Identity management method and device
Patent Information
- Application Number
- CN202380080623.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-09
- Publication Date
- 2025-07-04
AI Technical Summary
In the Internet of Vehicles system, due to the characteristics of node heterogeneity, large scale density, fast node movement speed, and open communication channels, communication between nodes faces huge security challenges, making it difficult to achieve privacy protection and real identity verification of terminal devices.
Distributed ledger technology and sparse Merkel trees are used to store the pseudonymous identity information of the terminal device. The pseudonymous identity of the terminal device is determined through a trusted authoritative device and encrypted during transmission in the network to ensure the security and privacy of the pseudonymous identity. , and at the same time, the pseudonymous identity can be revoked during malicious operations to achieve conditional privacy protection.
It achieves privacy protection and real identity verification of terminal devices, avoids the certificate management overhead of the PKI system and the secret key custody problem of the IBE scheme, improves the security and supervision efficiency of the system, and satisfies the lightweight and real-time requirements of the Internet of Vehicles system. sexual needs.
Smart Images

Figure CN120266435A_ABST
Abstract
Description
Identity management method and device Technical Field
[0001] The embodiments of the present application relate to the field of communications, and in particular to an identity management method and apparatus. Background Art
[0002] The maturity of communication and sensing technologies has driven the rapid development of connected vehicles (IoV) applications, making it a key focus of new global infrastructure development. Through data collection and information sharing, IoV can provide various application services to vehicles, improving road safety and traffic efficiency.
[0003] However, due to the characteristics of the Internet of Vehicles system such as strong node heterogeneity, large scale density, fast node mobility, and open communication channels, the communication between nodes in the Internet of Vehicles environment faces huge security challenges.
[0004] Summary of the Invention
[0005] The present application provides an identity management method and apparatus, which can obtain the true identity of the terminal device i while realizing privacy protection of the terminal device, thereby realizing conditional privacy protection.
[0006] In a first aspect, an identity management method is provided. The method can be performed by a trusted authority (TA) device, or by a component of the TA device, such as a processor, chip, or chip system of the TA device, or by a logic module or software that implements all or part of the functions of the TA device. The method includes: determining a pseudonymous identity (PID) of a terminal device i, and sending a first parameter to the terminal device i, where the first parameter is used to indicate the PID of the terminal device i. The PID of the terminal device i is determined based on the real identity (RID) of the terminal device i.
[0007] Based on this solution, on the one hand, the TA device can determine the PID of the terminal device i for the terminal device i, thereby protecting the RID of the terminal device i, that is, protecting the privacy of the terminal device i. On the other hand, the PID of the terminal device i is associated with the RID of the terminal device i, so that the TA device can determine the RID of the terminal device i based on the PID of the terminal device i, and can determine the true identity of the terminal device i when the terminal device i performs a malicious operation or an illegal operation. In other words, while protecting the privacy of the terminal device i, the true identity of the terminal device i can be obtained, that is, conditional privacy protection is achieved. On the other hand, the TA device sends a first parameter to the terminal device i to indicate the PID of the terminal device i, protecting the security and privacy of the PID of the terminal device i during transmission in the network, and can effectively prevent malicious nodes from intercepting the PID of the terminal device i to impersonate the terminal device i to perform illegal operations.
[0008] In one possible design, the method further includes: using distributed ledger technology to store PID information of terminal device i.
[0009] Based on this possible design, distributed ledger technology is used to store the PID information of terminal devices. Therefore, based on the characteristics of distributed ledgers, a secure, transparent, decentralized, scalable, and single-point attack-resistant identity management mechanism can be implemented, avoiding the certificate management overhead brought by the PKI system and the key custody problem brought by the IBE solution.
[0010] In one possible design, distributed ledger technology is used to store the PID information of the terminal device i, including: using distributed ledger technology to store a sparse Merkle tree (SMT); storing the PID information of the terminal device i in a leaf node with an index of (2i-1) in the SMT.
[0011] In one possible design, the method further includes: using distributed ledger technology to store the status of the PID information of the terminal device i, where the status includes revoked or valid.
[0012] Based on this possible design, distributed ledger technology is used to store the status of the PID information of the terminal device, so that the PID information of the terminal device can be revoked, that is, the pseudonym identity can be revoked, thereby supporting the revocation of the pseudonym identity of a terminal device when it performs illegal operations or malicious attacks, thereby improving the efficiency of supervision of illegal behaviors in the system.
[0013] In one possible design, the state of the PID information of the terminal device i is stored using distributed ledger technology, including: using distributed ledger technology to store the SMT; and storing the state of the PID information of the terminal device i in the leaf node indexed as (2i) in the SMT.
[0014] Based on the above possible design, the legitimacy and validity of the pseudonymous identity of the terminal device can be queried and verified through a public distributed ledger, thereby realizing the legitimacy verification of the pseudonymous identity of the terminal device.
[0015] In one possible design, determining the PID of the terminal device i includes: determining the PID of the terminal device i when the real identity list includes the RID of the terminal device i and the distributed ledger technology is not used to store the PID information of the terminal device i.
[0016] Based on this possible design, checking against the real identity list can prevent the TA device from determining the PID for an illegitimate terminal device (e.g., the terminal device's RID is not included in the real identity list). Furthermore, checking whether the PID information of terminal device i is stored using distributed ledger technology can prevent the TA device from repeatedly determining the PID of terminal device i, which would result in unnecessary waste of computing resources.
[0017] In one possible design, the PID of terminal device i is determined based on the RID of terminal device i, including: the PID of terminal device i is determined based on the RID of terminal device i and at least one of the following: a master private key s of the TA device, a first hash function H1, or a first timestamp T0. The first timestamp T0 is a timestamp carried in a first message from terminal device i, and the first message is used to request the PID of terminal device i.
[0018] Based on this possible design, when the master private key of the TA device participates in determining the PID of the terminal device i, since the master private key of the TA device is stored locally in the TA, it is difficult for other nodes to obtain the master private key of the TA device, and thus it is also difficult to obtain the RID of the terminal device i based on the PID of the terminal device i, further improving the privacy protection capability of the terminal device i.
[0019] In one possible design, the PID of terminal device i satisfies the following relationship:
[0020] Among them, PID i Indicates the PID and RID of terminal device i i Indicates the RID of terminal device i, Represents the exclusive OR operation, and || is the string concatenation operator.
[0021] Based on this possible design, if the PID of terminal device i satisfies the above formula, the PID of terminal device i can be obtained by XORing the RID, the hash value of the TA device's master private key, and the timestamp. In other words, the generation of pseudonymous identities is simple and efficient, reducing the computational complexity of the TA device.
[0022] In one possible design, the first parameter is determined based on the PID of terminal device i and the RID of terminal device i.
[0023] In one possible design, the method also includes: determining a master public key of the TA device, the master public key including a first-part master public key and a second-part master public key; the master public key is determined based on the master private key of the TA device and a generator of the additive group G1.
[0024] In one possible design, the master private key and / or master public key satisfy the following relationship:
[0025] P pub =(P pub1 ,P pub2 )=(sP,s -1 P)
[0026] Among them, s represents the master private key, represents the set of integers in the range [1,q-1], where q is the order of the additive group G1; P pub Represents the master public key, P pub1 Represents the first part of the master public key, P pub2 represents the second part of the master public key, and P represents the generator of the additive group G1.
[0027] Based on this possible design, if the TA device's master public key satisfies the above formula, the TA device's master public key can be obtained by multiplying the TA device's master private key with the generator of the additive group. This makes the generation of the master public key simple and efficient, reducing the computational complexity of the TA device.
[0028] In one possible design, the method further includes: determining a partial private key PSK of terminal device i i , sends a second parameter to terminal device i, where the second parameter is used to indicate the partial private key of terminal device i. Among them, the partial private key PSK of terminal device i i It is determined based on at least one of the following: the master private key s of the TA device, the first hash function H1, the RID of the terminal device i, the master public key P of the TA device pub , the second hash function H2, or the first random number λ i , Represents a set of integers in the range [1,q-1].
[0029] Based on this possible design, the TA device sends a second parameter to the terminal device i to indicate the partial private key of the terminal device i, thereby protecting the security and privacy of the partial private key of the terminal device i during transmission in the network, and effectively preventing malicious nodes from intercepting the partial private key of the terminal device i to impersonate the terminal device i and perform illegal operations.
[0030] In one possible design, the second parameter includes (A i ,K i ,Θ i ), part of the private key PSK i =(α i ,κ i ,θ i );in:
[0031] in, Represents the exclusive OR operation, and || is the string concatenation operator.
[0032] In one possible design, the partial private key PSK of terminal device i i =(α i ,κ i ,θ i ), α i , κ i ,θ i Satisfies the following relationship: α i =s -1 +λ i h i , h i =H2(RID i ||P pub ) κ i =λ i H1(RID i ) θ i =s -1 H1(RID i )
[0033] Among them, RID i Represents the RID of terminal device i, and || is a string concatenation operator.
[0034] In one possible design, the second parameter is based on the RID of the terminal device i and the partial private key PSK i Sure.
[0035] In one possible design, the method further includes: when the terminal device i performs an illegal operation, setting the status of the PID information of the terminal device i to revoked.
[0036] Based on this possible design, when the terminal device i performs an illegal operation, the PID information of the terminal device can be revoked, that is, the pseudonym identity can be revoked, thereby supporting the revocation of the pseudonym identity of a terminal device when it performs an illegal operation or malicious attack, thereby improving the efficiency of supervision of illegal behavior in the system.
[0037] In one possible design, the method further includes: when the terminal device i performs an illegal operation, determining the RID of the terminal device i based on the PID of the terminal device i.
[0038] Based on this possible design, since the true identity of the terminal device that performs illegal operations can be determined, relevant restrictions or penalties can be imposed on the terminal device, thereby improving security performance.
[0039] In one possible design, the method further includes: noting the illegal operation of the terminal device i in the real identity list.
[0040] Based on this possible design, the TA device notes the illegal operation of the terminal device i, which is beneficial to the subsequent management of the terminal device i. For example, the authorization related to the illegal operation of the terminal device i can be revoked, further improving the security performance.
[0041] In one possible design, the PID information of terminal device i is the PID of terminal device i, or a hash value of the PID of terminal device i.
[0042] In one possible design, the method further includes: sending a broadcast message, the broadcast message including the master public key and system parameters, the system parameters including at least one of the following: the additive group G1, the order q of the additive group G1, the generator P of the additive group G1, the multiplicative group G2, the bilinear mapping relationship e between the additive group G1 and the multiplicative group G2, the first hash function, the second hash function, or the third hash function. The first hash function and the third hash function are Sure, represents the set of integers in the range [1,q-1]; the second hash function is determined by the additive group G1.
[0043] In a second aspect, a message sending method is provided. This method can be executed by a terminal device, or by a component of the terminal device, such as a processor, chip, or chip system, or by a logic module or software that implements all or part of the terminal device's functionality. The method includes generating a third message and sending the third message. The third message includes a signature of the original message, determined based on the public key of terminal device i.
[0044] Based on this solution, the third message sent by the terminal device includes a signature of the original message, which can be used by the message recipient to verify the identity of the sender of the third message, thereby improving the security performance of communication.
[0045] In one possible design, the signature of the original message is determined based on the public key of the terminal device i, including: the signature of the original message is determined based on the public key of the terminal device i and at least one of the following: the private key of the terminal device i, or the first part of the master public key of the trusted authority TA device; the partial private key of the terminal device i is determined by the TA device.
[0046] In one possible design, the signature of the original message is expressed as (η i ,σ i ), η i , σ i Satisfies the following relationship: η i =γ i R i σ i =(γ i α i +β i )P pub1
[0047] Among them, R i Represents the second part of the public key of terminal device i, α i and β i The private key of terminal device i, P pub1 Indicates the first part of the master public key of the TA device. γ i It is determined based on at least one of the following: a third hash function, the original message, the PID of the terminal device i, the public key of the terminal device i, or a third timestamp, where the third timestamp is a timestamp carried in the third message.
[0048] In one possible design, γ i Satisfies the following relationship: γ i =H3(M i ||PID i ||PK i ||T i )
[0049] Among them, H3 represents the third hash function, M i Indicates the original message, PID i Indicates the PID and PK of terminal device i i represents the public key of terminal device i, T i Indicates the third timestamp, and || is a string concatenation operator.
[0050] In one possible design, before generating the third message, the method further includes: receiving a second parameter from the TA device, the second parameter being used to indicate a partial private key PSK of the terminal device i i ; According to the partial private key PSK of terminal device i i Determine the private key SK of terminal device i i; According to the private key SK of terminal device i i and the second part of the master public key of the TA device to determine the public key PK of the terminal device i i ; Public key PK of broadcast terminal device i i .
