Authentication method, device, medium, program product and vehicle

By generating pseudonyms and public keys for the interactive end through the key management end in a certificateless public key cryptography system, the problems of high certificate management resource consumption and low security in traditional public key cryptography systems are solved, and efficient and secure vehicle network identity authentication is achieved.

CN120880672APending Publication Date: 2025-10-31BYD CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511073002.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

In traditional public-key cryptography systems, Certificate Authorities (CAs) are responsible for managing public key certificates, which consumes huge resources and leads to low authentication efficiency. Furthermore, in identity-based cryptography systems, the Private Key Generation Center (PKG) may eavesdrop on the communication content of vehicle nodes, resulting in low security.

Method used

A certificateless public-key cryptosystem is adopted, which generates pseudonyms and public keys for the interaction terminal through the key management terminal to achieve certificateless authentication, reduce the complexity of certificate management, and enhance security by adopting a bilinear pairing authentication method with low computational cost.

Benefits of technology

It improves the authentication efficiency and security of vehicle-to-everything (V2X) communication, reduces the complexity of certificate management, solves the key escrow problem, and enhances the anonymity and security of identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880672A_ABST
    Figure CN120880672A_ABST
Patent Text Reader

Abstract

The invention relates to an authentication method and device, a medium, a program product and a vehicle, and the method comprises the steps: generating first authentication information according to a first pseudonym and a first public key when a first interaction end receives the first pseudonym and the first public key sent by a second interaction end; and sending the first authentication information, and a second pseudonym and a second public key of the first interaction end to a second interaction end, so that the second interaction end performs authentication based on the first authentication information, the second pseudonym and the second public key, and the first pseudonym and the second pseudonym are generated by key management ends corresponding to the first interaction end and the second interaction end, so that the authentication efficiency between the interaction ends can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of certification, and more particularly to a certification method, equipment, medium, procedure, product, and vehicle. Background Technology

[0002] Identity authentication is the first line of defense for secure vehicle-to-everything (V2X) communication. It verifies the authenticity of the other party's identity and establishes a secure channel for private communication. In traditional public-key cryptography systems, a trusted third-party Certificate Authority (CA) is responsible for binding a public-private key pair to each vehicle node. However, public key certificate management (such as distribution, storage, maintenance, and revocation) can consume enormous resources, resulting in low authentication efficiency. Summary of the Invention

[0003] This application provides an authentication method, device, medium, program product, and vehicle, which improves authentication efficiency and at least partially solves the above-mentioned technical problems.

[0004] To achieve the above objectives, according to a first aspect of this application, the authentication method, applied to a first interactive terminal, includes:

[0005] Upon receiving a first pseudonym and a first public key from a second interactive terminal, first authentication information is generated based on the first pseudonym and the first public key.

[0006] The first authentication information, the second pseudonym and the second public key of the first interactive terminal are sent to the second interactive terminal so that the second interactive terminal can perform authentication based on the first authentication information, the second pseudonym and the second public key. The first pseudonym and the second pseudonym are generated by the key management terminals corresponding to the first interactive terminal and the second interactive terminal.

[0007] Optionally, generating the first authentication information based on the first pseudonym and the first public key includes:

[0008] Generate the first complete public key for the second interactive terminal based on the first pseudonym and the first public key;

[0009] The first authentication information is generated based on the first complete public key.

[0010] Optionally, generating the first complete public key for the second interactive terminal based on the first pseudonym and the first public key includes:

[0011] The first public key coefficient is determined based on the first pseudonym and the public parameters of the key management terminal;

[0012] The first complete public key of the second interaction terminal is generated based on the first public key coefficient, the first public key, and the system master public key of the key management terminal.

[0013] Optionally, generating the first authentication information based on the first complete public key includes:

[0014] The first authentication information is generated based on the first complete public key and the first random number.

[0015] Optionally, generating the first authentication information based on the first complete public key and the first random number includes:

[0016] Based on the first random number and the public parameters of the key management terminal, a first verification value is obtained;

[0017] Based on the first complete public key and the first pseudonym, the second verification value is obtained;

[0018] The first authentication information is generated based on the first verification value and the second verification value.

[0019] Optionally, obtaining the second verification value based on the first complete public key and the first pseudonym includes:

[0020] A first intermediate verification value is generated based on the first complete public key, the first complete private key of the first interactive terminal, and the first random number; and a second intermediate verification value is determined based on the first pseudonym.

[0021] The second verification value is obtained based on the first intermediate verification value and the second intermediate verification value.

[0022] Optionally, after sending the first authentication information, the second pseudonym, and the second public key of the first interactive terminal to the second interactive terminal, the method further includes:

[0023] Receive the second authentication information sent by the second interactive terminal;

[0024] Authentication is performed based on the first random number and the second authentication information.

[0025] Optionally, the authentication based on the first random number and the second authentication information includes:

[0026] The seventh verification value is determined based on the first random number and the third verification value in the second authentication information;

[0027] Authentication is performed based on the seventh verification value and the fourth verification value in the second authentication information.

[0028] Optionally, the authentication based on the seventh verification value and the fourth verification value in the second authentication information includes:

[0029] If the seventh verification value and the fourth verification value satisfy the first preset relationship, it is determined that the first interactive terminal has successfully authenticated the second interactive terminal.

[0030] Optionally, determining the seventh verification value based on the first random number and the third verification value in the second authentication information includes:

[0031] Calculate the sixth intermediate verification value based on the first random number and the third verification value in the second authentication information;

[0032] The seventh verification value is determined based on the first intermediate verification value, the third verification value in the second authentication information, and the sixth intermediate verification value.

[0033] Optionally, the second authentication information includes a first timestamp of the second interactive terminal receiving the first authentication information, and the method further includes:

[0034] If the first timestamp meets the first preset time condition, authentication is performed based on the first random number and the second authentication information.

[0035] Optionally, the method further includes:

[0036] If the conditions for the first pseudonym application are met, a pseudonym application is sent to the key management terminal;

[0037] The key management terminal receives the second pseudonym returned by the first interaction terminal based on the pseudonym application.

[0038] Optionally, the application conditions for the first pseudonym include:

[0039] The conditions for updating the first preset pseudonym are met, there is a communication requirement with the second interactive terminal, and at least one of the following is received: the first preset pseudonym update condition is met, communication with the second interactive terminal exists, and the first pseudonym request instruction is received.

[0040] Optionally, the second pseudonym is generated by the key management terminal based on the real identity identifier of the first interaction terminal.

[0041] Optionally, before sending the pseudonym request to the key management terminal, the method further includes:

[0042] The third public key of the first interactive terminal and the real identity identifier of the first interactive terminal are sent to the key management terminal for registration.

[0043] Optionally, after sending the third public key of the first interactive terminal and the real identity identifier of the first interactive terminal to the key management terminal for registration, the method further includes:

[0044] The key management terminal receives a first related parameter sent by the key management terminal. The first related parameter is determined by the key management terminal based on the third public key of the first interaction terminal, the system master public key of the key management terminal, and the first private key set by the key management terminal for the first interaction terminal.

[0045] The first complete private key of the first interactive terminal is determined based on the first relevant parameters.

[0046] Optionally, determining the first complete private key of the first interactive terminal based on the relevant parameters includes:

[0047] The first complete private key of the first interactive terminal is determined based on the second private key of the first interactive terminal and the first related parameters.

[0048] Optionally, the method further includes:

[0049] The second public key of the first interactive terminal is determined based on the first relevant parameters.

[0050] According to a second aspect of this application, an authentication method is also provided, applied to a second interactive terminal, the authentication method comprising:

[0051] Receive the first authentication information sent by the first interactive terminal, as well as the second pseudonym and the second public key of the first interactive terminal;

[0052] Authentication is performed based on the second pseudonym, the second public key, and the first authentication information.

[0053] Optionally, the authentication based on the second pseudonym, the second public key, and the first authentication information includes:

[0054] Based on the second pseudonym and the second public key, generate the second complete public key for the first interactive terminal;

[0055] Authentication is performed based on the second complete public key and the first authentication information.

[0056] Optionally, generating the second complete public key for the first interactive terminal based on the second pseudonym and the second public key includes:

[0057] The second public key coefficient is determined based on the second pseudonym and the public parameters of the key management terminal;

[0058] The second complete public key of the first interaction terminal is generated based on the second public key coefficient, the second public key, and the system master public key of the key management terminal.

[0059] Optionally, the authentication based on the second complete public key and the first authentication information includes:

[0060] The third intermediate verification value is obtained based on the second complete public key, the first verification value in the first authentication information, and the second complete private key of the second interactive terminal;

[0061] A fourth intermediate verification value is obtained based on the third intermediate verification value and the second verification value in the first authentication information;

[0062] The second interaction terminal authenticates the first interaction terminal based on the fourth intermediate verification value.

[0063] Optionally, the step of authenticating the first interaction terminal by the second interaction terminal based on the fourth intermediate verification value includes:

[0064] If the relationship between the fourth intermediate verification value, the second complete public key, the public parameters of the key management terminal, and the first verification value in the first authentication information satisfies the second preset relationship, it is determined that the second interaction terminal has successfully authenticated the first interaction terminal.

[0065] Optionally, after determining that the second interactive terminal has successfully authenticated the first interactive terminal, the method further includes:

[0066] Based on the first verification value in the first authentication information, generate the second authentication information;

[0067] The second authentication information is sent to the first interactive terminal so that the first interactive terminal can authenticate the second interactive terminal.

[0068] Optionally, generating second authentication information based on the first verification value in the first authentication information includes:

[0069] The second authentication information is generated based on the second random number and the first verification value.

[0070] Optionally, generating the second authentication information based on the second random number and the first verification value includes:

[0071] Based on the second random number and the public parameters of the key management terminal, a third verification value is obtained;

[0072] A fourth verification value is generated based on the second random number and the first verification value in the first authentication information;

[0073] The second authentication information is generated based on the third verification value and the fourth verification value.

[0074] Optionally, generating a fourth verification value based on the second random number and the first verification value in the first authentication information includes:

[0075] Based on the second random number and the first verification value in the first authentication information, a fifth intermediate verification value is obtained;

[0076] The fourth verification value is generated based on the third intermediate verification value, the third verification value, and the fifth intermediate verification value.

[0077] Optionally, the first authentication information further includes a second timestamp of the first authentication information being sent by the first interactive terminal, and the method further includes:

[0078] If the second timestamp meets the second preset time condition, authentication is performed based on the second pseudonym, the second public key, and the first authentication information.

[0079] Optionally, before receiving the first authentication information sent by the first interactive terminal, and the second pseudonym and second public key of the first interactive terminal, the method further includes:

[0080] When there is a communication requirement with the first interactive terminal, the first pseudonym and the first public key of the second interactive terminal are sent to the first interactive terminal so that the first interactive terminal generates the first authentication information based on the first pseudonym and the first public key.

[0081] Optionally, before sending the first pseudonym and first public key of the second interactive terminal to the first interactive terminal, the method further includes:

[0082] If the conditions for applying for a second pseudonym are met, a pseudonym application is sent to the key management terminal;

[0083] The key management terminal receives the first pseudonym returned by the second interaction terminal based on the pseudonym application.

[0084] Optionally, the application requirements for the second pseudonym include:

[0085] The conditions include at least one of the following: reaching the second preset kana update time, having a communication requirement with the first interactive terminal, and receiving a second kana request instruction.

[0086] Optionally, the first pseudonym is generated by the key management terminal based on the real identity identifier of the second interaction terminal.

[0087] Optionally, before sending the pseudonym request to the key management terminal, the method further includes:

[0088] The fourth public key of the second interaction terminal and the real identity identifier of the second interaction terminal are sent to the key management terminal for registration.

[0089] Optionally, after sending the fourth public key of the second interaction terminal and the real identity identifier of the second interaction terminal to the key management terminal for registration, the method further includes:

[0090] The key management terminal receives a second related parameter sent by the key management terminal. The second related parameter is determined by the key management terminal based on the fourth public key of the second interaction terminal, the system master public key of the key management terminal, and the third private key set by the key management terminal for the second interaction terminal.

[0091] The second complete private key of the second interactive terminal is determined based on the second relevant parameters.

[0092] Optionally, determining the first complete private key of the first interactive terminal based on the second relevant parameters includes:

[0093] The second complete private key of the second interactive terminal is determined based on the fourth private key of the second interactive terminal and the second related parameters.

[0094] Optionally, the method further includes:

[0095] The first public key of the second interactive terminal is determined based on the second relevant parameters.

[0096] According to the three aspects of this application, an authentication method is also provided, applied to a key management terminal, the method comprising:

[0097] Upon receiving a pseudonym request from the interactive terminal, a pseudonym for the interactive terminal is generated based on the real identity identifier corresponding to the interactive terminal.

[0098] The pseudonym is sent to the interactive terminal, wherein the interactive terminal includes any first interactive terminal provided in the embodiments of this application, and / or any second interactive terminal provided in the embodiments of this application, and the pseudonym of the interactive terminal includes the second pseudonym of the first interactive terminal and / or the first pseudonym of the second interactive terminal.

[0099] Optionally, the real identity identifier corresponding to the interactive terminal generates the pseudonym of the interactive terminal, including:

[0100] The pseudonym parameter is determined based on the system master private key of the key management terminal and the third random number corresponding to the interaction terminal.

[0101] The pseudonym for the interactive terminal is generated based on the pseudonym parameters and the real identity identifier corresponding to the interactive terminal.

[0102] Optionally, the method further includes:

[0103] If a target interactive terminal with abnormal behavior is detected in the interactive terminal, a third random number corresponding to the target interactive terminal and the pseudonym of the target interactive terminal are obtained to determine the real identity of the target interactive terminal.

[0104] The target interactive terminal is monitored based on its real identity identifier.

[0105] Optionally, the regulatory operation includes:

[0106] Cancel the registration of the target interactive terminal and / or broadcast that the target interactive terminal has abnormal behavior.

[0107] Optionally, the method further includes:

[0108] Determine the target point on the elliptic curve;

[0109] The system master public key of the key management terminal is determined based on the target point.

[0110] Optionally, the method further includes:

[0111] The system master public key of the key management terminal is determined based on the system master private key of the key management terminal and the target point.

[0112] According to a fourth aspect of this application, an electronic device is also provided, including a processor connected to a memory storing a computer program, the processor being configured to run the computer program in the memory to perform any of the authentication methods provided in the embodiments of this application.

[0113] According to a fifth aspect of this application, a computer-readable storage medium is provided, the computer-readable storage medium storing a computer program that, when executed by a processor, implements any of the authentication methods provided in the embodiments of this application.

[0114] According to a sixth aspect of this application, a computer program product is provided, comprising a computer program that is executed by a processor to implement any of the authentication methods provided in the embodiments of this application.

[0115] According to a seventh aspect of this application, a vehicle is provided that performs any of the authentication methods provided in the embodiments of this application, or includes the electronic device described above.

[0116] In summary, in the embodiments of this application, upon receiving a first pseudonym and a first public key sent by a second interactive terminal, first authentication information is generated based on the first pseudonym and the first public key. The first authentication information, along with a second pseudonym and a second public key from the first interactive terminal, are sent to the second interactive terminal so that the second interactive terminal can perform authentication based on the first authentication information, the second pseudonym, and the second public key. The first pseudonym and the second pseudonym are generated by the key management terminals corresponding to the first and second interactive terminals. By generating pseudonyms used by the first and second interactive terminals during identity authentication through the key management terminals, certificate-free authentication is achieved, thereby improving authentication efficiency.

[0117] Other features and advantages of this application will be described in detail in the following detailed description section. Attached Figure Description

[0118] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0119] To gain a more complete understanding of this application and its beneficial effects, the following description will be provided in conjunction with the accompanying drawings, wherein the same reference numerals in the following description denote the same parts.

[0120] Figure 1 This is a flowchart illustrating an example of an authentication method provided in an embodiment of the present invention;

[0121] Figure 2 This is a system model architecture diagram corresponding to an authentication method provided in this embodiment of the invention;

[0122] Figure 3 This is a system initialization flowchart provided in an embodiment of the present invention;

[0123] Figure 4 This is a flowchart of a vehicle node registration process provided in an embodiment of the present invention;

[0124] Figure 5 This is a flowchart of a cloud platform registration process provided in an embodiment of the present invention;

[0125] Figure 6 This is a flowchart of a vehicle node authenticating with a cloud platform provided in an embodiment of the present invention;

[0126] Figure 7 This is a flowchart of a pseudonym update provided in an embodiment of the present invention;

[0127] Figure 8 This is a flowchart of a vehicle node traceability and monitoring process provided in an embodiment of the present invention;

[0128] Figure 9 This is a schematic diagram of the structure of the electronic device provided in the embodiment of the present invention. Detailed Implementation

[0129] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the protection scope of this application.

[0130] Based on the problems mentioned in the background technology, public key certificate management (such as distribution, storage, maintenance, revocation, etc.) may consume huge resources, resulting in low authentication efficiency.

[0131] Specifically, with the development of the modern automotive industry and the internet, advanced sensing and communication technologies have made vehicles more diversified and intelligent, leading to the rapid development of the Internet of Vehicles (IoV). Identity authentication is the first line of defense for the security of IoV communication, verifying the authenticity of the other party's identity and establishing a secure channel for private communication. IoV identity authentication schemes are mainly researched in traditional public-key cryptography systems, identity-based public-key cryptography systems, and certificate-free public-key cryptography systems.

[0132] In traditional public-key cryptography systems, a trusted third-party Certificate Authority (CA) is responsible for binding a public-private key pair to each vehicle node. Public key certificate management (such as distribution, storage, maintenance, and revocation) can consume enormous resources. In identity-based cryptography systems, a trusted third-party Private Key Generator (PKG) generates and sends private keys to vehicle nodes. The PKG may know the private keys of all vehicle nodes, allowing a dishonest PKG to steal communication content between all vehicle nodes. In certificate-free public-key cryptography systems, the private key of a vehicle node consists of a portion of the vehicle node's private key generated by the Key Generation Centre and a private value selected by the vehicle node. This eliminates the need for certificate management and solves the key escrow problem. Most existing certificate-free public-key cryptography authentication schemes in the Internet of Vehicles (IoV) employ computationally intensive bilinear pairing, and schemes that do not use bilinear pairing are rarely used in two-way authentication for vehicle-to-cloud (V2X) interactions.

[0133] In some related technologies, the alias of the vehicle-to-everything (V2X) terminal is generated by itself and sent to the other party. If an alias is forged abnormally for impersonation, it is impossible to trace and control the V2X terminal. Secondly, similar methods cannot resist replay attacks, and there is a risk that an abnormal V2X terminal may replay the verification message in the current session. In addition, similar methods are suitable for identity authentication between V2X terminals or roadside units, but are not used for two-way identity authentication between vehicle nodes and cloud platform TSP (Telematics Service Provider).

[0134] In some related technologies, a third-party private key generator (PKG) may generate and send private keys to vehicle nodes. However, the PKG may know the private keys of all vehicle nodes, so a dishonest PKG could steal the communication content between all vehicle nodes, resulting in low security.

[0135] To address the aforementioned issues, this application proposes an authentication method, device, medium, program product, and vehicle. In this application, a first interactive terminal, upon receiving a first pseudonym and a first public key from a second interactive terminal, generates first authentication information based on the first pseudonym and the first public key. The first authentication information, along with a second pseudonym and a second public key from the first interactive terminal, are then sent to the second interactive terminal, enabling the second interactive terminal to perform authentication based on the first authentication information, the second pseudonym, and the second public key. The first and second pseudonyms are generated by the key management terminals corresponding to the first and second interactive terminals, eliminating the need for certificate management and resolving key escrow issues. This improves authentication efficiency and security.

[0136] Specifically, the authentication method in this application can be applied to electronic devices, which can be either an interactive terminal or a key management terminal. The interactive terminal can be a vehicle-mounted device or a cloud platform (cloud). The following descriptions will primarily focus on examples where the authentication method is executed by an interactive terminal or a key management terminal, to provide detailed explanations of each embodiment.

[0137] This application provides an authentication method applied to a first interactive terminal. The authentication method provided in the embodiments of this application includes steps S10-S20. Please refer to [link to relevant documentation]. Figure 1 The following is a detailed introduction.

[0138] S10. Upon receiving the first pseudonym and the first public key sent by the second interactive terminal, generate first authentication information based on the first pseudonym and the first public key.

