A Metaverse Avatar Identity Authentication Method

By adopting the avatar identity authentication method in the metaverse, using fuzzy extractor and blockchain technology to encrypt user biological information, realizing avatar identity authentication and key negotiation, the problems of disguised attacks and privacy leakage are solved, and the security and credibility of the metaverse are improved.

CN120358097BActive Publication Date: 2025-08-15NANJING UNIV OF INFORMATION SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510847098.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-08-15
Estimated Expiration
2045-06-24

AI Technical Summary

Technical Problem

In the metaverse, disguised attacks and user privacy leaks threaten the user's security and trust basis, and existing technologies are difficult to improve security and credibility while ensuring an immersive experience.

Method used

The secure identity authentication method based on user avatar is adopted, and biological information is encrypted using a fuzzy extractor, user avatar data is stored in combination with the blockchain, and interactive information is encrypted through the session key to realize avatar identity authentication and key negotiation.

Benefits of technology

Ensure user privacy and significantly improve the security and credibility of the metaverse, prevent fraud and disguise, provide all-round protection, and enhance the security of users' activities in the virtual world.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358097B_ABST
    Figure CN120358097B_ABST
Patent Text Reader

Abstract

This invention discloses a metaverse avatar identity authentication method, belonging to the field of identity authentication technology. The method comprises: obtaining user and scenario server login results based on acquired user login information and information obtained when the user registered with the scenario server; and after the user successfully logs in to the scenario server, performing metaverse avatar identity authentication when the current user interacts with other users through a first-image-based secure identity authentication mechanism. This invention ensures user privacy while maintaining an immersive user experience, significantly enhancing the security and credibility of the metaverse. This first-image-based secure identity authentication mechanism effectively enhances user anti-fraud and anti-spoofing capabilities, providing comprehensive protection for user activities in the virtual world.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of identity authentication technology, and in particular to a metaverse avatar identity authentication method. Background Art

[0002] With the rapid development of technology and the acceleration of digitalization, the metaverse has become a new digital economic ecosystem, providing users with highly immersive experiences across diverse sectors, including social interaction, healthcare, entertainment, education, and commerce. Within the metaverse, users can create their own digital characters—avatars. These avatars can be exotic animals, human-like models, or even completely unique creative images. They serve not only as a user's identity within the virtual world but also as a medium for interaction with others.

[0003] Despite the immersive services provided by the Metaverse, impersonation attacks remain a potential threat. Attackers could impersonate someone else's avatar to defraud other users and steal their private information. Furthermore, because users communicate with the Metaverse's scenario servers through public channels, they are vulnerable to various external security threats, such as the leakage of personal information such as user habits and transaction records. These threats could not only endanger user privacy and security but also undermine the trust foundation of the Metaverse, hindering its healthy development. Therefore, how to ensure user privacy and the security and trustworthiness of the Metaverse while preserving user experience has become a pressing issue. Summary of the Invention

[0004] The purpose of the present invention is to overcome the deficiencies in the prior art and provide a metaverse avatar identity authentication method that can ensure user privacy while ensuring an immersive user experience and significantly improve the security and credibility of the metaverse.

[0005] To achieve the above object, the present invention is implemented by adopting the following technical solutions:

[0006] The present invention provides a metaverse avatar identity authentication method, comprising:

[0007] According to the acquired user login information and the information when the user registered with the scene server, the login results of the user and the scene server are obtained;

[0008] If the login result of the user and the scene server is a login failure, the identity authentication is stopped; if the login result of the user and the scene server is successful, when the current user interacts with other users, the current user sends an interaction notification to the scene server and sends a first interaction request to other users;

[0009] After receiving the first interaction request, the scene server encrypts the first image and secret value of the other user using the session key with the current user, generates the current communication ciphertext, and sends it to the current user; encrypts the first image and secret value of the current user using the session key with the other user, generates the other communication ciphertext, and sends it to the other user;

[0010] After receiving the first interaction request and other communication ciphertext, the other user sends a second interaction request to the current user;

[0011] After receiving the current communication ciphertext and the second interaction request, the current user decrypts the current communication ciphertext to obtain the current decryption result, calculates the current user authentication information based on the second interaction request and the current decryption result, and sends the current user authentication information to the other user;

[0012] After receiving the current user's authentication information, the other users decrypt the other communication ciphertexts to obtain other decryption results, obtain other user response information based on the current user's authentication information and other decryption results, and send the other user response information to the current user;

[0013] After receiving the response information of other users, the current user calculates the user identity information according to the response information of other users, and obtains the user avatar identity authentication result according to the user identity information.

