信息安全研究 ›› 2025, Vol. 11 ›› Issue (6): 521-.

• 学术论文 • 上一篇    下一篇

基于可撤销代理签名的分布式身份认证技术研究

高宏民1曾卓然2潘晓丰1赖冠辉3马兆丰2   

  1. 1(中移动信息技术有限公司北京100037)
    2(北京邮电大学网络空间安全学院北京100876)
    3(东莞市轨道交通有限公司广东东莞523073)
  • 出版日期:2025-06-22 发布日期:2025-06-22
  • 通讯作者: 高宏民 博士,工程师.主要研究方向为区块链、密码学和网络信息安全. gaohongmin@chinamobile.com
  • 作者简介:高宏民 博士,工程师.主要研究方向为区块链、密码学和网络信息安全. gaohongmin@chinamobile.com 曾卓然 硕士研究生.主要研究方向为基于区块链的隐私保护认证. liuliluren@163.com 潘晓丰 硕士,高级工程师.主要研究方向为区块链、密码学和网络信息安全. panxiaofeng@chinamobile.com 赖冠辉 硕士,信息系统项目管理师.主要研究方向为信息系统管理、网络与信息安全、物联网. Laiguanhui@dggdjt.com 马兆丰 博士,副教授,博士生导师.主要研究方向为区块链理论与技术. mzf@bupt.edu.cn

Research on Distributed Identity Authentication Technology Based on  Revocable Proxy Signature

Gao Hongmin1, Zeng Zhuoran2, Pan Xiaofeng1, Lai Guanhui3, and Ma Zhaofeng2   

  1. 1(China Mobile Information Technology Co., Ltd., Beijing 100037)
    2(School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876)
    3(Dongguan Rail Transit Co., Ltd., Dongguan, Guangdong 523073)
  • Online:2025-06-22 Published:2025-06-22

摘要: 随着数字化服务在人们的日常生活中的普及,传统身份有了另一种表现形式——数字身份.在传统网络数字化活动中,数字身份的管理由各中心化服务提供商管理,存在中心化存储管理难度大,用户隐私保障不足等系列问题,因此基于分布式数字身份(decentralized identifier, DID)的数字身份技术正成为当前的研究热点.但分布式数字身份的身份认证方案隐私泄露问题频出,同时伴随着用户签名认证流程繁琐等问题,是当前分布式身份认证技术的痛点.针对以上存在的系列问题,基于可撤销代理签名、可验证凭证、区块链等技术构建了基于可撤销代理签名的分布式身份认证协议,实现了用户友好安全的签名认证协议.对用户参与数字化活动的设备性能要求低,适用于更广泛的用户数字化活动.

关键词: 代理签名, 分布式数字身份, 可验证凭证, 区块链, 撤销

Abstract: With the proliferation of digital services in people’s daily lives, traditional identities have found a new form of expression—digital identities. In conventional network digital activities, the digital identity management is handled by centralized service providers, which brings a series of issues such as difficulties in centralized storage management and insufficient protection of user privacy. Consequently, the identity authentication technology based on decentralized identifier (DID) has become a current research hotspot. However, distributed digital identity authentication schemes often face problems of privacy leakage and cumbersome user signature authentication processes, presenting significant pain points in current distributed identity authentication technology. To address the aforementioned issues, this paper constructs a distributed identity authentication protocol based on revocable proxy signatures, verifiable credentials, and blockchain technology. This protocol achieves a userfriendly and secure signature authentication process, requiring low device performance from users participating in digital activities, making it suitable for a wider range of user digital activities.

Key words: proxy signature, decentralized digital identity, verifiable credential, blockchain, revocation

中图分类号: