计算机与现代化 ›› 2025, Vol. 0 ›› Issue (10): 110-117.doi: 10.3969/j.issn.1006-2475.2025.10.017

• 信息安全 • 上一篇    下一篇

基于区块链双线性映射的IBS用户身份认证仲裁

  


  1. (1.杭州季潮网络科技有限公司,浙江 杭州 310000; 2.浙江师范大学计算机学院,浙江 金华 321004;
    3.常山季潮网络科技有限公司,浙江 衢州 324000)
  • 出版日期:2025-10-27 发布日期:2025-10-28
  • 作者简介: 作者简介:余飞飞(1984—),男,浙江杭州人,高级工程师,博士,研究方向:用户身份认证,加密技术,网络安全,E-mail:jl_cl2024@126.com; 邵爱平(1989—),女,浙江杭州人,工程师,硕士,研究方向:网络安全,E-mail: shaoaip336@126.com。
  • 基金资助:
     基金项目:国家自然科学基金资助项目(62072411)
       

BBMA-IBS:Blockchain Bilinear Mapping Arbitration IBS User Identity Authentication


  1. (1. Hangzhou Jichao Network Technology Co., Ltd., Hangzhou 310000, China;
    2. School of Computer Science, Zhejiang Normal University, Jinhua 321004, China;
    3. Changshan Jichao Network Technology Co., Ltd., Quzhou 324000, China)
  • Online:2025-10-27 Published:2025-10-28

摘要:
摘要:为降低用户身份认证方案的主体存量系统接入成本,并提高系统用户身份认证安全性和认证效能,本文提出一种基于区块链双线性映射仲裁身份基签名(Identity-Based Signature, IBS)的用户身份认证方案。首先,该方案利用联盟链建立用户身份认证架构,包含区块链、注册服务器、用户和存量系统,采用模糊提取器将生物特征用于身份认证,并结合链上异构用户数字身份,构建用户身份统一认证兼容模型;其次,引入双线性映射提出一种基于标识的身份基签名算法,融入仲裁模块扩展原有算法安全功能,使其具备撤销功能,增强系统安全性;最后,结合区块链用户身份认证架构,对系统用户身份注册、跨域身份认证及域内身份认证3个模块进行流程设计。实验结果显示,本文算法在吞吐量、时延和资源开销等指标上均优于选取的对比算法,这表明所提算法可更加有效地提高系统用户身份认证安全性和效能。


关键词: 关键字:区块链, 用户身份认证, 双线性映射, 仲裁, 身份基签名, 模糊提取器

Abstract:
Abstract: In order to reduce the main system access cost of user identity authentication schemes and improve the security and efficiency of system user identity authentication, a user identity authentication scheme based on blockchain bilinear mapping arbitration identity-based signature (IBS) is proposed. Firstly, a user identity authentication architecture is established using the consortium chain, which includes blockchain, registration server, users, and existing systems. Fuzzy extractors are used to use biometric features for identity authentication, and a user identity unified authentication compatibility model is constructed by combining heterogeneous user digital identities on the chain. Secondly, bilinear mapping is introduced to propose an identity based signature algorithm based on identification, which incorporates an arbitration module to extend the security function of the original algorithm and makes it here a revocation function to enhance system security. Finally, based on the blockchain user identity authentication architecture, process design is carried out for the three modules of system user identity registration, cross domain identity authentication, and intra domain identity authentication. The experimental results show that the algorithm proposed in this paper outperforms the selected comparative algorithms in terms of throughput, latency, and resource overhead, indicating that the proposed algorithm can more effectively improve the security and efficiency of system user identity authentication.

Key words: Key words: blockchain, user identity authentication, bilinear mapping, arbitration, identity based signature, fuzzy extractor

中图分类号: