Double offline payment transaction method based on CA center and group signature
By adopting dual offline payment transaction methods based on CA center and group signature in a dual offline payment environment, the problem of how to trace malicious behavior while ensuring user anonymity is solved, the privacy protection of small transactions and identity traceability of large transactions is realized, and transaction security and user experience are improved.
Patent Information
- Application Number
- CN202510067388.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-05-13
AI Technical Summary
In a dual offline payment environment, how to ensure the anonymity of users and achieve effective traceability of malicious behavior has become a difficult point in the current technology.
The dual offline payment transaction method based on CA center and group signature is adopted to realize the privacy protection of small-value transactions and effective identity traceability of large-value transactions through group signature technology. The CA center sets system parameters, generates group and key pairs, assigns anonymous identifiers to each group member in the group, and generates a private key for each group member in the group based on system parameters, group and key pairs. The user terminal and the merchant terminal synchronize these parameters. The user terminal conducts group signatures based on the transaction amount and dynamic anonymity adjustment strategy, and the merchant terminal performs key verification on the signature.
It realizes high anonymity protection for small transactions and effective identity traceability for large transactions in dual offline payment environments, balances user privacy and regulatory needs, and improves transaction security and user experience.
Smart Images

Figure CN119991122A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and more particularly to a dual offline payment transaction method based on a CA center and a group signature. Background Art
[0002] With the continuous promotion and application of electronic payment, the digital RMB is currently being piloted in some regions. It can be predicted that in the near future, the digital RMB will become the main carrier of payment, which will provide great convenience for daily life. Unlike traditional banknotes and coins, the digital RMB has electronic characteristics, supporting faster payment methods and a wider range of application scenarios. However, digital currency also faces many challenges in the process of promotion, among which the security of transactions and user privacy protection have become key issues that need to be solved urgently. In addition, the application scenarios of the digital RMB are very diverse, and it has to face harsh scenarios such as imperfect networks and authentication systems. When facing offline or cross-border payments with poor networks in developing countries, it is possible that the connection with the central bank node is not smooth, and it is inevitable to use dual offline payments.
[0003] In the digital RMB system, dual offline payment is an important function that allows users and merchants to complete transactions without network connection, which greatly enhances the convenience and popularity of payment. However, in this dual offline environment, how to ensure the anonymity of users and effectively trace malicious behavior has become a difficulty in current technology. Specifically, users hope that small transactions have a high degree of anonymity to protect personal privacy from excessive disclosure, while for large transactions and transactions involving illegal activities such as fraud and money laundering, it is required to be able to effectively trace the true identity of the trader to meet the needs of regulatory compliance.
[0004] Traditional digital signature schemes can effectively ensure the integrity and non-repudiation of data, but it is often difficult to balance anonymity and traceability. For example, in digital signatures, the identity information of the signer is usually required to be disclosed to verify the legitimacy of the signature, which is obviously inappropriate for small transactions that require privacy protection. In addition, traditional schemes are inefficient and difficult to track malicious behavior when facing large-scale dual offline payment scenarios.
[0005] The group signature technology aims to enable any member of a group to sign on behalf of the entire group, so that external observers cannot directly identify the specific identity of the signer, thereby protecting the privacy of the signer. The SM9 algorithm is an identity-based public key cryptographic algorithm issued by the State Cryptography Administration. It effectively solves the complexity problem in public key management by directly using user identity information as the public key, and has good security and practicality. The security foundation of the SM9 algorithm is elliptic curves and bilinear mappings. Its security is widely recognized and has been applied in many fields, such as electronic authentication and electronic signatures.
[0006] Therefore, how to achieve anonymity and traceability under dual offline payment is a problem that technical personnel in this field urgently need to solve. Summary of the invention
[0007] In view of this, the present invention provides a dual offline payment transaction method based on CA center and group signature, which adopts group signature technology to realize privacy protection of small transactions and effective identity tracing of large transactions under digital RMB dual offline payment, balancing user privacy and regulatory needs.
[0008] In order to achieve the above object, the present invention adopts the following technical solution:
[0009] A dual offline payment transaction method based on CA center and group signature includes the following steps:
[0010] Step 1: The CA center sets the system parameters, generates a group and a key pair, assigns an anonymous identifier to each member in the group, and generates a private key for each member in the group based on the system parameters, group and key pair; the system parameters, group, key pair and private key are broadcasted synchronously to the user terminal and the merchant terminal;
[0011] Step 2: The user terminal receives the transaction amount, and generates a signature based on the system parameters, group, private key and dynamic anonymity adjustment strategy, and sends it to the merchant terminal;
[0012] Step 3: The merchant terminal verifies the signature based on the system parameters and key pair. If the signature is valid, the transaction is processed based on the transaction amount. Otherwise, the transaction is rejected.
