Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

39 results about "Anonymous authentication" patented technology

Blockchain-based anonymous authentication method for cross-trusted authority in internet of vehicles

PendingUS20260012346A1User identity/authority verificationTrusted authorityInternet privacy
The invention belongs to the field of computer security and discloses a blockchain-based anonymous authentication method for the Internet of Vehicles across trusted authorities, including registering the vehicle (with onboard unit) and roadside unit in their respective trusted authorities. When the vehicle enters different trusted authority domains, both the onboard unit and roadside unit generate corresponding authentication parameters and transmit them to the consortium blockchain of the Internet of Vehicles for verification and signature, obtaining authenticated data signed by the consortium blockchain. The onboard unit and roadside unit receive and verify the authenticated data, and upon successful verification, the onboard unit calculates a session key. The onboard unit uses the session key to sequentially transmit data with the roadside unit and the consortium blockchain. This technical solution allows vehicles from any trusted authority domain to authenticate and negotiate session keys with roadside units from different trusted authority domains.
Owner:HANGZHOU NORMAL UNIVERSITY

Distributed energy storage equipment cross-domain security access authentication method and related device

The invention belongs to the technical field of security authentication, and discloses a distributed energy storage equipment cross-domain security access authentication method and a related device, attribute information is submitted after zero-knowledge proof verification, and a certificate issuing party is triggered to generate a verifiable certificate based on a signature algorithm; then generating a zero-knowledge proof-based randomized verifiable representation based on the verifiable credentials; and finally, the energy storage device sends the generated randomized verifiable representation to a verifier to complete access authentication. According to the invention, cross-domain authentication is realized through a distributed architecture and verifiable certificates without depending on a single centralized mechanism. Verifiable certificates adopt a uniform format and support mutual recognition among different trust domains. And the certificate cannot be associated with a specific equipment identity after randomization processing, so that anonymous authentication is realized. And the verification process is realized through zero-knowledge proof, and the equipment can prove the identity legality without leaking sensitive information, so that the authentication security and privacy are effectively guaranteed.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD

Internet of Things data security sharing method facing block chain fragmentation

The invention relates to an Internet of Things data security sharing method for blockchain fragmentation. The method comprises the following steps: firstly, performing identity anonymous authentication based on an auditing mechanism combining encryption packaging and zero-knowledge proof; thirdly, performing threshold slicing on the to-be-stored data by adopting an IDA slicing algorithm, performing dynamic allocation of storage nodes based on weighted consistency hash, and performing data storage and distribution based on the allocated storage nodes; afterwards, a PBFT consensus mechanism based on behavior reputation is adopted to carry out security auditing of data recovery and storage, a recovery voucher is generated, and on-chip data recovery is carried out; and finally, querying a target fragment of data distribution based on a trusted relay cross-fragment transaction mechanism, and completing cross-fragment data recovery in the target fragment. According to the invention, high efficiency and security of IoT data sharing and terminal identity privacy protection can be realized, and application requirements in a large-scale IoT environment are well met.
Owner:SICHUAN UNIV +1

A secure and revocable anonymous authentication method for internet of things

The application discloses a kind of enhanced security revocable anonymous authentication method of Internet of Things, including the following steps, S1: system initialization, for generating public parameters and user registration;S2: authentication between user and gateway, for identity authentication and session key establishment;S3: password update and revocation, authorized user can update password, gateway can revoke malicious user.It is beneficial to generate a pseudonym using the random number of gateway, provide a safe and effective identity privacy protection scheme, perfectly solve the problem of anonymity and message unlinkability.Add an effective revocation mechanism, when malicious user appears, gateway will record it to revocation list, and gateway does not provide key generation service for the user, so as to realize user revocation, realize identity authentication, anonymity, unlinkability, password update and revocation, etc.Security requirements such as.
Owner:ANHUI AGRICULTURAL UNIVERSITY

