A Double-Blind Privacy Protection Method and System in a Compact Electronic Cash Scheme
In the compact electronic cash solution, users and merchants apply for signed e-wallets and anonymous certificates before the transaction, and the identity is verified in a double-blind manner during the transaction process, solving the privacy protection problem of payees and achieving anonymous conversion and efficient use of electronic currency.
Patent Information
- Application Number
- CN202210161661.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-22
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-02-22
AI Technical Summary
In the existing electronic cash scheme, the recipient's privacy protection is insufficient, especially when the recipient uses currency to trade later, the bank cannot anonymously convert it to spendable currency, resulting in the recipient's privacy leak.
The compact electronic cash solution is adopted, and users and merchants apply for signature e-wallets and anonymous certificates from the bank before the transaction. The identity is proved in a double-blind manner during the transaction. After the transaction, the bank verifies the legality and detects double payments to ensure the privacy protection of the recipient.
The privacy protection of the payee is realized. Merchants can convert currency anonymously, and the bank cannot identify the payee's specific identity. The system has high space utilization and security, and has small signature storage space.
Smart Images

Figure CN115170103B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic cash, and in particular, to a double-blind privacy protection method and system in a compact electronic cash scheme. Background Art
[0002] With the rapid development of the global network economy, Internet financial products in China are constantly being integrated with the world. In the field of e-commerce, with the development of online finance, online shopping, and online banking, electronic payment is gradually becoming the mainstream payment channel. Electronic payment has posed a subversive challenge to traditional financial institutions and traditional payment methods with its mobility, portability, and timeliness. Electronic payment can be seen everywhere in life, such as mobile payment, swiping cards for dining on campus, and using mobile NFC to take the bus. Electronic payment has truly changed people's lifestyle. Electronic cash (E-cash) is a means of electronic payment and has strong competitiveness among various payment means with its distinct usage characteristics. Compared with traditional bank cards (credit cards / debit cards), E-cash technology can achieve true anonymous payment and meet the privacy needs of consumers; E-cash does not require the bank to conduct online authentication during payment, improving the convenience of payment; compared with the widely used third-party payment system, a trusted third party is not necessary in E-cash, improving the payment efficiency; the E-cash scheme is constructed based on cryptography technology, and its security is based on cryptography theory and does not rely on the assumption of the security of the operating environment, having good system security.
[0003] The common problems existing in the application of existing electronic cash schemes are as follows: on the one hand, when designing the scheme, the payee is often regarded as a store or institution, and its identity is defaulted to be public, that is, the privacy of the payee is not protected. However, in some cases, the payee may be an individual user, and it is necessary to consider their privacy and anonymity at this time; on the other hand, when designing the scheme, only the situation where the payee clears the received currency is considered, and the situation where the payee subsequently uses the currency for transactions is not considered. If the payee wants to use electronic currency for transactions, they need to apply to the bank for new currency, and the bank will learn about their real account during the interaction process, and the privacy of the payee cannot be guaranteed. Summary of the Invention
[0004] In order to solve the problems existing in the background art, based on the compact electronic cash, the present invention provides a double-blind privacy protection method and system in a compact electronic cash scheme to solve the problem of payee privacy protection in the electronic cash scheme in an efficient and practical manner.
[0005] Double-blind means that during the transaction process, neither the payer nor the payee can determine the identity of the other party, so that the transaction cannot be associated with the true identity of the other party. The improvement of the present invention on the existing electronic cash scheme is mainly reflected in the protection of the privacy of the payee. On the one hand, it ensures that the payee will not disclose their own identity information during the transaction process; on the other hand, when the payee subsequently converts the received electronic currency into their own spendable electronic currency, they do not need to inform the bank of the account information of their real currency. The present invention can completely solve the problem of payee privacy protection in the electronic cash scheme, and effectively solve the problem that merchants cannot anonymously convert the currency sent by users into their own spendable currency.
[0006] The technical solution adopted by the present invention is as follows:
[0007] 1. A double-blind privacy protection method in a compact electronic cash scheme, including:
[0008] Before the transaction, the user applies to the bank for a signature of their electronic wallet, and uses the bank-signed electronic wallet as proof of the payer's validity in subsequent transactions; the merchant applies to the bank for a signature of their anonymous certificate, and uses the bank-signed anonymous certificate as proof of the payee's legitimacy in subsequent transactions;
[0009] During the transaction process, the user and the merchant respectively prove the validity / legitimacy of the electronic wallet and the anonymous certificate to each other in a double-blind form; the merchant sends transaction-related information to the user, and the user sends an electronic currency authentication serial number, a transaction serial number, and a security label generated by a random function to the merchant. The merchant verifies the validity of the electronic currency authentication serial number and the security label. After passing the verification, the merchant receives the electronic currency and the transaction is completed;
[0010] After the transaction, the merchant initiates a currency clearing protocol or a currency conversion protocol to the bank. The bank verifies the legitimacy of the merchant as the payee, the validity of the electronic currency, and whether there is double spending of the electronic currency. The bank first verifies the legitimacy of the merchant as the payee, the validity of the electronic currency, and whether the merchant is the payee of this electronic currency. After passing the verification, the bank combines the spent currency database to detect double spending behavior. If there is double spending behavior, the identity of the user who double-spent is identified and sanctioned; if there is no double spending behavior, the electronic currency is deposited into the spent currency database, and the equivalent real currency of the value of the electronic currency is deposited into the merchant's bank account, or the electronic currency is deposited into the merchant's electronic wallet.
[0011] Further, when the merchant initiates a currency conversion protocol to the bank, the converted electronic currency has no association with the previous transaction.
[0012] Further, before the above-mentioned transaction, the process of the user and the merchant respectively applying to the bank for an electronic wallet and an anonymous certificate includes:
[0013] Step A: The user initiates a withdrawal protocol with the bank. The user generates the secret parameters in the e-wallet and hides the secret parameters of the e-wallet in the knowledge commitment Z in the form of discrete logarithm and sends it to the bank, and at the same time provides the knowledge signature O that can prove that the secret parameters of the e-wallet are correctly generated. a1 After the bank verifies the knowledge signature O, a1 it signs the secret parameters of the user's e-wallet and debits the user's bank account. The user obtains the e-wallet signed by the bank as proof of the payer's validity in subsequent transactions. a1
[0014] Step B: The merchant initiates a signature protocol with the bank. The merchant generates the secret parameters in the anonymous certificate and hides the secret parameters of the anonymous certificate in the knowledge commitment Z in the form of discrete logarithm and sends it to the bank, and at the same time provides the knowledge signature O that can prove that the secret parameters of the anonymous certificate are correctly generated. b1 After the bank verifies the knowledge signature O, b1 it signs the secret parameters of the merchant's anonymous certificate. The merchant obtains the anonymous certificate signed by the bank as proof of the payee's legitimacy in subsequent transactions. b1
[0015] Furthermore, during the transaction process, the merchant needs to prove its legitimacy as the payee to the user in a zero-knowledge manner, and the user needs to prove the validity of the e-wallet for payment to the merchant in a zero-knowledge manner, including:
[0016] Step C1: The merchant generates the knowledge signature O b2 and the knowledge commitment Z b2 based on the secret parameters of the anonymous certificate combined with the bank's signature. During the generation of the knowledge signature O b2 and the knowledge commitment Z b2 , a randomization parameter is added for blinding processing. This knowledge signature O b2 is used to prove the validity of the anonymous certificate. The merchant sends the generated knowledge signature O b2 , the knowledge commitment Z b2 and the relevant transaction information to the user.