[0013] Preferably, the specific implementation process of step 1 is:
[0014] Step 11: The CA center sets the system parameters {q, E, P1, P2, e, H1, H2, H3, P pub}Includes security parameters, elliptic curves, base points, bilinear pair mappings, hash functions, and key pairs; security parameters include large prime numbers q and finite fields F q ; Elliptic curve E / F q, meet the security requirements; select two base points P1∈E(F q )and According to the base point P1∈E(F q ) Generate group G1, based on the base point Generate group G2, k is the embedding degree; perform bilinear pairing mapping on groups G1 and G2: e: G1×G2→G T , which satisfies bilinearity, non-degeneracy and computability, where the bilinearity is expressed as for any scalar There is any e(aP1,bP2)=e(P1,P2) ab , non-degeneracy is represented by e(P1, P2)≠1, computability is represented by the existence of an effective algorithm to calculate e(P1, P2); the hash function is H4: {0, 1} * →{0, 1} n , H4 chooses to use the national encryption algorithm SM3; n is the length of the hash value; represents the unit group under a large prime number q, which contains all integers coprime with q; a and b represent the unit group of a finite field respectively. The elements in are integers under the large prime number q and are coprime with the large prime number q;
[0015] Step 12: The key pair includes the master key (msk) and the group public key (mpk); Master key (msk): randomly selected The group public key (mpk) is denoted as P pub =sP2;
[0016] Step 13: Assign a unique anonymous identifier PID to each group member i i , and the real identity ID submitted by the user terminal in the identity authentication request sent to the CA center i To separate;
[0017] Step 14: Calculate the mapping points Generate the private key d of each group member based on the mapping point and the master key i =sQ i ∈G2, and assign the corresponding private key d to each group member i through a secure channel i , according to the anonymous identifier PID corresponding to the mapping point i and real ID i , maintain and generate an identity mapping table. The purpose of maintaining an efficient identity mapping table is to map anonymous identities to real identities and associate mapping points, which can be used for identity tracing.
[0018] Preferably, the dynamic anonymity adjustment strategy in step 2 is to determine the transaction type based on the transaction amount. When the transaction amount is less than or equal to the transaction threshold, it is a small transaction, and the small transaction process is executed. When the transaction amount is greater than the transaction threshold, it is a large transaction, and the large transaction process is executed.
[0019] Preferably, the small transaction process includes the following steps:
[0020] Step 211: The user terminal generates a message M and selects a random number r.
[0021] Step 212: Calculate a temporary value T according to the random number and the base point P1, T = r-P1∈G1;
[0022] Step 213: According to the private key d i and bilinear pairing mapping to calculate the session key g, g = e(P i , d i )∈G T ;P i represents the public key point of user terminal i in group G1, according to the private key d i Calculate P with base point P1 i , P i =d i ·P1;G T Describe the output group of the bilinear pairing map e;
[0023] Step 214: Calculate hash values h and H based on the message M, the temporary value T and the session key g M ,
[0024] H M =H4(M);
[0025] Step 215: Calculate the signature value S according to the random number r and the hash value h, S = (r + h·s) mod q, s represents the master key, and mod represents the modulus operation;
[0026] Step 216: Construct a signature σ according to the temporary value T and the signature value S, σ=(T, S), and send the message M and the signature σ to the merchant terminal.
[0027] Preferably, the large transaction process includes the following steps:
[0028] Step 221: The user terminal generates a message M and selects a random number r.
[0029] Step 222: Calculate additional identity information Info based on the anonymous identifier i , Info i =H(PID i );
[0030] Step 223: construct an update message M according to the message M and the additional identity information,
[0031] Step 224: Calculate a temporary value T according to the random number and the base point P1, T = r-P1∈G1;
[0032] Step 225: According to the private key d i Calculate the session key g, g = e(P i , d i )∈G T ;
[0033] Step 226: Calculate hash values h and H based on the update message M′, the temporary value T and the session key g M , H M =H4(M');
[0034] Step 227: Calculate the signature value S according to the random number r and the hash value h, S = (r + h·s) mod q;
[0035] Step 228: Construct a signature σ according to the temporary value T and the signature value S, σ=(T, S), and send the update message M and the signature σ to the merchant terminal.
[0036] Preferably, the process of performing key verification on the signature in step 3 is:
[0037] Step 31: Take the message M or the updated message M, the signature σ, and the system parameters as input. The system parameters include P1, P2, e, H2, P pub ; Parse the temporary value T and the signature value S from the signature σ, and calculate the signature verification session key g′=e(T, P pub )∈G T ;
[0038] Step 32: Calculate the signature hash value based on the signature verification session key or
[0039] Step 33: Calculate SP1=T+h P based on the temporary value T, signature value S and signature verification hash value pub Is it established? If so, the user terminal and the merchant terminal continue to process the transaction according to the transaction amount and generate a transaction record; otherwise, the transaction is rejected.
