Cross-domain identity authentication method based on secret sharing and SM2 algorithm

By introducing Shamir threshold secret sharing and national secret SM2 algorithm in cross-domain identity authentication, the single point of failure and computing overhead problems of traditional methods is solved, and a high security and low overhead two-way identity authentication is realized, which is suitable for complex network environments.

CN120281530APending Publication Date: 2025-07-08XIAN UNIV OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510416773.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

Traditional cross-domain identity authentication methods have problems such as single point of failure risk, complex key management, large computing overhead, and susceptibility to man-in-the-middle attacks, which are difficult to meet the high security and efficient authentication requirements between cross-domain devices.

Method used

Shamir threshold secret sharing protocol is used to store shared seed fragments in multiple domain control centers, and two-way identity authentication is performed in combination with the Guose SM2 algorithm, dynamically generate group keys and verify identity authenticity through the certificate system, avoid single point failure and improve computing efficiency.

Benefits of technology

It realizes cross-domain identity authentication with high security and low computing overhead, adapts to large-scale resource-constrained environments, has good scalability and fault tolerance, prevents man-in-the-middle attacks, and ensures the legality and authenticity between devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281530A_ABST
    Figure CN120281530A_ABST
Patent Text Reader

Abstract

The invention discloses a cross-domain identity authentication method based on secret sharing and an SM2 algorithm, belongs to the technical field of information security, and aims at solving the problems that in an existing authentication scheme, secret keys are managed in a centralized mode, an authentication path depends on a center node, and expansibility is poor. The method comprises the following steps that: each domain control center generates and distributes secret sub-shares based on a Shamir threshold secret sharing protocol, collaboratively recovers a shared seed, and dynamically generates a group key pair according to the shared seed; the terminal equipment generates an SM2 public and private key pair and applies for a digital certificate containing identity information from the CA; the terminal equipment completes certificate legality verification through certificate issuing and signature verification; exchanging certificates and random numbers among the devices, and performing signature and signature verification by using an SM2 algorithm to complete bidirectional identity authentication; and after authentication is completed, a secure communication channel is established. The method has the advantages of decentralization, high security, high efficiency, good expansibility and the like, and is suitable for identity authentication requirements in cross-domain collaborative environments such as the Internet of Things, cloud computing and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and specifically involves knowledge in multiple aspects such as cryptography, digital signature, authentication protocol, and encryption protocol. It provides a cross-domain identity authentication method based on secret sharing and the SM2 algorithm. Background Art

[0002] With the rapid development of information technology and the popularization of the Internet, the network environment has become increasingly complex. Especially in the fields of the Internet of Things, smart cities, cloud computing, and big data, collaborative work between cross-domain devices has become the norm. Although these technologies have brought great convenience and benefits, they have also posed severe challenges in terms of security and privacy protection. As the core technology for ensuring the security of information transmission, preventing illegal access, and defending against malicious attacks, identity authentication has become a key technology in the network security system.

[0003] Identity authentication technology is the primary line of defense against malicious attacks, protecting user privacy and data integrity. Early identity authentication methods (such as "username + password" and "key authentication") played an important role in the traditional network environment, ensuring the basic security of user identity verification and information transmission. However, with the evolution of the network environment, especially in the context of the widespread deployment of cross-domain systems and the continuous growth of large-scale heterogeneous network devices, the limitations of traditional methods have become increasingly apparent. Facing complex cross-domain authentication requirements, these methods expose security risks in key management, single-point failure risks, and authentication performance bottlenecks. In addition, due to the lack of unity in the authentication mechanisms of different systems, the complexity and security challenges of cross-domain identity authentication have been further exacerbated.

[0004] In the context of the proliferation of network devices and the complexity of management domains, the identity authentication problem of cross-domain devices is particularly critical. This not only concerns data security but also directly affects the ability to prevent network fraud, identity theft, and malicious attacks. Traditional centralized identity authentication mechanisms are insufficient in such scenarios, facing problems such as single-point failure risks, privacy leakage hazards, and lack of scalability. Especially in cross-domain communication, the identity authentication process between devices is more complex and more vulnerable to attacks.