[0017] Step C2: The user receives the knowledge signature O b2 and the knowledge commitment Z b2 sent by the merchant for verification. After passing the verification, the user generates the knowledge signature O a2 and the knowledge commitment Z a2 based on the secret parameters of the e-wallet combined with the bank's signature. During the generation of the knowledge signature O a2 and the knowledge commitment Z a2 , a randomization parameter is added for blinding processing. O a2For proving the validity of the e-wallet;
[0018] In the knowledge signature O b2 After successful verification, the user generates a transaction serial number R for this transaction based on the transaction-related information sent by the merchant. Meanwhile, the user uses a pseudo-random function to generate an authentication serial number SN and a security label T for the e-money used in this transaction, and generates a knowledge signature O based on the secret parameters in the e-wallet. a3 , for proving that the authentication serial number SN and the security label T are valid. The knowledge signature O a3 During the generation process, it signs on the knowledge commitment Z sent in step C1 b2 to associate the merchant as the payee with the e-money;
[0019] Step C3, the user sends the knowledge signature O generated in step C2 to the merchant. a2 The knowledge signature O a3 , the knowledge commitment Z a2 as well as the authentication serial number SN, the security label T, and the transaction serial number R of the e-money used in this transaction (the authentication serial number SN and the security label T are the knowledge commitments corresponding to the knowledge signature O a3 );
[0020] Step C4, the merchant verifies the information sent by the user, that is, verifies the validity of the e-wallet, the payee of the e-money, and the validity of the e-money authentication serial number and the security label respectively. After successful verification, the merchant receives the e-money and the transaction between the user and the merchant is completed.
[0021] Furthermore, the currency clearing protocol refers to the merchant requesting the bank to clear the real currency equal to the value of this e-money and deposit the real currency into the merchant's bank account; the currency conversion protocol refers to the bank allowing the merchant to anonymously apply for a new e-wallet and deposit this e-money into this e-wallet.
[0022] Furthermore, during the currency clearing or conversion process, it includes:
[0023] Step D1, the merchant initiates a currency clearing protocol or a currency conversion protocol to the bank, and sends the knowledge signature O b2 and the knowledge commitment Z b2 sent to the user during the transaction to the bank to prove its legal payee identity; meanwhile, the merchant sends the e-money received during the transaction (this e-money includes the authentication serial number SN, the security label T, the transaction serial number R, the knowledge signature O a3 and O a2 as well as the knowledge commitment Z a2 ) to the bank to verify whether this e-money is valid;
[0024] Step D2, the bank verifies the legitimacy of the merchant as the payee based on the knowledge signature O b2 and the knowledge commitment Z b2 If the verification result is true, continue with the subsequent steps; if the verification result is false, interrupt this protocol;
[0025] Step D3, the bank verifies the validity of the user as the payer based on the knowledge signature O a2 and the knowledge commitment Z a2 If the verification result is true, continue with the subsequent steps; if the verification result is false, interrupt this protocol;
[0026] Step D4, the bank verifies whether the authentication serial number SN, the security label T, the transaction serial number R, and the knowledge signature O a3 are correctly generated and whether the merchant is the payee corresponding to the currency (by verifying whether O a3 is signed on Z b2 to verify the payee of the electronic currency), if the verification result is true, continue with the subsequent steps; if the verification result is false, interrupt this protocol;
[0027] Step D5, the bank verifies whether there is double spending of this electronic currency based on the authentication serial number SN, the security label T, and the transaction serial number R;
[0028] If the same authentication serial number SN does not exist in the spent currency database, the transaction is normal, there is no double spending behavior, and continue with the subsequent steps;
[0029] If the same authentication serial number SN exists in the spent currency database and the transaction serial number R is also the same, then this electronic currency has been cleared or converted, and this protocol is interrupted;
[0030] If the same authentication serial number SN exists in the spent currency database and the transaction serial number R is different, it belongs to the user's repeated payment behavior. The bank identifies the user's true identity based on the security label T of this transaction and sanctions it, and this protocol is interrupted;
[0031] Step D6, if all of the above steps D2 - D5 pass the verification, the bank deposits the electronic currency into the spent currency database. For the currency clearing protocol, the merchant sends the bank account to the bank, and the bank deposits the real currency equal to the value of this electronic currency into the merchant's bank account; for the currency conversion protocol, the bank allows the merchant to apply for a new electronic wallet and deposits this electronic currency into this electronic wallet.
[0032] II. A double-blind privacy protection system in a compact electronic cash scheme is used to implement the above double-blind privacy protection method. The double-blind privacy protection system includes a user terminal, a merchant terminal, and a bank terminal;
[0033] Before the transaction, the user applies to the bank terminal for a signature of their electronic wallet through the user terminal, and uses the electronic wallet signed by the bank terminal as proof of the payer's validity in subsequent transactions; the merchant applies to the bank terminal for a signature of its anonymous certificate through the merchant terminal, and uses the anonymous certificate signed by the bank terminal as proof of the payee's legitimacy in subsequent transactions;
[0034] During the transaction process, the user terminal and the merchant terminal prove the validity of the electronic wallet and the legitimacy of the anonymous certificate to each other in a double-blind form; moreover, the merchant terminal sends transaction information to the user terminal, and the user terminal sends a transaction serial number, an electronic currency authentication serial number generated by using a random function, and a security label to the merchant terminal. The merchant terminal verifies the validity of the electronic currency authentication serial number and the security label. After passing the verification, the merchant terminal receives the electronic currency and the transaction is completed;
[0035] After the transaction, the merchant terminal initiates a currency clearing protocol or a currency conversion protocol to the bank terminal. The bank terminal verifies the legitimacy of the merchant terminal as the payee, the validity of the electronic currency, and whether there is double spending of the electronic currency. The bank terminal first verifies the legitimacy of the merchant terminal as the payee, the validity of the electronic currency, and whether the merchant terminal is the payee of this electronic currency. After passing the verification, the bank terminal combines the spent currency database to detect double spending behavior. If there is double spending behavior, it identifies the identity of the user who has double spent and imposes sanctions; if there is no double spending behavior, it deposits the electronic currency into the spent currency database, deposits real currency equal to the value of the electronic currency into the bank account of the merchant terminal, or deposits the electronic currency into the electronic wallet of the merchant terminal.
[0036] Furthermore, each merchant terminal is regarded as a user terminal when spending the converted electronic currency.
[0037] The beneficial effects of the present invention are as follows:
[0038] (1) By improving the electronic cash scheme, the present invention meets the privacy protection requirements of the payee during the transaction process, thus realizing that the merchant can maintain anonymity during the subsequent process of converting the received currency into the currency that can be spent by itself. Considering the privacy protection requirements of the merchant as the payee, a double-blind protection effect is achieved on the compact electronic cash scheme.
[0039] (2) Different from other types of electronic cash schemes, the most significant feature of the compact electronic cash scheme is its high space utilization rate. While other types of electronic cash can store only one electronic currency in a certain space, this scheme can store multiple ones.
[0040] (3) The CL signature scheme based on bilinear pairing is adopted in the present invention. Compared with other electronic signature schemes based on RSA groups, it has the characteristic of small signature storage space. The security level that its 160-bit parameter can achieve is equivalent to that of the RSA group signature scheme with 1024 bits. Brief Description of the Drawings
[0041] Figure 1 It is a schematic diagram of the system of the embodiment of the present invention.