[0040] Preferably, the method further includes step 4: after the network is restored, abnormal behavior detection is performed, which specifically includes the following steps:
[0041] Step 41: The merchant terminal synchronizes the stored transaction records to the central ledger system; the central ledger system is maintained by a bank terminal with a high security level, has an immutable structure, and is synchronized and shared with other bank terminals with a lower security level;
[0042] Step 42: The central ledger system verifies and compares the transaction records to check whether there is any malicious behavior. If there is any malicious behavior, it proceeds to step 43; if there is no malicious behavior, it updates the account balances of the user terminal and the merchant terminal, and sends transaction confirmation information to the user terminal and the merchant terminal to complete the transaction;
[0043] Step 421: The central ledger system performs a uniqueness check on the synchronized transaction record; the transaction record includes the message M or the update message M′, as well as the signature σ and the hash value H M ; The hash value H in the synchronized transaction record M Compare, if they are the same, confirm that the transaction record is unique and go to step 422, otherwise it is determined that there is malicious behavior and go to step 43;
[0044] Step 422: The central ledger system recalculates the verification hash value based on the message M or the update message M′ in the transaction record or If the verification hash value is the same as the hash value H in the transaction record M If the transaction records are the same, it is confirmed that the transaction records have not been tampered with and the process proceeds to step 423. Otherwise, it is determined that there is malicious behavior, and a tampering alarm notification is generated and transmitted to the user terminal and the merchant terminal, and abnormal information is generated at the same time, and the process proceeds to step 43;
[0045] Step 423: The central ledger system uses the group public key P pub Perform key verification on the signature σ, which is the same as the key verification process of the merchant terminal. If the verification passes, it will prompt that there is no abnormality. Otherwise, it is judged that there is malicious behavior and go to step 43;
[0046] Step 43: If the transaction is a large-value transaction, the CA center is authorized to perform identity tracing; if it is a small-value transaction, the corresponding user terminal and merchant terminal are marked as suspicious users, and are subject to key monitoring, and the CA center is authorized to perform identity tracing.
[0047] Preferably, authorizing the CA center to perform identity tracing specifically includes the following steps:
[0048] Step 431: Obtain signature σ, obtain message M in small transaction or update message M′ in large transaction;
[0049] Step 432: Based on the base point P1 and the private key d i Calculate the user session key g for all terminals i participating in the transaction i , gi =e(P1, d i ); Terminal i includes user terminal, merchant terminal and any other terminal involved in transaction signing;
[0050] Step 433: Based on the message M or the updated message M′, and the user session key g i , combined with the temporary value T obtained by parsing the signature σ, calculate the user hash value h i ,h i =H2(M||T||g i ) or h i =H2(M||T||g i );
[0051] Step 434: Calculate based on signature σ such that S·P1=T+h i ·P pub The hash value h i , according to the hash value h i Get the corresponding private key d i ; By hash value h i Calculate the corresponding user session key g i , by the user session key g i Calculate the corresponding private key d i ;
[0052] Step 435: According to the private key d i Calculate the corresponding mapping point Q i , perform mapping search according to the maintained identity mapping table and find the corresponding anonymous identifier PID i , according to the anonymous identifier PID i Confirm the real ID of the signer i The above tracing process can ensure privacy and ensure that the anonymous identification and real identity of other users will not be exposed during the tracing process.
[0053] Preferably, the CA center maintains a secure database of anonymous identification and real identity mapping to ensure that the association between the user's anonymous identification and real identity can only be accessed with legal authorization, and the real identity corresponding to the anonymous identification is searched according to the database during identity tracing.
[0054] It can be seen from the above technical solution that compared with the prior art, the present invention discloses a dual offline payment transaction method based on CA center and group signature, which aims to solve the balance problem of privacy protection in transactions of different amounts in dual offline payment. It uses improved SM9 group signature, introduces anonymous identification and dynamic anonymity adjustment strategy, and combines the management of CA center to achieve high anonymity protection for small transactions and effective identity tracing for large transactions, achieving a good balance between privacy protection and regulatory needs. While protecting user privacy, this method meets the regulatory agency's requirements for anti-illegal transaction compliance, and has broad application prospects, especially in the digital RMB system that supports dual offline transactions. It can significantly improve the security of transactions and user experience, and promote the healthy development of digital currency. Specifically, it has the following significant advantages:
[0055] (1) The introduction of anonymous identification (PID) allows users to complete signatures and transactions without revealing their real identities. This anonymous identification is independent of the user's real identity, making it impossible for a third party to associate transaction behavior with a specific user without legal authorization, fully protecting user privacy. In addition, the improved algorithm meets the security characteristics of group signatures, such as anonymity, unforgeability, and unlinkability, ensuring the privacy and security of transactions.
[0056] (2) Identity tracing capability for large-value transactions: For large-value transactions, considering the risk of illegal activities, the present invention adds some identity information to the signature, for example, by hashing the user's anonymous identifier to generate additional information. This method allows large-value transactions to be anonymous while still being able to be quickly traced back to the specific signatory's identity through the CA center with legal authorization. In this way, the present invention achieves effective tracing of large-value transactions and high-risk transactions, providing compliance assurance for regulators.
