Seller autonomous auction system and method with bid privacy and bidder anonymity

Through fully homomorphic encryption and zero-knowledge shielded group signature technology, the anonymity of bidders and the privacy of bids are protected in the seller-autonomous auction system, solving the trade-off between bidder privacy and seller autonomy, and ensuring transaction security and bidder identity privacy.

CN119477495BActive Publication Date: 2025-10-14WUHAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410292086.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-14
Publication Date
2025-10-14
Estimated Expiration
2044-03-14

AI Technical Summary

Technical Problem

Existing privacy-preserving auction systems find it difficult to strike a balance between protecting bidder privacy and seller autonomy, resulting in the leakage of bidder identity privacy or the damage of seller autonomy.

Method used

A seller-autonomous auction system with bid anonymity and bid privacy is adopted. Through fully homomorphic encryption, zero-knowledge shielded group signature and commitment technology, the bidder identity anonymity and bid privacy are achieved, while allowing sellers to customize blacklists to filter winning bidders.

Benefits of technology

While protecting bidders' privacy, sellers can customize blacklists to screen legitimate bidders, ensuring transaction security and bidder anonymity, and avoiding identity leakage and misconduct.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119477495B_ABST
    Figure CN119477495B_ABST
Patent Text Reader

Abstract

The application discloses a kind of seller autonomous auction system and method with bidding anonymity and bid privacy, system includes four entities of seller, bidder, auction platform and anonymous identity provider, and is divided into six stages of initialization, registration, auction release, bidding, winner calculation and transaction.The invention aims at the trade-off between seller autonomy and buyer privacy protection in anonymous auction, and designs a group signature variant-zero-knowledge screenable group signature.The signature combines zero-knowledge proof with group signature, ensuring that the black list screening mechanism defined by the seller does not destroy the anonymity of the bidder.At the same time, by using homomorphic encryption technology, the winning bid calculation of the auction is carried out entirely in ciphertext, realizing the bidding amount and ordering privacy of the bidder.In the final transaction stage, the winner opens the value by presenting the bidding commitment of the winning bid, enabling the seller to correctly identify the winner without revealing their identity, ensuring smooth transaction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of anonymity and data privacy protection in applied cryptography, and relates to a privacy-protected auction system and method, and specifically to a seller-autonomous auction system and method with bidding anonymity and bid privacy. Background Art

[0002] An e-auction is an online commodity trading method in which buyers bid publicly for an item. The highest bidder wins and purchases the item with their winning bid. However, the identity and bid price of bidders are crucial information in e-auctions, and their disclosure can harm bidders. For example, in auctions of expensive items, leaking bidders' identities and bids can expose them to risks such as theft and robbery.

[0003] To mitigate this threat, several privacy-preserving auction approaches have been proposed. In these schemes, the auction system verifies bidder identities and calculates the winner without revealing bidders' identities or bid prices. Unfortunately, these privacy-preserving auctions can compromise seller autonomy, as sellers may wish to prevent certain bidders with whom they have had unpleasant transactions from participating in future auctions.

[0004] Anonymous bidding schemes based on privacy-preserving signatures can reveal the identity of anonymous buyers by revealing the winning tag name, thereby rejecting misbehaving bidders. However, this solution undermines the identity privacy of legitimate bidders. Applying linkable ring (group) signatures can, to a certain extent, balance the aforementioned issues of bidder privacy and seller autonomy, as sellers can determine whether the winner is the same as the previous misbehaving bidder by linking the two signatures. While this linkability does not necessarily mean identity leakage, the bidding history of all bidders is leaked through the signature. In other words, these solutions also compromise bidder privacy. Summary of the Invention

[0005] In order to solve the trade-off problem between bidder privacy and seller autonomy, the present invention provides a seller-autonomous auction system and method with bidding anonymity and bid privacy.

[0006] The technical solution adopted by the system of the present invention is: a seller-autonomous auction system with bidding anonymity and bid privacy, including four entities: sellers, bidders, auction platforms and anonymous identity providers;

[0007] The seller, being the initiator of the auction, has a customized bidder blacklist, initiates an auction request to the auction platform, and trades with the winning bidder based on the results returned by the auction platform;

[0008] The bidders participate in the bidding by placing encrypted bids on the auction platform, and the winning bidder can purchase the items auctioned by the seller at their own bid;

[0009] The auction platform is responsible for processing the auction request from the seller and publishing it publicly, collecting the encrypted bids from the bidders, verifying the legitimacy of the bids, and calculating the winning bidder based on the bidder blacklist provided by the seller, and finally returning the result to the seller;

[0010] The anonymous identity provider provides anonymous identity authentication services to the bidders so that the auction platform can verify the legitimacy of the anonymous bids.

[0011] The technical solution adopted by the method of the present invention is: a seller-autonomous auction method with bidding anonymity and bid privacy, including an initialization stage, a registration stage, an auction publishing stage, a bidding stage, a winner calculation stage and a transaction stage;

[0012] During the initialization phase, the auction platform and the anonymous identity provider generate public parameters and keys;

[0013] During the registration phase, the user registers as a seller with the auction platform or as a bidder with an anonymous identity provider;

[0014] During the auction release phase, the seller releases the auction item information and blacklist to the auction platform, which then verifies and broadcasts the information to all bidders.

[0015] During the bidding phase, bidders participate in the auction and send their encrypted bids to the auction platform;

[0016] During the winner calculation phase, the auction platform collects all bids for the same auction, filters valid bids based on the seller's blacklist, calculates the winner under ciphertext, and sends the result to the seller for decryption;

[0017] During the transaction phase, the seller broadcasts the winner's bid commitment, and the winner proves his or her identity by presenting the open value of the commitment, thereby completing the transaction.

[0018] Preferably, in the initialization phase, the anonymous identity provider generates a group public key, an administrator private key, an opening private key and a group initial state, and sends the group public key to the auction platform; the auction platform generates its own signature public-private key pair and publicly releases its own signature public key.

[0019] Preferably, during the registration phase, the user registers as a seller or an anonymous bidder;

[0020] When registering as a seller, the user generates their own homomorphic encryption public-private key pair and signature public-private key pair, makes both public keys public, and sends a registration request containing their identity information to the auction platform;

[0021] When registering as a bidder, the user sends a registration request containing their identity information to the anonymous identity provider. The anonymous identity provider verifies the request, updates the group status, and generates a new group private key and returns it to the user.

[0022] Preferably, during the auction release phase, the seller signs the auction item information and blacklist, and then sends his or her identity number, signature, auction item information and blacklist to the auction platform; the auction platform verifies the signature, and if the verification is successful, an auction number is assigned to the auction, and an auction notice containing the auction number, seller identity number, auction item information and blacklist is generated, and then the auction notice is signed, and finally the signature and auction notice are broadcast to all bidders.

[0023] Preferably, the bidding stage is specifically implemented by the following steps:

[0024] Step 1: The bidder verifies the auction notice signature from the auction platform. If it passes and the bidder is interested in the auction, proceed to step 2, otherwise the auction ends.

[0025] Step 2: The bidder checks whether he is on the blacklist in the auction notice, that is, checks whether there is a blocked tag he has generated in the blacklist. If not, proceed to step 3, otherwise end;

[0026] Step 3: The bidder encrypts his bid with the seller’s public key.

[0027] Step 4: The bidder selects a random number and uses a hash function to calculate a bid commitment using the auction number, bid plaintext, and the random number in the auction notice.

[0028] Step 5: The bidder generates a bid containing the auction number, bid plaintext, and bid commitment, signs the bid, generates a shielding tag corresponding to the signature, and finally sends the signature, shielding tag, and bid to the auction platform.

[0029] Preferably, in the winner calculation stage, the auction platform collects all bids of the same auction according to the auction number and verifies the legitimacy of the bids; then the auction platform uses a fully homomorphic computing circuit to calculate the maximum bid price and the ciphertext of the bid commitment among all legal bids in the auction, and sends it to the seller after signing it and the auction number; after the seller verifies the signature, he uses the private key to decrypt it to obtain the plaintext of the maximum bid price and bid commitment.