[0042] Figure 2 It is a schematic diagram of the user application for the electronic wallet protocol of the embodiment of the present invention.
[0043] Figure 3 It is a schematic diagram of the merchant application for the anonymous certificate protocol of the embodiment of the present invention.
[0044] Figure 4 It is a schematic diagram of the user and merchant transaction protocol of the embodiment of the present invention.
[0045] Figure 5 It is a schematic diagram of the merchant-initiated settlement protocol of the embodiment of the present invention.
[0046] Figure 6 It is a schematic diagram of the merchant-initiated conversion protocol of the embodiment of the present invention.
[0047] Figure 7 It is a schematic diagram of the system double-spending behavior detection work of the embodiment of the present invention. Detailed Embodiment
[0048] The double-blind compact electronic cash scheme of the present invention will be further described below in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0049] As Figure 1 shown, the double-blind compact electronic cash scheme of the present invention includes users, merchants, and banks. The so-called double-blind means that users and merchants always interact anonymously during the transaction process. Both parties can only confirm the validity of the other party as a payer or the legality of the other party as a payee, but cannot confirm the specific identity information of the other party. Therefore, the anonymity protection of the payee and payer is achieved, and each transaction between the two parties does not have an identifiable linkability.
[0050] In this scheme, the privacy of honest users and merchants is absolutely protected. That is to say, after an honest user applies for an electronic wallet at a bank, he can anonymously prove the validity of the payee to the merchant and complete the transaction. No one (including the bank) can identify the user's identity, nor can it be determined whether any two transactions are from the same user. At the same time, once a user makes a double payment, by comparing the electronic currency sent by the merchant with the information of the spent currency recorded in the database, the bank can identify the double payment behavior and the true identity of the double payer, and impose sanctions on the double payer. After the merchant obtains the anonymous certificate signed by the bank during the signing process, he can anonymously prove the legitimacy of the payee to the user and complete the transaction. When the merchant completes the transaction and receives the electronic currency, he can choose to clear the electronic currency and deposit it into his own bank account, or anonymously convert it into electronic currency that he can spend later. It should be noted that in the process of clearing with the bank, the bank needs to deposit the currency into the merchant's real currency account. At this time, the bank will know the merchant's account information and thus the merchant's identity. Apart from this, no one (including the bank) can identify the merchant's identity, nor can they determine whether the recipient of any two transactions is the same merchant.
[0051] When a merchant spends the converted electronic currency, he or she can be regarded as a user. Figure 1 As shown, the user has a transaction with merchant 1, and pays merchant 1 with an electronic currency in his electronic wallet. Merchant 1 converts this electronic currency into electronic currency that can be spent by himself later, and pays in the transaction with merchant 2. Merchant 2-Merchant n-1 performs the above-mentioned operation of converting and paying the received currency until merchant n clears the electronic currency received in the transaction and deposits it into real currency of equal value into a bank account. When the electronic currency sent to the bank for conversion or clearing by merchant i (1<=i<=n) is detected to have double payment behavior, the double payer tracked by the bank is merchant i-1 (if i is 1, it is the user that is tracked), which has nothing to do with the honest merchant and user before.
[0052] In order to achieve double-blind privacy protection, users need to send the knowledge signature and knowledge commitment of the user's secret parameters to the bank before the transaction to prove that they are a valid payer and obtain the bank's signature on the secret parameters. The electronic wallet composed of the secret parameters and the bank's signature is the proof of the validity of the user's payer in subsequent transactions.
[0053] Before a transaction, the merchant needs to send a knowledge signature and knowledge commitment of the secret parameters to the bank to prove his or her legal identity and obtain the bank's signature on the secret parameters. The anonymous certificate consisting of the merchant's secret parameters and the bank's signature is the proof of the legitimacy of the merchant's payee in subsequent transactions.
[0054] In a specific implementation of the present invention, during the withdrawal process, the user applies to the bank for a signature on their secret parameter, obtains an electronic wallet signed by the bank, and thus becomes a valid payer. When the user applies to the bank for a signature, real-name information will be used (the authenticity of the real-name information can be verified by means of the account previously opened by the user at the bank) to ensure that double payers can be found and sanctioned. To ensure that honest users are not framed by the bank (for example, due to incorrect bank operations, etc., resulting in incorrect judgment of the user's behavior), when the user calculates and generates the knowledge signature O in the following step 405 a3 , the private key knowledge corresponding to the user's bank account will be used to complete the signature.
[0055] The user electronic wallet involved in the present invention refers to a certificate registered by the user in a real-name manner, selecting wallet parameters in a secret manner, and proving the user's knowledge of these parameters in a zero-knowledge manner, and then signed by the bank. The secret parameters in the electronic wallet are only known to the user and are not known to the bank and merchants, thus realizing the anonymous protection of the user.
[0056] Before the merchant conducts electronic collection, it needs to apply to the bank for a signature of the bank on its private key, obtain an anonymous certificate signed by the bank, and thus become a legal collector. When the merchant applies to the bank for a signature, real-name information will be used to ensure that when the merchant spends the converted electronic currency subsequently, double spending behavior will be detected and sanctioned.
[0057] The merchant anonymous certificate involved in the present invention refers to a certificate registered by the merchant in a real-name manner, selecting certificate parameters in a secret manner, and proving the merchant's knowledge of these parameters in a zero-knowledge manner, and then signed by the bank. The secret parameters in the merchant anonymous certificate are only known to the merchant, thus realizing the anonymous protection of the merchant.
[0058] During the transaction process, the user electronic wallet will be proved by the user in a zero-knowledge manner of its ownership (proving that the user has the knowledge of the secret parameters corresponding to the electronic wallet, but the merchant cannot obtain any information about the secret parameters during the verification process), and the merchant anonymous certificate will be proved by the merchant in a zero-knowledge manner of its ownership. Therefore, during the transaction process, the merchant and the user can verify the legitimacy of each other as a payer or a collector, but cannot determine the specific identity of the other party.
[0059] The zero-knowledge proof methods used in the present invention are knowledge signature and knowledge commitment. The knowledge commitment contains the secret parameters to be proved, but it is not feasible to infer relevant information about the secret parameters when knowing the knowledge commitment; the knowledge signature refers to the signature of the knowledge of the secret parameters on a certain message, and the verifier can judge whether the prover has the knowledge of the secret parameters contained in the knowledge commitment through verification.
[0060] Taking the proof of the knowledge of the user's private key as an example, the methods and principles of knowledge commitment and knowledge signature are described as follows:
[0061] Given a cyclic group G of unknown order = <g>, the bit length of the group element is l G . H: {0, 1} * →{0, 1} k is a collision-resistant hash function that can map binary strings of any length to k-bit binary strings.
[0062] Each user and merchant will have a public key and a private key. The public key is public and corresponds to a bank account. The private key is only known to the user or merchant themselves. The private key is u, and the public key is PKU = g u (The power operation here is the power operation in group G. Given u, it is easy to calculate PKU; conversely, given PKU, it is difficult to calculate u). Due to the special nature of the private key, no information about the private key can be revealed to the bank during the proof process to prevent the leakage of the private key.
[0063] The above public key PKU is the knowledge commitment corresponding to the private key u (containing the secret parameter to be proved, but no information about the secret parameter can be obtained).
