The invention discloses a zero-knowledge proof identity
authentication system and method based on an RISC-V trusted execution environment. The zero-knowledge proof identity
authentication system comprises a Keystone-Enclave trusted execution environment
system running on an RISC-V architecture; the Keystone-Enclave trusted execution environment system comprises two isolated Enclaves, namely, a ProverEnclave and a VerifierEnclave, and further comprises a Host application program which is operated in a common
operating system, and the Host application program is used for executing the Host application program in the common
operating system. The ProverEnclave is used for generating a zero-knowledge proof to prove that the ProverEnclave masters a legal user identity, the VerifierEnclave is internally provided with an
access control list (ACL) and is responsible for verifying the proof and authority, and the Host application program is only used as a message
relay for communication between the two Enclaves; the ProverEnclave and the VerifierEnclave cooperate with each other, so that all sensitive operations of
processing the private identity information user, generating and verifying the zero-knowledge proof, checking the ACL and managing the challenge value are limited to be completed in the trusted execution environment. The method has the advantages that whole-course secret-state calculation is achieved, secret keys and identity information never come out of Enclave, verifiability is high, replay and permission bypassing are resisted, and comprehensive safety and performance advantages can be achieved by efficient deployment on a lightweight RISC-V platform.