A group signature authentication method and system
By creating a public information list and identity traceability list in the group, and using elliptic curve group and secure hash function for group signature authentication, the problem of insufficient anonymity and traceability in traditional group signature schemes is solved, and the security and reliability of digital signatures are improved.
Patent Information
- Application Number
- CN202411048882.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-01
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2044-08-01
AI Technical Summary
Traditional group signature solutions cannot provide anonymity and traceability, and there is a risk of signature member information leakage and side channel attacks, threatening the security and reliability of digital signatures.
Build a group containing group administrators and members, create a public information list NList and identity traceability list TRlist, and use the addition subgroup GA and multiplication subgroup GT of the elliptic curve group E (FP), and use the secure hash functions H1 and H2 for group signature authentication to ensure the anonymity and traceability of signature members.
It realizes the anonymity of signature members and the traceability of group administrators, avoids information leakage and side channel attacks, and improves the security and reliability of digital signatures.
Smart Images

Figure CN118784246B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a group signature authentication method and system. Background Art
[0002] Signature is a fundamental term in cryptography, providing message integrity, authentication, and non-repudiation. Integrity means that a message cannot be tampered with during transmission; authentication means the recipient can trust that the signature originated with the signer; and non-repudiation means the signer cannot later deny their signature. With the development of cryptography, the concept of group signatures has been proposed. Compared to ordinary digital signatures, group signatures allow members of a group to anonymously sign on behalf of the entire group. This technology is primarily used to protect the privacy of signers while maintaining traceability.
[0003] Traditional group signature schemes typically consist of two components: a signature method and a verification method. The signature method takes as input a message m and a private key k, and outputs a member's digital signature on m. The verification method takes as input m and its corresponding digital signature, and outputs a true or false statement indicating the validity of the signature.
[0004] The defects of the above-mentioned existing technologies are: traditional group signature schemes cannot provide security properties such as anonymity and traceability, and there is a risk of signature member information leakage and side-channel attacks, which seriously threaten the security and reliability of digital signatures. Summary of the Invention
[0005] Based on this, it is necessary to provide a group signature authentication method and system to address the above technical issues.
[0006] An embodiment of the present invention provides a group signature authentication method, including:
[0007] Constructing a group including a group administrator and multiple members; wherein the group administrator has an independent identity identifier, and the members have identities that are kept confidential from each other;
[0008] The group administrator's group signature result G for message m S To authenticate, perform the following operations:
[0009] Based on the independent identity of the group administrator and the identity of each member in the group, create a public information list NList for storing the signature results of the group administrator and multiple members, and an identity tracing list TRlist containing the specific identity information of the group administrator and multiple members;
[0010] Get the group signature result G of the digital signature of message m within the groupS ;
[0011] The group signature result G S Traverse the public information list NList and verify the group signature result G S The validity of the signature and the identity of the signing member are obtained;
[0012] The valid group signature result G S The identity identifier of the corresponding signing member is traversed in the identity tracing list TRlist to obtain the specific identity information of the signing member to complete the authentication of the group signature.
[0013] In addition, the group is equipped with system public parameters for group signature authentication, which specifically include: large prime number p, finite field F P 、Elliptic curve group E(F P ), Group E(F P ) of order q additive subgroup G A 、Group E(F P )'s multiplicative subgroup G T , symmetric bilinear map e:G A ×G A →G T , G A The first elliptic curve generator g and the second elliptic curve generator h are mapped to the subgroup G A The secure hash function H1 and the mapping to The secure hash function H2.
[0014] In addition, the creation of a public information list NList for storing the signature results of the group administrator and multiple members and an identity tracing list TRlist containing the specific identity information of the group administrator and multiple members specifically includes:
[0015] Each member of the group M i Send the identity to the group administrator, who calculates each member's M based on the identity. i The identity secret value and the identity secret value Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements
[0016]
[0017] Where n is the product of large prime numbers p1 and p2, is the identity secret value, Secret identity value Corresponding to the elliptic curve group E(F P )'s additive subgroup GA element, h is the second elliptic curve generator, i is the number of members, id i Identification of members;
[0018] The identity secret value Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements As a public information list NList for storing the signature results of the group administrator and multiple members, the identity secret value Identity secret value Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements and member M i The composed set serves as an identity tracing list TRlist containing specific identity information of the group administrator and multiple members.
[0019] In addition, the group signature result G of the digital signature of the acquired message m within the group S , which specifically include:
[0020] Choose two random numbers d,l←Z p , where l is the secret value of the updated private key and d is the random number selected when signing;
[0021] Update the signing private key Calculate the secure hash function H m =H1(m) and the first part of the signature S1:
[0022]
[0023] Calculate the second-stage signature private key
[0024]
[0025] Among them, SK id,1 is the second part of the signature key group, l is the secret value of the updated private key, g is the first elliptic curve generator, H m is a secure hash function;
[0026] With identity secret value sk id As secret information, a partial anonymous identity authentication protocol is performed to obtain the group signature result G S ,for:
[0027]
[0028] Among them, σ1 and σ2 are the parts of the group signature related to the message, and σ3 is the part of the group signature used to verify the identity of the signing member. Secret identity value Corresponding to the elliptic curve group E(F P )'s additive subgroup G A elements, C is the commitment value generated based on the partial identity anonymous authentication protocol, r, z are random numbers selected during the execution phase of the partial identity anonymous authentication protocol, and k is the value mapped to The function value calculated by the secure hash function H2.
[0029] In addition, the identity secret value Partial anonymous identity authentication protocol as secret information, specifically including:
[0030] Select two random numbers r and r * ,calculate:
[0031]
[0032] Among them, h is the second elliptic curve generator, R is the random number r * Mapping elliptic curve group E(F P ), k is the result of mapping to The function value calculated by the secure hash function H2, m is the message, C is the signature member identity secret value sk id The commitment value, r, z are random numbers selected during the execution phase of the partial identity anonymous authentication protocol, is the identity secret value, Secret identity value Corresponding to the elliptic curve group E(F P )'s additive subgroup G A elements.
[0033] In addition, the verification group signature result G S The effectiveness of
[0034] For a signature (σ1, σ2, σ3), the verifier decrypts the part σ3 in the group signature used to verify the identity of the signature member and obtains the identity secret value Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements
[0035] Traverse the public information list NList to find out whether there is a secret value that matches the identity Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements The same value; if there is no identical value in the list, the signature is invalid;
[0036] If the secret value exists in the list Corresponding to the elliptic curve group E(F P )'s additive subgroup G A If the elements of R have the same value, then set R * =zh-kB, the calculation is mapped to the subgroup G A The function value k calculated by the secure hash function H1 * :
[0037] k * =H1(m|R * )
[0038] Among them, r and z are random numbers selected in the execution phase of the partial identity anonymous authentication protocol, m is the message, and R is the number of r * Mapping elliptic curve group E(F P ), h is the second elliptic curve generator;
[0039] Comparison is made by mapping to The function value k calculated by the secure hash function H2 is the same as the function value k mapped to the subgroup G A The function value k calculated by the secure hash function H1 * Is it consistent? When mapped to The function value k calculated by the secure hash function H2 is the same as the function value k mapped to the subgroup G A The function value k calculated by the secure hash function H1 * If they are inconsistent, the signature is invalid;
[0040] When mapped to The function value k calculated by the secure hash function H2 is the same as the function value k mapped to the subgroup G A The function value k calculated by the secure hash function H1 * When consistent, calculate the posterior commitment value C * :
[0041]
[0042] Verify the signature member's identity secret value sk id Is the commitment value C equal to the posterior commitment value C * , if the signature member has a secret identity value sk id The commitment value C is equal to the posterior commitment value C * , then the signature is valid; if the signature member has a secret identity value sk id The commitment value is not equal to the posterior commitment value C * , the signature is invalid;
[0043] Verify the signature information and calculate the bilinear pairing
[0044]
[0045] Among them, X T is the representation of the bilinear pairing e(g,X), σ1 and σ2 are the message-related parts of the group signature, g is the first elliptic curve generator, H m is a secure hash function, K is a public parameter;
[0046] Bilinear pairing The representation X of the bilinear pairing e(g,X) in the group public key set T For comparison, if the bilinear pairing The representation X of the bilinear pairing e(g,X) T If the bilinear pairing is equal, the signature is valid; The representation X of the bilinear pairing e(g,X) T If they are not equal, the signature is invalid.