[0030] The fully homomorphic computing circuit inputs the seller's homomorphic encryption public key epk sid , the encrypted price of all valid bids Bid receipts for all valid bids The parameters n and d of the approximate function Comp are: each time, all encrypted prices are divided into two groups, and the Comp algorithm is used to compare the sizes of the two groups. The larger encrypted price and its bid certificate are retained and enter the next round of comparison; after logk comparisons, the maximum encrypted bid is obtained. and its bid certificate And output; the approximate function Comp is:

[0031]

[0032]

[0033] Among them, a and b represent the two input values ​​that need to be compared, and d represents the function f n (x) is the number of iterations, n is a number used to limit 0≤i≤n, x represents the function f n The input of (x) is k, which represents the total number of bid certificates, and logk represents the logarithm operation with base 2 on k.

[0034] Preferably, during the transaction stage, the seller signs the winner's bid commitment, and then broadcasts the auction number, bid commitment, and signature; after the winner verifies the signature, it sends a transaction request message and the random number used to generate the bid commitment to the buyer; finally, the seller opens the commitment and conducts the transaction; if the seller is not satisfied with the transaction, he or she applies to the auction platform to add the blocking tag of the anonymous winning buyer to his or her own blacklist.

[0035] Preferably, the method includes a fully homomorphic encryption scheme, a zero-knowledge shieldable group signature scheme, a common signature scheme, and an encryption scheme;

[0036] The fully homomorphic encryption scheme includes four algorithms: key generation, encryption, evaluation, and decryption. It ensures that the decrypted result of the ciphertext calculation is equivalent to the result of the plaintext calculation, which is used to protect the bidder's price privacy.

[0037] The zero-knowledge shielded group signature scheme includes five algorithms: initialization, joining, signing, verification, and opening. It invalidates the signatures of blacklisted users without destroying user anonymity and is used to screen legitimate bids according to seller requirements during the winner calculation phase.

[0038] The common signature scheme includes three algorithms: key generation, signing, and verification, which are used to ensure the integrity of messages transmitted between entities.

[0039] The common encryption scheme includes three algorithms: key generation, encryption, and decryption, and is used to ensure the confidentiality of messages transmitted between entities.

[0040] The beneficial effects of the present invention include:

[0041] 1. This paper proposes a privacy-preserving seller autonomous auction system that supports the application of seller-defined auction blacklists while protecting bidders' bid privacy and identity privacy.

[0042] 2. This paper proposes a zero-knowledge shieldable group signature technology. By using zero-knowledge proof and pseudo-random functions to transform the original dynamic group signature technology, it is possible to invalidate the signatures of anonymous users on the blacklist in a specified round of verification without destroying the unlinkability of other signatures.

[0043] 3. By applying homomorphic encryption technology and designing homomorphic encryption circuits, the present invention enables the entire calculation of the winning bid in the auction to be performed in ciphertext, ensuring that, except for the winning bid being eventually known to the seller, all bid prices will not be known to any party other than the bidder.

[0044] 4. The present invention applies commitment technology and enables the final seller to confirm the transaction to the buyer by opening an identity-independent commitment, thereby maintaining the anonymity of the winning bidder in the transaction stage. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] The technical solution of the present invention is further illustrated below using embodiments and specific implementation methods. In addition, some drawings are also used in the process of illustrating the technical solution. For those skilled in the art, other drawings and the intention of the present invention can be obtained based on these drawings without making any creative efforts.

[0046] Figure 1 A system model diagram of an embodiment of the present invention;

[0047] Figure 2 This is a flowchart of a single-round auction according to an embodiment of the present invention. DETAILED DESCRIPTION

[0048] In order to facilitate ordinary technicians in this field to understand and implement the present invention, the present invention is further described in detail below with reference to the accompanying drawings and examples. It should be understood that the implementation examples described herein are only used to illustrate and explain the present invention and are not used to limit the present invention.

[0049] Please see Figure 1 ,This embodiment provides a seller-autonomous auction system with bidding anonymity and bid privacy,,including four entities: sellers, bidders, an auction platform, and an anonymous identity,provider;

[0050] Said sellers, can initiate auctions and manage their respective bidder blacklists;

[0051] The bidders may bid for the auction items they are interested in;

[0052] The auction platform organizes privacy-preserving auctions and calculates winners;

[0053] The anonymous identity provider provides anonymous authentication services to bidders;

[0054] The seller is the initiator of the auction, submitting an auction request to the auction platform and conducting transactions with the winning bidder based on the results returned by the auction platform; the auction platform is responsible for processing the auction request from the seller and publishing it publicly, collecting the bidders' encrypted bids, verifying the legitimacy of the bids, calculating the winning bidder, and finally returning the results to the seller; the bidder participates in the auction by submitting an encrypted bid to the auction platform, and the winning bidder can purchase the items auctioned by the seller at his or her own bid; the anonymous identity provider provides anonymous identity authentication services for the bidder so that the auction platform can verify the legitimacy of the anonymous bid.

[0055] Please see Figure 2 ,This embodiment provides a seller-autonomous auction method with bidding anonymity and bid privacy,,including six stages: initialization, registration, auction release, bidding, winner calculation, and transaction;

[0056] During the initialization phase, the auction platform and the anonymous identity provider generate necessary public parameters and keys;

[0057] In one embodiment, during the initialization phase, the anonymous identity provider runs the initialization protocol of the zero-knowledge shielded group signature scheme to generate a group public key, an administrator private key, an open private key, and a group initial state, and sends the group public key to the auction platform; the auction platform runs the key generation algorithm of the common signature scheme to generate its own signature public-private key pair, and publicly releases its own signature public key.

[0058] During the registration phase, users can register as sellers with the auction platform or as bidders with an anonymous identity provider;

[0059] In one embodiment, during the registration phase, a user can register as a seller or an anonymous bidder at the same time, but each person can only register one identity for each role; when registering as a seller, the user runs the homomorphic encryption key generation algorithm and the ordinary signature scheme key generation algorithm to generate their own homomorphic encryption public-private key pair and signature public-private key pair, discloses these two public keys and sends a registration request containing their identity information to the auction platform; when registering as a bidder, the user sends a registration request containing their identity information to the anonymous identity provider, the anonymous identity provider verifies the request and runs the joining algorithm of the zero-knowledge shielded group signature scheme, updates the group status, and generates a new group private key and returns it to the user.

[0060] Once the system is initialized and user registration is completed, the auction process can begin. A complete auction process consists of four stages: auction release, bidding, winner calculation, and transaction. Figure 2 .

[0061] During the auction release phase, the seller releases the auction item information and blacklist to the auction platform, which then verifies and broadcasts the information to all bidders.

[0062] In one embodiment, during the auction publishing stage, the seller runs the signature algorithm of the common signature scheme to sign the auction item information and the blacklist, and then sends his or her identity number, signature, auction item information and blacklist to the auction platform; the auction platform runs the verification algorithm of the common signature scheme to verify the signature. If the verification passes, an auction number is assigned to the auction, and an auction notice containing the auction number, the seller's identity number, auction item information and the blacklist is generated. The auction notice is then signed by the signature algorithm of the common signature scheme, and finally the signature and auction notice are broadcast to all bidders.

[0063] During the bidding phase, bidders can participate in the auction based on their interests and send their encrypted bids to the auction platform;

[0064] In one embodiment, the bidding stage includes the following steps:

[0065] Step 1: The bidder runs the verification algorithm of the common signature scheme to verify the auction notice signature from the auction platform. If it passes and the bidder is interested in the auction, they can proceed to step 2, otherwise the auction ends.

[0066] Step 2: The bidder checks whether he is on the blacklist in the auction notice, that is, checks whether there is a blocking tag he has generated in the blacklist. If not, he can proceed to step 3, otherwise the subsequent steps will be invalid;

[0067] Step 3: The bidder runs the encryption algorithm of the fully homomorphic encryption scheme and encrypts his bid with the seller's public key;

[0068] Step 4: The bidder selects a random number and uses a hash function to calculate a bid commitment using the auction number, bid plaintext, and the random number in the auction notice.

[0069] Step 5: The bidder generates a bid containing the auction number, bid plaintext, and bid commitment, signs the bid using the signature algorithm of the zero-knowledge shielded group signature scheme, generates a shielding tag corresponding to the signature, and finally sends the signature, shielding tag, and bid to the auction platform.

[0070] During the winner calculation phase, the auction platform collects all bids for the same auction, filters valid bids based on the seller's blacklist, calculates the winner under ciphertext, and sends the result to the seller for decryption;

[0071] In one embodiment, during the winner calculation phase, the auction platform collects all bids for the same auction based on the auction number and runs a verification algorithm based on a zero-knowledge shielded group signature scheme to verify the legitimacy of the bids. The auction platform then uses a fully homomorphic computing circuit to calculate the maximum bid price and the ciphertext of the bid commitment among all legal bids in the auction, signs it with the auction number, and sends it to the seller. After the seller verifies the signature, he uses his private key to decrypt the plaintext of the maximum bid price and bid commitment.

[0072] In one embodiment, see Table 1, the specific implementation process of the fully homomorphic computing circuit is:

[0073] Enter the seller's homomorphic encryption public key epk sid , the encrypted price of all valid bids Bid receipts for all valid bids The parameters n and d of the approximate function Comp are used. Each time, all encrypted prices are divided into two groups, and the Comp algorithm is used to compare the sizes of the two groups. The larger encrypted price and its bid certificate are retained and enter the next round of comparison. After logk comparisons, the maximum encrypted bid is obtained. and its bid certificate And output. The calculation formula of the approximate function is And there is Among them, a and b represent the two input values ​​that need to be compared, and d represents the function f n (x) is the number of iterations, n is a number used to limit 0≤i≤n, x represents the function f n The input of (x) is k, which represents the total number of bid certificates, and logk represents the logarithm operation with base 2 on k.

[0074]

[0075]

[0076] During the transaction phase, the seller broadcasts the winner's bid commitment, and the winner proves his or her identity by presenting the open value of the commitment, thereby completing the transaction.

[0077] In one embodiment, during the transaction phase, the seller signs the winner's bid commitment and then broadcasts the auction number, bid commitment, and signature. After verifying the signature, the winner sends a transaction request and the random number (i.e., the opening value) used to generate the bid commitment to the buyer. Finally, the seller opens the commitment and conducts the transaction. If the seller is dissatisfied with the transaction, they can apply to the auction platform to have the anonymous winning buyer's block tag added to their blacklist.

[0078] The various encryption and decryption signature schemes adopted by the present invention are further described below through specific embodiments.

[0079] The encryption and decryption signature schemes used in this embodiment include a fully homomorphic encryption scheme, a zero-knowledge shieldable group signature scheme, a general signature scheme, and an encryption scheme;

[0080] The fully homomorphic encryption scheme includes four algorithms: key generation, encryption, evaluation, and decryption. It ensures that the decrypted result of the ciphertext calculation is equivalent to the result of the plaintext calculation, which is used to protect the bidder's price privacy.

[0081] The fully homomorphic computing circuit can compare the plaintext values ​​of two homomorphically encrypted ciphertexts without decrypting them, and is used to calculate the maximum bid ciphertext and its bid commitment in the winner calculation phase;

[0082] The common signature scheme includes three algorithms: key generation, signing, and verification, which are used to ensure the integrity of messages transmitted between entities.

[0083] The common encryption scheme includes three algorithms: key generation, encryption, and decryption, which are used to ensure the confidentiality of messages transmitted between entities. For the sake of brevity, they are omitted in the following description.

[0084] The zero-knowledge shielded group signature scheme, which includes five algorithms for initialization, joining, signing, verification, and opening, can invalidate signatures of blacklisted users without compromising user anonymity, and is used to screen legitimate bids according to seller requirements during the winner calculation phase.

[0085] In one embodiment, the zero-knowledge shieldable group signature scheme is specifically implemented as follows:

[0086] If Alg is an algorithm, and x and y are two variables, this example uses y←Alg(x) to indicate that when the input is x, the output of running the probabilistic algorithm Alg is y. Use y:=Alg(x) to indicate that when the input is x, the output of running the deterministic algorithm Alg is y. This example uses ZKBGS.Setup, ZKBGS.Join, ZKBGS.Sign, ZKBGS.Verify, and ZKBGS.Open to represent the initialization, joining, signing, verification, and opening algorithms of the zero-knowledge shielded group signature scheme, respectively. DGS.Setup, DGS.Join, DGS.Sign, DGS.Verify, and DGS.Open to represent the initialization, joining, signing, verification, and opening algorithms of the dynamic group signature scheme, respectively. ZKP.Setup, ZKP.Prove, and ZKP.Verify to represent the initialization, proof, and verification algorithms of the zero-knowledge proof scheme, respectively.