[0005] To address these issues, distributed authentication mechanisms have gradually become a research hotspot. Although the traditional Public Key Infrastructure (PKI) has certain generality, it still has problems such as centralized key generation, heavy certificate management burden, and authentication path dependence on central nodes in a cross - domain environment, making it difficult to meet the flexible and highly available collaborative security requirements. In recent years, blockchain technology has been introduced into the identity authentication system due to its decentralized characteristics, improving the system's robustness. However, the visibility of on - chain data and high computational overhead also bring new challenges. Therefore, how to build a cross - domain identity authentication mechanism that supports distributed trust establishment, has a decentralized authentication process, and can adapt to a multi - domain collaborative environment while maintaining high security of authentication has become the core problem that needs to be urgently solved in current research. To address the above problems, this paper proposes a cross - domain identity authentication method based on secret sharing technology and the national cryptography SM2 algorithm. By collaborating with multiple domain control centers to generate shared seeds and construct a group key system, combined with SM2 certificates and a two - way authentication mechanism, it realizes secure, efficient, and scalable multi - domain device identity authentication and trust establishment without relying on the participation of a centralized CA. Summary of the Invention

[0006] The purpose of the present invention is to provide a cross - domain identity authentication method based on secret sharing technology and the national cryptography SM2 algorithm for the problems existing in the existing cross - domain identity authentication technology. The differences between the present invention and traditional methods are as follows:

[0007] Key management architecture: Traditional cross - domain identity authentication methods usually rely on a centralized authentication mechanism, where keys are generated and managed by a single CA node. Once this node is compromised, an attacker may obtain the global key, posing a serious single - point - of - failure risk. In addition, centralized key management also brings problems such as complex distribution and poor fault tolerance. In contrast, the present invention introduces the Shamir threshold secret sharing protocol, distributes and stores the shared seeds used to generate the group key in multiple domain control center nodes after sharding. Only when a threshold number of nodes participate collaboratively can the shared seeds be reconstructed and the group key be generated. Moreover, the group key itself is neither directly stored nor distributed among nodes, but is only dynamically generated when needed, thus effectively preventing key leakage and abuse and enhancing the security and robustness of the system.

[0008] Authentication protocol design: Most traditional authentication protocols are based on the RSA algorithm and adopt a one - way verification mode, that is, only the server verifies the identity of the client, making it vulnerable to threats such as man - in - the - middle attacks and identity forgery. The present invention designs a two - way authentication protocol combining the SM2 algorithm and the secret sharing mechanism to achieve mutual identity verification between the terminal device and the target device. This protocol not only ensures the legality and authenticity of the identities of both parties in the authentication, but also prevents replay attacks and forged authentication through the challenge - response mechanism, effectively enhancing the security and protection ability of the authentication process.

[0009] Algorithm and performance optimization: Existing cross-domain identity authentication methods generally use traditional digital signature algorithms such as RSA or ECC. Although they have certain security, they have problems such as high computational overhead and low efficiency in large-scale device deployment or resource-constrained scenarios. To this end, the present invention adopts the SM2 algorithm that complies with national cryptographic standards, which has better computing performance and stronger security strength, can significantly improve the operating efficiency during the authentication process, and is more suitable for low-power devices and edge computing scenarios.

[0010] To achieve the above purpose, the technical solution adopted by the present invention is: a cross-domain identity authentication method based on secret sharing technology and the national secret SM2 algorithm, comprising the following steps:

[0011] Step 1, system initialization: Each domain control center generates a secret share and distributes the secret sub-share to other control nodes to participate in the secret recovery process and then jointly generate the group key.

[0012] Step 2, terminal device key generation and certificate application: The terminal device generates a public-private key pair and submits a certificate application request (CSR) to the CA. The request includes the public key and identity information. After receiving it, the CA uses the SM2 algorithm to issue a digital certificate.

[0013] Step 3, certificate issuance and verification: CA uses the SM2 algorithm to issue a digital certificate. After the terminal device receives the certificate, it uses the SM2 algorithm to verify its validity and the legitimacy of the identity information.

