Identity authentication method and device

By distributing private key shards across the committee cluster and utilizing multi-party secure computation, the problem of user identities becoming unusable due to the failure of designated validators is solved, achieving highly robust and secure identity authentication and avoiding dependence on a single server.

CN121907463APending Publication Date: 2026-04-21INST OF SOFTWARE - CHINESE ACAD OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
INST OF SOFTWARE - CHINESE ACAD OF SCI
Filing Date
2025-11-28
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

The problem in existing technologies is that user identities cannot be used when the designated verifier fails, especially in strong authentication schemes that do not require security hardware on the user's end, where server malfunctions can lead to authentication failures.

Method used

By distributing fragments of the private key x across multiple committee nodes in the committee cluster, user authentication is achieved through multi-party secure computation. Alternative verification parameters are generated and verified. By combining zero-knowledge proofs and random values ​​to mask knowledge of the private key x, the security of protocol messages is ensured.

Benefits of technology

It achieves robustness and availability when a designated validator fails, avoids reliance on a single server, increases the cost for adversaries to forge legitimate user identities, and ensures the security and privacy of identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121907463A_ABST
    Figure CN121907463A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and provides an identity authentication method and device. The identity authentication method is applied to a committee node i and comprises the steps that user identity authentication request information is acquired, and the user identity authentication request information comprises a user identity identifier uid, a randomization voucher T, a zero-knowledge proof pi 2 and an alternative verification parameter E; based on the randomization voucher T, the random value fragment u2i and the private key association random value fragment w2i, generating and sending a verification fragment and a verification fragment proof to other committee nodes; generating a verification factor for replacing the verification parameter E under the condition that the number of the committee nodes with the validity of the generated verification fragment is greater than or equal to a first preset number; and under the condition that the replacement verification parameter E is verified to be correct based on the verification factor, verifying the zero-knowledge proof pi < 2 > to obtain a user identity authentication result. According to the identity authentication method and device provided by the invention, the problem that the identity of the user cannot be used easily caused by the failure of the specified verifier can be avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to an identity authentication method and apparatus. Background Technology

[0002] In strong authentication, users typically need to use security hardware to protect their credentials from being compromised. However, using security hardware incurs additional purchase and management costs for users, and the damage or loss of the security hardware means that the secrets it protects will no longer be usable.

[0003] Therefore, a strong authentication scheme that does not require secure hardware on the user's end is typically adopted. In this scheme, the server issues credentials to the user using its own private key. The challenge response to the credential can only be verified by the server, and the credentials are pseudo-random to third-party adversaries. Users can then encrypt the credentials locally with a password and store the encrypted credentials directly.

[0004] However, when the server malfunctions and is unable to provide authentication services, it can easily lead to the inability to use user identities. Summary of the Invention

[0005] This invention provides an identity authentication method and apparatus to solve the problem that user identities are easily rendered unusable when a designated verifier fails in the prior art.

[0006] In a first aspect, the present invention provides an identity authentication method, which is applied to any committee node i among multiple committee nodes in a committee cluster. Committee node i is deployed with a private key fragment xi of private key x, a random value fragment u2i of random value u2, and a private key associated random value fragment w2i of private key associated random value w2; the private key associated random value w2 is the product of private key x and random value u2.

[0007] The authentication method includes: obtaining user authentication request information, which includes a user identity identifier (User ID). The system consists of an identifier (uid), a randomized credential T, a zero-knowledge proof π2, and an alternative verification parameter E. The randomized credential T is generated based on the user's original credential A and a random value a. The zero-knowledge proof π2 is used to verify that the user possesses the original credential A. The alternative verification parameter E is generated based on a generator g, a random value a, the user's identifier uid, and the randomized credential T. Based on the randomized credential T, a random value fragment u2i, and a private key-associated random value fragment w2i, a verification fragment and a verification fragment proof for the alternative verification parameter E are generated and sent to other committee nodes. The verification fragment proof is proof of the validity of the verification fragment. If the number of committee nodes with valid verification fragments is greater than or equal to a first preset number, aggregation processing is performed on the valid verification fragments to generate a verification factor for the alternative verification parameter E. If the alternative verification parameter E is verified to be correct based on the verification factor, the zero-knowledge proof π2 is verified based on the user's identifier uid, the randomized credential T, and the alternative verification parameter E to obtain the user authentication result.

[0008] According to an identity authentication method provided by the present invention, the alternative verification parameter E is the product of the generator g raised to the power of a and the inverse of the randomized credential T raised to the power of uid; the verification fragment is the product of the randomized credential T raised to the power of w2i and the inverse of the alternative verification parameter E raised to the power of u2i.

[0009] According to an identity authentication method provided by the present invention, committee node i further deploys a random value fragment u1i of random value u1 and a private key associated random value fragment w1i of private key associated random value w1; the private key associated random value w1 is the product of private key x and random value u1; the original credential A is the target value power of generator g, the target value is the product between random value u1 and the inverse of the first sum value, the first sum value is the sum between private key associated random value w1 and the first product, and the first product is the product between random value u1 and user identity identifier uid; before obtaining the user's identity authentication request information, the method further includes: Receive credential request information sent by the user using the device. The credential request information includes the user's identity identifier (uid). Based on the generator g, random value fragment u1i, private key associated random value fragment w1i, and user identity identifier uid, the original credential fragment of the original credential A and the zero-knowledge proof π1 are generated. The original credential fragment includes the generator g raised to the power of u1i and the second sum. The second sum is the sum between the private key associated random value fragment w1i and the second product. The second product is the product of the random value fragment u1i and the user identity identifier uid. The zero-knowledge proof π1 is the proof that the original credential fragment is valid. Send user credential response information to the user's device. The user credential response information includes the original credential fragment of the original credential A and the zero-knowledge proof π1.

[0010] According to the identity authentication method provided by the present invention, committee node i also deploys a public key g. x The method further includes: a random value fragment u3i of random value u3, and a private key associated random value fragment w3i of random value w3; the private key associated random value w3 is the product of private key x and random value u3; the method also includes: Once user authentication is successful, based on the randomized credential T and the randomized value shard u3i, a commitment value shard and a commitment value shard proof are generated and sent to other committee nodes. The commitment value shard is the u3i power of the randomized credential T; the commitment value shard proof is proof that the commitment value shard is valid. If the number of committee nodes with valid commitment value shards is greater than or equal to the second preset number, aggregation is performed based on the valid commitment value shards to generate commitment value R. T ; Based on the commitment value R T The generator g raised to the power of u3, the randomized credential T, the substitution verification parameter E, the generator g, and the public key g x The challenge value c is generated, and based on the random value fragment u3i, the challenge value c, and the private key fragment xi, a response value fragment is generated and sent to other committee nodes; the challenge value c is transmitted via g. u3 With R T The product between them, T, E, g, g x The hash function is determined; the response value fragment is the sum of the product of the random value fragment u3i, the challenge value c, and the private key fragment xi; If the number of committee nodes that correctly verify the generated response value fragments is greater than or equal to the third preset number, aggregation processing is performed on the correctly verified response value fragments to generate response value s, which yields the user's third-party authentication credential information. This third-party authentication credential information includes a randomized credential T and a verifiable credential PK. T And zero-knowledge proof π3, verifiable credentials PK T To verify the validity of the randomized credential T, the zero-knowledge proof π3 includes a challenge value c and a response value s; Send third-party authentication credentials to users when they use the device.