A communication network anonymous authentication method, user equipment, home network and product

The application discloses a communication network anonymous authentication method, user equipment, a home network and a product, wherein a network side parameter value is obtained by calculating according to an encryption parameter value in received authentication data; and a replay attack is identified according to the size of the network side parameter value and a locally stored terminal parameter value. The application scheme can identify a tracking attack on user location information and protect the privacy security of a terminal user.
Owner:CHINA MOBILE COMM LTD RES INST +1

Unmanned aerial vehicle anonymous authentication and identity remote identification method, unmanned aerial vehicle and supervision equipment thereof

The application provides a kind of unmanned plane anonymous authentication and identity remote identification method, unmanned plane and its supervision equipment, the method includes: by unmanned plane service provider in advance selecting system main private key and main public key, define attribute set;And by unmanned plane registration process, generate and issue certificate for the unmanned plane;Unmanned plane running process, generate RID data packet that can be anonymous authentication and meet RID rule;RID data packet includes the following information: unmanned plane position, unmanned plane speed, unmanned plane attribute ciphertext, unmanned plane operator's location ciphertext, encrypted unmanned plane public key information, time stamp, group signature;Timing broadcast RID data packet, so that receiver obtains the position and flight speed of unmanned plane according to the received RID data packet. Utilize the scheme of the application, the effective management and privacy protection of unmanned plane can be realized.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA +1

Efficient anonymous authentication method and system applied to identity authentication

The invention discloses an efficient anonymous authentication method and system applied to identity authentication, an identity provider performs system initialization, a service provider performs legality check on user service qualification, and a block chain stores and manages identity information associated with a user and a data file of an anonymous certificate. After a delegation request of the user is received, re-proxy verification is completed; a user stores and manages the files through a block chain, the user sends a service request to the block chain when service qualification verification needs to be carried out, a service provider sends materials required by verification to the user and the block chain, and the block chain sends the materials required by verification to the user and the block chain after obtaining a one-time authorization token displayed by an anonymous certificate of the user. And the block chain completes service qualification verification of the user. According to the method, the block chain is integrated, and the proxy zero-knowledge proof scheme is introduced, so that the storage and calculation overhead is outsourced to the block chain, the privacy and the control right of the user are ensured, and seamless and efficient anonymous authentication between the user and the service provider is finally realized.
Owner:ANHUI UNIV

Security federal learning method and system based on dynamic group signature

The invention discloses a security federal learning method and system based on a dynamic group signature, an administrator generates a bilinear group and public and private keys, and a client encrypts gradient information after applying for joining the group and uploads the gradient information with a group signature. And the server decrypts and verifies the validity of the signature, detects malicious clients through cosine similarity, removes malicious nodes and generates a blacklist, and contributes a three-dimensional weight aggregation model to normal clients according to data volume, quality and history. According to the scheme, identity anonymous authentication and malicious detection are achieved, model aggregation safety is guaranteed, federal learning robustness and efficiency are improved, and the method is suitable for data privacy sensitive scenes.
Owner:湖南工商大学

Traceable anonymous token method and system based on completely extractable n-time signatures

PendingCN122069034AKey distribution for secure communicationUser identity/authority verificationCommitment schemeAnonymous authentication
The invention discloses a method capable of extracting an n-time signature, a method capable of completely extracting the n-time signature, and a traceable anonymous authentication method and system based on the n-time signature, in the n-time signature capable of being extracted, a public key and a private key are generated by a polynomial commitment scheme, and the private key comprises a core polynomial and a mask polynomial; an identifier bound with a public key can be extracted from the effective signature exceeding the signature capacity, and a user private key can also be extracted by the method for completely extracting the signatures for n times. Based on the fact that the application capable of completely extracting the signatures for n times is a traceable anonymous token, anonymity of the user is achieved through the signatures in the authentication process, and when the preset number of times is exceeded, the identity of the user can be traced by extracting the identifiers. The traceable anonymous token is jointly maintained by a plurality of participants, and operations such as key generation, signature verification and identity tracing need to be jointly completed by the participants, so that the traceable anonymous token method based on the extractable n-time signatures is realized.
Owner:WUHAN UNIV