[0139] S20. Send the first authentication information, the second pseudonym and the second public key of the first interactive terminal to the second interactive terminal, so that the second interactive terminal can perform authentication based on the first authentication information, the second pseudonym and the second public key, wherein the first pseudonym and the second pseudonym are generated by the key management terminals corresponding to the first interactive terminal and the second interactive terminal.

[0140] In this embodiment, authentication is required between the first and second interactive terminals to ensure secure communication. This authentication can be two-way authentication, where either the first or second interactive terminal can initiate the authentication process. For example, when the first interactive terminal needs to communicate with the second interactive terminal, it can initiate a communication request to indicate that there is a communication need between them. Upon receiving the communication request, the second interactive terminal can send its first pseudonym and first public key to the first interactive terminal. The first interactive terminal generates first authentication information based on the first pseudonym and first public key. Then, it sends the first authentication information, the first interactive terminal's second pseudonym, and second public key back to the second interactive terminal. The second interactive terminal can then perform authentication based on these information, thereby authenticating the identities of both parties.

[0141] The first pseudonym of the second interaction terminal is obtained by the second interaction terminal from the key management terminal corresponding to both the first and second interaction terminals. The second pseudonym of the first interaction terminal is obtained by the first interaction terminal from the same key management terminal. The key management terminal can be a shared key management terminal for both the first and second interaction terminals. The key management terminal (Key Generation Centre, KGC) is a key management center primarily responsible for generating, storing, and managing keys to ensure information security and data privacy. The KGC generates and stores session keys using strong encryption algorithms and enhances security by periodically updating the keys.

[0142] Both the first and second public keys are public keys, which are publicly available encryption keys used to encrypt information. Anyone can obtain and use a public key, but it cannot be used to decrypt information. A public key acts like a public address; anyone can send encrypted information to this address, but only the holder of the private key can decrypt it. The first public key can be a portion of the second interaction's public key generated based on KGC, and the second public key can be a portion of the first interaction's public key generated based on KGC. The first and second public keys can be distributed based on KGC.

[0143] In this embodiment, the pseudonyms used by the first and second interactive terminals during identity authentication are generated by KGC, enabling the determination of message integrity and the authenticity of the other party's identity even without a certificate. This achieves anonymous, certificate-free authentication key exchange between the interactive terminals, reducing the complexity of certificate generation, distribution, updating, and revocation, and improving authentication efficiency and security between the interactive terminals.

[0144] In one embodiment, generating the first authentication information based on the first pseudonym and the first public key includes:

[0145] Generate the first complete public key for the second interactive terminal based on the first pseudonym and the first public key;

[0146] The first authentication information is generated based on the first complete public key.

[0147] In this embodiment, on the first interactive terminal, a first complete public key of the second interactive terminal can be generated based on the first pseudonym and the first public key of the second interactive terminal. Then, first authentication information can be generated based on the first complete public key. The first authentication information is generated based on the first complete public key of the second interactive terminal and sent to the second interactive terminal. The second interactive terminal can then perform authentication based on the first complete public key, thereby realizing authentication between the interactive terminals.

[0148] In one embodiment, generating the first complete public key for the second interactive terminal based on the first pseudonym and the first public key includes:

[0149] The first public key coefficient is determined based on the first pseudonym and the public parameters of the key management terminal;

[0150] The first complete public key of the second interaction terminal is generated based on the first public key coefficient, the first public key, and the system master public key of the key management terminal.

[0151] In this embodiment, the first public key coefficient of the second interaction terminal can be determined based on the first pseudonym of the second interaction terminal and the public parameters such as the hash function disclosed by KGC. Then, based on the first public key coefficient and the system master public key of KGC, the first complete public key of the second interaction terminal is generated. Determining the first complete public key through the pseudonym and the information disclosed by KGC can improve security.

[0152] In one embodiment, generating the first authentication information based on the first complete public key includes:

[0153] The first authentication information is generated based on the first complete public key and the first random number.

[0154] In this embodiment, at the first interactive end, a first random number can also be selected, and first authentication information can be generated based on the first random number and the first complete public key to enhance the randomness of the first authentication information and improve authentication security.

[0155] In one embodiment, generating the first authentication information based on the first complete public key and the first random number includes:

[0156] Based on the first random number and the public parameters of the key management terminal, a first verification value is obtained;

[0157] Based on the first complete public key and the first pseudonym, the second verification value is obtained;

[0158] The first authentication information is generated based on the first verification value and the second verification value.

[0159] In this embodiment, the first authentication information may include a first verification value and a second verification value. The first verification value is obtained based on a first random number and public parameters of the key management terminal. The second verification value may be determined based on a first complete public key and a first pseudonym of the second interaction terminal. The first verification value and the second verification value can be used to form the first verification value and the second verification value in the first authentication information for authentication.

[0160] In one embodiment, obtaining the second verification value based on the first complete public key and the first pseudonym includes:

[0161] A first intermediate verification value is generated based on the first complete public key, the first complete private key of the first interactive terminal, and the first random number; and a second intermediate verification value is determined based on the first pseudonym.

[0162] The second verification value is obtained based on the first intermediate verification value and the second intermediate verification value.

[0163] In this embodiment, a first intermediate verification value can be generated based on the first complete public key, the first complete private key of the first interactive terminal, and the first random number, and a second intermediate verification value can be determined based on the first pseudonym of the second interactive terminal. The second verification value is determined by combining the first intermediate verification value and the second intermediate verification value. Since the first complete private key of the first interactive terminal is added during the generation of the second verification value, the first authentication information can be made more private.

[0164] In one embodiment, after sending the first authentication information, the second pseudonym, and the second public key of the first interactive terminal to the second interactive terminal, the method further includes:

[0165] Receive the second authentication information sent by the second interactive terminal;

[0166] Authentication is performed based on the first random number and the second authentication information.

[0167] In this embodiment, after the first authentication information, the second pseudonym and the second public key of the second interaction terminal are sent to the second interaction terminal, the second interaction terminal will perform authentication based on this information. If the authentication is successful, the second authentication information will be generated based on all or part of the information in the first authentication information and returned to the first interaction terminal. The first interaction terminal will then perform authentication again based on the first random number used when generating the first authentication information and the second authentication information, thereby further ensuring the security of the interaction between the two parties.

[0168] In one embodiment, the authentication based on the first random number and the second authentication information includes:

[0169] The seventh verification value is determined based on the first random number and the third verification value in the second authentication information;

[0170] Authentication is performed based on the seventh verification value and the fourth verification value in the second authentication information.

[0171] In this embodiment, the second authentication information includes a third verification value and a fourth verification value. The third verification value is determined by the second interaction terminal based on its selected second random number and the public parameters of KGC. The fourth verification value is generated by the second interaction terminal based on the second random number and the first verification value in the first authentication information. At the first interaction terminal, a seventh verification value corresponding to the fourth verification value in the second authentication information can be determined based on the corresponding first random number and the third verification value in the second authentication information. Then, the seventh verification value and the fourth verification value are compared, and authentication is performed again at the first interaction terminal based on the comparison result.

[0172] In one embodiment, the authentication based on the seventh verification value and the fourth verification value in the second authentication information includes:

[0173] If the seventh verification value and the fourth verification value satisfy the first preset relationship, it is determined that the first interactive terminal has successfully authenticated the second interactive terminal.

[0174] In this embodiment, if the comparison result shows that the seventh verification value and the fourth verification value satisfy the first preset relationship, it can be determined that the first interactive terminal has successfully authenticated the second interactive terminal. The first preset relationship can be an equality relationship or other mathematical relationship.

[0175] In one embodiment, determining the seventh verification value based on the first random number and the third verification value in the second authentication information includes:

[0176] Calculate the sixth intermediate verification value based on the first random number and the third verification value in the second authentication information;

[0177] The seventh verification value is determined based on the first intermediate verification value, the third verification value in the second authentication information, and the sixth intermediate verification value.

[0178] In this embodiment, at the second interaction terminal, the fourth verification value can be determined based on the second random number and the first verification value in the first authentication information, after obtaining the fifth intermediate verification value, and then based on the fifth intermediate verification value, the third verification value in the second authentication information, and the third intermediate verification value corresponding to the first intermediate verification value. Therefore, when determining the seventh verification value, it may be necessary to determine the seventh verification value corresponding to the fourth verification value based on the first random number, the third verification value in the second and the first intermediate verification value, for authentication performed on the first interaction terminal.

[0179] In one embodiment, the second authentication information includes a first timestamp of the second authentication information being sent by the second interactive terminal, and the method further includes:

[0180] If the first timestamp meets the first preset time condition, authentication is performed based on the first random number and the second authentication information.

[0181] In this embodiment, the second authentication information includes a first timestamp of the second authentication information sent by the second interactive terminal. The first interactive terminal can first perform timeliness verification based on the first timestamp to determine whether the first timestamp meets a first preset time condition. The first preset time condition is the condition for passing the timeliness verification. The first preset time condition can be that the time difference between the first timestamp and the time when the first interactive terminal receives the second authentication information is less than a first preset time difference. If the first timestamp meets the first preset time condition, the timeliness verification passes, and the first interactive terminal can further perform authentication based on the first random number and the second authentication information.

[0182] In some embodiments, when the second interaction terminal generates the fourth verification value, it can also generate the fourth verification value based on the first timestamp, the third intermediate verification value, the third verification value, and the fifth intermediate verification value. In this way, when the first interaction terminal generates the seventh verification value, it can also determine the seventh verification value based on the first timestamp, the third verification value, the first intermediate verification value, and the sixth intermediate verification value in the second authentication information, thereby further improving the authentication accuracy.

[0183] In one embodiment, the method further includes:

[0184] If the conditions for the first pseudonym application are met, a pseudonym application is sent to the key management terminal;

[0185] The key management terminal receives the second pseudonym returned by the first interaction terminal based on the pseudonym application.

[0186] In this embodiment, the first interactive terminal can send a pseudonym application to the key management terminal if the first pseudonym application conditions are met. After receiving the pseudonym application, the key management terminal can generate a second pseudonym for the first interactive terminal and return it to the first interactive terminal. The first interactive terminal receives the second pseudonym returned by the KGC based on the pseudonym application and performs subsequent anonymous authentication.