[0011] The identity authentication method provided by the present invention further includes: In the offline phase, generate private key x, private key fragment xi, and public key g. x Public key sharding g xiThe random value information includes random value fragment u1i of random value u1, random value fragment w1i associated with the private key of random value w1, random value fragment u2i of random value u2, random value fragment w2i associated with the private key of random value w2, random value fragment u3i of random value u3, and random value fragment w3i associated with the private key of random value w3. The random value w1 associated with the private key is the product of the private key x and the random value u1. The random value w2 associated with the private key is the product of the private key x and the random value u2. The random value w3 associated with the private key is the product of the private key x and the random value u3.

[0012] Secondly, the present invention provides an identity authentication method applied to a user's device, comprising: The system receives user credential response information sent by committee node i. This response information includes a fragment of the original credential A and a zero-knowledge proof π1. Committee node i is any one of multiple committee nodes in the committee cluster. Committee node i deploys a private key fragment xi of private key x, a random value fragment u1i of random value u1, and a private key-associated random value fragment w1i of private key associated with random value w1. The private key-associated random value w1 is the product of private key x and random value u1. The original credential fragment includes the u1i power of generator g and a second sum. The second sum is the sum between the private key-associated random value fragment w1i and the second product. The second product is the product between the random value fragment u1i and the user identifier uid. The zero-knowledge proof π1 is a proof that the original credential fragment possesses legality. If the number of valid original credential fragments received is greater than or equal to the fourth preset number, the valid original credential fragments are aggregated to obtain original credential A. Original credential A is the target value power of the generator g. The target value is the product between the random value u1 and the inverse of the first sum value. The first sum value is the sum between the private key associated random value w1 and the first product. The first product is the product between the random value u1 and the user identity identifier uid.

[0013] The identity authentication method provided by the present invention further includes: Receive the third-party authentication credential information sent by committee node i. The third-party authentication credential information includes the randomized credential T and the verifiable credential PK. T And zero-knowledge proof π3, verifiable credentials PK T To verify the validity of the randomized credential T, the zero-knowledge proof π3 includes a challenge value c and a response value s; Upon initial authentication with a third party based on third-party authentication credentials, a short-term signature, a verification key, and verification information are generated, and the verification information is sent to the third party. The verification key is used to verify the short-term signature. The verification information includes the short-term signature and the verification key signed by a random value 'a'. If a third party verifies the validity of the short-term signature, authentication will be performed with the third party based on the short-term signature within a predetermined period.

[0014] Thirdly, the present invention provides an identity authentication device, which is equipped with a private key fragment xi of a private key x, a random value fragment u2i of a random value u2, and a private key associated random value fragment w2i of a private key associated random value w2; the private key associated random value w2 is the product of the private key x and the random value u2.

[0015] The identity authentication device includes: The acquisition module is used to acquire user authentication request information, which includes user identifier uid, randomized credential T, zero-knowledge proof π2, and alternative verification parameter E; the randomized credential T is generated based on the user's original credential A and random value a; Zero-knowledge proof of π² Used for verification The user possesses original voucher A; The alternative verification parameter E is generated based on the generator g, the random value a, the user identifier uid, and the randomized credential T. The processing module is used to generate a verification fragment and a verification fragment proof that replaces the verification parameter E based on the randomized credential T, the random value fragment u2i, and the random value fragment w2i associated with the private key, and to send the generated verification fragment and verification fragment proof to other committee nodes; the verification fragment proof is proof that the verification fragment is legitimate. The processing module is also used to perform aggregation processing on the valid verification fragments when the number of committee nodes with valid verification fragments is greater than or equal to the first preset number, and generate a verification factor to replace the verification parameter E. The processing module is also used to verify the zero-knowledge proof π2 based on the user identity identifier uid, randomized credential T, and alternative verification parameter E, and obtain the user identity authentication result, provided that the alternative verification parameter E is correct based on the verification factor.

[0016] Fourthly, the present invention provides an identity authentication device, comprising: The receiving module receives user credential response information sent by committee node i. This response information includes a fragment of the original credential A and a zero-knowledge proof π1. Committee node i is any one of multiple committee nodes in the committee cluster. Committee node i deploys a private key fragment xi of private key x, a random value fragment u1i of random value u1, and a private key-associated random value fragment w1i of private key associated with random value w1. The private key-associated random value w1 is the product of private key x and random value u1. The original credential fragment includes the u1i power of generator g and a second sum. The second sum is the sum between the private key-associated random value fragment w1i and the second product. The second product is the product between the random value fragment u1i and the user identifier uid. The zero-knowledge proof π1 is a proof that the original credential fragment possesses legality. The processing module is used to perform aggregation processing on the legal original certificate fragments when the number of received original certificate fragments with legality is greater than or equal to the fourth preset number, to obtain original certificate A; original certificate A is the target value power of generator g, the target value is the product between random value u1 and the inverse of the first sum value, the first sum value is the sum between private key associated random value w1 and the first product, and the first product is the product between random value u1 and user identity identifier uid.

[0017] Fifthly, the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor executes the computer program to implement any of the authentication methods in the first aspect, or to implement any of the authentication methods in the second aspect.

[0018] In a sixth aspect, the present invention provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements any of the authentication methods in the first aspect or any of the authentication methods in the second aspect.

[0019] In a seventh aspect, the present invention provides a computer program product, including a computer program, which, when executed by a processor, implements any of the authentication methods in the first aspect.

[0020] The identity authentication method and apparatus provided by this invention, by distributing the private key x across various committee nodes, enables user authentication based on multi-party secure computation while simultaneously masking the knowledge of the private key x using random values. This ensures that protocol messages from honest committee nodes do not leak the private key x, achieving provable security. Furthermore, it guarantees that an adversary cannot impersonate a user for authentication before breaching more than a threshold number of nodes, increasing the cost for an adversary to forge a legitimate user identity. Moreover, it eliminates reliance on trust in a single server for credential authentication and security, avoiding the problem of user identities becoming unusable when a designated validator fails. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0022] Figure 1 This is a flowchart illustrating the interaction between committee node i and the user's device, provided by the present invention.

[0023] Figure 2 This is one of the flowcharts illustrating the identity authentication method provided by the present invention.

[0024] Figure 3 This is the second flowchart of the identity authentication method provided by the present invention.

[0025] Figure 4 This is the third flowchart of the identity authentication method provided by the present invention.

[0026] Figure 5 This is one of the structural schematic diagrams of the identity authentication device provided by the present invention.

[0027] Figure 6 This is the second structural schematic diagram of the identity authentication device provided by the present invention.

[0028] Figure 7 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0029] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0030] The authentication method provided by this invention can distribute the functionality of a designated verifier, that is, it implements the algorithm for the designated verifier in the issuance and authentication process through multi-party secure computation. Specifically, the authentication method provided by this invention can be implemented by a committee cluster. The committee cluster includes multiple committee nodes. Each committee node can execute the authentication method provided by this invention.

[0031] Furthermore, in the following embodiments of the present invention, the committee nodes, user devices, and third parties can all deploy cryptographic groups. A cryptographic group is a set of mathematical tools that satisfy a specific algebraic structure and possess core properties such as closure, associativity, identity, inverse, and commutativity. It is used to provide a secure foundation for cryptographic operations such as private keys, commitment mechanisms, and zero-knowledge proofs.