[0064] The user knows the private key knowledge u, generates a random number r, calculates c = H(PKU||g||g r ||m), s = r - cu, and can obtain (c, s), denoted as SPK(u: PKU = g u ), which is the knowledge signature of the private key on the message m. After receiving the knowledge signature (c, s) and the knowledge commitment PKU sent by the user, the bank calculates c' = H(PKU||g||PKU c g s ||m), and judges whether c and c' are equal. If it holds, it means the user has the private key knowledge corresponding to PKU; if it does not hold, it means the user does not have the corresponding private key knowledge.
[0065] The above is a way of knowledge signature in this application. The prover can prove to the verifier that they know the secret parameter without disclosing the secret parameter to the verifier.
[0066] In this embodiment, the method used by the user to prove that they have a valid electronic wallet and the merchant to prove that they have a valid anonymous certificate is the proof method in the CL signature algorithm based on bilinear pairing, which is an extension of the above zero-knowledge proof method.
[0067] In step C2, when the user generates the knowledge signature O a3 during the process, the knowledge commitment Z b2 of the merchant will be signed, indicating that the recipient of this currency is this merchant. When the bank generates c' using the hash function, the knowledge commitment Z b2 Input the hash function together. If the merchant is not the payee corresponding to this electronic currency, the knowledge signature O a3 will not pass the verification.
[0068] In a specific implementation of the present invention, during a transaction, the merchant sends the knowledge signature O b2 and knowledge commitment Z b2 of the secret parameter in the anonymous certificate to the user to prove its legitimacy as the payee. After the knowledge signature of the merchant passes the verification, the user generates the transaction serial number R of this transaction and the knowledge signature O a2 and knowledge commitment Z a2 to prove the validity of the payer. (When generating the knowledge signature and knowledge commitment, the user and the merchant will add a randomization parameter to blind the electronic wallet or anonymous certificate, making each generated knowledge signature and knowledge commitment different, so that others cannot associate a certain transaction with a specific user or merchant or associate two different transactions.)
[0069] The user inputs the secret parameter of the electronic wallet into the pseudo-random function, calculates the authentication serial number SN and security label T of the electronic currency used in this transaction, and generates the knowledge signature O that SN and T are correctly generated a3 , O a3 will sign on the knowledge commitment Z b2 , and the user sends the authentication serial number SN, security label and knowledge signature O a3 .
[0070] During the process of converting the received electronic currency into the electronic currency that the merchant can spend, the merchant sends the knowledge signature O b2 , knowledge commitment Z b2 and the received electronic currency of the transaction (the electronic currency is essentially a series of data, consisting of the authentication serial number SN, security label T, transaction serial number R and knowledge signature of the transaction) to prove that it is the payee of the currency and anonymously convert it into the electronic currency that it can spend.
[0071] The processing process of the anonymous application electronic wallet of the present invention is as Figure 2 shown:
[0072] Step 201, the user generates the secret parameter of the electronic wallet and generates its knowledge commitment Z a1 ;
[0073] Step 202, the user generates the knowledge signature O a1 by combining the knowledge of the secret parameter in the electronic wallet with the knowledge of the user's private key to prove the possession of the knowledge of the secret parameter of the electronic wallet and the user's private key;
[0074] Step 203: The user sends the public key PKU, the knowledge commitment Z a1 , the knowledge signature O a1 and the user's real-name information to the bank;
[0075] Step 204: The bank verifies the user's real-name information;
[0076] (To ensure that honest users are not framed, in this implementation, the user's real-name information is the information in the user's bank account. In this case, the way for the bank to verify the user's real-name information is: verify whether the user's bank account exists and whether the user uses the private key corresponding to the bank account to generate the knowledge signature O a1 .)
[0077] If the verification result is true, continue with the subsequent steps;
[0078] If the verification result is false, interrupt the current application protocol;
[0079] Step 205: The bank verifies the validity of the knowledge signature O a1 .
[0080] If the verification result is true, continue with the subsequent steps;
[0081] If the verification result is false, interrupt the current protocol;
[0082] Step 206: The bank uses its own private key to calculate the signature S u for the secret parameter in the user's e-wallet. In this embodiment, the bank uses the CL signature algorithm based on bilinear pairing;
[0083] Step 207: The bank records the user's real-money account;
[0084] Step 208: The bank sends the signature S u to the user.
[0085] Step 209: The user verifies the signature S u of the bank for the secret parameter of the e-wallet. In this embodiment, the user uses the CL signature verification algorithm based on bilinear pairing.
[0086] If the verification is invalid, the user's current application for the e-wallet fails; Since the CL signature algorithm based on bilinear pairing is a mature signature algorithm with high accuracy, the probability of the invalid verification situation can be ignored. During the specific implementation process, due to communication problems or other reasons, when the verification fails, the user can request the bank to send the signature again;
[0087] If the verification is valid, the user obtains the bank's signature on the secret parameter, generates a valid electronic wallet, and becomes a valid payer.
[0088] After completing the application for an electronic wallet as Figure 2 shown, during a transaction, the user can inform the merchant that they are a valid payer by proving to the merchant that they have a valid electronic wallet.
[0089] The process of the merchant applying for an anonymous certificate in the present invention is as Figure 3 shown:
[0090] Step 301, the merchant generates the secret parameter in the anonymous certificate and generates the knowledge commitment Z b1 ;
[0091] Step 302, the merchant generates the knowledge signature O b1 , based on the knowledge of the secret parameter in the anonymous certificate and combined with the knowledge of the merchant's private key, to prove the possession of the knowledge of the secret parameter of the anonymous certificate and the merchant's private key;
[0092] Step 303, the merchant sends the merchant's public key PKM, the knowledge commitment Z b1 , the knowledge signature O b1 and the merchant's real-name information to the bank;
[0093] Step 304, the bank verifies the merchant's real-name information;
[0094] If the verification result is true, continue with the subsequent steps;
[0095] If the verification result is false, interrupt this protocol;
[0096] Step 305, the bank verifies the validity of the knowledge signature O b1 .
[0097] If the verification result is true, continue with the subsequent steps;
[0098] If the verification result is false, interrupt this protocol;
[0099] Step 306, the bank uses its own private key to calculate the signature S m on the secret parameter of the merchant's anonymous certificate. In this embodiment, the bank uses the CL signature algorithm based on bilinear pairing;
[0100] Step 307, the bank sends the signature S m to the merchant.
[0101] Step 308, the merchant verifies the signature S m of the bank on the secret parameter of its anonymous certificate. In this embodiment, the merchant uses the CL signature verification algorithm based on bilinear pairing.
[0102] If the verification is invalid, the merchant's application for an anonymous certificate fails this time.
[0103] If the verification is valid, the user obtains an anonymous certificate issued by the bank and has the legality as a payee.
[0104] After completing the application for an anonymous certificate as Figure 3 shown, during the transaction process, the merchant can inform that it is a valid payee by proving to the user that it has a valid anonymous certificate.
[0105] As Figure 4 shown, the process of the user and the merchant conducting a transaction is as follows. To achieve the transaction between the user and the merchant under the double-blind condition, the user and the merchant need to complete 4 interaction processes during this process:
[0106] · The merchant zero-knowledge proves to the user that it owns a legal (signed by the bank) anonymous certificate and sends transaction-related information to the user;
[0107] · The user receives and verifies the knowledge signature, knowledge commitment, and transaction-related information sent by the merchant. After the knowledge signature verification passes, the user zero-knowledge proves to the merchant that it owns a valid e-wallet and generates the transaction serial number for this transaction at the same time.
