Method and system for traceable anonymous voucher revocation of limited equipment
By introducing authoritative organizations and global parameter generation methods into restricted devices, the problem that SIM cards cannot independently complete the credential system process is solved, and fast tracking and revocation of anonymous users is realized, which is suitable for restricted devices such as SIM cards of mobile phones.
Patent Information
- Application Number
- CN202510419759.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-22
AI Technical Summary
Traditional anonymous credential schemes cannot independently complete the credential system process on restricted devices such as SIM cards in mobile phones, and cannot quickly track and revoke anonymous users.
Introduce authoritative organizations to realize unified management of user identities by generating global parameters, public and private keys, registration, tracking keys and revocation functions, and support anonymous credential systems in restricted device scenarios.
It realizes fast tracking of anonymous users and rapid revocation of user identity. The calculation burden does not change with the number of attributes and is suitable for restricted devices.
Smart Images

Figure CN120358018A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cryptography, and in particular to a method and system for traceable revocation of anonymous credentials of a restricted device. Background Art
[0002] User credentials are a set of information used to verify the identity of a user, usually including a username and password, to ensure that only authorized users can access resources in a system or application. User credentials are a core component of network security and identity authentication, and they have a wide range of functions and application scenarios. User credentials are a set of information used to verify the identity of a user, usually including a username and password. This information ensures that only authorized users can access resources in a system or application. In addition, user credentials may also include security verification codes, access tokens, cookies, etc.
[0003] With the booming development of the Internet era, people are paying more and more attention to the protection of personal privacy. One of the effective solutions is to use anonymous credential technology to sign the user's attributes. The basic anonymous credential scheme includes the issuance, display and verification of credentials. However, anonymity can also lead to some abuse or malicious behavior. For example, if a malicious user illegally steals the credentials and corresponding secrets of a legitimate user, the user's credentials can be used illegally; or even a legitimate user may violate the corresponding agreement in the process of using the credentials, such as continuing to use expired credentials. Since the user's use of credentials is anonymous, the regulatory authorities cannot modify the credentials, nor can they find the corresponding users for reasonable sanctions. Therefore, this anonymity is not unlimited and needs to be subject to a certain range, that is, the regulatory authorities or authoritative centers need to track or revoke the violating users. At the same time, in the traditional mobile device scenario, the SIM card in the mobile phone is a security element that stores the user's secrets. However, the SIM card has weak computing power and is a limited device that cannot independently complete the entire credential system process. It needs to rely on external devices with strong computing power (such as mobile phones) to help it perform calculations. Therefore, the traditional anonymous credential scheme is not compatible with this scenario. Summary of the invention
[0004] The purpose of the present invention is to provide a method and system for traceable revocation of anonymous credentials for restricted devices. The method introduces an authoritative agency and adds registration, tracking and revocation functions, which can support restricted device scenarios and achieve rapid tracking and millisecond-level revocation while ensuring that the computational burden of the credentials no longer changes with the number of attributes.
[0005] A method for traceable revocation of anonymous credentials for a restricted device, comprising:
[0006] The system generates global parameters and sends them to authorities, issuing agencies, users, and service providers;
[0007] The certificate-issuing agency and the user generate corresponding public and private keys according to the global parameters;
[0008] The user sends the public key and the tracing key to the authority for registration;
[0009] The certificate-issuing agency generates a credential according to the user's public key and attributes;
[0010] The service provider returns service permissions to the user based on the user's registration status, user attributes, and user credentials;
[0011] The authority traces the user's identity public key;
[0012] The authority revokes the user's identity public key.
[0013] Preferably, the system generates global parameters and sends them to the authority, the certificate-issuing agency, the user, and the service provider, including:
[0014] The system executes the initialization algorithm Setup(1 λ )→pp: The algorithm takes the security parameter 1 λ as input and generates a bilinear mapping group where the generator
[0015] Select a random number Calculate
[0016] Select three hash functions H: H1: H2:
[0017] The authority clears the repository DB and sets a public blank blacklist L as the revocation list;
[0018] Output the public parameters pp = (BG, H, H1, H2, Y1, Y2, L).
[0019] Preferably, the certificate-issuing agency and the user generate corresponding public and private keys according to the global parameters, including:
[0020] The certificate-issuing agency executes the key generation algorithm IKGen(1 λ , t, l)→(isk, ipk): Taking the public parameter 1λ, the number of attributes t, and the size l = 2 of the user's public key vector as input, select the key rk of the pseudo-random function PRF;
[0021] For each i ∈ [t], select Calculate
[0022] Let the private key The public key
[0023] The user core device executes the key generation algorithm CKGen(1 λ ) → (upk, ssk, utk, st pub ) : Input the security parameter 1 λ , select a random number Calculate the user identity public key Tracking key
[0024] Select another random number Calculate the auxiliary public parameter
[0025] Let the user core device private key
[0026] Send upk, utk and st pub To the user auxiliary device.