[0032] In one embodiment, committee node i can generate a private key x, a private key fragment xi, and a public key g while offline. x Public key sharding g xi And random value information.

[0033] Here, committee node i is the i-th committee node among the multiple committee nodes that make up the committee cluster, that is, any committee node among the multiple committee nodes.

[0034] The random value information includes random value fragment u1i of random value u1, random value fragment w1i associated with the private key of random value w1, random value fragment u2i of random value u2, random value fragment w2i associated with the private key of random value w2, random value fragment u3i of random value u3, and random value fragment w3i associated with the private key of random value w3. The random value w1 associated with the private key is the product of the private key x and the random value u1. The random value w2 associated with the private key is the product of the private key x and the random value u2. The random value w3 associated with the private key is the product of the private key x and the random value u3.

[0035] Furthermore, the random value information may also include the Peterson polynomial commitment of random value fragment u1i, the Peterson polynomial commitment of random value fragment w1i associated with the private key, the Peterson polynomial commitment of random value fragment u2i, the Peterson polynomial commitment of random value fragment w2i associated with the private key, the Peterson polynomial commitment of random value fragment u3i, and the Peterson polynomial commitment of random value fragment w3i associated with the private key.

[0036] Optionally, random values ​​u1, u2, and u3 can be the same random value generated in the same way. Similarly, the private key associated random values ​​w1, w2, and w3 can also be the same random value. Alternatively, random values ​​u1, u2, and u3 can be different random values ​​generated in different ways, and similarly, the private key associated random values ​​w1, w2, and w3 can be different random values. This embodiment of the invention does not impose any limitations on these aspects.

[0037] Specifically, committee node i can identify whether it is in an offline phase based on predefined triggering rules. Predefined rules may include resource idle time triggering rules and / or no user request triggering rules.

[0038] The idle resource trigger rule refers to the situation where the computing resource utilization rate of committee node i is lower than the preset threshold. For example, the central processing unit (CPU) resource utilization rate is lower than 30%, the memory utilization rate is lower than 40%, the cryptographic operation unit utilization rate is lower than 20%, and there are no unfinished online computing tasks.

[0039] The "No User Request Trigger Rule" means that committee node i does not receive any user requests within a preset time window (e.g., 5 minutes). User requests may include user interaction-related messages such as authentication requests, original credential request requests, and verification result query requests.

[0040] Furthermore, when a predetermined triggering rule is triggered, committee node i can identify that it is in an offline phase and generate a private key x, a private key fragment xi, and a public key g based on globally public parameters. x Public key sharding g xi And random value information. Globally public parameters may include the generator g of the cryptographic group and polynomial commitment parameters, etc. Regarding the generation of distributed private keys, public keys, and random value information in the offline phase, please refer to the relevant protocol components, which will not be elaborated upon here.

[0041] Based on this, the overhead of committee nodes during busy and idle periods can be averaged, and the computational tasks of committee nodes can be divided into two stages: an offline stage and an online stage. In the offline stage, committee nodes pre-compute computational tasks unrelated to the user's request content, and then consume the parameters generated in the offline stage in the online stage to execute computational tasks dependent on user input. This reduces the complexity of computational tasks in the online stage, improves the response efficiency to user requests, and optimizes the user experience.

[0042] Thus, the private key x can be held distributed among multiple committee nodes, meaning each committee node holds a Shamir secret share xi of the private key x. Each committee node holds the public key g. x It also holds the corresponding public key fragment g.xi .

[0043] Furthermore, by distributing the private key x across all committee nodes in a secret manner, it is ensured that an adversary cannot impersonate a user to authenticate before breaching more than a threshold of nodes. This eliminates the reliance on trust in a single server, increasing the cost for an adversary to forge a legitimate user identity. Moreover, while possessing the advantage of not requiring client-side security hardware, it allows users to maintain the same level of control over their identity as in schemes requiring client-side security hardware, all under the distributed trust assumption.

[0044] Figure 1 This is a flowchart illustrating the interaction between committee node i and the user's device, as provided by this invention. Figure 1 As shown, the method includes the following steps: 101-104.

[0045] Step 101: The user sends a credential request message to committee node i using the device, and correspondingly, committee node i receives the credential request message sent by the user using the device.

[0046] The credential request information includes the user's identifier (uid).

[0047] Step 102: Committee node i generates the original credential fragment of the original credential A and the zero-knowledge proof π1 based on the generator g, the random value fragment u1i, the private key associated random value fragment w1i, and the user identity identifier uid.

[0048] The original credential fragments consist of the generator g raised to the power of u1i and a second sum. The second sum is the sum between the private key-associated random value fragment w1i and the second product, which is the product between the random value fragment u1i and the user identifier uid. g raised to the power of u1i is g... u1i The second sum is w1i + u1i·uid.

[0049] Zero-knowledge proof π1 is a proof that the fragmentation of the original voucher is valid, i.e., g u1i Zero-knowledge proofs that are consistent with the corresponding polynomial commitments of both w1i+u1i·uid.

[0050] Thus, committee node i can generate g based on the random value shard u1i computed in the offline phase and the random value shard w1i associated with the private key. u1i And w1i+u1i·uid, and zero-knowledge proof π1.

[0051] Step 103: Committee node i sends user credential response information to the user's device. Correspondingly, the user's device receives the user credential response information sent by committee node i.

[0052] The user credential response information includes the original credential fragment of original credential A and the zero-knowledge proof π1.

[0053] Specifically, committee node i can send (g) to the user's device via a secure channel. u1i ,w1i+u1i·uid,π1).

[0054] Step 104: If the number of valid original document fragments received by the user is greater than or equal to the fourth preset number, the user performs aggregation processing based on the valid original document fragments to obtain original document A.

[0055] The fourth preset number can be reasonably set according to the number of committee nodes in the committee cluster. For example, the fourth preset number can be two-thirds of the total number of committee nodes.

[0056] The original credential A is the power of the target value of the generator g. The target value is the product of the random value u1 and the inverse of the first sum value, which is the sum of the private key-associated random value w1 and the first product, which is the product of the random value u1 and the user identifier uid. In other words, the original credential A = g. u1 / (w1+u1·uid) .

[0057] Specifically, after receiving the user credential response information sent by committee node i, the user can verify the validity of the original credential fragment based on zero-knowledge proof π1. If the original credential fragment is verified to be valid, the original credential fragment is retained, and the number of valid original credential fragments is incremented by one. If the original credential fragment is verified to be invalid, the original credential fragment is discarded, and the number of valid original credential fragments remains unchanged.

[0058] Furthermore, if the number of valid original document fragments received is greater than or equal to the fourth preset number, the user can use the device to aggregate all valid original document fragments to obtain original document A.

[0059] Furthermore, the user can use the device to calculate the credential Apw = A·H(pw) encrypted with the password pw, where H is a hash function.

[0060] In this way, the issuance of original credentials can be securely achieved through distributed computation across multiple committee nodes. Even when the number of committee nodes that fail due to crashes or adversary control is less than the total number of committee nodes minus a fourth preset number, honest committee nodes will always output the correct computation result. This eliminates the problem of user identities becoming unusable due to a single designated validator refusing service, demonstrating high robustness and availability. Furthermore, for users using the device, only the registration phase requires additional reconstruction of g.u1 And w1+u1·uid, and complete the calculation of the original credential A. When authenticating identity and applying for credentials to authenticate third parties, the user program only needs to generate request messages and does not participate in the protocol interactively. The protocol process between committee nodes is transparent to the user.

