Threshold anonymous pass method

By introducing threshold and tagging mechanisms into the distributed identity authentication system, decentralized issuance and verification of anonymous tokens are achieved, solving the balance problem between user privacy protection and access control, and improving the security and applicability of the system.

CN121125117APending Publication Date: 2025-12-12XIAN UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511435977.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-09
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Existing anonymous token methods lack threshold control mechanisms in distributed identity authentication systems, pose a risk of centralization, and struggle to balance user privacy protection and access control in a decentralized architecture, thus failing to meet the diverse needs of business scenarios.

Method used

A threshold mechanism is adopted to distribute the signature key across multiple issuers. Combined with a tagging mechanism, a unique private attribute and message tag are generated for each user. Through multi-node collaboration, a blinded anonymous token is generated, thereby achieving decentralized token issuance and verification.

Benefits of technology

It enhances the system's resistance to attacks and fault tolerance, ensures the coordinated protection of user anonymity and access control, adapts to multi-party collaboration and cross-domain authentication scenarios, and supports business needs such as pay-per-use and time-limited access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125117A_ABST
    Figure CN121125117A_ABST
Patent Text Reader

Abstract

The invention specifically discloses a threshold anonymous token passing method, and relates to the technical field of identity authentication. The method comprises the following steps: establishing an identity authentication system and generating system parameters; generating a secret key of an issuer; generating a user key; an anonymous token is requested, the user interacts with an issuer, the anonymous token is requested to be acquired, and the user additionally generates a label about a unique private attribute and messages of the user to limit that each message of each user can only acquire one token; issuing the anonymous token, and generating a blind anonymous token after the issuer verifies the correctness of the tag; gathering blind anonymous passwords by the user; the user verifies the correctness of the aggregated anonymous token and de-blinding the aggregated anonymous token; and the verifier verifies the anonymous token. According to the method, decentralized issuing and verification of the anonymous token in a distributed environment are realized, and the problems that authority control and user anonymity are difficult to coordinate and privacy protection and access control are difficult to balance in a decentralized architecture are effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of identity authentication, and particularly relates to a threshold anonymous token method. BACKGROUND

[0002] With the vigorous development of digital economy and the increasing awareness of user privacy protection, anonymous authentication and access control technology has become a key requirement in many fields such as online payment, electronic voting, Internet of Things access, and blockchain systems. The core task of such technology is to accurately verify the user's access rights or use qualifications while fully protecting the user's privacy from being leaked. Therefore, the anonymous token (Anonymous Token) scheme based on the principle of cryptography has gradually become a research hotspot focused by both academia and industry.

[0003] In the past technical exploration, the existing schemes have shown certain advantages, but also exposed many limitations. Some technical schemes (such as the Privacy Pass scheme) can achieve anonymous identity verification and reduce the verification frequency in access control, but due to the lack of effective speed limiting mechanism, attackers can easily initiate denial of service attacks by hoarding tokens, which poses a serious threat to the usability of the system and greatly affects the stable operation of the system and user experience. Some other extended technical schemes (such as the PMB Tokens protocol) introduce a fraud detection mechanism while enhancing the user's privacy protection capability, trying to embed verifiable information on the basis of maintaining anonymity to improve the tracking ability of malicious behavior. However, these schemes still fail to fundamentally solve the core architectural problem, and in the face of complex and changing network environments and growing security challenges, existing technologies have been unable to effectively cope with them. The anonymous counting token scheme, although it supports users to apply for blinded tokens for specific messages and can limit each message to obtain at most one token, to a certain extent, it realizes the limit control of token issuance, and guarantees anonymity, but in actual application scenarios, its limitations have gradually emerged, and it is difficult to meet the diversified business needs and complex security requirements.

[0004] At present, most anonymous token methods generally rely on a single entity, such as a centralized authentication server, to fully take charge of the generation and verification of tokens. This traditional architecture has many key problems that cannot be ignored: Threshold control mechanism is missing: once the authentication server is attacked and compromised or exhibits malicious operation behavior, the token will face a high risk of abuse, and the user's rights will also be leaked, which undoubtedly poses a fatal threat to system security, which may lead to illegal acquisition of user information, malicious occupation of resources, and other serious consequences.

