Identity-based signature method and system, electronic equipment and storage medium
By using the Gadget sampling algorithm on the lattice and the Fiat-Shamir transform of discrete Gaussian convolution in the identity-based digital signature method, the problems of complex private key generation and large signature storage space in the prior art are solved, and more efficient signature generation and verification are achieved.
Patent Information
- Application Number
- CN202511268056.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-05
- Publication Date
- 2025-11-18
AI Technical Summary
Existing identity-based digital signature methods involve complex computational processes and large spatial dimensions during the private key extraction and signature generation stages, making them difficult to effectively resist quantum computing attacks.
The user's private key is generated using a compact Gadget sampling algorithm on the lattice, and the signature is generated using the Fiat-Shamir transform based on discrete Gaussian convolution, which reduces the computational complexity and storage space of the signature.
It effectively reduces the complexity of user private key generation and signature calculation, reduces storage space requirements, improves security and adaptability, and is suitable for different security levels.
Smart Images

Figure CN120979676A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of information security technology, and specifically relates to an identity-based signature method, system, electronic device, and storage medium. Background Technology
[0002] Shor's quantum algorithm can completely break public-key cryptography algorithms such as RSA and ECDSA, which are based on large number factorization, discrete logarithms, and elliptic curve group structures, in polynomial time. Quantum computers based on ion traps and superconductivity are developing rapidly, and in 2019, Google claimed to have achieved "quantum supremacy." Therefore, designing quantum-resistant "post-quantum cryptography" algorithms is urgent. In 2016, the National Institute of Standards and Technology (NIST) launched a competition for post-quantum public-key cryptography algorithm standards; the EU's "Horizon 2020" program also supports post-quantum-resistant cryptography research. Post-quantum public-key cryptography mainly includes five technical directions: lattice-based, encoding, multivariable equations, curve homology, and hash signatures. Among them, lattice cryptography has the best overall performance. Identity-based digital signatures can sign any message using the user's identity as the public key, with the private key generated by a key generation center. Since it does not require certificate verification based on traditional public-key infrastructure to confirm the legitimacy of the public key, it effectively solves the overhead associated with certificate management. Currently, identity-based digital signature methods on lattices use preimage sampling algorithms in both the private key extraction and signature generation stages, resulting in complex computational processes and large space dimensions. Summary of the Invention
[0003] The main objective of this invention is to provide an identity-based signature method, system, computer device, and storage medium. By using a compact Gadget sampling algorithm based on a lattice to reduce the complexity of generating user private keys, and by using the Fiat-Shamir transform based on discrete Gaussian convolution to generate signatures, the computational complexity and storage space of signatures are effectively reduced.
[0004] To achieve the above objectives, the technical solution adopted by the present invention is as follows:
[0005] In a first aspect, the present invention discloses an identity-based signature method, comprising the steps of:
[0006] Step 1: Initialize the key generation center to generate the master public key mpk and the master private key msk;
[0007] Step 2: For any user identity id∈{0,1} * The key generation center uses the master private key msk to generate the user ID's private key sk. id ;
[0008] Step 3: Use the master public key mpk, user ID, and private key sk idGenerate a signature for the message μ∈{0,1};
[0009] Step 4: Verify the signature using the master public key mpk and the user's identity ID.