[0108] · The user uses a pseudo-random function to generate the authentication serial number SN and the security label T of the currency used in this transaction and provides the knowledge signature that SN and T are correctly generated.
[0109] · The merchant verifies the knowledge signature, authentication serial number, security label, and transaction serial number sent by the user. After the knowledge signature verification passes, the merchant receives the electronic currency.
[0110] The specific process is as follows:
[0111] Step 401, the merchant uses the secret parameter of the merchant anonymous certificate to generate its knowledge signature O b2 and knowledge commitment Z b2 , and adds a randomization parameter for blinding processing during the generation process (making each transaction of the merchant unlinkable);
[0112] Step 402, the merchant sends the generated knowledge commitment Z b2 , knowledge signature O b2 and related transaction information to the user;
[0113] Step 403, the user verifies the knowledge signature O b2 sent by the merchant to judge the validity of the merchant anonymous certificate and generates the transaction serial number R for this transaction at the same time;
[0114] If the verification result is true, continue with the subsequent steps;
[0115] If the verification result is false, interrupt the current transaction agreement;
[0116] Step 404, the user generates a knowledge commitment Z a2 and a knowledge signature O a2 , and adds a randomization parameter during the generation process for blinding (making each transaction of the user non-linkable);
[0117] Step 405, the user generates an authentication serial number SN and a security label T for the electronic currency used in this transaction according to the secret parameters in the electronic wallet; then, generates a knowledge signature O a3 , this knowledge signature is used to prove that SN and T are correctly generated, and the knowledge commitment Z sent by the merchant in step 402 will be added during the generation process of this knowledge signature b2 , with the payee corresponding to the merchant;
[0118] Step 406, the user sends the generated knowledge signature O a2 and O a3 , the authentication serial number SN, the security label T, and the transaction serial number R to the merchant;
[0119] Step 407, the merchant verifies the knowledge signature O sent by the user a2 , to determine the validity of the user's electronic wallet, that is, whether this electronic wallet is bank-signed;
[0120] If the verification result is true, continue with the subsequent steps;
[0121] If the verification result is false, interrupt the current transaction agreement;
[0122] Step 408, the merchant verifies the knowledge signature O a3 , to determine whether the authentication serial number SN and the security label T are correctly generated, and whether it is the payee of this currency;
[0123] If the verification result is true, continue with the subsequent steps;
[0124] If the verification result is false, interrupt the current transaction agreement;
[0125] Step 409, the merchant receives the electronic currency;
[0126] Step 410, the merchant informs the user that the transaction is successful;
[0127] Step 411: After the user confirms that the merchant has received the currency, the user updates the status of their e-wallet (using a compact e-cash scheme. Multiple e-currencies can be stored in one e-wallet. For example, the applied e-wallet contains 1024 e-currencies, and each e-currency has a corresponding number. When the user completes a transaction, one of the currencies is spent, and the user needs to mark this numbered currency as unusable. If it is used again, the bank will determine that there is a double-spending behavior).
[0128] During the transaction process, the transaction serial number R, authentication serial number SN, and security label T generated by the user are generated according to the following formulas. H is a collision-resistant hash function, and info is the transaction information sent by the merchant. Due to the characteristics of the hash function, it can be ensured that the transaction serial numbers corresponding to different transactions are all different. The operations in the process of calculating SN and T are all operations on a group, where J is the number of the currency contained in the e-wallet, and u, s, t are the secret parameters in the e-wallet, and u is the user's private key.
[0129] R = H(Z b2 ||info)
[0130]
[0131]
[0132] After completing the transaction as Figure 4 shown, the merchant receives the e-currency sent by the user. The merchant can clear the e-currency to the bank and deposit it into their own bank account, or anonymously convert it into a new spendable e-currency for themselves.
[0133] As Figure 5 shown, the processing process for the merchant to initiate clearing to the bank is as follows:
[0134] Step 501: The merchant sends the knowledge commitment Z b2 and knowledge signature O b2 generated in Step 401, as well as the received e-currency of the transaction, to the bank;
[0135] Step 502: The bank receives the knowledge signature O b2 sent by the merchant and verifies whether the merchant is legitimate as the payee;
[0136] If the verification result is true, continue with the subsequent steps;
[0137] If the verification result is false, interrupt this clearing protocol;
[0138] Step 503: The bank, based on the knowledge commitment Z a2 and knowledge signature O a2 , verify whether the user is valid as a payer;
[0139] If the verification result is true, continue with the subsequent steps;
[0140] If the verification result is false, interrupt the current clearing agreement;
[0141] Step 504, the bank verifies whether the authentication serial number SN, the security label T, the transaction serial number R, and the knowledge signature O a3 are correctly generated and whether the merchant is the corresponding payee;
[0142] If the verification result is true, continue with the subsequent steps;
[0143] If the verification result is false, interrupt the current clearing agreement;
[0144] Step 505, the bank detects whether there is double spending of the electronic currency sent by the merchant;
[0145] If there is double spending behavior, interrupt the current agreement and use the double spender detection algorithm to identify the identity of the double spender and sanction the user;
[0146] If there is no double spending behavior, continue with the subsequent steps.
[0147] Step 506, the bank deposits the electronic currency into the database of spent currency, indicating that this currency has been spent, and deposits real currency equal to the value of the electronic currency into the merchant's bank account.
[0148] In this embodiment, once the authentication serial number SN received by the bank is the same as the historical authentication serial number SN (the authentication serial number of the spent currency), the bank will perform double spender judgment:
[0149] If the authentication serial numbers SN are the same and the corresponding transaction serial numbers R are also the same (in the present invention, the transaction serial number R is generated from transaction-related information, and if R is the same, it corresponds to the same transaction), it means that the electronic currency sent by the merchant this time has been cleared, and the merchant has sent the electronic currency of the same transaction repeatedly.
[0150] If the authentication serial numbers SN are the same and the corresponding transaction serial numbers R are different, confirm that it is the authentication information generated by double spending behavior. The bank calculates the public key used by the double spender based on the security labels T of the two transactions, thereby identifying the true identity of the double spender and sanctioning it. At the same time as the bank calculates the identity of the double spender, it is necessary to provide proof of its guilt for other users and merchants to verify (it is necessary to publish two electronic currencies with the same serial number SN, and other users and merchants can verify whether there is double spending behavior).