One-time pad key management method based on grouped confusion Merkel Hash tree

The invention discloses a one-time pad key management method based on a grouped confusion Merkel hash tree, and relates to the technical field of information security. According to the method, the Internet of Things equipment is divided into different equipment groups, a group administrator is introduced into each equipment group to replace a trusted center to perform key management in the group, and only the Merkel Hash tree constructed by taking the equipment one-time pad key as a leaf needs to be confused in the equipment group, so that the confusion scale and height of the Merkel Hash tree are reduced; a secure channel distribution authentication path only needs to be constructed in the device group, frequent intervention of a trusted center is avoided, and therefore the key management efficiency is improved. The method solves the problem of high efficiency in realizing conditional anonymous authentication of the Internet of Things equipment by confusing the Merkel Hash tree, is not only suitable for constructing a conditional anonymous lightweight Internet of Things authentication protocol, but also can be popularized and applied to post-quantum group signature based on the Merkel Hash tree.
Owner:JIANGSU UNIV OF TECH

Anti-quantum traceable anonymous authentication method and anti-quantum traceable anonymous authentication system for mobile Internet of Things

The invention discloses an anti-quantum traceable anonymous authentication method and system for a mobile internet of things, and belongs to the technical field of identity authentication and tracking. The method comprises an initialization stage, a mobile Internet of Things equipment registration stage, a mobile Internet of Things equipment authentication stage and a mobile Internet of Things equipment tracking and revocation stage. Bidirectional authentication and session key negotiation between an edge node and equipment are realized by utilizing a lattice-based chameleon hash and a short integer solution problem, quantum computing attacks are resisted, and meanwhile, the equipment identity and path privacy are protected through block chain evidence storage and a chameleon hash trap door technology, and the security of the equipment is improved. And on-demand accurate tracing and rapid revocation of malicious equipment by a law enforcement agency can be supported, and the requirements of safety, privacy and supervision in a mobile Internet of Things scene are met.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

A blockchain-based completely anonymous authentication and key agreement method in a vehicle networking environment

The application discloses a kind of complete anonymous authentication and key agreement method based on block chain in Internet of Vehicles, belong to block chain and vehicle-mounted network technical field, design a kind of pseudonym generation algorithm based on homomorphic encryption, guarantee the verifiability of vehicle pseudonym While, the complete anonymity of vehicle pseudonym is realized;On this basis, an automatic pseudonym revocation mechanism is designed, a time-dependent secret value is embedded into the pseudonym, and the secret value is updated regularly to automatically revoke the expired pseudonym;In addition, the vehicle certificate is verified and stored using decentralized blockchain technology, which improves the authentication efficiency of the vehicle certificate;The application not only realizes the verifiability and complete anonymity of vehicle pseudonym, but also realizes the automatic revocation of pseudonym, and can be used in various authentication scenarios under Internet of Vehicles environment.
Owner:QUFU NORMAL UNIV

Anonymous identity verification method and system

ActiveCN119854000Bwill not be leakedImplement anonymous authenticationKey distribution for secure communicationUser identity/authority verificationAlgorithmRandom array
The embodiments of the present specification provide an anonymous identity authentication method and device. According to the method, a first device generates a binary indication vector and an auxiliary vector having a predetermined relationship with the indication vector according to the sequence index of a first account in a target account set; and generates a signature value C according to the indication vector, the auxiliary vector and a private key of the first account. A first public key vector is also calculated according to a first random number selected by a verification device and a public key sequence of the target account set, and a blinding value is calculated based on the first public key vector and a random number array selected by the first device. The first device further generates a first and second group of commitment values according to the indication vector, the auxiliary vector and a challenge array and a variable value selected by the verification device. The first device provides the signature value C, the blinding value and the first and second group of commitment values to the verification device, and the verification device verifies whether the first account belongs to the target account set according to the foregoing.
Owner:ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD

A smart contract on-chain identity authentication permission authentication method and system

The application relates to the technical field of blockchains, in particular to a smart contract chain on-line identity authentication permission authentication method and system. The method comprises the following steps: generating a private certificate that can be directly verified in a cipher domain by adopting Paillier homomorphic encryption and zero-knowledge proof technology; structurally storing the private certificate by adopting a hierarchical Merkle tree, and taking a root hash as an efficient on-line identity identifier; realizing cross-chain anonymous authentication by adopting ring signature, guaranteeing the privacy of interaction; after authentication, constructing a channel based on a two-way commitment and a time lock, and ensuring that the encryption attribute is safely and atomically exchanged between chains; and introducing a differential privacy mechanism, adding noise to an authentication log, and generating privacy protection data that can be used for safe auditing. The application scheme constructs a decentralized identity authentication system that has strong privacy protection, high security and cross-chain interoperability.
Owner:YANCHENG SHURONGZHISHENG TECH CO LTD

Anonymous certificate registration method, anonymous authentication method and electronic equipment

The invention discloses an anonymous certificate registration method, an anonymous authentication method and electronic equipment, and relates to the technical field of computer and network security, and the method comprises the steps: sending an intra-domain user public key information request to a cloud, and receiving a public key information list returned by the cloud; constructing a to-be-signed message, generating a ring signature in combination with the message, a preset anonymous key pair set and a public key information list, and generating a holding certificate of a current user through a preset temporary anonymous key pair private key; an anonymous public key registration request is generated according to the ring signature, the to-be-signed message and the holding proof and sent to the cloud, and the cloud completes registration based on the request, generates an anonymous subject identifier of the temporary anonymous public key and stores a mapping relation between the anonymous subject identifier and the temporary anonymous public key in a public key library. A ring signature is introduced as a group qualification certificate, and registration of an anonymous public key is completed at a cloud end, so that the problems that all users share the same anonymous identity, so that the anonymous identity cannot be distinguished, and fine-grained management and auditing are difficult to perform are solved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Method and apparatus for authentication

Embodiments of the present application provide a method and an apparatus for authentication. In the present application, an authentication ID is introduced for authentication of a device by an authentication server, and a device's temporary ID is used for anonymous communication among gateways and service providers. The authentication ID is only known by an IDM function and the AS, thereby achieving anonymous authentication and device's ID privacy protection.
Owner:HUAWEI TECH CO LTD

Federal differential privacy logistics express sheet security processing system facing edge terminal

The invention discloses an edge terminal-oriented federal differential privacy logistics express sheet security processing system, and relates to the technical field of image processing and privacy computing. According to the invention, for a logistics tail end distribution scene, a cloud-side-end three-layer architecture is adopted; a cloud server is responsible for surface sheet image rough desensitization and sample distribution; the edge server is responsible for jurisdiction terminal management, gradient aggregation and malicious detection; the edge terminal is internally provided with an image acquisition module, a fine desensitization module, a lightweight model training module, a differential privacy disturbance module, an anonymous identity verification module and a breakpoint resume module. Differential privacy noise adding is completed locally at the terminal, and it is ensured that the original gradient does not go out of the terminal; bidirectional anonymous verification is realized through group signature and zero-knowledge proof, and malicious behavior traceability is supported; a breakpoint resume and three-level cache mechanism is designed for a weak network environment, and the uploading success rate is improved. According to the method, data localization storage and quantifiable privacy protection are realized, various threats such as gradient inversion, Sybil attack and replay attack are effectively defended, the method adapts to the actual working conditions that logistics handheld terminal resources are limited and the network is unstable, and the safety, reliability and compliance of the system are remarkably improved.
Owner:SHANGHAI LIXIN UNIV OF ACCOUNTING & FINANCE