[0061] Figure 2 This is one of the flowcharts illustrating the identity authentication method provided by the present invention. Figure 2 The authentication method shown can be applied to committee node i. For example... Figure 2 As shown, the method includes the following steps: 201-204.

[0062] Step 201: Obtain user authentication request information.

[0063] The user authentication request information includes the user identifier (uid), randomized credential (T), zero-knowledge proof (π2), and alternative verification parameter (E).

[0064] Randomized voucher T is generated based on the user's original voucher A and a random value a. For example, randomized voucher T=A a .

[0065] Zero-knowledge proof π2 is used to verify that a user possesses the original credential A.

[0066] The alternative verification parameter E is generated based on the generator g, the random value a, the user identifier uid, and the randomized credential T. For example, the alternative verification parameter E is the product of the generator g raised to the power of a and the inverse of the randomized credential T raised to the power of uid.

[0067] Specifically, when a user needs to authenticate their identity, the user can use their device to decrypt Apw using the password pw to obtain the original credential A, and then select a random value a to further randomize the original credential A to obtain the randomized credential T=A. a Furthermore, the user device can send an authentication request message to committee node i. The authentication request message may include the user's identifier (uid) and a randomized credential (T). Correspondingly, committee node i can receive the authentication request sent by the user device and send an authentication challenge value to the user device.

[0068] Furthermore, the user device can receive the authentication challenge value sent by committee node i and generate a signed zero-knowledge proof π2 against the authentication challenge value sent by committee node i. The zero-knowledge proof π2 can be used to prove that the user device possesses a random value a that satisfies proposition g. a =T (x+uid) In other words, zero-knowledge proof π2 proves that the user has the knowledge to calculate the original credential A, thus the effective zero-knowledge proof π2 can authenticate the user's identity.

[0069] Furthermore, to avoid using private keys x or T x To verify the potential leakage of private key x knowledge caused by zero-knowledge proof π², the user can use the device to additionally calculate and provide alternative verification parameters E=g. a / T uid =T x This is to enable provable security of the scheme when the private key x is held in a distributed manner by the committee nodes.

[0070] Step 202: Based on the randomized credential T, the random value fragment u2i, and the private key associated random value fragment w2i, generate a verification fragment and a verification fragment proof for the alternative verification parameter E, and send the generated verification fragment and verification fragment proof to other committee nodes.

[0071] The verification shard is the product of the randomized credential T raised to the power of w²i and the inverse of the alternative verification parameter E raised to the power of u²i. That is, the verification shard generated by committee node i is T. w2i / E u2i .

[0072] A verification piece proof is a proof that a verification piece is valid; that is, a zero-knowledge proof used to prove that the calculation process of the verification piece is correct.

[0073] Thus, committee node i can compute T. w2i / E u2i The calculation results, along with zero-knowledge proofs (i.e., verification of sharding proofs) proving the correctness of the calculation process, are sent to other committee nodes.

[0074] Step 203: If the number of committee nodes with valid verification fragments is greater than or equal to the first preset number, perform aggregation processing based on the valid verification fragments to generate a verification factor that replaces the verification parameter E.

[0075] The first preset number can be reasonably set according to the number of committee nodes in the committee cluster. For example, the first preset number can be two-thirds of the total number of committee nodes.

[0076] Specifically, committee node i can verify the validity of the verification fragment of its own generated alternative verification parameter E based on its own generated verification fragment proof. Furthermore, committee node i can receive verification fragments and verification fragment proofs of alternative verification parameter E sent by other committee nodes, and verify the validity of the verification fragments of alternative verification parameter E generated by other committee nodes based on the verification fragment proofs generated by other committee nodes.

[0077] If the verification shard is valid, keep the shard and increment the number of committee nodes with valid shards. If the verification shard is invalid, discard the shard and keep the number of committee nodes with valid shards unchanged.

[0078] Furthermore, if the number of committee nodes with valid verification shards is greater than or equal to a first preset number, committee node i can perform aggregation processing based on all valid verification shards to generate a verification factor for the alternative verification parameter E. The verification factor for the alternative verification parameter E is T. w2 / E u2 .

[0079] Step 204: If the alternative verification parameter E is correct based on the verification factor, verify the zero-knowledge proof π2 based on the user identity identifier uid, randomized credential T and alternative verification parameter E to obtain the user identity authentication result.

[0080] If the verification factor, T, is replaced by the verification parameter E, then... w2 / E u2 If T is the zero element of the group (i.e., the identity element of the cryptographic group), then the substitution verification parameter E is correct. In this case, E equals T. x This can be directly used to verify zero-knowledge proofs π². If the verification factor, T, is used to replace the verification parameter E... w2 / E u2 If it is a random element, it indicates that the alternative verification parameter E is incorrect.

[0081] In this way, while achieving user authentication through multi-party secure computation, the knowledge of the private key x can be masked by a random value, ensuring that the protocol messages of the honest committee nodes will not leak the private key x, thus achieving provable security.

[0082] Figure 3 This is the second flowchart of the identity authentication method provided by the present invention. Figure 3 The authentication method shown can be applied to committee node i. For example... Figure 3 As shown, when committee node i receives a third-party authentication request from a user using the device, the method further includes the following steps: 301-305.

[0083] Step 301: If the user identity authentication is successful, generate a commitment value shard and a commitment value shard proof based on the randomized credential T and the random value shard u3i, and send the generated commitment value shard and commitment value shard proof to other committee nodes.

[0084] Here, the commitment value sharding is the u3i power of the randomized credential T, i.e., T u3i .

[0085] A commitment value sharding proof is a proof that a commitment value sharding is valid; that is, a zero-knowledge proof used to prove that the calculation process of the commitment value sharding is correct.

[0086] Step 302: If the number of committee nodes with valid commitment value shards is greater than or equal to the second preset number, aggregate the valid commitment value shards to generate commitment value R. T .

[0087] The second preset number can be reasonably set according to the number of committee nodes in the committee cluster. For example, the second preset number can be two-thirds of the total number of committee nodes.

[0088] Specifically, committee node i can verify the validity of its own generated commitment value shards based on its own generated commitment value shard proof. Furthermore, committee node i can receive commitment value shards and commitment value shard proofs from other committee nodes, and verify the validity of commitment value shards generated by other committee nodes based on their generated commitment value shard proofs.

[0089] If the verified commitment value shard is valid, then the commitment value shard is retained, and the number of committee nodes with valid generated commitment value shards is incremented by one. If the verified commitment value shard is invalid, then the commitment value shard is discarded, and the number of committee nodes with valid generated commitment value shards remains unchanged.

[0090] Furthermore, if the number of committee nodes whose generated commitment value shards are valid is greater than or equal to the second preset number, committee node i can perform aggregation processing based on all valid commitment value shards to generate commitment value R. T Among them, the commitment value R T For T u3 .

[0091] Step 303, based on the commitment value R T The generator g raised to the power of u3, the randomized credential T, the substitution verification parameter E, the generator g, and the public key g x The challenge value c is generated, and based on the random value fragment u3i, the challenge value c and the private key fragment xi, the response value fragment is generated and sent to other committee nodes.

