Two-factor authentication method and system with zero knowledge and authentication under QROM (Quantum Read Only Memory) based on biological characteristics
Through a two-factor authentication method based on biometrics, combined with public key encryption and key encapsulation mechanism, the problems of low security and efficiency in existing technologies are solved, and efficient and secure two-factor authentication is achieved under the QROM model.
Patent Information
- Application Number
- CN202410483008.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-22
- Publication Date
- 2025-10-24
AI Technical Summary
Existing two-factor authentication schemes cannot resist replay attacks by malicious users or attacks by malicious servers, and their security is unknown under QROM and their efficiency is low.
A two-factor authentication method based on biometrics is adopted, which utilizes the public key encryption scheme PKE, the key encapsulation mechanism KEMFO based on FO transformation, the pseudo-random number generator PRG and the message authentication code MAC. It combines the user's biometric information and private information, and improves the authentication security and efficiency under the QROM model through the public key encryption scheme PKE with semantic security and the key encapsulation mechanism KEMFO based on FO transformation.
Under the QROM model, the security and efficiency of authentication are enhanced, which can effectively defend against malicious attacks and ensure that the user's biometrics and private key factors cannot be impersonated when one is missing, thus raising the threshold for authentication.
Smart Images

Figure CN120834931A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cryptography, and in particular to two-factor authentication technology. Background Art
[0002] A homomorphic encryption scheme HE = (HE.KeyGen, HE.Enc, HE.Dec, HE.Eval) consists of four algorithms:
[0003] (pk,sk)←HE.KeyGen(1 λ ): Input the security parameter λ and generate a pair of public and private keys (pk, sk).
[0004] c←HE.Enc(pk,m): Input public key pk and message m, and output ciphertext c.
[0005] m←HE.Dec(sk,c): Input private key sk and ciphertext c, and output decrypted message value m.
[0006] c′←HE.Eval(pk,C,c1,…,c n ): Input public key pk, circuit C and n ciphertexts c1,…,c n , output ciphertext c′.
[0007] The plaintext attack security of the homomorphic encryption scheme is semantic security. The homomorphic nature of HE means that when for a circuit family If for all All circuit inputs x1,…,x n have
[0008] Pr[HE.Dec(sk,HE.Eval(pk,C,c1,…,c n ))≠C(x1,…,x n )]=negl(λ),
[0009] where (pk,sk)←HE.KeyGen(1 λ ) and c i =HE.Enc(pk,x i ), we use negl(λ) to represent the negligible amount.
[0010] PKE = (PKE.KeyGen, PKE.Enc, PKE.Dec) constitutes a public key encryption scheme. The definitions of these three algorithms are the same as the first three algorithms of the above homomorphic encryption scheme.
[0011] Two-factor authentication refers to the use of two different authentication factors for authentication. Typically, the two factors include a user's physical characteristic (such as fingerprint, facial recognition, iris scan, etc.) and a secret factor (such as password, private key, etc.). Single-factor authentication refers to the use of a single authentication factor for authentication. In a two-factor authentication scheme, a user needs to provide both factors simultaneously to pass identity verification. Compared with single-factor authentication, a two-factor authentication scheme is more secure because an attacker needs to obtain both different factors simultaneously to successfully impersonate a user.
[0012] In the following, further introduce the existing two-factor authentication scheme in the prior art.
[0013] Referring to Figure 1 the user registration phase to the server shown in the figure:
[0014] In the registration phase, first, the user calls the key generation algorithm of homomorphic encryption to generate a pair of public and private keys (pk, sk) ← HE.KeyGen(1 λ ), and collects the user's face information feature vector Γ = (Γ1,..., Γ k ). Then call the encryption algorithm of homomorphic encryption to get c i = (α i , β i ) ← HE.Enc(pk, Γ i ). Send the user ID and the ciphertext c1,..., c k and the public key pk to the server for storage.
[0015] In the authentication phase, the blind square Euclidean distance algorithm is represented by the BlindESED algorithm.
[0016] Referring to Figure 2 the user authentication phase to the server shown in the figure:
[0017] When the user wants to authenticate, the following steps are performed:
[0018] Step 1: First, sample the face biometric feature to get Γ' = (Γ1',..., Γ k '), send the user's ID, and C i ' = (α i , β i ) ← HE.Enc(pk, Γ i ') to the server.
[0019] Step 2: After the server receives C i ', it generates r0, r1 uniformly at random and calls the blind square Euclidean distance calculation algorithm to get the second-order ciphertext S * = (α * , β * ) to the user.
[0020] Third step: the user receives S * , and then calls the decryption algorithm s * ← HE.Dec(sk, S * ) to send to the server.
[0021] Fourth step: the server calculates the threshold s * according to s * , compares it with the standard threshold, and judges whether to pass the authentication.
[0022] However, the above-mentioned two-factor authentication scheme based on homomorphic encryption has the following technical problems:
[0023] 1. Unable to resist the replay attack of malicious users. Assuming that a malicious adversary obtains the private key of a user, but does not obtain the user's face biometric feature. The adversary can pass the authentication without knowing the user's face feature vector by replaying the first message.
[0024] 2. The whole model is weak, which is specifically shown in the following two points:
[0025] (1) Only "honest but curious" server is considered. Unable to resist the attack of malicious server, because the server can replace the ciphertext C stored by itself with S * to send to the user for decryption, so that the server obtains the user's face feature vector, breaking the zero-knowledge property.
[0026] (2) The security under QROM is unknown.
[0027] 3. The scheme is low in efficiency. The quadratic homomorphic encryption scheme is used in the above-mentioned scheme, which is low in encryption and decryption efficiency, so that the efficiency problem may be faced in actual application.
[0028] Therefore, the existing two-factor authentication scheme in the prior art is low in security and efficiency, and cannot well meet the needs of users. SUMMARY
[0029] The purpose of the present application is to provide a two-factor authentication method and system based on biometric features with zero-knowledge property and authentication property under QROM to solve the technical problems in the background art.
[0030] The present application discloses a two-factor authentication method based on biometric features with zero-knowledge property and authentication property under QROM, comprising:
[0031] Step A: In the initialization stage, the server calls the key generation algorithm of public key encryption to generate the public and private key pair (pks ,sk s ), set the system's public parameter pp to the server's public key pk s , initialize the database to be empty and store the server's private key sk s ;
[0032] Step B: During the user registration phase, the user invokes the key generation algorithm based on the FO transformation key encapsulation mechanism to generate the user's public and private key pair (pk c ,sk c ), uniformly and randomly generate an m-bit string of 0s and 1s, and set the user's private information fa1 to (sk c ,s); users’ biometric information Sampling is performed to obtain the user's biometric feature w; the user calls the encryption algorithm of the public key encryption and uses the public key pk of the server s Encrypt the sum of the biometric feature w and the string s to obtain the ciphertext C ws ; Set the user's registration information c For (C ws ,pk C ) and the user's identity identifier id c and the registration information c saving into the database;
[0033] Step C: In the user authentication phase, the server retrieves the user's registration information from the database according to the user's request. c , and based on the user's private information fa1 and the user's biometric information Perform two-factor authentication.