Lightweight certificateless anonymous authentication method for industrial edge intelligent control system

The invention relates to a lightweight certificateless anonymous authentication method for an industrial edge intelligent control system, which can be applied to the field of industrial Internet of Things information security, and comprises the steps of system establishment, equipment registration, mutual authentication and key negotiation, batch authentication, illegal terminal equipment tracking, illegal terminal equipment revocation and the like. According to the invention, mutual anonymous authentication and key agreement between the edge intelligent controller and the terminal equipment can be realized, and batch anonymous authentication of the edge intelligent controller on multiple pieces of terminal equipment can also be realized. Once a certain terminal device has an illegal behavior, the method has the functions of tracking and cancelling the illegal terminal device. Compared with a traditional authentication method which is tedious in certificate management and high in calculation complexity, the authentication method has the advantages of being certificateless, lightweight and the like and is suitable for the industrial edge intelligent control system which is a resource-limited scene, and the credibility and the safety of the industrial edge intelligent control system are improved.
Owner:COLLEGE OF MOBILE TELECOMM CHONGQING UNIV OF POSTS & TELECOMM

Unmanned aerial vehicle authentication and key negotiation system and method based on PUF and chaotic mapping

The invention discloses an unmanned aerial vehicle authentication and key negotiation system and method based on PUF and chaotic mapping, and relates to the field of information security and cryptographic protocol security. The system generates a unique challenge-response pair through an unmanned aerial vehicle terminal PUF module to complete registration, a four-way handshake mechanism is adopted in the authentication stage, a session key is dynamically generated in combination with Henon chaotic mapping, the number of chaotic iterations is hidden through XOR operation, and identity legality is guaranteed through multi-layer MAC verification. According to the method, secret keys do not need to be pre-stored, the PUF physical unclonability and the chaotic mapping sensitivity are utilized, anonymous authentication and forward security are achieved, lightweight computing adapts to unmanned aerial vehicle resource constraints, various attacks are effectively resisted, and communication security is guaranteed.
Owner:JINLING INST OF TECH

Vehicle weighing intelligent monitoring method and system based on Internet of Things

The invention discloses a vehicle weighing intelligent monitoring method and system based on the Internet of Things, and the method comprises the steps: carrying out the bidirectional anonymous authentication through a vehicle-mounted OBU and a wagon balance edge node, verifying the legality of a vehicle, and starting a weighing process of a corresponding trust level; after successful authentication, heterogeneous physical field data are synchronously collected and processed in real time through multiple sensors, and a force-shape-heat-sound coupling verification vector is constructed; based on the collected data, the three-dimensional pose of the vehicle is reconstructed through the UWB positioning technology and the visual SLAM technology, and if the vehicle is unstable, the weighing is automatically cancelled; according to vehicle stability and abnormal judgment of weighing data, trust evaluation is carried out on vehicles through a dynamic trust scoring mechanism, high-trust vehicles enter a fast channel, and low-trust vehicles trigger full-mode monitoring and AI behavior analysis; weighing data, a risk assessment result and a model optimization log are encrypted and uploaded through a block chain technology, and a unique hash value is generated in combination with a timestamp.
Owner:ANHUI DIANHYDROGEN INTELLIGENT TRANSPORT IOT TECH CO LTD

Low-altitude Internet of Things bidirectional anonymous authentication method based on BLS aggregation signature