[0092] Among them, the challenge value c is achieved through g u3 With R T The product between them, T, E, g, g x The hash function is determined, i.e., the challenge value c = H(g) u3 ·R T T, E, g, g x), where H is a hash function. The response value slice is the sum of the product of the random value slice u3i, the challenge value c, and the private key slice xi, i.e., ui + c·xi.

[0093] Step 304: If the number of committee nodes that have been correctly verified in the generated response value shards is greater than or equal to the third preset number, aggregate the correctly verified response value shards to generate response value s and obtain the user's third-party authentication credential information.

[0094] The third-party authentication credential information includes the randomized credential T and the verifiable credential PK. T And zero-knowledge proof π3. After obtaining the third-party authentication credentials and verifying their correctness, the third-party verifier can verify the user's authentication request using randomized credentials T.

[0095] Verifiable credentials PK T Used to verify the validity of randomized credential T. For example, PK T =T x .

[0096] Zero-knowledge proof π3 consists of a challenge value c and a response value s, in the form (c, s). Zero-knowledge proof π3 is used to prove PK (Practice, Principle, and Application). T =T x For T, PK T Generator g and public key g x Verifying π / 3 is equivalent to verifying that for R=T s / PK T c ·g s / (g x ) c Does it have H(R,T,PK)? T g, g x )=c, where H is a hash function.

[0097] The third preset number can be reasonably set according to the number of multiple committee nodes in the committee cluster. For example, the third preset number can be two-thirds of the total number of multiple committee nodes.

[0098] Specifically, for response value fragments si, committee node i can be based on g si =g u3i ·(g xi ) c The relationship is verified to confirm whether si is correct. Among them, g... u3i and g xi The committee nodes within the committee cluster are made public.

[0099] Based on this, if the verified commitment value shard is correct, then the commitment value shard is retained, and the number of committee nodes with correctly verified generated commitment value shards is incremented by one. If the verified commitment value shard is incorrect, then the commitment value shard is discarded, and the number of committee nodes with correctly verified generated commitment value shards remains unchanged.

[0100] Furthermore, if the number of committee nodes whose generated commitment value shards have been correctly verified is greater than or equal to the third preset number, committee node i can aggregate all correctly verified commitment value shards to generate a response value s. Here, the response value s is u3 + c·x. In this way, the zero-knowledge proof π3 can be reconstructed and output.

[0101] Step 305: Send third-party authentication credentials to the user using the device.

[0102] Figure 4 This is the third flowchart of the identity authentication method provided by the present invention. Figure 4 The authentication method shown can be applied to users using devices. For example... Figure 4 As shown, the method includes the following steps: 401-403.

[0103] Step 401: Receive the third-party authentication credential information sent by committee node i.

[0104] The third-party authentication credential information includes the randomized credential T and the verifiable credential PK. T And zero-knowledge proof π3, verifiable credentials PK T To verify the validity of a randomized credential T, zero-knowledge proof π3 includes a challenge value c and a response value s.

[0105] Step 402: After completing the initial authentication with the third party based on the third party's authentication credentials, generate a short-term signature, a verification key, and verification information, and send the verification information to the third party.

[0106] The signature verification key is used to verify the short-lived signature. The verification information includes the short-lived signature and the signature verification key signed by a random value 'a'.

[0107] Step 403: If the short-term signature is verified to be valid by a third party, authentication is performed with the third party based on the short-term signature within a predetermined period of time.

[0108] Based on this, for scenarios where users need to authenticate with third parties multiple times in a short period of time, the user uses the device based on the third-party authentication credential information (T, PK). T After the first authentication with a third party, a pair of short-term signature and verification keys can be randomly selected, namely (sk, pk).

[0109] Then, a random value 'a' can be used to sign the verification key pk, resulting in a verification key pk signed by the random value 'a'. The short signature 'sk' and the verification key pk signed by the random value 'a' are then sent together to the third party. The third party uses g... a =ET x After verifying the validity of the signature key pk, it can be used to verify the signature generated by the user using the short-term signature sk within a predetermined time period agreed upon (or set by the protocol), thereby realizing the authentication process in which the short-term signature sk replaces the randomized credential T.

[0110] Thus, in scenarios involving multiple authentications with third parties within a short period, the public and private keys used for authentication will not reveal knowledge about the user's credentials. Furthermore, it avoids the use of a temporary random value 'a' for randomizing the original credential A and the randomized credential T=A. a Multiple authentication attempts can easily allow an adversary to obtain a random value 'a', and potentially use this random value to recover the user's original credentials, thereby gaining complete control over the user's identity. In this application, the random value 'a' can be promptly deleted after the initial authentication with a third party. Subsequent leaks of the private key used for authentication only allow an adversary to impersonate the user for authentication within the short validity period of the key pair, thus improving the security of the authentication process.

[0111] Based on the above embodiments, the present invention can improve the original strong authentication scheme that does not require the deployment of security hardware on the user end through secure multi-party computation technology. Under the distributed trust model, the user end only needs to incur a one-time additional overhead during the registration phase, thereby achieving higher availability and stronger security.

[0112] The identity authentication device provided by the present invention is described below. The identity authentication device described below can be referred to in correspondence with the identity authentication method described above.

[0113] Figure 5 This is one of the structural schematic diagrams of the identity authentication device provided in the embodiments of this application. The identity authentication device deploys a private key fragment xi of private key x, a random value fragment u2i of random value u2, and a private key associated random value fragment w2i of private key associated random value w2; the private key associated random value w2 is the product of private key x and random value u2. For example... Figure 5 As shown, the identity authentication device may include: The acquisition module 510 is used to acquire user identity authentication request information, which includes user identity identifier uid, randomized credential T, zero-knowledge proof π2, and alternative verification parameter E; randomized credential T is generated based on the user's original credential A and random value a; zero-knowledge proof π2 is used to verify that the user possesses the original credential A; alternative verification parameter E is generated based on generator g, random value a, user identity identifier uid, and randomized credential T; Processing module 520 is used to generate a verification fragment and a verification fragment proof based on the randomized credential T, the random value fragment u2i, and the private key associated random value fragment w2i. Sending module 530 is used to send the generated verification fragment and verification fragment proof to other committee nodes; the verification fragment proof is proof that the verification fragment is legitimate. The processing module 520 is also used to perform aggregation processing on the valid verification fragments when the number of committee nodes with valid verification fragments is greater than or equal to the first preset number, and generate a verification factor to replace the verification parameter E. The processing module 520 is also used to verify the zero-knowledge proof π2 based on the user identity identifier uid, the randomized credential T and the alternative verification parameter E, and obtain the user identity authentication result, provided that the alternative verification parameter E is correct based on the verification factor.

[0114] In one embodiment, the alternative verification parameter E is the product of the generator g raised to the power of a and the inverse of the randomized credential T raised to the power of uid; the verification fragment is the product of the randomized credential T raised to the power of w2i and the inverse of the alternative verification parameter E raised to the power of u2i.

[0115] In one embodiment, committee node i further deploys a random value fragment u1i of random value u1 and a private key associated random value fragment w1i of private key associated random value w1; the private key associated random value w1 is the product of private key x and random value u1; the original credential A is the target value power of generator g, the target value is the product between random value u1 and the inverse of the first sum value, the first sum value is the sum between private key associated random value w1 and the first product, and the first product is the product between random value u1 and user identity identifier uid.

