Authentication method and apparatus

By setting a limit on the number of authentications for anonymous credentials and binding the token identification with the number of authentications, the problem that anonymous users may share credentials has been solved, and the effect of improving network security and real-time continuity is achieved.

WO2025112618A1PCT designated stage expired Publication Date: 2025-06-05HUAWEI TECH CO LTD +1

Patent Information

Application Number
PCT/CN2024/109856
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-28
Filing Date
2024-08-05
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Anonymous users may share their credentials with unauthorized users in an anonymous credential system, resulting in an increase in the chances of illegal use of the service, affecting the real-time continuity and security of the service.

Method used

By setting a limit on the number of authentications for anonymous credentials, the token identification is bound to the number of authentications, ensuring that anonymous users can only generate authentication tokens less than or equal to the number of authentications, thereby avoiding illegal service provision.

Benefits of technology

It effectively avoids anonymous users providing illegal services to other users, improves network security and real-time continuity, and prevents unauthorized service access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024109856_05062025_PF_FP_ABST
    Figure CN2024109856_05062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communication. Provided are an authentication method and apparatus. The method comprises: issuing an anonymous credential to a second apparatus, wherein the anonymous credential comprises the number of authentications, and the number of authentications is used for indicating the number of token identifiers that can be generated by means of the anonymous credential; receiving an authentication token and a token identifier from the second apparatus in respect of a session, wherein the authentication token is bound to the token identifier, the authentication token and the token identifier are generated on the basis of the anonymous credential; and verifying the validity of the session on the basis of the number of authentication tokens bound to the token identifier. By means of the solution, the number of token identifiers is limited by the number of authentications, and the token identifier is bound to the number of authentications. In this way, the second apparatus can only generate authentication tokens, the number of which is less than or equal to the number of authentications, so that the second apparatus is prevented from providing illegal services to other users.
Need to check novelty before this filing date? Find Prior Art

Description

Authentication method and device

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on November 28, 2023, with application number 202311613749.9 and application name “Authentication Method and Device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and more particularly, to an authentication method and device. Background Art

[0003] Keyed-verification anonymous credential (KVAC) can be used to reduce authentication propagation delays and improve the efficiency of authentication schemes. In KVAC, the issuer of the anonymous credential and the verifier of the authentication token share the same secret key. However, to ensure real-time service continuity, anonymous users authenticate multiple times. Dishonest users may share their anonymous credentials with unauthorized users, providing them with more opportunities to illegally use the service.

[0004] Therefore, how to prevent anonymous users from providing illegal services is an urgent problem to be solved.

[0005] Summary of the Invention

[0006] The present application provides an authentication method and apparatus that can prevent anonymous users from providing illegal use of services.

[0007] In a first aspect, an authentication method is provided, which is applied to a first device, wherein the method includes: issuing an anonymous credential to a second device, the anonymous credential including a number of authentications, the number of authentications being used to indicate the number of token identifiers that can be generated by the anonymous credential; receiving an authentication token and a token identifier for a session from the second device, the authentication token and the token identifier being bound, the authentication token and the token identifier being generated based on the anonymous credential; and verifying the validity of the session based on the number of authentication tokens bound to the token identifier.

[0008] Through the above scheme, the number of token identifiers is limited by the number of authentication times, and the token identifier is bound to the number of authentication times. In this way, the second device can only generate authentication tokens that are less than or equal to the number of authentication times, thereby preventing the second device from providing illegal services to other users.

[0009] In combination with the first aspect, in certain implementations of the first aspect, the validity of the session is verified based on the number of authentication tokens bound to the token identifier, including: if there are multiple authentication tokens bound to the token identifier, determining that the session verification has failed.

[0010] Through the above solution, when the same token identifier is bound to multiple authentication tokens, the first device can determine that the session verification fails, thereby preventing the second device from providing illegal services to other users.

[0011] In combination with the first aspect, in some implementations of the first aspect, the method further includes: revealing the identity of the second device.

[0012] Through this solution, if a second device binds the same token identifier to multiple authentication tokens, the first device can determine that session verification has failed and reveal the identity of the second device. In other words, the first device can deprive the second device of its anonymity, thereby enabling identification. This solution prevents the identification of anonymous attackers, thereby improving network security.

[0013] In combination with the first aspect, in certain implementations of the first aspect, before issuing an anonymous credential to the second device, the method further includes: receiving a first zero-knowledge proof from the second device, the first zero-knowledge proof being used to prove the identity of the second device; and determining that the first zero-knowledge proof is successfully verified; wherein, issuing an anonymous credential to the second device includes: sending a tuple to the second device, the tuple including the anonymous credential and a second zero-knowledge proof being used to prove the identity of the first device.

[0014] Through the above embodiment, before issuing an anonymous credential, the first device can verify the identity of the second device, and during the anonymous credential issuance process, the second device can verify the identity of the first device. This can prevent other devices from impersonating the first or second device to communicate, thereby improving communication security.

[0015] In combination with the first aspect, in some implementations of the first aspect, the anonymous credential further includes time information, wherein the number of authentication times is used to indicate the number of token identifiers that can be generated by the anonymous credential within the time period indicated by the time information.

[0016] Through the above embodiment, the time information can limit the time period in which the number of authentications is applied, thereby further preventing anonymous users from illegally using services.

[0017] In a second aspect, an authentication method is provided, which is applied to a second device, wherein the method includes: obtaining an anonymous credential issued by a first device, the anonymous credential including a number of authentication times, the number of authentication times being used to indicate the number of token identifiers that can be generated by the anonymous credential; generating an authentication token and a token identifier for a session based on the anonymous credential, the authentication token and the token identifier being bound; and sending the authentication token and the token identifier to the first device.

[0018] Through the above scheme, the number of token identifiers is limited by the number of authentication times, and the token identifier is bound to the number of authentication times. In this way, the second device can only generate authentication tokens that are less than or equal to the number of authentication times, thereby preventing the second device from providing illegal services to other users.

[0019] In combination with the second aspect, in certain implementations of the second aspect, an authentication token and token identifier for a session are generated based on the anonymous credential, including: generating at least one authentication parameter, the number of the at least one authentication parameter being equal to the number of authentications; generating the token identifier based on one of the at least one authentication parameter, wherein different token identifiers are generated by different authentication parameters.

[0020] Through the above solution, the number of different token identifiers can be limited to be less than or equal to the number of authentication times through authentication parameters, further preventing anonymous users from providing illegal use of services.

[0021] In combination with the second aspect, in certain implementations of the second aspect, when there are multiple authentication tokens bound to the token identifier, the identity of the second device is revealed.

[0022] Through this solution, if a second device binds the same token identifier to multiple authentication tokens, the first device can determine that session verification has failed and reveal the identity of the second device. In other words, the first device can deprive the second device of its anonymity, thereby enabling identification. This solution prevents the identification of anonymous attackers, thereby improving network security.

[0023] In combination with the second aspect, in certain implementations of the second aspect, before obtaining the anonymous credential issued by the first device, the method further includes: generating a first zero-knowledge proof based on the private key of the second device, the first zero-knowledge proof being used to prove the identity of the second device; sending the first zero-knowledge proof to the first device; receiving a tuple from the first device, the tuple including the anonymous credential and a second zero-knowledge proof being used to prove the identity of the first device; and determining that the second zero-knowledge proof is successfully verified.

[0024] Through the above embodiment, before issuing an anonymous credential, the first device can verify the identity of the second device, and during the anonymous credential issuance process, the second device can verify the identity of the first device. This can prevent other devices from impersonating the first or second device to communicate, thereby improving communication security.

[0025] In combination with the second aspect, in some implementations of the second aspect, the anonymous credential further includes time information, wherein the number of authentication times is used to indicate the number of token identifiers that can be generated by the anonymous credential within the time period indicated by the time information.

[0026] Through the above embodiment, the time information can limit the time period in which the number of authentications is applied, thereby further preventing anonymous users from illegally using services.

[0027] In a third aspect, an embodiment of the present application provides a first device, which includes a module for implementing the first aspect or any possible implementation method of the first aspect.

[0028] In a fourth aspect, an embodiment of the present application provides a second device, which includes a module for implementing the second aspect or any possible implementation method of the second aspect.

[0029] In a fifth aspect, a computing device is provided, comprising a processor and a memory, wherein the processor is used to execute instructions stored in the memory so that the computing device executes the authentication method of the first aspect or any possible implementation of the first aspect, or so that the computing device executes the authentication method of the second aspect or any possible implementation of the second aspect.

[0030] In a sixth aspect, a computer program product comprising instructions is provided, which, when executed by a computing device, causes the computing device to execute the authentication method of the first aspect or any possible implementation of the first aspect, or causes the computing device to execute the authentication method of the second aspect or any possible implementation of the second aspect.

[0031] In the seventh aspect, a computer-readable storage medium is provided, comprising computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the authentication method of the first aspect or any possible implementation of the first aspect, or the computing device executes the authentication method of the second aspect or any possible implementation of the second aspect.

[0032] In an eighth aspect, a chip device is provided, comprising a processor for calling a computer program or computer instruction in a memory so that the processor executes any one of the implementations in the first aspect or any one of the implementations in the second aspect.

[0033] Optionally, the processor is coupled to the memory via an interface.

[0034] In a ninth aspect, a communication system is provided, comprising a first device and a second device; the first device is used to execute the method shown in the first aspect, and the second device is used to execute the method shown in the second aspect.

[0035] The description of the beneficial effects of any of the third to ninth aspects etc. may refer to the description of the beneficial effects of the first or second aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] FIG1 is a schematic diagram of a network architecture of a communication system applicable to an embodiment of the present application.

[0037] FIG2 is a schematic diagram of a network architecture of another communication system applicable to an embodiment of the present application.

[0038] FIG3 is a schematic flowchart of an authentication method provided in an embodiment of the present application.

[0039] FIG4 is a schematic flowchart of another authentication method provided in an embodiment of the present application.

[0040] FIG5 is a schematic diagram of a function provided in an embodiment of the present application.

[0041] FIG6 is a schematic diagram of some authentication switching provided in an embodiment of the present application.

[0042] FIG7 is a schematic flowchart of another authentication method provided in an embodiment of the present application.

[0043] FIG8 is a schematic block diagram of a communication device according to an embodiment of the present application.

[0044] FIG9 is a schematic block diagram of another communication device according to an embodiment of the present application. DETAILED DESCRIPTION

[0045] The technical solution in this application will be described below with reference to the accompanying drawings.

[0046] The technical solution provided by this application can be applied to various communication systems, such as the fifth generation (5 th generation, 5G) or new radio (NR) system, long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, etc. The technical solution provided by this application can also be applied to future communication systems, such as the sixth generation (6 th The technical solution provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.

[0047] Figure 1 shows a schematic diagram of the network architecture of a communication system applicable to an embodiment of the present application. The network architecture includes terminal equipment, access network equipment, access and mobility management network element, session management network element, user plane function network element, policy control network element, network slice selection network element, network warehouse function network element, network data analysis network element, unified data management network element, unified data storage network element, authentication service function network element, network capability exposure network element, application function network element, and a data network (DN) connected to the operator's network. The terminal equipment can send service data to the data network through the access network equipment and user plane function network element, and receive service data from the data network.

[0048] A terminal device is a device with wireless transceiver capabilities, which can be deployed on land, including indoors or outdoors, handheld, wearable or vehicle-mounted; it can also be deployed on water (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons and satellites, etc.). The terminal device can communicate with the core network via the radio access network (RAN) and exchange voice and / or data with the RAN. The terminal device can be a mobile phone, a tablet computer (Pad), a computer with wireless transceiver capabilities, a mobile internet device (MID), a wearable device, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. The embodiments of this application do not limit the application scenarios. Terminal devices may also be referred to as user equipment (UE), mobile stations, and remote stations. The embodiments of this application do not limit the specific technology, device form, or name of the terminal devices.

[0049] Access network equipment is a device in the network used to connect terminal devices to the wireless network. Access network equipment can be a node in the radio access network, which can also be called a base station, or a radio access network ((radio) access network, (R)AN) node (or device). In addition, (R)AN can also be equivalent to the next generation radio access network (NG-RAN) in the layer 3 relay architecture. In other words, (R)AN can be NG-RAN. For ease of description, RAN is sometimes used below to refer to access network equipment. It is understandable that RAN can also be AN.

[0050] The access network equipment may include an evolved base station (NodeB or eNB or e-NodeB, evolutionary Node B) in a long term evolution (LTE) system or an evolved LTE system (LTE-Advanced, LTE-A), such as a traditional macro base station eNB and a micro base station eNB in ​​a heterogeneous network scenario, or may also include a next generation node B (gNB) in a 5G or NR system, or may also include a radio network controller (RNC), a node B (NB), a base station controller (BSC), a base transceiver station (BTS), a transmission reception point (TRP), a home base station (e.g., home evolved NodeB, or home Node B, HNB), a base band unit (BBU), a base band pool BBU pool, or a WiFi access point (AP), etc., or may also include a centralized unit (CU) and a distributed unit (CU) in a cloud radio access network (CloudRAN) system. Unit (DU), not limited in the embodiments of the present application. In a separate deployment scenario where the access network equipment includes a CU and a DU, the CU supports protocols such as radio resource control (RRC), packet data convergence protocol (PDCP), and service data adaptation protocol (SDAP); the DU mainly supports the radio link control layer (RLC), media access control layer (MAC), and physical layer protocols.

[0051] The access and mobility management network element is mainly used for the attachment and tracking area update processes of terminals in mobile networks. The access and mobility management network element can provide non-access stratum (NAS) messages, complete registration management, connection management, reachability management, allocation of tracking area list (TA list), legal monitoring, access authorization, authentication and mobility management, etc., and transparently route session management (SM) messages to the session management network element. In the fifth generation (5G) communication system, the access and mobility management network element can be the access and mobility management function (AMF). In future communication systems (such as 6G communication systems), the mobility management network element can still be the AMF network element, or it can have other names, which is not limited in this application.

[0052] The session management network element is mainly used for session and bearer management in mobile networks, such as session establishment, modification, and release. Specific functions include allocating Internet Protocol (IP) addresses to terminals and selecting user plane function network elements that provide message forwarding functions. In 5G communication systems, the session management network element can be a session management function (SMF). In future communication systems (such as 6G communication systems), the session management network element can still be an SMF network element, or it can have other names, which are not limited by this application.

[0053] The user plane function network element is mainly used to process user messages, such as forwarding, billing, legal interception, etc. In addition, the user plane function network element can be used for routing and forwarding, threshold control, traffic monitoring, verification and other functions of user plane data. The user plane function network element can also be used for the management of UE IP addresses, the management of core network (CN) tunnel information, etc. The user plane function network element can also be called a protocol data unit (PDU) session anchor (PSA). In a 5G communication system, the user plane function network element can be a user plane function (UPF). In future communication systems (such as 6G communication systems), the user plane function network element can still be a UPF network element, or it can have other names, which is not limited in this application.

[0054] The policy control network element includes user subscription data management functions, policy control functions, billing policy control functions, QoS control, etc. In the 5G communication system, the policy control network element can be a policy control function (PCF). In future communication systems (such as 6G communication systems), the policy control network element can still be a PCF network element, or it can have other names, which is not limited in this application.

[0055] The network slice selection function network element is mainly used to select a suitable network slice for the service of the terminal device. In the 5G communication system, the network slice selection network element can be a network slice selection function (NSSF) network element. In future communication systems (such as 6G communication systems), the network slice selection network element can still be an NSSF network element, or it can have other names, which is not limited by this application.

[0056] The network registration function network element is mainly used to provide registration and discovery functions for network elements or services provided by network elements. In 5G communication systems, the network registration function network element can be a network registration function (NRF). In future communication systems (such as 6G communication systems), the network registration function network element can still be an NRF network element, or it can have other names, which is not limited by this application.

[0057] The network data analysis network element can collect data from various network functions (NFs), such as policy control network elements, session management network elements, user plane function network elements, access and mobility management network elements, and application function network elements (through network capability exposure function network elements), and perform analysis and prediction. In a 5G communication system, the network data analysis network element can be a network data analysis function (NWDAF). In future communication systems (such as 6G communication systems), the network data analysis network element can still be an NWDAF network element, or it can have other names, which is not limited by this application.

[0058] The unified data management network element is mainly used to manage the contract information of terminal devices. In the 5G communication system, the unified data management network element can be unified data management (UDM). In future communication systems (such as 6G communication systems), the unified data management network element can still be the UDM network element, or it can have other names, which is not limited by this application.

[0059] The unified data storage network element is mainly used to store structured data information, including contract information, policy information, and network data or business data defined in a standard format. In the 5G communication system, the unified data storage network element can be a unified data repository (UDR). In future communication systems (such as 6G communication systems), the unified data storage network element can still be a UDR network element, or it can have other names, which is not limited by this application.

[0060] The authentication service function network element is mainly used to perform security authentication on the terminal device. In the 5G communication system, the authentication service function network element can be the authentication server function (AUSF). In future communication systems (such as 6G communication systems), the authentication service function network element can still be the AUSF network element, or it can have other names, which is not limited by this application.

[0061] A network capability exposure network element can controllably expose some network functions to applications. In a 5G communication system, a network capability exposure network element can be a network exposure function (NEF). In future communication systems (such as a 6G communication system), the network capability exposure network element can still be an NEF network element, or it can have other names, which are not limited by this application.

[0062] The application function network element can provide service data of various applications to the control plane network elements of the operator's communication network, or obtain network data information and control information from the control plane network elements of the communication network. In the 5G communication system, the application function network element can be an application function (AF). In future communication systems (such as 6G communication systems), the application function network element can still be an AF network element, or it can have other names, which is not limited by this application. For example, the application function network element can also be called an application server or a service server. In addition, the application function network element can be deployed in the operator network or by a third party.

[0063] Data networks are primarily used to provide data transmission services to terminal devices. Data networks can be private networks, such as local area networks (LANs), public data networks (PDNs), such as the Internet, or proprietary networks deployed jointly by operators, such as those configured with IP multimedia core network subsystem (IMS) services. Data networks can also be provided by third parties.

[0064] In the architecture shown in Figure 1, the interface names and functions between the various network elements are as follows:

[0065] 1. N1: The interface between AMF and UE, which can be used to deliver QoS control rules to UE.

[0066] 2. N2: The interface between AMF and (R)AN, which can be used to transmit radio bearer control information from the core network side to the RAN.

[0067] 3. N3: Interface between RAN and UPF, used to transfer uplink or downlink user plane data between RAN and UPF.

[0068] 4. N4: The interface between SMF and UPF, which can be used to transmit information between the control plane and the user plane, including the control of the forwarding rules, QoS control rules, traffic statistics rules, etc. for the user plane and the reporting of information on the user plane.

[0069] 5. N6: Interface between UPF and DN, used to transmit uplink or downlink user data flow between UPF and DN.

[0070] 6. The service-oriented interfaces Nnssf, Nnef, Nausf, Nnrf, Namf, Npcf, Nsmf, and Nudm are respectively provided by the above-mentioned NSSF network element, NEF network element, AUSF network element, NRF network element, AMF network element, PCF network element, SMF network element, and UDM network element, and are used to call corresponding service-oriented operations.

[0071] It should be understood that the above-mentioned network elements or functions can be network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (for example, a cloud platform). Optionally, the above-mentioned network elements or functions can be implemented by one device, or by multiple devices together, or can be a functional module within a device, and the embodiments of the present application do not specifically limit this. Optionally, the above-mentioned network elements can be specific network elements of the 5G core network in the Layer 3 relay architecture.

[0072] It should also be understood that the above naming is only defined to facilitate the distinction between different functions and should not constitute any limitation to this application. This application does not exclude the possibility of adopting other naming in 5G networks and other networks in the future. For example, in a 6G network, some or all of the above networks may continue to use the terminology in 5G, or other names may be used. The interface name between the various network elements in Figure 1 is only an example. The name of the interface in the specific implementation may be other names, and this application does not make specific limitations on this. In addition, the name of the message (or signaling) transmitted between the above-mentioned network elements is only an example and does not constitute any limitation on the function of the message itself.

[0073] It should be noted that the aforementioned "network element" may also be referred to as an entity, device, apparatus, or module, and this application does not specifically limit this. Furthermore, in this application, for ease of understanding and explanation, the term "network element" is omitted in some descriptions. For example, the PCF network element is referred to as PCF. In this case, the "PCF" should be understood as a PCF network element or PCF entity. The following descriptions of identical or similar situations are omitted.

[0074] Figure 2 shows a schematic diagram of the network architecture of another communication system applicable to an embodiment of the present application. The network architecture includes a network control center (NCC), a ground station (GS), a low Earth orbit satellite (LEO), and a satellite user (SU). The SU can be the aforementioned access network device, core network device, or terminal device.

[0075] The NCC can generate global public and private keys, supporting attribute-based authentication. The GS can receive the GS public and private keys from the NCC to perform operations such as handover and session key negotiation with the SU. The LEO can receive the LEO public and private keys from the NCC to perform operations such as handover and anonymous authentication with the SU. The SU can register its identity with the NCC, and the NCC can send the SU its anonymous identity, which is used for authentication with the LEO and GS. The SU can also generate its public and private keys.

[0076] The network architecture shown in Figure 2 can also be called a space information network (SIN). SIN can be a network architecture that integrates ground communications and satellite systems. SIN can be built through spacecraft such as satellites, airships, and aircraft. Among them, LEO can forward and amplify ground signals, connect users (such as SU) with remote ground stations, and prevent unauthorized service access. In other words, LEO can establish a secure session between SU ​​and GS, and forward messages for SU or GS to the receiving end. In addition, LEO can provide seamless session switching services to ensure the stable network connection of SU. GS can provide ground network access for LEO and SU, GS can connect to NCC, and provide a ground interface for LEO. SU can be a mobile user, ship, vehicle, aircraft, etc. SU can register with NCC to subscribe to network access services, and then authenticate LEO to obtain network services.

[0077] The SIN system has the advantages of wide coverage and low fading margin. It can also overcome geographical limitations and provide services in special environments such as oceans, airspace, forests, and deserts. SIN is widely used in areas such as ship and aircraft navigation, long-distance telephone transmission, and real-time weather forecasting.

[0078] To prevent unauthorized access to services, implementing a reliable authentication mechanism within the SIN is essential. Similar to terrestrial communications, sensitive personal information and service data are transmitted via satellite ground links. Due to concerns about the misuse of personal data, users prefer to authenticate their SIN anonymously to keep their identities confidential from LEO and satellite operators.

[0079] Anonymous credentials allow individuals to conceal their true identity during identity verification. Anonymous credentials allow users to provide proof of certain attributes or permissions without revealing their true identity. Anonymous credentials can be used in many scenarios, such as online identity verification, digital payments, and access control. For example, anonymous credentials work as follows: a user first generates a credential containing a statement about certain attributes or permissions, such as age, qualifications, and membership level. This credential is then signed and encrypted to ensure its integrity and confidentiality. The user can then provide this anonymous credential to a third-party organization or system requiring identity verification without revealing any personal information. The third-party organization can verify the validity of the credential, but cannot obtain the true identity of the credential holder. This approach protects user privacy and allows users to remain anonymous in scenarios requiring identity verification. Anonymous credential technology relies on cryptographic algorithms, such as digital signatures, zero-knowledge proofs, and encryption, to ensure the security and reliability of the credential. Anonymous credentials provide a secure and privacy-preserving method that allows users to remain anonymous during identity verification while ensuring the validity and credibility of the verification. This is very useful for many application scenarios that need to protect user privacy, such as digital authentication, medical record sharing, identity proof, etc.