The invention discloses a low-altitude Internet of Things bidirectional anonymous authentication method based on a BLS aggregation signature. The method comprises the steps that a trusted mechanism generates and discloses bilinear pairing system parameters; the unmanned aerial vehicle registers with a ground control station to obtain a public and private key pair based on a BLS algorithm and an initial dynamic pseudonym with timeliness; the unmanned aerial vehicle generates a BLS signature for the authentication message by using the current dynamic pseudonym and the private key and broadcasts the BLS signature; the ground control station executes aggregation verification on the received at least one BLS signature, and verifies the validity of all signatures at one time; the two parties complete bidirectional authentication after the verification is passed; and after the authentication session ends, the unmanned aerial vehicle updates the dynamic pseudonym without mathematical association between the new and old pseudonyms. According to the method, the calculation complexity of batch verification is reduced to a constant level through the BLS aggregation signature, and the authentication delay in a high-concurrency scene is remarkably reduced; and intersession linkability is cut off through a dynamic pseudonym updating mechanism, and identity and track privacy protection is realized.
Owner:JIANGSU UNIV OF TECH

Anonymous authentication method, device, system and equipment, storage medium and program product

The invention provides an anonymous authentication method, device and system, equipment, a storage medium and a program product, and relates to the technical field of security. The method comprises the following steps: when UE needs to update an anonymous identifier, generating a first message authentication code based on the anonymous identifier of the UE; sending the first request message to an application function AF network element; the first request message comprises a first message authentication code and an anonymous identifier, and the first request message is used for indicating establishment of an application session; receiving a first response message returned by the AF network element; and updating the anonymous identifier if it is determined that the anonymous identifier needs to be updated based on the first response message. According to the method and the device, the anonymous identifiers are updated, and different anonymous identifiers can be adopted when the UE accesses the AF, namely, the UE can use the different anonymous identifiers to carry out service requests and access one or more AF network elements, so that the privacy information of the UE is better protected, and the security of the UE is improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Block chain-based anonymous authentication method and system for internet of vehicles

The application discloses a kind of based on block double chain's Internet of Vehicles anonymous authentication method and system, mainly solve the problems of low security, poor scalability and high centralization risk in prior art in authentication.Its implementation scheme includes: initializing vehicle service provider VSP and the block chain main chain maintained by it;Vehicle V submits registration application and real identity identification to adjacent VSP;VSP generates random pseudonym and issues anonymous pseudonym certificate, links it and generates Merkle root and writes into side chain;When vehicle V accesses network, it uses unused pseudonym certificate to send authentication request to RSU, RSU forwards it to main chain node, and side chain node obtains pseudonym certificate based on Merkle root to assist main chain node, verifies its consistency with main chain certificate, to determine the identity of vehicle V.The application has the advantages of strong identity privacy protection capability and high authentication efficiency, and can be used for identity privacy, authentication security and efficient information sharing in multi-domain communication environment.
Owner:XIDIAN UNIV

Multi-party federal learning method based on ring signature homomorphic compression and related device

The invention provides a multi-party federal learning method based on ring signature homomorphic compression and a related device. The method comprises the steps that a central aggregation platform generates a three-layer key system and initializes global model parameters through initialization operation; each participant platform trains a local model according to the initialized global model parameters and a local data set to obtain a model updating gradient, and processes the model updating gradient to obtain a hierarchical encryption gradient; anonymous identity verification information is generated based on the three-layer key system; the central aggregation platform performs identity authentication on each participant platform based on the anonymous identity authentication information and the hierarchical encryption gradient, and performs homomorphic aggregation operation based on the hierarchical encryption gradient to obtain a global aggregation gradient; and each participant platform receives and processes the global aggregation gradient, and updates the local model. According to the invention, the problems of data privacy security, communication efficiency and identity authentication in federated learning are solved, and the data privacy security of each participant is ensured at the same time.
Owner:FIBRLINK NETWORKS +5

Authority authentication method and system for identity authentication on smart contract chain