[0034] In a preferred embodiment, in step A, the formula of the key generation algorithm of the public key encryption is expressed as: (pk S ,sk S )←PKE.KGen(1 λ ), where the input is security parameter 1 λ , the output is the server's public and private key pair (pk s ,sk s ).
[0035] In a preferred embodiment, the step B includes the following sub-steps:
[0036] The user calls the key generation algorithm based on the FO transformation key encapsulation mechanism to generate the user's public and private key pair (pk c ,sk c ), the formula of the key generation algorithm of the key encapsulation mechanism based on FO transformation is expressed as: (pk C,sk C )←KEM FO .KGen(1 λ ), where the input is security parameter 1 λ , the output is the user's public and private key pair (pk c ,sk c ); User calls s← $ {0,1} m , uniformly and randomly generate an m-bit string of 0s and 1s; and set the user's private information fa1 to (sk C ,s);
[0037] User call Biometric information Perform sampling to obtain the user's biometric feature w;
[0038] The user calls the encryption algorithm of the public key encryption, and the formula of the encryption algorithm of the public key encryption is expressed as: C ws ←PKE.Enc(pk S ,w+s), using the server's public key pk s , encrypt w+s to get the ciphertext C ws ; Set the user's registration information c For (C ws ,pk C ) and the user's identity identifier id c and the registration information c Save to the database.
[0039] In a preferred embodiment, the step C includes the following sub-steps:
[0040] User Initialization And send an authentication request to the server (id c ,Request), where Ψ C Indicates the user's current execution status. Two states, initialized to Indicates empty;
[0041] After receiving the user's authentication request, the server initializes S :=reject, Among them, S Indicates the current execution state of the server, which has two states: {reject, accept}, and is initialized to reject; st S Represents the inter-round state stored by the server, initialized to The server obtains the user's identity identifier id from the databasec Corresponding registration information c If the registration information c If it does not exist, return Ψ S :=reject and terminate the authentication; otherwise, the server calls the key encapsulation algorithm of the key encapsulation mechanism based on FO transformation: (K,c r )←KEM FO .Encap(pk c ), enter the user's public key pk c , output key K and ciphertext c r ; The server calls the pseudo-random number generator: (K1, K2) ← PRG (K), and expands the key K to (K1, K2); the server stores st S :=(K1,K2,c r ), and the ciphertext c r Send to the user;
[0042] The user receives the ciphertext c r After that, read the user's private information fa1=:(sk C ,s), and again its biometric information Sampling is performed to obtain the user's biometric feature w'; the user calls the key decapsulation algorithm based on the FO transformation key encapsulation mechanism: K'←KEM FO .Decap(sk C ,c r ), enter the user's private key sk C With the ciphertext c r , output key K'; the user calls the pseudo-random number generator: (K'1, K'2)←PRK(K'), expands the key K' to (K'1, K'2); the user calls the encryption algorithm of public key encryption: C←PKE.Enc(pk S ,(w′+s)‖K′1||c r ), using the server's public key pk s , for (w′+s)‖K′1‖c r Encryption is performed to obtain the ciphertext C, where ‖ represents the string concatenation; the user calls the message authentication code generation algorithm: σ←MAC.Mac(K′2,c r ‖C), input K′2 and c r ‖C, output authentication symbol σ; user sets Ψ C :=finished, and send (C,σ) to the server;
[0043] After the server receives the message (C,σ), it reads st S :=(K1,K2,c r), and call the authentication algorithm of the message authentication code: MAC.Vrfy(K2,c r ‖C,σ), input K2, c r ‖C and σ, and verify whether the output is 1; if MAC.Vrfy(K2,c r ‖C,σ)≠1, then return Ψ s :=reject, and terminate the authentication; otherwise, call the public key encryption decryption algorithm: m′←PKE.Dec(sk S ,C), using the server's private key sk s Decrypt the ciphertext C to get the decryption result m′, and split m′=:u′‖K′1‖c′ r ; If K′1≠K1 or c′ r ≠c r , then return Ψ S :=reject, and terminate the authentication; otherwise, call the public key encryption decryption algorithm: u←PKE.Dec(sk S ,C ws ), using the server's private key sk s For ciphertext C ws Decrypt and get the decrypted result u, and call the Hamming distance judgment formula: b←HAM m,t (u,u′); if b=1, return Ψ S : = accept, authentication passed; if b = 0, then return Ψ s :=reject and terminate the authentication.
[0044] In a preferred embodiment, the user calls the key generation algorithm based on the key encapsulation mechanism of FO transformation to generate the user's public and private key pair (pk c ,sk c ), including the following sub-steps:
[0045] The user calls the key generation algorithm for public key encryption: Enter security parameter 1 λ , output the user's public and private key pair (pk c ,sk c ).
[0046] In a preferred embodiment, the server calls the key encapsulation algorithm of the key encapsulation mechanism based on FO transformation: (K, c r )←KEM FO .Encap(pk C ), enter the user's public key pk c , output key K and ciphertext c r The steps further include the following sub-steps:
[0047] The server calls the encryption algorithm of public key encryption: $ {0,1} λ , uniformly and randomly generates a λ-bit 0 and 1 string r;
[0048] The server calls the encryption algorithm of public key encryption: uses the public key pk of the user c , encrypts r using H(r) as a random number to obtain ciphertext c r , wherein H(r) represents a hash operation on the string r;
[0049] The server sets K:=H1(r), H1(r) represents a hash operation on the string r;
[0050] The user calls the key decapsulation algorithm of the FO transformation-based key encapsulation mechanism: K'←KEM FO .Decap(sk C ,c r ), inputs the private key sk of the user C and the ciphertext c r , and outputs the key K';
[0051] The user calls the decryption algorithm of public key encryption: inputs the private key sk of the user C and the ciphertext c r , and outputs the decryption result r';
[0052] The user calls the encryption algorithm of public key encryption: uses the public key pk of the user C , encrypts r' using H(r') as a random number, wherein H(r') represents a hash operation on the string r'; if , returns termination, otherwise, the user sets K':=H1(r'), H1(r') represents a hash operation on the string r'.