[0187] In one embodiment, the conditions for applying for the first pseudonym include:

[0188] The conditions for updating the first preset pseudonym are met, there is a communication requirement with the second interactive terminal, and at least one of the following is received: the first preset pseudonym update condition is met, communication with the second interactive terminal exists, and the first pseudonym request instruction is received.

[0189] In this embodiment, the first pseudonym application condition may be one of the following: satisfying the first preset pseudonym update condition of the first interactive terminal, the first interactive terminal having a communication requirement with the second interactive terminal, and the first interactive terminal receiving the first pseudonym application.

[0190] Among them, the first preset kana update condition indicates that the kana of the first interactive terminal needs to be updated, such as when a new kana update cycle is reached, or when the first interactive terminal has a communication need with the second interactive terminal, which may be that the first interactive terminal or the second interactive terminal has initiated a communication request to the other party. The first kana request instruction may be an instruction from the user or automatically triggered to request the first interactive terminal to obtain or change the second kana.

[0191] This avoids the risk of being bound to a single pseudonym due to prolonged use, and is beneficial for protecting identity privacy. Attackers cannot locate the interacting party by analyzing the interaction information, so changing pseudonyms periodically can reduce the risk of being attacked.

[0192] In some embodiments, the first or second interactive terminal may send a pseudonym request to the KGC before each communication to ensure the security of anonymous communication.

[0193] In one embodiment, the second pseudonym is generated by the key management terminal based on the real identity identifier of the first interaction terminal.

[0194] In this embodiment, KGC can be generated based on the real identity identifier of the first interactive terminal. KGC can select a third random number corresponding to the first interactive terminal, generate a second pseudonym for the first interactive terminal based on the third random number and the real identity identifier of the first interactive terminal, and send the second pseudonym to the first interactive terminal.

[0195] In one embodiment, before sending the pseudonym request to the key management terminal, the method further includes:

[0196] The third public key of the first interactive terminal and the real identity identifier of the first interactive terminal are sent to the key management terminal for registration.

[0197] In this implementation, since it is necessary to generate a pseudonym based on the real identity identifier, the third public key of the first interaction terminal needs to be sent to the first interaction terminal in advance for registration. The third public key is a part of the public key of the first interaction terminal, which is generally determined by the first interaction terminal itself.

[0198] In one embodiment, after sending the third public key of the first interactive terminal and the real identity identifier of the first interactive terminal to the key management terminal for registration, the method further includes:

[0199] The key management terminal receives a first related parameter sent by the key management terminal. The first related parameter is determined by the key management terminal based on the third public key of the first interaction terminal, the system master public key, and the first private key set by the key management terminal for the first interaction terminal.

[0200] The first complete private key of the first interactive terminal is determined based on the first relevant parameters.

[0201] In this embodiment, KGC receives the real identity identifier and third public key of the first interaction terminal for registration. During registration, the third public key and real identity identifier of the first interaction terminal are stored as registration information in the database associated with KGC. KGC determines the first relevant parameters corresponding to the first interaction terminal based on the third public key of the first interaction terminal, the system master public key of KGC, and the first private key set by KGC for the first interaction terminal. The first private key is a partial private key of the first interaction terminal. The first relevant parameters are related parameters and are intermediate calculation parameters in the authentication process, serving an encryption function. The first interaction terminal receives the first relevant parameters sent by KGC and determines its first complete private key based on these parameters, which is used for subsequent anonymous authentication.

[0202] In one embodiment, determining the first complete private key of the first interactive terminal based on the relevant parameters includes:

[0203] The first complete private key of the first interactive terminal is determined based on the second private key of the first interactive terminal and the first related parameters.

[0204] In this embodiment, the second private key of the first interactive terminal is a partial private key of the first interactive terminal, which is generally confirmed by the first interactive terminal itself. The first interactive terminal determines the first complete private key of the first interactive terminal based on its second private key and the first related parameters for subsequent anonymous authentication, and the security of the first complete private key is increased by the second private key.

[0205] In one embodiment, the method further includes:

[0206] The second public key of the first interactive terminal is determined based on the first relevant parameters.

[0207] In this embodiment, a second public key for the first interaction terminal can also be determined based on the first relevant parameters, serving as a partial public key for the first interaction terminal. Specifically, one of the relevant parameters from the first relevant parameters can be selected as the second public key for the second interaction terminal.

[0208] This application embodiment also provides an authentication method, which can be applied to any of the second interactive terminals provided in this application embodiment, the authentication method comprising:

[0209] Receive the first authentication information sent by the first interactive terminal, as well as the second pseudonym and the second public key of the first interactive terminal;

[0210] Authentication is performed based on the second pseudonym, the second public key, and the first authentication information.

[0211] In this embodiment, when the second interactive terminal receives the first authentication information, the second pseudonym, and the second public key sent by the first interactive terminal, the second interactive terminal can perform authentication based on this information so that the second interactive terminal can authenticate the identity of the first interactive terminal.

[0212] In one embodiment, the authentication based on the second pseudonym, the second public key, and the first authentication information includes:

[0213] Based on the second pseudonym and the second public key, generate the second complete public key for the first interactive terminal;

[0214] Authentication is performed based on the second complete public key and the first authentication information.

[0215] In this embodiment, the second interactive terminal generates a second complete public key for the first interactive terminal based on the second pseudonym and the second public key of the first interactive terminal, and authenticates the first authentication information based on the second complete public key of the first interactive terminal.

[0216] In one embodiment, generating the second complete public key for the first interactive terminal based on the second pseudonym and the second public key includes:

[0217] The second public key coefficient is determined based on the second pseudonym and the public parameters of the key management terminal;

[0218] The second complete public key of the first interaction terminal is generated based on the second public key coefficient, the second public key, and the system master public key of the key management terminal.

[0219] In this embodiment, the second public key coefficient of the first interaction terminal can be determined based on the second pseudonym of the first interaction terminal and the public parameters disclosed by KGC. The public parameters are parameters disclosed by KGC for authentication calculation. In addition, KGC can also disclose hash functions, system master public keys, etc. to facilitate authentication calculation. Then, based on the second public key coefficient and KGC's system master public key, the second complete public key of the first interaction terminal can be generated. The generation process of the second complete public key of the first interaction terminal corresponds to the generation method of the first complete public key of the second interaction terminal, so that the first complete public key and the second complete public key correspond to each other, realizing authentication on the second interaction terminal.

[0220] In one embodiment, the authentication based on the second complete public key and the first authentication information includes:

[0221] The third intermediate verification value is obtained based on the second complete public key, the first verification value in the first authentication information, and the second complete private key of the second interactive terminal;

[0222] A fourth intermediate verification value is obtained based on the third intermediate verification value and the second verification value in the first authentication information;

[0223] The second interaction terminal authenticates the first interaction terminal based on the fourth intermediate verification value.

[0224] In this embodiment, a third intermediate verification value is obtained based on the second complete public key, the first verification value in the first authentication information, and the second complete private key of the second interaction terminal. The method for determining the third intermediate verification value corresponds to the method for determining the first intermediate verification value on the first interaction terminal, so that the third intermediate verification value corresponds to the first intermediate verification value. Then, a fourth intermediate verification value is obtained based on the third intermediate verification value and the second verification value in the first authentication information. The method for determining the fourth intermediate verification value corresponds to the method for determining the second intermediate verification value, so that the fourth intermediate verification value corresponds to the second intermediate verification value. Therefore, the second interaction terminal can authenticate the first interaction terminal based on the fourth intermediate verification value.

[0225] In one embodiment, the step of authenticating the first interaction terminal by the second interaction terminal based on the fourth intermediate verification value includes:

[0226] If the relationship between the fourth intermediate verification value, the second complete public key, the public parameters of the key management terminal, and the first verification value in the first authentication information satisfies the second preset relationship, it is determined that the second interaction terminal has successfully authenticated the first interaction terminal.

[0227] In this embodiment, it is determined whether the relationship between the fourth intermediate verification value, the second complete public key, the public parameters of the key management terminal, and the first verification value in the first authentication information satisfies the second preset relationship. The second preset relationship is set based on the above intermediate verification values ​​and the specific determination method of the verification value, indicating that the calculated fourth intermediate verification value is correct. If the above parameters satisfy the second preset relationship, it can be determined that the second interaction terminal has successfully authenticated the first interaction terminal.

[0228] In one embodiment, after determining that the second interactive terminal has successfully authenticated the first interactive terminal, the method further includes:

[0229] Based on the first verification value in the first authentication information, generate the second authentication information;

[0230] The second authentication information is sent to the first interactive terminal so that the first interactive terminal can authenticate the second interactive terminal.

[0231] In this embodiment, after determining that the second interactive terminal has successfully authenticated the first interactive terminal, the second interactive terminal can receive the first authentication information sent by the first interactive terminal, and then generate the second authentication information based on the first verification value in the first authentication information, send the second authentication information to the first interactive terminal, and the first interactive terminal authenticates the second exchange based on the second authentication information, thereby further improving the security of two-way authentication.

[0232] In one embodiment, generating second authentication information based on the first verification value in the first authentication information includes:

[0233] The second authentication information is generated based on the second random number and the first verification value.

[0234] In this embodiment, the second interactive terminal selects a second random number and generates second authentication information based on the second random number and the first verification value in the first authentication information, thereby improving the randomness of the second authentication information and enhancing authentication security.

[0235] In one embodiment, generating the second authentication information based on the second random number and the first verification value includes:

[0236] Based on the second random number and the public parameters of the key management terminal, a third verification value is obtained;

[0237] A fourth verification value is generated based on the second random number and the first verification value in the first authentication information;

[0238] The second authentication information is generated based on the third verification value and the fourth verification value.

[0239] In this embodiment, a third verification value is obtained based on a second random number and the public parameters of the key management terminal. The public parameters used to calculate the third verification value are consistent with the public information of the KGC used to calculate the first verification value, such as the public parameters and public algorithm, so that the first verification value and the third verification value correspond. Then, a fourth verification value is generated based on the second random number and the first verification value in the first authentication information. Finally, a second authentication information is generated based on the third verification value and the fourth verification value and sent to the first interaction terminal for authentication.

[0240] In one embodiment, generating a fourth verification value based on the second random number and the first verification value in the first authentication information includes:

[0241] Based on the second random number and the first verification value in the first authentication information, a fifth intermediate verification value is obtained;

[0242] The fourth verification value is generated based on the third intermediate verification value, the third verification value, and the fifth intermediate verification value.