The invention relates to the technical field of block chains, in particular to an identity authentication authority authentication method and system on an intelligent contract chain, and the method comprises the steps: employing a Paillier homomorphic encryption and zero-knowledge proof technology, and generating a privacy certificate which can be directly verified in a ciphertext domain; the privacy voucher is stored in a hierarchical Merkel tree structure, and the root hash is used as an efficient on-chain identity identifier; according to the method, cross-chain anonymous authentication is realized by using a ring signature, the privacy of interaction is ensured, and after the authentication is passed, a channel based on bidirectional commitment and a time lock is constructed to ensure that encryption attributes are safely and atomized exchanged between chains; and introducing a differential privacy mechanism, adding noise to the authentication log, and generating privacy protection data for security audit. According to the scheme of the invention, a decentralized identity authentication system with strong privacy protection, high security and cross-chain interoperability is constructed.
Owner:YANCHENG SHURONGZHISHENG TECH CO LTD

Unmanned aerial vehicle swarm authentication and group key negotiation method and system based on TESLA protocol

The invention discloses an unmanned aerial vehicle swarm authentication and group key negotiation method and system based on a TESLA protocol, and belongs to the technical field of network security. The method comprises the steps that a trusted mechanism generates public parameters; the unmanned aerial vehicle generates a response by using a physical unclonable function, the trusted institution calculates a Pedersen commitment according to the response and stores the Pedersen commitment into the ground base station, and then the trusted institution can be offline; the unmanned aerial vehicle constructs a non-interactive zero-knowledge proof by using a local PUF response, and the ground base station negotiates a shared session key after verifying the commitment legality; the ground base station calculates a group key by using a Hash path, and broadcasts the group key through a TESLA protocol; for member joining or leaving, a hash path is reconstructed and an update message is broadcasted. According to the invention, anonymous authentication and privacy protection under the offline condition of the trusted mechanism are realized; and by utilizing TESLA broadcast authentication and a one-way hash chain mechanism, the communication overhead is effectively reduced, and the forward and backward security in a dynamic unmanned aerial vehicle swarm environment is ensured.
Owner:ANHUI UNIV

Lightweight certificateless authentication method based on double-layer threshold

The invention discloses a lightweight certificateless authentication scheme based on a double-layer threshold, and relates to the technical field of information security. The scheme aims to solve the problems of single-point failure of a key generation center and low key escrow and authentication efficiency in a certificateless system. According to the method, firstly, a decentralized key management mechanism is provided, a non-homogeneous double-variant polynomial is utilized to construct a double-layer threshold architecture of transverse node cooperation and longitudinal key synthesis, safe distribution and reconstruction of a main key and a private key are achieved, and the attack resistance and robustness of the key generation process are improved. On this basis, a lightweight anonymous authentication protocol is designed, a dynamic pseudo identity is generated through a random number to resist identity association attacks, and linear operation is adopted to replace bilinear pairing operation. The method is mainly used in a distributed network environment, reduces the calculation overhead while guaranteeing the privacy and anti-aggressiveness of the user, and improves the overall performance of an authentication system.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

An aircraft anonymous authentication method based on pseudonym aggregation index

The application discloses an aircraft anonymous authentication method based on pseudonym aggregation index, and the method constructs a hierarchical collaborative architecture of a trusted authority center, a regional management agency, a low-altitude base station and an unmanned aircraft, completes system initialization, strong authentication and key negotiation based on an elliptic curve cryptography system, generates an aircraft pseudonym by the regional management agency, and generates a unique index through aggregation operation, and the index is chained together with a certificate, and the trusted authority center stores the mapping relationship between the index and the real identity. The aircraft initiates an anonymous authentication request through additive homomorphic encryption, and the index level fast authentication is completed by a calculation node after verification by the base station; in a malicious scene, the ciphertext pseudonym is aggregated, and the real identity is traced back by controlled decryption of the trusted authority center, and the whole life cycle management of the certificate is realized, forming a 'one-time strong authentication and multiple fast authentication' mode. The method reduces authentication complexity and time delay, improves high-concurrency processing capacity, and realizes privacy protection and security supervision.
Owner:JIANGSU UNIV OF TECH