[0051] Based on this possible design, the TA device cannot obtain the complete private key of the terminal device, and thus cannot forge signatures or decrypt ciphertext, avoiding the privacy leakage risk caused by the private key custody problem of IBC.
[0052] In one possible design, the partial private key PSK of terminal device i i =(α i ,κ i ,θ i ); if α i H1(RID i )=θ i +κ i h i , then the private key SK of terminal device i i =(α i ,β i );in, Represents a set of integers in the range [1,q-1].
[0053] In one possible design, the public key PK of terminal device i i =(U i ,R i ), U i 、R i Satisfies the following relationship: U i =β i P pub2 R i =α i P pub2
[0054] Among them, P pub2 Indicates the second part of the master public key of the TA device.
[0055] In a third aspect, a message verification method is provided. This method can be executed by a message recipient, or by a component of the message recipient, such as a processor, chip, or chip system of the message recipient. It can also be implemented by a logic module or software that implements all or part of the message recipient's functions. The message recipient can be a terminal device or an intermediate node. The method includes: receiving N messages from N terminal devices, where message n from terminal device n includes a signature of original message n, where n is a positive integer from 1 to N and N is a positive integer greater than 1; determining an aggregate signature based on the signatures of original message n in the N messages; and verifying the N messages based on the aggregate signature.
[0056] Based on this solution, the message receiver verifies based on the aggregate signature of N messages. Compared with the method of verifying each message one by one, it can reduce the complexity of verification and improve verification efficiency.
[0057] In a possible design, the message n also includes a timestamp n; determining the aggregate signature includes: when the freshness of the message n meets a preset condition, determining the aggregate signature, and the freshness of the message n is determined based on the timestamp n of the message n.
[0058] Based on this possible design, the message recipient verifies the freshness of the message before determining the aggregate signature to determine whether the message has expired. If the message has not expired, the aggregate signature is determined. This avoids the message recipient determining the aggregate signature based on expired messages, which would increase the processing complexity for the message recipient.
[0059] In one possible design, determining the aggregate signature includes: storing PID information of the terminal device n using distributed ledger technology, and determining the aggregate signature when the status of the PID information is valid.
[0060] Based on this possible design, the message recipient verifies the validity of the terminal device's PID before determining the aggregate signature, confirming the legitimacy of the message sender's identity. The aggregate signature is then determined only if the sender's identity is legitimate. This prevents the recipient from determining the aggregate signature based on messages sent by an illegitimate terminal device, which would increase processing complexity for the recipient.
[0061] In one possible design, verifying N messages based on the aggregate signature includes: determining a first bilinear mapping result and a second bilinear mapping result based on the aggregate signature; if the first bilinear mapping result and the second bilinear mapping result are the same, the N messages are verified.
[0062] Based on this possible design, the message receiver can verify the message by performing two bilinear mapping calculations based on the aggregate signature. Compared with traditional certificateless signatures, where the bilinear mapping grows linearly with the number of messages, this improves verification efficiency and reduces computational overhead and communication latency. In the context of the Internet of Vehicles (IoV), this can meet the lightweight and real-time requirements of IoV systems.
[0063] In one possible design, the aggregate signature includes Among them, σ n and η n The signature of the original message in message n, U n Represents the first part of the public key of terminal device n.
[0064] In one possible design, the second bilinear mapping results in:
[0065] The result of the first bilinear mapping is:
[0066] Among them, e represents the bilinear mapping relationship, P pub1 Indicates the first part of the master public key of the TA device, P pub2 Indicates the second part of the master public key of the TA device.
[0067] In a fourth aspect, a communication device is provided for implementing various methods. The communication device may be the TA device in the first aspect, or a device included in the TA device, such as a chip or a chip system; or, the communication device may be the terminal device in the second aspect, or a device included in the terminal device, such as a chip or a chip system; or, the communication device may be the message receiver in the third aspect, or a device included in the message receiver, such as a chip or a chip system. The communication device includes a module, unit, or means corresponding to the implementation method, and the module, unit, or means may be implemented by hardware, software, or by executing the corresponding software implementation by hardware. The hardware or software includes one or more modules or units corresponding to the functions.
[0068] In some possible designs, the communication device may include a processing module and a transceiver module. The processing module may be configured to implement the processing functionality of any of the above aspects and any possible implementations thereof. The transceiver module may include a receiving module and a transmitting module, respectively configured to implement the receiving functionality and the transmitting functionality of any of the above aspects and any possible implementations thereof.
[0069] In some possible designs, the transceiver module may be composed of a transceiver circuit, a transceiver, a transceiver or a communication interface.
[0070] In a fifth aspect, a communication device is provided, comprising: a processor and a memory; the memory is configured to store computer instructions, and when the processor executes the instructions, the communication device performs the method described in any aspect. The communication device may be the TA device described in the first aspect, or a device included in the TA device, such as a chip or a chip system; or the communication device may be the terminal device described in the second aspect, or a device included in the terminal device, such as a chip or a chip system; or the communication device may be the message recipient described in the third aspect, or a device included in the message recipient, such as a chip or a chip system.
[0071] In a sixth aspect, a communication device is provided, comprising: a processor and a communication interface; the communication interface is configured to communicate with a module external to the communication device; and the processor is configured to execute a computer program or instruction to cause the communication device to perform the method described in any aspect. The communication device may be the TA device described in the first aspect, or a device included in the TA device, such as a chip or a chip system; or the communication device may be the terminal device described in the second aspect, or a device included in the terminal device, such as a chip or a chip system; or the communication device may be the message recipient described in the third aspect, or a device included in the message recipient, such as a chip or a chip system.
[0072] In a seventh aspect, a communication device is provided, comprising: at least one processor; the processor is configured to execute a computer program or instruction stored in a memory, so that the communication device performs the method described in any aspect. The memory may be coupled to the processor, or may be independent of the processor. The communication device may be the TA device described in the first aspect, or a device included in the TA device, such as a chip or a chip system; or the communication device may be the terminal device described in the second aspect, or a device included in the terminal device, such as a chip or a chip system; or the communication device may be the message recipient described in the third aspect, or a device included in the message recipient, such as a chip or a chip system.
[0073] In an eighth aspect, a computer-readable storage medium is provided, in which a computer program or instruction is stored. When the computer-readable storage medium is run on a communication device, the communication device can execute the method described in any one of the aspects.
[0074] In a ninth aspect, a computer program product comprising instructions is provided, which, when executed on a communication device, enables the communication device to execute the method described in any one of the aspects.
[0075] In a tenth aspect, a communication device is provided (for example, the communication device may be a chip or a chip system), which includes a processor for implementing the functions involved in any aspect.
[0076] In some possible designs, the communication device includes a memory for storing necessary program instructions and data.
[0077] In some possible designs, when the device is a chip system, it can be composed of a chip or include a chip and other discrete devices.
[0078] It can be understood that when the communication device provided in any one of the fourth to tenth aspects is a chip, the sending action / function of the communication device can be understood as output information, and the receiving action / function of the communication device can be understood as input information.
[0079] Among them, the technical effects brought about by any design method in the fourth to tenth aspects can refer to the technical effects brought about by different design methods in the first, second or third aspects, and will not be repeated here.
[0080] In an eleventh aspect, a communication system is provided, comprising a TA device and a terminal device. The TA device is configured to execute the solution described in the first aspect or any possible design of the first aspect. The terminal device is configured to execute the solution described in the second aspect or any possible design of the second aspect.
[0081] In some possible designs, the communication system further includes a message receiver. The message receiver is used to execute the solution described in the third aspect or any possible design of the third aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0082] FIG1 is a schematic diagram of the structure of a block provided by this application;
[0083] FIG2 is a schematic diagram of the structure of a blockchain provided by this application;
[0084] FIG3 is a schematic diagram of the structure of a sparse Merkle tree SMT provided by this application;
[0085] FIG4 is a schematic diagram of the structure of a communication system provided by the present application;
[0086] FIG5 is a flow chart of an identity management method provided by this application;
[0087] Figure 6a is a schematic diagram of a method for storing PID information using blockchain and SMT provided by this application;
[0088] Figure 6b is a schematic diagram of another method provided by the present application for storing PID information using blockchain and SMT;
[0089] FIG7 is a flow chart of a communication method provided by the present application;
[0090] FIG8 is a flow chart of another communication method provided by the present application;
[0091] FIG9 is a flow chart of a message sending method provided by the present application;
[0092] FIG10 is a flow chart of a message verification method provided by the present application;
[0093] FIG11 is a schematic diagram of a communication interface between a terminal device, an RSU, and a TA device provided by the present application;
[0094] FIG12 is a schematic structural diagram of a communication device provided by the present application;
[0095] FIG13 is a schematic structural diagram of another communication device provided by the present application;
[0096] FIG14 is a schematic structural diagram of another communication device provided in this application. DETAILED DESCRIPTION
[0097] In the description of this application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship, for example, A / B can represent A or B; "and / or" in this application is merely a description of the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural.
[0098] In addition, to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, the words "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that the words "first" and "second" do not limit the quantity or execution order, and the words "first" and "second" do not necessarily mean different.
[0099] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner to facilitate understanding.
[0100] It will be understood that the “embodiment” mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the various embodiments throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It will be understood that in the various embodiments of the present application, the size of the sequence number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present application.
[0101] It can be understood that in this application, "when" and "if" both mean that corresponding processing will be taken under certain objective circumstances, and do not limit the time, nor do they require any judgment action when implementing, nor do they mean that there are other limitations.
[0102] It is understood that some optional features in the embodiments of the present application may, in certain scenarios, be implemented independently of other features, such as the solution on which they are currently based, to solve corresponding technical problems and achieve corresponding effects. They may also be combined with other features in certain scenarios as needed. Accordingly, the devices provided in the embodiments of the present application may also implement these features or functions accordingly, which will not be described in detail here.
[0103] In this application, unless otherwise specified, the same or similar parts between the various embodiments can refer to each other. In this application, unless otherwise specified and there is no logical conflict between the various embodiments, the terms and / or descriptions between different embodiments are consistent and can be referenced to each other. The technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships. The following description of the embodiments of this application does not constitute a limitation on the scope of protection of this application.
[0104] Currently, IoT authentication schemes mainly include three categories: digital certificate authentication schemes based on the public key infrastructure (PKI) architecture, authentication schemes based on identity-based cryptography (IBC), and certificateless signature (CLS) schemes.
[0105] In a digital certificate authentication solution based on the PKI architecture:
[0106] A digital certificate is generated and issued by a certificate authority (CA). For example, upon receiving a digital certificate application, the CA may use the applicant's public key, identity information, the validity period of the digital certificate, and other information as the original message, perform a hash operation on the original message to obtain a hash digest of the original message, and then encrypt the hash digest using the CA's private key to obtain a digital signature. The digital signature and the original message serve as the applicant's digital certificate.
[0107] During subsequent physical communication, the authentication party can use the CA's public key to decrypt the digital signature in a device's digital certificate to obtain a message digest, and then hash the original message in the digital certificate to obtain a hash digest. Comparing the message digest and hash digest can then verify the authenticity and integrity of the digital certificate, thereby authenticating the device.
[0108] In an IBC-based authentication scheme:
[0109] The IBC signature scheme uses publicly identifiable, non-repudiable identity information (such as name, email address, address, phone number, etc.) as the entity's public key, and then implements identity authentication based on the IBC signature scheme. In addition, in the IBC-based authentication scheme, the entity's private key is generated by a key generation center (KGC).
[0110] In the certificateless signature (CLS) scheme:
[0111] KGC generates a partial private key for the entity based on its true identity. The entity then uses the secret value and this partial private key to generate the actual private key and save it locally. This means that KGC can only obtain a partial private key, not the complete private key.
[0112] All three authentication schemes mentioned above have some issues. In digital certificate authentication schemes based on the PKI architecture, the CA and database server, as centralized entities, are vulnerable to network attacks; certificate generation operations are completely dependent on the CA, which poses the risk of leaking user privacy and generating fraudulent certificates; and this scheme introduces high costs for certificate management (such as certificate status detection, certificate path construction, and certificate revocation).
[0113] In an IBC-based authentication scheme, publicly identifiable, non-repudiable identities are used as public keys, and authentication is achieved through IBC signatures, reducing the high certificate management overhead associated with PKI-based authentication schemes. However, this scheme relies heavily on the reliability of the key guarantee collection (KGC). A malicious KGC can easily obtain private key information and launch attacks. For example, a KGC can use a user's private key to decrypt any encrypted information of that user, posing a serious risk of privacy leakage. In other words, this scheme suffers from the key escrow issue.