[0053] In a preferred example, the user private information fa1 is stored secretly by the user, and the private key sk of the server s is stored secretly by the server.
[0054] In a preferred example, the biological characteristics of the user are one or any combination of the following: a face image of the user, a fingerprint of the user, and an iris of the user.
[0055] The application also discloses a two-factor authentication system comprising:
[0056] a memory for storing computer executable instructions; and,
[0057] a processor for implementing the steps of the above method when executing the computer executable instructions.
[0058] The application further discloses a computer readable storage medium, wherein computer executable instructions are stored in the computer readable storage medium, and the computer executable instructions are executed by a processor to implement the steps of the above method.
[0059] Compared with the prior art, the main difference and effect of the embodiments of the application are as follows:
[0060] The embodiments of the application provide a two-factor authentication scheme based on biological feature information of a user and private information (sk C ,s) of the user, semantic security public key encryption scheme PKE, key encapsulation mechanism KEM FO based on FO transformation, pseudo random number generator PRG, and message authentication code MAC, which improves the security and authentication efficiency of authentication under the QROM model and better meets the needs of the user.
[0061] A large number of technical features are described in the specification of the application and distributed in various technical solutions. If all possible combinations (i.e., technical solutions) of technical features of the application are listed, the specification will be too long. In order to avoid this problem, each technical feature disclosed in the above summary of the application, each technical feature disclosed in the following embodiments and examples, and each technical feature disclosed in the drawings can be freely combined to form various new technical solutions (these technical solutions are considered to have been described in the specification), unless such combination of technical features is technically infeasible. For example, features A+B+C are disclosed in one example, features A+B+D+E are disclosed in another example, features C and D are equivalent technical means that play the same role, and only one of them can be used technically, and feature E can be combined with feature C technically. Therefore, the scheme of A+B+C+D should not be considered to have been described because it is technically infeasible, and the scheme of A+B+C+E should be considered to have been described. BRIEF DESCRIPTION OF DRAWINGS
[0062] Figure 1 is a schematic diagram of a user registration stage in the prior art;
[0063] Figure 2 is a schematic diagram of a user authentication stage in the prior art;
[0064] Figure 3is a flowchart of a biometric-based dual-factor authentication method with QROM lower zero-knowledge and authentication according to the first embodiment of the present application;
[0065] Figure 4 is a schematic diagram of a practical biometric-based dual-factor authentication protocol 2FA with QROM lower zero-knowledge and authentication according to a preferred embodiment of the present application. DETAILED DESCRIPTION
[0066] In the following description, many technical details are presented in order to better enable the reader to understand the present application. However, it will be apparent to those skilled in the art that the claimed technical solutions can be implemented even without these technical details and based on various changes and modifications of the following embodiments.
[0067] Explanation of some concepts:
[0068] Authentication factor: the evidence provided by the authenticated party to prove his own identity, called authentication factor. The authentication factor can be a PIN value, a password value, a physically unclonable function value, an inherent biometric feature such as a fingerprint, a face, etc.
[0069] Dual-factor authentication: dual-factor authentication refers to using two different authentication factors for authentication. Single-factor authentication refers to using a single authentication factor for authentication. With the popularity of remote services, people's requirements for security are gradually increasing, and the security strength of single-factor authentication may not meet the requirements. Therefore, dual-factor authentication is gradually considered for application by some authentication schemes. Dual-factor authentication is more secure than single-factor authentication. Its advantage lies in that when one of the two authentication factors is obtained by an adversary, the other can still guarantee the security of authentication. In January 2022, the Office of the President of the United States issued a memorandum requiring federal government agencies to meet specific network security standards, including the use of multi-factor authentication to strengthen the government's defense against increasingly complex threat activities.
[0070] Client-server authentication system: there is a user and a server in the system. The user authenticates to the server by using a client device to obtain services. The server authenticates the identity of the user by executing an authentication protocol and provides services to the user who has passed the authentication.
[0071] Adversary's attack behavior: according to the nature of the adversary's attack behavior, it can be divided into two categories.
[0072] (1) Passive attack: the adversary can observe each message or data sent or received in the communication, but cannot update or modify them, such as eavesdropping, etc. behaviors belong to passive attack;
[0073] (2) Active attack: the adversary can modify, replay, and intercept the messages transmitted in the channel.
[0074] ROM / QROM: ROM (random oracle model) is an ideal random oracle model, which regards a hash function H: X→Y as a uniform random function. Compared with ROM, QROM allows the input to be queried in the form of quantum state.
[0075] Security model:
[0076] In the client-server authentication system, according to the role of the adversary and the nature of the above attack behaviors, the adversary can be divided into the following three types:
[0077] (1) Malicious server: the malicious server will try to obtain the user's privacy information related to the authentication factor through some active attacks, passive attacks, and other ways for a certain client;
[0078] (2) Honest but curious server: the honest but curious server will execute the protocol normally for a certain client, trying to learn the privacy information of the other party from the process of normally executing the protocol, but the server will not initiate malicious active attacks;
[0079] (3) Malicious user: the malicious user can both passively attack and initiate malicious active attacks to the server, and even steal part of the authentication factor of the target user (but not all), and then achieve the purpose of impersonating the target user to realize authentication;
[0080] From the above three types of adversaries, the following two security models and security goals can be obtained:
[0081] Model 1: The adversary can be a malicious server or a malicious user.
[0082] Model 2: The enemy can be an honest but curious server or a malicious user.
[0083] Security goal: When the adversary is a malicious server / honest but curious server, the goal of two-factor authentication is that the adversary cannot obtain the secret information of the supporting user authentication factor and cannot impersonate the target user to pass authentication; when the adversary is a malicious user, the goal of two-factor authentication is that the adversary cannot impersonate other legitimate users to pass authentication, and another factor has zero-knowledge property.
[0084] From the definition of the type of adversary, model 1 is stronger than model 2.
[0085] The technical solution of the application can be applied in scenarios such as e-commerce and online banking, and a user obtains a service through double-factor authentication. The user needs to hold two authentication factors at the same time to pass the authentication, and when an enemy steals one authentication factor and lacks the other authentication factor, the enemy cannot pass the authentication. Compared with single-factor authentication, double-factor authentication can greatly increase the threshold of authentication and prevent unauthorized users from abusing the power of authorized users. At the same time, the technical solution is also applicable to places that use biological information for authentication and have privacy requirements for biological information.