[0116] The acquisition module 510 is also used to receive credential request information sent by the user using the device, the credential request information including the user's identity identifier uid; Processing module 520 is further configured to generate an original credential fragment of the original credential A and a zero-knowledge proof π1 based on the generator g, random value fragment u1i, private key associated random value fragment w1i, and user identity identifier uid; the original credential fragment includes the generator g raised to the power of u1i and the second sum, the second sum being the sum between the private key associated random value fragment w1i and the second product, and the second product being the product between the random value fragment u1i and the user identity identifier uid; the zero-knowledge proof π1 is a proof that the original credential fragment possesses legality. The sending module 530 is also used to send user credential response information to the user's device. The user credential response information includes the original credential fragment of the original credential A and the zero-knowledge proof π1.

[0117] In one embodiment, committee node i also deploys public key g.x Random value fragment u3i of random value u3, and private key associated random value fragment w3i of random value w3; the private key associated random value w3 is the product of private key x and random value u3.

[0118] Processing module 520 is further configured to generate a commitment value shard and a commitment value shard proof based on the randomized credential T and the random value shard u3i, provided that user authentication is successful. Sending module 530 is further configured to send the generated commitment value shard and commitment value shard proof to other committee nodes; the commitment value shard is u3i raised to the power of the randomized credential T; the commitment value shard proof is proof that the commitment value shard is valid. Processing module 520 is further configured to perform aggregation processing on the legally valid commitment value shards to generate a commitment value R, provided that the number of committee nodes with valid commitment value shards is greater than or equal to a second preset number. T ; Processing module 520 is also used for processing based on the commitment value R T The generator g raised to the power of u3, the randomized credential T, the substitution verification parameter E, the generator g, and the public key g x The system generates a challenge value c, and based on the random value fragment u3i, the challenge value c, and the private key fragment xi, generates a response value fragment. The sending module 530 is also used to send the generated response value fragments to other committee nodes; the challenge value c is transmitted via g... u3 With R T The product between them, T, E, g, g x The hash function is determined; the response value fragment is the sum of the product of the random value fragment u3i, the challenge value c, and the private key fragment xi; Processing module 520 is further configured to perform aggregation processing on the correctly verified response value fragments, generating response value s, and obtaining user third-party authentication credential information, which includes randomized credential T and verifiable credential PK, when the number of committee nodes that have correctly verified the generated response value fragments is greater than or equal to a third preset number. T And zero-knowledge proof π3, verifiable credentials PK T To verify the validity of the randomized credential T, the zero-knowledge proof π3 includes a challenge value c and a response value s; The sending module 530 is also used to send third-party authentication credential information to the user's device.

[0119] In one embodiment, the processing module 520 is further configured to generate a private key x, a private key fragment xi, and a public key g when the process is offline. x Public key sharding g xiThe random value information includes random value fragment u1i of random value u1, random value fragment w1i associated with the private key of random value w1, random value fragment u2i of random value u2, random value fragment w2i associated with the private key of random value w2, random value fragment u3i of random value u3, and random value fragment w3i associated with the private key of random value w3. The random value w1 associated with the private key is the product of the private key x and the random value u1. The random value w2 associated with the private key is the product of the private key x and the random value u2. The random value w3 associated with the private key is the product of the private key x and the random value u3.

[0120] Figure 6 This is a second structural schematic diagram of the identity authentication device provided in the embodiments of this application. For example... Figure 6 As shown, the identity authentication device may include: The receiving module 610 is used to receive user credential response information sent by committee node i. The user credential response information includes the original credential fragment of the original credential A and the zero-knowledge proof π1. Committee node i is any committee node among multiple committee nodes in the committee cluster. Committee node i deploys a private key fragment xi of private key x, a random value fragment u1i of random value u1, and a private key associated random value fragment w1i of private key associated random value w1. The private key associated random value w1 is the product of private key x and random value u1. The original credential fragment includes the u1i power of generator g and the second sum. The second sum is the sum between the private key associated random value fragment w1i and the second product. The second product is the product between random value fragment u1i and user identity identifier uid. The zero-knowledge proof π1 is a proof that the original credential fragment has the validity. The processing module 620 is used to perform aggregation processing on the legal original certificate fragments when the number of received original certificate fragments with legality is greater than or equal to a fourth preset number, to obtain original certificate A; original certificate A is the target value power of generator g, the target value is the product between random value u1 and the inverse of the first sum value, the first sum value is the sum between private key associated random value w1 and the first product, and the first product is the product between random value u1 and user identity identifier uid.

[0121] In one embodiment, the receiving module 610 is further configured to receive third-party authentication credential information sent by the committee node i, the third-party authentication credential information including a randomized credential T and a verifiable credential PK. T And zero-knowledge proof π3, verifiable credentials PK T To verify the validity of the randomized credential T, the zero-knowledge proof π3 includes a challenge value c and a response value s; The processing module 620 is also used to generate a short signature, a verification key, and verification information when the first authentication is completed with the third party based on the third party's authentication credentials, and to send the verification information to the third party; the verification key is used to verify the short signature; the verification information includes the short signature and the verification key signed by a random value a; The processing module 620 is also used to authenticate with the third party based on the short-term signature within a predetermined period of time, provided that the short-term signature is verified to be valid by the third party.

[0122] Figure 7 An example is a schematic diagram of the structure of an electronic device, such as... Figure 7 As shown, the electronic device may include a processor 710, a communications interface 720, a memory 730, and a communication bus 740, wherein the processor 710, the communications interface 720, and the memory 730 communicate with each other through the communication bus 740. The processor 710 can call logical instructions in the memory 730 to execute an authentication method. This method can be used to implement user authentication and may include: obtaining user authentication request information, which includes user identity identifier uid, randomized credential T, zero-knowledge proof π2, and alternative verification parameter E; randomized credential T is generated based on the user's original credential A and random value a; zero-knowledge proof π2 is used to verify that the user possesses the original credential A; alternative verification parameter E is generated based on generator g, random value a, user identity identifier uid, and randomized credential T; based on randomized credential T, random value fragment u2i, and private key associated random value fragment w2i, a verification fragment and verification fragment proof of alternative verification parameter E are generated, and the generated verification fragment and verification fragment proof are sent to other committee nodes; the verification fragment proof is proof that the verification fragment is valid; if the number of committee nodes with valid verification fragments is greater than or equal to a first preset number, aggregation processing is performed on the valid verification fragments to generate a verification factor for alternative verification parameter E; if the alternative verification parameter E is verified to be correct based on the verification factor, the zero-knowledge proof π2 is verified based on user identity identifier uid, randomized credential T, and alternative verification parameter E to obtain the user authentication result. Alternatively, this method can be used to implement the issuance of user original credentials and may include: The system receives user credential response information sent by committee node i. This response information includes a fragment of the original credential A and a zero-knowledge proof π1. Committee node i is any one of the multiple committee nodes in the committee cluster. Committee node i deploys a private key fragment xi of private key x, a random value fragment u1i of random value u1, and a private key-associated random value fragment w1i of private key associated with random value w1. The private key-associated random value w1 is the product of private key x and random value u1. The original credential fragment includes the u1i power of the generator g and a second sum, where the second sum is the product of the private key-associated random value fragment w1i and the second sum. The sum between the two, the second product is the product between the random value fragment u1i and the user identity identifier uid; the zero-knowledge proof π1 is the proof that the original credential fragment has legality; when the number of legal original credential fragments received is greater than or equal to the fourth preset number, the original credential A is obtained by aggregation based on the legal original credential fragments; the original credential A is the target value power of the generator g, the target value is the product between the random value u1 and the inverse of the first sum, the first sum is the sum between the private key associated random value w1 and the first product, and the first product is the product between the random value u1 and the user identity identifier uid.