[0114] In the CLS solution, KGC cannot obtain the user's complete private key, making it impossible to forge signatures or decrypt ciphertext, thus avoiding the privacy leakage risk caused by the private key custody problem of IBC. However, the CLS solution still has the following problems:
[0115] 1. Most current CLS solutions use centralized identity revocation lists to manage and maintain user identities, i.e., they employ centralized identity management solutions. However, centralized identity management solutions have issues such as high maintenance costs, lack of scalability, and susceptibility to point attacks.
[0116] 2. The current CLS solution is based on bilinear mappings on elliptic curves, and its computational overhead increases linearly with the number of users. Therefore, excessive numbers of users lead to high computational overhead and long communication latency, making it impossible to meet the lightweight and real-time requirements of connected vehicle applications.
[0117] 3. The current CLS solution focuses on the problem of identity authentication, ignoring the protection of user identity privacy and the identification of malicious nodes.
[0118] Based on this, the present application provides an identity management method that can obtain the true identity of the terminal device i while achieving privacy protection for the terminal device, thereby realizing conditional privacy protection.
[0119] In order to facilitate understanding of the technical solutions of the embodiments of the present application, a brief introduction to the relevant technologies of the present application is first given as follows.
[0120] 1. Distributed Ledger Technology
[0121] A distributed ledger is a database that is shared, replicated, and synchronized among network members. It records transactions between network participants.
[0122] Participants in the network use a consensus mechanism to constrain and negotiate updates to records in the ledger, without the involvement of a third-party arbitration agency.
[0123] For example, a typical implementation of distributed ledger technology is blockchain technology. In this technology, data is generated and stored in blocks, and the chain data structure formed by sequentially linking blocks can be understood as a blockchain.
[0124] As you can understand, a block is also a data structure, and the device (or node) that stores a block can be called a blockchain node, maintenance node, or consensus node. A blockchain network consists of at least one blockchain node.
[0125] All nodes in a blockchain network jointly participate in data verification, storage, and maintenance, which can be understood as the blockchain's consensus mechanism. The creation of a new block requires the consensus of all nodes. Once a block is agreed upon by all nodes and added to their respective copies of the blockchain, it becomes immutable.
[0126] For example, as shown in Figure 1, a block consists of a block body and a block header. The block header stores information such as the version number, the block's hash value, necessary information to form a chain structure with the previous block (such as the hash value of the previous block), and a timestamp. The block body stores transaction records, which can be divided into transfer records, smart contract records, settlement records, data records, etc. according to specific application scenarios.
[0127] For example, assume a blockchain consists of three blocks, and its structure can be shown in Figure 2. The hash value of block 1 is recorded as A. Since block 1 is the first block and does not point to the previous block, the hash value of the previous block stored in it is 0. The hash value of block 2 is recorded as B. Since its previous block is block 1, the hash value of the previous block stored in it is A. The hash value of block 3 is recorded as C. Since its previous block is block 2, the hash value of the previous block stored in it is B.
[0128] 2. Sparse Merkle Tree (SMT):
[0129] The leaf nodes of SMT are the hash values of the data blocks, and the non-leaf nodes are the hash values of the concatenated strings of their corresponding child nodes. In addition, in SMT, data blocks are ordered.
[0130] For example, taking four data blocks A, B, C, and D as an example, a possible SMT structure may be shown in Figure 3, where H() represents a hash function.
[0131] The technical solution provided in this application can be used in various communication systems, which may be a third generation partnership project (3GPP) communication system, for example, a fourth generation (4G) long term evolution (LTE) system, a fifth generation (5G) new radio (NR) system, a vehicle to everything (V2X) system, a system of hybrid LTE and NR networking, or a device to device (D2D) system, a machine to machine (M2M) communication system, an Internet of Things (IoT), and other next generation communication systems. Alternatively, the communication system may also be a non-3GPP communication system, without limitation.
[0132] Among them, the above-mentioned communication system applicable to the present application is only an example, and the communication system applicable to the present application is not limited to this. It is uniformly described here and will not be repeated below.
[0133] Referring to Figure 4, an exemplary communication system provided by the present application is shown. The communication system includes a trusted authority (TA) device and at least one terminal device. Optionally, the communication system may also include an intermediate node.
[0134] Optionally, the TA device may be implemented in the form of a server, a network element, or a functional entity. Exemplarily, the TA device is mainly used for identity management and may participate in key generation.
[0135] Optionally, the terminal device may be a user-side device with wireless transceiver capabilities. The terminal device may also be referred to as user equipment (UE), terminal, access terminal, user unit, user station, mobile station (MS), remote station, remote terminal, mobile terminal (MT), user terminal, wireless communication device, user agent, or user device. The terminal may be, for example, a wireless terminal in IoT, V2X, D2D, M2M, 5G network, or future evolved PLMN. The terminal device may be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it may also be deployed on water (such as ships); it may also be deployed in the air (such as airplanes, balloons, and satellites).
[0136] Exemplarily, the terminal device may be a drone, an IoT device (e.g., a sensor, an electricity meter, a water meter, etc.), a V2X device, a station (ST) in a wireless local area network (WLAN), a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA) device, a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, an on-board device, an on-board unit (OBU) wearable device (also referred to as a wearable smart device), a tablet computer or a computer with wireless transceiver capabilities, a virtual reality (VR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a smart home, or a similar device. The main types of communication devices include wireless terminals in the home, vehicle-mounted terminals, vehicles with vehicle-to-vehicle (V2V) communication capabilities, intelligent connected vehicles, drones with UAV to UAV (U2U) communication capabilities, etc.
[0137] Optionally, the intermediate node may collect information of the terminal device and report it to the TA device, or may receive information from the TA device and send it to the terminal device.
[0138] For example, in a V2X environment, an intermediate node may have functions such as vehicle-road collaboration, intelligent computing, and perception fusion. For example, an intermediate node may be a roadside unit (RSU), which can obtain real-time road information such as traffic lights, traffic signs, and obstacles on the road, and transmit this road information to a terminal device (such as an onboard device).
[0139] Optionally, the intermediate node can communicate with the terminal device through the PC5 interface. In addition, the intermediate node can also communicate with the TA device through a wired connection or a wireless connection.
[0140] The following will be combined with the accompanying drawings to expand the method provided by the embodiment of the present application. It is understandable that in the embodiment of the present application, the execution subject can perform some or all of the steps in the embodiment of the present application, and these steps or operations are only examples. The embodiment of the present application can also perform other operations or variations of various operations. In addition, the various steps can be performed in a different order according to the embodiment of the present application, and it is possible that not all operations in the embodiment of the present application need to be performed.
[0141] For example, the solutions provided in the following embodiments of this application can be applied to Internet of Vehicles scenarios, as well as to scenarios such as IoT trusted management and data management. Furthermore, they can also be applied to other scenarios with a large number of distributed communication nodes. This application does not specifically limit the application scenarios of the following embodiments, and the application scenarios described herein do not constitute any limitation on the following embodiments.
[0142] As shown in FIG5 , an identity management method provided in an embodiment of the present application includes the following steps:
[0143] S501. The TA device determines the pseudonym identity (PID) of the terminal device i.
[0144] Optionally, the PID of the terminal device i is similar to anonymity, and can be understood as a non-real identity of the terminal device i, or in other words, not the real identity (RID) of the terminal device i.
[0145] Optionally, the terminal device i may request the PID of the terminal device i from the TA device, and the TA device may determine the PID for the terminal device i based on the request. For example, as shown in FIG5 , before step S501 , the method may further include the following step S500 :
[0146] S500: Terminal device i sends a first message to the TA device. Correspondingly, the TA device receives the first message from terminal device i. The first message is used to request the PID of terminal device i.
[0147] Optionally, the first message may include first encrypted information E1. Furthermore, the first message may also include a first timestamp T0. Exemplarily, the first timestamp can be understood as the time when the first message was generated. The first timestamp can be used to authenticate the generation time of the first message, to prevent replay attacks, or to check the freshness of the first message.
[0148] Optionally, the terminal device i can use the master public key P of the TA device pub Encrypt the RID of terminal device i (denoted as RID i ) to obtain the first encrypted information E1, or the master public key P of the TA device can be usedpub Encrypt the RID of the terminal device i and the first timestamp T0 to obtain the first encrypted information E1. pub This will be explained in the subsequent embodiments and will not be described in detail here.
[0149] Optionally, after receiving the first message, the TA device may use the master private key s of the TA device to decrypt the first encrypted information in the first message, obtain the RID of the terminal device i, and then determine the PID for the terminal device i.
[0150] The PID of the terminal device i is associated with the RID of the terminal device i, or in other words, the PID of the terminal device i is determined according to the RID of the terminal device i.
[0151] Furthermore, the PID of terminal device i can be determined based on the RID of terminal device i and at least one of the following: the master private key s of the TA device, the first hash function H1, or the first timestamp T0. The master private key s and the first hash function H1 of the TA device will be described in subsequent embodiments and will not be repeated here.
[0152] Exemplarily, the PID of terminal device i satisfies the relationship shown in the following formula (1):
[0153] Among them, PID i Indicates the PID and RID of terminal device i i Indicates the RID of terminal device i, Represents the exclusive OR operation, and || is the string concatenation operator.
[0154] S502: The TA device sends a first parameter to the terminal device i. Correspondingly, the terminal device i receives the first parameter from the TA device.
[0155] The first parameter is used to indicate the PID of the terminal device i. Exemplarily, after determining the PID of the terminal device i, the TA device may perform certain operations on the PID of the terminal device i, such as performing an exclusive OR operation on the PID of the terminal device i, to obtain the first parameter.
[0156] Optionally, the first parameter may be determined based on the PID of the terminal device i and the RID of the terminal device i. For example, Among them, Y i Indicates the first parameter.
[0157] Alternatively, the first parameter may be determined based on the PID of the terminal device i, the RID of the terminal device i, and the first timestamp. For example,
[0158] S503: The terminal device i determines the PID of the terminal device i according to the first parameter.
[0159] Optionally, after receiving the first parameter, the terminal device i may determine the PID of the terminal device i according to the first parameter.
[0160] For example, in the case where the first parameter is determined by the PID of terminal device i and the RID of terminal device i, terminal device i may determine In the case where the first parameter is determined by the PID of the terminal device i, the RID of the terminal device i, and the first timestamp, the terminal device i can determine
[0161] Based on this solution, the TA device can, on the one hand, determine the PID of terminal device i, thereby protecting the RID of terminal device i and, in other words, protecting the privacy of terminal device i. Furthermore, the PID of terminal device i is associated with the RID of terminal device i, allowing the TA device to determine the RID of terminal device i based on the PID of terminal device i. This allows the TA device to determine the true identity of terminal device i in the event that terminal device i performs malicious or illegal operations. In other words, while protecting the privacy of terminal device i, the true identity of terminal device i can also be obtained, achieving conditional privacy protection.
[0162] On the other hand, when the master private key of the TA device is involved in determining the PID of the terminal device i, since the master private key of the TA device is stored locally in the TA, it is difficult for other nodes to obtain the master private key of the TA device, and thus it is also difficult to obtain the RID of the terminal device i based on the PID of the terminal device i, further improving the privacy protection capability of the terminal device i.
[0163] On the other hand, the TA device sends a first parameter to the terminal device i to indicate the PID of the terminal device i, thereby protecting the security and privacy of the PID of the terminal device i during transmission in the network, and can effectively prevent malicious nodes from intercepting the PID of the terminal device i to impersonate the terminal device i and perform illegal operations.
[0164] On the other hand, if the PID of terminal device i satisfies the above formula (1), the PID of terminal device i can be obtained by XORing the RID, the hash value of the TA device's master private key, and the timestamp. In other words, the generation of pseudonymous identities is simple and efficient, reducing the computational complexity of the TA device.
[0165] Optionally, before the above step S501, the TA device may check the identity validity of the terminal device i, and execute the above step S501 if the check passes.
[0166] For example, the TA device may maintain a real identity list, such as a real vehicle list (RLV), which may store the RID of at least one terminal device. If the RID of the terminal device i is included in the real identity list, the check passes.
[0167] Furthermore, the TA device may also check whether the PID information of the terminal device i has been stored using the distributed ledger technology. If the PID information of the terminal device i has not been stored using the distributed ledger technology, the check passes.
