Abstract
The fast expansion of information technology and public concern for personal privacy and security have raised expectations for the authentication process. Although existing anonymous authentication schemes can achieve anonymous authentication and accountability, they all require users to apply for certificates from the authorization authority, resulting in a significant certificate storage overhead for the authority. Additionally, they have not implemented certificate revocation for anonymous users, which allows malicious users to potentially engage in malicious behavior. Therefore, this paper proposes an efficient and revocable anonymous account guarantee system based on blockchain (ERAAS). The system implements a guarantor mechanism where anonymous users can authenticate their identities through the guarantees provided by guarantors without the need to apply for certificates, reducing the storage overhead of certificates. Furthermore, the system utilizes cryptographic accumulators to enable fast revocation of accounts, preventing malicious users from engaging in further malicious behavior. Moreover, in this system, the certificate authority (CA) can enhance the system’s ability to handle concurrent requests by allocating group keys to the registration authority (RA), authorizing them to register guarantors and sign guarantees. Security analysis indicates that the proposed scheme enjoys anonymity, traceability, and revocability and can resist forgery attacks. The experimental comparison demonstrates its practicality.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Similar content being viewed by others
References
Arasan, A., Sadaiyandi, R., Al-Turjman, F., Rajasekaran, A.S., Selvi Karuppuswamy, K.: Computationally efficient and secure anonymous authentication scheme for cloud users. Personal Ubiquit. Comput. 1–11 (2021). https://doi.org/10.1007/s00779-021-01566-9
Banerjee, S., Odelu, V., Das, A.K., Chattopadhyay, S., Park, Y.: An efficient, anonymous and robust authentication scheme for smart home environments. Sensors 20(4), 1215 (2020)
Camenisch, J., et al.: Specification of the identity mixer cryptographic library. IBM Research-Zurich, pp. 1–48 (2010)
Cao, Y.N., Wang, Y., Ding, Y., Guo, Z., Wu, Q., Liang, H.: Blockchain-empowered security and privacy protection technologies for smart grid. Comput. Stand. Interfaces 85, 103708 (2022)
Cheng, L., Liu, J., Jin, Y., Li, Y., Wang, W.: Account guarantee scheme: making anonymous accounts supervised in blockchain. ACM Trans. Internet Technol. (TOIT) 21(1), 1–19 (2021)
Gao, T., Deng, X., Guo, N., Wang, X.: An anonymous authentication scheme based on pmipv6 for VANETs. IEEE Access 6, 14686–14698 (2018)
Han, M., Liu, S., Ma, S., Wan, A.: Anonymous-authentication scheme based on fog computing for VANET. PLoS ONE 15(2), e0228319 (2020)
Ho, T.H., Yen, L.H., Tseng, C.C.: Simple-yet-efficient construction and revocation of group signatures. Int. J. Found. Comput. Sci. 26(5), 611–624 (2015)
I’Anson, C., Mitchell, C.: Security defects in CCITT recommendation x. 509: the directory authentication framework. ACM SIGCOMM Comput. Commun. Rev. 20(2), 30–34 (1990)
Jegadeesan, S., Azees, M., Babu, N.R., Subramaniam, U., Almakhles, J.D.: EPAW: efficient privacy preserving anonymous mutual authentication scheme for wireless body area networks (WBANS). IEEE Access 8, 48576–48586 (2020)
Jiang, Y., Ge, S., Shen, X.: AAAS: an anonymous authentication scheme based on group signature in VANETs. IEEE Access 8, 98986–98998 (2020)
Khan, N., Zhang, J., Jan, S.U.: A robust and privacy-preserving anonymous user authentication scheme for public cloud server. Secur. Commun. Netw. 2022 (2022)
Lal, N.A., Prasad, S., Farik, M.: A review of authentication methods. Int. J. Sci. Technol. Res. 5, 246–249 (2016)
Liang, W., Wang, Y., Ding, Y., Zheng, H., Liang, H., Wang, H.: An efficient anonymous authentication and supervision system based on blockchain. In: 2022 7th IEEE International Conference on Data Science in Cyberspace (DSC), pp. 306–313. IEEE (2022)