[0086] The inventor of the application has creatively proposed a double-factor authentication method and system based on biological characteristics with zero knowledge and authentication under QROM after in-depth research and analysis of the technical problems in the background art. Compared with the prior art, the technical solution of the application is a new and efficient double-factor authentication protocol.
[0087] The double factor in the application is that one authentication factor fa1 is a knowledge factor (sk c ,s) of a user, and the other authentication factor fa2 is a sample of biological characteristic information of the user.
[0088] The double-factor authentication protocol of the application considers a stronger security model (server initiates malicious active attacks and is secure under QROM), and the authentication effect to be achieved is as follows:
[0089] 1. A legitimate user has two authentication factors of biological characteristic information and a private key of the user, and with the help of the two authentication factors, the user can achieve the purpose of authenticating the identity to the server;
[0090] 2. An enemy steals one authentication factor of a user (may steal a biological characteristic authentication factor of the user or a private key authentication factor of the user, but not both), and the other missing authentication factor can ensure that the enemy cannot impersonate the user to achieve authentication to the server, and the other missing authentication factor has zero knowledge.
[0091] 3. A malicious server can perform malicious active attacks, but still cannot obtain the secret information of any one authentication factor of the user.
[0092] 4. An enemy who obtains the secret information of the server cannot impersonate a target client to successfully authenticate to the server.
[0093] Therefore, the double-factor authentication based on biological characteristics with zero knowledge and authentication under QROM is a more secure and efficient identity authentication method, which can effectively defend against malicious attacks. In practical applications, the authentication protocol can be applied to identity authentication in various scenarios, such as finance, e-commerce, Internet of Things, and other fields.
[0094] The biometric-based two-factor authentication system is introduced as follows.
[0095] Definition 1 [Biometric-based two-factor authentication system]: A biometric-based two-factor authentication system involves two parties: a server and a user, and can be described as: 2FA = (2FA.Setup, 2FA.GenFactorl, 2FA.SampleFactor2, 2FA.Enroll, 2FA.Auth), where 2FA.Setup, 2FA.GenFactorl, 2FA.SampleFactor2, 2FA.Enroll are four probabilistic polynomial time algorithms, and 2FA.Auth is a probabilistic polynomial time authentication protocol run by the server and the user interactively.
[0096] The biometric-based two-factor authentication system consists of three phases:
[0097] Initialization phase: the server initializes the system, and in order to complete the initialization, the server invokes 2FA.Setup.
[0098] (pp, priv S ) ← 2FA.Setup(l λ ): The initialization algorithm generates system public parameters pp and secret information priv S . The server also initializes the database
[0099] Registration phase: in this phase, the user registers with the server by invoking 2FA.GenFactorl, 2FA.SampleFactor2, 2FA.Enroll.
[0100] (pub C , fa1) ← 2FA.GenFactorl(pp, id c ): The knowledge factor generation algorithm takes public parameters pp and the user's identity identifier id c as input, and outputs public information pub C and private information fa1. The user sets his knowledge factor as fa1 and stores (fa1, pub C ) locally.
[0101] The knowledge factor sampling algorithm takes the user's biometric source as input , and samples the biometric source to obtain the biometric feature w. The user sets his biometric possession factor as fa2:
[0102] infor c← 2FA. Enroll (pp, id c , pub C , fa1, fa2 = w): Enrollment algorithm takes as input the public parameters pp, the user's identity identifier id c , the public information pub C , the private information fa1 and the biometric fa2 = w and outputs the enrollment information infor c .
[0103] The user sends (id c , infor c ) to the server through a private channel and the server records DB := DB U {(id c , infor c )}.
[0104] Authentication phase: In this phase, the user and the server implement the user's authentication to the server by running 2FA. Auth.
[0105]
[0106] The authentication protocol is run by the user and the server. The user's input includes the public parameters pp, the user's identity id c , the public information pub C , the private information fa1 and the biometric sample The server's input is the public parameters pp, the secret information priv S and the database DB. After the interaction is completed, the user outputs the state The server outputs Ψ S ∈ {accept, reject}.
[0107] Correctness: For any user with a sample close to , for any (pp, priv S ) <- 2FA. Setup (1 λ ), (pub C , fa1) <- 2FA. GenFactor1 (pp, id c ), infor c <- 2FA. Enroll (pp, id c , pub C , fa1, w), DB := {(id c , infor c )}, the following holds:
[0108]
[0109] In the above formula, C is the abbreviation of Client, which means a client; S is the abbreviation of Server, which means a server.
[0110] It should be noted that in the biometric-based dual-factor authentication system, one authentication factor fa1 is the private information (sk C ,s) of the user, and the other authentication factor fa2 is the biometric information of the user. In the authentication process, the biometric information of the user is sampled twice by the biometric-based dual-factor authentication system: the first time is in the registration phase, and the biometric information w of the user is sampled; the second time is in the authentication phase, and the biometric information w' of the user is sampled. In other words, fa2 = w in the registration phase, and fa2 = w' in the authentication phase.
[0111] In the technical solution of the present application, four components will be used: a public key encryption scheme PKE, a key encapsulation mechanism KEM FO based on FO transformation, a message authentication code MAC, and a pseudo-random number generator PRG. Next, we will introduce these four components one by one.
[0112] Definition 2 [Public Key Encryption Scheme PKE]: A public key encryption scheme PKE = (PKE.KGen, PKE.Enc, PKE.Dec) consists of three probabilistic polynomial time algorithms, which are defined as follows:
[0113] PKE.KGen(1 λ ): Key generation algorithm, input security parameter 1 λ , output a pair of public and private keys (pk, sk).
[0114] PKE.Enc(pk, m): Encryption algorithm, input public key pk and encrypted message , output ciphertext c.
[0115] PKE.Dec(sk, c): Decryption algorithm, input private key and ciphertext c, output decryption result m'.
[0116] Correctness: For any (pk, sk) <- PKE.KGen(1 λ ), PKE.Dec(sk, PKE.Enc(pk, m)) = m holds.
[0117] Definition 3 [Key Encapsulation Mechanism KEM FO Based on FO Transformation]: A key encapsulation mechanism KEM FO based on FO transformation consists of three polynomial time algorithms, which are defined as follows:
[0118] KEMFO .KGen(1 λ ): Key generation algorithm input security parameter 1 λ , output a pair of encapsulation key and decapsulation key (pk, sk).
[0119] KEM FO .Encap(pk): The key encapsulation algorithm inputs the encapsulation key pk and outputs the key K and the ciphertext c.
[0120] KEM FO .Decap(sk,c): Decapsulates the key. Inputs the decapsulation key sk and the ciphertext c, and outputs K / ⊥.