[0243] In this embodiment, the second interactive terminal can generate a fifth intermediate verification value based on the second random number and the first verification value in the first authentication information, and then generate a fourth verification value based on the third intermediate verification value, the third verification value and the fifth intermediate verification value.

[0244] In one embodiment, the first authentication information further includes a second timestamp of the first interactive terminal sending the second authentication information, and the method further includes:

[0245] If the second timestamp meets the second preset time condition, authentication is performed based on the second pseudonym, the second public key, and the first authentication information.

[0246] In this embodiment, the first authentication information also includes a second timestamp of the first authentication information sent by the first interactive terminal. The second interactive terminal can first perform timeliness verification based on the second timestamp to determine whether the second timestamp meets a second preset time condition. The second preset time condition is the condition for the first authentication information to pass the timeliness verification. The first preset time condition can be that the time difference between the second timestamp and the time when the second interactive terminal receives the first authentication information is less than the second preset time difference. If the second timestamp meets the second preset time condition, the timeliness verification passes, and the second interactive terminal can further perform authentication based on the second pseudonym, the second public key, and the first authentication information.

[0247] In one embodiment, before receiving the first authentication information sent by the first interactive terminal, and the second pseudonym and second public key of the first interactive terminal, the method further includes:

[0248] When there is a communication requirement with the first interactive terminal, the first pseudonym and the first public key of the second interactive terminal are sent to the first interactive terminal so that the first interactive terminal generates the first authentication information based on the first pseudonym and the first public key.

[0249] In this embodiment, when the first interactive terminal initiates a communication request to the second interactive terminal, or when the second interactive terminal needs to initiate a communication request to the first interactive terminal, the second interactive terminal has a communication need with the first interactive terminal. When the second interactive terminal has a communication need with the first interactive terminal, it can actively send the first pseudonym and the first public key of the second interactive terminal to the first interactive terminal, so that the first interactive terminal can generate the first authentication information based on the first pseudonym and the first public key.

[0250] In one embodiment, before sending the first pseudonym and first public key of the second interactive terminal to the first interactive terminal, the method further includes:

[0251] If the conditions for applying for a second pseudonym are met, a pseudonym application is sent to the key management terminal;

[0252] The key management terminal receives the first pseudonym returned by the second interaction terminal based on the pseudonym application.

[0253] In this embodiment, the second interactive terminal can send a pseudonym application to the key management terminal when the second pseudonym application conditions are met. After receiving the pseudonym application, the key management terminal can generate a first pseudonym for the second interactive terminal and return it to the second interactive terminal. The second interactive terminal receives the first pseudonym returned by the KGC based on the pseudonym application and performs subsequent anonymous authentication.

[0254] In one embodiment, the conditions for applying for the second pseudonym include:

[0255] The conditions include at least one of the following: reaching the second preset kana update time, having a communication requirement with the first interactive terminal, and receiving a second kana request instruction.

[0256] In this embodiment, the second pseudonym application condition may be one of the following: satisfying the second preset pseudonym update condition of the second interactive terminal, the second interactive terminal having a communication requirement with the first interactive terminal, and the second interactive terminal receiving the second pseudonym application.

[0257] The second preset kana update condition indicates that the first kana of the second interactive terminal needs to be updated. For example, when a new kana update cycle is reached, the second interactive terminal has a communication need with the first interactive terminal. This could be that either the first or second interactive terminal has initiated a communication request to the other party. The second kana request instruction could be an instruction from the user or an automatically triggered instruction to the second interactive terminal to obtain or change the first kana.

[0258] This avoids the risk of being bound to a single pseudonym due to prolonged use, and is beneficial for protecting identity privacy. Attackers cannot locate the interacting party by analyzing the interaction information, so changing pseudonyms periodically can reduce the risk of being attacked.

[0259] In one embodiment, the first pseudonym is generated by the key management terminal based on the real identity identifier of the second interaction terminal.

[0260] In this embodiment, KGC can be generated based on the real identity identifier of the second interaction terminal. KGC can select a third random number corresponding to the second interaction terminal, generate a first pseudonym of the second interaction terminal based on the third random number and the real identity identifier of the second interaction terminal, and send the first pseudonym to the second interaction terminal.

[0261] In one embodiment, before sending the pseudonym request to the key management terminal, the method further includes:

[0262] The fourth public key of the second interaction terminal and the real identity identifier of the second interaction terminal are sent to the key management terminal for registration.

[0263] In this implementation, since it is necessary to generate a pseudonym based on the real identity identifier, the fourth public key of the second interaction terminal needs to be sent to the second interaction terminal in advance for registration. The fourth public key is a part of the public key of the second interaction terminal, which is generally determined by the second interaction terminal itself.

[0264] In one embodiment, after sending the fourth public key of the second interaction terminal and the real identity identifier of the second interaction terminal to the key management terminal for registration, the method further includes:

[0265] The key management terminal receives a second related parameter sent by the key management terminal. The second related parameter is determined by the key management terminal based on the fourth public key of the second interaction terminal, the system master public key of the key management terminal, and the third private key set by the key management terminal for the second interaction terminal.

[0266] The second complete private key of the second interactive terminal is determined based on the second relevant parameters.

[0267] In this embodiment, KGC receives the real identity identifier and fourth public key of the second interaction terminal for registration. During registration, the fourth public key and real identity identifier of the second interaction terminal are stored as registration information in the database associated with KGC. Based on the fourth public key of the second interaction terminal, KGC's system master public key, and the third private key set by KGC for the second interaction terminal, the second related parameters corresponding to the second interaction terminal are determined. The third private key is a partial private key of the first interaction terminal. The second related parameters are intermediate calculation parameters in the authentication process, serving an encryption function. The second interaction terminal receives the second related parameters sent by KGC and determines its second complete private key based on these parameters, which is used for subsequent anonymous authentication.

[0268] In one embodiment, determining the first complete private key of the first interactive terminal based on the second relevant parameters includes:

[0269] The second complete private key of the second interactive terminal is determined based on the fourth private key of the second interactive terminal and the second related parameters.

[0270] In this embodiment, the fourth private key of the second interaction terminal is a partial private key of the second interaction terminal, which is generally confirmed by the second interaction terminal itself. The second interaction terminal determines the second complete private key of the second interaction terminal based on its fourth private key and the second related parameters for subsequent anonymous authentication, thereby increasing the security of the second complete private key through the fourth private key.

[0271] In one embodiment, the method further includes:

[0272] The first public key of the second interactive terminal is determined based on the second relevant parameters.

[0273] This application embodiment also provides an authentication method, which can be applied to any key management terminal provided in this application embodiment, the method comprising:

[0274] Upon receiving a pseudonym request from the interactive terminal, a pseudonym for the interactive terminal is generated based on the real identity identifier corresponding to the interactive terminal.

[0275] The pseudonym is sent to the interactive terminal, wherein the interactive terminal includes any first interactive terminal provided in the embodiments of this application, and / or any second interactive terminal provided in the embodiments of this application, and the pseudonym of the interactive terminal includes the second pseudonym of the first interactive terminal and / or the first pseudonym of the second interactive terminal.

[0276] In this embodiment, both the first and second interactive terminals are interactive terminals and can send pseudonym requests to KGC independently. KGC selects the third random number corresponding to the interactive terminal and the real identity identifier corresponding to the interactive terminal to generate a pseudonym for the interactive terminal, and sends the pseudonym to the interactive terminal that initiated the pseudonym request.

[0277] In one embodiment, generating the pseudonym for the interactive terminal based on a third random number corresponding to the interactive terminal and the real identity identifier corresponding to the interactive terminal includes:

[0278] The pseudonym parameter is determined based on the system master private key of the key management terminal and the third random number corresponding to the interaction terminal.

[0279] The pseudonym for the interactive terminal is generated based on the pseudonym parameters and the real identity identifier corresponding to the interactive terminal.

[0280] In this embodiment, KGC has a system master private key, which is a key that KGC does not disclose. The third random number corresponding to the interaction terminal can be a random number selected by KGC for the interaction terminal that initiates the pseudonym request. Based on the system master private key and the third random number corresponding to the interaction terminal, a pseudonym parameter corresponding to the interaction terminal can be generated. Based on the pseudonym parameter and the real identity identifier corresponding to the interaction terminal, a pseudonym for the interaction terminal is generated.

[0281] In one embodiment, the method further includes:

[0282] If a target interactive terminal with abnormal behavior is detected in the interactive terminal, a third random number corresponding to the target interactive terminal and the pseudonym of the target interactive terminal are obtained to determine the real identity of the target interactive terminal.

[0283] The target interactive terminal is monitored based on its real identity identifier.

[0284] In this embodiment, the interactive terminals use pseudonyms for communication. If a registered interactive terminal exhibits abnormal behavior, such as malicious communication, the KGC can trace the identity of the interactive terminal based on its pseudonym to achieve supervision of each interactive terminal. Since the pseudonym is generated using a third random number and a real identity identifier, if a target interactive terminal with abnormal behavior is detected among the interactive terminals managed by the KGC, its pseudonym and the third random number can be obtained to trace its real identity identifier, allowing for supervision of the target interactive terminal based on its real identity identifier.

[0285] In one embodiment, the regulatory operation includes:

[0286] Cancel the registration of the target interactive terminal and / or broadcast that the target interactive terminal has abnormal behavior.

[0287] In this embodiment, KGC can revoke the legitimate identity of the target interactive terminal, cancel its registration in KGC, and broadcast the target interactive terminal with abnormal behavior, making it unable to operate normally.

[0288] In one embodiment, the method further includes:

[0289] Determine the target point on the elliptic curve;

[0290] The system master public key of the key management terminal is determined based on the target point.

[0291] In this embodiment, the public parameters of KGC can be set based on the elliptic curve algorithm. The elliptic curve algorithm is a type of public-key cryptosystem based on elliptic curve mathematics. A target point is selected on the elliptic curve, and the public parameters of KGC, the system master public key, authentication algorithm (such as hash algorithm), etc. are determined based on the target point.

[0292] In one embodiment, the method further includes:

[0293] The system master public key of the key management terminal is determined based on the system master private key of the key management terminal and the target point.

[0294] In this embodiment, the system master public key of the key management terminal can be determined based on the system master private key of the KGC and the target point.