[0014] Optionally, also include:

[0015] Scene Server Constructing identity authentication system parameters ;in, represents a non-singular finite field; Represents large prime numbers; Represents a cyclic additive group The prime order of Represents a nonsingular finite field The cyclic additive group consisting of the set of all integer points of the elliptic curve on ; Represents a cyclic additive group Generators of Indicates the identity of the scene server; Represents a one-way hash function.

[0016] Optionally, obtaining information when a user registers with a scene server includes:

[0017] Current User Smart devices connecting the Metaverse Enter the current user account , Current user password and the current user's biometric information ; Select a random number as the first secret value and the current user's private key , current user Using smart devices The fuzzy extractor in the first secret value and the current user's private key , for the current user's biometric information Perform encryption processing to generate the current user encrypted value and the current user auxiliary parameters ; Based on the current user account , Current user encrypted value , the first secret value , Current user private key , calculate the current user pseudo identity , current user public key , current user avatar ; The current user will register his own information Send to scene server ;

[0018] Scene Server Receive the current user's registration information Afterwards, check Existence and uniqueness in its database and blockchain; if If only one exists, the registration process is terminated. Otherwise, the scene server Capture the appearance characteristics of the current user's avatar ; Scene Server Select random numbers as the second secret value , the third secret value , based on the current user avatar , the appearance characteristics of the current user avatar , the second secret value , the third secret value , calculate the current registration identifier , first ciphertext , the first image of the current user's avatar , first communication ciphertext ; Scene Server Will Stored in its database, Upload to the blockchain and send the first communication ciphertext Send to current user ;

[0019] Current User Receive the first communication ciphertext Then, use the current user's private key Decrypt the first communication ciphertext , get the first decrypted ciphertext ; According to the first decrypted ciphertext , calculate the first current user ciphertext , Second current user ciphertext , Current user registration and login verification value ; The information when the user registers with the scene server Store on smart device in the database; among them, Represents a cyclic additive group Generators of Represents a one-way hash function; Indicates the identity of the scene server; Indicates the private key of the scene server; Indicates encryption using the current user's public key; Indicates using the current user's private key for decryption; Represents the exclusive OR operation;

[0020] The same applies to other users To the scene server Information provided during registration.

[0021] Optionally, based on the acquired user login information and the information when the user registered with the scenario server, the login results of the user and the scenario server are obtained, including:

[0022] Current User Smart devices connected to the Metaverse Enter the current user account , Current user password and the current user's biometric information ; Current user Using smart devices The fuzzy extractor in the current user encrypted value verification value is calculated , Current registration identifier verification value , first ciphertext verification value , Current user login verification value ; Current user verify Is it true? If not, the login process is terminated. If it is true, the login verification is successful. After the login is successful, the current user Select a random number as the fourth secret value , and generate the first timestamp ; According to the fourth secret value and the first timestamp , calculate the first communication summary , Second Communication Summary ; Current user First login information Send to scene server ;

[0023] Scene Server Upon receiving the current user First login information After that, generate the second timestamp , and check Is it true? If not, discard the first login information ; Otherwise, calculate the first update value , second communication digest verification value ;verify Is it true? If not, the scene server For the current user Login failed; if established, the scene server For the current user Login successful, scene server Choose a random number as the fifth secret value , according to the fifth secret value , calculate the second ciphertext , Summary of the Third Communication , current user With scene server The session key between , Summary of the Fourth Communication ; Scene Server Second login information Send to current user ;in, Indicates the preset timestamp difference;

[0024] Current User Received second login information After that, generate the third timestamp , and verify Is it true? If not, discard the second login information ; Otherwise, calculate the second update value , current user and scene server The session key verification value between , the fourth communication digest verification value ;verify Is it true? If the equation is not true, then the current user For scene servers Login failed, otherwise, the current user For scene servers Login successful, current user With scene server Successfully completed identity authentication and key negotiation; Indicates the current user avatar verification value; represents the fourth secret numerical verification value; Represents the second ciphertext verification value; represents the fifth secret numerical verification value;

[0025] The same applies to other users and scene server Login result.

[0026] Optionally, the current user sends an interaction notification to the scene server and sends a first interaction request to other users, including:

[0027] Current User To the scene server Send interactive notification to the current user Capture other user avatars Appearance feature verification value ; Current user To other users Send the first interaction request ;in, Indicates the current user's pseudo identity; Represents the current user avatar.