[0005] The high level of centralization risk stems from the single-point issuance and verification mechanism, which makes the entire system overly reliant on the server, making it a prime target for attackers. Furthermore, this architecture lacks effective fault tolerance for server failures or malicious behavior. In complex scenarios involving multi-party collaboration or cross-domain authentication, its scalability and resilience are significantly insufficient, making it unable to flexibly adapt to authorization requirements in different scenarios and unable to support decentralized operations. This severely restricts the system's application and promotion in large-scale, complex environments.

[0006] Application scenarios are severely limited: Some solutions cannot effectively limit the number of times or the amount of token usage, making it difficult to meet the needs of actual business scenarios such as pay-per-use and time-limited access. This greatly hinders their widespread application and further development in the business field, and fails to provide solutions that meet the actual needs of enterprises and users.

[0007] In summary, current distributed identity authentication systems suffer from problems such as a lack of threshold control mechanisms, significant centralization risks, and insufficient access control capabilities, making it difficult to balance user privacy protection and access control needs under a decentralized architecture. Summary of the Invention

[0008] The purpose of this invention is to propose a threshold-based anonymous token method to address the problem of ineffective balance between user privacy protection and access control in distributed identity authentication systems. This method ensures that user privacy is fully protected while endowing the system with reasonable and effective access control capabilities, thereby successfully achieving a perfect balance between privacy protection and access control.

[0009] To achieve the above objectives, this invention proposes a threshold-based anonymous token method, the steps of which are as follows: Step S1: Establish an identity authentication system and generate publicly available system parameters; Step S2: Generate the issuer key based on the encryption algorithm and secret sharing; Step S3: Generate user keys based on the commitment algorithm; Step S4: The user interacts with the issuer to request an anonymous token, and at the same time, the user generates a unique private attribute. With message Tags; Step S5: Issue anonymous tokens. After the issuer verifies the correctness of the tag, a blinded anonymous token is generated. Step S6: User aggregation and blinding of anonymous tokens; Step S7: The user verifies the correctness of the aggregated anonymous tokens and performs deblinding. Step S8: The verifier verifies the anonymous token.

[0010] Preferably, in step S1, the specific steps for generating the publicly available system parameters are as follows: Step S11: Given security parameters The generation order is Cyclic group Select Cyclic group Generators; Step S12: Set up bilinear mapping , recorded as ;in, Let be the set of parameters for a bilinear mapping. To and Multiplicative cyclic groups of the same order, It is a bilinear mapping function; Step S13: Generate extractable commitment parameters, as follows: Randomly select two prime number of bits ,calculate: , , ; in, prime number The binary length, and It is a prime number; Select random number ,calculate: ; , and ; Select random number Calculate public parameters : ; The publicly available parameters for extractable commitments are: ; The trapdoor parameters for extractable commitments are: ; in, For publicly available parameters that can be extracted from commitments, For large prime numbers, For publicly available parameters that can be extracted from commitments, For the modulo operator, To conduct The result of the multiplication operation For model multiplication group From arrive The set of integers, Cryptographic symbols, For publicly available parameters that can be extracted from commitments, For trapdoor parameters that can be extracted from commitments; Step S14, Generate Commitment parameters, select random number ;in, For model The multiplication group; Step S15: Output system public parameters .

