A user behavior cross-domain tracing authentication method based on fuzzy identity
Patent Information
- Application Number
- CN202610250763.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-03
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2046-03-03
AI Technical Summary
[0005]本发明的目的在于提供一种基于模糊身份的用户行为跨域追溯认证方法,解决了现有技术中身份集中管理导致的隐私泄露风险、跨系统互信困难、匿名性与可追溯性难以兼顾,以及用户身份更新与伪名管理效率低的问题
[0016]This invention discloses a cross-domain user behavior tracing and authentication method based on fuzzy identity. The method involves generating system public parameters and creating decentralized identifiers through a trusted issuing institution. The user terminal generates a stable secret value and auxiliary data based on their real identity using a fuzzy extractor, and creates an updatable pseudo-identity using a Hamming distance-controlled pseudo-identity generation algorithm. The user registers with the trusted issuing institution and obtains a verifiable credential binding their real and pseudo-identities. In the original sub-campus system, the user creates a virtual avatar based on this credential and performs intra-domain two-way authentication with the original sub-system to update their pseudo-identity. When accessing the target sub-system, cross-domain two-way authentication is completed through the original sub-system's guarantee, and a new virtual identity record is established. When a violation occurs, the original sub-system reconstructs the stable secret value based on the auxiliary data and combines it with the verifiable credential to parse the user's real identity, achieving cross-domain tracing. By using a decentralized identifier system, the risks of single point of failure and privacy leakage associated with centralized management are avoided. By using a fuzzy identity mechanism, anonymous access with unassociated cross-domain identities is achieved. Through verifiable credential binding and fuzzy identity reconstruction mechanisms, controllable traceability is achieved while ensuring privacy. At the same time, users can update their pseudonyms independently. This solves the technical problems of cross-domain mutual trust difficulties, the difficulty in balancing anonymity and traceability, and low efficiency of identity update in existing technologies.
Smart Images

Figure CN122053197B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of traceable identity authentication technology, and in particular to a cross-domain traceability authentication method for user behavior based on fuzzy identity. Background Technology
[0002] With the continuous advancement of digitalization and informatization, digital campuses have formed a multi-source, heterogeneous environment covering various business systems such as teaching management, scientific research collaboration, experimental data management, library borrowing, campus card systems, and logistics services. These subsystems are typically built independently by different departments or vendors, lacking a unified identity management framework. This leads to users frequently switching identities and repeatedly registering and verifying across multiple systems, impacting user experience and increasing security risks. Existing campus authentication systems generally rely on centralized single sign-on or fixed identifier mechanisms. Once the central node is attacked or malfunctions, the authentication capabilities of the entire campus will be affected, exhibiting a significant single point of failure.
[0003] Furthermore, centralized identity management stores a large amount of user identity data, access records, and behavioral patterns within the same institution. Attackers only need to breach a single point to obtain the identity information of all faculty and students, posing an extremely high risk of privacy breaches. In multi-system environments, user identities often remain consistent or inferable across different domains, allowing attackers to merge and map identities from multiple subsystems to the same user by comparing behavioral patterns, metadata, or access characteristics, thus compromising privacy isolation. In sensitive business scenarios such as psychological counseling, academic review, and exam management, users desire both anonymity and traceability in the event of violations. Traditional tracking methods based on static identifiers or centralized logs struggle to simultaneously achieve both anonymity and accountability.
[0004] Faced with the continuous growth in cross-domain access demands, existing distributed identity management solutions, multi-system joint authentication schemes based on public key infrastructure (PKI), and blockchain-driven identity frameworks, while alleviating some mutual trust issues, still have shortcomings in addressing the needs of digital campus scenarios. For example, PKI systems require multiple authentication centers to establish complex trust relationships, resulting in high cross-domain verification costs; blockchain-based identity identifiers are immutable, but they are typically static information, making it difficult to associate user identities across different domains; some multi-domain single sign-on solutions still rely on central agency coordination, failing to meet the independent trust requirements of autonomous domain environments. Furthermore, existing solutions generally lack lightweight identity update mechanisms; when user roles, permissions, or states change, re-registration or reissue of credentials is still required, which is unsuitable for high-frequency dynamic interaction scenarios. Therefore, how to achieve trusted cross-domain authentication and controllable traceability while ensuring strong user privacy protection has become a critical issue that urgently needs to be addressed in the current digital campus security system. Summary of the Invention
[0005] The purpose of this invention is to provide a cross-domain traceability authentication method for user behavior based on fuzzy identity, which solves the problems of privacy leakage risk caused by centralized identity management, difficulty in cross-system mutual trust, difficulty in balancing anonymity and traceability, and low efficiency of user identity update and pseudonym management in the prior art.
[0006] To achieve the above objectives, this invention provides a cross-domain user behavior tracing and authentication method based on fuzzy identity, comprising the following steps: Trusted issuing institutions generate public system parameters and create decentralized identifiers; The user terminal generates a stable secret value and auxiliary data based on the user's real identity through a fuzzy extractor, and generates an updatable pseudo-identity through a Hamming distance-controlled pseudo-identity generation algorithm, and initiates registration with a trusted issuing institution. After verifying the consistency between the pseudonym and auxiliary data submitted by the user, the trusted issuing institution issues a verifiable credential to the user's decentralized identifier. The verifiable credential is used to bind the real identity and the pseudonym. Users create virtual avatars in the original sub-campus system based on the verifiable credentials, and use the pseudo-identity to perform intra-domain two-way authentication with the original sub-campus system to update the pseudo-identity; When a user accesses the target sub-campus system, cross-domain two-way authentication is performed between the original sub-campus system and the target sub-campus system through the guarantee of the original sub-campus system, and a new virtual identity record is established in the target sub-campus system; When a violation is detected using a pseudonym, the original sub-campus system reconstructs a stable secret value based on locally stored auxiliary data and combines it with verifiable credentials to parse the user's true identity, enabling cross-domain tracing.
[0007] Specifically, the generation of updatable pseudonyms using a Hamming distance-controlled pseudonym generation algorithm includes: By using a Hamming distance-controlled pseudonym generation algorithm to randomly perturb identity data within a limited range, different pseudonyms remain uncorrelated and support multiple updates.
[0008] Specifically, issuing verifiable credentials to users' decentralized identifiers includes: Based on user pseudonyms and auxiliary data verification of fuzzy identity consistency, a digital credential is generated by combining the user identifier and the issuing institution identifier. The verifiable credential includes user pseudonym binding information, user identity identifier, issuing institution identifier, and digital signature.
[0009] Before initiating intra-domain two-way authentication, the user must also include: The local binding parameters are restored by entering a password and biometric information, and the virtual avatar is activated after successful verification.
[0010] Specifically, the use of pseudonyms to perform two-way authentication within the domain with the original sub-campus system includes: The user terminal constructs an authentication message containing a random number and an updated pseudonym identity and sends it to the original sub-campus system; after verifying the freshness of the message and the consistency of the pseudonym, the original sub-campus system negotiates with the user to share the session key and updates the locally stored pseudonym identity.
[0011] Specifically, cross-domain two-way authentication is performed through the guarantee of the original sub-campus system and the target sub-campus system, including: The user terminal sends a cross-domain request to the original sub-campus system; after verifying the user's identity, the original sub-campus system forwards the endorsed cross-domain message to the target sub-campus system; the target sub-campus system and the user terminal complete two-way authentication and negotiate a session key, while storing the user's new pseudonym locally.
[0012] Specifically, cross-domain traceability includes: The target sub-campus system that detects the violation submits the violating pseudonym to the user's original sub-campus system; the original sub-campus system reconstructs a stable secret value based on locally stored auxiliary data and parses the user's real identity identifier in conjunction with verifiable credentials.
[0013] The tracing process only exposes the real identity corresponding to the illegal pseudonym, without disclosing other pseudonym information of the user, and is completed independently by the original sub-campus system and the trusted issuing agency, without relying on third-party institutions.
[0014] In this process, the public key of the trusted issuing institution is embedded in its decentralized identifier document and recorded on the blockchain; the user terminal generates its own decentralized identifier and uploads auxiliary data to the corresponding decentralized identifier document for storage on the blockchain.
[0015] The method further includes: It supports users to update their pseudonyms independently, maintains the non-associability of identity during cross-domain access, and enables the traceability of real identity through fuzzy identity reconstruction when necessary.