[0295] In some embodiments, the authentication method can be applied to vehicle-to-everything (V2X) scenarios for the authentication of various interactive nodes in the V2X. Both the first interactive terminal and the second interactive terminal can be interactive terminals in the V2X. The interactive terminal can be a vehicle terminal, a cloud terminal, a roadside terminal, etc. The first interactive terminal can be a vehicle terminal and the second interactive terminal can be a cloud terminal, or the first interactive terminal can be a cloud terminal or a vehicle terminal.

[0296] To better understand, the following descriptions will use the example of the first interaction terminal being the vehicle (i.e., the vehicle node) and the second interaction terminal being the cloud platform (TSP) to illustrate each embodiment, but this does not constitute a limitation on the embodiments. Figure 2 As shown, the authentication method provided in this application involves three types of entities: vehicle nodes, TSPs, and KGCs. The vehicle node is the first interaction terminal, and the TSP is the second interaction terminal. The vehicle node is responsible for initiating communication connections with other entities and obtaining information services provided by the vehicle network. The TSP is responsible for responding to communication requests from the vehicle node, communicating with the vehicle node, and authenticating the vehicle node's identity. The KGC, as a semi-trusted organization, is responsible for generating partial public keys and pseudonyms for both the vehicle node and the KGC.

[0297] The KGC selects its public parameters, generates a system master public key and a system master private key based on the public parameters, publishes the public parameters and the system master public key, and keeps the system master private key secret. The vehicle node or TSP generates a pair of first part public keys and first part private keys, and sends its first part public key and real identity identifier to the KGC for registration. The KGC generates a second part private key for the vehicle node or cloud platform, calculates the relevant parameters corresponding to the second part private key, stores the registration information with the real identity identifier, and forwards the relevant parameters to the vehicle node or TSP. The vehicle node or TSP generates its complete private key based on its first part private key and relevant parameters, generates its second part public key based on relevant parameters, and can also calculate and generate its complete public key based on its second part public key and the system master public key.

[0298] When a vehicle node requests communication with a TSP, both the vehicle node and the TSP send a pseudonym request to the KGC. The KGC updates the real identity registration information of the vehicle node or TSP with the pseudonym and sends the pseudonym to the vehicle node or TSP respectively. The TSP sends its pseudonym and second part of its public key to the vehicle node. The vehicle node generates the TSP's complete public key and first authentication information based on the TSP's pseudonym and second part of its public key. Then, the vehicle node sends its pseudonym, second part of its public key, and first authentication information to the TSP. The vehicle node or TSP performs two-way identity authentication based on the vehicle node or TSP's public and private key pair and timestamp. During each communication, the vehicle node or TSP sends a pseudonym request to the KGC to request a change of pseudonym. The KGC sends the new pseudonym to the vehicle node or TSP. If the KGC detects abnormal behavior of the vehicle node or TSP, it revokes its legitimate identity after verification and broadcasts the information to the vehicle node or cloud platform to prevent subsequent insecure communication.

[0299] In some examples, such as Figure 3 As shown, KGC needs to be initialized to determine the public parameters required for authentication between the interactive terminals. These public parameters include KGC's system master public key, etc. Interactive terminals such as vehicle nodes and TSPs can obtain these public parameters from KGC for the calculations involved in authentication.

[0300] KGC chooses large prime numbers p and q, and in the finite field F corresponding to p... p Let an elliptic curve E be defined on the , where the elliptic curve E satisfies (4a) 3 +27b 2 )≠0, and a,b∈F p KGC selects a target point P on the elliptic curve E and generates a cyclic additive group G of order q. KGC then selects a fourth random number. As the system's master private key, calculate P pub =s·P is used as the system's master public key. KGC selects the first hash function H1: {0,1}* →{0,1} n Second hash function The final KGC public parameters are {a, b, q, P, P}. pub H1(·), H2(·)}.

[0301] In some examples, such as Figure 4 As shown, the specific steps of the vehicle node registration process in KGC are as follows:

[0302] 1. Vehicle node selection As its first part of the private key (second private key), calculate As the first part of the public key (the third public key) of the vehicle node, it will then be Send to KGC, where, This serves as the true identity identifier for vehicle nodes;

[0303] 2. KGC selects random numbers As the second part of the private key (the first private key) of the vehicle node, calculate X = ω·P. Final calculation and The first relevant parameter Send to the vehicle node;

[0304] 3. The vehicle node receives the first relevant parameters. Then, calculate For the complete private key of the vehicle node (the first complete private key), calculate This is the second part of the vehicle node's public key (second public key), while the vehicle node's complete public key (second complete public key) is...

[0305] 4. The vehicle node sends a pseudonym request to KGC, and KGC selects a third random number corresponding to the vehicle node. Calculate the kana parameter h = (f + s) mod q, based on h. As the second pseudonym for the vehicle node, Send to the vehicle node;

[0306] 5. Vehicle node received Then, save. This serves as a second pseudonym for subsequent anonymous communication.

[0307] In some examples, such as Figure 5 As shown, the specific steps of the TSP registration process in KGC are as follows:

[0308] 1. TSP Selection As its first part of the private key (fourth private key), calculate As the first part of the public key of the TSP (the fourth public key), it will then be Send to KGC, where This serves as the true identity identifier for TSP;

[0309] 2. KGC selects random numbers As the second part of the TSP's private key (the third private key), calculate X = ω k ·P, Final calculation and The second relevant parameter Send to TSP;

[0310] 3. TSP receives the second relevant parameter Then, calculate Calculate the full private key (second full private key) for the TSP. This is the second part of the TSP public key (the first public key), while the complete public key of the TSP (the first complete public key) is...

[0311] 4. The TSP sends a pseudonym request to the KGC, and the KGC selects a third random number corresponding to the TSP. Calculate the kana parameter h = (f + s) mod q, based on h. As the first katakana of TSP, Send to TSP;

[0312] 5. TSP received Then, save. This serves as the first pseudonym for subsequent anonymous communication.

[0313] In some examples, such as Figure 6 As shown, the specific steps of the two-way authentication key exchange process between the vehicle node and the TSP are as follows:

[0314] The vehicle node requests communication with the TSP. Simultaneously, the vehicle node requests the KGC to generate a second pseudonym, and the TSP requests the KGC to generate a first pseudonym. The KGC sends the generated pseudonyms to both the vehicle node and the TSP. The TSP then sends the first pseudonym... and the first public key Send to the vehicle node;

[0315] Vehicle node calculation And further calculate the first public key coefficient of TSP. Further, the first complete public key of TSP can be obtained. And select the first random number Calculate the first verification value R i =ri P, the first intermediate verification value Second intermediate verification value Further calculate the second verification value C i =H1(S i )⊕k i ,make To generate the first authentication information, the vehicle node will Send to TSP, where T i The second timestamp for sending the first authentication information;

[0316] TSP verifies the first authentication information, first checking the time |T in the first authentication information. j -T i |<ΔT, where T j This is the first timestamp when the TSP receives the message. If the condition is not met, the message is discarded; otherwise, authentication continues. The TSP first calculates the timestamp using the information sent by the vehicle node. Then calculate the second public key coefficient of the vehicle node. Obtain the second complete public key of the vehicle node. Calculate the third intermediate verification value Calculate the fourth intermediate verification value k′ i =H1(Si i )⊕C i Verify whether the first preset relationship is satisfied. If the conditions are met, the TSP successfully authenticates the vehicle node, and the TSP accepts the first verification value R. i Select the second random number Calculate the third intermediate verification value sk ji =r j ·R i Calculate the third verification value R j =r j ·P, calculate the fourth verification value d j =H2(S′) i ||R j ||T j ||sk ji ), TSP will {d j R j T j This information is sent to the vehicle node as the second authentication information.

[0317] Vehicle node verification second authentication information: Inspection time | T i' -T j |<ΔT, where T i' The timestamp for the vehicle node receiving the second authentication information is used. If the condition is not met, the second authentication information is discarded; otherwise, authentication continues. The sixth intermediate verification value sk is calculated. ij=r i ·R j Then, further calculate the seventh verification value d' j =H2(S) i ||R j ||T j ||sk ij Determine whether the first preset relationship d is satisfied. j =d' j If the conditions are met, the authentication is successful.

[0318] In some examples, such as Figure 7 As shown, vehicles using the same pseudonym for an extended period pose a risk of being bound to that pseudonym, compromising identity privacy. Attackers can analyze vehicle information to locate the vehicle. Therefore, periodically changing the pseudonym to reduce the risk of attack is necessary. Before each communication, the vehicle node can request a pseudonym update from the KGC. The specific steps of the process are as follows:

[0319] Before communication begins, the vehicle node requests a change of pseudonym from the KGC.

[0320] After receiving the application, KGC selects a new third random number. Calculate h = (m + s) mod q, and change the new kana. Send to the vehicle node.

[0321] In some examples, such as Figure 8 As shown, both vehicle nodes and TSPs communicate using pseudonyms. If a registered vehicle node or TSP exhibits abnormal behavior, KGC can trace its identity based on the pseudonym of the abnormal vehicle node or TSP. Taking KGC tracing and controlling the identity of vehicle nodes as an example, the specific steps are as follows:

[0322] KGC detected malicious behavior from a vehicle node. KGC found the third random number m corresponding to the vehicle node in the database, calculated h = (m + s) mod q, and used the XOR property to trace its true identity. KGC revokes the legitimate registration of the vehicle node based on the traced real identity and broadcasts the malicious node, rendering it unable to function properly.

[0323] The technical solution disclosed in this embodiment proposes a certificate-free bidirectional authentication scheme for vehicle-to-everything (V2X) communication. This transforms bidirectional authentication from certificate-based to certificate-free authentication, reducing resource consumption for certificate management, mitigating the risk of man-in-the-middle attacks, and better aligning with the limited cloud and communication resources available in vehicles. Certificate-free authentication improves overall system performance and reduces the likelihood of communication failures due to certificate-based authentication failures. This scheme can be applied to bidirectional identity authentication in intelligent vehicle-to-cloud communication.

[0324] The advantages of the technical solution disclosed in this embodiment are as follows:

[0325] First, the pseudonym is not generated and sent to the other party by the vehicle-to-everything (V2X) terminal or roadside unit itself, so there is no risk of maliciously forging pseudonyms for impersonation. The pseudonym used by vehicle nodes and TSPs for identity authentication is generated by KGC, which can determine the integrity of the message and the authenticity of the other party's identity even without a certificate.

