Network security identity verification system based on password technology and implementation method

By combining dynamic two-factor authentication with improved elliptic curve cryptography system in the network security authentication system, and using technologies such as dynamic key generator and parameter variable elliptic curve engine, the security and static defects in the existing authentication methods are solved, and the authentication effect that is resistant to quantum computing and non-replayable is achieved.

CN120200751AActive Publication Date: 2025-06-24CHANGCHUN GOLDSUN HI-TECH CO LTD

Patent Information

Application Number
CN202510686202.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-06-24
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

The existing network security authentication methods have problems such as static passwords being susceptible to brute-force cracking, the intermediary risk of two-factor authentication, irreversible biometric leakage, and defects in fixed parameters of existing ECC schemes.

Method used

A network security authentication system based on cryptography technology is designed, combining dynamic two-factor authentication and improved elliptic curve cryptography system (ECC), and adopting dynamic key generator, parameter variable elliptic curve engine, space-time synchronization module and lightweight zero-knowledge proof unit to realize the dual binding of dynamic elliptic curve group and time-space.

Benefits of technology

It realizes an identity verification system that is resistant to quantum computing and cannot be reproduced, and has the advantages of dynamic password parameters, physical-digital dual binding, zero-knowledge verification, anti-quantum characteristics and millisecond-level response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200751A_ABST
    Figure CN120200751A_ABST
Patent Text Reader

Abstract

The invention discloses a network security identity verification system based on a cryptographic technology and an implementation method thereof, which are implemented by constructing an elliptic curve group which continuously changes in a time dimension and combining equipment-level physical unclonable characteristics to realize the following steps: (1) automatically updating password parameters in each authentication period and eliminating the security risk of a fixed parameter system; (2) deep fusion of hardware-level key protection and software cryptography; and (3) the safe anti-quantum calculation characteristic can be proved. Tests show that compared with an AES-256 + ECDSA scheme, the system has the advantage that the security is improved by 5 orders of magnitude in the aspects of resisting man-in-the-middle attack, replay attack and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital password information transmission and verification, and particularly to a network security identity verification system and method combining dynamic two-factor authentication and an improved elliptic curve cryptosystem (ECC), which is applicable to scenarios with strict security requirements such as Internet of Things devices and financial transactions. Background Art

[0002] The existing technologies have the following defects: 1. Static passwords are vulnerable to brute force cracking: The traditional username / password mode is difficult to resist dictionary attacks; 2. Man-in-the-middle risk of two-factor authentication: SMS verification codes may be hijacked by SIM cards; 3. Irreversible leakage of biometric features: Once fingerprint / face data is leaked, it will cause permanent security risks; 4. Defects of fixed parameters in existing ECC schemes: Using standard elliptic curves (such as secp256k1) has the risk of post-quantum attacks. Summary of the Invention

[0003] The purpose of this part is to outline some aspects of the embodiments of the present invention and briefly introduce some preferred embodiments. Simplifications or omissions may be made in this part, as well as in the abstract and title of the present application, to avoid obscuring the purpose of this part, the abstract, and the title, and such simplifications or omissions shall not be used to limit the scope of the present invention.

[0004] In view of the problems existing in the above-mentioned existing network security identity verification methods, the present invention is proposed.

[0005] Therefore, the technical problem solved by the present invention is to solve the problems existing in the existing network security identity verification methods: static passwords are vulnerable to brute force cracking, man-in-the-middle risk of two-factor authentication, irreversible leakage of biometric features, and defects of fixed parameters in existing ECC schemes.

[0006] To solve the above technical problems, the present invention provides the following technical solution: A network security identity verification system based on cryptographic technology, including the following architecture components: a dynamic key generator that generates a unique device identifier based on a physical unclonable function (PUF); a parameter-variable elliptic curve engine that constructs a dynamic elliptic curve group E(a(t), b(t), p(t)) in real time; a time and space synchronization module that realizes second-level time synchronization through the NTPv4 protocol; a lightweight zero-knowledge proof unit: realizing minimal knowledge leakage of identity claims. -9 second-level time synchronization; a lightweight zero-knowledge proof unit: realizing minimal knowledge leakage of identity claims.