[0057] (3) Dynamic anonymity adjustment strategy: The present invention also introduces a dynamic anonymity adjustment strategy, which can dynamically adjust the anonymity according to the transaction amount and risk level. When the transaction amount is small, the system provides a high degree of anonymity protection to ensure that the user's privacy is not leaked; when the transaction amount is large, the system appropriately reduces the anonymity and enhances the traceability of the identity to achieve effective monitoring of high-risk transactions. This dynamic adjustment mechanism enables the present invention to find a balance between protecting user privacy and meeting regulatory requirements, and is suitable for different transaction scenarios.
[0058] (4) Abnormal behavior detection and identity tracing: In a dual offline transaction scenario, the transaction records of users and merchants will be synchronized to the central account system of the central bank after the network is restored. The present invention has a complete abnormal behavior detection mechanism. By comparing and verifying transaction records, it can promptly detect abnormal behaviors such as repeated transactions, forged signatures, and tampered transactions. For malicious behaviors in large transactions, the CA center can be authorized to conduct identity tracing, accurately locate the true identity of the attacker, and help regulatory agencies conduct subsequent investigations and penalties; and for users who frequently conduct small transactions of the same amount, the system will mark them as suspicious users and conduct key monitoring, thereby achieving an effective balance between transaction security and user privacy. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0060] Figure 1 A schematic diagram of a transaction method for dual offline payment based on CA center and group signature provided by the present invention;
[0061] Figure 2 A timing diagram of a transaction method under dual offline payment based on CA center and group signature provided by the present invention. DETAILED DESCRIPTION
[0062] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0063] The embodiment of the present invention discloses a transaction method under dual offline payment based on CA center and group signature, which adopts CA center and group signature technology to realize the dynamic balance between privacy protection and attack tracing of dual offline transactions of digital RMB, wherein the CA center is the trust root of the system, responsible for the initialization and management of the entire system, and generates system parameters, master keys, group public keys, and private keys for each group member. The CA center also assigns an anonymous identifier (PID) to each user to protect the privacy of the user. Under legal authorization, the CA center can perform identity disclosure and trace the true identity of malicious users; group signature is a cryptographic technology that allows any member of a group to sign on behalf of the entire group, so that external observers cannot identify the specific identity of the signer, thereby protecting the privacy of the signer. The group signature has the characteristics of unforgeability, unlinkability and traceability under legal authorization; dual offline transactions are payment transactions conducted when both users and merchants have no network connection. This mode supports users and merchants to complete payment operations in an offline environment, which greatly enhances the popularity and application scenarios of digital RMB. After the network is restored, the transaction records will be synchronized to the central account book of the central bank for verification and anomaly detection. The overall flow chart of the present invention is as follows Figure 1 As shown, the following steps are included:
[0064] S1: CA center performs system initialization:
[0065] Select security parameters: select a large prime number q, define a finite field; define an elliptic curve: define an elliptic curve E / F q , meet the security requirements; select the base point: select the base point P1∈E(F q ), generate group G1; select base point Where k is the embedding degree, generating group G2; define the bilinear pairing mapping e: G1×G2→G T , where the bilinear representation is for any scalar There is any e(aP1,bP2)=e(P1,P2) ab , non-degeneracy is expressed as e(P1, P2)≠1, and computability is expressed as the existence of an effective algorithm to calculate e(P1, P2); choose the corresponding hash function: H4: {0, 1} * →{0, 1} n , H4 chooses to use the national encryption algorithm SM3; n is the length of the hash value; represents the unit group under a large prime number q, which contains all integers coprime with q; a and b represent the unit group of a finite field respectively. The elements in are integers under the large prime number q and are coprime with the large prime number q;
[0066] The CA center generates the master key: generates the master key and group public key and publishes the system parameters, which include {q, E, P1, P2, e, H1, H2, H3, P pub}; The CA center performs key generation for each group member, and the master key is randomly selected Group public key P pub =sP2;
[0067] Assign anonymous identifiers: Assign a unique anonymous identifier PID to each group member i i , and the real identity ID submitted by the user terminal in the identity authentication request sent to the CA center i Separation; the CA center maintains a secure database mapping anonymous identification and real identity, ensuring that the association between the user's anonymous identification and real identity can only be accessed with legal authorization;
[0068] Calculate the mapping points Generate the private key d for each group member i =sQ i ∈G2, assign a private key to group member i through a secure channel; according to the anonymous identifier PID corresponding to the mapping point i and real ID i , maintain and generate an identity mapping table and store it in the database; the purpose of maintaining an efficient identity mapping table is to map anonymous identifiers to real identities and associate mapping points, which can be used for identity tracing.
[0069] S2: The user terminal receives the transaction amount, and generates a signature based on the system parameters, group, private key and dynamic anonymity adjustment strategy, and sends it to the merchant terminal;
[0070] The dynamic anonymity adjustment strategy is to determine the transaction type based on the transaction amount. When the transaction amount is less than or equal to the transaction threshold, it is a small transaction and the small transaction process is executed. When the transaction amount is greater than the transaction threshold, it is a large transaction and the large transaction process is executed.
[0071] The small transaction process includes the following steps:
[0072] S211: The user terminal generates a message M and selects a random number r.
[0073] S212: Calculate a temporary value T according to the random number and the base point P1, T = r-P1∈G1;
[0074] S213: According to the private key d i Calculate the session key g, g = e(P i , d i )∈G T ;P irepresents the public key point of user terminal i in group G1, according to the private key d i Calculate P with base point P1 i , G T Describe the output group of the bilinear pairing map e;
[0075] S214: Calculate hash values h and HM based on the message M, the temporary value T and the session key g. H M =H4(M);
[0076] S215: Calculate a signature value S according to the random number r and the hash value h, S = (r + h·s) mod q; s represents the master key, and mod represents a modulus operation;
[0077] S216: Construct a signature σ according to the temporary value T and the signature value S, σ=(T, S), and send the message M and the signature σ to the merchant terminal;
[0078] The large transaction process includes the following steps:
[0079] S221: The user terminal generates a message M and selects a random number r.
[0080] S222: Calculate additional identity information Info based on the anonymous identifier i , Info i =H(PID i );
[0081] S223: Construct an update message M′ according to the message M and the additional identity information, where M′=M||Info i ;
[0082] S224: Calculate a temporary value T according to the random number and the base point P1, T = r-P1∈G1;
[0083] S225: According to the private key d i Calculate the session key g, g = e(P i , d i )∈G T ;
[0084] S226: Calculate hash values h and H based on the update message M′, the temporary value T and the session key g M , H M =H4(M');
[0085] S227: Calculate the signature value S according to the random number r and the hash value h, S = (r + h·s) mod q;
[0086] S228: Construct a signature σ according to the temporary value T and the signature value S, σ=(T, S), and send the update message M′ and the signature σ to the merchant terminal;
[0087] S3: The merchant terminal verifies the signature based on the system parameters and key pair. If the signature is valid, the transaction is processed based on the transaction amount. Otherwise, the transaction is rejected.
[0088] S31: Take message M or updated message M′, signature σ, and system parameters as input. System parameters include P1, P2, e, H2, P pub ; Parse the temporary value T and the signature value S from the signature σ, and calculate the signature verification session key g′=e(T, P pub )∈G T ;
[0089] S32: Calculate the signature verification hash value based on the signature verification session key or
[0090] S33: Calculate SP1=T+hP based on the temporary value T, signature value S and signature verification hash value pub Is it established? If so, the user terminal and the merchant terminal continue to process the transaction according to the transaction amount and generate a transaction record; otherwise, the transaction is rejected;
[0091] S4: After the network is restored, abnormal behavior detection is performed;
[0092] S41: The merchant terminal synchronizes the stored transaction records to the central ledger system; the central ledger system is maintained by a bank terminal with a high security level, has an immutable structure, and is synchronized and shared with other bank terminals with a lower security level;
[0093] S42: The central ledger system verifies and compares the transaction records to check whether there is any malicious behavior. If there is any malicious behavior, it proceeds to S43; if there is no malicious behavior, it updates the account balances of the user terminal and the merchant terminal, and sends transaction confirmation information to the user terminal and the merchant terminal to complete the transaction;
[0094] S421: The central ledger system performs a uniqueness check on the synchronized transaction record; the transaction record includes the message M or the update message M′, as well as the signature σ and the hash value H M ; The hash value H in the synchronized transaction record M Compare them. If they are the same, confirm that the transaction record is unique and proceed to S422. Otherwise, determine that there is malicious behavior and proceed to S43.
[0095] S422: The central ledger system recalculates the verification hash value based on the message M or the update message M′ in the transaction record or If the verification hash value is the same as the hash value H in the transaction record M If the transaction record is the same, it is confirmed that the transaction record has not been tampered with and the process proceeds to S423. Otherwise, it is determined that there is malicious behavior, and a tampering alarm notification is generated and transmitted to the user terminal and the merchant terminal. At the same time, abnormal information is generated and the process proceeds to S43.
[0096] S423: The central ledger system uses the group public key P pub Perform key verification on the signature σ, which is the same as the key verification process of the merchant terminal. If the verification passes, it will prompt that there is no abnormality. Otherwise, it is judged that there is malicious behavior and enter S43;
[0097] S43: If the transaction is a large-value transaction, the CA center is authorized to perform identity tracing; if it is a small-value transaction, the corresponding user terminal and merchant terminal are marked as suspicious users, and are monitored, and the CA center is authorized to perform identity tracing; the identity tracing process is:
[0098] S431: Obtain signature σ, obtain message M in a small transaction or update message M in a large transaction;
[0099] S432: Based on the base point P1 and the private key d i Calculate the user session key g for all terminals i participating in the transaction i , g i =e(P1, d i );
[0100] S433: Based on the message M and the user session key g i Calculate the user hash value h i ,h i =H2(M||T||g i ) or h i =H2(M||T||g i );
[0101] S434: Calculate based on signature σ such that S·P1=T+h i ·P pub The hash value h i , according to the hash value h i Calculate the corresponding private key d i ; By hash value h i Calculate the corresponding user session key g i , by the user session key g i Calculate the corresponding private key d i ;
[0102] S435: By PID i Find the signer's real ID i ; According to the private key d iCalculate the corresponding mapping point Q i , perform mapping search according to the maintained identity mapping table and find the corresponding anonymous identifier PID i , determine the real identity ID of the signer based on the anonymous identifier PID i .