[0010] Preferably, step 1 specifically includes the following steps:
[0011] Step 1.1: Let the matrix Among them I d Represents a polynomial ring The d-order identity matrix on Represents a polynomial ring A ring modulo Q, where d is a positive integer, and Q = p·q represents the modulus, where p and q are two positive integers. Represents a polynomial ring A d×2d matrix on the surface, Represents a polynomial ring A d-order square matrix on which each element obeys A uniform random distribution on;
[0012] Step 1.2: Let b represent an integer, calculate... Construct matrix F = in Let f represent the tensor product. t =p·[1,b,…,b w-1 ] represents the transpose of column vector f, where each integer is considered an element of the polynomial ring R; a trapdoor matrix is chosen. Each element follows a central binomial distribution with parameter η. Let the check matrix be... Where the matrix m = (2 + w)·d;
[0013] Step 1.3: Let the matrix Where s1 and s2 are two positive real numbers; the covariance matrix of the perturbation vector p is defined as
[0014]
[0015] Where σ represents the smoothing parameter of G-lattice;
[0016] Judgment∑ p Is it a positive definite matrix? If ∑ p If positive definite, proceed to step 1.4. If Σ p If the result is not positive definite, return to repeat step 1.2 until Σ. p It is a positive definite matrix;
[0017] Step 1.4: Let the matrix Output the master public key mpk=A' and the master private key msk=R.
[0018] Preferably, step 2 specifically includes the following steps:
[0019] Step 2.1: Calculate based on user ID in This represents a collision-resistant hash function. Represents a polynomial ring A column vector of dimension 2;
[0020] Step 2.2: Use the master private key msk to sample the perturbation vector. in Represents an m-dimensional vector space Above Σ p The covariance matrix is a discrete Gaussian distribution. Represents the Gaussian function. Gaussian function In m-dimensional vector space Summation on;
[0021] Step 2.3: Let g t =[1,b,…,b w-1 ], Calculate the target vector in Representing the nearest integer, this operation naturally extends to each coefficient of the polynomial ring element, and then to the coset of the G-lattice. Based on discrete Gaussian distribution The target vector x is obtained by sampling, where σ = b·r, and r represents the m-dimensional integer vector space. Smoothing parameters;
[0022] Step 2.4: Calculation Discarding the first d polynomials of z, we obtain a polynomial vector.
[0023] Step 2.5: Output z' as the private key sk of the user ID. id .
[0024] Preferably, step 3 specifically includes the following steps:
[0025] Step 3.1: Calculation Let y = (z0, z');
[0026] Step 3.2: Sample the perturbation vector in and Given two positive real numbers, Represents an m+1 dimensional vector space above Let be a discrete Gaussian distribution of the covariance matrix, where Represents the Gaussian function. Gaussian function In m+1 dimensional vector space Summation on;
[0027] Step 3.3: Let Where vector Define matrix Calculate vectors Order, among which Represents a collision-resistant hash function, sampling ring elements. in Indicates definition in the ring Above, a discrete Gaussian distribution with r as the Gaussian parameter and centered at -c / 2;
[0028] Step 3.4: Calculation judge The function checks whether the condition is true, where γ is a positive real number. If true, proceed to step 3.5; otherwise, return to step 3.2 and repeat until...
[0029] Step 3.5: Output As a signature of message μ.
[0030] Preferably, step 4 specifically includes the following steps:
[0031] Step 4.1: Calculation
[0032] Step 4.2: If and Outputting 1 indicates that the signature has passed verification; otherwise, outputting 0 indicates that the signature has failed verification.
[0033] Secondly, this invention discloses an identity-based digital signature system, which includes the following modules:
[0034] The initial generation module is used for initializing the key generation center and generating the master public key mpk and the master private key msk.
[0035] The private key generation module is used to generate private keys for any user identity id∈{0,1}. * The key generation center uses the master private key msk to generate the user ID's private key sk. id ;
[0036] The signature module is used to utilize the master public key mpk, the user identity ID, and the private key sk. id Generate a signature for the message μ∈{0,1};
[0037] The verification module is used to verify the signature using the master public key mpk and the user identity ID.
[0038] Thirdly, the present invention discloses a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the method described above.
[0039] Fourthly, the present invention discloses a computer-readable storage medium having a computer program stored thereon, which is executed by a processor to implement the method described above.