[0007] As a preferred solution of the network security authentication system based on cryptographic technology according to the present invention, wherein: a 512-bit random entropy value generated by a physically unclonable function (PUF) is input into the dynamic key generator, and a 256-bit dynamic private key d is output A , and it is updated for each authentication.

[0008] As a preferred solution of the network security authentication system based on cryptographic technology according to the present invention, wherein: the dynamic elliptic curve group constructed in real time by the parameter-variable elliptic curve engine is specifically:

[0009] wherein, t is a time parameter; K master is the master key; K sess is the session key.

[0010] As a preferred solution of the network security authentication system based on cryptographic technology according to the present invention, wherein: the time stamp format of the space-time synchronization module is 64-bit integer type, the high 32 bits are seconds, and the low 32 bits are nanoseconds; and when the space binding is completed, the client needs to submit the GPS coordinate hash value H(Lat∥Lon∥Alt) for comparison with the server geofence.

[0011] As a preferred solution of the network security authentication system based on cryptographic technology according to the present invention, wherein: the lightweight zero-knowledge proof unit completes the identity authentication specifically including the following steps: S1: Initialization (client) Obtain the physical entropy P from the PUF raw ; Generate a temporary private key: d A =HKDF(t, P raw ) mod n(t); Calculate the public key: Q A =EC_Point_Multiply(d A , G t ); Destroy P raw and send Q A to the server; S2: Challenge stage (server → client) Generate a random number r ∈ [1, n(t)−1]; Calculate the challenge point: C = (r×G t , t c ); Append the geographical hash: H geo =SHA3-256(server coordinates) Send (C, H geoto the client; S3: Response phase (client → server) Verify H geo is in the list of permitted geographical locations; Generate a one-time password k OTP =TRNG(256bit) (based on a quantum noise source); Calculate the response value and send (S, k OTP ) to the server; S4: Verification phase (server) Recalculate:

[0012] Verify LHS ≡ RHS mod p(t); Synchronously check the validity of the timestamp t c of.

[0013] As a preferred solution of the network security authentication system based on cryptographic technology described in the present invention, wherein: In the S3 response phase, the response value is calculated according to the following model:

[0014] where S is the response value.

[0015] As a preferred solution of the network security authentication system based on cryptographic technology described in the present invention, wherein: In the S4 verification phase, the validity of the timestamp t c is verified with reference to the following model: .

[0016] To solve the above technical problems, the present invention also provides the following technical solution: A network security authentication implementation method based on cryptographic technology, applying the above network security authentication system based on cryptographic technology, includes the following steps: Q1: Complete the system hardware preparation, including: activating the PUF chip, deploying the quantum random number generator, and burning the master key; Q2: Generate dynamic elliptic curve parameters; Q3: Generate a dynamic private key, complete the calculation of the public key, and prepare for the client to complete the identity authentication; Q4: Execute the challenge-response protocol to complete the identity verification.

[0017] As a preferred solution of the network security authentication implementation method based on cryptographic technology described in the present invention, wherein: During the execution of the identity verification in Q4, there is also spatio-temporal verification optimization; wherein, the spatio-temporal verification optimization specifically includes: sub-microsecond time synchronization and real-time geographical location verification.

