A three-factor decentralized identity authentication scheme in metaverse
Online published: 2026-01-04
Copyright
The Metaverse, an immersive parallel digital world, faces critical security challenges such as data leakage and impersonation attack. Existing authentication schemes often suffer from single-point failures due to centralization, incomplete decentralization, and low efficiency. To address these challenges, this paper proposes TDID, a three-factor decentralized identity authentication scheme. Our core contribution lies in the novel synergy of a confidential smart contract, executed within a Trusted Execution Environment (TEE), with the offline attack-resistant OPAQUE password-authenticated key exchange protocol. The scheme achieves full decentralization by using the TEE-based contract as a decentralized root of trust. It allows users to establish a globally unique, collision-resistant identity, and ensures that a user's password and biometric key are never revealed to the server during authentication, thus providing robust resistance against offline dictionary attacks even from a compromised server. Rigorous security analysis, including formal verification using ProVerif and a provable security proof, along with performance evaluations, demonstrates that the proposed scheme significantly enhances security while maintaining efficient computational and communication performance.
CHENG Mengfei , CUI Jie , ZHANG Jing , WANG Li , ZHONG Hong . A three-factor decentralized identity authentication scheme in metaverse[J]. Journal of Cybersecurity, 2025 , 3(4) : 81 -93 . DOI: 10.20172/j.issn.2097-3136.250407
表 1 方案的符号表Table 1 Notations of the scheme |
| 符号 | 定义 |
| 用户的用户名、密码和化身身份 | |
| 用户注册与认证合约 | |
| 用户的生物信息 | |
| 从X中生成的生物特征密钥 | |
| 生物特征密钥恢复的辅助数据 | |
| 用户的私钥和公钥对 | |
| 服务器的公钥和私钥对 | |
| URAC的公钥和私钥对 | |
| 用户选择的随机数 | |
| 用于密钥交换的临时随机数 | |
| 会话密钥 | |
| 用户的元数据 | |
| 密码和生物特征密钥的验证值 | |
| 密钥交换协议中的中间值 | |
| 协议加密消息,i=1,2,3,4,··· | |
| 模糊提取器的生成/恢复函数 | |
| 对称加密/解密操作 | |
| 公钥加密/私钥解密操作 | |
| 时间戳,i=1,2,3,4,··· |
表 2 相关操作的执行时间(ms)Table 2 Execution time (ms) of the related operations |
| 操作 | 符号 | 执行时间 |
| 双线性配对运算 | 12.06 | |
| 点对映射哈希运算 | 8.42 | |
| 交易数据读取与解析 | 4.52 | |
| 公钥加密/解密操作 | 1.63 | |
| 点乘运算 | 1.18 | |
| 随机密钥生成操作 | 1.15 | |
| 对称加密/解密操作 | 0.13 | |
| 哈希函数运算 | 0.04 | |
| 生物特征哈希函数运算 | 0.01 |
表 3 用户注册阶段计算开销(ms)Table 3 Computational cost (ms) at user registration phase |
| 方案 | 计算开销 | 总耗时 |
| 方案[12] | 40.67 | |
| 方案[16] | 7.54 | |
| 方案[26] | 10.29 | |
| TDID | 11.45 |
表 4 用户注册登录与服务器认证阶段计算开销(ms)Table 4 Computational cost (ms) at user login and server authentication phase |
| 方案 | 计算开销 | 总耗时 |
| 方案[12] | 134.56 | |
| 方案[16] | 12.42 | |
| 方案[26] | 9.97 | |
| TDID | 18.56 |
表 5 化身相互认证阶段计算开销(ms)Table 5 Computational cost (ms) at avatar mutual authentication phase |
| 方案 | 计算开销 | 总耗时 |
| 方案[12] | 189.81 | |
| 方案[16] | — | — |
| 方案[26] | 15.11 | |
| TDID | 7.71 |
| 1 |
WANG H, NING H, LIN Y, et al. A survey on the metaverse: The state-of-the-art, technologies, applications, and challenges[J]. IEEE Internet of Things Journal, 2023, 10 (16): 14671- 14688.
|
| 2 |
CHENG R, WU N, CHEN S, et al. Will metaverse be Next G internet? Vision, hype, and reality[J]. IEEE Network, 2022, 36 (5): 97- 204.
|
| 3 |
ZYDA M. Let’s rename everything “the Metaverse!”[J]. Computer, 2022, 55 (3): 124- 129.
|
| 4 |
SHEN K, GUO C, KAUFMANN M, et al. X-avatar: Expressive human avatars[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. New York, USA: Association for Computing Machinery (ACM) & Institute of Electrical and Electronics Engineers (IEEE), 2023: 16911-16921.
|
| 5 |
TSAI T Y, ONUMA Y, ZłAHODA-HUZIOR A, et al. Merging virtual and physical experiences: Extended realities in cardiovascular medicine[J]. European Heart Journal, 2023, 44 (35): 3311- 3322.
|
| 6 |
SOLIMAN M M, DARWISH A, HASSANIEN A E. The threat of the digital human in the metaverse: Security and privacy[M]//The future of metaverse in the virtual era and physical world. Cham: Springer International Publishing, 2023: 247-265.
|
| 7 |
WANG Y, SU Z, ZHANG N, et al. A survey on metaverse: Fundamentals, security, and privacy[J]. IEEE Communications Surveys & Tutorials, 2022, 25 (1): 319- 352.
|
| 8 |
YAO Y, CHANG X, LI L, et al. DIDs-assisted secure cross-metaverse authentication scheme for MEC-enabled metaverse[C]//ICC 2023-IEEE International Conference on Communications. IEEE, 2023: 6318-6323.
|
| 9 |
YANG K, ZHANG Z, YOULIANG T, et al. A secure authentication framework to guarantee the traceability of avatars in metaverse[J]. IEEE Transactions on Information Forensics and Security, 2023, 18, 3817- 3832.
|
| 10 |
PATWE S, MANE S. Blockchain enabled architecture for secure authentication in the metaverse environment[C]//2023 IEEE 8th International Conference for Convergence in Technology (I2CT). IEEE, 2023: 1-8.
|
| 11 |
SEO J, KO H, PARK S. Space authentication in the metaverse: A blockchain-based user-centric approach[J]. IEEE Access, 2024, 12, 18703- 18713.
|
| 12 |
ZHANG Z, YANG K, TIAN Y, et al. An anti-disguise authentication system using the first impression of avatar in metaverse[J]. IEEE Transactions on Information Forensics and Security, 2024, 19, 6393- 6408.
|
| 13 |
MATHIS F, FAWAZ H I, KHAMIS M. Knowledge-driven biometric authentication in virtual reality [C]//Extended Abstracts of the 2020 CHI Conference on Human Factors in Computing Systems. New York, USA: ACM, 2020: 1-10.
|
| 14 |
WANG K, KUMAR A. Human identification in metaverse using egocentric iris recognition[EP]. Atypon (part of Wiley), United States: Authorea Preprints, 2022: 1 - 13.
|
| 15 |
RYU J, SON S, LEE J, et al. Design of secure mutual authentication scheme for metaverse environments using blockchain[J]. IEEE Access, 2022, 10, 98944- 98958.
|
| 16 |
LI G, LUAN T H, LI Z, et al. A lightweight and secure three-factor access authentication scheme in metaverse[C]//2023 IEEE International Conference on Metaverse Computing, Networking and Applications (MetaCom). IEEE, 2023: 488-495.
|
| 17 |
LI P, PAN L, CHEN F, et al. TOTPAuth: A time-based one time password authentication proof-of-concept against metaverse user identity theft[C]//2023 IEEE International Conference on Metaverse Computing, Networking and Applications (MetaCom). IEEE, 2023: 662-665.
|
| 18 |
YAO Y, CHANG X, LI L, et al. Metaverse-aka: A lightweight and privacy preserving seamless cross-metaverse authentication and key agreement scheme[C]//2022 IEEE Smartworld, Ubiquitous Intelligence & Computing, Scalable Computing & Communications, Digital Twin, Privacy Computing, Metaverse, Autonomous & Trusted Vehicles (SmartWorld/UIC/ScalCom/DigitalTwin/PriComp/Meta). IEEE, 2022: 2421-2427.
|
| 19 |
BELLOVIN S M, MERRITT M. Encrypted key exchange: Password-based protocols secure against dictionary attacks[C]//Proceedings 1992 IEEE Computer Society Symposium on Research in Security and Privacy. Oakland, CA, USA: IEEE, 1992: 72 - 84.
|
| 20 |
JARECKI S, KRAWCZYK H, XU J. OPAQUE: An asymmetric PAKE protocol secure against pre-computation attacks[C]//Annual International Conference on the Theory and Applications of Cryptographic Techniques. Cham: Springer International Publishing, 2018: 456-486.
|
| 21 |
QI H, XU M, YU D, et al. SoK: Privacy-preserving smart contract[J]. High-Confidence Computing, 2024, 4 (1): 100183.
|
| 22 |
COSTAN V, LEBEDEV I, DEVADAS S. Secure processors part I: background, taxonomy for secure enclaves and Intel SGX architecture[J]. Foundations and Trends® in Electronic Design Automation, 2017, 11 (1-2): 1- 248.
|
| 23 |
NGUYEN H, GANAPATHY V. EnGarde: Mutually-trusted inspection of SGX enclaves[C]//2017 IEEE 37th International Conference On Distributed Computing Systems (ICDCS). IEEE, 2017: 2458-2465.
|
| 24 |
BRANDENBURGER M, CACHIN C, KAPITZA R, et al. Blockchain and trusted computing: Problems, pitfalls, and a solution for hyperledger fabric[J]. arXiv preprint, arXiv:, 1805, 08541, 2018.
|
| 25 |
DODIS Y, REYZIN L, SMITH A. Fuzzy extractors: How to generate strong keys from biometrics and other noisy data[C]//International conference on the theory and applications of cryptographic techniques. Berlin, Heidelberg: Springer, 2004: 523-540.
|
| 26 |
THAKUR G, KUMAR P, CHEN C M, et al. A robust privacy-preserving ECC-based three-factor authentication scheme for metaverse environment[J]. Computer Communications, 2023, 211, 271- 285.
|
| 27 |
GORENFLO C, LEE S, GOLAB L, et al. FastFabric: Scaling hyperledger fabric to 20 000 transactions per second[J]. International Journal of Network Management, 2020, 30 (5): e2099.
|
/
| 〈 |
|
〉 |