[0014] Step 4, cross-domain authentication request and response: The terminal device first initiates an authentication request to the target device and authenticates the identity through a digital certificate and a random number. After receiving the request, the target device verifies the legitimacy of the terminal device's certificate and returns its own certificate and random number. After completing the legitimacy verification, the terminal device and the target device mutually verify the signature sent by each other to verify the authenticity of the identity. If passed, it means that the two-way identity authentication is successful.

[0015] Step 5, two-way authentication and session establishment: Both devices verify the certificate and signature information to ensure the legitimacy and authenticity of the certificate. After the two-way authentication is passed, a secure cross-domain communication channel is established.

[0016] Preferably, in step 1, each domain control center generates secret shares using the Shamir secret sharing algorithm and distributes these secret sub-shares to other control nodes. Each domain control center uses a combination of secret sub-shares to restore the original secret, thereby generating a shared key and providing a basis for subsequent identity authentication processes.

[0017] Preferably, the specific steps of step 2 are as follows:

[0018] Step 2.1, the terminal device generates a public-private key pair. The private key is securely stored in the terminal device, and the public key is sent to the CA for certificate application.

[0019] Step 2.2, the terminal device submits a certificate application request (CSR) to the CA. The request includes the public key and the identity information of the device.

[0020] Step 2.3, the CA verifies the identity information of the terminal device and issues a digital certificate through the SM2 algorithm.

[0021] Preferably, the specific steps of step 3 are as follows:

[0022] Step 3.1, after receiving the certificate, the terminal device verifies the validity of the certificate through the group public key.

[0023] Step 3.2, the terminal device confirms whether the identity information in the certificate is legal and ensures that the certificate is within the validity period.

[0024] Preferably, the specific steps of step 4 are as follows:

[0025] Step 4.1, the terminal device generates an authentication request, which includes its own digital certificate and a random number, and sends it to the target domain device.

[0026] Step 4.2, the target device uses the group public key to verify the validity of the terminal device certificate and confirm its legality. After the target device's legality authentication is successful, it sends its digital certificate and a random number to the terminal device and waits for the terminal device to verify.

[0027] Step 4.3, after two-way legality verification, the terminal device sends the identity information signed with its private key to the target device. After receiving the signature, the target device extracts the public key of the terminal device from the previously received certificate for signature verification. If the signature verification passes, the authenticity verification passes. After the target device's authenticity verification is successful, it sends the identity information signed with its private key and waits for the terminal device to verify. After the terminal device's authenticity verification is successful, the two-way identity authentication passes.

[0028] Compared with the prior art, the present invention has the following beneficial effects: Traditional cross-domain identity authentication methods generally rely on centralized CA for key management, which has a significant single point of failure risk. Once the CA node is attacked or fails, it may lead to the leakage of the global key, seriously threatening system security. In addition, traditional authentication processes are mostly based on the RSA algorithm and usually adopt a one-way authentication mode from the server to the client, making them vulnerable to man-in-the-middle attacks. At the same time, when a higher security strength is required, the RSA algorithm needs to use a key of more than 2048 bits, bringing significant computational and communication burdens and being unsuitable for resource-constrained or high-frequency communication environments. In contrast, the present invention integrates the secret sharing technology and the national cryptographic SM2 algorithm to construct a multi-center distributed key management and authentication mechanism. Through the Shamir threshold protocol, each domain control center collaborates to generate the shared seed of the group key and distributes and stores its shards in multiple control nodes. The system can dynamically recover the shared seed and generate the group key pair only when the threshold number of nodes participate collaboratively, thus avoiding the single point of failure and the risk of long-term private key holding in the traditional centralized key architecture. Even if some control nodes are attacked or fail, the system still has fault tolerance, ensuring the availability and security of the overall authentication system. The present invention introduces the national cryptographic SM2 algorithm in the authentication process to implement a two-way identity authentication mechanism between the terminal device and the target device, ensuring the legality and authenticity of the identities of both communication parties and effectively preventing security threats such as forged authentication requests and man-in-the-middle attacks. The SM2 algorithm has a high signature and verification efficiency, and has a smaller key length and lower computational overhead than RSA under the same strength conditions, significantly improving the authentication response speed and the overall operation efficiency of the system, and being particularly suitable for large-scale, resource-constrained cross-domain network environments. In addition, the authentication system proposed by the present invention has good scalability and adaptability, can flexibly access multiple domain control centers, meet the authentication requirements of large-scale collaborative deployment of cross-domain devices, and provide effective support for constructing a highly secure and highly available cross-domain identity authentication architecture while ensuring the stable operation of the system.

[0029] The present invention proposes a cross-domain identity authentication method based on the secret sharing technology and the SM2 algorithm, and its innovations are mainly reflected in the following aspects:

[0030] Decentralized key collaboration mechanism: This method combines the Shamir threshold secret sharing technology to fragment the shared seed required for generating the group key and stores them separately in multiple domain control center nodes. Only when the set threshold number of nodes participate collaboratively can the seed recovery be completed and the group key pair be dynamically generated. This mechanism avoids the single point of failure risk in traditional centralized key management and improves the security and fault tolerance of the system.

[0031] SM2 Algorithm Improves Security and Computational Efficiency: This method uses the national cryptographic SM2 algorithm for digital signature and verification operations. Compared with traditional algorithms such as RSA, SM2 has a shorter key length and higher computational efficiency under the premise of providing the same security strength, significantly reducing the computational and communication overhead in the authentication process, and is suitable for large-scale deployment in resource-constrained device environments.

[0032] Certificate-Based Mutual Authentication Mechanism: The present invention realizes mutual authentication between devices through the SM2 certificate system, combines digital signature and random number challenge-response mechanism to ensure the legality and authenticity of the identities of both communication parties, effectively prevents man-in-the-middle attacks and forged authentication requests, and enhances the security strength of the overall authentication process.

[0033] Good Scalability and Adaptability: The proposed distributed authentication architecture has high scalability, can flexibly support the collaborative authentication of multiple domain control centers and large-scale terminal devices, adapt to the dynamically changing cross-domain network environment, and meet the high availability and sustainability requirements of complex systems for security authentication. Description of the Drawings

[0034] Figure 1 is the flowchart of a cross-domain identity authentication method based on secret sharing and SM2 algorithm of the present invention;

[0035] Figure 2 is the system architecture diagram of a cross-domain identity authentication method based on secret sharing and SM2 algorithm of the present invention;

[0036] Figure 3 is the specific content of the certificates of CA and terminal devices in a cross-domain identity authentication method based on secret sharing and SM2 algorithm of the present invention;

[0037] Figure 4 is the result diagram of two-way authentication between two terminals in a cross-domain identity authentication method based on secret sharing and SM2 algorithm of the present invention; Detailed Embodiments

[0038] The following will disclose multiple embodiments of the present invention. For the sake of clarity, many physical details will be described together in the following narrative. However, it should be understood that these physical details are not used to limit the present invention. That is to say, in some embodiments of the present invention, these physical details are unnecessary.

[0039] In addition, the technical solutions between various embodiments can be combined with each other, but it must be based on the ability of those of ordinary skill in the art to implement. When the combination of technical solutions results in contradictions or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present invention.

[0040] The following is combined withFigures 1-4 , a further detailed description of a cross - domain identity authentication method based on secret sharing and the SM2 algorithm of the present invention is given.

[0041] The system architecture of this method is as Figure 2 shown, and the method includes the following participants:

[0042] (1) Domain Control Center D: Verifies the identity of the terminal making a cross - domain request;

[0043] (2) Terminal DN, completes the cross - domain identity authentication process;

[0044] (3) Certificate Authority CA, responsible for issuing, verifying, and revoking digital certificates;

[0045] The process of the cross - domain identity authentication method based on secret sharing and the SM2 algorithm is as Figure 1 shown, and the specific implementation steps are as follows:

[0046] Step 1, System initialization: Each domain control center generates secret shares, distributes the secret sub - shares to other control nodes, participates in the secret recovery process, and then jointly generates a group public - private key pair, which is used to generate terminal user certificates and signature opening. Suppose there are n domain control centers D1, D2,..., D n , and the (t, n) threshold secret sharing protocol (t ≤ n) is adopted. Each domain control center D i generates a random number and records s i = a i0 , and constructs a polynomial f i (x)= a i0 + a i1 x + … + a i(t-1) x t-1 . Then for j = 1, 2,..., n, D i calculates the sub - share f i (j), and then encodes each sub - share f i (j). The public key pk j of each receiver encrypts the encoded sub - share f' i (j) to obtain the encrypted sub - share pair. After encryption is completed, the participant D i sends the encrypted secret sub - share to the corresponding receiver D j . After decrypting the sub - share, verifies the zero - knowledge proof and calculates the aggregated sub - share selects t valid sub - shares, reconstructs the polynomial to obtain the shared seed performs a hash operation on the shared seed s to obtain a random number S, and then generates a group public - private key pair (sk group , pkgroup )。

[0047] Step 2, Terminal Device Key Generation and Certificate Application: The terminal device generates a public-private key pair and submits a certificate application request (CSR) to the CA. The request contains the public key and identity information. After receiving the request, the CA issues a digital certificate using the SM2 algorithm. The specific contents of the certificates of the CA and the terminal device are as Figure 2 shown.

[0048] Step 2.1, The terminal device generates a public-private key pair (pk A , sk A ). The private key is securely stored in the terminal device, and the public key is sent to the CA for certificate application.

[0049] Step 2.2, The terminal device submits a certificate application request (CSR) to the CA. The request includes the public key pk A and the identity information ID A of the device.

[0050] Step 2.3, The CA verifies the identity information of the terminal device and issues a digital certificate cert α using the SM2 algorithm. First, calculate the hash value e = SM3(Z CA ||ID A ||pk A ), then generate a random number k ∈ [1, n - 1], calculate the elliptic curve point G1(x1, y1) = kG, calculate the signature (r A , s A ) and then issue the certificate cert A .

[0051] Step 3, Certificate Issuance and Verification: The CA issues a digital certificate using the SM2 algorithm. After receiving the certificate, the terminal device verifies its validity and the legality of the identity information.

[0052] Step 3.1, After receiving the certificate, the terminal device verifies the authenticity of the certificate cert group through pk A , and then secretly stores the certificate.

[0053] Step 3.2, The terminal device confirms whether the identity information in the certificate is legal and ensures that the certificate is within the validity period. Calculate t = (r A +s A ) mod n, verify that t ≠ 0; calculate the point (x'1, y'1) on the elliptic curve = s A ·G + t·pk group ; verify that R = (e + x'1) mod n = r A .

[0054] Step 4, Cross-Domain Authentication Request and Response: The terminal device first sends an authentication request to the target device and performs identity verification using a digital certificate and a random number. After receiving the request, the target device verifies the legality of the terminal device's certificate and returns its own certificate and random number. After completing the legality verification, the terminal device and the target device mutually verify the signatures sent by each other to verify the authenticity of the identity. Passing the verification indicates successful two-way identity authentication.

[0055] Step 4.1, The terminal device generates an authentication request, which includes the digital certificate cert A of the terminal device and a random number T1, and sends them to the target domain device.

[0056] Step 4.2, The target device uses the group public key pk group to verify the validity of the terminal device's certificate, calculates t = (r A + s A ) mod n (check that t ≠ 0), generates an elliptic curve point (x'1, y'1) = s A ·G + t·pk group , and verifies that R = (e + x'1) mod n = r A , to confirm its legality. After the terminal device receives the response, it repeats the above process to verify the legality of the target device's certificate.

[0057] Step 4.3, After passing the two-way legality verification, the terminal device sends the identity information signed with its private key sk A to the target device. After receiving the signature, the target device extracts the public key pk A of the terminal device from the previously received certificate for signature verification, (x A , y A ) = s' A ·G + SM3(ID A )·pk A . If the signature verification passes, the authenticity verification of the terminal device passes. After the authenticity verification of the target device is successful, it sends the identity information signed with its private key and repeats the above process to verify the authenticity of the target device. After the authenticity verification of the terminal device passes, the two-way identity authentication passes.