[0028] Optionally, after receiving the first interaction request, the scene server encrypts the first image and secret value of the other user using the session key with the current user to generate current communication ciphertext and sends it to the current user; and encrypts the first image and secret value of the current user using the session key with the other user to generate other communication ciphertext and sends it to the other user, including:

[0029] Scene Server Receive the current user After the interaction notification, use other users With scene server The session key between , for the current user The first image and the third secret value Encrypt and generate the third communication ciphertext ; Use current user With scene server The session key between , to other users The first image and the third secret value Encrypt to generate the fourth communication ciphertext ; Scene Server The third communication ciphertext Send to other users , the fourth communication ciphertext Send to current user ; Among them, the fourth communication ciphertext is the current communication ciphertext, the third communication ciphertext For other communication ciphertexts, Indicates encryption using the session key between other users and the scene server; Indicates encryption using the session key between the current user and the scene server.

[0030] Optionally, after receiving the first interaction request and the other communication ciphertext, the other user sends a second interaction request to the current user, including:

[0031] Other users Receive the current user The first interaction request sent to the scene server After sending other communication ciphertext, capture the current user avatar Appearance feature verification value ; The second interactive information Send to current user ;in, Indicates other users’ pseudo identities; Represents other user avatars.

[0032] Optionally, after receiving the current communication ciphertext and the second interaction request, the current user decrypts the current communication ciphertext to obtain a current decryption result, calculates current user authentication information based on the second interaction request and the current decryption result, and sends the current user authentication information to the other user, including:

[0033] Current User Received from other users The second interactive request sent to the scene server After sending the current communication ciphertext, use other users Fake identity As an index, retrieve other users' public keys from the blockchain , select a random number as the sixth secret value , generating the fourth timestamp ;

[0034] Use with scene server The session key between For the fourth communication ciphertext Decrypt and get the current decryption result ;

[0035] Calculate the first image verification value of the current user avatar based on the second interaction request and the current decryption result 、The fifth ciphertext 、The sixth ciphertext , Summary of the Fifth Communication , the current user authentication information Send to other users ;in, Indicates other users The first image of represents the third secret value; Represents the current user avatar Verification value of appearance features; Represents a cyclic additive group Generators of Represents other users' public keys; Represents other user avatars; Indicates that the session key between the current user and the scene server is used for decryption; Represents a one-way hash function.

[0036] Optionally, after receiving the current user authentication information, the other user decrypts the other communication ciphertext to obtain other decryption results, obtains other user response information based on the current user authentication information and other decryption results, and sends the other user response information to the current user, including:

[0037] Other users Receive the current user After sending the current user authentication information, generate the fifth timestamp , and check Is it true? If not, discard the current user authentication information; otherwise, use the scene server The session key between For the third communication ciphertext Decrypt and get other decryption results ;

[0038] Calculate the sixth ciphertext verification value based on the current user authentication information and other decryption results and the fifth communication digest verification value , and verify Is it true? If not, then other users For the current user Identity authentication failed. If successful, other users For the current user Identity authentication is successful;

[0039] Using the current user Fake identity As an index, retrieve the current user's public key from the blockchain , select a random number as the seventh secret value ;

[0040] Based on the current user's public key and the seventh secret value , calculate the first image verification value of other user avatars 、The seventh ciphertext 、The eighth ciphertext , current user With other users The session key between , Sixth Communication Summary , other users' response information Send to current user ;in, Indicates the fourth timestamp; Indicates the preset timestamp difference; Indicates the first image of the current user; represents the third secret value; Indicates that the session key between other users and the scene server is used for decryption; Indicates the fifth ciphertext; Represents other users’ private keys; represents a fifth communication summary; Represents other user avatars; Represents the appearance feature verification value of other user avatars; Represents a cyclic additive group Generators of Indicates the sixth ciphertext; Represents the current user avatar; Represents a one-way hash function.

[0041] Optionally, after receiving the response information from the other user, the current user calculates the user identity information based on the response information from the other user, and obtains the user avatar identity authentication result based on the user identity information, including:

[0042] Current User Received from other users After sending other user response information, generate the sixth timestamp , and check Is it true? If not, discard the other user response information; otherwise, calculate the eighth ciphertext verification value based on the other user response information. , current user With other users The session key verification value between , the sixth communication digest verification value ;

[0043] verify Is it true? If not, the current user To other users Avatar identity authentication failed. If successful, the current user To other users The avatar identity authentication is successful; among them, Indicates the fifth timestamp; Indicates the preset timestamp difference; Indicates the seventh ciphertext; Indicates the current user's private key; Indicates the sixth ciphertext; Current user avatar; Indicates the first image of other users; represents a sixth communication summary; Represents a one-way hash function.

[0044] Compared with the prior art, the present invention has the following beneficial effects:

[0045] 1. This invention can ensure user privacy while guaranteeing an immersive user experience, and significantly enhance the security and credibility of the metaverse. Through a secure identity authentication mechanism based on the first image, it can effectively enhance the user's anti-fraud and anti-impersonation capabilities, providing comprehensive protection for users' activities in the virtual world. The immutability of the first image allows users to be confident that the virtual avatar they see is real and unique, and not tampered with or impersonated by others. This trust mechanism is extremely critical for social interaction, economic transactions, and data sharing in the metaverse.

[0046] 2. In order to prevent login information leakage, this invention introduces fuzzy extractor technology, which is specifically used to protect the user's biometric information. At the same time, blockchain technology is used to store user avatar data in preparation for subsequent identity authentication. With its decentralized and tamper-proof characteristics, it prevents data from being maliciously tampered with, enhances privacy protection, and improves the security of identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 FIG2 is a flow chart of an embodiment of a method for authenticating a metaverse avatar identity according to the present invention;

[0048] Figure 2 Shown is a schematic structural diagram of the metaverse avatar identity authentication system in one embodiment of the present invention. DETAILED DESCRIPTION

[0049] The technical solution of the present invention is described in detail below through the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solution of the present invention, rather than limitations on the technical solution of the present invention. In the absence of conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.

[0050] The term "and / or" simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, or B exists alone. Additionally, the character " / " generally indicates an "or" relationship between the related objects.

[0051] Example 1

[0052] like Figure 1 As shown, this embodiment introduces a method for authenticating a Metaverse avatar identity, including the following steps:

[0053] Step 1: System initialization, specifically:

[0054] Scene Server Constructing identity authentication system parameters ;in, represents a non-singular finite field; Represents large prime numbers; Represents a cyclic additive group The prime order of Represents a nonsingular finite field The cyclic additive group consisting of the set of all integer points of the elliptic curve on ; Represents a cyclic additive group Generators of Indicates the identity of the scene server; Represents a one-way hash function.

[0055] Step 2: User registration, specifically:

[0056] In the virtual world of the Metaverse, if users want to immersively experience various services, they must first use smart devices, such as head-mounted displays or virtual reality glasses, to connect to the scene server and complete registration. After successful registration, the user becomes a legitimate user and can enjoy the immersive service experience brought by the Metaverse, namely:

[0057] Current User Smart devices connecting the Metaverse Enter the current user account , Current user password and the current user's biometric information ; Select a random number as the first secret value and the current user's private key , current user Using smart devices The fuzzy extractor in the first secret value and the current user's private key , for the current user's biometric information Perform encryption processing to generate the current user encrypted value and the current user auxiliary parameters ; Based on the current user account , Current user encrypted value , the first secret value , Current user private key , calculate the current user pseudo identity , current user public key , current user avatar ; The current user will register his own information Sent to the scene server via a secure channel ;in, Represents a cyclic additive group The prime order of The multiplicative group of integers contains all integers less than And with mutually prime positive integers;

[0058] Scene Server Receive the current user's registration information Afterwards, check Existence and uniqueness in its database and blockchain; if If only one exists, the registration process is terminated. Otherwise, the scene server Capture the appearance characteristics of the current user's avatar ; Scene Server Select random numbers as the second secret value , the third secret value , based on the current user avatar , the appearance characteristics of the current user avatar , the second secret value , the third secret value , calculate the current registration identifier , first ciphertext , the first image of the current user's avatar , first communication ciphertext ; Scene Server Will Stored in its database, Upload to the blockchain and send the first communication ciphertext Send to current user ;in, Indicates the private key of the scene server; Indicates encryption using the current user's public key;

[0059] Current User Receive the first communication ciphertext Then, use the current user's private key Decrypt the first communication ciphertext , get the first decrypted ciphertext ; According to the first decrypted ciphertext , calculate the first current user ciphertext , Second current user ciphertext , Current user registration and login verification value ; The information when the user registers with the scene server Store on smart device in the database; among them, Indicates using the current user's private key for decryption; Represents the exclusive OR operation.

[0060] The same applies to other users To the scene server The information provided during registration will not be repeated here.