[0121] Correctness: For any (pk,sk)←KEM FO .KGen(1 λ ), (K, c)←KEM FO .Encap(pk) has KEM FO .Decap(sk,c)=m holds.
[0122] Definition 4 [Message Authentication Code MAC]: The message authentication code MAC = (MAC.Mac, MAC.Vrfy) consists of two polynomial-time algorithms. Let K be the key space, M be the message space, and T be the authenticator space. It is defined as follows:
[0123] MAC.Mac(k,m): Generates an algorithm that takes as input a key k∈K and a message m∈M and outputs an authenticator σ∈T.
[0124] MAC.Vrfy(k,m,σ): The authentication algorithm takes as input the key k, the message m, and the authenticator σ, and outputs bits 0 / 1.
[0125] Correctness: For any k∈K, m∈M, MAC.Vrfy(k,m,MAC.Mac(k,m))=1.
[0126] Definition 5 [Pseudo-random number generator PRG]: A pseudo-random number generator PRG: K → K′ is a polynomial time deterministic function, where K is the seed space and K′ is the output space. Here, |K| < |K′| is required.
[0127] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0128] The first embodiment of the present application relates to a two-factor authentication method based on biometrics with zero-knowledge and authentication under QROM. The process is as follows: Figure 3 shown.
[0129] Specifically, if Figure 3 As shown, the two-factor authentication method includes the following steps:
[0130] In step 101, during the initialization phase, the server invokes a public key encryption key generation algorithm to generate the server's public and private key pair (pk s ,sk s ), set the system's public parameter pp to the server's public key pk s , initialize the database to be empty and store the server's private key sk s .
[0131] In this embodiment, preferably, the formula of the key generation algorithm of the public key encryption is expressed as: (pk S ,sk S )←PKE.KGen(1 λ ), where the input is security parameter 1 λ , the output is the server's public and private key pair (pk s ,sk s ).
[0132] Then, step 102 is entered. During the user registration phase, the user calls the key generation algorithm based on the key encapsulation mechanism of the FO transformation to generate the user's public and private key pair (pk c ,sk c ), uniformly and randomly generate an m-bit string of 0s and 1s, and set the user's private information fa1 to (sk C ,s); users’ biometric information Sampling is performed to obtain the user's biometric feature w; the user calls the encryption algorithm of the public key encryption and uses the public key pk of the server s Encrypt the sum of the biometric feature w and the string s to obtain the ciphertext C ws ; Set the user's registration information c For (C ws ,pk C ) and the user's identity identifier id c And the registration information inforc c Save to the database.
[0133] In this embodiment, preferably, the above step 102 includes the following sub-steps:
[0134] The user calls the key generation algorithm based on the FO transformation key encapsulation mechanism to generate the user's public and private key pair (pk c ,sk c ), the formula of the key generation algorithm of the key encapsulation mechanism based on FO transformation is expressed as: (pk C ,skC )←KEM FO .KGen(1 λ ), where the input is a security parameter 1 λ , and the output is a user's public-private key pair (pk c , sk c ); the user calls s← $ {0,1} m , uniformly randomly generates a 0 and 1 string s of m bits; and sets the user's private information fa1 as (sk C , s).
[0135] The user calls to sample the user's biometric information , and obtains the user's biometric w.
[0136] The user calls the public key encryption encryption algorithm, and the formula of the public key encryption encryption algorithm is represented as: C ws ← PKE.Enc(pk S , w + s), encrypts w + s using the public key pk s of the server to obtain ciphertext C ws ; sets the user's registration information infor c as (C ws , pk C ), and saves the user's identity identifier id c and the registration information infor c to the database.
[0137] Further, preferably, in the step of generating the user's public-private key pair (pk c , sk c ) by the user calling the key generation algorithm of the FO transformation-based key encapsulation mechanism, the following sub-steps are included:
[0138] The user calls the public key encryption key generation algorithm: The input is a security parameter 1 λ , and the output is a user's public-private key pair (pk c , sk c ).
[0139] Thereafter, step 103 is entered, in the user authentication phase, the server takes out the user's registration information infor c from the database according to the user's request, and performs double-factor authentication according to the user's private information fa1 and the user's biometric information .
[0140] In the present embodiment, preferably, in the above step 103, the following sub-steps are included:
[0141] User initialization and sends an authentication request (id c , Request) to the server, where Ψ C represents the current execution state of the user, which has two states, initialized as Ψ represents empty;
[0142] After the server receives the authentication request of the user, it initializes Ψ S : = reject, where Ψ S represents the current execution state of the server, which has two states {reject, accept}, initialized as reject; st S represents the inter-round state stored by the server, initialized as The server obtains the registration information infor c corresponding to the identity identifier id c of the user from the database, and if the registration information infor c does not exist, returns Ψ S : = reject, and terminates the authentication; otherwise, the server calls the key encapsulation algorithm of the FO transformation-based key encapsulation mechanism: (K, c r ) <- KEM FO .Encap(pk C ), inputting the public key pk c of the user, and outputting the key K and the ciphertext c r ; the server calls the pseudo-random number generator: (K1, K2) <- PRG(K), to expand the key K into (K1, K2); the server stores st S : = (K1, K2, c r ), and sends the ciphertext c r to the user;
[0143] After the user receives the ciphertext c r , the user reads the private information fa1 =: (sk C , s) of the user, and samples the biometric information again to obtain the biometric feature w'; the user calls the key decapsulation algorithm of the FO transformation-based key encapsulation mechanism: K' <- KEM FO .Decap(sk C , c r ), inputting the private key sk C of the user and the ciphertext c r, outputs a key K'; the user invokes the pseudo-random number generator: (K'1, K'2) <- PRG(K'), which expands the key K' into (K'1, K'2); the user invokes the encryption algorithm of the public-key encryption: C <- PKE.Enc(pk s ,(w' + s) || K'1 || c r ), encrypts (w' + s) || K'1 || c s using the public key pk r of the server, obtaining the ciphertext C, where || denotes concatenation of strings; the user invokes the generation algorithm of the message authentication code: σ <- MAC.Mac(K'2, c r || C), inputs K'2 and c r || C, and outputs the authenticator σ; the user sets Ψ C := finished, and sends (C, σ) to the server;
[0144] Upon receiving the message (C, σ), the server reads st S :=(K1, K2, c r ), and invokes the verification algorithm of the message authentication code: MAC.Vrfy(K2, c r || C, σ), inputs K2, c r || C, and σ, and verifies whether the output is 1; if MAC.Vrfy(K2, c r || C, σ)≠1, the server returns Ψ S := reject, and terminates the authentication; otherwise, the server invokes the decryption algorithm of the public-key encryption: m' <- PKE.Dec(sk S , C), decrypts the ciphertext C using the private key sk s of the server, and obtains the decrypted result m', and splits m' := u' || K'1 || c' r ; if K'1≠K1 or c' r ≠c r , the server returns Ψ S := reject, and terminates the authentication; otherwise, the server invokes the decryption algorithm of the public-key encryption: u <- PKE.Dec(sk S , c ws ), decrypts the ciphertext c s using the private key sk ws of the server, and obtains the decrypted result u, and invokes the Hamming distance judgment formula: b <- HAM m,t (u, u'), where HAM is the Hamming distance function; if b = 1, the server returns Ψ S := accept, and the authentication is passed; if b = 0, the server returns Ψ S := reject, and terminates the authentication.