[0168] That is, if the real identity list includes the RID of terminal device i, the PID of terminal device i is determined. Alternatively, if the real identity list includes the RID of terminal device i and the distributed ledger technology is not used to store the PID information of terminal device i, the PID of terminal device i is determined.
[0169] This solution, by checking against the real identity list, can prevent the TA from determining the PID for an illegitimate terminal device (e.g., a terminal device whose RID is not included in the real identity list). Furthermore, by checking whether the PID information of terminal device i is stored using distributed ledger technology, the TA can avoid unnecessary waste of computing resources caused by repeated determination of the PID of terminal device i.
[0170] Optionally, as shown in Figure 5, after determining the PID of terminal device i, the TA device may also use distributed ledger technology to store the PID information of terminal device i. Exemplarily, the PID information of terminal device i may be the PID of terminal device i, or a hash value of the PID of terminal device i.
[0171] Exemplarily, the TA device may use distributed ledger technology to store the SMT, and store the PID information of the terminal device i in the leaf node indexed as (2i-1) in the SMT.
[0172] Taking the distributed ledger technology implemented through blockchain as an example, the TA device can store the PID information of the terminal device i in the blockchain network. For example, as shown in Figure 6a, the TA device can store the SMT in the blockchain network and preset the leaf node of the SMT to H(null). After determining the PID of the terminal device i, the leaf node with index (2i-1) in the SMT is updated to the PID information of the terminal device i (such as H(PID i )).
[0173] Optionally, the TA device may also utilize distributed ledger technology to store the status of the PID information of terminal device i. The status may include revoked or valid. If the status of the PID information of terminal device i is revoked, it indicates that the PID of terminal device i is invalid, unavailable, or has been revoked. If the status of the PID information of terminal device i is valid, it indicates that the PID of terminal device i is available.
[0174] Exemplarily, the TA device may use distributed ledger technology to store the SMT, and store the status of the PID information of the terminal device i in the leaf node indexed as (2i) in the SMT.
[0175] Taking the implementation of distributed ledger technology through blockchain as an example, the TA device can store the status of the PID information of terminal device i in the blockchain network. For example, as shown in Figure 6a, the TA device can store an SMT in the blockchain network, presetting the leaf node of the SMT to H(null). The TA device then stores the status of the PID information of terminal device i in the leaf node indexed by (2i) in the SMT.
[0176] For example, if the status of the PID information of the terminal device i is revoked, the leaf node indexed as (2i) in the SMT can be updated to H ("first value"). If the status of the PID information of the terminal device i is valid, the leaf node indexed as (2i) in the SMT can be kept as H (null), or the leaf node indexed as (2i) in the SMT can be updated to H ("second value"). The first value and the second value are different. The first value can be 1, for example. That is, when the leaf node indexed as (2i) in the SMT is H ("1"), it indicates that the status of the PID information of the terminal device i is revoked.
[0177] Optionally, since the PID information of the terminal device i and the status of the PID information are stored in the distributed ledger, the devices in the system can access the distributed ledger in real time to verify the legitimacy of the pseudonymous identity of a certain terminal device.
[0178] For example, taking the distributed ledger implemented by blockchain as an example, for the legitimacy verification of the pseudonymous identity of terminal device i, the verifier can query the blockchain network to see whether the leaf node with index (2i-1) in the SMT of the latest block is H(PID i ), and whether the leaf node with index (2i) is H(null) or H("second value"). If the leaf node with index (2i-1) in the SMT is H(PID i ), and the leaf node with index (2i) is H(null) or H("second value"), indicating that the pseudonym identity of terminal device i is legal. If the leaf node with index (2i-1) in SMT is H(PID i), but the leaf node with index (2i) is H ("first value"), indicating that the pseudonym identity of the terminal device i is illegal.
[0179] Optionally, in the case that the terminal device i performs an illegal operation, the TA device may set the status of the PID information of the terminal device i to be revoked, that is, revoke the PID of the terminal device i.
[0180] For example, based on the example shown in FIG6a , as shown in FIG6b , the TA device may update the leaf node indexed at (2i) in the SMT to H (the "first value"), indicating that the pseudonymous identity of terminal device i has been revoked, or that the pseudonymous identity of terminal device i is invalid. It is understood that FIG6b illustrates the example of the first value being 1.
[0181] Optionally, if terminal device i performs an illegal operation, the TA device can determine the RID of terminal device i based on the PID of terminal device i. That is, the TA device can determine the true identity of the terminal device that performed the illegal operation. For example, the relationship between the PID of terminal device i and the RID of terminal device i can be found in the description of step S501 above and will not be repeated here.
[0182] Based on this solution, since the true identity of a terminal device that has performed an illegal operation can be determined, relevant restrictions or penalties can be imposed on the terminal device, thereby improving security performance.
[0183] Optionally, after the TA device determines the true identity of the terminal device that performed the illegal operation, that is, after determining the RID of terminal device i based on the PID of terminal device i, the illegal operation of the terminal device i can be noted or recorded in the true identity list.
[0184] Based on this solution, the TA device notes the illegal operation of the terminal device i, which is beneficial to the subsequent management of the terminal device i. For example, the authorization related to the illegal operation of the terminal device i can be revoked, further improving the security performance.
[0185] Optionally, the illegal operation performed by terminal device i can be reported to the TA device by the victim of the illegal operation, or by an intermediate node after monitoring the illegal operation of terminal device i. For example, the victim or intermediate node can report the PID of terminal device i and the illegal operation to the TA device. In other words, the TA device can learn that terminal device i has performed an illegal operation through the report from the victim or intermediate node.
[0186] Based on the above solution, on the one hand, the PID information of the terminal device is stored using distributed ledger technology and SMT data structure. Therefore, based on the characteristics of distributed ledger and SMT data structure, a secure, transparent, decentralized, scalable, and single-point attack-resistant identity management mechanism can be implemented, avoiding the certificate management overhead brought by the PKI system and the key custody problem brought by the IBE solution.
[0187] On the other hand, the use of distributed ledger technology and SMT data structure to store the status of the terminal device's PID information enables the terminal device's PID information to be revoked, that is, the pseudonym identity can be revoked, thereby supporting the revocation of the pseudonym identity of a terminal device when it performs illegal operations or malicious attacks, thereby improving the efficiency of supervision of illegal behaviors in the system.
[0188] On the other hand, the legitimacy and validity of the pseudonymous identity of the terminal device can be queried and verified through a public distributed ledger, thereby realizing the legitimacy verification of the pseudonymous identity of the terminal device.
[0189] The above embodiments illustrate the identity management method provided by this application. The following provides a communication method to illustrate the secret key and system parameters of the TA device. As shown in Figure 7, the communication method includes the following steps:
[0190] S701. The TA device determines a master public key of the TA device, a master private key of the TA device, or system parameters.
[0191] Optionally, the master private key s of the TA device satisfies: in, represents the set of integers in the range [1,q-1], where q is the order of the additive group G1, and q is a prime number. That is, G1 is an additive group of order prime number q.
[0192] Optional, the master public key P of the TA device pub Including the first part of the master public key P pub1 and the second part of the master public key P pub2 The master public key can be determined based on the master private key of the TA device and the generator of the additive group G1. pub The following relationship can be satisfied: pub =(P pub1 ,P pub2 )=(sP,s -1 P)
[0193] That is, P pub1 =sP,P pub2 =s -1 P. Where P represents the generator of the additive group G1. -1 Represents the reciprocal of the master private key s.
[0194] Optionally, the system parameters include at least one of the following: the additive group G1, the order q of the additive group G1, the generator P of the additive group G1, the multiplicative group G2, the bilinear mapping relationship e between the additive group G1 and the multiplicative group G2, the first hash function H1, the second hash function H2, or the third hash function H3. For example, the bilinear mapping relationship e between the additive group G1 and the multiplicative group G2 can be: e:G1×G1→G2. The order of the multiplicative group G2 is also q.
[0195] Optionally, the first hash function and the third hash function are For example, the first hash function and the third hash function can be defined as: Among them, {0,1} * Refers to a non-zero binary sequence, Indicates that the first hash function can be mapped to a non-zero binary sequence
[0196] Optionally, the second hash function is determined by the additive group G1. For example, the second hash function can be defined as: H2:{0,1} * →G1, indicating that the second hash function can be mapped to G1 in the form of a non-zero binary sequence.
[0197] S702: The TA device sends a broadcast message.
[0198] The broadcast message includes the master public key of the TA device and system parameters. The master private key of the TA device is secretly stored locally by the TA device.
[0199] Optionally, the master private key of the TA device, the master public key of the TA device, or some system parameters involved in the method shown in FIG5 can be determined according to the method shown in FIG7. In addition, the method shown in FIG7 can be performed independently without relying on the method shown in FIG5, or can be performed in combination with the method shown in FIG5, and this application does not make any specific restrictions on this.
[0200] In addition to determining the master public key and master private key of the TA device, the TA device can also generate a partial private key of the terminal device. The following is an explanation of the private key generation method. As shown in Figure 8, the private key generation method includes the following steps:
[0201] S801. The TA device determines the partial private key PSK of the terminal device i. i .
[0202] Optionally, the partial private key PSK of the terminal device i i It is determined based on at least one of the following: the master private key s of the TA device, the first hash function H1, the RID of the terminal device i, the master public key P of the TA device pub, the second hash function H2, or the first random number λ i , Exemplarily, each parameter may be implemented based on the description in the method shown in FIG. 7 , or each parameter may also be implemented in other ways, which is not specifically limited in this application.
[0203] For example, the partial private key PSK of terminal device i i =(α i ,κ i ,θ i ). Among them, α i , κ i ,θ i The following relationship can be satisfied: i =s -1 +λ i h i , h i =H2(RID i ||P pub ) κ i =λ i H1(RID i ) θ i =s -1 H1(RID i )
[0204] Among them, RID i represents the RID of the terminal device i, and || is a string connector.
[0205] Optionally, the terminal device i can request the TA device for the partial private key PSK of the terminal device i i , the TA device can determine a portion of the private key for it based on the request. Exemplarily, as shown in FIG8 , before step S801 , the method can further include the following step S800 :
[0206] S800: Terminal device i sends a second message to the TA device. Correspondingly, the TA device receives the second message from terminal device i. The second message is used to request the partial private key PSK of terminal device i. i .
[0207] Optionally, the second message includes second encrypted information E2. Furthermore, the second message may also include a second timestamp T'0. Exemplarily, the second timestamp can be understood as the time when the second message was generated. The second timestamp can be used to authenticate the time when the second message was generated, to prevent replay attacks, or to check the freshness of the second message.
[0208] Optionally, the terminal device i can use the master public key P of the TA device pubEncrypt the index i of the terminal device i to obtain the second encrypted information E2, or use the master public key P of the TA device pub Encrypt the index i of terminal device i and the second timestamp T0 ′ The second encrypted information E2 is obtained.
[0209] Optionally, after receiving the second message, the TA device may use the master private key s of the TA device to decrypt the second encrypted information in the second message, obtain the index i of the terminal device i, and then determine the partial private key of the terminal device i.
[0210] Optionally, before determining the partial private key of terminal device i, the TA device may verify the authenticity of the RID of terminal device i. For example, after decrypting the second encrypted information to obtain index i, the TA device may check whether the index i exists in the real identity list. If so, it indicates that the RID of terminal device i is authentic or legal, and the partial private key of terminal device i can be determined.
[0211] S802: The TA device sends a second parameter to the terminal device i. Correspondingly, the terminal device i receives the second parameter from the TA device.
[0212] The second parameter is used to indicate the partial private key PSK of the terminal device i. i Exemplarily, after determining the partial private key of the terminal device i, the TA device may perform certain operations on the partial private key of the terminal device i, thereby obtaining the second parameter.
[0213] Optionally, the second parameter may be determined based on the RID of terminal device i and a portion of the private key of terminal device i. Alternatively, the second parameter may be determined based on the RID of terminal device i, a portion of the private key of terminal device i, and the second timestamp.
[0214] Exemplarily, the second parameter may include (A i ,K i ,Θ i ), where A i , K i 、Θ i The following relationship can be satisfied:
[0215] Based on this scheme, the TA device sends a second parameter to the terminal device i to indicate the partial private key of the terminal device i, thereby protecting the security and privacy of the partial private key of the terminal device i during transmission in the network, and effectively preventing malicious nodes from intercepting the partial private key of the terminal device i to impersonate the terminal device i and perform illegal operations.
[0216] S803. Terminal device i determines a partial private key of terminal device i according to the second parameter.
[0217] Optionally, after receiving the second parameter, the terminal device i can determine the partial private key PSK of the terminal device i according to the second parameter i =(α i ,κ i ,θ i ).
[0218] S804: Terminal device i uses the partial private key PSK of terminal device i i Determine the private key SK of terminal device i i .
[0219] Optional, private key SK of terminal device i i It can include a first part private key and a second part private key. The first part private key can be a part private key PSK of the terminal device i. i The second part of the private key can be a random number.
[0220] For example, if α i H1(RID i )=θ i +κ i h i , then the first part of the private key of terminal device i can be α i The second part of the private key can be expressed as β i .in, represents the set of integers in the range [1,q-1]. That is, if α i H1(RID i )=θ i +κ i h i , then the private key SK of terminal device i i =(α i ,β i ).
[0221] Based on this scheme, the partial private key PSK received by terminal device i i After that, we can use equation α i H1(RID i )=θ i +κ i h i Verification is performed and the private key of terminal i is determined when the equation is established, thereby improving the correctness of partial private keys and private keys.
[0222] S805, terminal device i uses the private key SK of terminal device i i and the second part of the master public key of the TA device to determine the public key PK of the terminal device ii .
[0223] Optional, the public key PK of terminal device i i Including the first part of the public key U i and the second part of the public key R i The first part of the public key U i The second part of the private key β of the terminal device i can be used i The second part of the public key R i According to the first part of the private key α of the terminal device i i and the second part of the master public key of the TA device.
[0224] For example, the first part of the public key U i and the second part of the public key R i The following relations can be satisfied respectively: U i =β i P pub2 R i =α i P pub2
[0225] S806. Terminal device i broadcasts the public key PK of terminal device i i .
[0226] Optionally, after terminal device i broadcasts its public key, other terminal devices or intermediate nodes can receive the public key of terminal device i. When subsequently sending a message to terminal device i, the public key of terminal device i can be used to encrypt the message.
[0227] Based on this solution, the TA device cannot obtain the complete private key of the terminal device, and thus cannot forge signatures or decrypt ciphertext, avoiding the privacy leakage risk caused by the private key custody problem of IBC.
[0228] In addition, the present application also provides a message sending method. As shown in FIG9 , the message sending method may include the following steps:
[0229] S901: Terminal device i generates a third message, wherein the third message includes a signature of the original message.
[0230] Optionally, in addition to the signature of the original message, the third message also includes the original message and at least one of the following: the PID of the terminal device i, or a third timestamp T i The third timestamp can be understood as the time when the third message was generated. The third timestamp can be used to authenticate the generation time of the third message, or to prevent replay attacks, or to check the freshness of the third message.
[0231] The signature of the original message is determined based on the public key of the terminal device i. For example, the public key of the terminal device i can be implemented in the manner shown in the embodiment of FIG8 , or other implementation methods are also possible, which are not specifically limited in this application.
[0232] Furthermore, the signature of the original message can be determined based on the public key of terminal device i and at least one of the following: the private key of terminal device i, or the first partial master public key of the TA device. The partial private key of terminal device i is determined by the TA device. For example, the private key of terminal device i and the first partial master public key of the TA device can be implemented using the methods described in the aforementioned embodiments, or other implementation methods are also possible, and this application does not specifically limit this.
[0233] Optionally, the signature of the original message may include the first part signature n i and the second part signature σ i The first part signature η i The second part of the signature σ can be determined based on the public key of the terminal device i. i It can be determined based on the private key of terminal device i and the first part of the master public key of the TA device.
[0234] Exemplarily, the signature of the original message can be expressed as: (n i ,σ i ). η i , σ i The following relations can be satisfied respectively: η i =γ i R i σ i =(γ i α i +β i )P pub1
[0235] Among them, R i Represents the second part of the public key of terminal device i, α i and β i The private key of terminal device i, P pub1 Indicates the first part of the master public key of the TA device.
[0236] Optional, γ i is determined based on at least one of the following: a third hash function, a message text in the third message, a PID of the terminal device i, a public key of the terminal device i, or a third timestamp. i The following relationship can be satisfied: γ i =H3(M i ||PID i ||PK i ||Ti )
[0237] Among them, H3 represents the third hash function, M i Indicates the original message, PID i Indicates the PID and PK of terminal device i i represents the public key of terminal device i, T i The third timestamp is represented by ||, which is a string concatenation operator. For example, the third hash function can be implemented in the manner shown in the embodiment of FIG7 , or in other implementation manners, which are not specifically limited in this application.
[0238] S902. Terminal device i sends a third message.
[0239] Optionally, the terminal device i may send the third message to the intermediate node, or may send the third message to other terminal devices, which is not specifically limited in this application.
[0240] Figure 9 illustrates the sending of a message from the perspective of the message sender, and the following describes the receiving (or verification) of a message from the perspective of the message receiver. As shown in Figure 10, the message verification method provided by this application may include the following steps:
[0241] S1001: A message receiver receives N messages from N terminal devices. That is, the message receiver receives message n from terminal device n, where n is a positive integer from 1 to N.
[0242] Exemplarily, the message recipient may be an intermediate node, such as an RSU; or, the message recipient may be a terminal device (a terminal device other than the N terminal devices).
[0243] Optionally, the N messages may be received by the message recipient within a period of time (or a time interval T). The duration of the period of time or the time interval T may be determined by the message recipient or may be predefined, and this application does not impose any specific restrictions on this.
[0244] The message n of the terminal device n includes the signature of the original message n. The signature of the original message n is determined based on the public key of the terminal device n. Please refer to the relevant description of the original message in step S901 above, which will not be repeated here.
[0245] Optionally, in addition to the signature of the original message n, the message n also includes the original message n and at least one of the following: the PID of the terminal device n, or the timestamp n. Please refer to the relevant description of the third message in step S901 above, which will not be repeated here.
[0246] For example, message n includes message original n (denoted as Mn ), the PID of terminal device n (denoted as PID n ), the signature of the original message n (denoted as η n ,σ n ), and timestamp n (denoted as T n ) as an example, message n can be expressed as {M n ,PID n ,η n ,σ n ,T n That is, the N messages received by the message receiver can be expressed as: {M1,PID1,η1,σ1,T1}, {M2,PID2,η2,σ2,T2}, ..., {M n ,PID n ,η n ,σ n ,T n}.
[0247] S1002: The message receiver determines an aggregate signature based on the signatures of the original message n in the N messages. That is, the aggregate signature is determined based on the signatures of the N original messages.
[0248] Optionally, the aggregate signature includes a first aggregate signature and a second aggregate signature. The first aggregate signature may be an aggregation of the first signatures of the N message originals and the first public key of the terminal device n, and the second aggregate signature may be an aggregation of the second signatures of the N message originals.
[0249] For example, the first part of the aggregate signature can be expressed as The second part of the aggregate signature can be expressed as: That is, the aggregate signature may include Among them, σ n and η n The signature of the original message n, U n Represents the first part of the public key of terminal device n.
[0250] Optionally, before step S1002 , the message receiver may check the freshness of the message n, and determine the aggregate signature if the freshness of the message n meets a preset condition.
[0251] Exemplarily, the freshness of message n is determined based on timestamp n of message n. For example, the freshness of message n may be the time difference between timestamp n′ when the message recipient receives message n and timestamp n. The preset condition may be that the time difference between timestamp n′ and timestamp n is less than or equal to a certain threshold.
[0252] Optionally, if the freshness of a message among the N messages does not meet the preset conditions, the message recipient may discard the message and determine the aggregate signature based on the signatures of the original messages in the remaining N-1 messages. This embodiment uses the example of the case where the freshness of N messages all meet the preset conditions.
[0253] Based on this solution, the message recipient verifies the freshness of the message before determining the aggregate signature to determine whether the message has expired. If the message has not expired, the aggregate signature is determined. This avoids the message recipient determining the aggregate signature based on expired messages, which would increase the processing complexity for the message recipient.
[0254] Optionally, before step S1002 , the message receiver may verify the legality or validity of the PID of the terminal device n, and determine the aggregate signature if the PID of the terminal device n is legal or valid.
[0255] Exemplarily, when the PID information of the terminal device n is stored using distributed ledger technology and the status of the PID information is valid, the PID of the terminal device n can be considered legal or valid, and thus the aggregate signature can be determined.
[0256] For example, taking the distributed ledger implemented by blockchain as an example, the TA device can query the blockchain network to see whether the leaf node with index (2n-1) in the SMT of the latest block is H (PID i ), and whether the leaf node with index (2n) is H(null) or H("second value"). If the leaf node with index (2n-1) in the SMT is H(PID i ), and the leaf node with index (2n) is H(null) or H("second value"), indicating that the PID of terminal device n is legal or valid.
[0257] Optionally, if the PID of a terminal device among the N terminal devices is invalid or revoked, the message recipient can discard the message sent by the terminal device and determine the aggregate signature based on the signatures of the original messages in the remaining N-1 messages. This embodiment is described as an example in which the PIDs of the N terminal devices are all valid.
[0258] Based on this solution, the message receiver verifies the validity of the terminal device's PID before determining the aggregate signature. This verifies the legitimacy of the message sender's identity and then determines the aggregate signature based on the legitimacy of the message sender. This prevents the message receiver from determining the aggregate signature based on messages sent by an illegitimate terminal device, which would increase processing complexity for the message receiver.
[0259] S1003. The message receiver verifies N messages according to the aggregate signature.
[0260] Optionally, the message receiver may determine the first bilinear mapping result and the second bilinear mapping result based on the aggregate signature, and verify the N messages based on the first bilinear mapping result and the second bilinear mapping result.
[0261] For example, if the first bilinear mapping result and the second bilinear mapping result are the same, the N messages are verified successfully. The message receiver can perform subsequent processing based on the N messages.
[0262] If the first bilinear mapping result and the second bilinear mapping result are different, the N messages fail verification. The message receiver may discard the N messages and continue to receive messages in the next time period.
[0263] Optionally, the first bilinear mapping result can be obtained based on the first aggregate signature and the first partial master public key P of the TA device. pub1 Determine. Exemplarily, the first bilinear mapping result may be:
[0264] Optionally, the second bilinear mapping result can be obtained based on the second aggregate signature and the second part of the master public key P of the TA device. pub2 Determine. Exemplarily, the second bilinear mapping result may be:
[0265] That is to say, in In this case, the N messages are verified successfully.
[0266] Here, e represents a bilinear mapping relationship. For the bilinear mapping relationship, reference may be made to the relevant description in the above step S701 and will not be repeated here.
[0267] Based on this scheme, the message receiver can verify the message by performing two bilinear mapping calculations based on the aggregate signature. Compared with traditional certificateless signature schemes where the bilinear mapping grows linearly with the number of messages, this scheme improves verification efficiency and reduces computational overhead and communication latency. In the context of the Internet of Vehicles (IoV), it can meet the lightweight and real-time requirements of IoV systems.
[0268] It should be noted that, in the methods shown in Figures 5 to 10 above, each method can be executed independently, that is, each method can be independent of each other. Alternatively, multiple methods can be executed in combination, which is not specifically limited in this application.
[0269] For example, taking the method provided in the above embodiments of this application as applied to a connected vehicle system, with the intermediate node being an RSU as an example, FIG11 is a schematic diagram of the communication interface between a terminal device, an RSU, and a TA device. Communication between the terminal device, the RSU, and the TA device can be achieved through the interface shown in FIG11.
[0270] As shown in Figure 11 (a), the TA device can be collocated with the application server, or in other words, located in the same network location as the application server, with the RSU acting as a UE (i.e., UE-type). In this case, the terminal device and the TA device can communicate via the V1 interface; the TA device or application server communicates with the RSU-side V2X application via the V1 interface, and the RSU-side V2X application communicates with the terminal device-side V2X application via the V5 interface. The V1 and V5 interfaces can be understood as logical interfaces.
[0271] In addition, the terminal device and the RSU can communicate via the PC5 interface, and the RSU and the base station (such as the next-generation node B (gNB)) can communicate via the Uu interface. The user plane function (UPF) network element can receive data from the application server and send it to the base station, or it can receive data from the base station and send it to the application server.
[0272] Referring to (b) in Figure 11, the TA device can serve as a new functional entity, and the RSU serves as a base station (i.e., gNB-type). In this case, the TA device and the terminal device can communicate via the V1′ interface, which can be understood as a newly added logical interface in the embodiment of the present application.
[0273] In addition, the V2X application on the terminal device side and the V2X application server can communicate through the V1 interface; the terminal device and the base station or RSU can communicate through the Uu interface.