[0011] Preferably, in step S2, based on the encryption algorithm The specific steps for generating and secretly sharing the issuer's key are as follows: Step S21: Given threshold parameters ,generate The encryption parameters are as follows: Select random number ,calculate: ; , and ; Select random number Calculate the public parameters: ; The public parameters for encryption are: ; The private parameters are: ; in, t The minimum number of participants required to restore the secret n The total number of participants. These are the public parameters of the CS encryption algorithm. These are the public parameters of the CS encryption algorithm. To conduct The result of the second group operation For the issuer The public key for the corresponding CS encryption algorithm, To conduct The result of the second group operation For the issuer The corresponding publicly available parameters of the CS encryption algorithm, For the issuer The corresponding CS encryption algorithm private key; Step S22: Randomly select a secret value ,calculate , ;in, For module group The set of integers of order 1. secret value The corresponding public parameters, secret value The corresponding public parameters, , It is a secret value; Step S23, Generate Secret Shares , ,based on The secret of individual share restructuring ;in, secret value of A secret shared share, secret value of A secret shared share; Step S24, Encryption The formula is as follows: ; in, , From Random numbers selected uniformly from the middle, From arrive The set of integers, To use the CS encryption algorithm for secret shares The result of encryption, This is a representation of the CS encryption algorithm; encryption The formula is as follows: ; in, , From Random numbers selected uniformly from the middle, To use the CS encryption algorithm for secret shares The result of encryption; Step S25, Output the issuer public key issuer private key .

[0012] Preferably, in step S3, a user key is generated, and the specific steps are as follows: Step S31: Randomly select a key ;in, From A randomly selected key that is uniformly chosen from the data. For model The set of integers; Step S32, Generate Commitment value: ; in, , From Random numbers selected uniformly from the middle, for The value of the commitment; Step S33: Set the user's public key as The user's private key is .

[0013] Preferably, in step S4, the specific steps for obtaining the anonymous token are as follows: Step S41: Calculate the message promise ,in, , From Random numbers selected uniformly from the middle; Step S42: Calculate the evaluation value using the pseudo-random function PRF as the user's response to the message. The label formula is as follows: ; in, For users to message Tags; calculate The corresponding zero-knowledge proof formula is as follows: ; in, for The corresponding zero-knowledge proof, For existence symbols, A representation method for zero-knowledge proofs; Step S43, Select Each awardee ,in, Generate random numbers And calculate Commitment value: ; in, , From Random numbers selected uniformly from the middle, Selected by the user A collection of issuers, For random numbers The value of the commitment; Step S44: Calculate the anonymous token request, as follows: Select random number , ,calculate The ciphertext: ; in, The blinding value for the message. To use the CS encryption algorithm to The result of encryption; calculate The ciphertext: ; in, For server The blinding value, To use the CS encryption algorithm to The result of encryption, For the issuer Public parameters, For the issuer Public parameters; calculate and Commitment value: ; ; in, for The value of the commitment, for The value of the commitment, From Random numbers selected uniformly from the middle, From Random numbers selected uniformly from the middle; make , ,calculate and The commitment value is calculated, and the corresponding zero-knowledge proof is generated, as shown in the following formula: ; ; ; in, , for The calculation results for The calculation results From Random numbers selected uniformly from the middle, From Random numbers selected uniformly from the middle, The zero-knowledge proof corresponding to the anonymous token request. for The value of the commitment, for The value of the commitment; Step S45: Output anonymous token request .

[0014] Preferably, in step S5, the specific steps are as follows: Step S51: Verify zero-knowledge proof and If the verification fails, the process will terminate. Step S52, through the issuer The calculation of blinded tokens is as follows: calculate , ,make ;in, For the issuer Received CS decryption results For Lagrange coefficients; Random selection ,calculate and It satisfies the following formula: ; ; in, From Random numbers selected uniformly from the middle, For the issuer The share held, For the issuer The share held, for The zero element; calculate , Using the shared conversion protocol with the issuer Secret Exchange and The information is returned. and ;in, For the issuer With the issuer The return value obtained from the interaction For the issuer With the issuer The return value obtained from the interaction; calculate: ; ; in, , For the issuer The generated blinded token, For the issuer The results obtained through calculation For the issuer The shareholding; Step S53: Output blinded anonymous tokens And save the tags Go to the corresponding tag list.

[0015] Preferably, in step S6, the specific steps are as follows: Step S61, Aggregation Partial blinded tokens: ; in, For the aggregated blinded token; Step S62: Output the aggregated blinded token .

[0016] Preferably, in step S7, the specific steps are as follows: Step S71: Verify the correctness of the tokens. If they are not equal, the process terminates. The formula is as follows: ; Step S72: Deblind the token to obtain the final token: ; Step S73: Set the token as and output .