[0040] Compared with the prior art, the identity-based signature method, system, electronic device, and storage medium of the present invention have at least the following beneficial effects:
[0041] 1. In this invention, the key generation center uses a preimage sampling method based on ellipsoidal discrete Gaussian convolution and Gadget techniques on a modular grid during the calculation of the user's private key. This introduces less noise, resulting in a smaller maximum singular value for the user's private key and reducing the parameter size of the signature algorithm. Simultaneously, the modular grid structure provides more flexible parameter selection, suitable for different security levels.
[0042] 2. In this invention, signature generation first uses ellipsoidal discrete Gaussian convolution on a lattice to obtain an authentication protocol (implicit in the signature process), and then obtains the signature through Fiat-Shamir transform. Based on the above techniques, a more compact signature can be obtained.
[0043] 3. This invention uses preimage sampling to generate a private key for the user and Fiat-Shamir transform to generate a signature. Compared to other methods that use trapdoor derivation to generate a private key and preimage sampling to generate a signature, this invention can significantly reduce complexity and parameter size. Furthermore, compared to other methods that use preimage sampling to generate a private key and Fiat-Shamir transform to generate a signature, this invention combines techniques such as modularity, ellipsoidal discrete Gaussian convolution, and Gadget sampling, which can effectively reduce parameter size and implementation complexity. Attached Figure Description
[0044] Figure 1 This is a flowchart illustrating the identity-based signature method of the present invention;
[0045] Figure 2 This is a schematic diagram of the identity-based signature system of the present invention;
[0046] Figure 3 This is a circuit module connection diagram of the computer device of the present invention.
[0047] In the diagram: 101, Initial generation module; 102, Private key generation module; 103, Signature module; 104, Verification module.
[0048] 300. Bus; 301. Receiver; 302. Processor; 303. Transmitter; 304. Memory; 306. Bus interface. Detailed Implementation
[0049] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0050] Example 1
[0051] This embodiment combines Figure 1 The flowchart illustrates how the identity-based signature method is used in practical applications. In this demonstration scenario, after initialization, the key generation center generates a master public key and a master private key, and then uses the master private key to generate a private key for the signer S. The signer S uses the master public key, its own identity ID, and the private key to sign the message μ. Finally, the verifier V uses the master public key and the signer S's identity ID to verify the message μ and its signature. The specific flow of this signature method is as follows:
[0052] Step 1: After initialization, the key generation center generates the master public key mpk and the master private key msk.
[0053] This step specifically includes:
[0054] Step 1.1: Let the matrix Where I d Represents a polynomial ring The d-order identity matrix on Represents a polynomial ring A ring modulo Q, where d is a positive integer, and Q = p·q represents the modulus, where p and q are two positive integers. Represents a polynomial ring A d×2d matrix on the surface, Represents a polynomial ring A d-order square matrix on which each element obeys A uniform random distribution on;
[0055] Step 1.2: Let b represent an integer, calculate... Constructing a matrix in Let f represent the tensor product. t =p·[1,b,…,b w-1 ] represents the transpose of column vector f, where each integer is considered as a polynomial ring. Elements on the matrix. Select the trapdoor matrix. Each element follows a central binomial distribution with parameter η. Let the check matrix be... Where the matrix
[0056] In this step This embodies the fault-tolerant learning (LWE) assumption and ensures the security of the master private key;
[0057] Step 1.3: Let the matrix Let represent the covariance matrix of the approximate preimage, where Given two positive real numbers, compared to s 2 ·I (2+w)d The covariance matrix is in the form of a spherical Gaussian, where ∑ reflects the characteristics of the ellipsoidal Gaussian distribution. Since s1≈s and s2<<s in this invention, the size of the preimage corresponding to s2 and the Euclidean norm can be effectively reduced, thereby reducing the size and improving security.
[0058] make
[0059]
[0060] Let represent the covariance matrix of the perturbation vector p, where σ represents the smoothing parameter of the G-lattice. The correctness requirement of the sampling algorithm is ∑ p It is a positive definite matrix, if Σ p If positive definite, proceed to step 1.4. If Σ p If the result is not positive definite, return to repeat step 1.2 until Σ. p Since it is a positive definite matrix, the positive definiteness of the matrix can be determined using the standard Cholesky decomposition.