[0326] Secondly, the use of timestamps in the authentication information helps prevent replay attacks and avoids the risk of malicious vehicle-to-everything (V2X) terminals replaying authentication messages in the current session. Vehicle nodes and TSPs send timestamps along with the authentication information; if the timestamp is not met, the message is discarded. The TSP verifies the integrity of the message by checking the first authentication information sent by the vehicle node, and the vehicle node calculates the session key and confirms its consistency using the second authentication information returned by the TSP.

[0327] Third, a pseudonym update mechanism is adopted before each communication to reduce the risk of attack and avoid the risk of being bound by the same pseudonym for a long time. In addition, KGC can detect abnormal behavior of vehicle nodes or cloud platforms, trace the real identity corresponding to the abnormal behavior through pseudonyms, revoke the legitimate identity after verification, and broadcast the corresponding vehicle node or cloud platform to ensure the security of the communication process.

[0328] Accordingly, embodiments of this application also provide an electronic device, such as... Figure 9 As shown, Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. The electronic device 1100 further includes a processor 1101 with one or more processing cores, a memory 1102 with one or more computer-readable storage media, and a computer program stored on the memory 1102 and executable on the processor. The processor 1101 and the memory 1102 are electrically connected. Those skilled in the art will understand that the electronic device structure shown in the figure does not constitute a limitation on the electronic device, and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0329] The processor 1101 is the control center of the electronic device 1100. It connects various parts of the electronic device 1100 via various interfaces and lines. By running or loading software programs and / or units stored in the memory 1102, and by calling data stored in the memory 1102, it executes various functions and processes data of the electronic device 1100, thereby providing overall monitoring of the electronic device 1100. The processor 1101 can be a processor (Central Processing Unit, CPU), a graphics processing unit (GPU), a network processor (NP), etc., and can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application.

[0330] In this embodiment, the processor 1101 in the electronic device 1100 loads the instructions corresponding to the processes of one or more applications into the memory 1102 according to the following steps, and the processor 1101 runs the applications stored in the memory 1102 to realize various functions, such as:

[0331] Upon receiving a first pseudonym and a first public key from a second interactive terminal, first authentication information is generated based on the first pseudonym and the first public key.

[0332] The first authentication information, the second pseudonym and the second public key of the first interactive terminal are sent to the second interactive terminal so that the second interactive terminal can perform authentication based on the first authentication information, the second pseudonym and the second public key. The first pseudonym and the second pseudonym are generated by the key management terminals corresponding to the first interactive terminal and the second interactive terminal.

[0333] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.

[0334] Optional, such as Figure 9 As shown, the electronic device 1100 also includes: a touch display screen 1103, a radio frequency circuit 1104, an audio circuit 1105, an input unit 1106, and a power supply 1107. The processor 1101 is electrically connected to the touch display screen 1103, the radio frequency circuit 1104, the audio circuit 1105, the input unit 1106, and the power supply 1107. Those skilled in the art will understand that... Figure 9 The electronic device structure shown does not constitute a limitation on the electronic device and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0335] The touch display screen 1103 can be used to display a graphical user interface (GUI) and receive operation commands generated by the user interacting with the GUI. The touch display screen 1103 may include a display panel and a touch panel. The display panel can be used to display information input by the user or information provided to the user, as well as various graphical user interfaces of the electronic device. These graphical user interfaces can be composed of graphics, text, icons, video, and any combination thereof. Optionally, the display panel can be configured using a liquid crystal display (LCD), organic light-emitting diode (OLED), or other similar technologies. The touch panel can be used to collect touch operations performed by the user on or near it (such as operations performed by the user using a finger, stylus, or any suitable object or accessory on or near the touch panel), generate corresponding operation commands, and execute the corresponding program according to the operation commands. Optionally, the touch panel may include two parts: a touch detection device and a touch controller. The touch detection device detects the user's touch location and the signal generated by the touch operation, transmitting the signal to the touch controller. The touch controller receives touch information from the touch detection device, converts it into touch point coordinates, and sends it to the processor 1101. It can also receive and execute commands from the processor 1101. The touch panel can cover the display panel. When the touch panel detects a touch operation on or near it, it transmits the information to the processor 1101 to determine the type of touch event. Subsequently, the processor 1101 provides corresponding visual output on the display panel based on the type of touch event. In this embodiment, the touch panel and the display panel can be integrated into the touch display screen 1103 to achieve input and output functions. However, in some embodiments, the touch panel and the touch display screen 1103 can be used as two independent components to achieve input and output functions. That is, the touch display screen 1103 can also be used as part of the input unit 1106 to achieve input functions.

[0336] The radio frequency circuit 1104 can be used to transmit and receive radio frequency signals to establish wireless communication with networked medical devices or other electronic devices, and to transmit and receive signals with networked medical devices or other electronic devices.

[0337] Audio circuit 1105 can be used to provide an audio interface between a user and an electronic device via a speaker and a microphone. Audio circuit 1105 can convert received audio data into electrical signals and transmit them to the speaker, where the speaker converts them into sound signals for output. Conversely, the microphone converts the collected sound signals into electrical signals, which are then received by audio circuit 1105, converted back into audio data, and then processed by processor 1101 before being transmitted via radio frequency circuit 1104 to, for example, another electronic device, or output to memory 1102 for further processing. Audio circuit 1105 may also include an earphone jack to provide communication between peripheral headphones and electronic devices.

[0338] The input unit 1106 can be used to receive input numbers, characters, or user characteristic information (such as fingerprints, iris, facial information, etc.), and to generate keyboard, mouse, joystick, optical, or trackball signal inputs related to user settings and function control.

[0339] Power supply 1107 is used to supply power to various components of electronic device 1100. Optionally, power supply 1107 can be logically connected to processor 1101 through a power management device, thereby enabling functions such as charging, discharging, and power consumption management through the power management device. Power supply 1107 may also include one or more DC or AC power supplies, recharging devices, power fault detection circuits, power converters or inverters, power status indicators, and other arbitrary components.

[0340] although Figure 9 As not shown in the diagram, the electronic device 1100 may also include a camera, sensor, wireless fidelity module, Bluetooth module, etc., which will not be described in detail here.

[0341] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0342] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be performed by instructions, or by instructions controlling related hardware. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.

[0343] Therefore, embodiments of this application provide a computer-readable storage medium storing a plurality of computer programs. These computer programs can be loaded by a processor to execute any of the authentication methods provided in this application. The computer program can perform the steps of the following authentication method:

[0344] Upon receiving a first pseudonym and a first public key from a second interactive terminal, first authentication information is generated based on the first pseudonym and the first public key.

[0345] The first authentication information, the second pseudonym and the second public key of the first interactive terminal are sent to the second interactive terminal so that the second interactive terminal can perform authentication based on the first authentication information, the second pseudonym and the second public key. The first pseudonym and the second pseudonym are generated by the key management terminals corresponding to the first interactive terminal and the second interactive terminal.

[0346] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.

[0347] The computer-readable storage medium may include: read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0348] Since the computer-readable storage medium contains a computer program that can implement any of the authentication methods provided in the embodiments of this application, and can execute any of the authentication methods provided in the embodiments of this application, the effects are detailed in the preceding embodiments and will not be repeated here.

[0349] This application also provides a computer program product that can be loaded by a processor to execute any of the authentication methods provided in this application. Specific implementations of each operation of the authentication method can be found in the preceding embodiments and will not be repeated here.

[0350] Since this computer program can execute any of the authentication methods provided in the embodiments of this application, it can achieve the beneficial effects that any of the authentication methods provided in the embodiments of this application can achieve. Therefore, its beneficial effects are detailed in the preceding embodiments and will not be repeated here.

[0351] This application also provides a vehicle that includes any of the above-described electronic devices, computer-readable storage media, computer program products, or performs any of the above-described methods.

[0352] In the description of this application, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more features. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.

[0353] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0354] The embodiments, implementation methods, and related technical features of this application can be combined and substituted for each other without conflict.

[0355] The above are merely preferred embodiments of this application and are not intended to limit this application in any way. Any simple modifications, equivalent changes, and alterations made to the above embodiments based on the technical essence of this application without departing from the scope of the technical solution of this application shall still fall within the scope of the technical solution of this application.

Claims

1. An authentication method, characterized in that, Applied to the first interactive terminal, the authentication method includes: Upon receiving a first pseudonym and a first public key from a second interactive terminal, first authentication information is generated based on the first pseudonym and the first public key. The first authentication information, the second pseudonym and the second public key of the first interactive terminal are sent to the second interactive terminal so that the second interactive terminal can perform authentication based on the first authentication information, the second pseudonym and the second public key. The first pseudonym and the second pseudonym are generated by the key management terminals corresponding to the first interactive terminal and the second interactive terminal.

2. The method as described in claim 1, characterized in that, The step of generating the first authentication information based on the first pseudonym and the first public key includes: Generate the first complete public key for the second interactive terminal based on the first pseudonym and the first public key; The first authentication information is generated based on the first complete public key.

3. The method as described in claim 2, characterized in that, The step of generating the first complete public key for the second interactive terminal based on the first pseudonym and the first public key includes: The first public key coefficient is determined based on the first pseudonym and the public parameters of the key management terminal; The first complete public key of the second interaction terminal is generated based on the first public key coefficient, the first public key, and the system master public key of the key management terminal.

4. The method as described in claim 2, characterized in that, The step of generating the first authentication information based on the first complete public key includes: The first authentication information is generated based on the first complete public key and the first random number.

5. The method as described in claim 4, characterized in that, The step of generating the first authentication information based on the first complete public key and the first random number includes: Based on the first random number and the public parameters of the key management terminal, a first verification value is obtained; Based on the first complete public key and the first pseudonym, the second verification value is obtained; The first authentication information is generated based on the first verification value and the second verification value.

6. The method as described in claim 5, characterized in that, The step of obtaining the second verification value based on the first complete public key and the first pseudonym includes: A first intermediate verification value is generated based on the first complete public key, the first complete private key of the first interactive terminal, and the first random number; and a second intermediate verification value is determined based on the first pseudonym. The second verification value is obtained based on the first intermediate verification value and the second intermediate verification value.