[0061] Step 3: User login and identity authentication, specifically:

[0062] Before users can access Metaverse services, they must first log in. Users must enter their login account, password, and biometric information on a Metaverse-connected smart device. Based on this information, the system calculates a user login verification value and compares it with the user's registered login verification value stored on the smart device. If the two match, login is successful; otherwise, login fails, and the entire process terminates. After successful login, the user sends an authentication request to the scenario server, which contains their authentication information and avatar information. Upon receiving the request, the scenario server first checks whether the timestamp is valid. If not, the request is discarded. If valid, it further verifies whether the authentication information matches the information submitted by the user. If successful, the scenario server successfully authenticates the user, confirming that the requesting user is legitimate. The scenario server then generates a session key with the user and sends it to the user along with its own authentication information. Upon receiving the response, the user also verifies the timestamp. After successful verification, the user calculates a session key with the scenario server and verifies whether the message digest matches the information submitted. If the verification is successful, it means that the user has successfully authenticated the scene server, and the identity authentication and key negotiation process of both parties is completed.

[0063] That is: the current user Smart devices connected to the Metaverse Enter the current user account , Current user password and the current user's biometric information ; Current user Using smart devices The fuzzy extractor in the current user encrypted value verification value is calculated , Current registration identifier verification value , first ciphertext verification value , Current user login verification value ; Current user verify Is it true? If not, the login process is terminated. If it is true, the login verification is successful. After the login is successful, the current user Select a random number as the fourth secret value , and generate the first timestamp ; According to the fourth secret value and the first timestamp , calculate the first communication summary , Second Communication Summary ; Current user First login information Send to scene server ;

[0064] Scene Server Upon receiving the current user First login information After that, generate the second timestamp , and check Is it true? If not, discard the first login information , the program terminates immediately; otherwise, calculate the first update value , second communication digest verification value ;verify Is it true? If not, the scene server For the current user Login failed; if established, the scene server For the current user Login successful, scene server Choose a random number as the fifth secret value , according to the fifth secret value , calculate the second ciphertext , Summary of the Third Communication , current user With scene server The session key between , Summary of the Fourth Communication ; Scene Server Second login information Send to current user ;in, Indicates the preset timestamp difference;

[0065] Current User Received second login information After that, generate the third timestamp , and verify Is it true? If not, discard the second login information ; Otherwise, calculate the second update value , current user and scene server The session key verification value between , the fourth communication digest verification value ;verify Is it true? If the equation is not true, then the current user For scene servers Login fails, terminate the entire process, otherwise, the current user For scene servers Login successful, current user With scene server After successful completion of identity authentication and key negotiation, both parties can communicate securely using the established session key. Indicates the current user avatar verification value; represents the fourth secret numerical verification value; Represents the second ciphertext verification value; Represents the fifth secret numerical verification value.

[0066] The same applies to other users and scene server The login results are not described here.

[0067] Step 4: Authentication between avatars, specifically:

[0068] Due to the existence of impersonation attacks in the Metaverse, attackers can impersonate other users' avatars to defraud them and steal their private information, such as personal transaction logs and habits. To ensure the security of interactions between avatars, we have implemented an authentication mechanism based on the immutability of the user's avatar's first image. This mechanism compares the first image recorded when the user's avatar registers with the scene server with the first image presented when interacting with other avatars to determine whether the avatar currently interacting is the real user, rather than an impersonator. This allows users to more confidently engage in social activities, transactions, and other activities in the virtual world, significantly enhancing the security and trustworthiness of the Metaverse.

[0069] That is: after the user successfully logs in to the scene server, the current user With other users When interacting, the current user To the scene server Send interactive notification to the current user Capture other user avatars Appearance feature verification value ; Current user To other users Send the first interaction request ;

[0070] Scene Server Receive the current user After the interaction notification, use other users With scene server The session key between , for the current user The first image and the third secret value Encrypt and generate the third communication ciphertext ; Use current user With scene server The session key between , to other users The first image and the third secret value Encrypt to generate the fourth communication ciphertext ; Scene Server The third communication ciphertext Send to other users , the fourth communication ciphertext Send to current user ; Among them, the fourth communication ciphertext is the current communication ciphertext, the third communication ciphertext For other communication ciphertexts, Indicates encryption using the session key between other users and the scene server; Indicates encryption using the session key between the current user and the scene server;

[0071] Other users Receive the current user The first interaction request sent to the scene server After sending other communication ciphertext, capture the current user avatar Appearance feature verification value ; The second interactive information Send to current user ;in, Indicates other users’ pseudo identities; Represents other user avatars;

[0072] Current User Received from other users The second interactive request sent to the scene server After sending the current communication ciphertext, use other users Fake identity As an index, retrieve other users' public keys from the blockchain , select a random number as the sixth secret value , generating the fourth timestamp ; Use with scene server The session key between For the fourth communication ciphertext Decrypt and get the current decryption result ; Calculate the first image verification value of the current user avatar based on the second interaction request and the current decryption result 、The fifth ciphertext 、The sixth ciphertext , Summary of the Fifth Communication , the current user authentication information Send to other users ;in, Indicates other users The first image of Represents other users' public keys; Indicates that the session key between the current user and the scene server is used for decryption;