[0061] Step 1.4: Let the matrix Output the master public key mpk = A' and the master private key msk = R, where R is the trapdoor matrix from step 1.2.
[0062] Step 2: For any user identity id∈{0,1} * The key generation center uses the master private key msk to generate the private key sk based on the identity identifier id of the signer S. id Specifically, the steps include the following:
[0063] Step 2.1: Calculate based on user ID in This represents a collision-resistant hash function. Represents a polynomial ring d-dimensional column vectors on;
[0064] Step 2.2: Sample the perturbation vector using the master private key msk in Represents an m-dimensional vector space Above Σ p The covariance matrix is a discrete Gaussian distribution. Represents the Gaussian function. Gaussian function In m-dimensional vector space Summation over [amount]. The specific sampling method for this step is as follows:
[0065] Step 2.2.1: Sampling That is to With Gaussian parameters and centered at 0, Upsample wd·n integers following a discrete Gaussian distribution to form a vector p2. This sampling process can be accomplished using industry-standard algorithms (such as rejection sampling), which will not be elaborated here;
[0066] Step 2.2.2: Let
[0067] Step 2.2.3: Loop through i = 2d-1 to 0, and let First, using polynomial f as the Gaussian parameter and polynomial c' as the center, in the polynomial ring... Discrete Gaussian sampling is performed on the polynomial p to obtain the polynomial p i This sampling process can be completed using industry-standard algorithms; then c is updated. i =c i +f -1 Y(p i -c'), Σ2=Xf -1 YY t ;
[0068] Step 2.2.4: Convert the above 2d polynomials p i The combination forms a vector p1 = (p0, ..., p 2d-1 Let p = (p1, p2).
[0069] Step 2.3: Let Calculate the target vector in Representing the nearest integer, this operation naturally extends to each coefficient of the polynomial ring element, and then to the coset of the G-lattice. x = v mod q} follows a discrete Gaussian distribution The target vector x is obtained by sampling, where σ = b·r, and r represents the m-dimensional integer vector space. Smoothing parameters;
[0070] The specific steps of G-lattic upsampling are as follows:
[0071] (1) Let
[0072] (2) For i = 0, ..., d-1, the sampling vector Satisfy f·x i =v i mod Q, the specific steps are as follows:
[0073] (2.1) For j = 1, ..., w, sampling And update v i The value is
[0074] (2.2) Let
[0075] (3) Let x = (x0, ..., x d-1 ).
[0076] Step 2.4: Calculation Discarding the first d polynomials of z, we obtain a polynomial vector. Discarding d polynomials can reduce the user size, and the discarded parts can be recovered during signing;
[0077] Step 2.5: Output z' as the private key sk of the user ID. id .
[0078] Step 3: The signer S uses the master public key mpk, the user's identity ID, and the private key sk id Generate a signature for message μ∈{0,1}:
[0079] Step 3.1: Calculation Let y = (z0, z');
[0080] Step 3.2: Sample the perturbation vector in and Let ⊕ be two positive real numbers, and ⊕ indicates that the matrices are concatenated diagonally. Represents an m+1 dimensional vector space above Let be a discrete Gaussian distribution of the covariance matrix, where Represents the Gaussian function. Gaussian function In m+1 dimensional vector space Summation over [amount]. The specific sampling method for this step is as follows:
[0081] Step 3.2.1: Sampling That is to With Gaussian parameters and centered at 0, Upsample n integers that follow a discrete Gaussian distribution to form a vector p'2. This sampling process can be completed using industry-standard algorithms (such as rejection sampling).
