the hash value h? 3) Verify the consistency of public keys: The verifier retrieves the public keys pk of the user and the verifier from the blockchain u With pk i ; 4) Verify whether the signatures of the certificate issuer and the user are consistent; If all four aspects are verified, the verifier considers the user to be authenticated.
9. The distributed identity authentication method based on chameleon signature for Web3 according to claim 8, characterized in that: The verifier checks the trapdoor information including: The verifier checks the verifier public key pk provided by the user v Whether it matches the verifier's own public key, If they match, the trapdoor information is considered correct, and the hash value is calculated using the trapdoor information; If they do not match, the verifier public key pk provided by the user is v Further verification, If the user provides the verifier public key pk v If it is the public key of another verifier, the verification fails and the verifiable claim VP u Not credible; If the user provides a validator pk v If it is not the public key of another verifier, the correct public key of the verifier is sent to the user, and the user uses the correct public key to recalculate the hash value and perform the signature operation to generate a new verifiable statement and re-authenticate; If the trapdoor information check passes, the verifier will be able to verify the credential VC u , random number r, verifier public key pk v The hash value h is input into the hash verification function Ch_Ver(); Hash verification function Ch_Ver() calculates the verifiable credential VC u The hash value h′ is compared to see if the hash value h′ is equal to the hash value h. If the comparison is successful, the VP is considered to be verifiable. u If it has not been tampered with during the transmission process, the output is 1, which means the verification is successful. Otherwise, the output is 0, which means the verification fails.
10. The distributed identity authentication method based on chameleon signature for Web3 according to claim 9, characterized in that: The hash verification function Ch_Ver() performs the following operations: Will be able to verify the statement VP u Verifiable Credentials in VC u Encode to In the group, we get m2, and then based on m2, the public key pk of the verifier v The hash value h′ is calculated using the following formula with the random number r: Compare whether the hash value h′ is equal to the hash value h. If the comparison is successful, it is considered that the output is 1 and the verification is successful. Otherwise, it is considered that the verification fails.
11. A distributed identity authentication device based on chameleon signature for Web3, characterized in that: It includes a processor capable of executing the steps of the distributed identity authentication method based on chameleon signature for Web3 as described in any one of claims 1-10.
Citation Information
Patent Citations
Identity authorization method and device, storage medium and equipment
CN112291245A
Heterogeneous industrial equipment credible interconnection method and device based on distributed identity label
CN113452704A
Digital identity management method and device
CN114444125A
Private data protection method based on block chain in communication network and network slice
CN117201182A
Block chain data modification method and device, equipment, medium and product
CN118427889A
Cited By
Electronic contract signing method and device based on DID, equipment and medium
CN122247688A