[0073] Other users Receive the current user After sending the current user authentication information, generate the fifth timestamp , and check Is it true? If not, discard the current user authentication information; otherwise, use the scene server The session key between For the third communication ciphertext Decrypt and get other decryption results ; Calculate the sixth ciphertext verification value based on the current user authentication information and other decryption results and the fifth communication digest verification value , and verify Is it true? If not, then other users For the current user Identity authentication failed. If successful, other users For the current user Identity authentication is successful; use the current user Fake identity As an index, retrieve the current user's public key from the blockchain , select a random number as the seventh secret value ; Based on the current user public key and the seventh secret value , calculate the first image verification value of other user avatars 、The seventh ciphertext 、The eighth ciphertext , current user With other users The session key between , Sixth Communication Summary , other users' response information Send to current user ;in, Indicates that the session key between other users and the scene server is used for decryption; Represents other users’ private keys;

[0074] Current User Received from other users After sending other user response information, generate the sixth timestamp , and check Is it true? If not, discard the other user response information; otherwise, calculate the eighth ciphertext verification value based on the other user response information. , current user With other users The session key verification value between , the sixth communication digest verification value ;verify Is it true? If not, the current user To other users Avatar identity authentication failed. If successful, the current user To other users Once the avatar identity authentication is successful, both parties have completed identity authentication and key negotiation, laying the foundation for subsequent secure interactions.

[0075] This embodiment can ensure user privacy while guaranteeing an immersive user experience, and significantly improve the security and credibility of the metaverse. Through a secure identity authentication mechanism based on the first image, it can effectively enhance the user's anti-fraud and anti-impersonation capabilities, and provide all-round protection for the user's activities in the virtual world. The immutability of the first image allows users to be confident that the virtual avatar they see is real and unique, and not tampered with or impersonated by others.

[0076] Example 2

[0077] like Figure 2 As shown, this embodiment introduces a metaverse avatar identity authentication system, which consists of three core components: scene server, blockchain, and user, specifically including:

[0078] As the core hub of the system, the scene server is a trustworthy, secure and reliable entity that undertakes key tasks such as system initialization, user registration and recording the first image of the user avatar.

[0079] During the user registration process, the scene server will capture and record the first image of the user's avatar and store it in its own database. At the same time, the avatar's identity data will be uploaded and saved on the blockchain.

[0080] The introduction of blockchain aims to provide strong protection for user privacy and ensure the immutability of data, thereby providing a reliable basis for identity authentication between avatars.

[0081] As a core participant of the metaverse, users need to log in and authenticate after completing registration through the scene server. After successful login and authentication, users can immersively experience the rich services provided by the scene server. The use of the first image is a key mechanism to ensure secure avatar identity authentication and key negotiation between avatars, ensuring that the user's interaction process in the metaverse world is safe and reliable.

[0082] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0083] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0084] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0085] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0086] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the purpose of the present invention and the claims, which are all protected by the present invention.

Claims

1. A method for authenticating a metaverse avatar identity, characterized in that: include: According to the acquired user login information and the information when the user registered with the scene server, the login results of the user and the scene server are obtained; If the login result of the user and the scene server is a login failure, the identity authentication is stopped; If the login result of the user and the scene server is successful, when the current user interacts with other users, the current user sends an interaction notification to the scene server and sends a first interaction request to the other users; After receiving the first interaction request, the scene server encrypts the first image and secret value of the other user using the session key with the current user, generates the current communication ciphertext, and sends it to the current user; encrypts the first image and secret value of the current user using the session key with the other user, generates the other communication ciphertext, and sends it to the other user; After receiving the first interaction request and other communication ciphertext, the other user sends a second interaction request to the current user; After receiving the current communication ciphertext and the second interaction request, the current user decrypts the current communication ciphertext to obtain the current decryption result, calculates the current user authentication information based on the second interaction request and the current decryption result, and sends the current user authentication information to the other user; After receiving the current user's authentication information, the other users decrypt the other communication ciphertexts to obtain other decryption results, obtain other user response information based on the current user's authentication information and other decryption results, and send the other user response information to the current user; After receiving the response information of other users, the current user calculates the user identity information according to the response information of other users, and obtains the user avatar identity authentication result according to the user identity information; The information obtained when the user registers with the scene server includes: Current User Smart devices connecting the Metaverse Enter the current user account , Current user password and the current user's biometric information ; Select a random number as the first secret value and the current user's private key , current user Using smart devices The fuzzy extractor in the first secret value and the current user's private key , for the current user's biometric information Perform encryption processing to generate the current user encrypted value and the current user auxiliary parameters ; Based on the current user account , Current user encrypted value , the first secret value , Current user private key , calculate the current user pseudo identity , current user public key , current user avatar ; The current user will register his own information Send to scene server ; Scene Server Receive the current user's registration information Afterwards, check Existence and uniqueness in its database and blockchain; if If only one exists, the registration process is terminated. Otherwise, the scene server Capture the appearance characteristics of the current user's avatar ; Scene Server Select random numbers as the second secret value , the third secret value , based on the current user avatar , the appearance characteristics of the current user avatar , the second secret value , the third secret value , calculate the current registration identifier , first ciphertext , the first image of the current user's avatar , first communication ciphertext ; Scene Server Will Stored in its database, Upload to the blockchain and send the first communication ciphertext Send to current user ; Current User Receive the first communication ciphertext Then, use the current user's private key Decrypt the first communication ciphertext , get the first decrypted ciphertext ; According to the first decrypted ciphertext , calculate the first current user ciphertext , Second current user ciphertext , Current user registration and login verification value ; The information when the user registers with the scene server Store on smart device in the database; among them, Represents a cyclic additive group Generators of Represents a one-way hash function; Indicates the identity of the scene server; Indicates the private key of the scene server; Indicates encryption using the current user's public key; Indicates using the current user's private key for decryption; Represents the exclusive OR operation; The same applies to other users To the scene server Information provided during registration.