[0082] Step 3.2.2: Let
[0083] Step 3.2.3: Loop through i = (2 + w)d - 1 to 0, and let c' = (c' i ,c”), First, using polynomial f' as the Gaussian parameter and polynomial c” as the center, in the polynomial ring... Discrete Gaussian sampling is performed on the polynomial p' to obtain the polynomial. i This sampling process can be completed using industry-standard algorithms; then c' is updated. i =c' i +f' -1 Y'(p' i -c”), Σ'2=X'-f' -1 Y'Y' t ;
[0084] Step 3.2.4: Convert the above (2+w)d polynomials p' i The combination forms a vector p'1 = (p'0, ..., p' 2d-1 Let p = (p'1, p'2).
[0085] Step 3.3: Let Where vector Define matrix Calculate vectors make in Represents a collision-resistant hash function, sampling ring elements. in Indicates definition in the ring The above is a discrete Gaussian distribution with r as the Gaussian parameter and centered at -c / 2.
[0086] Step 3.4: Calculation judge Check if the condition is true, where γ is a positive real number. If true, proceed to step 3.5; otherwise, return to and repeat step 3.2 until...
[0087] Step 3.5: Output As a signature of message μ.
[0088] Step 4: Verifier V verifies the signature using the master public key mpk and the signer S's identity ID:
[0089] Step 4.1: Calculation
[0090] Step 4.2: If and Outputting 1 indicates that the signature has passed verification; otherwise, outputting 0 indicates that the signature has failed verification.
[0091] Compared with existing technologies, the technical solution of the present invention has the following advantages:
[0092] (1) In this invention, the key generation center uses a preimage sampling method based on discrete Gaussian convolution and Gadget techniques on a lattice to calculate the user's private key. Each component of the introduced noise follows a uniform distribution over the interval [-p / 2, p / 2), which has a smaller variance than a discrete Gaussian with the same parameter size, resulting in less noise. This makes the maximum singular value of the user's private key z' smaller, reducing the parameter size of the signature algorithm. At the same time, a more general lattice structure is used, and more flexible parameter selection is achieved by adjusting the rank d of the lattice, making it suitable for different security levels.
[0093] (2) This invention uses ellipsoidal Gaussian sampling technology in both key generation and signature generation processes, which is reflected in the covariance matrix Σ of the private key approximation preimage and the covariance matrix of the signature approximation preimage. By reducing the Gaussian parameter s2 in Σ and Gaussian parameters in This reduces the overall size of the Gaussian parameter, thereby reducing the storage space and Euclidean norm of the user's private key and signature, thus reducing the parameter size and improving security.
[0094] (3) The key technology of this invention can greatly reduce the parameter scale of preimage sampling, better combine preimage sampling and Fiat-Shamir technology, and can be applied to other lattice-based advanced cryptographic applications, such as attribute-based encryption and attribute-based signatures.
[0095] Example 2
[0096] See Figure 2 For Embodiment 1, this embodiment discloses an identity-based signature method, including the following modules:
[0097] Initial generation module 101 is used to initialize the key generation center and generate the master public key mpk and the master private key msk.
[0098] Private key generation module 102 is used by the key generation center to generate user identities id∈{0,1} using the master private key msk. * Generate private key sk id ;
[0099] Signature module 103 is used to utilize the master public key mpk, user identity ID, and private key sk id Generate a signature for the message μ∈{0,1};
[0100] Verification module 104 verifies the signature using the master public key mpk and the user identity ID.
[0101] The above four steps are used to execute the four implementation steps of Example 1, respectively.
[0102] The identity-based signature system in this embodiment is used to execute and implement the identity-based signature method of Embodiment 1, so this embodiment will not elaborate on it.
[0103] Example 3
[0104] See Figure 3 This embodiment discloses a computer device, which includes a memory 304, a processor 302, and a computer program stored in the memory and executable on the processor. When the processor 302 executes the program, it implements the steps of the method described in Embodiment 1.