[0145] Further, preferably,
[0146] The server calls the key encapsulation algorithm of the FO-transform based key encapsulation mechanism: K <- KEM r FO .Encap(pk C ), inputting the public key pk c of the user, and outputting the key K and the ciphertext c r , further comprising the following sub-steps:
[0147] The server calls r <- {0,1} $ λ , and generates a 0 and 1 string r of λ bits uniformly at random;
[0148] The server calls the encryption algorithm of the public key encryption: encrypts r using H(r) as the random number using the public key pk C of the user, to obtain the ciphertext c r , wherein H(r) represents a hash operation on the string r;
[0149] The server sets K := H1(r), wherein H1(r) represents a hash operation on the string r.
[0150] The user calls the key decapsulation algorithm of the FO-transform based key encapsulation mechanism: K' <- KEM FO .Decap(sk C , c r ), inputting the private key sk C of the user and the ciphertext c r , and outputting the key K', further comprising the following sub-steps:
[0151] The user calls the decryption algorithm of the public key encryption: inputting the private key sk C of the user and the ciphertext c r , and outputting the decryption result r';
[0152] The user calls the encryption algorithm of the public key encryption: encrypts r' using H(r') as the random number using the public key pk C of the user, wherein H(r') represents a hash operation on the string r'; if , the user returns to terminate, otherwise, the user sets K' := H1(r'), wherein H1(r') represents a hash operation on the string r'.
[0153] The procedure ends thereafter.
[0154] In the embodiment, preferably, the user private information privC is stored secretly by the user, the private key sk s of the server is stored secretly by the server, and no one else can get it.
[0155] In addition, the biometric feature of the user is one or any combination of the following: a face image of the user, a fingerprint of the user, and an iris of the user.
[0156] In order to better understand the technical solutions of the present specification, the following will be described in combination with a preferred embodiment, and the details listed in the preferred embodiment are mainly for the purpose of understanding and are not intended to limit the protection scope of the present application.
[0157] In the preferred embodiment, the specific construction of the practical two-factor authentication protocol 2FA with QROM lower zero knowledge and authentication based on biometric features is as follows: Figure 4 Each step will be described in detail below.
[0158] Initialization phase: the server calls (pk S , sk S )←PKE.KGen(1 λ ) to initialize the database Set the public parameter of the system as pp:=pk S , and store sk S secretly locally.
[0159] Registration phase: in this phase, the user calls 2FA.GenFactor1, 2FA.SampleFactor2, and 2FA.Enroll to register with the server. More specifically, the following steps are included:
[0160] (pk C , (sk C , s))←2FA.GenFactor1(1 λ ): the user first calls (pub C , priv C )←2FA.GenFactor1(pp, id c ), that is, the user first calls (pk C , sk C )←KEM FO .KGen(1 λ ), and then calls s← $ {0, 1} m , and sets the authentication factor one as
[0161] The user stores the biometric source Sampling is performed to obtain w.
[0162] 2FA.Enroll(pp,id c ,pk C ,fa1=(sk C ,s),fa2=w): user uses public parameter pp, user's identity id c , public information pk C , private information (sk C ,s), with the biometric feature w as input, first call C ws ←PKE.Enc(pk S ,w+s), set DB:=DB∪{(id c ,inforc c :=(C ws ,pk C ))}.
[0163] Authentication phase: The user and the server perform an interactive authentication, which is described as follows:
[0164] Step 1: First, user initialization And send to the server (id c ,Request) authentication request;
[0165] Step 2: After the server receives the user's authentication request, it first initializes S :=reject, then check if the entry exists in the database DB (id c ,·). If it does not exist, return Ψ S :=reject and terminate the authentication. Otherwise, the server takes out (id c ,inforc c =:(C ws ,pk c )). The server runs (K,c r )←KEM FO .Encap(pk C ), call (K1, K2)←PRG(K), store st S :=(K1,K2,c r ). The server sends c r To the user.
[0166] Step 3: User receives c r After that, read priv C =:(sk C ,s). The biological source was sampled again to obtain Call the decapsulation algorithm K′←KEM FO .Decap(skC ,c r ). Then call (K′1,K′2)←PRG(K′), and then calculate C←PKE.Enc(pk S ,(w′+s)‖K′1‖c r ) and σ←MAC.Mac(K′2,c r ‖C), the user sends (C,σ) to the server.
[0167] Step 4: After the server receives the message (C,σ), it reads st S =:(K1,K2,c r ), and verify MAC.Vrfy(K2,c r ‖C,σ) outputs 1. If MAC.Vrfy(K2,c r ‖C,σ)≠1, then return Ψ S :=reject and terminate the authentication; otherwise, calculate m′←PKE.Dec(sk S ,C) and split m′=:u′‖K′1‖c′ r If K′1≠K1 or c′ r ≠c r , then return Ψ S :=reject and terminate the authentication; otherwise, calculate u←PKE.Dec(sk S ,C ws ) and calculate b←HAM m,t (u,u′). If b=1, return Ψ s :=accept;If b=0, return Ψ s :=reject.
[0168] Correctness: Assuming that the Hamming distance between different bios of the same user's bio source does not exceed d, then for all (pk S ,sk S )←PKE.KGen(1 λ ), (pk C ,(sk C ,s))←2FA.GenFactor1(1 λ ), (id c ,infor c :=(C ws ,pk C ))←2FA.Enroll(pp,id c ,pk c ,(sk C ,s),w), let DB:=DB∪{(id c ,infor c :=(Cws pk C ). The correctness of the MAC ensures that MAC. Vrfy (K2, c r ‖ C, σ) = 1; the correctness of the PKE and KEM FO guarantees K' = K and u' = w' + s; and the correctness of the Hamming distance judgment guarantees b = 1. Therefore, there are
[0169]
[0170] In the above formula, C is the abbreviation of Client, which means the client; S is the abbreviation of Server, which means the server.
[0171] Advantages and positive technical effects:
[0172] According to the above description, the biometric-based two-factor authentication scheme with QROM zero-knowledge and authentication, aims to improve the security and efficiency of authentication. The scheme can resist replay attacks and attacks by malicious servers, and has high efficiency compared with the existing homomorphic encryption-based scheme in the prior art. Specifically, the advantages and positive technical effects of the scheme are as follows:
[0173] 1. High security: The security of the above authentication protocol of the present application will be analyzed in five cases as follows:
[0174] (1) The server uses a fresh number K as a challenge in the second step, so the challenge is different each time. In order to pass the authentication, the enemy must respond correctly to the fresh number, so the enemy cannot replay the message to pass the authentication.
[0175] (2) The enemy only obtains the user's private key authentication factor, but does not have the user's other authentication factor--biometric, nor the server's secret information: In this case, since the enemy does not have the user's biometric information, even if the random number K given by the server is decrypted by the private key, the value of w or w + s cannot be forged or guessed, and thus the ciphertext C ws that can pass the authentication cannot be given.
[0176] (3) The enemy only obtains the user's biometric authentication factor, but does not have the user's other authentication factor--private key, nor the server's secret information (private key): In this case, since the enemy does not have the user's private key, according to the security definition of the key encapsulation mechanism with semantic security, the enemy cannot correctly decrypt the value of the random number K, and thus cannot give the ciphertext C and the authenticator σ that can pass the authentication.
[0177] (4) For a malicious server, the server has the secret information, but does not have the private key of the user and the biological information: in this case, since the server does not have the private key of the user. Therefore, even if the server conducts active attack and passive attack, we can always replace sk with the QROM model C The simulation is performed, and the randomness of the string s is used to mask w, so that the adversary cannot obtain the secret information of the target user from the active attack and the passive attack, and therefore the scheme can realize the double-factor zero-knowledge property for a malicious server.
[0178] (5) For an adversary who obtains the secret information of the server, since it does not have the private key of the user, it cannot respond to the challenge of the server, so it cannot successfully impersonate the target user to realize authentication to the server.
[0179] Therefore, compared with the existing homomorphic encryption-based scheme in the prior art, the authentication scheme of the present application can resist attacks by malicious servers.
[0180] 2. High efficiency: compared with the use of the existing homomorphic encryption-based scheme in the prior art, the authentication scheme of the present application is more efficient.
[0181] The construction of the technical scheme of the present application is based on a public key encryption scheme PKE with semantic security, a key encapsulation mechanism KEM with semantic security realized based on FO transformation FO , a pseudo-random number generator PRG, and a message authentication code MAC. PKE has many efficient instantiations, such as using the Kyber scheme combined with symmetric encryption, etc.; KEM FO can be instantiated based on an efficient PKE scheme and a hash function, such as Kyber, PRG and MAC are efficient and lightweight components. The existing scheme technical solution is not efficient because it involves quadratic homomorphic encryption.
[0182] 3. Scalability: the technical scheme of the present application can be further extended to bidirectional authentication: the present authentication protocol realizes the authentication of the server to the user, which is a one-way authentication. In the second step of the protocol, the server side can sign the message it sends, and the user verifies the signature of the message. In this way, the user can authenticate the server, and then realize mutual authentication. Alternatively, the user can add a random number challenge in the first step, and let the server respond in the second step.
[0183] In summary, the embodiments of the present application provide a double-factor authentication scheme based on the biological feature information of the user and the private information (sk C , s) of the user, which is realized by a public key encryption scheme PKE with semantic security, a key encapsulation mechanism KEM with semantic security realized based on FO transformation FOThe pseudo-random number generator PRG and the message authentication code MAC improve the security and authentication efficiency of the authentication under the QROM model, and can better meet the needs of users.
[0184] In addition, the embodiments of the present application also provide a two-factor authentication system, which comprises a memory for storing computer executable instructions, and a processor; the processor is used to implement the steps in the above method embodiments when executing the computer executable instructions in the memory. The processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), etc. The memory can be a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk or a solid state disk, etc. The steps of the method disclosed in the embodiments of the present application can be directly embodied as the execution of a hardware processor, or the execution of a combination of hardware and software modules in the processor.
[0185] It should be noted that, in the application file of the present patent, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or equipment. Without more limitations, the element defined by the statement "including one" does not exclude the presence of another identical element in the process, method, article or equipment including the element. In the application file of the present patent, if it is mentioned that a certain behavior is performed according to a certain element, it means that the behavior is performed at least according to the element, which includes two cases: the behavior is performed only according to the element, and the behavior is performed according to the element and other elements. The expressions of multiple, multiple times, multiple kinds, etc. include 2, 2 times, 2 kinds and more than 2, more than 2 times, more than 2 kinds.
[0186] All documents mentioned in this application are incorporated herein by reference in their entirety to provide public access to the teachings of this application to the extent necessary to practice it. In addition, it should be understood that various modifications and substitutions can be made by those skilled in the art who have the benefit of the teachings of this application without departing from the spirit and scope of the application.
Claims
1. A biometric-based two-factor authentication method with QROM lower zero-knowledge and authentication, characterized in that, Comprising: Step A: In the initialization phase, the server calls a key generation algorithm of public key encryption to generate a public-private key pair (pk s , sk s ) of the server, sets the public parameter pp of the system as the public key pk s of the server, initializes the database as empty, and stores the private key sk s of the server; Step B: in the user registration stage, the user calls the key generation algorithm of the key encapsulation mechanism based on FO transformation to generate the public and private key pair (pk c , sk c ) of the user, uniformly randomly generates an m-bit 0 and 1 string s, and sets the private information fai of the user as (sk C , s); the user samples the biometric information of the user to obtain the biometric w of the user; the user calls the encryption algorithm of the public key encryption, encrypts the sum of the biometric w and the string s using the public key pk s of the server to obtain the ciphertext C ws ; sets the registration information infor c of the user as (C ws , pk C ), and saves the identity identifier id c of the user and the registration information infor c to the database; Step C: In the user authentication stage, the server takes out the user's registration information infor from the database according to the user's request c and performs double-factor authentication according to the user's private information fa1 and the user's biometric information .
2. The method of claim 1, wherein, In the step A, the formula of the public key encryption key generation algorithm is: (pk S ,sk S )←PKE.KGen(1 λ ), wherein the input is a security parameter 1 λ , and the output is a public-private key pair (pk s ,sk s ) of the server.
3. The method of claim 1, wherein, In the step B, comprising the following sub-steps: A user invokes a key generation algorithm of a FO transform based key encapsulation mechanism to generate a user's public-private key pair (pk c ,sk c ), the formula of the key generation algorithm of the FO transform based key encapsulation mechanism is represented as: (pk C ,sk C )←KEM FO .KGen(1 λ ), wherein the input is a security parameter 1 λ , and the output is the user's public-private key pair (pk c ,sk c ); the user invokes s← $ {0,1} m to uniformly randomly generate a 0 and 1 string s of m bits; and sets the user's private information fa1 as (sk C ,s). User invokes The biological feature information of the user Sampling is performed to obtain the biological feature w of the user The user calls a public key encryption encryption algorithm, and a formula of the public key encryption encryption algorithm is represented as: C ws ← PKE.Enc(pk S , w + s), uses the public key pk s of the server to encrypt w + s to obtain ciphertext C ws ; sets registration information infor c of the user as (C ws , pk C ), and saves an identifier id c of the user and the registration information infor c to the database.
4. The method of claim 1, characterized in that, in the step C, comprising the following sub-steps: User initialization and sends an authentication request (id c , Request) to the server, wherein Ψ C represents the current execution state of the user, has two states, initialized to represents empty; The server receives the authentication request of the user, initializes Ψ S = reject, wherein, Ψ S represents the current execution state of the server, has two states of {reject, accept}, and is initialized as reject; st S represents the inter-round state stored by the server, and is initialized as The server obtains the corresponding registration information infor c from the database according to the identity identifier id c of the user, if the registration information infor c does not exist, returns Ψ S := reject, and terminates the authentication; otherwise, the server calls a key encapsulation algorithm of a key encapsulation mechanism based on FO transformation: (K, c r ) <- KEM FO .Encap (pk C ), inputs the public key pk c of the user, and outputs the key K and the ciphertext c r ; the server calls a pseudo-random number generator: (K1, K2) <- PRK (K), and expands the key K into (K1, K2); the server stores st S := (K1, K2, c r ), and sends the ciphertext c r to the user; The user receives the ciphertext c r After that, the user's private information f a1 = : (sk C , s) is read, and the user's biometric information is sampled again to obtain the user's biometric w'; the user calls the key unsealing algorithm of the key encapsulation mechanism based on FO transformation: K' <- KEM FO . Decap (sk C , c r ), inputs the user's private key sk C and the ciphertext c r , and outputs the key K'; the user calls the pseudo-random number generator: (K'1, K'2) <- PRG (K'), and expands the key K' to (K'1, K'2); the user calls the encryption algorithm of the public key encryption: C <- PKE. Enc (pk S , (w' + s)‖K'1‖c r ), encrypts (w' + s)‖K'1‖c s using the public key pk r of the server to obtain the ciphertext C, wherein ‖ represents concatenating strings together; the user calls the generation algorithm of the message authentication code: σ <- MAC. Mac (K'2, c r ‖C), inputs K'2 and c r ‖C, and outputs the authenticator σ; the user sets Ψ C : = finished, and sends (C, σ) to the server; After the server receives the message (C,σ), it reads st S :=(K1,K2,c r ), and call the authentication algorithm of the message authentication code: MAC.Vrfy(K2,c r ‖C,σ), input K2, c r ‖C and σ, and verify whether the output is 1; if MAC.Vrfy(K2,c r ‖C,σ)≠1, then return Ψ S :=reject, and terminate the authentication; otherwise, call the public key encryption decryption algorithm: m′←PKE.Dec(sk S ,C), using the server's private key sk s Decrypt the ciphertext C to get the decryption result m′, and split m′=:u′‖K′1‖c′ r ; If K′1≠K1 or c′ r ≠c r , then return Ψ S :=reject, and terminate the authentication; otherwise, call the public key encryption decryption algorithm: u←PKE.Dec(sk S ,C ws ), using the server's private key sk s For ciphertext C ws Decrypt and get the decrypted result u, and call the Hamming distance judgment formula: b←HAM m,t (u,u′); if b=1, return Ψ S : = accept, authentication passed; if b = 0, then return Ψ S :=reject and terminate the authentication.
5. The method of claim 3, wherein, In a step of said user invoking a key generation algorithm of a FO transformation based key encapsulation mechanism to generate a user's public-private key pair (pk c ,sk c ), comprising the following sub-steps: A user invokes a key generation algorithm for public key encryption: Input a security parameter 1 λ , and outputs a user's public-private key pair (pk c , sk c ).
6. The method of claim 4, wherein, The server invokes a key encapsulation algorithm of a FO transformation based key encapsulation mechanism: (K, c) <- KEM.Encap(pk, sk, id, m) r ) FO .Encap(pk C ), inputting the public key pk of the user c , outputting a key K and a ciphertext c r , further comprising the following sub-steps: server calls r← $ {0,1} λ uniformly randomly generates a string r of λ bits of 0s and 1s; The server calls an encryption algorithm of public key encryption: Using the public key pk of the user C Encrypting r using H(r) as a random number to obtain ciphertext c r Wherein H(r) represents a hash operation on the string r; The server sets K: = H1(r), H1(r) represents a hash operation on the string r; The user calls the key decapsulation algorithm based on the FO transformation key encapsulation mechanism: K′←KEM FO .Decap(sk C ,c r ), enter the user's private key sk C With the ciphertext c r , the step of outputting the key K′ further includes the following sub-steps: The user calls a decryption algorithm of public key encryption: Input the private key sk of the user C And the ciphertext c r Output the decryption result r′; The user calls the encryption algorithm of the public key encryption: Using the public key pk of the user C Encrypts using H(r') as a random number for r', where H(r') means hashing the string r'; if Termination is returned, otherwise the user sets K' := H1(r'), where H1(r') means hashing the string r'.
7. The method according to claim 1, characterized in that said user private information priv C is stored secret by said user, said server's private key sk s is stored secret by said server.
8. The method according to any one of claims 1 to 7, characterized in that, The biological characteristics of the user are one or any combination of the following: a face image of the user, a fingerprint of the user, and an iris of the user.
9. A two-factor authentication system, characterized by, Comprising: A memory for storing computer executable instructions; And, A processor for implementing the steps in the method of any one of claims 1 to 8 when executing the computer executable instructions.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer executable instructions, and the computer executable instructions are executed by the processor to implement the steps in the method of any one of claims 1 to 8.
Citation Information
Patent Citations
Multi-factor authentication key negotiation method for intelligent equipment communication
CN114125833A
Registration and login method and device based on authentication information of user
CN117729001A