2. The method for authenticating the metaverse avatar identity according to claim 1, wherein: Also includes: Scene Server Constructing identity authentication system parameters ;in, represents a non-singular finite field; Represents large prime numbers; Represents a cyclic additive group The prime order of Represents a nonsingular finite field The cyclic additive group consisting of the set of all integer points of the elliptic curve on ; Represents a cyclic additive group Generators of Indicates the identity of the scene server; Represents a one-way hash function.

3. The method for authenticating the metaverse avatar identity according to claim 1, wherein: Based on the acquired user login information and the information when the user registered with the scene server, the login results of the user and the scene server are obtained, including: Current User Smart devices connected to the Metaverse Enter the current user account , Current user password and the current user's biometric information ; Current user Using smart devices The fuzzy extractor in the current user encrypted value verification value is calculated , Current registration identifier verification value , first ciphertext verification value , Current user login verification value ; Current user verify Is it true? If not, the login process is terminated. If it is true, the login verification is successful. After the login is successful, the current user Select a random number as the fourth secret value , and generate the first timestamp ; According to the fourth secret value and the first timestamp , calculate the first communication summary , Second Communication Summary ; Current user First login information Send to scene server ; Scene Server Upon receiving the current user First login information After that, generate the second timestamp , and check Is it true? If not, discard the first login information ; Otherwise, calculate the first update value , second communication digest verification value ;verify Is it true? If not, the scene server For the current user Login failed; if established, the scene server For the current user Login successful, scene server Choose a random number as the fifth secret value , according to the fifth secret value , calculate the second ciphertext , Summary of the Third Communication , current user With scene server The session key between , Summary of the Fourth Communication ; Scene Server Second login information Send to current user ;in, Indicates the preset timestamp difference; Current User Received second login information After that, generate the third timestamp , and verify Is it true? If not, discard the second login information ; Otherwise, calculate the second update value , current user and scene server The session key verification value between , the fourth communication digest verification value ;verify Is it true? If the equation is not true, then the current user For scene servers Login failed, otherwise, the current user For scene servers Login successful, current user With scene server Successfully completed identity authentication and key negotiation; Indicates the current user avatar verification value; represents the fourth secret numerical verification value; Represents the second ciphertext verification value; represents the fifth secret numerical verification value; The same applies to other users and scene server Login result.

4. The method for authenticating a metaverse avatar identity according to claim 1, wherein: The current user sends an interaction notification to the scene server and sends a first interaction request to other users, including: Current User To the scene server Send interactive notification to the current user Capture other user avatars Appearance feature verification value ; Current user To other users Send the first interaction request ;in, Indicates the current user's pseudo identity; Represents the current user avatar.