[0087] The key generation algorithm of the zero-knowledge shielded group signature scheme is expressed as (gpk, isk, osk, st)←ZKBGS.Setup(1 λ ), whose input is the security parameter λ. First, the algorithm runs the dynamic group signature initialization algorithm (gpk DGS , isk DGS ,osk,st)←DGS.Setup(1 λ ), whose input is the security parameter λ, and the output is the group public key gpk of the dynamic group signature algorithm DGS , administrator private key isk, open private key osk, group status st. Then set the relationship R that needs to be proved L ={(x=(nonce, tag), w=gsk): tag=PRF gsk (nonce)}, where the statement x includes a random number nonce and a tag tag, the knowledge w is the user's private key gsk, and the relationship tag = PRF gsk (nonce) indicates the tag (length l out ) is gsk as the key (length l key ), with nonce as input (length l in ), calculated using the pseudo-random function PRF. Then execute the zero-knowledge proof initialization algorithm pp←ZKP.Setup(1 λ , R L ) obtains the output proof parameter pp. Set the zero-knowledge shielded group signature group public key gpk = (gpk DGS ,pp), administrator private key isk=isk DGS , output (gpk, isk, osk, st).

[0088] The joining algorithm of the zero-knowledge shielded group signature scheme is expressed as (gsk i , st′)←ZKBGS.Join(isk,st,i), whose input is an administrator private key isk, group state st and a user identity i. The algorithm first runs the dynamic group signature joining algorithm DGS.Jion(isk,st,i) to get (gsk DGS,i , st′ DGS ), where gsk DGS,i is the group private key of the dynamic group signature algorithm of user i, st′ DGS is the new group state. Let user i’s zero-knowledge shield the group signature’s group private key gsk i =gsk DGS,i , the new zero-knowledge shielded group state st′=st′ DGS , output (gsk i , st′).

[0089] The signature algorithm of the zero-knowledge shieldable group signature scheme is expressed as (σ, bt)←ZKBGS.Sign(gpk, gsk i , m, list), whose input is a group public key gpk=(gpk DGS ,pp)(where gpk DGS is the dynamic group signature public key, pp is the zero-knowledge proof parameter), a private key gsk of user i i =gsk DGS,i (i.e., the dynamic group signature private key of user i), a message m and a blacklist list consisting of n tuples = {(nonce1, tag1), (nonce2, tag2), ..., (nonce n , tag n )}, where each tuple (nonce i , tag i ) includes a random number nonce i and a tag i The algorithm first runs the dynamic group signature algorithm σ DGS ←DGS.Sign(gpk DGS , gsk DGS,i , m) obtain user i’s dynamic group signature σ for message m DGS Next, select a length l in The random value nonce0 is used to calculate a tag for the message. In addition, for j = 0, 1, ..., n, this embodiment also calculates the label And by running the proof algorithm π of the zero-knowledge proof scheme j←ZKP.Prove(pp,(nonce j , tag′ j ), gsk DGS,i ) Generate the corresponding proof π j , to prove that tag′ j It is a legitimate private key gsk DGS,i Finally, this embodiment sets the proof material Π=(π0,π1,...,π n ), signature σ=(σ DGS ,tag′1,...,tag′ n , П), shield the tag bt = (nonce0, tag′0), and output (σ, bt).

[0090] The verification algorithm of the zero-knowledge shielded group signature scheme is expressed as 0 / 1: =ZKBGS.Verify(gpk, m, list, σ, bt), whose input is a group public key gpk=(gpk DES , pp), a message m, a signature σ=(σ DGS ,tag′1,...,tag′ n , ∏), a blacklist list = {(nonce1, tag1), (nonce2, tag2), ..., (nonce n , tag n )} and a masking tag bt = (nonce0, tag′0), where Π = (π0, π1, ..., π n ) to check the validity of these proofs. That is, 1) the verification algorithm of the dynamic group signature scheme DGS.Verify(gpk DGS , m, σ DGS ) output 1, which is the signature σ DGS is a valid dynamic group signature; 2) for any j = 1, ..., n, there is a tag j ≠tag′ j , that is, all the labels in the blacklist are not calculated by the private key of the signing user; 3) For any j = 0, ..., n, the algorithm ZKP.Verify(pp, (nonce j , tag′ j ),π j ) Output 1, which proves π j Valid, all tags are correctly calculated using the signing user's private key. If all three of the above conditions are met, the algorithm outputs 1, otherwise it outputs 0.