7. The method as described in claim 6, characterized in that, After sending the first authentication information, the second pseudonym, and the second public key of the first interactive terminal to the second interactive terminal, the method further includes: Receive the second authentication information sent by the second interactive terminal; Authentication is performed based on the first random number and the second authentication information.

8. The method as described in claim 7, characterized in that, The authentication based on the first random number and the second authentication information includes: The seventh verification value is determined based on the first random number and the third verification value in the second authentication information; Authentication is performed based on the seventh verification value and the fourth verification value in the second authentication information.

9. The method as described in claim 8, characterized in that, The authentication process based on the seventh verification value and the fourth verification value in the second authentication information includes: If the seventh verification value and the fourth verification value satisfy the first preset relationship, it is determined that the first interactive terminal has successfully authenticated the second interactive terminal.

10. The method as described in claim 8, characterized in that, The step of determining the seventh verification value based on the first random number and the third verification value in the second authentication information includes: Calculate the sixth intermediate verification value based on the first random number and the third verification value in the second authentication information; The seventh verification value is determined based on the first intermediate verification value, the third verification value in the second authentication information, and the sixth intermediate verification value.

11. The method as described in claim 7, characterized in that, The second authentication information includes a first timestamp of the second interactive terminal receiving the first authentication information, and the method further includes: If the first timestamp meets the first preset time condition, authentication is performed based on the first random number and the second authentication information.

12. The method according to any one of claims 1-11, characterized in that, The method further includes: If the conditions for the first pseudonym application are met, a pseudonym application is sent to the key management terminal; The key management terminal receives the second pseudonym returned by the first interaction terminal based on the pseudonym application.

13. The method as described in claim 12, characterized in that, The requirements for applying for the first pseudonym include: The conditions for updating the first preset pseudonym are met, there is a communication requirement with the second interactive terminal, and at least one of the following is received: the first preset pseudonym update condition is met, communication with the second interactive terminal exists, and the first pseudonym request instruction is received.

14. The method as described in claim 12, characterized in that, The second pseudonym is generated by the key management terminal based on the real identity identifier of the first interaction terminal.

15. The method as described in claim 14, characterized in that, Before sending the pseudonym request to the key management terminal, the method further includes: The third public key of the first interactive terminal and the real identity identifier of the first interactive terminal are sent to the key management terminal for registration.

16. The method as described in claim 15, characterized in that, After sending the third public key of the first interactive terminal and the real identity identifier of the first interactive terminal to the key management terminal for registration, the method further includes: The key management terminal receives a first related parameter sent by the key management terminal. The first related parameter is determined by the key management terminal based on the third public key of the first interaction terminal, the system master public key of the key management terminal, and the first private key set by the key management terminal for the first interaction terminal. The first complete private key of the first interactive terminal is determined based on the first relevant parameters.

17. The method as described in claim 16, characterized in that, Determining the first complete private key of the first interactive terminal based on the relevant parameters includes: The first complete private key of the first interactive terminal is determined based on the second private key of the first interactive terminal and the first related parameters.

18. The method as described in claim 16, characterized in that, The method further includes: The second public key of the first interactive terminal is determined based on the first relevant parameters.

19. An authentication method, characterized in that, The authentication method, applied to the second interactive terminal, includes: Receive the first authentication information sent by the first interactive terminal, as well as the second pseudonym and the second public key of the first interactive terminal; Authentication is performed based on the second pseudonym, the second public key, and the first authentication information.

20. The method as described in claim 19, characterized in that, The authentication process based on the second pseudonym, the second public key, and the first authentication information includes: Based on the second pseudonym and the second public key, generate the second complete public key for the first interactive terminal; Authentication is performed based on the second complete public key and the first authentication information.

21. The method as described in claim 20, characterized in that, The step of generating the second complete public key for the first interactive terminal based on the second pseudonym and the second public key includes: The second public key coefficient is determined based on the second pseudonym and the public parameters of the key management terminal; The second complete public key of the first interaction terminal is generated based on the second public key coefficient, the second public key, and the system master public key of the key management terminal.

22. The method as described in claim 20, characterized in that, The authentication process based on the second complete public key and the first authentication information includes: The third intermediate verification value is obtained based on the second complete public key, the first verification value in the first authentication information, and the second complete private key of the second interactive terminal; A fourth intermediate verification value is obtained based on the third intermediate verification value and the second verification value in the first authentication information; The second interaction terminal authenticates the first interaction terminal based on the fourth intermediate verification value.

23. The method as described in claim 22, characterized in that, The step of authenticating the first interaction terminal by the second interaction terminal based on the fourth intermediate verification value includes: If the relationship between the fourth intermediate verification value, the second complete public key, the public parameters of the key management terminal, and the first verification value in the first authentication information satisfies the second preset relationship, it is determined that the second interaction terminal has successfully authenticated the first interaction terminal.

24. The method as described in claim 23, characterized in that, After determining that the second interactive terminal has successfully authenticated the first interactive terminal, the process further includes: Based on the first verification value in the first authentication information, generate the second authentication information; The second authentication information is sent to the first interactive terminal so that the first interactive terminal can authenticate the second interactive terminal.

25. The method as described in claim 24, characterized in that, The step of generating second authentication information based on the first verification value in the first authentication information includes: The second authentication information is generated based on the second random number and the first verification value.

26. The method as described in claim 25, characterized in that, The generation of second authentication information based on the second random number and the first verification value includes: Based on the second random number and the public parameters of the key management terminal, a third verification value is obtained; A fourth verification value is generated based on the second random number and the first verification value in the first authentication information; The second authentication information is generated based on the third verification value and the fourth verification value.

27. The method as described in claim 26, characterized in that, The step of generating a fourth verification value based on the second random number and the first verification value in the first authentication information includes: Based on the second random number and the first verification value in the first authentication information, a fifth intermediate verification value is obtained; The fourth verification value is generated based on the third intermediate verification value, the third verification value, and the fifth intermediate verification value.

28. The method as described in claim 20, characterized in that, The first authentication information also includes a second timestamp of the first authentication information sent by the first interactive terminal, and the method further includes: If the second timestamp meets the second preset time condition, authentication is performed based on the second pseudonym, the second public key, and the first authentication information.

29. The method as described in claim 20, characterized in that, Before receiving the first authentication information sent by the first interactive terminal, and the second pseudonym and second public key of the first interactive terminal, the process further includes: When there is a communication requirement with the first interactive terminal, the first pseudonym and the first public key of the second interactive terminal are sent to the first interactive terminal so that the first interactive terminal generates the first authentication information based on the first pseudonym and the first public key.

30. The method as described in claim 29, characterized in that, Before sending the first pseudonym and first public key of the second interactive terminal to the first interactive terminal, the method further includes: If the conditions for applying for a second pseudonym are met, a pseudonym application is sent to the key management terminal; The key management terminal receives the first pseudonym returned by the second interaction terminal based on the pseudonym application.

31. The method as described in claim 30, characterized in that, The requirements for applying for a second pseudonym include: The conditions include at least one of the following: reaching the second preset kana update time, having a communication requirement with the first interactive terminal, and receiving a second kana request instruction.

32. The method as described in claim 30, characterized in that, The first pseudonym is generated by the key management terminal based on the real identity identifier of the second interaction terminal.

33. The method as described in claim 32, characterized in that, Before sending the pseudonym request to the key management terminal, the method further includes: The fourth public key of the second interaction terminal and the real identity identifier of the second interaction terminal are sent to the key management terminal for registration.

34. The method as described in claim 33, characterized in that, After sending the fourth public key of the second interaction terminal and the real identity identifier of the second interaction terminal to the key management terminal for registration, the method further includes: The key management terminal receives a second related parameter sent by the key management terminal. The second related parameter is determined by the key management terminal based on the fourth public key of the second interaction terminal, the system master public key of the key management terminal, and the third private key set by the key management terminal for the second interaction terminal. The second complete private key of the second interactive terminal is determined based on the second relevant parameters.

35. The method as described in claim 34, characterized in that, Determining the first complete private key of the first interactive terminal based on the second relevant parameters includes: The second complete private key of the second interactive terminal is determined based on the fourth private key of the second interactive terminal and the second related parameters.

36. The method as described in claim 34, characterized in that, The method further includes: The first public key of the second interactive terminal is determined based on the second relevant parameters.

37. An authentication method, characterized in that, Applied to a key management terminal, the method includes: Upon receiving a pseudonym request from the interactive terminal, a pseudonym for the interactive terminal is generated based on the real identity identifier corresponding to the interactive terminal. The pseudonym is sent to the interactive terminal, wherein the interactive terminal includes a first interactive terminal and / or a second interactive terminal, and the pseudonym of the interactive terminal includes the second pseudonym of the first interactive terminal and / or the first pseudonym of the second interactive terminal.

38. The method as described in claim 37, characterized in that, The real identity identifier corresponding to the interactive terminal generates the pseudonym of the interactive terminal, including: The pseudonym parameter is determined based on the system master private key of the key management terminal and the third random number corresponding to the interaction terminal. The pseudonym for the interactive terminal is generated based on the pseudonym parameters and the real identity identifier corresponding to the interactive terminal.

39. The method as described in claim 38, characterized in that, The method further includes: If a target interactive terminal with abnormal behavior is detected in the interactive terminal, a third random number corresponding to the target interactive terminal and the pseudonym of the target interactive terminal are obtained to determine the real identity of the target interactive terminal. The target interactive terminal is monitored based on its real identity identifier.

40. The method as described in claim 39, characterized in that, The regulatory operations include: Cancel the registration of the target interactive terminal and / or broadcast that the target interactive terminal has abnormal behavior.

41. The method as described in claim 37, characterized in that, The method further includes: Determine the target point on the elliptic curve; The system master public key of the key management terminal is determined based on the target point.

42. The method as described in claim 41, characterized in that, The method further includes: The system master public key of the key management terminal is determined based on the system master private key of the key management terminal and the target point.

43. An electronic device, characterized in that, The device includes a processor connected to a memory storing a computer program, the processor being configured to run the computer program in the memory to perform the authentication method according to any one of claims 1 to 42.

44. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the authentication method according to any one of claims 1 to 42.

45. A computer program product, characterized in that, It includes a computer program that is executed by a processor to implement the authentication method according to any one of claims 1 to 42.

46. ​​A vehicle, characterized in that, The vehicle performs the authentication method as described in any one of claims 1 to 42, or includes the electronic device as described in claim 43.