Liang, W., Wang, Y., Ding, Y., Zheng, H., Liang, H., Wang, H.: An efficient blockchain-based anonymous authentication and supervision system. Peer-to-Peer Networking and Applications, pp. 1–20 (2023)
Liu, H., Sun, Y., Xu, Y., Xu, R., Wei, Z.: A secure lattice-based anonymous authentication scheme for VANETs. J. Chin. Inst. Eng. 42(1), 66–73 (2019)
Mehmood, A., Natgunanathan, I., Xiang, Y., Poston, H., Zhang, Y.: Anonymous authentication scheme for smart cloud based healthcare applications. IEEE access 6, 33552–33567 (2018)
Nguyen, L.: Accumulators from Bilinear Pairings and Applications. In: Menezes, A. (ed.) CT-RSA 2005. LNCS, vol. 3376, pp. 275–292. Springer, Heidelberg (2005). https://doi.org/10.1007/978-3-540-30574-3_19
Rana, R., Zaeem, R.N., Barber, K.S.: An assessment of blockchain identity solutions: Minimizing risk and liability of authentication. In: 2019 IEEE/WIC/ACM International Conference on Web Intelligence (WI), pp. 26–33. IEEE (2019)
Saleem, T., et al.: ProofChain: an x. 509-compatible blockchain-based PKI framework with decentralized trust. Comput. Netw. 213, 109069 (2022)
Wang, F., Xu, G., Gu, L.: A secure and efficient ECC-based anonymous authentication protocol. Secur. Commun. Netw. 2019 (2019)
Wang, X., Yan, Z., Zhang, R., Zhang, P.: Attacks and defenses in user authentication systems: a survey. J. Netw. Comput. Appl. 188, 103080 (2021)
Wang, Z., Fan, J., Cheng, L., An, H.Z., Zheng, H.B., Niu, J.X.: Supervised anonymous authentication scheme. J. Softw. 6, 1705–1720 (2019)
Wen, B., Wang, Y., Ding, Y., Zheng, H., Qin, B., Yang, C.: Security and privacy protection technologies in securing blockchain applications. Inf. Sci. 645, 119322 (2023)
Zhang, L., Li, H., Li, Y., Yu, Y., Au, M.H., Wang, B.: An efficient linkable group signature for payer tracing in anonymous cryptocurrencies. Futur. Gener. Comput. Syst. 101, 29–38 (2019)
Zhang, M., Zhou, J., Zhang, G., Zou, M., Chen, M.: EC-BAAS: elliptic curve-based batch anonymous authentication scheme for internet of vehicles. J. Syst. Architect. 117, 102161 (2021)
Zhang, T., Wang, Y., Ding, Y., Wu, Q., Liang, H., Wang, H.: Multi-party electronic contract signing protocol based on blockchain. IEICE Trans. Inf. Syst. 105(2), 264–271 (2022)
Zimmermann, V., Gerber, N.: The password is dead, long live the password-a laboratory study on user perceptions of authentication schemes. Int. J. Hum Comput. Stud. 133, 26–44 (2020)
Zulfiqar, M., Janjua, M.U., Hassan, M., Ahmad, T., Saleem, T., Stokes, J.W.: Tracking adoption of revocation and cryptographic features in x. 509 certificates. Int. J. Inf. Secur. 21(3), 653–668 (2022)
Acknowledgements
This article is supported in part by the National Key R &D Program of China under project 2020YFB1006003, the Guangxi Natural Science Foundation under grant 2023GXNSFAA026236, the National Natural Science Foundation of China under projects 62162017, 62172119 and 61962012, the Zhejiang Provincial Natural Science Foundation of China under Grant No. LZ23F020012, the Guangdong Key R &D Program under project 2020B0101090002, and the special fund of the High-level Innovation Team and Outstanding Scholar Program for universities of Guangxi.
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2024 ICST Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
About this paper
Cite this paper
Liang, W., Wang, Y., Ding, Y., Liang, H., Yang, C., Wang, H. (2024). Efficient and Revocable Anonymous Account Guarantee System Based on Blockchain. In: Gao, H., Wang, X., Voros, N. (eds) Collaborative Computing: Networking, Applications and Worksharing. CollaborateCom 2023. Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, vol 561. Springer, Cham. https://doi.org/10.1007/978-3-031-54521-4_10
Download citation
DOI: https://doi.org/10.1007/978-3-031-54521-4_10
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-031-54520-7
Online ISBN: 978-3-031-54521-4
eBook Packages: Computer ScienceComputer Science (R0)