Safe and efficient warrant aggregation proxy signature method
Through the warrant aggregation proxy signature method, combined with partial delegation and authorization certificate delegation, the elliptic curve algorithm is used to generate and verify proxy signatures, which solves the security and efficiency problems of proxy signatures and realizes safe and efficient proxy signatures.
Patent Information
- Application Number
- CN202410519158.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-28
- Publication Date
- 2025-10-28
AI Technical Summary
Among existing proxy signature technologies, full delegation is not secure enough, partial delegation is complex and inefficient to manage, and there are security threats in the authorization certificate delegation process.
The certificate aggregation proxy signature method is adopted, combined with partial delegation and authorization certificate delegation. By generating the public and private keys of the principal and the authorized agent, and using the elliptic curve algorithm for digital signature and verification, the security and efficiency of proxy signature are improved.
It enhances the security of proxy signatures, simplifies authority management, improves processing speed and efficiency, reduces computational complexity, and clarifies the limitations and validity periods of signed documents.
Smart Images

Figure CN120856338A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of cryptography and network security technology, and in particular to a secure and efficient method for aggregated proxy signature of credentials. Background Technology
[0002] As digital signatures become an indispensable infrastructure in cybersecurity applications, signature variants for various scenarios are becoming increasingly important in e-commerce and e-government applications. In real life, people sometimes need to authorize others to sign on their behalf. Proxy signing allows the original signer (i.e., the principal) to grant their signing rights to another person, who is called the proxy signer (i.e., the agent).
[0003] Proxy signatures can be divided into two types of authorization: full delegation and partial delegation.
[0004] In the case of full delegation, the proxy obtains the exact same signing permissions as the original signer. If the proxy's private key is leaked or maliciously used, it may lead to unauthorized signing behavior. Full delegation does not allow fine-grained control over authorization and cannot limit the signing permissions of the proxy signer for specific content. Once the signing permissions of full delegation are granted, it is difficult to revoke them, which may lead to the signer abusing the signing permissions or signing unauthorized content, resulting in insufficient security.
[0005] For some delegations, the original signer needs to make fine-grained settings for the delegate, which can only sign under specific conditions. This makes auditing and supervision difficult, and the permission management complex, increasing complexity and reducing processing efficiency.
[0006] There are two proxy signature algorithms that use authorization certificates: proxy and holder proxy. In the authorization certificate proxy method, the authorization certificate must be passed to the proxy signer. If the authorization certificate is intercepted, tampered with, or forged during the transmission process, the security of the proxy signature will be threatened. Summary of the Invention
[0007] Based on the above analysis, the embodiments of the present invention aim to provide a secure and efficient certificate aggregation proxy signature method to solve the technical problems of insufficient security of existing fully delegated proxy signatures and the complexity and low efficiency of partially delegated proxy signatures.
[0008] This invention provides a secure and efficient method for aggregated proxy signature of certificates, comprising the following steps:
[0009] Generate the public and private keys for principal i and authorized agent j respectively, and obtain the identity identifier of authorized agent j;
[0010] The principal i uses its private key to generate a digital signature using its public key, a signable message space, and the public key and identity identifier of the authorized agent j; the digital signature and the signable message space constitute the delegation information.
[0011] Agent j receives the delegation information and verifies the validity of the delegation information based on the public key of the delegator i. If valid, agent j calculates and obtains the agent signing private key and uses the agent signing private key to sign the message.
[0012] After the proxy signature is completed, the verifier verifies whether the proxy signature is a valid proxy signature for the message by the proxy j (based on the proxy principal i). If it is valid, the verifier further verifies whether the proxy j is an authorized proxy j. If so, the proxy signature takes effect; otherwise, the proxy signature is invalidated.
[0013] Further, the public and private keys of the principal i and authorized agent j are generated respectively using the key generation algorithm KeyGen(pp); including:
[0014] The common parameters pp are generated using the ParGen algorithm for generating common parameters of elliptic curves, where pp ← ParGen(1). λ ), where λ is the safety parameter;
[0015] Based on the public parameter pp, the private key sk of the delegator i is generated using the KeyGen key generation algorithm. i and the private key sk of the authorized agent j j ;
[0016] The private key sk of the principal i i The private key sk of the authorized agent j j By performing dot products with the base point G of the elliptic curve, the public key pk of the delegator i can be obtained. i PK with the public key of authorized agent j j .