[0027] Preferably, the user sending the public key and the tracking key to the authority for registration includes:
[0028] The user core device and the user auxiliary device run an interactive protocol The user core device executes the CRegister algorithm, inputting the private key ssk; the user auxiliary device executes the HRegister algorithm, inputting the user public key upk, the tracking key utk and the auxiliary public parameter st pub ;
[0029] Record upk = (upk1, upk2), run the zero - knowledge proof protocol Calculate the proof π and send it to the authority:
[0030] The user core device selects a random number Calculate temp x = r x · k -1 And send it to the user auxiliary device;
[0031] The user auxiliary device calculates respectively c x = H(h1||h2||upk2||utk), and send c x To the user core device;
[0032] The user core device calculates s = r x + c x · x, and send s to the user auxiliary device;
[0033] The user auxiliary device constructs π = (h1, h2, cx , s);
[0034] The authoritative institution executes the user registration algorithm AuthRegister(UPK, upk, utk, π) → UPK′: Given the set of registered user public keys UPK, the user public key upk, the tracing key utk, and the relevant proof π, the authoritative institution verifies the proof π by performing the following two steps:
[0035] Verify c x = H(h1||h2||upk2||utk) holds;
[0036] Verify and hold
[0037] If both verifications pass, update the set of registered user public keys UPK′ = UPK ∪ upk, add the entry upk - utk to the repository DB, and return 1 to the user auxiliary device to notify successful registration; otherwise, directly return 0 to the user auxiliary device to notify registration failure.
[0038] Preferably, the certificate - issuing institution generates a credential based on the user public key and attributes, including:
[0039] Generate a credential request:
[0040] The user core device and the user auxiliary device run an interactive protocol The user core device executes the CObtain algorithm, and the user auxiliary device executes the HObtain algorithm to calculate the credential request areq and send it to the certificate - issuing institution:
[0041] The user auxiliary device executes the attribute identifier generation algorithm AIDGen(Attr, nonce) → aid: Given the set of attributes Attr, select a random value nonce, generate the attribute identifier aid and send it to the user core device;
[0042] The user core device selects a random number Calculate the pre - processed credential signature where The pre - processed credential request apreq = (σ pIss , st pub ) is sent to the user auxiliary device;
[0043] The user auxiliary device calculates The random value nonce and the credential request areq = (upk, σ Iss ) are sent to the certificate - issuing institution.
[0044] Preferably, the certificate issuing agency generating a credential according to the user public key and attributes includes:
[0045] The certificate issuing agency executes the certificate issuing algorithm Issue(Attr, nonce, areq, isk) → cred: input the set of attributes Attr, random value nonce, certificate request areq and private key isk:
[0046] Interact with the authoritative agency to check whether the public key upk is stored in the set of registered user public keys UPK. If not, it means the user is not registered, and directly return certificate issuing failure to the user;
[0047] Execute the AIDGen algorithm to generate the attribute identifier aid;
[0048] Verify the signature σ Iss Denote σ Iss =(σ Iss1 , σ Iss2 , σ Iss3 ), upk=(upk1, upk2), check whether the equations e(σ Iss2 , g2)=e(g1, σ Iss3 ) and e(σ Iss1 , g2)=e(upk2, Y2)·e(H1(aid), σ Iss3 ) hold. If any equation does not hold, directly return certificate issuing failure to the user;
[0049] For each i ∈ [n], obtain the corresponding attribute private key Denote the value of the corresponding attribute Attr i as The seed string = upk, use the PRF function key rk and the seed string to calculate y ← PRF(rk, upk), calculate Denote Return the credential to the user;
[0050] After receiving the credential, the user auxiliary device verifies the credential and for each checks whether the equation holds;
[0051] If all hold, then check whether the equation e(Y 1,1 , g2)=e(g1, Y 2,1 ) holds. If it holds, the user auxiliary device stores the credential.
[0052] Preferably, the certificate issuing agency generating a credential according to the user public key and attributes includes:
[0053] The user core device and the user auxiliary device run an interaction protocol The user core device executes the CShow algorithm, and the user auxiliary device executes the HShow algorithm to calculate the credential presentation ashow and send it to the service provider:
[0054] The user auxiliary device executes the attribute identifier generation algorithm AIDGen(Attr, nonce) → aid: Input the set of attributes Attr required by the service provider's access policy, select a random value nonce, generate the attribute identifier aid and send it to the user core device;
[0055] The user core device selects a random number Calculate the preprocessed credential presentation Send the preprocessed credential request apshow = (σ pS , st pub ) to the user auxiliary device;
[0056] The user auxiliary device calculates Where Denote the index set D of the presented attributes, the signature corresponding to the attribute Attr j Calculate the aggregated signature σ =(Z1, Y1, Y2, V2)=(∏ Attr Z j∈D , Y 1,j , Y 1,1 , Y 2,1 ,∏ j∈D V 2,j ), select a random number And a random number Calculate the randomized public key And the randomized signature Select another random number Calculate the randomized credential Send the random value nonce and the credential presentation ashow = (upk′, σ′ S , σ′ Attr ) to the service provider.
[0057] Preferably, the service provider returns service permissions to the user according to the user registration situation, user attributes, and user credentials, including:
[0058] The service provider executes the verification algorithm Verify(L, Attr, nonce, ipk, ashow) → 0 / 1: Given the blacklist attribute L, the set Attr, the nonce, the public key ipk of the issuing authority, and the credential show ashow, the service provider sequentially performs the following steps:
[0059] The service provider queries the blacklist L provided by the authoritative institution and sequentially pairs utk' with the tracing keys on L: Assume L = (utk1, utk2,..., utk num ), denote upk' = (upk'1, upk'2), for each i ∈ [num], the service provider sequentially calculates whether the equation e(upk'1, utk i ) = e(upk'2, g2) holds. If any of the equations holds, it indicates that the user has been revoked, and the service provider directly returns an application failure to the user;
[0060] The service provider checks whether the attribute set Attr satisfies the access policy. If it does not satisfy the access policy, the service provider directly returns an application failure to the user;
[0061] The service provider verifies the signature σ' S : Denote σ' S = (σ' S1 , σ' S2 , σ' S3 ), check whether the equations e(σ' S2 , g2) = e(g1, σ' S3 ) and e(σ' S1 , g2) = e(upk'2, Y2) · e(H1(aid), σ' S3 ) hold. If any of the equations does not hold, the service provider directly returns an application failure to the user;
[0062] The service provider verifies the signature σ' Attr : Denote σ' Attr = (Z'1, Y'1, Y'2, V'2), check whether the equation e(Y'1, g2) = e(g1, Y'2), holds;
[0063] If any of the equations does not hold, the service provider directly returns an application failure to the user. Otherwise, the service provider provides the corresponding access permission to the user.
[0064] Preferably, the authoritative institution tracing the user's identity public key and revoking the user's identity public key includes:
[0065] The authority executes the tracing algorithm Trace(upk′, utk) → upk: Pair the randomized public key upk′ of the user to be traced with the tracing key utk of the entry in the repository DB in sequence;
[0066] Suppose DB = {(upk1 - utk1), (upk2 - utk2), …, (utk num -utk num )}, and denote upk′ = (upk′1, upk′2);
[0067] For each i ∈ [num], calculate in sequence whether the equation e(upk′1, utk i ) = e(upk′2, g2) holds. The tracing key utk i corresponding to the entry of i is the actual identity public key of the user to be traced;
[0068] The authority executes the algorithm Revoke(upk, UPK, L) → (UPK′, L′): Find the entry upk - utk corresponding to upk in the repository DB and delete it. Remove upk from the set of registered user public keys UPK′ = UPK \ upk, and add the tracing key utk to the blacklist L′ = L ∪ utk.
[0069] A traceable revocation anonymous credential system for restricted devices, comprising:
[0070] A parameter generation module, used for the system to generate global parameters and send them to the authority, the credential issuer, the user, and the service provider;
[0071] A key generation module, used for the credential issuer and the user to generate corresponding public and private keys according to the global parameters;
[0072] A registration module, used for the user to send the public key and the tracing key to the authority for registration;
[0073] A credential generation module, used for the credential issuer to generate credentials according to the user's public key and attributes;
[0074] A verification module, used for the service provider to return service permissions to the user according to the user's registration status, user attributes, and user credentials;
[0075] A tracing module, used for the authority to trace the identity public key of the user;
[0076] A revocation module, used for the authority to revoke the identity public key of the user.
[0077] The beneficial effects of the present invention are as follows: 1. Unified management of user identities in the present invention: An authoritative institution is introduced to register users, achieving unified management of user identities; 2. Quick tracking of anonymous users in the present invention: When a user registers with the authoritative institution, a tracking key needs to be provided. If the user violates the agreement, the authoritative institution can execute the Trace algorithm to traverse the tracking keys in the repository and match them with the randomized public key of the user to be tracked. Those that pass the match are the users to be tracked, realizing quick tracking of anonymous users; 3. Quick revocation of users in the present invention: If a user needs to be revoked, the authoritative institution can execute the Revoke algorithm to remove the user's public key from the repository and add the corresponding tracking key to the blacklist, realizing quick revocation of users. BRIEF DESCRIPTION OF THE DRAWINGS
[0078] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with the present invention and, together with the specification, are used to explain the principles of the present invention.
[0079] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the accompanying drawings required for describing the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0080] Figure 1 It is a flowchart of a traceable revocation anonymous credential method for a restricted device of the present invention;
[0081] Figure 2 It is a structural diagram of a traceable revocation anonymous credential system for a restricted device of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0082] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0083] It should be noted that all directional indications (such as up, down, left, right, front, back...) in the embodiments of the present invention are only used to explain the relative positional relationship and movement conditions between components in a specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indications will also change accordingly.
[0084] In addition, the descriptions involving "first", "second", etc. in the present invention are only for descriptive purposes and should not be construed as indicating or implying their relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In addition, the technical solutions between various embodiments may be combined with each other, but it must be based on the ability of those of ordinary skill in the art to implement. When the combination of technical solutions results in contradictions or inability to implement, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present invention.
[0085] In the traditional mobile device scenario, the SIM card in a mobile phone, as a security element, stores the user's secrets. However, the SIM card has weak computing power and is a restricted device that cannot complete the entire credential system process independently and needs to rely on an external device with stronger computing power (such as a mobile phone) to assist in its operation. Therefore, the traditional anonymous credential scheme is not compatible.