[0103] On the other hand, in a specific embodiment, user A buys some daily necessities in a supermarket, and the transaction amount is 100 yuan, which is a small transaction. In order to protect the user's privacy information, user A uses the improved SM9 group signature scheme to complete the transaction. The specific process is as follows:
[0104] S1. Transaction preparation:
[0105] User A prepares a transaction message through his mobile device (UE), which includes basic transaction information such as transaction amount, merchant information, and timestamp. The transaction message is generated in plain text so that the user can sign it later. After the transaction message is generated, the system enters the signature generation step;
[0106] S2. Signature generation:
[0107] User A's mobile device generates a transaction signature; User A signs the transaction message with his private key and uses the improved SM9 group signature algorithm to generate a signature, which consists of two parts: a transaction signature part, which is used to prove the authenticity of the transaction, and a signature part generated based on the user's private key, which is used to prove that the signature is a legitimate group signature; when generating the signature, the signing process ensures that the identity information of User A is not directly exposed in the signature, thereby achieving the anonymity of the transaction. After the signature is generated, the system is ready to transmit the transaction message;
[0108] S3. Transaction transmission:
[0109] User A sends the transaction message and its signature to the merchant terminal device (ME) through NFC or QR code. In a dual offline environment, the transaction message is transmitted through communication between local devices without the need for network connection. After the message transmission is completed, the merchant terminal device is ready for signature verification;
[0110] S4.Signature verification:
[0111] After receiving the transaction message and signature from user A, the merchant terminal device B uses the group public key to verify the validity of the signature; the merchant verifies whether it is established through bilinear pairing operation. If it is established, it indicates that the signature is valid. After the verification is successful, the merchant accepts the transaction and generates receipt information, and the system enters the transaction completion state. If the verification fails, the merchant terminal device will reject the transaction and display a prompt message that the transaction is invalid to the user. At the same time, the merchant terminal device will record the information of the abnormal transaction for subsequent audit and investigation;
[0112] S5. Transaction completed:
[0113] After the transaction is completed, the merchant terminal device records the transaction information and synchronizes it with the central account system of the central bank after the network is restored. During the transaction synchronization process, the identity information of user A is still not exposed, ensuring that the user's privacy is protected.
[0114] S6. Perform anomaly detection and perform the following operations to ensure transaction security:
[0115] Transaction record synchronization: The transaction records of users and merchants are synchronized to the central bank's central ledger system, and the synchronized transaction records are checked for uniqueness to detect whether there are duplicate transactions;
[0116] Recalculate the hash value of the transaction message and compare it with the original record. If they are different, mark it as a tampered transaction;
[0117] Use the group public key to verify the signature. If the verification fails, it is marked as a forged signature.
[0118] S7.Exception handling:
[0119] Different handling measures are taken for detected abnormal behaviors: if frequent small-amount abnormal transactions are found, the system will mark the user as a suspect and conduct key monitoring; if transactions are tampered with or signatures are forged, the transaction will be terminated and identity tracing will be carried out.
[0120] S8. Identity tracing:
[0121] With legal authorization, the CA center conducts identity tracing on malicious users. The specific process is as follows: obtain the message and signature of the target transaction, calculate the session key for all users, find possible signers, recalculate the hash value of the transaction message, and compare it with the signature part to find the signer who meets the verification conditions and confirm the true identity of the malicious user; during the tracing process, ensure that the anonymous identification and identity information of other users are not leaked.
[0122] On the other hand, in a specific embodiment, in a large transaction, a user generates a message M, which represents the relevant content of the transaction, including the transaction amount and product details. For example, the message M is "A = 3000 yuan commodity X transaction". The user calculates the identity information i to indicate his role in the transaction. Assume that the user's anonymous identifier is i = "user 1234", and the local calculation user ID = H(i). The user appends the identity information to the original message M to construct an updated message M'. The updated message M' is "A = 3000 yuan commodity X transaction, user ID = H(i)".