[0016] This invention discloses a cross-domain user behavior tracing and authentication method based on fuzzy identity. The method involves generating system public parameters and creating decentralized identifiers through a trusted issuing institution. The user terminal generates a stable secret value and auxiliary data based on their real identity using a fuzzy extractor, and creates an updatable pseudo-identity using a Hamming distance-controlled pseudo-identity generation algorithm. The user registers with the trusted issuing institution and obtains a verifiable credential binding their real and pseudo-identities. In the original sub-campus system, the user creates a virtual avatar based on this credential and performs intra-domain two-way authentication with the original sub-system to update their pseudo-identity. When accessing the target sub-system, cross-domain two-way authentication is completed through the original sub-system's guarantee, and a new virtual identity record is established. When a violation occurs, the original sub-system reconstructs the stable secret value based on the auxiliary data and combines it with the verifiable credential to parse the user's real identity, achieving cross-domain tracing. By using a decentralized identifier system, the risks of single point of failure and privacy leakage associated with centralized management are avoided. By using a fuzzy identity mechanism, anonymous access with unassociated cross-domain identities is achieved. Through verifiable credential binding and fuzzy identity reconstruction mechanisms, controllable traceability is achieved while ensuring privacy. At the same time, users can update their pseudonyms independently. This solves the technical problems of cross-domain mutual trust difficulties, the difficulty in balancing anonymity and traceability, and low efficiency of identity update in existing technologies. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below.
[0018] Figure 1 This is a system model diagram of the cross-domain tracing and authentication method for user behavior based on fuzzy identity according to the present invention.
[0019] Figure 2 This is a flowchart of the steps of the cross-domain tracing and authentication method for user behavior based on fuzzy identity according to the present invention. Detailed Implementation
[0020] The embodiments of the present invention are described in detail below. Examples of the embodiments are shown in the accompanying drawings. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain the present invention, but should not be construed as limiting the present invention.
[0021] Please see Figure 1 and Figure 2 This invention provides a cross-domain user behavior tracing and authentication method based on fuzzy identity, comprising the following steps: S101: Trusted issuing institutions generate public system parameters and create decentralized identifiers; S102: The user terminal generates a stable secret value and auxiliary data based on the user's real identity through a fuzzy extractor, and generates an updatable pseudo-identity through a Hamming distance-controlled pseudo-identity generation algorithm, and initiates registration with a trusted issuing institution. S103: After verifying the consistency between the pseudo-identity and auxiliary data submitted by the user, the trusted issuing institution issues a verifiable credential to the user's decentralized identifier. The verifiable credential is used to bind the real identity and the pseudo-identity. S104: The user creates a virtual avatar in the original sub-campus system based on the verifiable credentials, and performs intra-domain two-way authentication with the original sub-campus system using the pseudo-identity, and updates the pseudo-identity. S105: When a user accesses the target sub-campus system, cross-domain two-way authentication is performed with the target sub-campus system through the guarantee of the original sub-campus system, and a new virtual identity record is established in the target sub-campus system; S106: When a violation is detected by a pseudonym, the original sub-campus system reconstructs a stable secret value based on locally stored auxiliary data and combines it with verifiable credentials to parse the user's real identity, thereby achieving cross-domain tracing.
[0022] Specifically, during the initialization phase: TI first selects security parameters. And select one - large prime numbers TI defines a finite field. ;exist Define nonsingular elliptic curves And determine its addition cyclic group. Its order is a prime number. Selecting a base point As the generator, TI further selects a collision-resistant hash function. And generate a fuzz extractor TI generates its decentralized identifier. Run the key generation algorithm To obtain the signing key pair. TI's public key. This information is embedded in its DID document and recorded on the campus consortium blockchain to ensure its integrity and verifiability. TI's final released system public parameters: .
[0023] User registration phase: User Through smart devices Enter their real identity above Initiate the registration process. Then, Virtual identities are selected using the Hamming sphere sampling algorithm. ,satisfy Users can further select parameters. and Used for fuzz extractor, then generate . Random selection Use it as the private key, and calculate the corresponding public key. Users generate their decentralized identifiers. It can be used to locate the corresponding DID document on the blockchain. Specifically, auxiliary data With public key Upload them together to their DID document for subsequent identity reconstruction. Finally, Registration Request Send to TI.
[0024] TI received a registration request Then, use Locate the user's DID document on the blockchain and obtain the user's public key. and auxiliary data Then, TI calculates... and check Check if the database already exists. If it does, reject the registration request. Otherwise, TI calculates... and check If true, TI calculates... Use private key right Perform signing, generate signature Subsequently, TI calculates the user's verifiable credential VC as... Ultimately, TI will... Return to and will Stored in a secure database.
[0025] receive Then, the algorithm was verified. Check TI and The authenticity of which If the verification is successful, Create a transaction to update its DID document. The transaction is then submitted to the blockchain. (Updated DID document) It is then stored on the blockchain.
[0026] Virtual avatar creation stage: Choose a password Random numbers In smart devices Input biometric information and choose a new virtual identity. .Then calculate , , , , , and send a virtual avatar creation request Send to sub-campus system ,in Indicates user The rendering parameters for the virtual avatar. The parameters for the virtual avatar created by the user at this stage are... ,in As an identity identifier for a virtual avatar.