[0086] Unified management of user identities in the present invention: An authoritative institution is introduced to register users and achieve unified management of user identities; Quick tracking of anonymous users in the present invention: When a user registers with the authoritative institution, a tracking key needs to be provided. If the user violates the protocol, the authoritative institution can execute the Trace algorithm to traverse the tracking keys in the repository and match them with the randomized public key of the user to be tracked. The user whose match passes is the required tracked user, realizing quick tracking of anonymous users; Quick revocation of users in the present invention: If a user needs to be revoked, the authoritative institution can execute the Revoke algorithm to remove the user's public key from the repository and add the corresponding tracking key to the blacklist, realizing quick revocation of users.
[0087] Embodiment 1
[0088] A traceable revocation anonymous credential method for a restricted device, referring to Figure 1 , includes:
[0089] S100, the system generates global parameters and sends them to the authoritative institution, the credential-issuing institution, the user, and the service provider;
[0090] S200, the credential-issuing institution and the user generate corresponding public and private keys according to the global parameters;
[0091] S300, the user sends the public key and the tracking key to the authoritative institution for registration;
[0092] S400, the credential-issuing institution generates a credential according to the user's public key and attributes;
[0093] S500, the service provider returns service permissions to the user according to the user's registration status, user attributes, and user credentials;
[0094] S600, the authoritative institution tracks the user's identity public key
[0095] S700, the authoritative institution revokes the user's identity public key.
[0096] The present invention proposes a traceable revocation anonymous credential scheme and system for restricted devices. Based on the core / auxiliary device anonymous credential scheme, an authoritative institution is introduced and registration, tracking, and revocation functions are added. The user generates an identity public key and a tracking key, and needs to provide them to the authoritative institution before obtaining the credential to complete the registration, realizing the unified management of user identities. The authoritative institution establishes a blacklist to store the information of revoked users. When obtaining and presenting the credential, both the credential-issuing institution and the service provider need to verify the user's registration status, and only support users who have been registered and not revoked. If the user violates the protocol, the authoritative institution executes the Trace algorithm to search and match the tracking key in the repository with the user's randomized public key to be tracked. Specifically, the successful matching tracking key is the tracked user, and the user identity is found according to the user public key-tracking key entry in the repository, realizing the rapid tracking of anonymous users. If a user needs to be revoked, the authoritative institution can execute the Revoke algorithm to remove the user's public key from the repository and add the corresponding tracking key to the blacklist, realizing the rapid revocation of the user. This scheme can support the restricted device scenario and achieve rapid tracking and millisecond-level revocation on the premise that the computational burden of the credential no longer changes with the number of attributes.
[0097] Preferably, S100, the system generates global parameters and sends them to the authoritative institution, the credential-issuing institution, the user, and the service provider, including:
[0098] The system executes the initialization algorithm Setup(1 λ )→pp: The algorithm inputs the security parameter 1 λ , generates a bilinear mapping group where the generator
[0099] Select a random number Calculate
[0100] Select three hash functions H: H1: H2:
[0101] The authoritative institution clears the repository DB and sets a public blank blacklist L as the revocation list;
[0102] Output the public parameters pp = (BG, H, H1, H2, Y1, Y2, L).
[0103] Preferably, in S200, the certificate-issuing agency and the user generate corresponding public and private keys based on the global parameters, including:
[0104] The certificate-issuing agency executes the key generation algorithm IKGen(1 λ , t, l) → (isk, ipk): Input the public parameter 1 λ , the number of attributes t, and the size l of the user's public key vector = 2, and select the key rk of the pseudo-random function PRF;
[0105] For each i ∈ [t], select Calculate
[0106] Let the private key Publish the public key
[0107] The user's core device executes the key generation algorithm CKGen(1 λ ) → (upk, ssk, utk, st pub ): Input the security parameter 1 λ , select a random number Calculate the user's identity public key Tracking key
[0108] Select another random number Calculate the auxiliary public parameter
[0109] Let the private key of the user's core device
[0110] Send upk, utk, and st pub To the user's auxiliary device.
[0111] Preferably, in S300, the user sends the public key and the tracking key to the authoritative agency for registration, including:
[0112] The user's core device and the user's auxiliary device run the interactive protocol The user's core device executes the CRegister algorithm, inputting the private key ssk; the user's auxiliary device executes the HRegister algorithm, inputting the user's public key upk, the tracking key utk, and the auxiliary public parameter st pub ;
[0113] Record upk = (upk1, upk2), run the zero-knowledge proof protocol Calculate the proof π and send it to the authoritative agency:
[0114] The user's core device selects a random number Calculate tempx = r x · k -1 and send it to the user auxiliary device;
[0115] The user auxiliary device calculates respectively c x = H(h1||h2||upk2||utk), and send c x to the user core device;
[0116] The user core device calculates s = r x + c x · x, and send s to the user auxiliary device;
[0117] The user auxiliary device constructs π = (h1, h2, c x , s);
[0118] The authority executes the user registration algorithm AuthRegister(UPK, upk, utk, π) → UPK′: Input the set of registered user public keys UPK, the user public key upk, the tracing key utk and the related proof π. The authority verifies the proof π by performing the following two steps:
[0119] Verify whether c x = H(h1||h2||upk2||utk) holds;
[0120] Verify whether and hold
[0121] If both steps of verification pass, update the set of registered user public keys UPK′ = UPK ∪ upk, add an entry upk - utk to the repository DB, and return 1 to the user auxiliary device to notify the successful registration; otherwise, directly return 0 to the user auxiliary device to notify the failed registration.