[0274] It can be understood that in the above embodiments, the methods and / or steps implemented by the TA device can also be implemented by components that can be used for the TA device (such as processors, chips, chip systems, circuits, logic modules, or software such as chips or circuits); the methods and / or steps implemented by the terminal device can also be implemented by components that can be used for the terminal device (such as processors, chips, chip systems, circuits, logic modules, or software such as chips or circuits); the methods and / or steps implemented by the message recipient can also be implemented by components that can be used for the message recipient (such as processors, chips, chip systems, circuits, logic modules, or software such as chips or circuits).
[0275] The above mainly introduces the solution provided by this application. Accordingly, this application also provides a communication device, which is used to implement the various methods mentioned above. The communication device can be the TA device in the above method embodiment, or a device including the above TA device, or a component that can be used for the TA device, such as a chip or a chip system; or, the communication device can be the terminal device in the above method embodiment, or a device including the above terminal device, or a component that can be used for the terminal device, such as a chip or a chip system; or, the communication device can be the message receiver in the above method embodiment, or a device including the above message receiver, or a component that can be used for the message receiver, such as a chip or a chip system.
[0276] It is understandable that, in order to realize the above functions, the communication device includes hardware structures and / or software modules corresponding to the execution of each function. It should be easily appreciated by those skilled in the art that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0277] The embodiment of the present application can divide the functional modules of the communication device according to the above method embodiment. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. In actual implementation, there may be other division methods.
[0278] Communication Device Figure 12 shows a schematic structural diagram of a communication device 120. The communication device 120 includes a processing module 1201 and a transceiver module 1202. The communication device 120 can be used to implement the functions of the above-mentioned TA device, terminal device, or message receiver.
[0279] In some embodiments, the communication device 120 may further include a storage module (not shown in FIG. 12 ) for storing program instructions and data.
[0280] In some embodiments, the transceiver module 1202, which may also be referred to as a transceiver unit, is configured to implement a transmitting and / or receiving function. The transceiver module 1202 may be composed of a transceiver circuit, a transceiver, a transceiver, or a communication interface.
[0281] In some embodiments, the transceiver module 1202 may include a receiving module and a sending module, which are respectively used to execute the receiving and sending steps performed by the TA device or terminal device or message recipient in the above method embodiments, and / or used to support other processes of the technology described herein; the processing module 1201 may be used to execute the processing steps (such as determination, generation, etc.) performed by the TA device or terminal device or message recipient in the above method embodiments, and / or used to support other processes of the technology described herein.
[0282] When the communication device 120 is used to implement the functions of the above-mentioned TA device:
[0283] The processing module 1201 is used to determine the pseudonymous identity PID of the terminal device i, where the PID of the terminal device i is determined based on the real identity RID of the terminal device i. The transceiver module 1202 is used to send a first parameter to the terminal device i, where the first parameter is used to indicate the PID of the terminal device i.
[0284] Optionally, the processing module 1201 is further configured to store the PID information of the terminal device i using a distributed ledger technology.
[0285] Optionally, the processing module 1201 is also used to store the PID information of the terminal device i using distributed ledger technology, including: the processing module 1201 is also used to store the sparse Merkle tree SMT using distributed ledger technology; the processing module 1201 is also used to store the PID information of the terminal device i in the leaf node indexed as (2i-1) in the SMT.
[0286] Optionally, the processing module 1201 is further configured to store the status of the PID information of the terminal device i using a distributed ledger technology, where the status includes revoked or valid.
[0287] Optionally, the processing module 1201 is also used to store the status of the PID information of the terminal device i using the distributed ledger technology, including: the processing module 1201 is also used to store the SMT using the distributed ledger technology; the processing module 1201 is also used to store the status of the PID information of the terminal device i in the leaf node indexed as (2i) in the SMT.
[0288] Optionally, the processing module 1201 is used to determine the PID of the terminal device i, including: the processing module 1201 is used to determine the PID of the terminal device i when the RID of the terminal device i is included in the real identity list and the PID information of the terminal device i is not stored using distributed ledger technology.
[0289] Optionally, the PID of terminal device i is determined based on the RID of terminal device i, including: the PID of terminal device i is determined based on the RID of terminal device i and at least one of the following: the master private key s of the TA device, the first hash function H1, or the first timestamp T0; wherein, the first timestamp T0 is the timestamp carried in the first message from terminal device i, and the first message is used to request the PID of terminal device i.
[0290] Optionally, the PID of terminal device i satisfies the following relationship:
[0291] Among them, PID i Indicates the PID and RID of terminal device i i Indicates the RID of terminal device i, Represents the exclusive OR operation, and || is the string concatenation operator.
[0292] Optionally, the first parameter is determined based on the PID of terminal device i and the RID of terminal device i.
[0293] Optionally, the processing module 1201 is further used to determine the master public key of the TA device, where the master public key includes a first part of the master public key and a second part of the master public key; the master public key is determined based on the master private key of the TA device and the generator of the additive group G1.
[0294] Optionally, the master private key and / or master public key satisfy the following relationship: P pub =(P pub1 ,P pub2 )=(sP,s -1 P)
[0295] Among them, s represents the master private key, represents the set of integers in the range [1,q-1], where q is the order of the additive group G1; P pub Represents the master public key, P pub1 Represents the first part of the master public key, P pub2 represents the second part of the master public key, and P represents the generator of the additive group G1.
[0296] Optionally, the processing module 1201 is further configured to determine a partial private key PSK of the terminal device i. i , partial private key PSK of terminal device i i It is determined based on at least one of the following: the master private key s of the TA device, the first hash function H1, the RID of the terminal device i, the master public key P of the TA device pub , the second hash function H2, or the first random number λ i , represents a set of integers with a value range of [1, q-1]; the transceiver module 1202 is also used to send a second parameter to the terminal device i, and the second parameter is used to indicate a partial private key of the terminal device i.
[0297] Optional, partial private key PSK of terminal device i i =(α i ,κ i ,θ i ), α i , κ i ,θ i Satisfies the following relationship: α i =s -1 +λ i h i , h i =H2(RID i ||P pub ) κ i =λ i H1(RID) θ i =s -1 H1(RID i )
[0298] Among them, RID i Represents the RID of terminal device i, and || is a string concatenation operator.
[0299] Optionally, the second parameter is based on the RID of the terminal device i and the partial private key PSK i Sure.
[0300] Optionally, the processing module 1201 is further configured to set the status of the PID information of the terminal device i to revoked when the terminal device i performs an illegal operation.
[0301] Optionally, the processing module 1201 is further configured to determine the RID of the terminal device i according to the PID of the terminal device i when the terminal device i performs an illegal operation.
[0302] Optionally, the processing module 1201 is further configured to note the illegal operation of the terminal device i in the real identity list.
[0303] When the communication device 120 is used to implement the functions of the above-mentioned terminal device:
[0304] Among them, the processing module 1201 is used to generate a third message, the third message includes a signature of the original message, and the signature of the original message is determined according to the public key of the terminal device i; the transceiver module 1202 is used to send the third message.
[0305] Optionally, the signature of the original message is determined based on the public key of the terminal device i, including: the signature of the original message is determined based on the public key of the terminal device i and at least one of the following: the private key of the terminal device i, or the first part of the master public key of the trusted authoritative TA device; the partial private key of the terminal device i is determined by the TA device.
[0306] Optionally, the signature of the original message is expressed as (η i ,σ i ), η i , σ i Satisfies the following relationship: η i =γ i R i σ i =(γ i α i +β i )P pub1
[0307] Among them, R i Represents the second part of the public key of terminal device i, α i and β i The private key of terminal device i, P pub1 Indicates the first part of the master public key of the TA device. γ i It is determined based on at least one of the following: a third hash function, the original message, the PID of the terminal device i, the public key of the terminal device i, or a third timestamp, where the third timestamp is a timestamp carried in the third message.
[0308] Optional, γ i Satisfies the following relationship: γ i =H3(M i ||PID i ||PK i ||T i )
[0309] Among them, H3 represents the third hash function, M i Indicates the original message, PID i Indicates the PID and PK of terminal device i i represents the public key of terminal device i, T i Indicates the third timestamp, and || is a string concatenation operator.
[0310] Optionally, the transceiver module 1202 is further configured to receive a second parameter from the TA device, the second parameter being used to indicate a partial private key PSK of the terminal device i. i Processing module 1201 is also used to calculate the partial private key PSK of terminal device i i Determine the private key SK of terminal device i i; Processing module 1201, further configured to obtain the private key SK of the terminal device i i and the second part of the master public key of the TA device to determine the public key PK of the terminal device i i ; Transceiver module 1202, also used to broadcast the public key PK of terminal device i i .
[0311] Optional, partial private key PSK of terminal device i i =(α i ,κ i ,θ i ); if α i H1(RID i )=θ i +κ i h i , then the private key SK of terminal device i i =(α i ,β i );in, Represents a set of integers in the range [1,q-1].
[0312] Optional, the public key PK of terminal device i i =(U i ,R i ), U i 、R i Satisfies the following relationship: U i =β i P pub2 R i =α i P pub2
[0313] Among them, P pub2 Indicates the second part of the master public key of the TA device.
[0314] When the communication device 120 is used to implement the above-mentioned message receiver function:
[0315] Among them, the transceiver module 1202 is used to receive N messages from N terminal devices, where the message n of the terminal device n includes the signature of the original message n, n is a positive integer from 1 to N, and N is a positive integer greater than 1; the processing module 1201 is used to determine the aggregate signature based on the signature of the original message n in the N messages; the processing module 1201 is also used to verify the N messages based on the aggregate signature.
[0316] Optionally, message n also includes a timestamp n; processing module 1201 is used to determine the aggregate signature, including: processing module 1201 is used to determine the aggregate signature when the freshness of message n meets a preset condition, and the freshness of message n is determined based on the timestamp n of message n.
[0317] Optionally, the processing module 1201 is used to determine the aggregate signature, including: the processing module 1201 is used to determine the aggregate signature when the PID information of the terminal device n is stored using the distributed ledger technology and the status of the PID information is valid.
[0318] Optionally, the processing module 1201 is used to verify N messages based on the aggregate signature, including: the processing module 1201 is used to determine the first bilinear mapping result and the second bilinear mapping result based on the aggregate signature; when the first bilinear mapping result and the second bilinear mapping result are the same, the N messages are verified.
[0319] Optionally, the aggregate signature includes Among them, σ n and η n The signature of the original message in message n, U n Represents the first part of the public key of terminal device n.
[0320] Optionally, the second bilinear mapping result is:
[0321] The first bilinear mapping result is:
[0322] Among them, e represents the bilinear mapping relationship, P pub1 Indicates the first part of the master public key of the TA device, P pub2 Indicates the second part of the master public key of the TA device.
[0323] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0324] In the present application, the communication device 120 may be presented in the form of functional modules divided in an integrated manner. The "module" here may refer to a specific application-specific integrated circuit (ASIC), a circuit, a processor and memory that executes one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions.
[0325] In some embodiments, when the communication device 120 in Figure 12 is a chip or a chip system, the function / implementation process of the transceiver module 1202 can be implemented through the input and output interface (or communication interface) of the chip or chip system, and the function / implementation process of the processing module 1201 can be implemented through the processor (or processing circuit) of the chip or chip system.
[0326] Since the communication device 120 provided in this embodiment can execute the above method, the technical effects that can be obtained can refer to the above method embodiments and will not be repeated here.
[0327] As a possible product form, the TA device or terminal device or message receiver described in the embodiments of the present application can also be implemented using the following: one or more field programmable gate arrays (FPGAs), programmable logic devices (PLDs), controllers, state machines, gate logic, discrete hardware components, any other suitable circuits, or any combination of circuits that can perform the various functions described throughout this application.
[0328] As another possible product form, the terminal device or message receiver of the embodiment of the present application can be implemented by a general bus architecture. For ease of explanation, refer to Figure 13, which is a structural diagram of a communication device 1300 provided in an embodiment of the present application, and the communication device 1300 includes a processor 1301 and a transceiver 1302. The communication device 1300 can be a terminal device, or a chip or chip system therein; or, the communication device 1300 can be a TA device, or a chip or module therein. Figure 13 only shows the main components of the communication device 1300. In addition to the processor 1301 and the transceiver 1302, the communication device may further include a memory 1303, and an input and output device (not shown in the figure).
[0329] Optionally, processor 1301 is primarily used to process communication protocols and communication data, as well as control the entire communication device, execute software programs, and process software program data. Memory 1303 is primarily used to store software programs and data. Transceiver 1302 may include a radio frequency circuit and an antenna. The radio frequency circuit is primarily used to convert baseband signals into radio frequency signals and process radio frequency signals. The antenna is primarily used to transmit and receive radio frequency signals in the form of electromagnetic waves. Input and output devices, such as a touch screen, display, and keyboard, are primarily used to receive user input and output data to the user.