[0123] The user performs the same signature generation process as for small transactions, the specific steps are as follows:
[0124] S1: The user terminal device selects a random number r and calculates a temporary value T = r-P1, where P1 is the base point of the elliptic curve;
[0125] The session key is as follows: g = e(P pub , T), where P pub is the group public key of the system, e is a bilinear pairing mapping;
[0126] Calculate the hash value h = H(M');
[0127] Calculate the signature value S = (r + h·s) mod q;
[0128] Construct signature o = (T, S), the user sends the message M' and signature σ to the merchant terminal device;
[0129] S2: Signature verification:
[0130] Executed by the merchant terminal device, with the message M', signature σ and system parameters as input, calculate the signature verification session key g'=e(P pub , T), calculate the signature verification hash value: h'=H(M'), and check whether S·P1=T+h′·P pub ; If the conditions are met, the verification is successful, the signature is valid, and the merchant terminal device continues to process the transaction; otherwise, the transaction is rejected and the exception is recorded;
[0131] S3: Anomaly detection, when the network is restored, perform the following operations:
[0132] Transaction record synchronization: User terminal equipment (UE) and merchant terminal equipment (ME) synchronize the stored transaction records to the central bank's central ledger system; the central bank's central ledger system verifies and compares the transaction data to detect whether there are any abnormalities;
[0133] S4: Exception handling: If malicious behavior is found in an abnormal situation, the central bank authorizes the CA center to conduct identity tracing. With the authorization of the central bank, the CA center performs the following operations:
[0134] Get the signature σ and message M';
[0135] Calculate the user session key gi for all users i;
[0136] Calculate the user hash value h i =H(M');
[0137] Verify the match: Check if there is a user who meets the conditions, so that S·P1=T+h i ·P pub, find the anonymous identifier that meets the conditions and thus find the real identity of the corresponding signer. During the tracing process, ensure that the anonymous identifier and real identity of other users will not be exposed.
[0138] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0139] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A dual offline payment transaction method based on CA center and group signature, characterized in that: The following steps are involved: Step 1: The CA center sets the system parameters, generates a group and a key pair, assigns an anonymous identifier to each member in the group, and generates a private key for each member in the group based on the system parameters, group and key pair; Synchronously broadcast system parameters, groups, key pairs and private keys to user terminals and merchant terminals; Step 2: The user terminal receives the transaction amount, and generates a signature based on the system parameters, group, private key and dynamic anonymity adjustment strategy, and sends it to the merchant terminal; Step 3: The merchant terminal verifies the signature based on the system parameters and key pair. If the signature is valid, the transaction is processed based on the transaction amount. Otherwise, the transaction is rejected.
2. A dual offline payment transaction method based on CA center and group signature according to claim 1, characterized in that: The specific implementation process of step 1 is: Step 11: The CA center sets the system parameters {q, E, P1, P2, e, H1, H2, H3, P pub }Includes security parameters, elliptic curves, base points, bilinear pair mappings, hash functions, and key pairs; security parameters include large prime numbers q and finite fields F q ; Elliptic curve E / F q , meet the security requirements; select two base points P1∈E(F q )and According to the base point P1∈E(F q ) Generate group G1, based on the base point Generate group G2, k is the embedding degree; perform bilinear pairing mapping on groups G1 and G2: e: G1×G2→G T , which satisfies bilinearity, non-degeneracy and computability, where the bilinearity is expressed as for any scalar There is any e(aP1, bP2) = e(P1, P2) ab , non-degeneracy is represented by e(P1, P2)≠1, computability is represented by the existence of an effective algorithm to calculate e(P1, P2); the hash function is H4: {0, 1} * →{0, 1} n , H4 chooses to use the national encryption algorithm SM3; n is the length of the hash value; represents the unit group under a large prime number q, which contains all integers coprime with q; a and b represent the unit group of a finite field respectively. The elements in are integers under the large prime number q and are coprime with the large prime number q; Step 12: The key pair includes a master key and a group public key. The master key is randomly selected. Group public key P pub =sP2; Step 13: Assign a unique anonymous identifier PID to each group member i i , and the real identity ID submitted by the user terminal in the identity authentication request sent to the CA center i To separate; Step 14: Calculate the mapping points Generate the private key d of each group member based on the mapping point and the master key i =sQ i ∈G2, and assign the corresponding private key d to each group member i through a secure channel i , according to the anonymous identifier PID corresponding to the mapping point i and real ID i , maintain and generate identity mapping table.
3. A dual offline payment transaction method based on CA center and group signature according to claim 2, characterized in that: The dynamic anonymity adjustment strategy in step 2 is to determine the transaction type based on the transaction amount. When the transaction amount is less than or equal to the transaction threshold, it is a small transaction, and the small transaction process is executed. When the transaction amount is greater than the transaction threshold, it is a large transaction, and the large transaction process is executed.
4. According to claim 3, a dual offline payment transaction method based on CA center and group signature is characterized in that: The small transaction process includes the following steps: Step 211: The user terminal generates a message M and selects a random number r. Step 212: Calculate a temporary value T according to the random number and the base point P1, T = r-P1∈G1; Step 213: According to the private key d i and bilinear pairing mapping to calculate the session key g, g = e(P i , d i )∈G T ;P i represents the public key point of user terminal i in group G1, according to the private key d i Calculate P with base point P1 i , P i =d i ·P1;G T Describe the output group of the bilinear pairing map e; Step 214: Calculate hash values h and H based on the message M, the temporary value T and the session key g M , H M =H4(M); Step 215: Calculate the signature value S according to the random number r and the hash value h, S = (r + h·s) mod q, s represents the master key, and mod represents the modulus operation; Step 216: Construct a signature σ according to the temporary value T and the signature value S, σ=(T, S), and send the message M and the signature σ to the merchant terminal.