[0017] Preferably, in step S8, the verifier verifies the anonymous token, specifically: if If the verification is successful, output 1 and return the required resources or permissions to the user; if they are not equal, the verification fails and output 0, rejecting the user's request.

[0018] Therefore, this invention proposes a threshold-based anonymous token method, which has the following beneficial effects: (1) By introducing a threshold mechanism into the token issuance process, the present invention distributes and manages the signature key among multiple issuers, avoiding the risk of a single entity controlling all permissions, effectively preventing single point of failure and trust concentration problems, and greatly improving the system's anti-attack capability and fault tolerance.

[0019] (2) This invention innovatively proposes a tagging mechanism. The tag attached by the user when requesting a token is generated jointly by the user's unique private attribute and the message. This can accurately limit the number of times each user can request tokens for the same message (avoiding abuse) and ensure that the issuer cannot associate the token with a specific user's identity. The user's identity information is not leaked throughout the entire interaction process, achieving a synergistic guarantee of anonymity and access control.

[0020] (3) The present invention adopts a decentralized token issuance and verification architecture, which eliminates the dependence on centralized servers and can flexibly support multi-party collaboration or cross-domain authentication scenarios. Through the threshold collaboration mechanism, each participant can complete token generation and verification in a distributed manner, which improves the scalability and elasticity of the system and meets the actual application needs of decentralized services.

[0021] (4) The present invention combines the tag mechanism and the token verification logic, which can effectively limit the request frequency and usage of tokens, preventing attackers from launching denial-of-service attacks by hoarding tokens, and can also be adapted to commercial scenarios such as pay-per-use and time-limited access, thus enhancing the applicability and controllability of the method in actual business.

[0022] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0023] Figure 1 This is a model diagram of a threshold-based anonymous token method according to the present invention; Figure 2 This is a flowchart of a threshold-based anonymous token method according to the present invention. Detailed Implementation

[0024] To make the technical solutions, advantages, and objectives of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below. The described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the described embodiments of the present invention without creative effort are within the protection scope of the present invention.

[0025] Unless otherwise defined, the technical or scientific terms used in this invention shall have the ordinary meaning as understood by one of ordinary skill in the art to which this invention pertains.

[0026] Example likeFigure 1 The diagram shown is a model of a threshold-based anonymous token method according to the present invention, which includes three entities: issuer, user, and verifier. Arrows indicate sending messages, double arrows indicate information exchange between the two parties, and sequence numbers indicate execution steps.

[0027] The system first completes the initialization process and generates a complete set of system parameters. Based on the system parameters, the system generates the keys required for token issuance and distributes them to each issuer. Users simultaneously generate their own key pairs to provide basic support for subsequent token request operations.

[0028] When an anonymous token needs to be applied for, the user sends a request to the issuer, along with a tag generated by their own unique key and the target message. This tag implicitly binds the requester's identity and strictly limits each user to obtaining only one token for the same message, effectively preventing the risk of abuse.

[0029] After verifying the validity of the tag, the issuer exchanges secure information with other issuers. Once the information synchronization is complete, each issuer generates blinded anonymous token shares for the user. After the user collects a sufficient number of shares, they are aggregated. After verifying the correctness of the aggregated tokens, a deblinding operation is performed, ultimately resulting in a usable anonymous token.

[0030] When a user needs to obtain specific permissions or resources, they submit an anonymous token to a validator. The validator verifies the validity of the token, and if the verification is successful, the validator grants the user the corresponding access permission or resource access qualification.