[0330] Optionally, the processor 1301 , the transceiver 1302 , and the memory 1303 may be connected via a communication bus.
[0331] When the communication device is powered on, the processor 1301 can read the software program in the memory 1303, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be sent wirelessly, the processor 1301 performs baseband processing on the data to be sent and outputs the baseband signal to the radio frequency circuit. The radio frequency circuit performs radio frequency processing on the baseband signal and then transmits the radio frequency signal to the outside in the form of electromagnetic waves through the antenna. When data is sent to the communication device, the radio frequency circuit receives the radio frequency signal through the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor 1301. The processor 1301 converts the baseband signal into data and processes the data.
[0332] In another implementation, the RF circuit and antenna may be provided independently of the processor performing baseband processing. For example, in a distributed scenario, the RF circuit and antenna may be remotely arranged independent of the communication device.
[0333] In some embodiments, in terms of hardware implementation, those skilled in the art may conceive that the communication device 120 may take the form of the communication device 1300 shown in FIG. 13 .
[0334] As an example, the functions / implementation process of the processing module 1201 in FIG12 can be implemented by the processor 1301 in the communication device 1300 shown in FIG13 calling the computer-executable instructions stored in the memory 1303. The functions / implementation process of the transceiver module 1202 in FIG12 can be implemented by the transceiver 1302 in the communication device 1300 shown in FIG13.
[0335] As another possible product form, the TA device, terminal device, or message receiver in this application may adopt the structure shown in Figure 14, or include the components shown in Figure 14. Figure 14 is a schematic diagram of the structure of a communication device 1400 provided in this application. The communication device 1400 may be a terminal device, a chip, or a system-on-chip in a terminal device; or, it may be a TA device, a module, a chip, or a system-on-chip in a TA device.
[0336] As shown in FIG14 , the communication device 1400 includes at least one processor 1401 and at least one communication interface ( FIG14 is merely an example of one communication interface 1404 and one processor 1401). Optionally, the communication device 1400 may further include a communication bus 1402 and a memory 1403.
[0337] Processor 1401 can be a general-purpose central processing unit (CPU), a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. Processor 1401 can also be other devices with processing capabilities, such as circuits, devices, or software modules, without limitation.
[0338] Communication bus 1402 is used to connect the various components in communication device 1400, enabling communication between them. Communication bus 1402 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, for example. Such buses may be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG14 shows a single bold line, but this does not imply a single bus or type of bus.
[0339] Communication interface 1404 is used to communicate with other devices or communication networks. Exemplarily, communication interface 1404 can be a module, circuit, transceiver, or any other device capable of communication. Optionally, communication interface 1404 can also be an input / output interface within processor 1401, used to implement signal input and output to the processor.
[0340] The memory 1403 may be a device with a storage function, used to store instructions and / or data, wherein the instructions may be computer programs.
[0341] Exemplarily, the memory 1403 may be a read-only memory (ROM) or other types of static storage devices that can store static information and / or instructions, or a random access memory (RAM) or other types of dynamic storage devices that can store information and / or instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, etc., without limitation.
[0342] It should be noted that the memory 1403 can exist independently of the processor 1401 or can be integrated with the processor 1401. The memory 1403 can be located within the communication device 1400 or outside the communication device 1400, without limitation. The processor 1401 can be used to execute instructions stored in the memory 1403 to implement the methods provided in the following embodiments of the present application.
[0343] As an optional implementation, the communication device 1400 may further include an output device 1405 and an input device 1406. The output device 1405 communicates with the processor 1401 and can display information in a variety of ways. For example, the output device 1405 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 1406 communicates with the processor 1401 and can receive user input in a variety of ways. For example, the input device 1406 can be a mouse, a keyboard, a touch screen device, or a sensor device.
[0344] In some embodiments, in terms of hardware implementation, those skilled in the art may conceive that the above-mentioned communication device 120 may take the form of a communication device 1400 shown in FIG. 14 .
[0345] As an example, the functions / implementation process of the processing module 1201 in FIG12 can be implemented by the processor 1401 in the communication device 1400 shown in FIG14 calling the computer-executable instructions stored in the memory 1403. The functions / implementation process of the transceiver module 1202 in FIG12 can be implemented by the communication interface 1404 in the communication device 1400 shown in FIG14.
[0346] It should be noted that the structure shown in FIG14 does not constitute a specific limitation on the TA device, terminal device, or message receiver. For example, in other embodiments of the present application, the TA device, terminal device, or message receiver may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0347] In some embodiments, an embodiment of the present application further provides a communication device, which includes a processor for implementing the method in any of the above method embodiments.
[0348] As a possible implementation, the communication device further includes a memory. The memory is used to store necessary computer programs and data. The computer program may include instructions, and the processor may invoke the instructions in the computer program stored in the memory to instruct the communication device to execute any of the above-described method embodiments. Of course, the memory may not be located in the communication device.
[0349] As another possible implementation, the communication device also includes an interface circuit, which is a code / data read / write interface circuit, and the interface circuit is used to receive computer execution instructions (computer execution instructions are stored in a memory, may be read directly from the memory, or may pass through other devices) and transmit them to the processor.
[0350] As another possible implementation, the communication device further includes a communication interface, where the communication interface is used to communicate with a module outside the communication device.
[0351] It can be understood that the communication device can be a chip or a chip system. When the communication device is a chip system, it can be composed of chips or include chips and other discrete devices. The embodiments of the present application do not specifically limit this.
[0352] The present application also provides a computer-readable storage medium having a computer program or instruction stored thereon, which implements the functions of any of the above method embodiments when executed by a computer.
[0353] The present application also provides a computer program product, which implements the functions of any of the above method embodiments when executed by a computer.
[0354] Those skilled in the art will appreciate that, for the sake of convenience and brevity of description, the specific working processes of the above-described systems, devices, and units may refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0355] It is understood that the systems, devices, and methods described in this application may also be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection shown or discussed may be through some interface, indirect coupling or communication connection of devices or units, and may be electrical, mechanical, or other forms.
[0356] The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Components shown as units may or may not be physical units. Some or all of these units may be selected to achieve the objectives of this embodiment as needed.
[0357] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0358] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using a software program, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more media integrated therein. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state disk (SSD)). In the embodiment of the present application, the computer may include the aforementioned device.
[0359] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art can understand and implement other changes to the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit can implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0360] Although the present application has been described with reference to specific features and embodiments thereof, it is apparent that various modifications and combinations may be made thereto without departing from the scope of the present application. Accordingly, this specification and the drawings are merely illustrative of the present application as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the scope of the present application. Thus, the present application is intended to include such modifications and variations as fall within the scope of the claims of the present application and their equivalents.
Claims
1. A method for identity management, It is characterized in that The method is applied to a trusted authoritative TA device, and the method comprises: Determine a pseudonymous identity PID of a terminal device i, wherein the PID of the terminal device i is determined according to a real identity RID of the terminal device i; A first parameter is sent to the terminal device i, where the first parameter is used to indicate the PID of the terminal device i.
2. The method according to claim 1, It is characterized in that The method further comprises: Distributed ledger technology is used to store the PID information of the terminal device i.
3. The method according to claim 2, It is characterized in that The adopting of distributed ledger technology to store the PID information of the terminal device i includes: Use distributed ledger technology to store sparse Merkle trees SMT; The PID information of the terminal device i is stored in the leaf node indexed as (2i-1) in the SMT.
4. The method according to claim 2 or 3, It is characterized in that The method further comprises: Distributed ledger technology is used to store the status of the PID information of the terminal device i, where the status includes revoked or valid.
5. The method according to claim 4, It is characterized in that The state of using the distributed ledger technology to store the PID information of the terminal device i includes: Use distributed ledger technology to store SMT; The status of the PID information of the terminal device i is stored in the leaf node indexed as (2i) in the SMT.
6. The method according to any one of claims 1 to 5, It is characterized in that The determining the PID of the terminal device i includes: When the real identity list includes the RID of the terminal device i and the PID information of the terminal device i is not stored using distributed ledger technology, the PID of the terminal device i is determined.
7. The method according to any one of claims 1 to 6, It is characterized in that The PID of the terminal device i is determined according to the RID of the terminal device i, including: The PID of the terminal device i is determined according to the RID of the terminal device i and at least one of the following: the master private key s of the TA device, the first hash function H 1 , or the first timestamp T 0 ; Among them, the first timestamp T 0 It is the timestamp carried in the first message from the terminal device i, and the first message is used to request the PID of the terminal device i.
8. The method according to claim 7, It is characterized in that The PID of the terminal device i satisfies the following relationship: Among them, PID i Indicates the PID and RID of the terminal device i i represents the RID of the terminal device i, It represents XOR operation, and || is the string concatenation operator.
9. The method according to any one of claims 1 to 8, It is characterized in that The first parameter is determined according to the PID of the terminal device i and the RID of the terminal device i.
10. The method according to any one of claims 1 to 9, It is characterized in that The method further includes: determining a master public key of the TA device, wherein the master public key includes a first master public key and a second master public key; the master public key is a master private key of the TA device and an additive group G 1 The generators of are determined.
11. The method according to claim 10, It is characterized in that The master private key and / or the master public key satisfy the following relationship: P pub =(P pub1 ,P pub2 )=(sP,s -1 P) Wherein, s represents the master private key, represents the set of integers in the range [1,q-1], where q is the additive group G 1 The order of P pub represents the master public key, P pub1 represents the first part of the master public key, P pub2 represents the second part of the master public key, and P represents the additive group G 1 The generator of .
12. The method according to any one of claims 1 to 11, It is characterized in that The method further comprises: Determine the partial private key PSK of the terminal device i i , the partial private key PSK of the terminal device i i is determined based on at least one of the following: the master private key s of the TA device, the first hash function H 1 , the RID of the terminal device i, the master public key P of the TA device pub , the second hash function H 2 , or the first random number λ i , represents a set of integers in the range [1,q-1]; A second parameter is sent to the terminal device i, where the second parameter is used to indicate a partial private key of the terminal device i.
13. The method according to claim 12, It is characterized in that The partial private key PSK of the terminal device i i =(α i ,κ i ,θ i ), the α i , κ i ,θ i Satisfies the following relationship: α i =s -1 +λ i h i ,h i =H 2 (RID i ||P pub ) κ i =λ i H 1 (RID i ) θ i =s -1 H 1 (RID i ) Among them, RID i represents the RID of the terminal device i, and || is a string connector.
14. The method according to claim 12 or 13, It is characterized in that The second parameter is based on the RID of the terminal device i and the partial private key PSK i Sure.
15. The method according to claim 4 or 5, It is characterized in that The method further comprises: When the terminal device i performs an illegal operation, the status of the PID information of the terminal device i is set to be revoked.
16. The method according to any one of claims 1 to 15, It is characterized in that The method further comprises: When the terminal device i performs an illegal operation, the RID of the terminal device i is determined according to the PID of the terminal device i.
17. The method according to claim 16, It is characterized in that The method further comprises: noting the illegal operation of the terminal device i in the real identity list.
18. A method for sending a message, It is characterized in that The method comprises: Generate a third message, the third message including a signature of the original message, the signature of the original message being determined according to the public key of the terminal device i; The third message is sent.
19. The method according to claim 18, It is characterized in that The signature of the original message is determined according to the public key of the terminal device i, including: The signature of the original message is determined based on the public key of the terminal device i and at least one of the following: the private key of the terminal device i, or the first part of the master public key of the trusted authoritative TA device; the partial private key of the terminal device i is determined by the TA device.
20. The method according to claim 19, It is characterized in that The signature of the original message is expressed as (n i ,σ i ), said n i , σ i Satisfies the following relationship: η i =γ i R i σ i =(γ i α i +β i ) pub1 Among them, R i represents the second part of the public key of the terminal device i, α i and β i The private key of the terminal device i, P pub1 Represents the first part of the master public key of the TA device; The gamma i is determined according to at least one of the following: a third hash function, the original message, the PID of the terminal device i, the public key of the terminal device i, or a third timestamp, the third timestamp being the time carried in the third message stamp.
21. The method according to claim 20, It is characterized in that The gamma i Satisfies the following relationship: γ i =H 3 (M i ||PID i ||PK i ||T i ) Among them, H 3 represents the third hash function, M i Indicates the original message, PID i Indicates the PID of the terminal device i, PK i represents the public key of the terminal device i, T i represents the third timestamp, and || is a string connector.