[0027] Received Then, locate the user and TI's DID documents on the blockchain to obtain auxiliary data. , and Used for verification Signature in After successful signature verification, calculate , , , , then calculate . Random selection ,calculate , , . Local save and will Send to the user.
[0028] User Receive Then, calculate , , and will Stored on the user's device.
[0029] User login phase: When the user... Want to use a virtual avatar Accessing its original sub-campus system requires logging in via a smart device by entering its DID, password, and biometric information. Specifically, enter , , ,calculate , , .Then Based on current virtual identity calculations Further Derivation and check If true, the smart device initializes and the user logs in successfully; otherwise, the login attempt is rejected due to identity mismatch.
[0030] Intra-domain mutual authentication: After the smart device is initialized, Select random number and new virtual identities Then extract , ,calculate , , and send a message Give ,in For timestamps. take over Afterwards, check Freshness. If , Request rejected; otherwise, calculate. , , , and check If true, Random selection ,calculate , , and the message Return to At the same time, update the virtual identity of the virtual avatar in the database. Information updated to .
[0031] User Receive back, First check The freshness, and then calculate and shared session key Then calculate And verify whether it matches the received Match. If a match is successful, and Mutual authentication is complete, and the session key is shared. Once established, it can be used for subsequent secure communication.
[0032] Cross-domain authentication: When a user wants to use their virtual avatar to access other sub-campus systems (not the original sub-campus system), cross-domain authentication is required, involving three parties: the user... The user's original sub-campus system and target sub-campus system .
[0033] The user first queries the blockchain to obtain... Decentralized identifier Users update their virtual avatars by generating a new virtual identity and modifying rendering parameters to achieve anonymity. Specifically, users select a new virtual identity. And update the rendering parameters to The device randomly selects a temporary private key and a random number. ,calculate Subsequently, calculate and cross-domain requests Send to the original sub-campus system .
[0034] Decryption ,calculate and .like Established, calculate and send Give Subsequently, Update its database virtual identity as The database information has been updated to .
[0035] take over Then, calculate And select two random numbers. Subsequently, Use the user's temporary public key and long-term public keys Encrypt separately and Receive ciphertext and .Then Calculation and Shared session key And generate a message authentication code. To achieve explicit authentication, then send Give .
[0036] take over Then, decrypt get Calculate the shared session key and calculate , and received Compare. If a match is found, Generate message authentication code And send Give .
[0037] calculate And verify If a match is found, The updated virtual avatar information is stored in a local database, including the new virtual identity, rendering parameters, and... Decentralized identifier, recorded as .at this time, and The cross-universe authentication process has been successfully completed, and a shared session key has been negotiated. .
[0038] Malicious Identity Tracing: When Virtual Identity When a virtual avatar engages in illegal activities within a specific sub-campus system, two possibilities exist: the sub-campus system is... The original sub-campus system, or a non-original sub-campus system. These two cases correspond to intra-domain tracing and cross-domain tracing, respectively.
[0039] For cross-domain tracing (i.e., malicious users in non-original sub-campus systems) (Regarding illegal activities within the campus), the tracking process is as follows: Sub-campus system Will Submitted to the original sub-campus system of the malicious virtual avatar The latter was previously accessed by users. Proof of guarantee was provided. Then, Based on the malicious user's virtual identity and auxiliary data stored in its database Derivation .then, Retrieve the user's decentralized identifier from the local database. Locate the corresponding DID document and extract its contents. ,calculate and will Submitted to TI. TI searches its local database. Obtaining malicious user information .
[0040] For intra-domain tracing (i.e., malicious users in their original sub-campus system) (engaging in illegal activities within the campus system) Virtual identities of virtual avatars can be retrieved directly from the local database. and corresponding auxiliary data And obtain the same derivation steps as in cross-domain tracing. ,calculate This information is then submitted to TI, thus revealing the user's true identity. In summary, in both cross-domain and intra-domain scenarios, the true identity of malicious users can be revealed when necessary, facilitating the enforcement of punitive measures.
[0041] This system achieves dynamic updates of pseudonymous identities through a fuzzy identity mechanism, trusted binding of identity credentials through a decentralized identifier system, secure mutual trust between multiple subsystems through cross-domain authentication guaranteed by the original subsystem, and restoration of the true identity after malicious behavior through a controllable traceability mechanism. It eliminates the need for a centralized authentication center, resulting in higher reliability; it requires no complex additional overhead, adapting to the needs of multiple scenarios and high-frequency interactions in digital campuses; and it ensures traceability of responsibility even with anonymous access, thus building an efficient, secure, and controllable identity authentication system for digital campuses.