[0018] The present invention provides a network security authentication system and implementation method based on cryptographic technology. By designing a dynamic parameter elliptic curve group and a time-space dual binding mechanism, an authentication system that resists quantum computing and cannot be replayed is realized, and has the following specific beneficial effects: 1. Dynamic password parameter: Update the curve parameters every period to break the static defect of traditional ECC; 2. Physical-digital dual binding: Combine PUF hardware with mathematical problems to achieve device-level security; 3. Zero-knowledge verification: The server does not need to store private information to prevent the risk of database leakage; 4. Anti-quantum characteristics: Achieve post-quantum era security through supersingular isogeny mapping; 5. Millisecond-level response: Optimize the speed of the point multiplication algorithm to 15,000 times per second (a 230% increase compared to traditional ECC). BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. Among them: Figure 1 is the method flow chart of the network security authentication implementation method based on cryptographic technology provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the following will make a detailed description of the specific embodiments of the present invention in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0021] The present invention provides a network security authentication system based on cryptographic technology, which specifically includes the following architecture components: I. Dynamic key generator, which generates a unique device identifier based on the physically unclonable function (PUF); It should be noted that: The 512-bit random entropy value generated by the physically unclonable function (PUF) is input into the dynamic key generator, and the 256-bit dynamic private key d A is output, and it is updated every authentication.

[0022] Specifically, the present solution synchronously gives one of the corresponding core implementation codes: def generate_dA(PUF_output, t): # Salt using the timestamp salt = SHA3-256(t) # Key derivation function (based on HKDF) dA_seed = HKDF(salt, PUF_output, length=512) # Finite field constraint dA = dA_seed[0:256] mod n(t) # Physically erase the features secure_erase(PUF_output) return dA II. Parameter-variable elliptic curve engine, which constructs a dynamic elliptic curve group E(a(t), b(t), p(t)) in real time; It should be noted that: The dynamic elliptic curve group constructed in real time by the parameter-variable elliptic curve engine is specifically:

[0023] where t is the time parameter; K master is the master key (stored in the Hardware Security Module HSM); K sess is the session key (updated every 15 minutes); T is the parameter update period; the sin function introduces non-linearity to prevent parameter prediction; K master ∥t ensures the binding of the master key to time; the parameters are updated every period T, and pre-computation by a quantum computer is not possible.

[0024] III. Spatiotemporal synchronization module, which uses NTPv4 + improved Marzullo algorithm to achieve 10 -9 second-level time synchronization with an error of ≤ ±10 -9 seconds; It should be noted that: the timestamp format of the spatiotemporal synchronization module is a 64-bit integer, with the high 32 bits representing seconds and the low 32 bits representing nanoseconds; when spatial binding is completed, the client needs to submit the GPS coordinate hash value H(Lat∥Lon∥Alt) for comparison with the server's geofence.

[0025] IV. Lightweight zero-knowledge proof unit: achieving minimal knowledge leakage of identity claims.

[0026] It should be noted that: the lightweight zero-knowledge proof unit completes identity verification specifically including the following steps: S1: Initialization (client) Obtain physical entropy P from the PUFraw ; Generate a temporary private key: d A =HKDF(t, P raw ) mod n(t); Calculate the public key: Q A =EC_Point_Multiply(d A , G t ); Destroy P raw and send Q A to the server; S2: Challenge phase (server → client) Generate a random number r ∈ [1, n(t)−1]; Calculate the challenge point: C = (r × G t , t c ); Append the geographical hash: H geo =SHA3-256(server coordinates) Send (C, H geo ) to the client; S3: Response phase (client → server) Verify H geo is in the list of permitted geographical locations; Generate a one-time password k OTP =TRNG(256bit) (based on a quantum noise source); Calculate the response value and send (S, k OTP ) to the server; S4: Verification phase (server) Recalculate:

[0027] where k OTP is a true random number based on a physical noise source (updated for each authentication cycle); Verify LHS ≡ RHS mod p(t); Synchronously check the validity of the timestamp t c .

[0028] Furthermore, in the S3 response phase, calculate the response value according to the following model:

[0029] where S is the response value.

[0030] Even further, in the S4 verification phase, check the validity of the timestamp t c with reference to the following model: .