[0122] Preferably, in S400, the credential issuing agency generates a credential according to the user public key and attributes, including:
[0123] The user core device and the user auxiliary device run an interactive protocol The user core device executes the CObtain algorithm, and the user auxiliary device executes the HObtain algorithm, calculates the credential request areq and sends it to the credential issuing agency:
[0124] The user auxiliary device executes the attribute identifier generation algorithm AIDGen(Attr, nonce) → aid: Input the set of attributes Attr, select a random value nonce, generate the attribute identifier aid and send it to the user core device;
[0125] The user's core device selects a random number Calculate the preprocessing credential signature Where Send the preprocessing credential request apreq = (σ pIss , st pub ) to the user's auxiliary device;
[0126] The user's auxiliary device calculates Send the random value nonce and the credential request areq = (upk, σ Iss ) to the credential-issuing authority.
[0127] The credential-issuing authority executes the credential-issuing algorithm Issue(Attr, nonce, areq, isk) → cred: Input the attribute set Attr, the random value nonce, the credential request areq, and the private key isk:
[0128] Interact with the authoritative institution to check whether the public key set UPK of the registered users stores the public key upk. If it does not store, it means the user is not registered, and directly return credential issuance failure to the user;
[0129] Execute the AIDGen algorithm to generate the attribute identifier aid;
[0130] Verify the signature σIss: Denote σ Iss =(σ Iss1 , σ Iss2 , σ Iss3 ), upk = (upk1, upk2), and check whether the equations e(σ Iss2 , g2) = e(g1, σ Iss3 ) and e(σ Iss1 , g2) = e(upk2, Y2)·e(H1(aid), σ Iss3 ) hold. If any equation does not hold, directly return credential issuance failure to the user;
[0131] For each i ∈ [n], obtain the corresponding attribute private key Denote the value of the corresponding attribute Attr i as The seed string = upk, use the PRF function key rk and the seed string to calculate y ← PRF(rk, upk), and calculate Denote Return the credential to the user;
[0132] After receiving the credential, the user's auxiliary device verifies the credential Perform verification for each Check the equation to see if it holds;
[0133] If all hold, then check if the equation e(Y 1,1 , g2) = e(g1, Y 2,1 ) holds. If it holds, the user auxiliary device stores the credential.
[0134] Preferably, in S500, the service provider returns service permissions to the user based on the user registration situation, user attributes, and user credentials, including:
[0135] The user core device and the user auxiliary device run an interactive protocol nonce, ipk, cred) → ashow: The user core device executes the CShow algorithm, and the user auxiliary device executes the HShow algorithm to calculate the credential display ashow and send it to the service provider:
[0136] The user auxiliary device executes the attribute identifier generation algorithm AIDGen(Attr, nonce) → aid: Input the set of attributes Attr required by the service provider access policy, select a random value nonce, generate the attribute identifier aid and send it to the user core device;
[0137] The user core device selects a random number Calculate the pre - processed credential display Send the pre - processed credential request apshow = (σ pS , st pub ) to the user auxiliary device;
[0138] The user auxiliary device calculates where Denote the index set D of the attributes shown, the signature corresponding to the attribute Attr j Calculate the aggregated signature σ =(Z1, Y1, Y2, V2)=(∏ Attr Z j∈D Z 1,j , Y 1,1 , Y 2,1 ,∏ j∈D V 2,j ), select a random number and a random number Calculate the randomized public key and the randomized signature Select another random number Calculate the randomized credential Show the random value nonce and the credential ashow = (upk′, σ′ S , σ′ Attr ) and send them to the service provider.
[0139] The service provider executes the verification algorithm Verify(L, Attr, nonce, ipk, ashow) → 0 / 1: Given the blacklist attribute L, the set Attr, the random value nonce, the public key ipk of the issuing authority, and the credential show ashow, the service provider sequentially performs the following steps:
[0140] The service provider queries the blacklist L provided by the authoritative institution and sequentially pairs upk′ with the tracing keys on L: Suppose L = (utk1, utk2, …, utk num ), and denote upk′ = (upk′1, upk′2). For each i ∈ [num], the service provider sequentially calculates whether the equation e(upk′1, utk i ) = e(upk′2, g2) holds. If any of the equations holds, it means the user has been revoked, and directly return an application failure to the user;
[0141] The service provider checks whether the attribute set Attr satisfies the access policy. If it does not satisfy the access policy, directly return an application failure to the user;
[0142] The service provider verifies the signature σ′ S : Denote σ′ S = (σ′ S1 , σ′ S2 , σ′ S3 ), and check whether the equations e(σ′ S2 , g2) = e(g1, σ′ S3 ) and e(σ′ S1 , g2) = e(upk′2, Y2)·e(H1(aid), σ′ S3 ) hold. If any of the equations does not hold, directly return an application failure to the user;
[0143] The service provider verifies the signature σ′ Attr : Denote σ′ Attr = (Z′1, Y′1, Y′2, V′2), and check whether the equations e(Y′1, g2) = e(g1, Y′2), e(g1, V′2) = E hold;
[0144] If any of the equations does not hold, directly return an application failure to the user. Otherwise, provide the corresponding access permission to the user.
[0145] Preferably, for S600, the identity public key of the user tracked by the authority includes:
[0146] The authority executes the tracking algorithm Trace(upk′, utk) → upk: Pair the randomized public key upk′ of the user to be tracked with the tracking key utk of the entry in the repository DB in sequence;
[0147] Assume DB = {(upk1 - utk1), (upk2 - utk2), …, (upk num -utk num )}, and denote upk′ = (upk′1, upk′2);
[0148] For each i ∈ [num], calculate in sequence whether the equation e(upk′1, utk i ) = e(upk′2, g2) holds. The tracking key utk i corresponding to the entry whose upk i is the actual identity public key of the user to be tracked;
[0149] Preferably, for S700, the revocation of the identity public key of the user by the authority includes:
[0150] The authority executes the algorithm Revoke(upk, UPK, L) → (UPK′, L′): Find the entry upk - utk corresponding to upk in the repository DB and delete it. Remove upk from the set of registered user public keys UPK′ = UPK \ upk, and add the tracking key utk to the blacklist L′ = L ∪ utk.
[0151] Embodiment 2
[0152] A traceable revocation anonymous credential system for restricted devices, referring to Figure 2 , includes:
[0153] A parameter generation module, used for the system to generate global parameters and send them to the authority, the credential issuer, the user, and the service provider;
[0154] A key generation module, used for the credential issuer and the user to generate corresponding public and private keys according to the global parameters;
[0155] A registration module, used for the user to send the public key and the tracking key to the authority for registration;
[0156] A credential generation module, used for the credential issuer to generate credentials according to the user's public key and attributes;
[0157] A verification module, used for the service provider to return service permissions to the user according to the user's registration status, user attributes, and user credentials;
[0158] A tracing module for an authoritative agency to trace the identity public key of a user;
[0159] A revocation module for an authoritative agency to revoke the identity public key of a user.
[0160] The system of the present invention includes an authoritative agency, an issuing agency, a user, and a service provider. The user includes a user auxiliary device, a mobile phone, and a user core device, a SIM card. First, the system executes an initialization Setup algorithm to generate global parameters and share them with the above four entities. The issuing agency and the SIM card respectively call the IKGen and CKGen algorithms to generate their respective public and private keys. The CKGen algorithm also generates a tracing key and some other auxiliary parameters. The public key generated by CKGen is used as the user identity. The user needs to provide the identity public key and the tracing key to the authoritative agency to complete registration. The SIM card and the mobile phone execute the CRegister and HRegister interaction protocols to generate relevant proofs π, which, together with the identity public key and the tracing key, are used as a registration request. The authoritative agency initially establishes a blacklist to store revoked user information, calls the AuthRegister algorithm to verify π, and stores the user public key - tracing key to complete user registration. In the issuing phase, the SIM card and the mobile phone execute the CObtain and HObtain interaction protocols to generate a credential acquisition request areq. The issuing agency calls the Issue algorithm to verify the user registration status and the credential request. After verification, it signs the user public key and attributes to generate a credential cred, which the user receives and stores on the mobile phone. In the credential presentation and verification phase, the SIM card and the mobile phone execute the CShow and HShow interaction protocols to generate a credential presentation request a show. The service provider calls the Verify algorithm to verify the user registration status, whether the user attributes meet the access policy, and whether the user has the corresponding legal credential. If the verification passes, the service provider returns service permissions to the user. If the user violates the relevant protocol, the authoritative agency executes the Trace algorithm to match the tracing key in the repository with the randomized user public key to be traced, find the tracing key that makes the equation hold, and the corresponding user public key - tracing key is the user identity. If a user needs to be revoked, the authoritative agency executes the Revoke algorithm to delete its user public key - tracing key and add the tracing key to the blacklist.
[0161] Unified management of user identities in the present invention: An authoritative institution is introduced to register users, achieving unified management of user identities; Quick tracing of anonymous users in the present invention: When a user registers with the authoritative institution, a tracing key needs to be provided. If the user violates the agreement, the authoritative institution can execute the Trace algorithm to traverse the tracing keys in the repository and match them with the randomized public key of the user to be traced. The user whose match passes is the required traced user, realizing quick tracing of anonymous users; Quick revocation of users in the present invention: If a user needs to be revoked, the authoritative institution can execute the Revoke algorithm to remove the user's public key from the repository and add the corresponding tracing key to the blacklist, realizing quick revocation of users.
[0162] The above are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features claimed herein.
Claims
1. A traceable revocation anonymous credential method for a restricted device, characterized in that, including: The system generates global parameters and sends them to the authority, the credential issuer, the user, and the service provider; The credential issuer and the user generate corresponding public and private keys according to the global parameters; The user sends the public key and the tracing key to the authority for registration; The credential issuer generates a credential based on the user's public key and attributes; The service provider returns service permissions to the user based on the user's registration status, user attributes, and user credentials; The authority traces the user's identity public key; The authority revokes the user's identity public key.
2. The traceable revocation anonymous credential method for a restricted device according to claim 1, wherein The system generates global parameters and sends them to the authority, the credential issuer, the user, and the service provider includes: The system executes the initialization algorithm Setup(1 λ ) → pp: The algorithm inputs the security parameter 1 λ , and generates a bilinear mapping group where the generator Select a random number Calculate Select three hash functions The authority clears the repository DB and sets a public blank blacklist L as the revocation list; Output the public parameters pp = (BG, H, H1, H2, Y1, Y2, L).
3. The traceable revocation anonymous credential method for a restricted device according to claim 1, characterized in that, The credential issuer and the user generate corresponding public and private keys according to the global parameters includes: The issuing authority executes the key generation algorithm IKGen(1 λ , t, l) → (isk, ipk): Given the public parameter 1λ, the number of attributes t, and the size of the user public key vector l = 2, select the key rk of the pseudorandom function PRF; For each \(i\in[t]\), select Calculate Let the private key Reveal the public key The user's core device executes the key generation algorithm CKGen(1 λ )→(upk, ssk, utk, st pub ):Input the security parameter 1 λ , select a random number Calculate the user identity public key Trace key Select another random number Calculate the auxiliary public parameter Let the user's core device private key Send upk, utk, and st pub to the user assistance device.
4. The traceable revocation anonymous credential method for a restricted device according to claim 1, characterized in that, The user sends the public key and the tracing key to the authority for registration includes: The core user device and the auxiliary user device run an interaction protocol The core user device executes the CRegister algorithm and inputs the private key ssk; the auxiliary user device executes the HRegister algorithm and inputs the user public key upk, the tracing key utk, and the auxiliary public parameter st pub ; Let upk = (upk1, upk2), and run the zero - knowledge proof protocol Calculate the proof π and send it to the authority; The user's core device selects a random number Calculate temp x = r x ·k -1 And send it to the user's auxiliary device; The user assistance device calculates respectively c x = H(h1||h2||upk2||utk), and sends c x to the user core device; The user's core device calculates s = r x + c x · x and sends s to the user's auxiliary device; User assistance device configuration π=(h1,h2,c x ,s); The authority executes the user registration algorithm AuthRegister(UPK, upk, utk, π) → UPK': Input the set of registered user public keys UPK, the user's public key upk, the tracing key utk, and the related proof π. The authority performs the following two steps to verify the proof π: Verify c x = H(h1||h2||upk2||utk) holds; Verification and whether it holds; If both steps of the verification pass, then update the set of registered user public keys UPK' = UPK ∪ upk, add an entry upk-utk to the repository DB, and return 1 to the user auxiliary device to notify the registration success; otherwise, directly return 0 to the user auxiliary device to notify the registration failure.
5. The traceable revocation anonymous credential method for a restricted device according to claim 1, wherein The credential issuer generates a credential based on the user's public key and attributes includes: The user core device and the user auxiliary device run an interaction protocol The user core device executes the CObtain algorithm, and the user auxiliary device executes the HObtain algorithm to calculate the credential request areq and send it to the credential-issuing agency: The user auxiliary device executes the attribute identifier generation algorithm AIDGen(Attr, nonce) → aid: Input the set of attributes Attr, select a random value nonce, generate the attribute identifier aid and send it to the user core device; The user's core device selects a random number Calculate the preprocessing credential signature Where Send the preprocessing credential request apreq = (σ pIss , st pub ) to the user's auxiliary device; User-assisted device calculation Send the random value nonce and the credential request areq=(upk,σ Iss ) to the issuing authority.
6. The traceable revocation anonymous credential method for a restricted device according to claim 5, characterized in that, The credential issuer generates a credential based on the user's public key and attributes includes: The credential issuer executes the credential issuance algorithm Issue(Attr, nonce, areq, isk) → cred: Input the set of attributes Attr, the random value nonce, the credential request areq, and the private key isk: Interact with the authority to check whether the set of registered user public keys UPK stores the public key upk. If it does not store it, it means the user is not registered, and directly return the credential issuance failure to the user; Execute the AIDGen algorithm to generate the attribute identifier aid; Verify the signature σ Iss : Denote σ Iss =(σ Iss1 , σ Iss2 , σ Iss3 ), upk = (upk1, upk2), and check whether the equations e(σ Iss2 , g2) = e(g1, σ Iss3 ) and e(σ Iss1 , g2) = e(upk2, Y2) · e(H1(aid), σ Iss3 ) hold. If any of the equations does not hold, directly return the certificate issuance failure to the user; For each \(i\in[n]\), obtain the corresponding attribute private key Denote the corresponding attribute as Attr i The value of The seed string = upk. Use the PRF function key rk and the seed string to calculate \(y\leftarrow PRF(rk,upk)\), and calculate Denote Return the credential to the user; After receiving the voucher, the user assistance device verifies the voucher and checks, for each whether the equation holds; If all hold, then check the equation e(Y 1,1 , g2) = e(g1, Y 2,1 ) to see if it holds. If it holds, the user auxiliary device stores the credential.