[0123] Furthermore, the logical instructions in the aforementioned memory 730 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0124] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer is able to execute the authentication methods provided by the above methods. This method can be used to implement user authentication and may include: obtaining user authentication request information, which includes user identity identifier uid, randomized credential T, zero-knowledge proof π2, and alternative verification parameter E; randomized credential T is generated based on the user's original credential A and random value a; zero-knowledge proof π2 is used to verify that the user possesses the original credential A; alternative verification parameter E is generated based on generator g, random value a, user identity identifier uid, and randomized credential T; based on randomized credential T, random value fragment u2i, and private key associated random value fragment w2i, a verification fragment and verification fragment proof of alternative verification parameter E are generated, and the generated verification fragment and verification fragment proof are sent to other committee nodes; the verification fragment proof is proof that the verification fragment is valid; if the number of committee nodes with valid verification fragments is greater than or equal to a first preset number, aggregation processing is performed on the valid verification fragments to generate a verification factor for alternative verification parameter E; if the alternative verification parameter E is verified to be correct based on the verification factor, the zero-knowledge proof π2 is verified based on user identity identifier uid, randomized credential T, and alternative verification parameter E to obtain the user authentication result. Alternatively, this method can be used to implement the issuance of user original credentials and may include: The system receives user credential response information sent by committee node i. This response information includes a fragment of the original credential A and a zero-knowledge proof π1. Committee node i is any one of the multiple committee nodes in the committee cluster. Committee node i deploys a private key fragment xi of private key x, a random value fragment u1i of random value u1, and a private key-associated random value fragment w1i of private key associated with random value w1. The private key-associated random value w1 is the product of private key x and random value u1. The original credential fragment includes the u1i power of the generator g and a second sum, where the second sum is the product of the private key-associated random value fragment w1i and the second sum. The sum between the two, the second product is the product between the random value fragment u1i and the user identity identifier uid; the zero-knowledge proof π1 is the proof that the original credential fragment has legality; when the number of legal original credential fragments received is greater than or equal to the fourth preset number, the original credential A is obtained by aggregation based on the legal original credential fragments; the original credential A is the target value power of the generator g, the target value is the product between the random value u1 and the inverse of the first sum, the first sum is the sum between the private key associated random value w1 and the first product, and the first product is the product between the random value u1 and the user identity identifier uid.

[0125] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the authentication methods provided by the methods described above. This method can be used to implement user authentication and may include: obtaining user authentication request information, which includes user identity identifier uid, randomized credential T, zero-knowledge proof π2, and alternative verification parameter E; randomized credential T is generated based on the user's original credential A and random value a; zero-knowledge proof π2 is used to verify that the user possesses the original credential A; alternative verification parameter E is generated based on generator g, random value a, user identity identifier uid, and randomized credential T; based on randomized credential T, random value fragment u2i, and private key associated random value fragment w2i, a verification fragment and verification fragment proof of alternative verification parameter E are generated, and the generated verification fragment and verification fragment proof are sent to other committee nodes; the verification fragment proof is proof that the verification fragment is valid; if the number of committee nodes with valid verification fragments is greater than or equal to a first preset number, aggregation processing is performed on the valid verification fragments to generate a verification factor for alternative verification parameter E; if the alternative verification parameter E is verified to be correct based on the verification factor, the zero-knowledge proof π2 is verified based on user identity identifier uid, randomized credential T, and alternative verification parameter E to obtain the user authentication result. Alternatively, this method can be used to implement the issuance of user original credentials and may include: The system receives user credential response information sent by committee node i. This response information includes a fragment of the original credential A and a zero-knowledge proof π1. Committee node i is any one of the multiple committee nodes in the committee cluster. Committee node i deploys a private key fragment xi of private key x, a random value fragment u1i of random value u1, and a private key-associated random value fragment w1i of private key associated with random value w1. The private key-associated random value w1 is the product of private key x and random value u1. The original credential fragment includes the u1i power of the generator g and a second sum, where the second sum is the product of the private key-associated random value fragment w1i and the second sum. The sum between the two, the second product is the product between the random value fragment u1i and the user identity identifier uid; the zero-knowledge proof π1 is the proof that the original credential fragment has legality; when the number of legal original credential fragments received is greater than or equal to the fourth preset number, the original credential A is obtained by aggregation based on the legal original credential fragments; the original credential A is the target value power of the generator g, the target value is the product between the random value u1 and the inverse of the first sum, the first sum is the sum between the private key associated random value w1 and the first product, and the first product is the product between the random value u1 and the user identity identifier uid.

[0126] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0127] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0128] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An identity authentication method, characterized in that, It is applied to any committee node i among multiple committee nodes in a committee cluster, wherein the committee node i is deployed with a private key fragment xi of private key x, a random value fragment u2i of random value u2, and a private key associated random value fragment w2i of private key associated random value w2; The random value w2 associated with the private key is the product of the private key x and the random value u2; The method includes: Obtain user authentication request information, which includes user identifier uid, randomized credential T, zero-knowledge proof π2, and alternative verification parameter E; the randomized credential T is generated based on the user's original credential A and a random value a; the zero-knowledge proof π2 is used to verify that the user possesses the original credential A; the alternative verification parameter E is generated based on generator g, the random value a, the user identifier uid, and the randomized credential T. Based on the randomized credential T, the random value fragment u2i, and the random value fragment w2i associated with the private key, a verification fragment and a verification fragment proof are generated to replace the verification parameter E, and the generated verification fragment and verification fragment proof are sent to other committee nodes; the verification fragment proof is proof that the verification fragment is legitimate. If the number of committee nodes with valid verification fragments is greater than or equal to the first preset number, the valid verification fragments are aggregated to generate a verification factor that replaces the verification parameter E. If the alternative verification parameter E is verified to be correct based on the verification factor, the zero-knowledge proof π2 is verified based on the user identity identifier uid, the randomized credential T, and the alternative verification parameter E to obtain the user identity authentication result.

2. The identity authentication method according to claim 1, characterized in that, The alternative verification parameter E is the product of the generator g raised to the power of a and the inverse of the randomized certificate T raised to the power of uid; the verification fragment is the product of the randomized certificate T raised to the power of w2i and the inverse of the alternative verification parameter E raised to the power of u2i.

3. The identity authentication method according to claim 1, characterized in that, The committee node i also deploys a random value fragment u1i of random value u1 and a private key associated random value fragment w1i of private key associated random value w1; The private key associated random value w1 is the product of the private key x and the random value u1; the original credential A is the target value of the generator g raised to the power of the target value, the target value is the product of the random value u1 and the inverse of the first sum value, the first sum value is the sum of the private key associated random value w1 and the first product, and the first product is the product of the random value u1 and the user identity identifier uid; Before obtaining the user's identity authentication request information, the method further includes: Receive credential request information sent by the user using the device, wherein the credential request information includes the user's identity identifier (uid); Based on the generator g, random value fragment u1i, private key associated random value fragment w1i, and user identity identifier uid, the original credential fragment of the original credential A and the zero-knowledge proof π1 are generated; the original credential fragment includes the generator g raised to the power of u1i and the second sum, the second sum being the sum between the private key associated random value fragment w1i and the second product, and the second product being the product of the random value fragment u1i and the user identity identifier uid; the zero-knowledge proof π1 is the proof that the original credential fragment possesses legality. Send user credential response information to the user's device. The user credential response information includes the original credential fragment of the original credential A and the zero-knowledge proof π1.