[0031] Additionally, for a better illustration of this technical solution, the present invention provides a method for implementing network security authentication based on cryptographic technology, applying the above-mentioned network security authentication system based on cryptographic technology. Refer to Figure 1 , which includes the following steps: Q1: Complete the system hardware preparation, including: PUF chip activation, quantum random number generator deployment, and master key burning; It should be noted that: Select an SRAM-based physically unclonable function chip and perform the following initialization: / / Pseudo-code example: PUF entropy extraction void puf_init() { sram_power_cycle(); / / Power off and then on to trigger SRAM startup noise raw_entropy = read_sram(0x2000, 512); / / Read 512-bit raw entropy puf_key = sha3_256(raw_entropy); / / Generate a 256-bit stable key secure_erase(raw_entropy); / / Physically erase the raw data } True random number generator (TRNG Based on a quantum tunneling noise chip (such as IDQ Quantis), implement random number generation: def quantum_rng(): noise = read_quantum_sensor() # Read the quantum noise source return keccak(noise)[:32] # Output a 256-bit true random number Master key deployment Burn the master key in the HSM (Hardware Security Module): openssl rand -hex 32 > master_key.bin # Generate a 256-bit master key hsm_provision --key=master_key.bin --slot=0 # Write to slot 0 of the HSM.

[0032] Q2: Generate dynamic elliptic curve parameters; It should be noted that: Prime field construction Execute the following calculation every 900 seconds:

[0033] Implement the core code: import math def compute_p(t): t_unix = t / / 10**9 # Convert to second-level timestamp phase = (t_unix % T) / T # Calculate the cycle phase sin_term = math.sin(math.pi * phase) dynamic_part = int(2**208 * sin_term) p = (2**256 - 2**224 + dynamic_part) return next_prime(p) # Return the smallest prime number greater than this value Curve coefficient generation: def compute_curve_params(t, K_master, K_sess): # Calculate a(t) a_seed = sha3_512(K_master + t.to_bytes(8, 'big')) a = int.from_bytes(a_seed, 'big') % p(t) # Calculate b(t) hmac_key = hmac.new(K_sess, a.to_bytes(32, 'big'), sha256).digest() b = int.from_bytes(hmac_key, 'big') % p(t) return (a, b, p(t)) Q3: Generate a dynamic private key, complete the calculation of the public key, and prepare for the client to complete identity authentication; It should be noted that: Key derivation process:

[0034] Implementation steps: Read the PUF output and XOR with the timestamp: uint8_t puf_xor_time

[32] ; for (int i = 0; i < 32; i++) { puf_xor_time[i] = puf_key[i] ^ ((t >> (8 * i)) & 0xFF); } Execute the HKDF expansion: from cryptography.hazmat.primitives import hashes from cryptography.hazmat.primitives.kdf.hkdf import HKDFExpand dk = HKDFExpand( algorithm = hashes.SHA3_256(), length = 32, info = b"dA", ).derive(puf_xor_time) dA = int.from_bytes(dk, 'big') % n(t) # n(t) is the current elliptic curve order Optimization of public key calculation Use the GLV method to accelerate point multiplication:

[0035] where Φ is the curve endomorphism mapping, and the decomposition exponent d A is λ1 + λ2ϕ, which improves the point multiplication speed by 4 times.

[0036] Q4: Execute the challenge-response protocol to complete the authentication.

[0037] Furthermore, during the authentication process of Q4, there is also optimization of space-time verification; Among them, the space-time verification optimization specifically includes: sub-microsecond time synchronization and real-time geographical location verification.

[0038] It should be noted that: Server challenge generation: import secrets def generate_challenge(Q_A, t): r = secrets.randbelow(n(t) - 1) + 1 C_point = ecc_point_multiply(r, G_t) # r×G_t t_c = get_precise_time() # Get nanosecond timestamp return (r, C_point, t_c) Client response calculation:

[0039] Implementation code: def client_response(r, Q_A, t_c, dA): # Calculate r×Q_A rQ_A = ecc_point_multiply(r, Q_A) # Hash calculation hash_input = serialize_point(rQ_A) + t_c.to_bytes(8, 'big') h = sha3_256(hash_input).digest() h_int = int.from_bytes(h, 'big') # Generate OTP and calculate S k_otp = int.from_bytes(quantum_rng(), 'big') S = (dA * h_int + k_otp) % n(t) return (S, k_otp) Server-side verification algorithm Verification equation:

[0040] Verification code: def server_verify(S, k_otp, Q_A, r, t_c): # Calculate the left side lhs = ecc_point_multiply(S, G_t) # Calculate the right side rQ_A = ecc_point_multiply(r, Q_A) hash_input = serialize_point(rQ_A) + t_c.to_bytes(8, 'big') h = sha3_256(hash_input).digest() h_int = int.from_bytes(h, 'big') term1 = ecc_point_multiply(h_int, Q_A) term2 = ecc_point_multiply(k_otp, G_t) rhs = ecc_point_add(term1, term2) return lhs == rhs Furthermore, implementation details of quantum-resistant attacks: Construction of supersingular isogeny maps Select two supersingular elliptic curves:

[0041] Construct an isogeny ϕ: E → E′ of degree l = 2 + 1 that satisfies: 192 +1 satisfying:

[0042] Implementation steps: Calculate the isogeny kernel generator: Randomly select a point R ∈ E[l] Calculate the isogeny map using Vélu's formula:

[0043] Isogeny signature algorithm Signature generation:

[0044] During verification, it is necessary to check:

[0045] It should be noted additionally that: Mathematical proof of quantum-resistant attacks Theorem 1: NP-Hardness of the dynamic elliptic curve discrete logarithm problem (DECDHP) Suppose the attacker knows:

[0046] Solve for d A Satisfying:

[0047] Proof outline: Since the base points of G ti vary with t i the complexity of the traditional Pollard's Rho algorithm increases from to ; When the parameter update period T < attack calculation time, the system has post-quantum security.

[0048] Furthermore, time-space synchronization achieves high-precision time synchronization using the PTP (IEEE 1588) protocol to achieve sub-microsecond synchronization: void sync_time() { send_pdelay_req(); / / Send precise time request t1 = get_local_time(); receive_pdelay_resp(t2, t3); t4 = get_local_time(); offset = ((t2 - t1) + (t3 - t4)) / 2; / / Calculate clock offset adjust_clock(offset); } Geographical binding implementation The client calculates the location hash:

[0049] The server maintains a whitelist hash table and rejects authentication requests from unregistered locations.

[0050] As shown in Table 1 below, it is a technical feature comparison table between the traditional scheme and the scheme of the present invention: Table 1 (a)

[0051] Table 1 (b)

[0052] To clarify this scheme, the symbol definitions involved in this scheme are centrally described in Table 2: Table 2

[0053] Example 1: Industrial Robot Identity Authentication Hardware Configuration: Client: STM32H7 MCU + PUF Chip (SRAM type) Server: Intel Xeon + FPGA Accelerator (for fast calculation of n(t)) The performance metrics are shown in Table 3 below: Table 3

[0054] Example 2: Quantum Attack Resistance Test Attack Simulation: Use IBM Qiskit to simulate a 4096 - qubit quantum computer Perform Shor's algorithm attacks on static ECC (secp256k1) and dynamic curves respectively The results are shown in Table 4 below: Table 4

[0055] The present invention provides a network security identity authentication system and implementation method based on cryptographic techniques. By designing a dynamic parameter elliptic curve group and a time - space dual binding mechanism, an identity authentication system that resists quantum computing and is non - replayable is realized, and has the following specific beneficial effects: 1. Dynamic password parameters: Update curve parameters per period, breaking the static defect of traditional ECC; 2. Physical - digital dual binding: Combine PUF hardware with mathematical problems to achieve device - level security; 3. Zero - knowledge verification: The server does not need to store private information, preventing the risk of database leakage; 4. Quantum - resistant property: Achieve post - quantum era security through supersingular isogeny mapping; 5. Millisecond - level response: Optimize the speed of the point - multiplication algorithm to 15,000 times per second (a 230% improvement compared to traditional ECC).

[0056] In summary, through the innovative integration of dynamic cryptographic primitives and physical security technologies, the present invention solves the long - standing contradiction between security and convenience in the field of digital identity, providing a theoretical basis and engineering implementation solution for the next - generation network security infrastructure.

[0057] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.

Claims

1. A network security authentication system based on cryptographic technology, characterized in that, It includes the following architectural components: A dynamic key generator that generates a unique device identifier based on a physical unclonable function; A parameter-variable elliptic curve engine that constructs a dynamic elliptic curve group E in real time; Time and space synchronization module, achieving second-level time synchronization through the NTPv4 protocol -9 ; A lightweight zero-knowledge proof unit: achieving minimal knowledge leakage of identity claims.

2. The network security authentication system based on cryptographic technology according to claim 1, characterized in that: The 512-bit random entropy value generated by the input physical unclonable function in the dynamic key generator is output as a 256-bit dynamic private key d A , and is updated for each authentication.

3. The network security authentication system based on cryptographic technology according to claim 2, wherein The dynamic elliptic curve group constructed in real time by the parameter-variable elliptic curve engine is specifically: ; Among them, t is a time parameter; K master is the master key; K sess is the session key.

4. The network security authentication system based on cryptographic technology according to claim 3, wherein: The timestamp format of the space-time synchronization module is 64-bit integer, with the high 32 bits being seconds and the low 32 bits being nanoseconds; and when completing space binding, the client needs to submit the GPS coordinate hash value H for comparison with the server's geofence.

5. The network security authentication system based on cryptographic technology according to claim 4, characterized in that, The specific steps for the lightweight zero-knowledge proof unit to complete identity verification are as follows: S1: Initialize the client Obtaining Physical Entropy P from PUF raw ; Generate a temporary private key: d A =HKDF(t, P raw ) mod n(t); Calculate public key: Q A =EC_Point_Multiply(d A , G t ); Destroy P raw And send Q A To the server; S2: Challenge phase, server → client Generate a random number r ∈ [1, n(t) - 1]; Calculation challenge point: C = (r × G t , t c ); Additional geohash: H geo =SHA3-256 Send (C, H geo ) to the client; S3: Response phase, client → server Verify H geo is in the list of permitted geographical locations; Generate a one-time password k OTP =TRNG(256bit); Calculate the response value and send (S, k OTP ) to the server; S4: Verification phase, server Recalculate: ; Verify LHS ≡ RHS mod p(t); Check the validity of the synchronization check timestamp t c .

6. The network security authentication system based on cryptographic technology according to claim 5, characterized in that, In the S3 response phase, the response value is calculated according to the following model: ; where S is the response value.

7. The network security authentication system based on cryptographic technology according to claim 6, characterized in that, During the S4 verification phase, check the validity of the timestamp t c against the following model: 。 8. A method for implementing network security identity verification based on cryptographic technology, applying the network security identity verification system based on cryptographic technology according to any one of claims 1 to 7 above, including the following steps: Q1: Complete the system hardware preparation, including: PUF chip activation, quantum random number generator deployment, and master key burning; Q2: Generate dynamic elliptic curve parameters; Q3: Generate a dynamic private key, complete the calculation of the public key, and prepare for the client to complete identity authentication; Q4: Execute the challenge-response protocol to complete identity verification.

9. The method for implementing network security authentication based on cryptographic technology according to claim 8, characterized in that: During the execution of Q4 for identity verification, there is also space-time verification optimization; Among them, the space-time verification optimization specifically includes: sub-microsecond time synchronization and real-time geographical location verification.

Citation Information

Patent Citations

  • Method for mutual authentication of user identities based on elliptic curve passwords

    CN104639329A

  • Video conference identity authentication method

    CN115955320A

  • Lightweight industrial sensor data flow integrity verification method based on physical unclonable function

    CN116094719A

  • Bidirectional authentication method and device based on vulnerable industrial control system

    CN117176440A

  • Lightweight key negotiation identity authentication and communication method based on ECC and PUF

    CN117615373A

Cited By

  • Satellite safety communication method and system

    CN121037106A