[0017] Furthermore, the principal i uses its public key, the signable message space ω, and the public key and identity identifier id of the authorized agent j. j Generate message 0||pk i ||id j ||pk j ||ω, and use the private key sk i Sign the message to obtain the digital signature τ = Sig(sk) i ,0||pk i ||id j ||pk j ||ω).
[0018] Furthermore, the agent j receives (τ,ω) and verifies the validity of the delegation information based on the public key of the delegator i;
[0019] If Ver(pk) i ,0||pk i ||id j ||pk j If ||ω,τ)≠0 holds true, then it is valid, and is based on the proxy j's own private key sk. j Calculate and obtain the proxy signing private key skp, where skp = (pk i ||id j ||pk j ||ω||τ,sk j Otherwise, the entrustment will be terminated.
[0020] Furthermore, based on the proxy signature private key skp, the proxy j uses a proxy signature algorithm to perform proxy signature on the message;
[0021] The proxy signature algorithm is PSig(skp,mess), where mess is the message.
[0022] Furthermore, before performing the proxy signing, it also includes determining whether the message is within the signable message space. If so, the proxy signing is performed to obtain the proxy signature γ: γ = id j ||pk j ||ω||τ||β;
[0023] Where β=Sig(sk j ,1||pk i ||id j ||pk j ||ω||τ||mess).
[0024] Furthermore, the verifier uses a proxy signature algorithm to verify whether the proxy signature γ is a valid proxy signature of the authorized proxy j based on the principal i for the message; the proxy signature verification algorithm is PVer(pk) i The proxy identification algorithm is PIde(pk), ,mess,γ). i ,γ).
[0025] Furthermore, the verification process includes:
[0026] If γ = ⊥, then return 0; where ⊥ is an error symbol.
[0027] If parsing the proxy signature γ = id j ||pk j If ||ω||τ||β fails, return 0;
[0028] like Then it returns 0;
[0029] If Ver(pk) i ,0||pk i ||id j ||pk j If ||ω,τ)=0, then return 0;
[0030] If Ver(pk) j ,1||pk i ||id j ||pk j ||ω||τ||mess,β)=0, then 0 is returned;
[0031] Otherwise, return 1;
[0032] Where 1 represents a valid proxy signature and 0 represents an invalid proxy signature.
[0033] Furthermore, based on the validity of the proxy signature, the verifier uses the public key of the principal i and a proxy identification algorithm to identify the proxy identity of the generated proxy signature γ, and determines whether the obtained proxy identity identifier matches the identity identifier id of the authorized proxy j. j If they match, then the agent is the authorized agent j, and the agent signature is valid; otherwise, the agent signature γ is invalid.
[0034] The proxy identification algorithm is PIde(pk) i ,γ).
[0035] Furthermore, the identity of agent j that generates the agent signature γ using agent identification is then used to execute the agent identification algorithm PIde(pk). i ,γ) includes:
[0036] If the analysis γ = id j ||pk j If ||ω||τ||β fails, return ⊥;
[0037] If Ver(pk) i ,0||pk i ||id j ||pk j If ||ω,τ)=0, then return ⊥;
[0038] Otherwise, return the identity identifier id of the authorized agent j. j .
[0039] Compared with the prior art, the present invention can achieve at least one of the following beneficial effects:
[0040] 1. The certificate aggregation proxy signature algorithm in this invention is a combination of partial delegation and authorization certificate delegation, providing a method for proxy signature with protection of partial delegation, and simultaneously aggregating the proxy signatures of authorization certificates and messages, thereby enhancing the security of proxy signature;
[0041] 2. In this invention, the proxy signature algorithm PSig only calls the ordinary digital signature algorithm DS's Sig once, and achieves efficient signature generation through a single dot product operation of Y = y·G;
[0042] 3. The proxy signature verification algorithm PVer of this invention calls Ver in the ordinary digital signature algorithm DS twice, and Ver(pk) i ,0||pk i ||id j ||pk j The calculation of ||ω,τ) is independent of the message and can be pre-calculated when necessary. This reduces the computational load during signature verification and improves verification efficiency.
[0043] 4. Partially delegated proxy signature algorithms are more secure than fully delegated ones, and usually have an advantage in processing speed and efficiency.
[0044] 5. The proxy signature algorithm through the authorization certificate can clearly specify the restrictions and validity period of the signed document in the authorization certificate, without the need for an additional proxy revocation agreement, thereby simplifying the processing process, improving processing speed and efficiency.
[0045] In this invention, the above-described technical solutions can be combined with each other to achieve more preferred combinations. Other features and advantages of this invention will be set forth in the following description, and some advantages may become apparent from the description or be learned by practicing the invention. The objects and other advantages of this invention can be realized and obtained from what is particularly pointed out in the description and drawings. Attached Figure Description
[0046] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Throughout the drawings, the same reference numerals denote the same parts.
[0047] Figure 1 A flowchart illustrating a secure and efficient certificate aggregation proxy signature method;
[0048] Figure 2 This is a schematic diagram of a certificate aggregation proxy signature algorithm. Detailed Implementation
[0049] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which form part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not intended to limit the scope of the present invention.
[0050] This invention pertains to partial delegation using a license. For example, the license is calculated from the principal Alice's secret 's' and transmitted to the agent Bob. For security reasons, 's' cannot be calculated from the license.
[0051] This invention falls under the category of partial entrustment using a license, such as... Figure 1 As shown, the PSA (Proxy Signature Algorithm) method for certificate aggregation in this invention includes:
[0052] (1) A common digital signature algorithm, which is the part executed by the principal i in the proxy agreement;
[0053] (2) An interactive delegation protocol (delegation protocol) that runs between users, in which one user acts as the original signer (i.e., the delegator i) and delegates another user as the proxy signer (i.e., the proxy j);
[0054] (3) A proxy signature algorithm;
[0055] (4) The proxy signature verification algorithm corresponding to the proxy signature algorithm;
[0056] (5) A proxy identification algorithm that identifies the identity identifier of the proxy signer from the proxy signature.
[0057] like Figure 2 As shown in the figure, a specific embodiment of the present invention discloses a secure and efficient certificate aggregation proxy signature method, comprising the following steps:
[0058] Step S1: Generate the public and private keys of the principal i and the authorized agent j respectively, and obtain the identity identifier of the authorized agent j;
[0059] Step S2: The principal i uses its private key to generate a digital signature using its public key, the signable message space, and the public key and identity identifier of the authorized agent j; the digital signature and the signable message space constitute the delegation information.
[0060] Step S3: Agent j receives the delegation information and verifies whether the delegation information is valid based on the public key of the delegator i. If valid, the agent calculates and obtains the agent signing private key and uses the agent signing private key to perform agent signing on the message.
[0061] Step S4: After the proxy signature is completed, the verifier verifies whether the proxy signature is a valid proxy signature for the message by proxy j; if so, the proxy signature is effective; otherwise, the proxy signature is invalid.
[0062] Step S1 includes steps S11-S12, specifically.
[0063] Step S11: Generate the public and private keys for the principal i and the authorized agent j, respectively.
[0064] The public and private keys of the principal i and authorized agent j are generated respectively using the key generation algorithm KeyGen(pp); including:
[0065] The common parameters pp are generated using the ParGen algorithm for generating common parameters of elliptic curves, where pp ← ParGen(1). λ ), where λ is the safety parameter;
[0066] Based on the public parameter pp, the private key sk of the delegator i is generated using the KeyGen key generation algorithm. i and the private key sk of the authorized agent j j ;
[0067] The private key sk of the principal i i The private key sk of the authorized agent j j By performing dot products with the base point G of the elliptic curve, the public key pk of the delegator i can be obtained. i PK with the public key of authorized agent j j .
[0068] (1) First, the common parameter pp is generated using the elliptic curve common parameter generation algorithm ParGen, where pp ← ParGen(1 λ ), where pp is a common parameter of the elliptic curve cryptography algorithm, and λ is a security parameter;
[0069] (2) Generate the private keys of the principal i and the authorized agent j using the key generation algorithm KeyGen(pp); the input and output of the key generation algorithm are as follows:
[0070] Input: Common parameter pp;
[0071] Output: The private and public keys of principal i and authorized agent j.
[0072] (pk i ,sk i )←KeyGen(pp),(pk j ,sk j )←KeyGen(pp);
[0073] Randomly select a private key, the private key sk of the delegator i. i ←Z n * The private key sk of authorized agent j j ←Z n * Among them, Z n * Z is a number that is coprime from 1 to n; n * In this context, Z represents the set of integers, and n represents a positive integer.
[0074] The public key is obtained by multiplying the private key and G, and the public key pk of the delegator i is also calculated. i =sk i ·G, the public key pk of authorized agent j j =sk j ·G, where G is the base point on the elliptic curve.
[0075] G is the base point on the elliptic curve, a fixed point used to generate keys and perform encryption operations. In key generation algorithms, the base point G is usually used to generate the public key, which is obtained by multiplying the private key by the base point G.
[0076] Among them, the key generation algorithm KeyGen(pp) is the KeyGen algorithm in the elliptic curve signature algorithm DS=(ParGen,KeyGen,Sig,Ver).
[0077] Step S12: Obtain the identity identifier of the authorized agent j.
[0078] Get the identity identifier (id) of authorized agent j j .
[0079] Identity identifier id j The ID is the identity identifier for authorized agent j, used to identify and recognize a specific authorized agent. j Used in the agency agreement between principal i and authorized agent j;
[0080] For example, id j It can be a unique user identifier assigned to authorized agent j in the system using the certificate aggregation proxy signature algorithm, or it can be a specific name or number set in the system using the certificate aggregation proxy signature algorithm.
[0081] In practical applications, id j The method for obtaining the ID can be determined by the system designer, or it can be pre-assigned, specified during user registration, or automatically generated by the system. During implementation, ensure that the ID... j It possesses uniqueness and identifiability to ensure proper use and verification during agency authorization, signature verification, and identification processes.
[0082] Step S1 involves the principal i and the authorized agent j generating their respective keys using the public parameter pp, including the public and private keys of the principal i and the authorized agent j, and obtaining the identity identifier id of the authorized agent j. j .
[0083] Step S2, specifically.
[0084] The principal i generates a digital signature using its private key, along with its public key, the signable message space, and the public key and identity identifier of the authorized agent j. The digital signature content and the digital signature together constitute the delegation information.
[0085] The signable message space ω refers to the range or set of messages that the authorized agent j can digitally sign. In the certificate aggregation agent signing method, the principal i entrusts agent j to sign messages within a specific range, and the authorized agent j can only perform signing operations within this specific message space.
[0086] This message space can be defined according to specific application requirements, and is usually specified by the delegator i in the delegation agreement.
[0087] For example, a signable message space can be a collection of specified files, documents, and data, or it can be a specific business transaction or operation record.
[0088] After obtaining the authorization from the principal i, the authorized agent j can only sign messages within the specified message space, i.e., the specified range, and cannot sign other messages. This helps to limit the scope of the authorized agent's operation and improve security.
[0089] The principal i uses its public key, the signable message space ω, and the public key and identity identifier id of the authorized agent j. j Generate message 0||pk i ||id j ||pk j ||ω, and use the private key sk i Sign the message to obtain the digital signature τ = Sig(sk) i ,0||pk i ||id j ||pk j ||ω).
[0090] Among them, the signature algorithm Sig(sk i ,0||pk i ||id j ||pk j ||ω):
[0091] Input: including the private key sk of the delegator i i and 0||pk i ||id j ||pk j ||ω represents a message.
[0092] Output: Digital signature τ.
[0093] The signature algorithm Sig is an improvement and optimization of Sig(sk,mess) in the elliptic curve signature algorithm DS=(ParGen,KeyGen,Sig,Ver). The two parameters of the signature algorithm Sig in the elliptic curve signature algorithm are: sk is the private key and mess is the message.
[0094] This section describes how the principal i uses its private key to generate a digital signature from its public key, the signable message space, and the authorized agent j's public key and identifier. The digital signature content and the digital signature together constitute the delegation information. It should be noted that while the principal i sends the delegation information to the authorized agent j, the recipient could be the authorized agent j, other interceptors, or tamperers due to the possibility of interception.
[0095] The next part represents the recipient as agent j, and the following steps require verification of whether agent j is an authorized agent j to ensure the security of the agent signature.
[0096] Step S3 includes steps S31-S32, specifically.
[0097] Step S31: Agent j receives the delegation information and verifies the validity of the delegation information based on the public key of the delegator i.
[0098] The agent j receives (τ,ω) and verifies the validity of the delegation information based on the public key of the delegator i;
[0099] If Ver(pk) i ,0||pk i ||id j ||pk j If ||ω,τ)≠0 holds true, then it is valid, and is based on the proxy j's own private key sk. j Calculate and obtain the proxy signing private key skp, where skp = (pk i ||id j ||pk j ||ω||τ,sk j Otherwise, the entrustment will be terminated.
[0100] Ver(pk i ,0||pk i ||id j||pk j If ||ω,τ)≠0 holds true, it means that agent j uses the public key pk of principal i. i The information provided by the client is valid when it is verified.
[0101] The delegation information includes the public key pk of the delegator i. i The identity identifier id of agent j j , public key pk of proxy j j And a signatureable message space ω, and the delegator i has signed this delegation information. Successful verification means that the delegation is valid and the content of the delegation information is complete, without being tampered with or forged.
[0102] This indicates that the principal i has also made a valid delegation to the agent j, and the generated digital signature can be correctly identified and verified, meeting the requirements of security and legality. Therefore, the delegation information is considered valid.
[0103] Among them, sk j This is the private key of agent j. Whether it is the private key of authorized agent j will be verified later.
[0104] In the PSA (Power Assignment Allocation) method for certificate aggregation in this invention, self-delegation is allowed, that is, i = j is allowed.
[0105] Verification algorithm Ver(pk) i ,0||pk i ||id j ||pk j ||ω,τ), where pk i For the public key of the delegator i, 0||pk i ||id j ||pk j ||ω is the message generated by principal i, and τ is the digital signature generated by principal i.
[0106] Verification algorithm Ver(pk) i ,0||pk i ||id j ||pk j The ||ω,τ) algorithm is an optimization and improvement upon Ver(pk,mess,σ) in the elliptic curve signature algorithm. The three parameters of the Ver verification algorithm in the elliptic curve signature algorithm are: pk (the public key), mess (the message), and σ (the digital signature).
[0107] The purpose of signature verification is for the agent to use PK. i Verify if the digital signature τ is a pk i A valid delegation corresponding to the principal i.
[0108] The purpose of this section is to allow the principal i to delegate authority to the authorized agent j, and, provided that the authorized agent j verifies that the delegation is valid, to calculate the agent signature private key skp.
[0109] Step S32: Provided the delegation is valid, agent j calculates the agent signature key and uses the agent signature key to sign the message.
[0110] Based on the proxy signature private key skp, the proxy j uses a proxy signature algorithm to perform proxy signature on the message;
[0111] The proxy signature algorithm is PSig(skp,mess), where mess is the message.
[0112] Before performing the proxy signature, it is also included to determine whether the message is within the signable message space. If so, the proxy signature is performed to obtain the proxy signature γ: γ = id j ||pk j ||ω||τ||β;
[0113] Where β=Sig(sk j ,1||pk i ||id j ||pk j ||ω||τ||mess).
[0114] To determine if a message is within the signable message space, if... If the message to be signed is not in the signable message space, return ⊥, where ⊥ is an error symbol; if it is, perform proxy signing to obtain the proxy signature; let β = Sig(sk j ,1||pk i ||id j ||pk j ||ω||τ||mess), returns the proxy signature γ: γ=id j ||pk j ||ω||τ||β.
[0115] Among them, the Sig algorithm is an improvement and optimization of the Sig algorithm in DS=(ParGen,KeyGen,Sig,Ver) of the elliptic curve signature algorithm.
[0116] Step S3 involves agent j using the agent signing private key skp to perform agent signing on the message message mess within the signable message space ω.
[0117] Step S4 includes steps S41-S42, specifically.
[0118] Step S41: After the proxy signature is completed, the verifier verifies whether the proxy signature is a valid proxy signature for the message by proxy j.
[0119] The verifier uses a proxy signature algorithm to verify whether the proxy signature γ is a valid proxy signature for the message by the authorized proxy j; the proxy signature verification algorithm is PVer(pk) i ,mess,γ).
[0120] Any user can act as a signature verifier, using a proxy signature algorithm to verify the validity of the proxy signature γ as a proxy signature of the message by proxy j; the proxy signature verification algorithm is PVer(pk) i ,mess,γ).
[0121] Among them, input pk i γ is the public key of the principal i, message is the message, and γ is the proxy signature.
[0122] The verification of signatures includes:
[0123] If γ = ⊥, then return 0; where ⊥ is an error symbol.
[0124] If parsing the proxy signature γ = id j ||pk j If ||ω||τ||β fails, return 0;
[0125] like Then it returns 0;
[0126] If Ver(pk) i ,0||pk i ||id j ||pk j If ||ω,τ)=0, then return 0;
[0127] If Ver(pk) j ,1||pk i ||id j ||pk j ||ω||τ||mess,β)=0, then 0 is returned;
[0128] Otherwise, return 1;
[0129] Where 1 represents a valid proxy signature and 0 represents an invalid proxy signature.
[0130] Among them, the Ver algorithm is an improvement and optimization of the Ver algorithm in DS=(ParGen,KeyGen,Sig,Ver) of the elliptic curve signature algorithm.
[0131] The purpose of this section is to allow any user to verify whether γ is a valid signature of the principal i for the message message, that is, a valid proxy signature of the proxy for the message message.
[0132] Step S42: Based on the validity of the proxy signature, the verifier further verifies the identity of the authorized proxy j.
[0133] Based on the validity of the proxy signature, the verifier, using the public key of the principal i, employs a proxy identification algorithm to identify the identity of the proxy that generated the proxy signature γ, and determines whether the obtained proxy identity identifier matches the identity identifier id of the authorized proxy j. j If they match, then the agent is the authorized agent j, and the agent signature is valid; otherwise, the agent signature γ is invalid.
[0134] The proxy identification algorithm is PIde(pk) i ,γ).
[0135] Among them, the Proxy Identification Algorithm PIde is an improvement and optimization of the Proxy Identification Algorithm PIde in the Elliptic Curve Signature Algorithm.
[0136] The Proxy Identification Algorithm (PIde) in elliptic curve signature algorithms takes a valid proxy signature as input and outputs a proxy identifier (id). j Or ⊥;
[0137] The input parameters of the proxy identification algorithm PIde are the public key of the principal i and the proxy signature γ, and the output is the identity identifier of the proxy j.
[0138] The identity of proxy j, which is generated by proxy identification to generate proxy signature γ, is determined by executing the proxy identification algorithm PIde(pk). i ,γ) includes:
[0139] If the analysis γ = id j ||pk j If ||ω||τ||β fails, return ⊥;
[0140] If Ver(pk) i ,0||pk i ||id j ||pk j If ||ω,τ)=0, then return ⊥;
[0141] Otherwise, return the identity identifier id of the authorized agent j. j .
[0142] Among them, the Ver algorithm is an improvement and optimization of the Ver algorithm in DS=(ParGen,KeyGen,Sig,Ver) of the elliptic curve signature algorithm.
[0143] If the identity identifier of agent j output by the agent identification algorithm matches the identity identifier of authorized agent j, the identification is successful, and the identity identifier id of authorized agent j is returned. j .
[0144] The purpose of this section is to identify whether the identity identifier of the generated proxy signature γ is consistent with the identity identifier of the authorized proxy j.
[0145] The main components of the Power of Attraction (PSA) certificate aggregation proxy signature method in this invention include: key generation, signature, verification of signature delegation validity, proxy delegation, proxy signature, proxy verification, and proxy identification.
[0146] The correctness verification of the PSA (Power Assignment Synthesis) method for token aggregation in this invention is easily proven by the correctness of DS = (ParGen, KeyGen, Sig, Ver) in the elliptic curve signature algorithm:
[0147] When τ = Sig(sk) i ,0||pk i ||id j ||pk j ||ω) and β=Sig(sk j ,1||pk i ||id j ||pk j When ||ω||τ||mess):
[0148] Ver(pk i ,0||pk i ||id j ||pk j ||ω,τ)=1;
[0149] Ver(pk j ,1||pk i ||id j ||pk j ||ω||τ||mess,β)=1.
[0150] In this invention, the correctness verification of the PSA (Power Assignment Algorithm) method for token aggregation is proved by the correctness of the digital signature algorithm DS = (ParGen, KeyGen, Sig, Ver).
[0151] Specifically: In the Power of Attorney Signature (PSA) method for warrant aggregation, the digital signature is divided into two parts: one part is generated by the principal i, and the other part is generated by the authorized agent j, as follows:
[0152] (1) The digital signature of principal i is τ = Sig(sk i ,0||pk i||id j ||pk j ||ω), indicating that the principal i authorizes the authorized agent j to sign on behalf of the principal;
[0153] (2) The signature of the authorized agent j is β = Sig(sk j ,1||pk i ||id j ||pk j ||ω||τ||mess), indicating that the authorized agent j signs the message.
[0154] The correctness verification of the PSA (Power-Only Signature) method for warrant aggregation is performed through the following two steps:
[0155] (1) Verify the validity of the delegation by the delegator i: Verify whether the signature generated by the delegator is valid, through Ver(pk i ,0||pk i ||id j ||pk j ||ω,τ)=1, ensuring that the entrustment by the entrustor i is valid;
[0156] (2) Verify the validity of the signature generated by proxy j: Verify that the signature generated by the proxy is valid by Ver(pk) j ,1||pk i ||id j ||pk j ||ω||τ||mess,β)=1, ensuring the proxy signature is valid.
[0157] If both steps pass, i.e., the verification result is 1, then the PSA certificate aggregation proxy signature method in this invention can be concluded to be correct.
[0158] In summary, the secure and efficient certificate aggregation proxy signature method of this invention has the following beneficial effects:
[0159] 1. The certificate aggregation proxy signature algorithm in this invention is a combination of partial delegation and authorization certificate delegation, providing a method for proxy signature with protection of partial delegation, and simultaneously aggregating the proxy signatures of authorization certificates and messages, thereby enhancing the security of proxy signature;
[0160] 2. In this invention, the proxy signature algorithm PSig only calls the ordinary digital signature algorithm DS's Sig once, and achieves efficient signature generation through a single dot product operation of Y = y·G;
[0161] 3. The proxy signature verification algorithm PVer of this invention calls the Ver of the ordinary digital signature algorithm DS twice, and Ver(pk) i ,0||pk i||id j ||pk j The calculation of ||ω,τ) is independent of the message and can be pre-calculated when necessary. This reduces the computational load during signature verification and improves verification efficiency.
[0162] 4. Partially delegated proxy signature algorithms are more secure than fully delegated ones, and usually have an advantage in processing speed and efficiency.
[0163] 5. The proxy signature algorithm through the authorization certificate can clearly specify the restrictions and validity period of the signed document in the authorization certificate, without the need for an additional proxy revocation agreement, thereby simplifying the processing process, improving processing speed and efficiency.
[0164] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.
Claims
1. A secure and efficient method for aggregated proxy signature of certificates, characterized in that, The steps include: Generate the public and private keys for principal i and authorized agent j respectively, and obtain the identity identifier of authorized agent j; The principal i uses its private key to generate a digital signature using its public key, a signable message space, and the public key and identity identifier of the authorized agent j; the digital signature and the signable message space constitute the delegation information. Agent j receives the delegation information and verifies the validity of the delegation information based on the public key of the delegator i. If valid, agent j calculates and obtains the agent signing private key and uses the agent signing private key to sign the message. After the proxy signature is completed, the verifier verifies whether the proxy signature is a valid proxy signature for the message by proxy j; if so, the proxy signature is valid; otherwise, the proxy signature is invalid.
2. The method according to claim 1, characterized in that, The public and private keys of the principal i and authorized agent j are generated respectively using the key generation algorithm KeyGen(pp); including: The common parameters pp are generated using the ParGen algorithm for generating common parameters of elliptic curves, where pp ← ParGen(1). λ ), where λ is the safety parameter; Based on the public parameter pp, the private key sk of the delegator i is generated using the KeyGen key generation algorithm. i and the private key sk of the authorized agent j j ; The private key sk of the principal i i The private key sk of the authorized agent j j By performing dot products with the base point G of the elliptic curve, the public key pk of the delegator i can be obtained. i PK with the public key of authorized agent j j .
3. The method according to claim 2, characterized in that, The principal i uses its public key, the signable message space ω, and the public key and identity identifier id of the authorized agent j. j Generate message 0||pk i ||id j ||pk j ||ω, and use the private key sk i Sign the message to obtain the digital signature τ = Sig(sk) i ,0||pk i ||id j ||pk j ||ω).
4. The method according to claim 3, characterized in that, The agent j receives (τ,ω) and verifies the validity of the delegation information based on the public key of the delegator i; If Ver(pk) i ,0||pk i ||id j ||pk j If ||ω,τ)|p holds true, then it is valid, and based on the proxy j's own private key sk. j Calculate and obtain the proxy signing private key skp, where skp = (pk i ||id j ||pk j ||ω||τ,sk j Otherwise, the entrustment will be terminated.
5. The method according to claim 4, characterized in that, Based on the proxy signature private key skp, the proxy j uses a proxy signature algorithm to perform proxy signature on the message; The proxy signature algorithm is PSig(skp,mess), where mess is the message.
6. The method according to claim 5, characterized in that, Before performing the proxy signature, it is also included to determine whether the message is within the signable message space. If so, the proxy signature is performed to obtain the proxy signature γ: γ = id j ||pk j ||ω||τ||β; where β = Sig(sk j , 1||pk i ||id j ||pk j ||ω||τ||mess).
7. The method according to claim 6, characterized in that, The verifier uses a proxy signature algorithm to verify whether the proxy signature γ is a valid proxy signature for the message by the authorized proxy j; the proxy signature verification algorithm is PVer(pk) i The proxy identification algorithm is PIde(pk), ,mess,γ). i ,γ).
8. The method according to claim 7, characterized in that, The verification of signatures includes: If γ = ⊥, then return 0; where ⊥ is an error symbol. If parsing the proxy signature γ = id j ||pk j If ||ω||τ||β fails, return 0; like Then it returns 0; If Ver(pk) i ,0||pk i ||id j ||pk j If ||ω,τ)=0, then return 0; If Ver(pk) j ,1||pk i ||id j ||pk j ||ω||τ||mess,β)=0, then 0 is returned; Otherwise, return 1; Where 1 represents a valid proxy signature and 0 represents an invalid proxy signature.
9. The method according to claim 8, characterized in that, Based on the validity of the proxy signature, the verifier, using the public key of the principal i, employs a proxy identification algorithm to identify the identity of the proxy that generated the proxy signature γ, and determines whether the obtained proxy identity identifier matches the identity identifier id of the authorized proxy j. j If they match, then the agent is the authorized agent j, and the agent signature is valid; otherwise, the agent signature γ is invalid. The proxy identification algorithm is PIde(pk) i ,γ).
10. The method according to claim 9, characterized in that, The identity of proxy j, which is generated by proxy identification to generate proxy signature γ, is determined by executing the proxy identification algorithm PIde(pk). i ,γ) includes: If the analysis γ = id j ||pk j If ||ω||τ||β fails, return ⊥; If Ver(pk) i ,0||pk i ||id j ||pk j If ||ω,τ)=0, then return ⊥; Otherwise, return the identity identifier id of the authorized agent j. j .