5. According to claim 3, a dual offline payment transaction method based on CA center and group signature is characterized in that: The large transaction process includes the following steps: Step 221: The user terminal generates a message M and selects a random number r. Step 222: Calculate additional identity information Info based on the anonymous identifier i , Info i =H(PID i ); Step 223: Construct an update message M′ according to the message M and the additional identity information, where M′=M||Info i ; Step 224: Calculate a temporary value T according to the random number and the base point P1, T = r-P1∈G1; Step 225: According to the private key d i Calculate the session key g, g = e(P i , d i )∈G T ; Step 226: Calculate hash values h and H based on the update message M′, the temporary value T and the session key g M , H M =H4(M'); Step 227: Calculate the signature value S according to the random number r and the hash value h, S = (r + h·s) mod q; Step 228: Construct a signature σ according to the temporary value T and the signature value S, σ=(T, S), and send the update message M and the signature σ to the merchant terminal.
6. A dual offline payment transaction method based on CA center and group signature according to claim 4 or 5, characterized in that: The process of key verification of the signature in step 3 is as follows: Step 31: Take the message M or the updated message M′, the signature σ, and the system parameters as input. The system parameters include P1, P2, e, H2, P pub ; Parse the temporary value T and the signature value S from the signature σ, and calculate the signature verification session key g′=e(T, P pub )∈G T ; Step 32: Calculate the signature hash value based on the signature verification session key or Step 33: Calculate S·P1=T+h′·P based on the temporary value T, signature value S and signature verification hash value pub Is it established? If so, the user terminal and the merchant terminal continue to process the transaction according to the transaction amount and generate a transaction record, otherwise the transaction is rejected.
7. A dual offline payment transaction method based on CA center and group signature according to claim 6, characterized in that: The step 4 is also included: after the network is restored, abnormal behavior detection is performed, which specifically includes the following steps: Step 41: The merchant terminal synchronizes the stored transaction records to the central ledger system; Step 42: The central ledger system verifies and compares the transaction records to check whether there is any malicious behavior. If there is any malicious behavior, it proceeds to step 43; if there is no malicious behavior, it updates the account balances of the user terminal and the merchant terminal, and sends transaction confirmation information to the user terminal and the merchant terminal to complete the transaction; Step 421: The central ledger system performs a uniqueness check on the synchronized transaction record; the transaction record includes the message M or the update message M′, as well as the signature σ and the hash value H M ; The hash value H in the synchronized transaction record M Compare, if they are the same, confirm that the transaction record is unique and go to step 422, otherwise it is determined that there is malicious behavior and go to step 43; Step 422: The central ledger system recalculates the verification hash value based on the message M or the update message M′ in the transaction record or If the verification hash value is the same as the hash value H in the transaction record M If the transaction records are the same, it is confirmed that the transaction records have not been tampered with and the process proceeds to step 423. Otherwise, it is determined that there is malicious behavior, and a tampering alarm notification is generated and transmitted to the user terminal and the merchant terminal, and abnormal information is generated at the same time, and the process proceeds to step 43; Step 423: The central ledger system uses the group public key P pub Perform key verification on the signature σ, which is the same as the key verification process of the merchant terminal. If the verification passes, it will prompt that there is no abnormality. Otherwise, it is judged that there is malicious behavior and go to step 43; Step 43: If the transaction is a large-value transaction, the CA center is authorized to perform identity tracing; if it is a small-value transaction, the corresponding user terminal and merchant terminal are marked as suspicious users, and are subject to key monitoring, and the CA center is authorized to perform identity tracing.
8. A dual offline payment transaction method based on CA center and group signature according to claim 7, characterized in that: Authorizing the CA center to conduct identity tracing specifically includes the following steps: Step 431: Obtain signature σ, obtain message M in small transaction or update message M′ in large transaction; Step 432: Based on the base point P1 and the private key d i Calculate the user session key g for all terminals i participating in the transaction i , g i =e(P1, d i ); Step 433: Based on the message M or the updated message M′, and the user session key g i , combined with the temporary value T obtained by parsing the signature σ, calculate the user hash value h i ,h i =H2(M||T||g i ) or h i =H2(M||T||g i ); Step 434: Calculate based on signature σ such that S·P1=T+h i ·P pub The hash value h i , according to the hash value h i Calculate the corresponding private key d i ; Step 435: According to the private key d i Calculate the corresponding mapping point Q i , according to the mapping point Q i Search in the identity mapping table and find the corresponding anonymous identifier PID i , according to the anonymous identifier PID i Find the signer's real ID i .
9. A dual offline payment transaction method based on CA center and group signature according to claim 8, characterized in that: The CA center builds a database based on anonymous identifiers and corresponding real identities, and searches the database for the real identity corresponding to the anonymous identifier during identity tracing.
Citation Information
Cited By
Privacy protection method and system based on password application security
CN122204350A