[0031] like Figure 2 The diagram shows a flowchart of a threshold-based anonymous token method according to the present invention. The specific steps are as follows: S1. Establish an identity authentication system and generate publicly available system parameters; the specific steps for generating publicly available system parameters are as follows: S11, Given security parameters The generation order is Cyclic group Select Cyclic group Generators; Step S12: Set up bilinear mapping , recorded as ;in, Let be the set of parameters for a bilinear mapping. To and Multiplicative cyclic groups of the same order, It is a bilinear mapping function; S13. Generate extractable commitment parameters, as follows: Randomly select two prime number of bits ,calculate: , , ; in, prime number The binary length, and It is a prime number; Select random number ,calculate: ; , and ; Select random number Calculate public parameters : ; The publicly available parameters for extractable commitments are: ; The trapdoor parameters for extractable commitments are: ; in, For publicly available parameters that can be extracted from commitments, For large prime numbers, For publicly available parameters that can be extracted from commitments, For the modulo operator, To conduct The result of the multiplication operation For model multiplication group From arrive The set of integers, Cryptographic symbols, For publicly available parameters that can be extracted from commitments, For trapdoor parameters that can be extracted from commitments; S14, Generation Commitment parameters, select random number ;in, For model The multiplication group; S15, Output System Public Parameters .

[0032] S2. Generate the issuer key based on the Camenisch-Shoup (CS) encryption algorithm and Shamir secret sharing. The specific steps are as follows: S21. Given threshold parameters ,generate The encryption parameters are as follows: Select random number ,calculate: ; , and ; Select random number Calculate the public parameters: ; The public parameters for encryption are: ; The private parameters are: ; in, t The minimum number of participants required to restore the secret n The total number of participants. These are the public parameters of the CS encryption algorithm. These are the public parameters of the CS encryption algorithm. To conduct The result of the second group operation For the issuer The public key for the corresponding CS encryption algorithm, To conduct The result of the second group operation For the issuer The corresponding publicly available parameters of the CS encryption algorithm, For the issuer The corresponding CS encryption algorithm private key; S22, Randomly select a secret value ,calculate , ;in, For module group The set of integers of order 1. secret value The corresponding public parameters, secret value The corresponding public parameters, , It is a secret value; S23, Generation Secret Shares , ,based on The secret of individual share restructuring ;in, secret value of A secret shared share, secret value of A secret shared share; S24, Encryption The formula is as follows: ; in, , From Random numbers selected uniformly from the middle, From arrive The set of integers, To use the CS encryption algorithm for secret shares The result of encryption, This is a representation of the CS encryption algorithm; encryption The formula is as follows: ; in, , From Random numbers selected uniformly from the middle, To use the CS encryption algorithm for secret shares The result of encryption; S25, Output Issuer public key issuer private key .

[0033] S3. Generate the user key based on the commitment algorithm. The specific steps are as follows: S31. Randomly select a key ;in, From A randomly selected key that is uniformly chosen from the data. For model The set of integers; S32, Generation Commitment value: ; in, , From Random numbers selected uniformly from the middle, for The value of the commitment; S33. Set the user's public key as follows The user's private key is .

[0034] S4. The user interacts with the issuer to request an anonymous token, and at the same time, the user generates unique private attributes. With message The tags; the specific steps to obtain the anonymous token are as follows: S41, Calculation Message promise ,in, , From Random numbers selected uniformly from the middle; S42. Calculate the evaluation value using the pseudo-random function PRF as the user's response to the message. The label formula is as follows: ; in, For users to message Tags; calculate The corresponding zero-knowledge proof formula is as follows: ; in, for The corresponding zero-knowledge proof, For existence symbols, A representation method for zero-knowledge proofs; S43, Selection Each awardee ,in, Generate random numbers And calculate Commitment value: ; in, , From Random numbers selected uniformly from the middle, Selected by the user A collection of issuers, For random numbers The value of the commitment; S44. Calculate the anonymous token request, as follows: Select random number , ,calculate The ciphertext: ; in, The blinding value for the message. To use the CS encryption algorithm to The result of encryption; calculate The ciphertext: ; in, For server The blinding value, To use the CS encryption algorithm to The result of encryption, For the issuer Public parameters, For the issuer Public parameters; calculate and Commitment value: ; ; in, for The value of the commitment, for The value of the commitment, From Random numbers selected uniformly from the middle, From Random numbers selected uniformly from the middle; make , ,calculate and The commitment value is calculated, and the corresponding zero-knowledge proof is generated, as shown in the following formula: ; ; ; in, , for The calculation results for The calculation results From Random numbers selected uniformly from the middle, From Random numbers selected uniformly from the middle, The zero-knowledge proof corresponding to the anonymous token request. for The value of the commitment, for The value of the commitment; S45, Output Anonymous Token Request .

[0035] S5. Issue anonymous tokens. After verifying the correctness of the tag, the issuer generates blinded anonymous tokens. The specific steps are as follows: S51, Verifying Zero-Knowledge Proofs and If the verification fails, the process will terminate. S52, through the issuer The calculation of blinded tokens is as follows: calculate , ,make ;in, For the issuer Received CS decryption results For Lagrange coefficients; Random selection ,calculate and It satisfies the following formula: ; ; in, From Random numbers selected uniformly from the middle, For the issuer The share held, For the issuer The share held, for The zero element; calculate , Using the shared conversion protocol with the issuer Secret Exchange and The information is returned. and ;in, For the issuer With the issuer The return value obtained from the interaction For the issuer With the issuer The return value obtained from the interaction; calculate: ; ; in, , For the issuer The generated blinded token, For the issuer The results obtained through calculation For the issuer The shareholding; S53, Output blinded anonymous tokens And save the tags Go to the corresponding tag list.

[0036] S6. User-aggregated blinded anonymous tokens, the specific steps are as follows: S61, Aggregation Partial blinded tokens: ; in, For the aggregated blinded token; S62, Blinding Tokens for Output Aggregation .

[0037] S7. Users verify the correctness of the aggregated anonymous tokens and perform deblinding. The specific steps are as follows: S71. Verify the correctness of the tokens. If they are not equal, the process terminates. The formula is as follows: ; S72, Deblind the token to obtain the final token: ; S73, Set the token as and output .

[0038] S8. The validator verifies the anonymous token, specifically as follows: if If the verification is successful, output 1 and return the required resources or permissions to the user; if they are not equal, the verification fails and output 0, rejecting the user's request.

[0039] This invention effectively avoids single points of failure and trust concentration risks by distributing threshold key signing keys across multiple issuer nodes, significantly improving the system's robustness and security level. Simultaneously, it innovatively designs a tagging mechanism, allowing users to flexibly limit the number of token requests for any message, and ensuring that issuers cannot associate tokens with specific user identities, thus strengthening user anonymity protection from a technical perspective. The specific operation process is as follows: First, the system is initialized, generating a complete set of basic parameters. Then, key pairs are generated for multiple issuers. When a user initiates an anonymous token request, they must interact with the issuer and attach a specific tag—this tag is calculated using the message content and the user's key, and is associated only with the user and the request message, precisely limiting the number of token requests a single user can make for the same message. Upon receiving the request, the issuer first verifies the tag and the validity of the request, then generates a blinded anonymous token share through multi-node collaborative calculation and returns it to the user. Once the user has collected at least a threshold number of token shares, and after verification, aggregation and deblinding are performed to generate a complete, usable anonymous token. In the subsequent identity authentication process, the user submits this token for verification by a validator; successful verification grants the user the corresponding service resources or access permissions.

[0040] The threshold-based anonymous token method proposed in this invention is primarily used for privacy-preserving identity authentication. Besides its application in anonymous authentication, this method has a wide range of applications. For example, in e-government and electronic voting systems, users need to complete a one-time authentication operation without revealing their real identity. This method ensures that each voter can only vote once, and the voting behavior cannot be associated with their identity. In anonymous subscription and metered payment services, such as online journal reading and digital resource access, users can anonymously obtain access rights and be subject to restrictions on the number of accesses or time limits, thus achieving pay-as-you-go rather than account-bound billing. Furthermore, in scenarios such as intelligent transportation, smart cities, and the Internet of Things, this method can be used to control threshold access for users or devices. Devices or users can only enter the system or enjoy services after obtaining a sufficient number of authentication tokens, and the entire process does not require the exposure of real identity information. In blockchain and digital asset trading scenarios, threshold-based anonymous tokens can also be used to enhance transaction privacy and controllability, prevent the same anonymous identity from excessively using resources or frequently performing operations, and reduce the risk of system abuse.

