OBIA: A Distributed Multiauthority Service Identity Authentication Scheme for Online Banking
Abstract
Existing online banking identity authentication protocols typically rely on centralized authorization centers or trusted third parties, which can lead to single points of failure, key escrow risks, and privacy leaks. Addressing multi-party collaboration scenarios under a trustless assumption, this paper proposes an Overseen-by-Multiple-Authorities Identity Authentication (OBIA) scheme tailored for electronic banking environments. This solution integrates attribute-based cryptography with distributed key generation (DKG) mechanisms across multiple authorization centers. Users derive complete personal keys from attribute-based private keys embedded with random factors, enabling implicit binding of identity and attributes. To support dynamic attribute changes and permission revocation, a hierarchical time-driven key update mechanism is designed. Combined with non-interactive zero-knowledge proofs (NIZK) and elliptic curve cryptography (ECC), this enables efficient, privacy-preserving authentication. At the data storage layer, an optimized multi-layer Merkle hash tree (MMHT) structure reduces blockchain storage and verification overhead. Security analysis demonstrates that the proposed scheme effectively resists forgery, replay, man-in-the-middle, and key compromise attacks. Experimental results show that compared to existing multi-authorization authentication schemes, this approach exhibits superior or comparable computational and communication overhead while significantly enhancing the system’s decentralization and auditability.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.