[0151] As Figure 6 shown, the processing procedure for a merchant to initiate a conversion to the bank is as follows:
[0152] Step 601, the merchant sends the knowledge commitment Z b2 and the knowledge signature O b2 generated in step 401, as well as the electronic currency received in the transaction, to the bank;
[0153] Step 602, the bank receives the knowledge signature O b2 sent by the merchant and verifies whether it is legal as the payee;
[0154] If the verification result is true, continue with the subsequent steps;
[0155] If the verification result is false, interrupt this conversion protocol;
[0156] Step 603, the bank verifies whether the user is valid as the payer based on the knowledge commitment Z a2 and the knowledge signature O a2 ;
[0157] If the verification result is true, continue with the subsequent steps;
[0158] If the verification result is false, interrupt this conversion protocol;
[0159] Step 604, the bank verifies whether the authentication serial number SN, the security label T, the transaction serial number R, and the knowledge signature O a3 are correctly generated and whether the merchant is the corresponding payee;
[0160] If the verification result is true, continue with the subsequent steps;
[0161] If the verification result is false, interrupt this conversion protocol;
[0162] Step 605, the bank detects whether there is double spending of the electronic currency sent by the merchant;
[0163] If there is double spending behavior, interrupt this protocol and use the double spender detection algorithm to identify the identity of the double spender and impose sanctions on the user;
[0164] If there is no double spending behavior, continue with the subsequent steps;
[0165] Step 606, the bank deposits this electronic currency into the database of spent currency, indicating that this currency has been spent, and at the same time allows the merchant to apply for an electronic wallet;
[0166] Step 607, the bank sends a verification passed message to the merchant, allowing the merchant to apply for a new e-wallet;
[0167] Step 608, the merchant selects the secret parameters of the merchant e-wallet and generates its knowledge commitment Z m1 ;
[0168] Step 609, the merchant uses the knowledge of the secret parameters in the merchant e-wallet and combines it with the knowledge of the merchant's private key to calculate the knowledge signature O m1 , to prove that the knowledge commitment Z m1 is correctly generated;;
[0169] Step 610, the merchant sends the knowledge commitment Z m1 and the knowledge signature O m1 to the bank;
[0170] Step 611, the bank verifies the validity of the knowledge signature O m1 ;
[0171] If the verification result is true, continue with the subsequent steps;
[0172] If the verification result is false, interrupt this conversion protocol;
[0173] Step 612, the bank uses its own private key to calculate the signature S m’ for the secret parameters in the merchant e-wallet. In this embodiment, the bank uses the CL signature algorithm based on bilinear pairing;
[0174] Step 613, the bank sends the signature S m’ to the merchant.
[0175] Step 614, the merchant verifies the signature S m’ of the bank for its e-wallet secret parameters. In this embodiment, the merchant uses the CL signature verification algorithm based on bilinear pairing.
[0176] If the verification is invalid, the merchant's e-money conversion fails this time;
[0177] If the verification is valid, the merchant obtains the e-wallet issued by the system and has the validity as a payer.
[0178] Figure 5 As shown, during the interaction between the merchant and the bank, the merchant proves that it is the recipient of the currency by sending the knowledge signature O b2 sent to the user during the transaction to the bank again. At the same time, the merchant sends its bank account to the bank, and at this time the bank will determine the specific identity of the merchant; Figure 6 During the interaction between the merchant and the bank, the merchant anonymously converts the electronic currency into electronic currency that can be spent later by itself instead of depositing it into its own bank account. Therefore, the merchant does not need to send account information to the bank, and the bank cannot determine the specific identity of the merchant.
[0179] As Figure 7 shown, the steps for the system to detect double-spending behavior are as follows:
[0180] Step 701, a transaction is conducted between the merchant and the user, and steps 401 - 411 are executed;
[0181] Step 702, the merchant executes step 601, and sends the knowledge commitment Z b2 and knowledge signature O b2 generated in step 401, as well as the electronic currency received in the transaction, to the bank;
[0182] Step 703, the bank executes steps 602 - 604. If double-spending behavior is detected, steps 704 - 706 are continued;
[0183] Step 704, the bank obtains the public key of the double spender according to the double-spender tracking algorithm;
[0184] Step 705, the bank discloses the identity of the double spender and provides proof of its double-spending (the electronic currency of the two transactions, including the authentication serial number SN, security label T, and transaction serial number R. The user and the merchant can verify whether the double spender has double-spending behavior based on the publicly available information);
[0185] Step 706, the bank sanctions the double spender.
[0186] In a specific implementation of the present invention, the double-spender detection process is as follows: For double-spending behavior, if a user wants to double-spend a certain electronic currency it owns, the same currency authentication serial number SN is used in the two transactions. In this case, the bank compares the spent currency with the currency sent by the merchant. Once it is found that the authentication serial number SN is the same, the transaction serial numbers R corresponding to the two electronic currencies are judged. The transaction serial number R is generated based on the transaction-related information sent by the merchant. If the transaction serial numbers R are the same, it proves that the two transactions are the same, and the merchant has sent the electronic currency of the same transaction to the bank twice, and there is no double-spending behavior; if the two transaction serial numbers R are different, it proves that the electronic currency corresponds to two different transactions, and double-spending behavior has occurred. The bank account information of the double-spending user can be identified according to the designed double-spender identification algorithm, and sanctions can be imposed on it.
[0187] When a double - spending behavior is detected, the public - key information of the double - spender can be calculated according to the following formula. In the formula, (T1, R1) is the security label and transaction serial number of the electronic currency that has been stored in the bank's spent - currency database, while (T2, R2) corresponds to the security label and transaction serial number of the electronic currency that the merchant currently requests for clearing or conversion. α is a fraction that can be cancelled out during the calculation process.
[0188]
[0189] In a specific implementation of the present invention, a complete transaction process is as follows:
[0190] Step A, the user initiates a withdrawal protocol to the bank. The user generates the secret parameters in the electronic wallet and hides the secret parameters of the electronic wallet in the knowledge commitment Z a1 in a discrete - logarithm manner and sends it to the bank. At the same time, the user provides a knowledge signature O a1 that can prove that the secret parameters of the electronic wallet are correctly generated. The bank verifies the knowledge signature O a1 and then signs the secret parameters of the user's electronic wallet and debits the user's bank account. The user obtains the bank - signed electronic wallet as proof of the payer's validity in subsequent transactions;
[0191] Step B, the merchant initiates a signature protocol to the bank. The merchant generates the secret parameters in the anonymous certificate and hides the secret parameters of the anonymous certificate in the knowledge commitment Z b1 in a discrete - logarithm manner and sends it to the bank. At the same time, the merchant provides a knowledge signature O b1 that can prove that the secret parameters of the anonymous certificate are correctly generated. The bank verifies the knowledge signature O b1 and then signs the secret parameters of the merchant's anonymous certificate. The merchant obtains the bank - signed anonymous certificate as proof of the payee's legality in subsequent transactions;
[0192] Step C1, the merchant generates a knowledge signature O b2 and a knowledge commitment Z b2 based on the secret parameters of the anonymous certificate combined with the bank's signature. During the generation of the knowledge signature O b2 and the knowledge commitment Z b2 , a randomization parameter is added for blinding processing. This knowledge signature O b2 is used to prove the validity of the anonymous certificate. The merchant sends the generated knowledge signature O b2 , the knowledge commitment Z b2 and the relevant transaction information to the user;
[0193] Step C2, the user receives the knowledge signature O b2 and the knowledge commitment Z b2 After verification, the user generates a knowledge signature O by combining the secret parameters of the e-wallet with the bank's signature a2 and a knowledge commitment Z a2 , and during the generation of the knowledge signature O a2 and the knowledge commitment Z a2 , a randomization parameter is added for blinding processing. O a2 is used to prove the validity of the e-wallet;
[0194] After the knowledge signature O b2 is verified, the user generates a transaction serial number R for this transaction based on the transaction-related information sent by the merchant. At the same time, the user uses a pseudo-random function to generate an authentication serial number SN and a security label T for the electronic currency used in this transaction, and generates a knowledge signature O a3 based on the secret parameters in the e-wallet, which is used to prove that the authentication serial number SN and the security label T are valid. The knowledge signature O a3 will include the knowledge commitment Z sent by the merchant in step C1 during the generation process b2 , so that the merchant, as the payee, can be associated with the electronic currency;
[0195] Step C3, the user sends the knowledge signature O a2 , the knowledge signature O a3 , the knowledge commitment Z a2 , as well as the authentication serial number SN, the security label T, and the transaction serial number R of the electronic currency used in this transaction (the authentication serial number SN and the security label T are the knowledge commitments corresponding to the knowledge signature O a3 ) to the merchant;
[0196] Step C4, the merchant verifies the information sent by the user, that is, verifies the validity of the e-wallet, the payee of the electronic currency, and the validity of the authentication serial number and the security label of the electronic currency. After the verification passes, the merchant receives the electronic currency, and the transaction between the user and the merchant is completed;
[0197] Step D1, the merchant initiates a currency clearing protocol or a currency conversion protocol to the bank, and sends the knowledge signature O b2 and the knowledge commitment Z b2 sent to the user during the transaction process to the bank to prove its legal payee identity; at the same time, the merchant sends the electronic currency received during the transaction (this electronic currency includes the authentication serial number SN, the security label T, the transaction serial number R, the knowledge signature O a3 and O a2 as well as the knowledge commitment Z a2 ) to the bank to verify whether the electronic currency is valid;
[0198] Step D2, the bank verifies according to the knowledge signature O b2 and knowledge commitment Z b2 Verify the legitimacy of the merchant as the payee. If the verification result is true, continue with the subsequent steps; if the verification result is false, interrupt this agreement.