[0091] The opening algorithm of the zero-knowledge maskable group signature scheme is expressed as i := ZKBGS. Open(gpk, osk, m, σ), which inputs a group public key gpk = (gpk DGS , pp), a message m, and a signature σ = (σ DGS , tag'1,..., tag' n , П). The algorithm runs the opening algorithm of the dynamic group signature i := DGS. Open(gpk DGS , osk, m, σ DGS ), and outputs the obtained user identity i.

[0092] It should be understood that the above-described embodiments are part of the embodiments of the present application, rather than all the embodiments. In addition, the technical features of each embodiment or individual embodiment provided by the present application can be combined with each other to form a feasible technical solution, and such combination is not restricted by the order of steps and / or structure mode, but must be based on the realization by the ordinary skilled person in the art, and when the combination of technical solutions appears contradictory or unfeasible, it should be considered that such combination of technical solutions does not exist and is not within the protection scope of the present application.

[0093] It should be understood that the above description of the preferred embodiments is more detailed, and therefore should not be considered as a limitation on the scope of patent protection of the present application. The ordinary skilled person in the art can make substitutions or modifications under the inspiration of the present application without departing from the scope of protection claimed by the present application, and all fall within the scope of protection of the present application. The scope of protection of the present application should be subject to the appended claims.

Claims

1. A seller-autonomous auction method with bid anonymity and bid privacy, characterized by: It includes the initialization phase, registration phase, auction release phase, bidding phase, winner calculation phase and transaction phase; In the initialization phase, the anonymous identity provider runs the initialization protocol of the zero-knowledge shielded group signature scheme to generate the group public key, the administrator private key, the open private key, and the group initial state; During the registration phase, the user registers as a seller on the auction platform or as a bidder with an anonymous identity provider. When registering as a bidder, the user sends a registration request containing their identity information to the anonymous identity provider. The anonymous identity provider verifies the request and runs the joining algorithm of the zero-knowledge shielded group signature scheme, updates the group status, and generates a new dynamic group signature private key and returns it to the user. During the auction release phase, the seller releases the auction item information and blacklist to the auction platform, which then verifies and broadcasts the information to all bidders. During the bidding phase, bidders participate in the auction and send their encrypted bids to the auction platform; Use the signature algorithm of the zero-knowledge shielded group signature scheme to sign the bid and obtain the corresponding dynamic group signature; In the winner calculation phase, the auction platform collects all bids for the same auction based on the auction number and runs the verification algorithm of the zero-knowledge shielded group signature scheme to verify the legitimacy of the bids. The verification content includes (1) that the dynamic group signature is a valid dynamic group signature, (2) that all labels in the blacklist are not calculated using the dynamic group signature private key of the signing user, and (3) that all labels are correctly calculated using the dynamic group signature private key of the signing user. When all three of the above conditions are met, the verification is passed. The result is sent to the seller for decryption. During the transaction phase, the seller broadcasts the winner's bid commitment, and the winner proves his or her identity by presenting the open value of the commitment, thereby completing the transaction.

2. The seller-autonomous auction method with bid anonymity and bid privacy according to claim 1, characterized in that: During the initialization phase, the anonymous identity provider sends the group public key to the auction platform; the auction platform generates its own signature public-private key pair and publicly releases its own signature public key.

3. The seller-autonomous auction method with bid anonymity and bid privacy according to claim 1, characterized in that: During the registration phase, users register as sellers or anonymous bidders; When registering as a seller, the user generates his or her own homomorphic encryption public-private key pair and signature public-private key pair, makes these two public keys public, and sends a registration request containing his or her identity information to the auction platform.

4. The seller-autonomous auction method with bid anonymity and bid privacy according to claim 1, characterized in that: During the auction publishing stage, the seller signs the auction item information and blacklist, and then sends his or her identity number, signature, auction item information and blacklist to the auction platform; the auction platform verifies the signature, and if the verification is successful, it assigns an auction number to the auction and generates an auction notice containing the auction number, seller identity number, auction item information and blacklist, and then signs the auction notice. Finally, the signature and auction notice are broadcast to all bidders.