[0080] Zero-knowledge proof is a cryptographic concept used to prove that a statement is true without revealing its specific content. In a zero-knowledge proof, a prover can prove the correctness of a statement to a verifier without revealing any other information related to the statement. The unique feature of zero-knowledge proof is that it allows the prover to interactively prove the truth of a statement to the verifier while avoiding revealing sensitive information about the statement. In this process, the prover provides the verifier with a series of interactive proofs to convince the verifier of the statement's truth without revealing any information about the statement itself. Zero-knowledge proof has a wide range of applications in many fields, including cryptography, authentication, security protocols, and privacy protection. Using zero-knowledge proofs, it is possible to achieve the need to prove authenticity while protecting privacy and sensitive information.

[0081] Authentication propagation delay is a challenge that SIN must consider. LEOs orbit the Earth at altitudes of 500-2000 kilometers, with propagation delays of approximately 10-40 milliseconds. To reduce authentication latency, related technical solutions have given LEOs independent authentication capabilities, allowing user verification to be performed with the participation of ground entities (such as SUs and GSs) or requiring LEOs to perform complex calculations (for example, bilinear pairing operations). Due to the difficulty of launching and maintaining satellites in space, LEOs are severely limited in computing resources, making them unsuitable for heavy computing tasks.

[0082] Keyed-verification anonymous credential (KVAC) can be used to reduce the propagation delay of authentication in SIN and improve the efficiency of the authentication scheme. In KVAC, the issuer of the anonymous credential and the verifier of the authentication token share the same secret key, which enables a more efficient anonymous credential design that avoids complex bilinear pairing calculations. KVAC significantly outperforms traditional anonymous credentials in computational overhead. Because LEO orbits far from Earth, verification keys can be deployed in LEO without excessive concern for being compromised by attackers.

[0083] However, the SIN system faces several additional challenges due to its unique deployment environment. The speed of LEOs is approximately 7.5 kilometers per second, and the effective service duration for a given user is 5 to 15 minutes. To ensure real-time service continuity, anonymous users must authenticate different LEOs. Dishonest users may share their anonymous credentials with unauthorized users, which not only provides unauthorized users with more opportunities for illegal use of the service but also reduces the profitability of the SIN service.

[0084] Therefore, how to prevent anonymous users from providing illegal services is an urgent problem to be solved.

[0085] FIG3 is a schematic flow chart of an authentication method 300 provided in an embodiment of the present application. Method 300 can prevent anonymous users from providing illegal services. An embodiment of method 300 is described below with reference to FIG3.

[0086] S310: The first device issues an anonymous credential to the second device. Correspondingly, the second device obtains the anonymous credential issued by the first device.

[0087] The anonymous credential may include a number of authentication times, and the number of authentication times may be used to indicate the number of token identifiers that can be generated by the anonymous credential.

[0088] The first device may be the NCC, LEO or other devices mentioned above. The second device may be the terminal device, access network device, core network device or other devices mentioned above.

[0089] As an example, a first device can send an anonymous credential to a second device, which then receives the credential. As another example, the first device can send a tuple to the second device, which includes the anonymous credential and a zero-knowledge proof that authenticates the first device. The second device can then verify the identity of the first device based on the zero-knowledge proof and, if successful, save the anonymous credential.

[0090] Anonymous credentials can include information such as the number of authentication attempts. They can also include information associated with attribute information. The number of authentication attempts can be used to indicate the number of token identifiers that can be generated by the anonymous credential. The meaning of token identifiers is discussed below and is not detailed here.

[0091] Optionally, in some other implementation scenarios of the above embodiment, the anonymous credential further includes time information, wherein the number of authentication times is used to indicate the number of token identifiers that can be generated by the anonymous credential within the time period indicated by the time information.

[0092] The time information may be an identifier of a time period (TP), and the identifier of the time period is used to indicate in which time period the number of authentication times is valid.

[0093] Through the above embodiment, the time information can limit the time period in which the number of authentications is applied, thereby further preventing anonymous users from illegally using services.

[0094] Optionally, in some other implementation scenarios of the above embodiments, before S310, the method 300 also includes: the first device receives a first zero-knowledge proof from the second device, and the first zero-knowledge proof is used to prove the identity of the second device; the first device determines that the first zero-knowledge proof is successfully verified; wherein S310 includes: the first device sends a tuple to the second device, and the tuple includes the anonymous credential and the second zero-knowledge proof, and the second zero-knowledge proof is used to prove the identity of the first device.

[0095] Accordingly, before S310, the method 300 also includes: the second device generates a first zero-knowledge proof based on the private key of the second device, and the first zero-knowledge proof is used to prove the identity of the second device; the second device sends the first zero-knowledge proof to the first device; the second device receives a tuple from the first device, and the tuple includes the anonymous credential and the second zero-knowledge proof, and the second zero-knowledge proof is used to prove the identity of the first device; the second device determines that the second zero-knowledge proof is successfully verified.

[0096] The second device may generate a private key of the second device. In some optional implementations, the second device may generate the private key of the second device based on a public parameter (PP). The first zero-knowledge proof may prove that the second device possesses the private key of the second device.

[0097] Through the above embodiment, before issuing an anonymous credential, the first device can verify the identity of the second device, and during the anonymous credential issuance process, the second device can verify the identity of the first device. This can prevent other devices from impersonating the first or second device to communicate, thereby improving communication security.

[0098] S320: The second device generates an authentication token and a token identifier for the session based on the anonymous credential.

[0099] The authentication token can be bound to the token identifier. In other words, the authentication token can have a corresponding relationship with the token identifier. In other words, the token identifier is used to identify the authentication token.

[0100] The authentication token and token identifier are session specific, where there can be one or more sessions.

[0101] Optionally, in other implementation scenarios of the above embodiments, S320 includes: the second device generates at least one authentication parameter, the number of the at least one authentication parameter is equal to the number of authentications; the second device generates the token identifier based on one of the at least one authentication parameter, wherein different authentication parameters generate different token identifiers.

[0102] In some other optional implementations, the second device generates a distributor, the distributor including at least one authentication parameter. Thus, each time a token identifier is generated based on one of the at least one authentication parameter, the number of authentication parameters in the distributor is reduced by one.

[0103] As an example, at least one authentication parameter is a sequence of positive integers less than or equal to the number of authentications. For example, if the number of authentications is 5, then the at least one authentication parameter is 1, 2, 3, 4, or 5. As another example, the first device may send instruction information to instruct the second device on how to generate the at least one authentication parameter. For example, the instruction information may indicate that the authentication parameter is a sequence of positive even numbers less than or equal to the number of authentications. Thus, if the number of authentications is 5, then the at least one authentication parameter is 2, 4, 6, 8, or 10. For another example, the instruction information may indicate that the at least one authentication parameter is an arbitrary parameter. Thus, if the number of authentications is 5, then the at least one authentication parameter is an arbitrary real number, complex number, rational number, irrational number, or integer.

[0104] Different authentication parameters generate different token identifiers. In other words, the token identifier is uniquely determined by the authentication parameter. In this way, by at least one authentication parameter, the number of different token identifiers can be limited to be less than or equal to the number of authentication times.

[0105] Through the above solution, the number of different token identifiers can be limited to be less than or equal to the number of authentication times through authentication parameters, further preventing anonymous users from providing illegal use of services.