[0199] Step D3. The bank verifies the validity of the user as the payer based on the knowledge signature O a2 and knowledge commitment Z a2 Verify the validity of the user as the payer. If the verification result is true, continue with the subsequent steps; if the verification result is false, interrupt this agreement.
[0200] Step D4. The bank verifies whether the authentication serial number SN, security label T, transaction serial number R, and knowledge signature O a3 are correctly generated and whether the merchant is the payee corresponding to the currency. If the verification result is true, continue with the subsequent steps; if the verification result is false, interrupt this agreement.
[0201] Step D5. The bank verifies whether there is double spending of this electronic currency based on the authentication serial number SN, security label T, and transaction serial number R.
[0202] If the same authentication serial number SN does not exist in the spent currency database, the transaction is normal, there is no double spending behavior, and continue with the subsequent steps.
[0203] If the same authentication serial number SN exists in the spent currency database and the transaction serial number R is also the same, then this electronic currency has been cleared or converted, and this agreement is interrupted.
[0204] If the same authentication serial number SN exists in the spent currency database and the transaction serial number R is different, it belongs to the user's repeated payment behavior. The bank identifies the user's true identity based on the security label T of this transaction and sanctions it, and this agreement is interrupted.
[0205] Step D6. If the above steps D2 - D5 all pass the verification, the bank deposits the electronic currency into the spent currency database. For the currency clearing agreement, the merchant sends the bank account to the bank, and the bank deposits the real currency equal to the value of this electronic currency into the merchant's bank account; for the currency conversion agreement, the bank allows the merchant to apply for a new electronic wallet and deposits this electronic currency into this electronic wallet.
[0206] Corresponding to the embodiment of the double - blind privacy protection method in a compact electronic cash scheme described above, the present invention also provides a double - blind privacy protection system in a compact electronic cash scheme, including a user terminal, a merchant terminal, and a bank terminal.
[0207] The bank terminal is responsible for issuing user e-wallets and merchant anonymous certificates. By collecting information on electronic currency sent by merchants, it conducts knowledge signature verification and double-spending behavior detection. If a double-spending behavior is detected, the true identity of the double spender is revealed, sanctions are imposed on them, and it is made public.
[0208] The merchant terminal is responsible for conducting transactions with the user terminal, receiving the electronic currency sent by the user terminal and providing corresponding goods or services. After receiving the electronic currency sent by the user terminal, the merchant terminal sends it to the above-mentioned bank for knowledge signature verification and double-spending behavior detection. After passing the verification, the merchant terminal can choose to anonymously convert the electronic currency into subsequent spendable electronic currency or convert it into real currency and deposit it into the bank account.
[0209] The user terminal is the initiator of transactions in the electronic cash scheme. The user first registers with the bank under their real name and obtains a user e-wallet signed by the bank. After that, when the user terminal initiates a transaction with the merchant terminal, it zero-knowledge proves to the merchant that it owns a certain legal and valid user e-wallet. The above-mentioned user terminal and merchant terminal can communicate with the bank terminal, and the terminal can be an electronic device capable of executing a communication protocol.
[0210] For the system embodiment, since it basically corresponds to the method embodiment, the relevant parts can be referred to the description of the method embodiment. The present invention describes specific embodiments to simplify the present invention. However, it should be recognized that the present invention is not limited to the described embodiments, and various modifications of the present invention are possible without departing from the basic principles, and these equivalent forms also fall within the scope defined by the appended claims of this application.< / g>
Claims
1. A double-blind privacy protection method in a compact electronic cash scheme, characterized in that, Including: Before the transaction, the user applies to the bank for a signature of their e-wallet, and uses the bank-signed e-wallet as proof of the payer's validity in subsequent transactions; The merchant applies to the bank for a signature of their anonymous certificate, and uses the bank-signed anonymous certificate as proof of the payee's legitimacy in subsequent transactions; During the transaction process, the user and the merchant prove the validity / legitimacy of the e-wallet and the anonymous certificate to each other in a blind form; The merchant sends transaction-related information to the user. The user sends the e-money authentication serial number, transaction serial number, and security label generated using a random function to the merchant. The merchant verifies the validity of the e-money authentication serial number and the security label. After passing the verification, the merchant receives the e-money and the transaction is completed; After the transaction, the merchant initiates a currency clearing agreement or a currency conversion agreement with the bank. The bank verifies the legitimacy of the merchant as the payee, the validity of the e-money, and whether there is double spending of the e-money: The bank first verifies the legitimacy of the merchant as the payee, the validity of the e-money, and whether the merchant is the payee of this e-money. After passing the verification, the bank combines the spent currency database to detect double spending behavior; If there is double spending behavior, the identity of the user who double-spent is identified and sanctions are imposed; If there is no double spending behavior, the e-money is deposited into the spent currency database, and the equivalent real currency of the e-money value is deposited into the merchant's bank account, or the e-money is deposited into the merchant's e-wallet; During the transaction process, the merchant needs to prove their legitimacy as the payee to the user in a zero-knowledge manner, and the user needs to prove the validity of their payment e-wallet to the merchant in a zero-knowledge manner, including: Step C1: The merchant generates a knowledge signature O by combining the secret parameters of the anonymous certificate with the bank's signature b2 and a knowledge commitment Z b2 . During the generation of the knowledge signature O b2 and the knowledge commitment Z b2 , a randomization parameter is added for blinding processing. This knowledge signature O b2 is used to prove the validity of the anonymous certificate. The merchant sends the generated knowledge signature O b2 , the knowledge commitment Z b2 and the relevant transaction information to the user Step C2, the user receives the knowledge signature O b2 and the knowledge commitment Z b2 for verification. After successful verification, the user generates the knowledge signature O a2 and the knowledge commitment Z a2 by combining the secret parameters of the e-wallet with the bank's signature. During the generation of the knowledge signature O a2 and the knowledge commitment Z a2 , a randomization parameter is added for blinding. O a2 is used to prove the validity of the e-wallet; In the knowledge signature O b2 After verification, the user will generate a transaction serial number R for this transaction according to the transaction-related information sent by the merchant. At the same time, the user uses a pseudo-random function to generate an authentication serial number SN and a security label T for the electronic currency used in this transaction, and generates a knowledge signature O according to the secret parameters in the electronic wallet a3 , used to prove that the authentication serial number SN and the security label T are valid. The knowledge signature O a3 will be signed on the knowledge commitment Z sent in step C1 during the generation process b2 to associate the merchant as the payee with the electronic currency; Step C3, the user sends the knowledge signature O generated in step C2 to the merchant a2 , the knowledge signature O a3 , the knowledge commitment Z a2 and the authentication serial number SN, security label T and transaction serial number R of the electronic currency used in this transaction; In step C4, the merchant verifies the information sent by the user, that is, verifies the validity of the e-wallet, the payee of the e-money, and the validity of the e-money authentication serial number and the security label respectively. After passing the verification, the merchant receives the e-money and the transaction between the user and the merchant is completed.