4. The identity authentication method according to claim 1, characterized in that, The committee node i also deploys the public key g. x Random value fragment u3i of random value u3, and private key associated random value fragment w3i of random value w3; The private key associated with the random value w3 is the product of the private key x and the random value u3; the method further includes: Once user authentication is successful, based on the randomized credential T and the randomized value shard u3i, a commitment value shard and a commitment value shard proof are generated and sent to other committee nodes. The commitment value shard is the u3i power of the randomized credential T; the commitment value shard proof is proof that the commitment value shard is valid. If the number of committee nodes with valid commitment value shards is greater than or equal to the second preset number, aggregation is performed based on the valid commitment value shards to generate commitment value R. T ; Based on the commitment value R T The generator g raised to the power of u3, the randomized credential T, the substitution verification parameter E, the generator g, and the public key g x A challenge value c is generated, and based on the random value fragment u3i, the challenge value c, and the private key fragment xi, a response value fragment is generated and sent to other committee nodes; the challenge value c is transmitted via g. u3 With R T The product between them, T, E, g, g x The hash function is determined; the response value slice is the sum of the product of the random value slice u3i, the challenge value c, and the private key slice xi; If the number of committee nodes that have correctly verified the generated response value fragments is greater than or equal to a third preset number, aggregation processing is performed on the correctly verified response value fragments to generate response value s, thereby obtaining the user's third-party authentication credential information. The third-party authentication credential information includes a randomized credential T and a verifiable credential PK. T And zero-knowledge proof π3, the verifiable credential PK T The zero-knowledge proof π3, used to verify the legality of the randomized credential T, includes a challenge value c and a response value s. Send the third-party authentication credentials to the user using the device.

5. The identity authentication method according to claim 1, characterized in that, The method further includes: In the offline phase, generate private key x, private key fragment xi, and public key g. x Public key sharding g xi The random value information includes random value fragment u1i of random value u1, random value fragment w1i associated with private key of random value w1, random value fragment u2i of random value u2, random value fragment w2i associated with private key of random value w2, random value fragment u3i of random value u3, and random value fragment w3i associated with private key of random value w3; the random value w1 associated with private key is the product of private key x and random value u1; the random value w2 associated with private key is the product of private key x and random value u2; and the random value w3 associated with private key is the product of private key x and random value u3.

6. An identity authentication method, characterized in that, Applied to user-used devices, including: The system receives user credential response information sent by committee node i. This response information includes a fragment of the original credential A and a zero-knowledge proof π1. Committee node i is any one of multiple committee nodes in the committee cluster. Committee node i deploys a private key fragment xi of private key x, a random value fragment u1i of random value u1, and a private key-associated random value fragment w1i of private key associated with random value w1. The private key-associated random value w1 is the product of private key x and random value u1. The original credential fragment includes a generator g raised to the power of u1i and a second sum. The second sum is the sum between the private key-associated random value fragment w1i and the second product, which is the product between the random value fragment u1i and the user identifier uid. The zero-knowledge proof π1 is a proof that the original credential fragment possesses legality. If the number of valid original credential fragments received is greater than or equal to the fourth preset number, the valid original credential fragments are aggregated to obtain original credential A; the original credential A is the target value power of the generator g, the target value is the product between the random value u1 and the inverse of the first sum value, the first sum value is the sum between the private key associated random value w1 and the first product, and the first product is the product between the random value u1 and the user identity identifier uid.

7. The identity authentication method according to claim 6, characterized in that, The method further includes: Receive third-party authentication credential information sent by committee node i, the third-party authentication credential information including randomized credential T and verifiable credential PK. T And zero-knowledge proof π3, the verifiable credential PK T The zero-knowledge proof π3, used to verify the legality of the randomized credential T, includes a challenge value c and a response value s. Upon initial authentication with a third party based on the aforementioned third-party authentication credentials, a short-term signature, a verification key, and verification information are generated, and the verification information is sent to the third party. The verification key is used to verify the short-term signature. The verification information includes the short-term signature and the verification key signed by a random value 'a'. If a third party verifies the validity of the short-term signature, authentication is performed with the third party based on the short-term signature within a predetermined period of time.

8. An identity authentication device, characterized in that, The identity authentication device is equipped with a private key fragment xi of private key x, a random value fragment u2i of random value u2, and a private key associated random value fragment w2i of private key associated random value w2. The private key associated random value w2 is the product of the private key x and the random value u2; the authentication device includes: The acquisition module is used to acquire user identity authentication request information, which includes user identity identifier uid, randomized credential T, zero-knowledge proof π2, and alternative verification parameter E; the randomized credential T is generated based on the user's original credential A and a random value a; the zero-knowledge proof π2 is used to verify that the user possesses the original credential A; the alternative verification parameter E is generated based on generator g, the random value a, the user identity identifier uid, and the randomized credential T. The processing module is used to generate a verification fragment and a verification fragment proof that replaces the verification parameter E based on the randomized credential T, the random value fragment u2i, and the random value fragment w2i associated with the private key, and to send the generated verification fragment and verification fragment proof to other committee nodes; the verification fragment proof is proof that the verification fragment is legitimate. The processing module is also used to perform aggregation processing on the valid verification fragments when the number of committee nodes with valid verification fragments is greater than or equal to the first preset number, and generate a verification factor to replace the verification parameter E. The processing module is further configured to, under the condition that the alternative verification parameter E is correct based on the verification factor, verify the zero-knowledge proof π2 based on the user identity identifier uid, the randomized credential T, and the alternative verification parameter E, and obtain the user identity authentication result.

9. An identity authentication device, characterized in that, include: The receiving module is used to receive user credential response information sent by committee node i. The user credential response information includes the original credential fragment of the original credential A and the zero-knowledge proof π1. The committee node i is any one of the multiple committee nodes included in the committee cluster. The committee node i has deployed a private key fragment xi of private key x, a random value fragment u1i of random value u1, and a private key associated random value fragment w1i of private key associated random value w1. The private key associated random value w1 is the product of the private key x and the random value u1; the original credential fragment includes the u1i power of the generator g and the second sum, the second sum is the sum between the private key associated random value fragment w1i and the second product, and the second product is the product between the random value fragment u1i and the user identity identifier uid; Zero-knowledge proof π1 is proof that the fragmentation of the original voucher is valid; The processing module is used to perform aggregation processing on the legal original credential fragments when the number of received original credential fragments with legality is greater than or equal to a fourth preset number, to obtain original credential A; the original credential A is the target value power of the generator g, the target value is the product between the random value u1 and the inverse of the first sum value, the first sum value is the sum between the private key associated random value w1 and the first product, and the first product is the product between the random value u1 and the user identity identifier uid.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the authentication method as described in any one of claims 1 to 5, or the authentication method as described in claim 6 or 7.

11. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the authentication method as described in any one of claims 1 to 5, or the authentication method as described in claim 6 or 7.

12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the authentication method as described in any one of claims 1 to 5, or the authentication method as described in claim 6 or 7.