5. The seller-autonomous auction method with bid anonymity and bid privacy according to claim 1, characterized in that: The bidding stage specifically includes the following steps: Step 1: The bidder verifies the auction notice signature from the auction platform. If it passes and the bidder is interested in the auction, proceed to step 2, otherwise the process ends; Step 2: The bidder checks whether he is on the blacklist in the auction notice, that is, checks whether there is a blocking tag he has generated in the blacklist. If not, proceed to step 3, otherwise the process ends; Step 3: The bidder encrypts his bid with the seller’s public key. Step 4: The bidder selects a random number and uses a hash function to calculate a bid commitment using the auction number, bid plaintext, and the random number in the auction notice. Step 5: The bidder generates a bid containing the auction number, bid plaintext, and bid commitment, signs the bid, generates a shielding tag corresponding to the signature, and finally sends the signature, shielding tag, and bid to the auction platform.

6. The seller-autonomous auction method with bid anonymity and bid privacy according to claim 1, characterized in that: During the winner calculation phase, the auction platform uses a fully homomorphic computing circuit to calculate the maximum bid price and bid commitment ciphertext among all legal bids in the auction, and signs it with the auction number before sending it to the seller. After the seller verifies the signature, he uses his private key to decrypt the plaintext of the maximum bid price and bid commitment. The fully homomorphic computing circuit inputs the seller's homomorphic encryption public key epk sid , the encrypted price of all valid bids Bid receipts for all valid bids Approximate the parameters n and d of the function Comp; each time, all encrypted prices are divided into two groups, and the Comp algorithm is used to compare their sizes. The larger encrypted price and its bid certificate are retained and enter the next round of comparison; after logk comparisons, the maximum encrypted bid is obtained and its bid certificate And output; the approximate function Comp is: Among them, a and b represent the two input values ​​that need to be compared, and d represents the function f n (x) is the number of iterations, n is a number used to limit 0≤j≤n, x represents the function f n The input of (x) is k, which represents the total number of bid certificates, and logk represents the logarithm operation with base 2 on k.

7. The seller-autonomous auction method with bid anonymity and bid privacy according to claim 1, characterized in that: During the transaction phase, the seller signs the winner's bid commitment and then broadcasts the auction number, bid commitment, and signature. After verifying the signature, the winner sends a transaction request message and the random number used to generate the bid commitment to the buyer. Finally, the seller opens the commitment and conducts the transaction. If the seller is dissatisfied with the transaction, he or she may apply to the auction platform to add the anonymous winning buyer's blocking tag to his or her blacklist.

8. The seller-autonomous auction method with bid anonymity and bid privacy according to any one of claims 1 to 7, characterized in that: Including fully homomorphic encryption scheme, zero-knowledge shielded group signature scheme, ordinary signature scheme and encryption scheme; The fully homomorphic encryption scheme includes four algorithms: key generation, encryption, evaluation, and decryption. It ensures that the decrypted result of the ciphertext calculation is equivalent to the result of the plaintext calculation, which is used to protect the bidder's price privacy. The zero-knowledge shielded group signature scheme invalidates the signatures of blacklisted users without destroying user anonymity, and is used to screen legitimate bids according to seller requirements during the winner calculation phase; The common signature scheme includes three algorithms: key generation, signing, and verification, which are used to ensure the integrity of messages transmitted between entities. The common encryption scheme includes three algorithms: key generation, encryption, and decryption, and is used to ensure the confidentiality of messages transmitted between entities.

9. A seller-autonomous auction system with bid anonymity and bid privacy, for implementing the method according to any one of claims 1 to 8; characterized in that: It includes four entities: sellers, bidders, auction platforms, and anonymous identity providers; The seller, being the initiator of the auction, has a customized bidder blacklist, initiates an auction request to the auction platform, and trades with the winning bidder based on the results returned by the auction platform; The bidders participate in the bidding by placing encrypted bids on the auction platform, and the winning bidder can purchase the items auctioned by the seller at their own bid; The auction platform is responsible for processing auction requests from the sellers and publishing them publicly, collecting the encrypted bids from the bidders, verifying the legitimacy of the bids, calculating the winning bidder, and finally returning the results to the sellers; The anonymous identity provider provides anonymous identity authentication services to the bidders so that the auction platform can verify the legitimacy of the anonymous bids.

Citation Information

Patent Citations

  • Auction tracing method based on Ethereum privacy protection and implementation system

    CN113962714A

  • System for providing continuity between session clients and method therefor

    CN1656453A