22. The method according to any one of claims 18 to 21, It is characterized in that Before generating the third message, the method further includes: Receive a second parameter from the TA device, where the second parameter is used to indicate a partial private key PSK of the terminal device i i ; According to the partial private key PSK of the terminal device i i Determine the private key SK of the terminal device i i ; According to the private key SK of the terminal device i i and the second part of the master public key of the TA device to determine the public key PK of the terminal device i i ; Broadcast the public key PK of the terminal device i i .
23. The method according to claim 22, It is characterized in that The partial private key PSK of the terminal device i i =(α i ,κ i ,θ i ); If α i H 1 (RID i )=θ i +κ i h i , then the private key SK of the terminal device i i =(α i ,β i );in, Represents a set of integers in the range [1,q-1].
24. The method according to claim 23, It is characterized in that The public key PK of the terminal device i i =(U i ,R i ), the U i , R i Satisfies the following relationship: i =β i P pub2 R i =α i P pub2 Among them, P pub2 Represents the second part of the master public key of the TA device.
25. A message verification method, It is characterized in that The method comprises: Receiving N messages from N terminal devices, wherein message n of terminal device n includes a signature of original message n, where n is a positive integer from 1 to N, and N is a positive integer greater than 1; Determine an aggregate signature according to the signature of the original message n in the N messages; The N messages are verified according to the aggregate signature.
26. The method according to claim 25, It is characterized in that The message n also includes a timestamp n; and the determining of the aggregate signature includes: When the freshness of the message n meets a preset condition, the aggregate signature is determined, and the freshness of the message n is determined according to the timestamp n of the message n.
27. The method according to claim 25 or 26, It is characterized in that The determining of the aggregate signature includes: The PID information of the terminal device n is stored using a distributed ledger technology, and when the status of the PID information is valid, the aggregate signature is determined.
28. The method according to any one of claims 25 to 27, It is characterized in that Verifying the N messages according to the aggregate signature includes: Determine a first bilinear mapping result and a second bilinear mapping result according to the aggregate signature; When the first bilinear mapping result and the second bilinear mapping result are the same, the N messages are verified successfully.
29. The method according to claim 28, It is characterized in that The aggregate signature includes Among them, σ n and η n The signature of the original message in the message n, U n Represents the first part of the public key of the terminal device n.
30. The method according to claim 29, It is characterized in that The second bilinear mapping result is: The first bilinear mapping result is: Among them, e represents the bilinear mapping relationship, P pub1 Indicates the first part of the master public key of the TA device, P pub2 Represents the second part of the master public key of the TA device.
31. A communication device, It is characterized in that The communication device comprises: a processing module and a transceiver module; The processing module is used to determine the pseudonymous identity PID of the terminal device i, where the PID of the terminal device i is determined based on the real identity RID of the terminal device i; The transceiver module is used to send a first parameter to the terminal device i, where the first parameter is used to indicate the PID of the terminal device i.
32. The communication device according to claim 31, It is characterized in that The processing module is also used to store the PID information of the terminal device i using distributed ledger technology.
33. The communication device according to claim 32, It is characterized in that The processing module is also used for storing the PID information of the terminal device i by using the distributed ledger technology, including: The processing module is further used to store the sparse Merkle tree SMT using distributed ledger technology; The processing module is also used to store the PID information of the terminal device i in the leaf node indexed as (2i-1) in the SMT.
34. The communication device according to claim 32 or 33, It is characterized in that The processing module is further used to store the status of the PID information of the terminal device i using distributed ledger technology, where the status includes revoked or valid.
35. The communication device according to claim 34, It is characterized in that The processing module is also used for storing the state of the PID information of the terminal device i using the distributed ledger technology, including: The processing module is also used to store the SMT using distributed ledger technology; The processing module is also used to store the status of the PID information of the terminal device i in the leaf node indexed as (2i) in the SMT.
36. The communication device according to any one of claims 31 to 35, It is characterized in that The processing module is used to determine the PID of the terminal device i, including: The processing module is used to determine the PID of the terminal device i when the RID of the terminal device i is included in the real identity list and the PID information of the terminal device i is not stored using distributed ledger technology.
37. The communication device according to any one of claims 31 to 36, It is characterized in that The PID of the terminal device i is determined according to the RID of the terminal device i, including: The PID of the terminal device i is determined according to the RID of the terminal device i and at least one of the following: the master private key s of the TA device, the first hash function H 1 , or the first timestamp T 0 ; Among them, the first timestamp T 0 It is the timestamp carried in the first message from the terminal device i, and the first message is used to request the PID of the terminal device i.
38. The communication device according to claim 37, It is characterized in that The PID of the terminal device i satisfies the following relationship: Among them, PID i Indicates the PID and RID of the terminal device i i represents the RID of the terminal device i, It represents XOR operation, and || is the string concatenation operator.
39. The communication device according to any one of claims 31 to 38, It is characterized in that The first parameter is determined according to the PID of the terminal device i and the RID of the terminal device i.
40. The communication device according to any one of claims 31 to 39, It is characterized in that The processing module is also used to determine the master public key of the TA device, the master public key includes a first part master public key and a second part master public key; the master public key is based on the master private key of the TA device and the addition group G 1 The generators of are determined.
41. The communication device according to claim 40, It is characterized in that The master private key and / or the master public key satisfy the following relationship: P pub =(P pub1 ,P pub2 )=(sP,s -1 P) Wherein, s represents the master private key, represents the set of integers in the range [1,q-1], where q is the additive group G 1 The order of P pub represents the master public key, P pub1 represents the first part of the master public key, P pub2 represents the second part of the master public key, and P represents the additive group G 1 The generator of .
42. The communication device according to any one of claims 31 to 41, It is characterized in that The processing module is also used to determine the partial private key PSK of the terminal device i i , the partial private key PSK of the terminal device i i is determined based on at least one of the following: the master private key s of the TA device, the first hash function H 1 , the RID of the terminal device i, the master public key P of the TA device pub , the second hash function H 2 , or the first random number λ i , represents a set of integers in the range [1,q-1]; The transceiver module is further used to send a second parameter to the terminal device i, where the second parameter is used to indicate a partial private key of the terminal device i.
43. The communication device according to claim 42, It is characterized in that The partial private key PSK of the terminal device i i =(α i ,κ i ,θ i ), the α i , κ i ,θ i Satisfies the following relationship: α i =s -1 +λ i h i ,h i =H 2 (RID i ||P pub ) κ i =λ i H 1 (RID i ) θ i =s -1 H 1 (RID i ) Among them, RID i represents the RID of the terminal device i, and || is a string connector.
44. The communication device according to claim 42 or 43, It is characterized in that The second parameter is based on the RID of the terminal device i and the partial private key PSK i Sure.
45. The communication device according to claim 34 or 35, It is characterized in that The processing module is further configured to set the status of the PID information of the terminal device i to be revoked when the terminal device i performs an illegal operation.
46. The communication device according to any one of claims 31 to 45, It is characterized in that The processing module is further configured to determine the RID of the terminal device i according to the PID of the terminal device i when the terminal device i performs an illegal operation.
47. The communication device according to claim 46, It is characterized in that The processing module is further used to note the illegal operation of the terminal device i in the real identity list.
48. A communication device, It is characterized in that The communication device comprises: a processing module and a transceiver module; The processing module is used to generate a third message, wherein the third message includes a signature of an original message, and the signature of the original message is determined according to the public key of the terminal device i; The transceiver module is used to send the third message.
49. The communication device according to claim 48, It is characterized in that The signature of the original message is determined according to the public key of the terminal device i, including: The signature of the original message is determined based on the public key of the terminal device i and at least one of the following: the private key of the terminal device i, or the first part of the master public key of the trusted authoritative TA device; the partial private key of the terminal device i is determined by the TA device.
50. The communication device according to claim 49, It is characterized in that The signature of the original message is expressed as (n i ,σ i ), said n i , σ i Satisfies the following relationship: η i =γ i R i σ i =(γ i α i +β i ) pub1 Among them, R i represents the second part of the public key of the terminal device i, α i and β i The private key of the terminal device i, P pub1 Represents the first part of the master public key of the TA device; The gamma i It is determined based on at least one of the following: a third hash function, the original message, the PID of the terminal device i, the public key of the terminal device i, or a third timestamp, where the third timestamp is a timestamp carried in the third message.
51. The communication device according to claim 50, It is characterized in that The gamma i Satisfies the following relationship: γ i =H 3 (M i ||PID i ||PK i ||T i ) Among them, H 3 represents the third hash function, M i Indicates the original message, PID i Indicates the PID of the terminal device i, PK i represents the public key of the terminal device i, T i represents the third timestamp, and || is a string connector.
52. The communication device according to any one of claims 48 to 51, It is characterized in that The transceiver module is also used to receive a second parameter from the TA device, where the second parameter is used to indicate a partial private key PSK of the terminal device i. i ; The processing module is also used to calculate the partial private key PSK of the terminal device i i Determine the private key SK of the terminal device i i ; The processing module is also used to obtain the private key SK of the terminal device i. i and the second part of the master public key of the TA device to determine the public key PK of the terminal device i i ; The transceiver module is also used to broadcast the public key PK of the terminal device i. i .
53. The communication device according to claim 52, It is characterized in that The partial private key PSK of the terminal device i i =(α i ,κ i ,θ i ); If α i H 1 (RID i )=θ i +κ i h i , then the private key SK of the terminal device i i =(α i ,β i );in, Represents a set of integers in the range [1,q-1].
54. The communication device according to claim 53 or 54, It is characterized in that The public key PK of the terminal device i i =(U i ,R i ), the U i , R i Satisfies the following relationship: i =β i P pub2 R i =α i P pub2 Among them, P pub2 Represents the second part of the master public key of the TA device.
55. A communication device, It is characterized in that The communication device comprises: a processing module and a transceiver module; The transceiver module is used to receive N messages from N terminal devices, wherein the message n of the terminal device n includes the signature of the original message n, where n is a positive integer from 1 to N, and N is a positive integer greater than 1; The processing module is used to determine the aggregate signature according to the signature of the original message n in the N messages; The processing module is further used to verify the N messages according to the aggregate signature.
56. The communication device according to claim 55, It is characterized in that The message n also includes a timestamp n; the processing module is used to determine the aggregate signature, including: The processing module is used to determine the aggregate signature when the freshness of the message n meets a preset condition, and the freshness of the message n is determined according to the timestamp n of the message n.
57. The communication device according to claim 55 or 56, It is characterized in that The processing module is used to determine the aggregate signature, including: The processing module is used to determine the aggregate signature when the PID information of the terminal device n is stored using the distributed ledger technology and the status of the PID information is valid.
58. The communication device according to any one of claims 55 to 57, It is characterized in that The processing module, used to verify the N messages according to the aggregate signature, includes: The processing module is used to determine a first bilinear mapping result and a second bilinear mapping result according to the aggregate signature; When the first bilinear mapping result and the second bilinear mapping result are the same, the N messages are verified successfully.
59. The communication device according to claim 58, It is characterized in that The aggregate signature includes Among them, σ n and η n The signature of the original message in the message n, U n Represents the first part of the public key of the terminal device n.
60. The communication device according to claim 59, It is characterized in that The second bilinear mapping result is: The first bilinear mapping result is: Among them, e represents the bilinear mapping relationship, P pub1 Indicates the first part of the master public key of the TA device, P pub2 Represents the second part of the master public key of the TA device.
61. A communication device, It is characterized in that The communication device includes a processor; the processor is used to run a computer program or instructions so that the communication device performs the method described in any one of claims 1-17, or so that the communication device performs the method described in any one of claims 18-24, or so that the communication device performs the method described in any one of claims 25-30.
62. A computer readable storage medium, It is characterized in that The computer-readable storage medium stores computer instructions or programs. When the computer instructions or programs are executed on a computer, the method according to any one of claims 1 to 17 is executed, or the method according to any one of claims 18 to 24 is executed, or the method according to any one of claims 25 to 30 is executed.
63. A computer program product, It is characterized in that The computer program product comprises program instructions, and when the program instructions are executed by a processor, the method according to any one of claims 1 to 17 is implemented, or the method according to any one of claims 18 to 24 is implemented, or the method according to any one of claims 25 to 30 is implemented.
64. A communication device, It is characterized in that The communication device includes a unit or module for executing the method as described in any one of claims 1-17; or, the communication device includes a unit or module for executing the method as described in any one of claims 18-24; or, the communication device includes a module for executing the method as described in any one of claims 25-30.