[0058] Step 5, Two-Way Authentication and Session Establishment: The two devices verify the certificate and signature information to ensure the legality and authenticity of the identity of the certificate. After the two-way authentication passes, a secure cross-domain communication channel is established. The specific result diagram of the two-way authentication of the two terminals is as Figure 4 shown.

[0059] The above are only the embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, various modifications and variations can be made to the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.

Claims

1. A cross - domain identity authentication method based on secret sharing and SM2 algorithm, characterized in that Follow the steps below to implement it: Step 1, system initialization: domain control center key generation and sharing, each domain control center generates a secret share and distributes the secret sub-share to other control nodes to participate in the secret recovery process and jointly generate the group key; Step 2: Terminal device key generation and certificate application: The terminal device generates a public-private key pair and submits a certificate application request (CSR) to the CA. The request includes the public key and identity information. After receiving the request, the CA uses the SM2 algorithm to issue a digital certificate. Step 3, certificate issuance and verification: CA uses the SM2 algorithm to issue a digital certificate. After receiving the certificate, the terminal device uses the SM2 algorithm to verify its validity and the legitimacy of the identity information; Step 4, cross-domain authentication request and response: The terminal device first initiates an authentication request to the target device and authenticates the identity through a digital certificate and a random number; after receiving the request, the target device verifies the legitimacy of the terminal device's certificate and returns its own certificate and random number; After completing the legitimacy verification, the terminal device and the target device mutually verify the signature sent by each other to verify the authenticity of the identity. If passed, it means that the two-way identity authentication is successful; Step 5, two-way authentication and session establishment: Both devices verify the certificate and signature information to ensure identity authenticity; after the two-way authentication is passed, the shared key is used to encrypt the communication and establish a secure cross-domain communication channel.

2. The cross-domain identity authentication method based on secret sharing and SM2 algorithm according to claim 1, characterized in that, In step 1, each domain control center generates secret shares using the Shamir secret sharing algorithm and distributes these secret sub-shares to other control nodes; each domain control center uses a combination of secret sub-shares to restore the original secret, thereby generating a shared key and providing a basis for the subsequent identity authentication process.

3. According to claim 1, a cross-domain identity authentication method based on secret sharing and SM2 algorithm is characterized in that: The specific steps of step 2 are as follows: Step 2.1: The terminal device generates a public-private key pair; the private key is securely stored in the terminal device, and the public key is sent to the CA for certificate application; Step 2.2: The terminal device submits a certificate request (CSR) to the CA, which includes the public key and the device's identity information. Step 2.3: CA verifies the identity information of the terminal device and issues a digital certificate using the SM2 algorithm.

4. According to claim 1, a cross-domain identity authentication method based on secret sharing and SM2 algorithm is characterized in that: The specific steps of step 3 are as follows: Step 3.1: After receiving the certificate, the terminal device verifies the validity of the certificate through the group public key; Step 3.2: The terminal device confirms whether the identity information in the certificate is legal and ensures that the certificate is within the validity period.

5. According to claim 1, a cross-domain identity authentication method based on secret sharing and SM2 algorithm is characterized in that: The specific steps of step 4 are as follows: Step 4.1: The terminal device generates an authentication request, including its own digital certificate and random number, and sends it to the target domain device; Step 4.2, the target device uses the group public key to verify the validity of the terminal device certificate and confirm its legitimacy; After the target device successfully authenticates its legitimacy, it sends its digital certificate and random number to the terminal device and waits for verification by the terminal device; Step 4.3, after passing the two-way legality verification, the terminal device sends the identity information signed with its private key to the target device. After receiving the signature, the target device extracts the public key of the terminal device from the previously received certificate for signature verification. If the signature verification passes, the authenticity verification passes. After the target device's authenticity verification is successful, it sends the identity information signed with its private key and waits for the verification of the terminal device. After the terminal device's authenticity verification passes, the two-way identity authentication passes.