[0041] It is worth noting that all contents not described in detail in this invention are existing technologies and are well known to those skilled in the art.

[0042] Therefore, this invention provides a threshold-based anonymous token method, which successfully realizes decentralized issuance and verification of anonymous tokens based on a threshold mechanism in a distributed identity authentication system. Throughout the process, the issuer cannot obtain the user's identity information, fundamentally solving the problem that existing identity authentication systems in a decentralized architecture are difficult to coordinate with access control and user anonymity, and cannot effectively balance privacy protection and access control.

[0043] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the technical solutions of the present invention, and these modifications or equivalent substitutions cannot cause the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.

Claims

1. A threshold-based anonymous token method, characterized in that, The steps are as follows: Step S1: Establish an identity authentication system and generate publicly available system parameters; Step S2: Generate the issuer key based on the encryption algorithm and secret sharing; Step S3: Generate user keys based on the commitment algorithm; Step S4: The user interacts with the issuer to request an anonymous token, and at the same time, the user generates a unique private attribute. With message Tags; Step S5: Issue anonymous tokens. After the issuer verifies the correctness of the tag, a blinded anonymous token is generated. Step S6: User aggregation and blinding of anonymous tokens; Step S7: The user verifies the correctness of the aggregated anonymous tokens and performs deblinding. Step S8: The verifier verifies the anonymous token.

2. The threshold-based anonymous token method according to claim 1, characterized in that, In step S1, the specific steps for generating the publicly available system parameters are as follows: Step S11: Given security parameters The generation order is Cyclic group Select Cyclic group Generators; Step S12: Set up bilinear mapping , recorded as ;in, Let be the set of parameters for a bilinear mapping. To and Multiplicative cyclic groups of the same order, It is a bilinear mapping function; Step S13: Generate extractable commitment parameters, as follows: Randomly select two prime number of bits ,calculate: , , ; in, prime number The binary length, and It is a prime number; Select random number ,calculate: ; , and ; Select random number Calculate public parameters : ; The publicly available parameters for extractable commitments are: ; The trapdoor parameters for extractable commitments are: ; in, For publicly available parameters that can be extracted from commitments, For large prime numbers, For publicly available parameters that can be extracted from commitments, For the modulo operator, To conduct The result of the multiplication operation For model multiplication group From arrive The set of integers, Cryptographic symbols, For publicly available parameters that can be extracted from commitments, For trapdoor parameters that can be extracted from commitments; Step S14, Generate Commitment parameters, select random number ;in, For model The multiplication group; Step S15: Output system public parameters .

3. The threshold-based anonymous token method according to claim 2, characterized in that, In step S2, based on the encryption algorithm The specific steps for generating and secretly sharing the issuer's key are as follows: Step S21: Given threshold parameters ,generate The encryption parameters are as follows: Select random number ,calculate: ; , and ; Select random number Calculate the public parameters: ; The public parameters for encryption are: ; The private parameters are: ; in, t The minimum number of participants required to restore the secret n The total number of participants. These are the public parameters of the CS encryption algorithm. These are the public parameters of the CS encryption algorithm. To conduct The result of the second group operation For the issuer The public key for the corresponding CS encryption algorithm, To conduct The result of the second group operation For the issuer The corresponding publicly available parameters of the CS encryption algorithm, For the issuer The corresponding CS encryption algorithm private key; Step S22: Randomly select a secret value ,calculate , ;in, For module group The set of integers of order 1. secret value The corresponding public parameters, secret value The corresponding public parameters, , It is a secret value; Step S23, Generate Secret Shares , ,based on The secret of individual share restructuring ;in, secret value of A secret shared share, secret value of A secret shared share; Step S24, Encryption The formula is as follows: ; in, , From Random numbers selected uniformly from the middle, From arrive The set of integers, To use the CS encryption algorithm for secret shares The result of encryption, This is a representation of the CS encryption algorithm; encryption The formula is as follows: ; in, , From Random numbers selected uniformly from the middle, To use the CS encryption algorithm for secret shares The result of encryption; Step S25, Output the issuer public key issuer private key .