[0106] S330: The first device receives the authentication token and token identifier for the session from the second device. Correspondingly, the second device sends the authentication token and token identifier to the first device.

[0107] The authentication token and the token identifier are bound together, and the authentication token and the token identifier are generated according to the anonymous credential.

[0108] S340: Verify the validity of the session according to the number of authentication tokens bound to the token identifier.

[0109] Through the above scheme, the number of token identifiers is limited by the number of authentication times, and the token identifier is bound to the number of authentication times. In this way, the second device can only generate authentication tokens that are less than or equal to the number of authentication times, thereby preventing the second device from providing illegal services to other users.

[0110] Optionally, in some other implementation scenarios of the above embodiment, S340 includes: when there are multiple authentication tokens bound to the token identifier, determining that the session verification fails.

[0111] Through the above solution, when the same token identifier is bound to multiple authentication tokens, the first device can determine that the session verification fails, thereby preventing the second device from providing illegal services to other users.

[0112] Optionally, in some other implementation scenarios of the above embodiment, the method 300 further includes: revealing the identity of the second device.

[0113] That is, when there are multiple authentication tokens bound to the token identifier, the identity of the second device is revealed.

[0114] Malicious users may launch distributed denial of service (DDoS) attacks, but due to the anonymous authentication protection mechanism, malicious attackers cannot be identified.

[0115] Through this solution, if a second device binds the same token identifier to multiple authentication tokens, the first device can determine that session verification has failed and reveal the identity of the second device. In other words, the first device can deprive the second device of its anonymity, thereby enabling identification. This solution prevents the identification of anonymous attackers, thereby improving network security.

[0116] FIG4 is a schematic flow chart of another authentication method 400 provided in an embodiment of the present application. Method 400 can be combined with method 300. Method 400 is described below in conjunction with FIG4.

[0117] S410: The first device performs initialization.

[0118] The first device can input security parameter 1 λ and the maximum number of attributes n in an anonymous credential. Among them, security parameter 1 λ Indicates the size of various parameters generated. The first device can λ , n and the initialization (Setup) algorithm output common parameters. The formula is shown below.

[0119] Setup(1 λ ,n)→pp.

[0120] Specifically, the first device may generate a cyclic group G with an order of a prime number p, and randomly extract a random number from the cyclic group G according to the following formula.

[0121] Among them, “$” indicates that the random number on the left side of the arrow is randomly drawn from the cyclic group G. i ,h i ,u i , are the random numbers drawn respectively. It should be noted that u i and They are not associated at the time of extraction, but may be used together in subsequent use.

[0122] The first device may set a hash function according to the following formula.

[0123] H2:{0,1} * →G.

[0124] Where H1 and H2 are hash functions set by the first device. {0,1} * Indicates bits of any length, where H1 indicates bits of any length are mapped to is an integer from 1 to p-1 inclusive; H2 represents the mapping of bits of arbitrary length to the cyclic group G.

[0125] FIG5 is a schematic diagram of a function 500 provided in an embodiment of the present application.

[0126] 5, function 500 includes a 1-bit flag, l TP The time period mark and l k Authentication parameters of bits, The flag may be 0 or 1. Function 500 may be expressed using the following formula.

[0127] Here, function 500 is represented by f. That is, function 500 can be a function with a length of l. k +l TP +1 in binary.

[0128] Alternatively, function 500 may be expressed using the following formula.

[0129] Wherein, a represents the value of the flag, b represents the time period identifier, and c represents the authentication parameter. In some optional implementations, the authentication parameter can be an integer less than or equal to the number of authentications and greater than or equal to 1.

[0130] The public parameter pp can be determined according to the following formula.

[0131] The above formula indicates that pp includes the elements in the brackets to the right of the equal sign. Similar expressions such as (a, b, c) appear below, also indicating that a, b, and c are included, and will not be repeated here. In particular, pp can be used as the default input for other algorithms in method 400.

[0132] S420: The first device generates a first device key, and the second device generates a second device key.

[0133] The first device may generate a first device key according to the following formula.

[0134] IKeyGen(pp)→(isk,ipk).

[0135] The above formula indicates that the first device can take the public parameter pp as input and output the first device public key ipk and the first device private key isk.

[0136] For example, the first device may select multiple random numbers according to the following formula.

[0137] The first device may determine the first device private key isk according to the following formula.

[0138] isk=({x i ,y i} i∈[1,3] ,{z i} i∈[0,n] ).

[0139] The first device may determine multiple parameters according to the following formula.

[0140] in, It represents g1 raised to the power of x1. The meaning of the exponents in other parameters is similar to this, which also represents power exponential operations.

[0141] The first device may determine the first device public key ipk according to the following formula.

[0142] ipk=(X,Y1,Y2,Z).

[0143] The second device may generate the first device key according to the following formula.

[0144] UKeygen(pp,ID u )→(usk,upk).

[0145] The above formula indicates that the second device can use the public parameter pp and the user identity ID u As input, a second device public key upk and a second device private key usk are output.

[0146] For example, the second device may select a random number according to the following formula.

[0147] The second device can calculate the second device public key upk and the second device private key usk according to the following formulas respectively.

[0148] usk=x u ;

[0149] upk=Y u .

[0150] The second device can then use the user IDu and the second device private key usk as registration information, and send the registration information to the first device.

[0151] S430: The first device issues an anonymous credential to the second device.

[0152] In the process of issuing an anonymous credential to a second device by a first device, the first device may take the first device private key isk, the time period identifier TP, and the number of authentication times k as input, and the second device may take the second device private key usk, the second device public key upk, and the second device attribute ATTR as input. The first device and the second device alternately execute the algorithm, so that the second device can obtain the anonymous credential cred TP,k The above process can be expressed by the following formula.

[0153] Among them, D u represents a distributor for managing the number of authentication times, I represents a first device, and U represents a second device.

[0154] For example, the second device can select a random number s′ and calculate the commitment Cm, commitment Cm′ and the first zero-knowledge proof using the following formula:

[0155] Among them, “||” means splicing, which is similar to the meaning of “,”. The second device can use the first zero-knowledge proof Send to the first device. The first device can calculate c and verify the first zero-knowledge proof by the following formula

[0156] If the above equation is true, the first device verifies that the first zero-knowledge proof is successful. The first device can determine the second zero-knowledge proof Π by the following formula I and tuple A.

[0157] ATTR = {attr i} i∈[n] ;

[0158] A=(s″,t,U,V,TP,k,Π I ).

[0159] The first device can send tuple A to the second device. The second device can calculate c' and verify the second zero-knowledge proof Π according to the following formula I .

[0160] If the above equation is true, the second device verifies that the second zero-knowledge proof is successful. The second device can save the anonymous credential cred by the following formula TP,k .

[0161] s=s′+s″;

[0162] cred TP,k =(s,t,U,V,TP,k).

[0163] The second device can initialize the distributor D by the following formula u .

[0164] D u ={1,2,…,k}.

[0165] S440: The second device sends an authentication token to the first device.

[0166] The second device can use the second device private key usk and the anonymous credential cred TP,k , public attribute subset ATTR D , Distributor D u and the message M to be signed as input, generating the authentication token tok, token identifier TIN and the updated distributor D u The above process can be expressed by the following formula.

[0167] TokGen(usk,cred TP,k ,ATTR D ,D u ,M)→(tok,TIN,D u ′).

[0168] For example, the second device may check the distributor D u Is it empty? In the distributor D u If it is not empty, the second device can be in the distributor D u Select authentication parameter Ju , and generate the authentication token tok, token identifier TIN and updated distributor D through the following formula u ′.

[0169] α0=f(0,TP,J u );

[0170] α1=f(1,TP,J u );

[0171] E u ={E0,E1,…,E n};

[0172] w=H1(C u ||D u ||E u );

[0173] Λ4=g0 w ;

[0174] TIN=T u ;

[0175] Among them, E u It can be determined by the following formula.

[0176] For the property element disclosed to the first device.