2. The double-blind privacy protection method in a compact electronic cash scheme according to claim 1, characterized in that When the merchant initiates a currency conversion agreement with the bank, the converted e-money has no association with the previous transaction.
3. The double-blind privacy protection method in a compact electronic cash scheme according to claim 1, characterized in that Before the described transaction, the process of the user and the merchant applying to the bank for the e-wallet and the anonymous certificate respectively includes: Step A: The user initiates a withdrawal agreement with the bank; the user generates the secret parameters in the e-wallet and hides the secret parameters of the e-wallet in the knowledge commitment Z in the form of discrete logarithm and sends it to the bank, and at the same time provides the knowledge signature O that can prove that the secret parameters of the e-wallet are correctly generated a1 ; the bank verifies the knowledge signature O a1 ; after that, the bank signs the secret parameters of the user's e-wallet and records the user's bank account, and the user obtains the e-wallet signed by the bank as proof of the validity of the payer in subsequent transactions; a1 Step B, the merchant initiates a signature agreement with the bank; the merchant generates the secret parameters in the anonymous certificate and hides the secret parameters of the anonymous certificate in the knowledge commitment Z in the form of discrete logarithm and sends it to the bank. At the same time, the merchant provides a knowledge signature O that can prove that the secret parameters of the anonymous certificate are correctly generated. b1 After the bank verifies the knowledge signature O b1 , the bank signs the secret parameters of the merchant's anonymous certificate, and the merchant obtains the bank-signed anonymous certificate as proof of the legitimacy of the payee in subsequent transactions. b1 4. The double-blind privacy protection method in a compact electronic cash scheme according to claim 1, characterized in that The described currency clearing agreement means that the merchant requests the bank to clear the real currency equivalent to the value of the e-money and deposit the real currency into the merchant's bank account; The described currency conversion agreement means that the merchant requests the bank to deposit the e-money into the merchant's e-wallet.
5. The double-blind privacy protection method in a compact electronic cash scheme according to claim 4, characterized in that During the currency clearing or conversion process, it includes: Step D1, the merchant initiates a currency clearing agreement or a currency conversion agreement with the bank and sends the knowledge signature O b2 and the knowledge commitment Z b2 to the bank to prove its legal recipient identity; at the same time, the merchant sends the electronic currency received during the transaction to the bank to verify whether the electronic currency is valid; the said electronic currency includes an authentication serial number SN, a security label T, a transaction serial number R, the knowledge signature O a3 and O a2 as well as the knowledge commitment Z a2 ; Step D2, the bank verifies the legitimacy of the merchant as the payee based on the knowledge signature O b2 and the knowledge commitment Z b2 If the verification result is true, proceed with the subsequent steps; if the verification result is false, interrupt this protocol Step D3: The bank verifies the validity of the user as a payer based on the knowledge signature O a2 and the knowledge commitment Z a2 If the verification result is true, continue with the subsequent steps; if the verification result is false, interrupt the current protocol Step D4, the bank verifies the authentication serial number SN, the security label T, the transaction serial number R, and the knowledge signature O a3 to verify whether the authentication serial number SN and the security label T are correctly generated and whether the merchant is the recipient corresponding to the currency. If the verification result is true, continue with the subsequent steps; if the verification result is false, interrupt this protocol; In step D5, the bank verifies whether there is double spending of the e-money according to the authentication serial number SN, the security label T, and the transaction serial number R; If there is no same authentication serial number SN in the spent currency database, the transaction is normal, there is no double spending behavior, and the subsequent steps are continued; If there is the same authentication serial number SN in the spent currency database and the transaction serial number R is also the same, then the e-money has been cleared or converted, and this agreement is interrupted; If there is the same authentication serial number SN in the spent currency database and the transaction serial number R is different, it belongs to the user's repeated payment behavior. The bank identifies the user's real identity based on the security label T of this transaction and sanctions it, and this agreement is interrupted; Step D6, if all of the above steps D2 - D5 are verified, the bank deposits the electronic currency into the spent currency database. For the currency clearing agreement, the merchant sends the bank account to the bank, and the bank deposits the real currency equal to the value of the electronic currency into the merchant's bank account; for the currency conversion agreement, the bank allows the merchant to apply for a new electronic wallet and deposits the electronic currency into this electronic wallet.
6. A double-blind privacy protection system in a compact electronic cash scheme, characterized in that, For implementing the double - blind privacy protection method described in claim 1, the double - blind privacy protection system includes a user terminal, a merchant terminal, and a bank terminal; Before the transaction, the user applies to the bank terminal for a signature of its electronic wallet through the user terminal, and uses the electronic wallet signed by the bank terminal as proof of the payer's validity in subsequent transactions; the merchant applies to the bank terminal for a signature of its anonymous certificate through the merchant terminal, and uses the anonymous certificate signed by the bank terminal as proof of the payee's legality in subsequent transactions; During the transaction, the user terminal and the merchant terminal prove the validity of the electronic wallet and the legality of the anonymous certificate to each other in a double - blind form; and, the merchant terminal sends transaction information to the user terminal, the user terminal sends the transaction serial number, the electronic currency authentication serial number generated by using a random function, and the security label to the merchant terminal. The merchant terminal verifies the validity of the electronic currency authentication serial number and the security label. After verification, it receives the electronic currency and the transaction is completed; After the transaction, the merchant terminal initiates a currency clearing agreement or a currency conversion agreement to the bank terminal. The bank terminal verifies the legality of the merchant terminal as the payee, the validity of the electronic currency, and whether there is double - spending of this electronic currency; the bank terminal first verifies the legality of the merchant terminal as the payee, the validity of the electronic currency, and whether the merchant terminal is the payee of this electronic currency. After verification, the bank terminal combines the spent currency database to detect double - spending behavior; if there is double - spending behavior, it identifies the identity of the user with double - spending and sanctions it; if there is no double - spending behavior, it deposits the electronic currency into the spent currency database, deposits the real currency equal to the value of the electronic currency into the merchant terminal's bank account, or deposits the electronic currency into the merchant terminal's electronic wallet.
7. The double-blind privacy protection system in a compact electronic cash scheme according to claim 6, characterized in that, Each merchant terminal is regarded as a user terminal when spending the converted electronic currency.
Citation Information
Patent Citations
Safe operation method for offline payment of electronic money
CN104850984A