4. The threshold-based anonymity token method according to claim 3, characterized in that, In step S3, the user key is generated, and the specific steps are as follows: Step S31: Randomly select a key ;in, From A randomly selected key that is uniformly chosen from the data. For model The set of integers; Step S32, Generate Commitment value: ; in, , From Random numbers selected uniformly from the middle, for The value of the commitment; Step S33: Set the user's public key as The user's private key is .

5. The threshold-based anonymous token method according to claim 4, characterized in that, In step S4, the specific steps for obtaining the anonymous token are as follows: Step S41: Calculate the message promise ,in, , From Random numbers selected uniformly from the middle; Step S42: Calculate the evaluation value using the pseudo-random function PRF as the user's response to the message. The label formula is as follows: ; in, For users to message Tags; calculate The corresponding zero-knowledge proof formula is as follows: ; in, for The corresponding zero-knowledge proof, For existence symbols, A representation method for zero-knowledge proofs; Step S43, Select Each awardee ,in, Generate random numbers And calculate Commitment value: ; in, , From Random numbers selected uniformly from the middle, Selected by the user A collection of issuers, For random numbers The value of the commitment; Step S44: Calculate the anonymous token request, as follows: Select random number , ,calculate The ciphertext: ; in, The blinding value for the message. To use the CS encryption algorithm to The result of encryption; calculate The ciphertext: ; in, For server The blinding value, To use the CS encryption algorithm to The result of encryption, For the issuer Public parameters, For the issuer Public parameters; calculate and Commitment value: ; ; in, for The value of the commitment, for The value of the commitment, From Random numbers selected uniformly from the middle, From Random numbers selected uniformly from the middle; make , ,calculate and The commitment value is calculated, and the corresponding zero-knowledge proof is generated, as shown in the following formula: ; ; ; in, , for The calculation results for The calculation results From Random numbers selected uniformly from the middle, From Random numbers selected uniformly from the middle, The zero-knowledge proof corresponding to the anonymous token request. for The value of the commitment, for The value of the commitment; Step S45: Output anonymous token request .

6. The threshold-based anonymity token method according to claim 5, characterized in that, In step S5, the specific steps are as follows: Step S51: Verify zero-knowledge proof and If the verification fails, the process will terminate. Step S52, through the issuer The calculation of blinded tokens is as follows: calculate , ,make ;in, For the issuer Received CS decryption results For Lagrange coefficients; Random selection ,calculate and It satisfies the following formula: ; ; in, From Random numbers selected uniformly from the middle, For the issuer The share held, For the issuer The share held, for The zero element; calculate , Using the shared conversion protocol with the issuer Secret Exchange and The information is returned. and ;in, For the issuer With the issuer The return value obtained from the interaction For the issuer With the issuer The return value obtained from the interaction; calculate: ; ; in, , For the issuer The generated blinded token, For the issuer The results obtained through calculation For the issuer The shareholding; Step S53: Output blinded anonymous tokens And save the tags Go to the corresponding tag list.

7. The threshold-based anonymity token method according to claim 6, characterized in that, In step S6, the specific steps are as follows: Step S61, Aggregation Partial blinded tokens: ; in, For the aggregated blinded token; Step S62: Output the aggregated blinded token .

8. The threshold-based anonymous token method according to claim 7, characterized in that, In step S7, the specific steps are as follows: Step S71: Verify the correctness of the tokens. If they are not equal, the process terminates. The formula is as follows: ; Step S72: Deblind the token to obtain the final token: ; Step S73: Set the token as and output .

9. The threshold-based anonymous token method according to claim 8, characterized in that, In step S8, the validator verifies the anonymous token, specifically: if If the verification is successful, output 1 and return the required resources or permissions to the user; if they are not equal, the verification fails and output 0, rejecting the user's request.

Citation Information

Patent Citations

  • Attribute-based anonymous authentication method and system thereof

    CN104125199A

  • Methods and apparatus for anonymising user data by aggregation

    US20130132473A1