[0177] For attribute elements that need to remain hidden.

[0178] The second device may send the authentication token tok and the token identifier TIN to the first device, wherein the authentication token tok includes the third zero-knowledge proof The second device can update the distributor to set the authentication parameter Ju , from the initial distributor D u Removed, the formula can be expressed as follows.

[0179] D u′ =D u \{J u}.

[0180] If the dispenser is empty, it indicates that the second device has used up the authorized service times within the time period indicated by the TP. The authentication times for the next time period can be replenished automatically according to the service billing amount.

[0181] S450, the first device verifies the authentication token.

[0182] The first device can use the first device private key isk, the authentication token tok, the token identifier TIN, the public attribute subset ATTR D The message M to be signed is used as input to verify the validity of the session. If it is valid, 1 is output, otherwise 0 is output. The above process can be expressed by the following formula.

[0183] Verify(isk,tok,TIN,ATTR D ,M)→0 / 1.

[0184] The first device can calculate c", and verify the third zero-knowledge proof according to the following formula

[0185] If the above equation is true, the first device successfully verifies the third zero-knowledge proof. If the above equation is not true, the authentication token verification fails and 0 can be output.

[0186] The first device may check whether the time period identifier TP in the authentication token tok is the current time. If it is not the current time, the authentication token verification fails and 0 may be output.

[0187] The first device may check the authentication parameter J in the authentication token tok u Is it an integer between 1 and the number of authentications k? If not, the authentication token verification fails and 0 can be output.

[0188] The first device can be verified according to the following formula.

[0189] If the above equation does not hold, the authentication token verification fails and 0 may be output.

[0190] If the third zero-knowledge proof succeeds, the time period identifier TP is the current time, and the authentication parameter J u is an integer between 1 and the number of authentications k, and if the above equation holds, the authentication token is successfully verified and 1 can be output.

[0191] S460: The second device reveals the identity of the first device.

[0192] The first device can take the authentication token tok, the token identification TIN, and another authentication token tok' as input. If the authentication token tok and the other authentication token tok' are found to be bound to the same token identification TIN, the dishonest user, i.e., the public key upk and identity ID of the first device, can be exposed. u The above process can be expressed by the following formula.

[0193] Reveal(TIN,tok,tok′)→(upk,ID u ).

[0194] For example, the first device may reveal the identity of the first device through the following formula.

[0195] w=H1(C u ||D u ||E u );

[0196] w′=H1(C u′ ||D u′ ||E u′ );

[0197] upk=T2 / (F w )=Y u .

[0198] According to the first device public key upk, the identity ID of the first device can be determined u It is understood that the token identifier TIN is composed of the secret s, the time period identifier TP and the authentication parameter J u It is uniquely determined that a legitimate user cannot generate more than k legitimate identifiers that can be verified by the knowledge signature within the time period indicated by TP.

[0199] The following describes an embodiment of the present application applied to the SIN system with reference to FIG4 .

[0200] The first device may be an NCC. During the execution of S410, the NCC may define the number of authentications k within each time period according to the service time of each LEO. During the execution of S410, the NCC may also be initialized according to the following formula.

[0201] H3:{0,1} * →{0,1} K ;

[0202] SE=(KeyGen,SEnc,SDec);

[0203] DSS=(KeyGen,Sign,Verify).

[0204] Where K is the key space of the secret session key, is the length of the session identifier, and sid is the session identifier. SE represents the symmetric encryption (SE) scheme, which includes the key generation (KeyGen) algorithm, the symmetric encryption (SEnc) algorithm, and the symmetric decryption (SDec) algorithm. DSS represents the digital signature standard (DSS) scheme, which includes the key generation algorithm, the signature (Sign) algorithm, and the verification (Verify) algorithm.

[0205] Alternatively, NCC can initialize two empty lists L user and L tok , used to save the user's registration information and authentication token respectively.

[0206] After executing S410 , the NCC may generate keys for the LEO and the GS.

[0207] For example, the NCC may generate the LEO key according to the following formula.

[0208] sk leo =(x leo ,isk);

[0209] pk leo =(Y leo ,ipk).

[0210] Among them, sk leo is the LEO private key, pk leo is the LEO public key.

[0211] For example, the NCC may generate the key of the GS according to the following formula.

[0212] DSS.Keygen→(Dsk gs ,Dvk gs );

[0213] sk gs =(x gs ,Dsk gs );

[0214] pk gs =(Y gs ,Dvk gs ).

[0215] Among them, sk gs is the GS private key, pk gs GS public key. (Dsk gs ,Dvk gs ) is a signature / verification pair.

[0216] For example, GS can generate a temporary DH pair according to the DH (Diffie-Hellman) algorithm in each time period. GS can run Sig gs =DSS.Sign Dskgs (ID gs ||R gs ||TP), to (ID gs ,R gs ,TP) calculates the signature and (ID gs ,R gs ,Sig gs ) keys are sent to each connected LEO.

[0217] In S420, the SU can u and SU private key usk as registration information, and send the registration information to NCC. After registration is completed, NCC can u ,upk) insert L user .

[0218] When SU ​​subscribes to SIN service, it can first pay the service fee according to the number of authentications k within a certain period, and then execute the interactive protocol with NCC, i.e. S430. NCC can package the service-related data into service transaction parameters SVC. For example, SVC can include package type, validity period, number of authentications and TP corresponding to the number of authentications. NCC can package (upk,cred TP,k ,SVC) insert L user In addition, the NCC key isk can be shared by the NCC and the LEO for verification of the authentication token during the session establishment phase.

[0219] When the SU accesses the SIN, a secure session may be established.

[0220] For example, SU can calculate Execute S440, change (tok, TIN, R u ) is sent to LEO.

[0221] After receiving the request from SU, LEO can execute S450 to verify the legitimacy of SU. If the verification is successful, LEO can calculate the symmetric key shared between LEO and SU. Then, LEO can select the appropriate GS and calculate the symmetric key shared between LEO and GS The appropriate GS may be the GS closest to the SU. The LEO may send a ciphertext to the SU. Send ciphertext to GS LEO can send (tok, TIN) to NCC through a secure channel, and NCC can insert (tok, TIN) into the list L tok .

[0222] After SU receives the message from LEO, SU can calculate and restore (ID gs ,pk gs ,R gs ,Sig gs ). If the signature verification algorithm Returns 1, SU can calculate the secret session key shared between SU ​​and GS Similarly, GS can calculate To restore (R u ,TP,J u ), thereby obtaining the session key SU and GS can calculate the session identifier sid=H4(ssk,TP,J u ). At this point, a secure session using the session key ssk and session identifier ssid is established between the SU and the GS.

[0223] Because LEOs orbit the Earth at high speeds in fixed orbits above the Earth's surface, the topology of the SIN system is constantly changing. This dynamic nature poses challenges to maintaining continuous and private conversations. Therefore, improving the security and service quality of real-time communications is an urgent issue. The handover rate caused by LEO motion can be calculated based on the orbiting satellite's altitude and is periodic and predictable. In contrast, high-speed user movement, such as that of vehicles and aircraft, is another significant and uncontrollable factor leading to session handovers. This necessitates handovers between LEOs and between GSs to provide continuous service.

[0224] FIG6 is a schematic diagram of some authentication switching provided by an embodiment of the present application. In FIG6 , a black solid square represents an SU, a dashed line composed of short lines represents the coverage of an LEO (or C-LEO, or N-LEO), and a dashed line composed of dots represents the coverage of a GS (or GS').

[0225] Compared to the constantly moving LEO, the slow-moving SU is stationary relative to the GS. As shown in Figure 6(a), in this case, LEO handover is the main factor affecting the stability of the session connection due to the shift in LEO coverage. Handover authentication occurs when the current satellite C-LEO leaves the SU's coverage area and can no longer provide SIN service. At this time, the satellite user SU needs to anonymously switch its connection to the new satellite N-LEO.