7. The traceable revocation anonymous credential method for a restricted device according to claim 6, characterized in that, The credential issuer generates a credential based on the user's public key and attributes includes: The user's core device and the user's auxiliary device run an interaction protocol The user's core device executes the CShow algorithm, and the user's auxiliary device executes the HShow algorithm to calculate the proof of presentation ashow and send it to the service provider: The user auxiliary device executes the attribute identifier generation algorithm AIDGen(Attr, nonce) → aid: Input the set of attributes Attr required by the service provider access policy, select a random value nonce, generate the attribute identifier aid and send it to the user core device; The user's core device selects a random number Calculate and display the preprocessing voucher Send the preprocessing voucher request apshow=(σ pS , st pub ) to the user's auxiliary device; User-assisted device calculation Where Denote the index set D of the presented attributes, the attribute Attr j The corresponding signature Calculate the aggregated signature σ Attr =(Z1, Y1, Y2, V2)=(∏ j∈D Z 1,j , Y 1,1 , Y 2,1 , ∏ j∈D V 2,j ), select a random number And a random number Calculate the randomized public key And the randomized signature Select another random number Calculate the randomized credential Send the random value nonce and the credential show = (upk′, σ′ S , σ′ Attr ) to the service provider.
8. The traceable revocation anonymous credential method for a restricted device according to claim 6, characterized in that, The service provider returns service permissions to the user based on the user's registration status, user attributes, and user credentials includes: The service provider executes the verification algorithm Verify(L, Attr, nonce, ipk, ashow) → 0 / 1: Given the blacklist attribute L, the set Attr, the nonce, the public key ipk of the issuing authority, and the credential show ashow, the service provider sequentially performs the following steps: The service provider queries the blacklist L provided by the authoritative institution and pairs the upk' with the tracing keys on L in sequence: Assume L = (utk1, utk2, …, utk num ), let upk' = (upk'1, upk'2), for each i ∈ [num], the service provider calculates the equation e(upk'1, utk i ) = e(upk'2, g2) in sequence. If any of the equations holds, it means that the user has been revoked, and the service provider directly returns an application failure to the user; The service provider checks whether the attribute set Attr satisfies the access policy. If it does not satisfy the access policy, it directly returns an application failure to the user. The service provider verifies the signature σ′ S : Denote σ′ S =(σ′ S1 , σ′ S2 , σ′ S3 ), and check whether the equations e(σ′ S2 , g2)=e(g1, σ′ S3 ) and e(σ′ S1 , g2)=e(upk′2, Y2)·e(H1(aid), σ′ S3 ) hold. If any of the equations does not hold, directly return an application failure to the user; The service provider verifies the signature σ′ Attr : Denote σ′ Attr =(Z′1,Y′1,Y′2,V′2), and check whether the equation e(Y′1,g2)=e(g1,Y′2), holds; If any equation does not hold, it directly returns an application failure to the user. Otherwise, it provides the corresponding access permission to the user.
9. The traceable revocation anonymous credential method for a restricted device according to claim 1, wherein The authoritative institution tracks the user's identity public key and revokes the user's identity public key, including: The authoritative institution executes the tracking algorithm Trace(upk′, utk) → upk: Pair the randomized public key upk′ of the user to be tracked with the tracking key utk of the entry in the repository DB in sequence. Suppose DB = { (upk1 - utk1), (upk2 - utk2), …, (upk num - utk num )}, and let upk′ = (upk′1, upk′2); For each \(i\in[\text{num}]\), sequentially calculate whether the equation \(e(\text{upk}'_1,\text{utk} i ) = e(\text{upk}'_2,g_2)\) holds. The tracing key \(\text{utk} i corresponding to the entry i is the actual identity public key of the user to be traced; Upon revocation, the authoritative institution executes the algorithm Revoke(upk, UPK, L) → (UPK′, L′): Find the entry upk - utk corresponding to upk in the repository DB and delete it. Remove upk from the set of registered user public keys UPK′ = UPK\upk, and add the tracking key utk to the blacklist L′ = L ∪ utk.
10. A traceable revocation anonymous credential system for a restricted device, characterized in that, Including: The parameter generation module is used for the system to generate global parameters and send them to the authoritative institution, the issuing authority, the user, and the service provider. The key generation module is used for the issuing authority and the user to generate corresponding public and private keys according to the global parameters. The registration module is used for the user to send the public key and the tracking key to the authoritative institution for registration. The credential generation module is used for the issuing authority to generate credentials according to the user's public key and attributes. The verification module is used for the service provider to return service permissions to the user according to the user's registration status, user attributes, and user credentials. The tracking module is used for the authoritative institution to track the user's identity public key. The revocation module is used for the authoritative institution to revoke the user's identity public key.