[0042] The above-disclosed embodiments are merely one or more preferred embodiments of this application and should not be construed as limiting the scope of this application. Those skilled in the art can understand that all or part of the processes for implementing the above embodiments and equivalent changes made in accordance with the claims of this application still fall within the scope of this application.
Claims
1. A method for cross-domain tracing and authentication of user behavior based on fuzzy identity, characterized in that, Includes the following steps: Trusted issuing institutions generate public system parameters and create decentralized identifiers; The user terminal generates a stable secret value and auxiliary data based on the user's real identity through a fuzzy extractor, and generates an updatable pseudo-identity through a Hamming distance-controlled pseudo-identity generation algorithm, and initiates registration with a trusted issuing institution. In this process, the identity data is randomly perturbed within a limited range by the Hamming distance-controlled pseudo-identity generation algorithm, so that different pseudo-identities remain uncorrelated and support multiple updates. After verifying the consistency between the pseudonym and auxiliary data submitted by the user, the trusted issuing institution issues a verifiable credential to the user's decentralized identifier. The verifiable credential is used to bind the real identity and the pseudonym. In the original sub-campus system, the user creates a virtual avatar based on the verifiable credentials and performs intra-domain two-way authentication with the original sub-campus system using the pseudo-identity, and updates the pseudo-identity; wherein, the user terminal constructs an authentication message containing a random number and the updated pseudo-identity and sends it to the original sub-campus system; after verifying the freshness of the message and the consistency of the pseudo-identity, the original sub-campus system negotiates with the user to share a session key and updates the locally stored pseudo-identity. When a user accesses the target sub-campus system, cross-domain two-way authentication is performed between the target sub-campus system and the original sub-campus system through the guarantee of the original sub-campus system, and a new virtual identity record is established in the target sub-campus system. Specifically, the user terminal sends a cross-domain request to the original sub-campus system; after verifying the user's identity, the original sub-campus system forwards the endorsed cross-domain message to the target sub-campus system; the target sub-campus system and the user terminal complete two-way authentication and negotiate a session key, while storing the user's new pseudonym locally. When a violation is detected using a pseudonym, the original sub-campus system reconstructs a stable secret value based on locally stored auxiliary data and combines it with verifiable credentials to parse the user's real identity, enabling cross-domain tracing. During the tracing process, only the real identity corresponding to the violating pseudonym is exposed, without revealing other pseudonyms of the user. This process is completed independently by the original sub-campus system and a trusted issuing institution, without relying on third-party institutions.
2. The cross-domain tracing and authentication method for user behavior based on fuzzy identity as described in claim 1, characterized in that, Issuing verifiable credentials to users' decentralized identifiers, specifically including: Based on the consistency of fuzzy identity verification using pseudo-identity and auxiliary data, a digital credential is generated by combining the user identifier and the issuing institution identifier. The verifiable credential includes pseudo-identity binding information, user identity identifier, issuing institution identifier, and digital signature.
3. The cross-domain tracing and authentication method for user behavior based on fuzzy identity as described in claim 1, characterized in that, Before initiating intra-domain two-way authentication, the user also needs to: The local binding parameters are restored by entering a password and biometric information, and the virtual avatar is activated after successful verification.
4. The cross-domain tracing and authentication method for user behavior based on fuzzy identity as described in claim 1, characterized in that, To achieve cross-domain traceability, the specific steps include: The target sub-campus system that detects the violation submits the violating pseudonym to the user's original sub-campus system; the original sub-campus system reconstructs a stable secret value based on locally stored auxiliary data and parses the user's real identity identifier in conjunction with verifiable credentials.
5. The cross-domain tracing and authentication method for user behavior based on fuzzy identity as described in claim 1, characterized in that, The public key of a trusted issuing institution is embedded in its decentralized identifier document and recorded on the blockchain; the user terminal generates its own decentralized identifier and uploads auxiliary data to the corresponding decentralized identifier document for storage on the blockchain.
6. The cross-domain tracing and authentication method for user behavior based on fuzzy identity as described in any one of claims 1 to 5, characterized in that, The method further includes: It supports users to update their pseudonyms independently, maintains the non-associativity of identities during cross-domain access, and enables the traceability of real identities through fuzzy identity reconstruction.
Citation Information
Patent Citations
Anonymous identity authentication method, system and program product based on privacy calculation
CN119026112A
Metacosm cross-scene anonymous seamless identity authentication method based on double block chains
CN119299224A