[0226] For example, SU is allowed to perform at most k anonymous handover authentications within a time period TP. u If it is not empty, the SU can execute S440 to send the authentication token tok and token identifier TIN to the N-LEO. In some optional implementations, the SU can first generate (tok, TIN, D u′ ),Will The ciphertext is sent to the N-LEO as a handover authentication request. After receiving the handover authentication request, the N-LEO can execute S450 to verify the authentication token tok. If the verification is successful, the SU is allowed to continue the secure session with the GS through the N-LEO using the current session identifier sid and secret session key ssk.

[0227] When a Surviving Unit (SU) moves at high speed, for example, when it's carried by various types of vehicles, the GS closest to the SU will constantly change. As shown in Figure 6(b), the SU is within the coverage of the same LEO. However, due to the SU's rapid movement, the connection switches from the current ground station GS to a new ground station GS'. Therefore, the LEO needs to use the updated session identifier sid' and session key ssk' to help the SU establish a new secure session with GS'.

[0228] For high-speed mobile subscribers (SUs), such as those on airplanes and vehicles, handover authentication may involve both a transfer to the covered LEO and a GS handover, as shown in Figure 6(c). Therefore, the secure session is not only handed over from the current C-LEO to the N-LEO, but also from the GS to the GS'. The SU needs to authenticate itself with the N-LEO and then update the secure session information with the GS'. In this scenario, the SU collaborates with the N-LEO and GS' to execute the session establishment protocol described above to generate a new session identifier sid' and secure session key ssk'.

[0229] It should be noted that the embodiments of the present application are not limited to the SIN scenario, for example, they can also be applied to a service-based architecture (SBA).

[0230] FIG7 is a schematic flow chart of another authentication method 700 provided in an embodiment of the present application. Method 700 can be combined with method 300. The embodiment of method 700 is described below in conjunction with FIG7.

[0231] S701: The NRF registers with the NCC and obtains a global parameter pp, where the global parameter pp may include a global public key.

[0232] S702: NCC returns the global parameter pp to NRF.

[0233] S703, network function (NF) 1 initiates a registration request to NRF.

[0234] Among them, NF1 may correspond to the first device, and NF1 may be a terminal device, an access network device, a core network device, etc.

[0235] S704, NRF returns information such as NCC address, certificate, global parameters, and access control attributes endorsed by NRF to NF1.

[0236] S705 , NF1 sends an anonymous identity acquisition request to the NCC, which includes parameters such as NF1's ID, NF1's public key or the access control attributes endorsed by the NRF.

[0237] S706 , NCC issues an anonymous certificate to NF1 , where the anonymous certificate includes information such as the number of authentication times k.

[0238] The above S706 can be understood as some embodiments of S310.

[0239] S707, NF1 determines the service to be accessed.

[0240] S708, NF1 sends a service query request to NRF.

[0241] S709 , the NRF returns the address of the network element providing the service and the attributes required for authenticating NF1 to NF1 according to the service query request of NF1 .

[0242] S710, NF1 generates information such as an authentication token tok and a token identifier TIN according to the received attribute information.

[0243] The above S710 can be understood as some embodiments of S320.

[0244] S711, NF1 initiates a request to the service provider (NF2), which contains the authentication token tok, token identifier TIN and R u and other information.

[0245] S712, NF2 verifies the authentication token tok.

[0246] S713, after NF2 passes the verification, NF2 sends the authentication token tok and token identifier TIN to the NCC.

[0247] The above S711 to S713 can be understood as some embodiments of S330.

[0248] S714, the NCC verifies the authentication token tok and the token identifier TIN, and confirms that the authentication token tok has not been reused.

[0249] The above S714 can be understood as some embodiments of S340.

[0250] S715, NCC returns confirmation information of the verification result to NF2.

[0251] S716, after receiving the confirmation result, NF2 provides service to NF1.

[0252] The following is an introduction to the device embodiment corresponding to the method embodiment of the present application. The following is only a brief introduction to the device, and the specific implementation steps and details of the solution can be referred to the method embodiment above.

[0253] To implement the various functions of the method provided herein, both the first device and the second device may include hardware structures and / or software modules, and implement the aforementioned functions in the form of hardware structures, software modules, or a combination of hardware structures and software modules. Whether a particular one of the aforementioned functions is implemented in the form of hardware structures, software modules, or a combination of hardware structures and software modules depends on the specific application and design constraints of the technical solution.

[0254] 8 is a schematic block diagram of a communication device 800 according to an embodiment of the present application. The communication device 800 includes a processor 810 and a transceiver 820, which may be interconnected via a bus 830. The communication device 800 may be a first device or a second device.

[0255] Optionally, the communication device 800 may further include a memory 840. The memory 840 includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or portable read-only memory (CD-ROM), and is used for related instructions and data.

[0256] The processor 810 may be one or more central processing units (CPUs). In the case where the processor 810 is a CPU, the CPU may be a single-core CPU or a multi-core CPU. The processor 810 may be a signal processor, a chip, or other integrated circuit that can implement the method of the present application, or a portion of the circuitry used for processing functions in the aforementioned processor, chip, or integrated circuit. In addition, the transceiver 820 may also be referred to as an input / output interface or a communication interface. The transceiver 820 is used for input or output of signals or data, and may also be an input / output circuit.

[0257] When communication device 800 is a first device, communication device 800 illustratively includes a processor 810 and a transceiver 820. Transceiver 820 is configured to issue an anonymous credential to a second device and to receive an authentication token and token identifier for a session from the second device. Processor 810 is configured to verify the validity of the session based on the number of authentication tokens bound to the token identifier.

[0258] When the communication device 800 is the second device, the communication device 800 illustratively includes a processor 810 and a transceiver 820. The transceiver 820 is configured to obtain an anonymous credential issued by the first device and to send the authentication token and the token identifier to the first device. The processor 810 is configured to generate an authentication token and a token identifier for the session based on the anonymous credential.

[0259] The above description is merely exemplary. For details, please refer to the contents of the above method embodiments. The implementation of each operation in FIG8 may also correspond to the corresponding description of the method embodiments shown in FIG3 to FIG7.

[0260] Figure 9 is a schematic block diagram of another communication device 900 according to an embodiment of the present application. Communication device 900 can be the first device or the second device, or a chip or module within the first device or the second device, configured to implement the methods described in the above embodiments. Communication device 900 includes a transceiver unit 910. The following provides an exemplary description of transceiver unit 910.

[0261] The transceiver unit 910 may include a transmitting unit and a receiving unit. The transmitting unit is used to perform a transmitting operation of the communication device, and the receiving unit is used to perform a receiving operation of the communication device. For ease of description, this embodiment of the application combines the transmitting unit and the receiving unit into a single transceiver unit. This is described here as a unified description and will not be repeated later.

[0262] When the communication device 900 is a first device, illustratively, the transceiver unit 910 is configured to issue an anonymous credential, etc. to a second device.

[0263] Optionally, the communication device 900 may further include a processing unit 920, which is used to execute the content of the terminal device involving processing, coordination and other steps.

[0264] When the communication device 900 is the second device, illustratively, the transceiver unit 910 is configured to obtain an anonymous credential issued by the first device.

[0265] Optionally, the communication device 900 may further include a processing unit 920, which is used to execute the content of steps involving processing, coordination, etc. of the network device.

[0266] The above contents are merely exemplary descriptions. When the communication device 900 is a terminal device or a network device, it will be responsible for executing the methods or steps related to the terminal device or the network device in the above method embodiments.

[0267] Optionally, the communication device 900 further includes a storage unit 930, which is used to store a program or code for executing the aforementioned method.

[0268] The device embodiments shown in Figures 8 and 9 are used to implement the contents described in Figures 3 to 7. The specific execution steps and methods of the devices shown in Figures 8 and 9 can refer to the contents described in the above method embodiments.