5. The method for authenticating the metaverse avatar identity according to claim 1, wherein: After receiving the first interaction request, the scene server encrypts the first image and secret value of the other user using the session key with the current user, generates the current communication ciphertext, and sends it to the current user; encrypts the first image and secret value of the current user using the session key with other users, generates other communication ciphertext, and sends it to other users, including: Scene Server Receive the current user After the interaction notification, use other users With scene server The session key between , for the current user The first image and the third secret value Encrypt and generate the third communication ciphertext ; Use current user With scene server The session key between , to other users The first image and the third secret value Encrypt to generate the fourth communication ciphertext ; Scene Server The third communication ciphertext Send to other users , the fourth communication ciphertext Send to current user ; Among them, the fourth communication ciphertext is the current communication ciphertext, the third communication ciphertext For other communication ciphertexts, Indicates encryption using the session key between other users and the scene server; Indicates encryption using the session key between the current user and the scene server.

6. The method for authenticating a metaverse avatar identity according to claim 1, wherein: After receiving the first interaction request and other communication ciphertext, the other user sends a second interaction request to the current user, including: Other users Receive the current user The first interaction request sent to the scene server After sending other communication ciphertext, capture the current user avatar Appearance feature verification value ; The second interactive information Send to current user ;in, Indicates other users’ pseudo identities; Represents other user avatars.

7. The method for authenticating the metaverse avatar identity according to claim 1, wherein: After receiving the current communication ciphertext and the second interaction request, the current user decrypts the current communication ciphertext to obtain a current decryption result, calculates the current user authentication information based on the second interaction request and the current decryption result, and sends the current user authentication information to the other user, including: Current User Received from other users The second interactive request sent to the scene server After sending the current communication ciphertext, use other users Fake identity As an index, retrieve other users' public keys from the blockchain , select a random number as the sixth secret value , generating the fourth timestamp ; Use with scene server The session key between For the fourth communication ciphertext Decrypt and get the current decryption result ; Calculate the first image verification value of the current user avatar based on the second interaction request and the current decryption result 、The fifth ciphertext 、The sixth ciphertext , Summary of the Fifth Communication , the current user authentication information Send to other users ;in, Indicates other users The first image of represents the third secret value; Represents the current user avatar Verification value of appearance features; Represents a cyclic additive group Generators of Represents other users' public keys; Represents other user avatars; Indicates that the session key between the current user and the scene server is used for decryption; Represents a one-way hash function.

8. The method for authenticating a metaverse avatar identity according to claim 1, wherein: After receiving the current user's authentication information, the other users decrypt the other communication ciphertexts to obtain other decryption results. Based on the current user's authentication information and other decryption results, they obtain other user response information and send the other user response information to the current user, including: Other users Receive the current user After sending the current user authentication information, generate the fifth timestamp , and check Is it true? If not, discard the current user authentication information; otherwise, use the scene server The session key between For the third communication ciphertext Decrypt and get other decryption results ; Calculate the sixth ciphertext verification value based on the current user authentication information and other decryption results and the fifth communication digest verification value , and verify Is it true? If not, then other users For the current user Identity authentication failed. If successful, other users For the current user Identity authentication is successful; Using the current user Fake identity As an index, retrieve the current user's public key from the blockchain , select a random number as the seventh secret value ; Based on the current user's public key and the seventh secret value , calculate the first image verification value of other user avatars 、The seventh ciphertext 、The eighth ciphertext , current user With other users The session key between , Sixth Communication Summary , other users' response information Send to current user ;in, Indicates the fourth timestamp; Indicates the preset timestamp difference; Indicates the first image of the current user; represents the third secret value; Indicates that the session key between other users and the scene server is used for decryption; Indicates the fifth ciphertext; Represents other users’ private keys; represents a fifth communication summary; Represents other user avatars; Represents the appearance feature verification value of other user avatars; Represents a cyclic additive group Generators of Indicates the sixth ciphertext; Represents the current user avatar; Represents a one-way hash function.

9. The method for authenticating a metaverse avatar identity according to claim 1, wherein: After receiving the response information from other users, the current user calculates the user identity information based on the response information from other users and obtains the user avatar identity authentication result based on the user identity information, including: Current User Received from other users After sending other user response information, generate the sixth timestamp , and check Is it true? If not, discard the other user response information; otherwise, calculate the eighth ciphertext verification value based on the other user response information. , current user With other users The session key verification value between , the sixth communication digest verification value ; verify Is it true? If not, the current user To other users Avatar identity authentication failed. If successful, the current user To other users The avatar identity authentication is successful; among them, Indicates the fifth timestamp; Indicates the preset timestamp difference; Indicates the seventh ciphertext; Indicates the current user's private key; Indicates the sixth ciphertext; Current user avatar; Indicates the first image of other users; represents a sixth communication summary; Represents a one-way hash function.

Citation Information

Patent Citations

  • Anti-arbor identity authentication method based on first impression in element universe

    CN118282663A

  • Metacosm cross-scene anonymous seamless identity authentication method based on double block chains

    CN119299224A