[0047] In addition, a group signature authentication system includes:
[0048] A group module is used to build a group including a group administrator and multiple members; wherein the group administrator has an independent identity identifier, and the members have identities that are kept confidential from each other;
[0049] A list creation module is used to create a public information list NList for storing the signature results of the group administrator and multiple members, and an identity tracing list TRlist containing the specific identity information of the group administrator and multiple members based on the independent identity identifier of the group administrator and the identity identifier of each member in the group;
[0050] The signature acquisition module is used to obtain the group signature result G of the digital signature of the message m within the group S ;
[0051] Verification module, used to group signature result G S Traverse the public information list NList and verify the group signature result G S The validity of the signature and the identity of the signing member are obtained;
[0052] Signature authentication module, used to validate the group signature result G S The identity identifier of the corresponding signing member is traversed in the identity tracing list TRlist to obtain the specific identity information of the signing member to complete the authentication of the group signature.
[0053] The group signature authentication method and system provided by the embodiments of the present invention have the following advantages compared to the prior art:
[0054] Existing digital signature schemes cannot provide security properties such as anonymity and traceability, and there is a risk of information leakage and side-channel attacks, which seriously threaten the security and reliability of digital signatures.
[0055] The present invention uses the group signature result G S Traverse the public information list NList and verify the group signature result G S The validity of the group signature result G S The identity of the corresponding signing member is traversed in the identity tracing list TRlist to obtain the specific identity information of the signing member to complete the authentication of the group signature. It can provide anonymity for the signing member and traceability for the group administrator, avoiding the risk of signing member information leakage and side channel attacks, thereby improving the security and reliability of the digital signature. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 A schematic diagram of an anonymous authentication protocol for a group signature authentication method provided in one embodiment;
[0057] Figure 2 The figure is a flowchart of a group signature authentication method provided in one embodiment. DETAILED DESCRIPTION
[0058] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0059] In one embodiment, a group signature authentication method is provided, such as Figure 1 As shown, the method includes:
[0060] Step 1: Construct a group including a group administrator and multiple members; wherein the group administrator has an independent identity; the members M i Have a mutually confidential identity ID i , i is the number of members in the group. This allows members to prove their membership to other members without revealing their identity, and also allows group administrators to quickly identify the true identity of members.
[0061] Step 2: The group has system public parameters for group signature authentication, including: large prime number p, finite field F p 、Elliptic curve group E(F p), Group E(F p ) of order q additive subgroup G A 、Group E(F p )'s multiplicative subgroup G T , a symmetric bilinear map e:G A ×G A →G T , G A The first elliptic curve generator g and the second elliptic curve generator h, a mapping to the subgroup G A A secure hash function H1 and a mapping to The secure hash function H2.
[0062] Step 3: The group administrator's group signature result G for message m S To authenticate, perform the following operations:
[0063] 3.1 According to the independent identity of the group administrator and each member M i Identity ID i , create a public information list NList for storing the signature results of the group administrator and multiple members and an identity tracing list TRlist containing the specific identity information of the group administrator and multiple members.
[0064] The specific process includes: each member M in the group i Send the identity to the group administrator, who calculates each member's M based on the identity. i The identity secret value and the identity secret value Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements
[0065]
[0066] Where n is the product of large prime numbers p1 and p2, h is the second elliptic curve generator, and i is the number of members.
[0067] The identity secret value Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements As a public information list NList for storing the signature results of the group administrator and multiple members, the identity secret value Identity secret value Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements and member M iThe composed set serves as an identity tracing list TRlist containing specific identity information of the group administrator and multiple members.
[0068] 3.2 Obtain the group signature result G of the digital signature of message m within the group S .
[0069] 3.3 Group signature result G S Traverse the public information list NList and verify the group signature result G S The validity of the signature member and the identity id of the signature member i .
[0070] 3.4 The valid group signature result G S The identity ID of the corresponding signing member i Traverse the identity tracing list TRlist to obtain the specific identity information of the signing member to complete the authentication of the digital signature.
[0071] In one embodiment, a group signature authentication system is provided, the system comprising:
[0072] A group module is used to build a group including a group administrator and multiple members; wherein the group administrator has an independent identity identifier, and the members have identities that are kept confidential from each other;
[0073] A list creation module is used to create a public information list NList for storing the signature results of the group administrator and multiple members, and an identity tracing list TRlist containing the specific identity information of the group administrator and multiple members based on the independent identity identifier of the group administrator and the identity identifier of each member in the group;
[0074] The signature acquisition module is used to obtain the group signature result G of the digital signature of the message m within the group S ;
[0075] Verification module, used to group signature result G S Traverse the public information list NList and verify the group signature result G S The validity of the signature and the identity of the signing member are obtained;
[0076] Signature authentication module, used to validate the group signature result G S The identity identifier of the corresponding signing member is traversed in the identity tracing list TRlist to obtain the specific identity information of the signing member to complete the authentication of the group signature.
[0077] Example 1
[0078] like Figure 2 As shown in the figure, the specific steps of the digital signature authentication method are:
[0079] 1. Construct a group including a group administrator and multiple members; wherein the group administrator has an independent identity; the members M i Have a mutually confidential identity ID i , i is the number of members in the group.
[0080] 2. The group has system public parameters for group signature authentication, including: large prime number p, finite field F P 、Elliptic curve group E(F P ), Group E(F P ) of order q additive subgroup G A 、Group E(F P )'s multiplicative subgroup G T , a symmetric bilinear map e:G A ×G A →G T , G A The first elliptic curve generator g and the second elliptic curve generator h, a mapping to the subgroup G A A secure hash function H1 and a mapping to The secure hash function H2.
[0081] 3. Generate group private key and group public key. Group administrator can choose Calculate X = xg as the group private key, let G T The unit element is denoted as g T =e(g,g), X T As a representation of bilinear pairing e(g,X). The group administrator arbitrarily selects two large prime numbers p1 and p2 and calculates their product n=p1p2 and e(ng,g)=K. Group public key PK=(p,G A , G T ,e,g,K,X T ), group private key SK = (n, x).
[0082] 4. Members join. Group administrators create and maintain TRlist identity traceability lists and NList public information lists. Member M i Apply to join the group and send your real identity to the group administrator. First, the group administrator will identify the member i , calculate the congruence A secret identity value This information is only known to members and administrators. in The identity secret value Mapping to the elliptic curve group E(F P ) results, Open to everyone, but and The corresponding relationship is kept confidential, that is, any member’s It can only verify whether it belongs to the group, but cannot verify its specific legal membership. Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements As a public information list NList for storing the signature results of the group administrator and multiple members, the identity secret value Identity secret value Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements and member M i The composed set serves as the identity tracing list TRlist containing the specific identity information of the group administrator and multiple members:
[0083]
[0084] Where x is the group private key, n is the product of large prime numbers p1 and p2, g is the elliptic curve generator, and H1 is mapped to the subgroup G A The secure hash function H1.
[0085] And the signature key group (SK id,0 ,SK id,1 ) and the secret value sk id Sent to member M i .here Corresponding to the secret identity value id of the group member in the partial identity anonymous authentication protocol i .
[0086] 5. Get the group signature result G of the member's digital signature on the message m S The specific process is as follows:
[0087] Phase 1: Select two random numbers d, l←Z p , where l is the secret value of the updated private key and d is the random number selected when signing. Calculate the secure hash function H m =H1(m) Calculate the first part of the signature:
[0088] Phase 2: The signing member performs the following operations using the output value from Phase 1:
[0089] (1) Calculate the second-stage signature private key
[0090] Among them SK id,1 is the second part of the signature key group, l is the secret value of the updated private key, g is the first elliptic curve generator, H m A secure hash function.
[0091] (2) The signature member uses the identity secret value As secret information, a partial anonymous identity authentication protocol is performed. The specific operation is as follows: select two random numbers r and r * ,calculate:
[0092] R=r*h,(1)
[0093] Where h is a generator of the elliptic curve group, and R is the sum of r * Mapping elliptic curve group E(F P ) results.
[0094] k=H2(m|R),
[0095] Where k is the function value calculated by the secure hash function, which binds the message m to R.
[0096]
[0097] The purpose of this step is to select the random number r * and the identity secret value sk id Binding
[0098]
[0099] Among them B id It is sk id The result of mapping to the elliptic curve group.
[0100]
[0101] Among them, C is the secret value sk of the signature member pair id Commitment value.
[0102] (3) The final group signature is
[0103]
[0104] Among them, σ1 and σ2 are the parts of the group signature related to the message, and σ3 is the part of the group signature used to verify the identity of the signing member. Secret identity value Corresponding to the elliptic curve group E(F P )'s additive subgroup G Aelements, C is the commitment value generated based on the partial identity anonymous authentication protocol, r, z are random numbers selected during the execution phase of the partial identity anonymous authentication protocol, and k is the value mapped to The function value calculated by the secure hash function H2.
[0105] 6. The group signature result G S Traverse the public information list NList and verify the group signature result G S The validity of the signature member and the identity id of the signature member i The specific process is as follows:
[0106] First, verify the identity of the signature member, that is, ensure that the signature is a legal group signature. The specific operation is as follows: for a signature (σ1, σ2, σ3), decrypt the part σ3 in the group signature used to verify the identity of the signature member, and obtain the identity secret value Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements
[0107] Traverse the public information list NList to find out whether there is a secret value that matches the identity Corresponding to the elliptic curve group E(F P )'s additive subgroup G A Elements If the same value does not exist in the list, the signature is invalid; if it does exist, continue with the following calculation: Set The computation is performed by mapping to the subgroup G A The function value k calculated by the secure hash function H1 * =H1(m|R * ).
[0108] Comparison is made by mapping to The function value k calculated by the secure hash function H2 is the same as the function value k mapped to the subgroup G A The function value k calculated by the secure hash function H1 * Is it consistent? When mapped to The function value k calculated by the secure hash function H2 is the same as the function value k mapped to the subgroup G A The function value k calculated by the secure hash function H1 * If they are inconsistent, the signature is invalid. If they are consistent, the posterior commitment value is further calculated.
[0109] Verify the signature member's identity secret value sk id Is the commitment value C equal to the posterior commitment value C * , if the signature member has a secret identity value sk idThe commitment value C is equal to the posterior commitment value C * , then the signature is valid and the signing member is a valid member (but the specific identity cannot be identified); if the signing member has a secret identity value sk id The commitment value is not equal to the posterior commitment value C * , the signature is invalid.
[0110] Secondly, the signature information is verified. The process is as follows: The verifier calculates the bilinear pairing Bilinear pairing The representation X of the bilinear pairing e(g,X) in the group public key set T For comparison, if the bilinear pairing The representation X of the bilinear pairing e(g,X) T If the bilinear pairing is equal, the signature is valid; The representation X of the bilinear pairing e(g,X) T If they are not equal, the signature is invalid.
[0111] 7. The valid group signature result G S The identity ID of the corresponding signing member i Traverse the identity tracing list TRlist to obtain the specific identity information of the signing member to complete the authentication of the digital signature.
[0112] 8. Summary
[0113] Proof of signature correctness:
[0114]
[0115] Where σ1 is the first part of the signature, σ2 is the second part of the signature, H1(m) is the result of running the secure hash function H1 on message m, K is the public parameter, e(*,*) is the bilinear pairing operation, and X T It is the group public key.
[0116] Anonymity: For a group signature (σ1, σ2, σ3), only the group public key is used in the verification phase, so any two group signatures cannot be distinguished, that is, anonymity is satisfied.
[0117] Traceability: For a group signature (σ1, σ2, σ3), the group administrator opens according to Information, traverse the identity tracing list TRlist, find Reveal signing membership.
[0118] The above-described embodiments merely illustrate several implementations of the present invention, and while their descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present invention. Therefore, the scope of protection of the patent for this invention shall be determined by the appended claims.
Claims
1. A group signature authentication method, characterized in that: include: Constructing a group including a group administrator and multiple members; wherein the group administrator has an independent identity identifier; and the members have identities that are kept confidential from each other; Group administrator's message m Group signature result G S To authenticate, perform the following operations: Based on the independent identity of the group administrator and the identity of each member in the group, create a public information list NList for storing the signature results of the group administrator and multiple members, and an identity tracing list TRlist containing the specific identity information of the group administrator and multiple members; Get Message m Group signature result of digital signature within the group G S , specifically including: selecting two random numbers ,in, To update the secret value of the private key, A random number selected when signing; Update the signing private key , calculate the secure hash function and the first part of the signature : Calculate the second-stage signature private key : in, The second part of the signature key group, is the first elliptic curve generator, is a secure hash function; Secret value Use it as secret information to perform partial anonymous identity authentication protocol and obtain the group signature result G S ,for: in, These are the message-related parts of the group signature. It is the part of the group signature used to verify the identity of the signature members. Secret identity value Corresponding to the elliptic curve group The additive subgroup of Elements, is the commitment value generated by the partial identity anonymous authentication protocol, The random number selected for the execution phase of the partial identity anonymous authentication protocol, Mapped to Secure hash function H 2 The calculated function value; The group signature result G S Traverse the public information list NList and verify the group signature result G S The validity of the signature and the identity of the signing member are obtained; The valid group signature result G S The identity identifier of the corresponding signing member is traversed in the identity tracing list TRlist to obtain the specific identity information of the signing member to complete the authentication of the group signature.
2. A group signature authentication method according to claim 1, characterized in that: The group is provided with system public parameters for group signature authentication, which specifically include: large prime number p, finite field , elliptic curve group ,group The additive subgroup G of order q A ,group The multiplicative subgroup G of T , symmetric bilinear mapping e : G A ×G A →G T , G A The first elliptic curve generator g and the second elliptic curve generator h , mapped to subgroup G A Secure hash function H 1 and mapped to Secure hash function H 2 .
3. A group signature authentication method according to claim 1, characterized in that: The creation of a public information list NList for storing the signature results of the group administrator and multiple members and an identity tracing list TRlist containing the specific identity information of the group administrator and multiple members specifically includes: Each member of the group Send the identity to the group administrator, who calculates each member's The identity secret value and the identity secret value Corresponding to the elliptic curve group The additive subgroup of Elements : in, n A large prime number The product of is the identity secret value, Secret identity value Corresponding to the elliptic curve group The additive subgroup of Elements, h is the second elliptic curve generator, i is the number of members, Identification of members; The identity secret value Corresponding to the elliptic curve group The additive subgroup of Elements As a public information list NList for storing the signature results of the group administrator and multiple members, the identity secret value , Identity Secret Value Corresponding to the elliptic curve group The additive subgroup of Elements and members The composed set serves as an identity tracing list TRlist containing specific identity information of the group administrator and multiple members.
4. A group signature authentication method according to claim 1, characterized in that: The identity secret value Partial anonymous identity authentication protocol as secret information, specifically including: Pick two random numbers , calculate the signature member identity secret value Commitment value : in, is the second elliptic curve generator, Is the random number Mapping elliptic curve groups results.
5. A group signature authentication method according to claim 1, characterized in that: The verification group signature result G S The effectiveness of For a signature , the verifier decrypts the part of the group signature used to verify the identity of the signature member , get the identity secret value Corresponding to the elliptic curve group The additive subgroup of Elements ; Traverse the public information list NList to find out whether there is a secret value that matches the identity Corresponding to the elliptic curve group The additive subgroup of Elements The same value; if there is no identical value in the list, the signature is invalid; If the secret value exists in the list Corresponding to the elliptic curve group The additive subgroup of If the elements of , the calculation is performed by mapping to the subgroup G A Secure hash function H 1 Calculated function value : Comparison is made by mapping to Secure hash function H 2 Calculated function value and mapped to the subgroup G A Secure hash function H 1 Calculated function value Is it consistent? When mapped to Secure hash function H 2 Calculated function value and mapped to the subgroup G A Secure hash function H 1 Calculated function value If they are inconsistent, the signature is invalid; When mapped to Secure hash function H 2 Calculated function value and mapped to the subgroup G A Secure hash function H 1 Calculated function value When consistent, calculate the posterior commitment value : Verify the signature member's identity secret value Commitment value Is it equal to the posterior commitment value? If the signature member has a secret value for the identity Commitment value Equal to the posterior commitment value , then the signature is valid; if the signature member has a secret value for the identity The commitment value is not equal to the posterior commitment value , the signature is invalid; Verify the signature information and calculate the bilinear pairing : in, For bilinear pairing form of expression, K is a public parameter; Bilinear pairing Bilinear pairings with the group public key set manifestations For comparison, if the bilinear pairing With bilinear pairing manifestations If the bilinear pairing is equal, the signature is valid; With bilinear pairing manifestations If they are not equal, the signature is invalid.
6. A group signature authentication system based on a group signature authentication method according to any one of claims 1 to 5, characterized in that: include: A group module is used to build a group including a group administrator and multiple members; wherein the group administrator has an independent identity identifier, and the members have identities that are kept confidential from each other; A list creation module is used to create a public information list NList for storing the signature results of the group administrator and multiple members, and an identity tracing list TRlist containing the specific identity information of the group administrator and multiple members based on the independent identity identifier of the group administrator and the identity identifier of each member in the group; Signature acquisition module, used to obtain messages m Group signature result of digital signature within the group G S ; Verification module, used to group signature results G S Traverse the public information list NList and verify the group signature result G S The validity of the signature and the identity of the signing member are obtained; Signature authentication module, used to validate the group signature result G S The identity identifier of the corresponding signing member is traversed in the identity tracing list TRlist to obtain the specific identity information of the signing member to complete the authentication of the group signature.