[0269] The present application also provides a chip, including a processor, for calling and executing instructions stored in a memory, so that a communication device equipped with the chip executes the methods in the above examples.

[0270] The present application also provides another chip, comprising: an input interface, an output interface, and a processor, wherein the input interface, the output interface, and the processor are connected via an internal connection path, and the processor is configured to execute code in a memory. When the code is executed, the processor is configured to execute the methods in the above examples. Optionally, the chip also includes a memory, which is configured to store computer programs or code.

[0271] The present application also provides a processor for coupling with a memory, and for executing the methods and functions involving a terminal device or a network device in any of the above embodiments.

[0272] In another embodiment of the present application, a computer program product including instructions is provided. When the computer program product is run on a computer, the method of the above embodiment is implemented.

[0273] The present application also provides a computer program. When the computer program is executed in a computer, the method of the aforementioned embodiment is implemented.

[0274] In another embodiment of the present application, a computer-readable storage medium is provided, which stores a computer program. When the computer program is executed by a computer, the method described in the above embodiment is implemented.

[0275] The present application also provides a communication system, including a first device and a second device, wherein the first device and the second device respectively execute the methods corresponding to the first device and the second device in the present application.

[0276] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0277] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0278] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0279] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0280] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0281] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0282] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. An authentication method, characterized in that: The method is applied to a first device, wherein the method comprises: issuing an anonymous credential to the second device, the anonymous credential comprising an authentication number, the authentication number being used to indicate the number of token identifiers that can be generated by the anonymous credential; receiving an authentication token and a token identifier for a session from the second device, the authentication token and the token identifier being bound, and the authentication token and the token identifier being generated based on the anonymous credential; The validity of the session is verified according to the number of authentication tokens bound to the token identifier.

2. The method according to claim 1, characterized in that: The verifying the validity of the session according to the number of authentication tokens bound to the token identifier comprises: In the case that there are multiple authentication tokens bound to the token identifier, it is determined that the session verification fails.

3. The method according to claim 2, characterized in that Also includes: The identity of the second device is revealed.

4. The method according to any one of claims 1 to 3, characterized in that Before issuing the anonymous credential to the second device, the method further includes: receiving a first zero-knowledge proof from the second device, where the first zero-knowledge proof is used to prove the identity of the second device; Determine that the first zero-knowledge proof is successfully verified; wherein, The issuing of an anonymous credential to the second device comprises: A tuple is sent to the second device, the tuple including the anonymous credential and a second zero-knowledge proof for proving the identity of the first device.

5. The method according to any one of claims 1 to 4, characterized in that The anonymous credential further includes time information, wherein the number of authentication times is used to indicate the number of token identifiers that can be generated by the anonymous credential within the time period indicated by the time information.

6. An authentication method, characterized in that: The method is applied to a second device, wherein the method comprises: Acquire an anonymous credential issued by the first device, wherein the anonymous credential includes an authentication number, and the authentication number is used to indicate the number of token identifiers that can be generated by the anonymous credential; Generate an authentication token and a token identifier for a session according to the anonymous credential, wherein the authentication token and the token identifier are bound; The authentication token and the token identifier are sent to the first device.

7. The method according to claim 6, characterized in that The step of generating an authentication token and a token identifier for a session according to the anonymous credential comprises: generating at least one authentication parameter, wherein the number of the at least one authentication parameter is equal to the number of authentication times; The token identifier is generated according to one of the at least one authentication parameter, wherein different token identifiers are generated by different authentication parameters.

8. The method according to claim 7, characterized in that In the case that there are multiple authentication tokens bound to the token identifier, the identity of the second device is revealed.

9. The method according to any one of claims 6 to 8, characterized in that Before obtaining the anonymous credential issued by the first device, the method further includes: generating a first zero-knowledge proof according to the private key of the second device, where the first zero-knowledge proof is used to prove the identity of the second device; sending the first zero-knowledge proof to the first device; receiving a tuple from the first device, the tuple comprising the anonymous credential and a second zero-knowledge proof, the second zero-knowledge proof being used to prove the identity of the first device; It is determined that the second zero-knowledge proof verification is successful.

10. The method according to any one of claims 6 to 9, characterized in that The anonymous credential further includes time information, wherein the number of authentication times is used to indicate the number of token identifiers that can be generated by the anonymous credential within the time period indicated by the time information.

11. A first device, characterized in that: include: A credential issuing module, used to issue an anonymous credential to the second device, wherein the anonymous credential includes an authentication number, and the authentication number is used to indicate the number of token identifiers that can be generated by the anonymous credential; a transceiver module, configured to receive an authentication token and a token identifier for a session from the second device, wherein the authentication token and the token identifier are bound and are generated according to the anonymous credential; The verification module is used to verify the validity of the session according to the number of authentication tokens bound to the token identifier.

12. The device according to claim 11, characterized in that The verification module is specifically used for: In the case that there are multiple authentication tokens bound to the token identifier, it is determined that the session verification fails.

13. The device according to claim 12, characterized in that Also includes: The disclosure module is configured to disclose the identity of the second device.

14. The device according to any one of claims 11 to 13, characterized in that The transceiver module is further used to receive the zero-knowledge proof from the second device; The verification module is also used to determine whether the zero-knowledge proof verification is successful.

15. The device according to any one of claims 11 to 14, characterized in that The anonymous credential further includes time information, wherein the number of authentication times is used to indicate the number of token identifiers that can be generated by the anonymous credential within the time period indicated by the time information.

16. A second device, characterized in that: include: A transceiver module, used to obtain an anonymous credential issued by a first device, wherein the anonymous credential includes a number of authentication times, and the number of authentication times is used to indicate the number of token identifiers that can be generated by the anonymous credential; A token generation module, used to generate an authentication token and a token identifier for a session according to the anonymous credential, wherein the authentication token and the token identifier are bound; The transceiver module is further configured to send the authentication token and the token identifier to the first device.

17. The device according to claim 16, characterized in that The token generation module is specifically used for: generating at least one authentication parameter, wherein the number of the at least one authentication parameter is equal to the number of authentication times; The token identifier is generated according to one of the at least one authentication parameter, wherein different token identifiers are generated by different authentication parameters.

18. The device according to claim 17, characterized in that In the case that there are multiple authentication tokens bound to the token identifier, the identity of the second device is revealed.

19. The device according to any one of claims 16 to 18, characterized in that Also includes: a verification module, configured to generate a first zero-knowledge proof according to a private key of the second device; The transceiver module is further used to send the first zero-knowledge proof to the first device, and is also used to receive a tuple from the first device, the tuple including the anonymous credential and the second zero-knowledge proof; The verification module is further configured to determine whether the second zero-knowledge proof is successfully verified.

20. The device according to any one of claims 16 to 19, characterized in that The anonymous credential further includes time information, wherein the number of authentication times is used to indicate the number of token identifiers that can be generated by the anonymous credential within the time period indicated by the time information.

21. A computing device, characterized in that The method comprises a processor and a memory, wherein the processor is used to execute instructions stored in the memory so that the computing device executes the method according to any one of claims 1 to 5, or the computing device executes the method according to any one of claims 6 to 10.

22. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device, the computing device is caused to execute the method according to any one of claims 1 to 5, or the computing device is caused to execute the method according to any one of claims 6 to 10.

23. A computer-readable storage medium, characterized in that: The method comprises computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the method according to any one of claims 1 to 5, or the computing device executes the method according to any one of claims 6 to 10.

Citation Information

Patent Citations

  • Efficient anonymous single sign-on system and method based on secret key verification voucher

    CN115941232A

  • Traceable anonymous authentication method and system

    CN116582275A

  • A system and method of dynamic issuance of privacy preserving credentials

    US20150341340A1

  • Filtering incoming e-mail

    US6484197B1

Cited By

  • Identity authentication authorization method and system

    CN121037138A