[0105] Furthermore, in Figure 3In this embodiment, a bus architecture (represented by bus 300) is also included. Bus 300 may include any number of interconnected buses and bridges, linking various circuits including one or more processors represented by processor 302 and memory represented by memory 304. Bus 300 may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. Bus interface 306 provides an interface between bus 300 and receiver 301 and transmitter 303. Receiver 301 and transmitter 303 may be the same element, i.e., a transceiver, providing a unit for communicating with various other devices over a transmission medium. Processor 302 is responsible for managing bus 300 and general processing, while memory 304 may be used to store data used by processor 302 during operation.
[0106] Example 4
[0107] This embodiment provides a computer-readable storage medium having a computer program stored thereon, which is executed by a processor to implement the method described in Embodiment 1.
[0108] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0109] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0110] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0111] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0112] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention.
[0113] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. An identity-based signature method, characterized in that, Including the following steps: Step 1: Initialize the key generation center to generate the master public key mpk and the master private key msk; Step 2: For any user identity id∈{0,1} * The key generation center uses the master private key msk to generate the user ID's private key sk. id ; Step 3: Use the master public key mpk, user ID, and private key sk id Generate a signature for the message μ∈{0,1}; Step 4: Verify the signature using the master public key mpk and the user's identity ID.
2. The identity-based signature method as described in claim 1, characterized in that, Step 1 specifically includes the following steps: Step 1.1: Let the matrix Among them I d Represents a polynomial ring The d-order identity matrix on Represents a polynomial ring A ring modulo Q, where d is a positive integer, and Q = p·q represents the modulus, where p and q are two positive integers. Represents a polynomial ring A d×2d matrix on the surface, Represents a polynomial ring A d-order square matrix on which each element obeys A uniform random distribution on; Step 1.2: Let b represent an integer, calculate... Constructing a matrix in Let f represent the tensor product. t =p·[1,b,…,b w-1 ] represents the transpose of column vector f, where each integer is considered as a polynomial ring. Elements on; Selecting the trapdoor matrix Each element follows a central binomial distribution with parameter η. Let the check matrix be... Where the matrix m = (2 + w)·d; Step 1.3: Let the matrix Where s1 and s2 are two positive real numbers; the covariance matrix of the perturbation vector p is defined as Where σ represents the smoothing parameter of G-lattice; Judgment∑ p Is it a positive definite matrix? If ∑ p If positive definite, proceed to step 1.
4. If Σ p If the result is not positive definite, return to and repeat step 1.2 until Σ. p It is a positive definite matrix; Step 1.4: Let the matrix Output the master public key mpk=A' and the master private key msk=R.
3. The identity-based signature method as described in claim 1, characterized in that, Step 2 specifically includes the following steps: Step 2.1: Calculate based on user ID in This represents a collision-resistant hash function. Represents a polynomial ring d-dimensional column vectors on; Step 2.2: Use the master private key msk to sample the perturbation vector. in Represents an m-dimensional vector space Above Σ p The covariance matrix is a discrete Gaussian distribution. Represents the Gaussian function. Gaussian function In m-dimensional vector space Summation on; Step 2.3: Let g t =[1,b,…,b w-1 ], Calculate the target vector in Representing the nearest integer, this operation naturally extends to each coefficient of the polynomial ring element, and then to the coset of the G-lattice. Based on discrete Gaussian distribution The target vector x is obtained by sampling, where σ = b·r, and r represents the m-dimensional integer vector space. Smoothing parameters; Step 2.4: Calculation Discarding the first d polynomials of z, we obtain a polynomial vector. Step 2.5: Output z' as the private key sk of the user ID. id .
4. The identity-based signature method as described in claim 1, characterized in that, Step 3 specifically includes the following steps: Step 3.1: Calculation Let y = (z0, z'); Step 3.2: Sample the perturbation vector in and Given two positive real numbers, Represents an m+1 dimensional vector space above Let be a discrete Gaussian distribution of the covariance matrix, where Represents the Gaussian function. Gaussian function In m+1 dimensional vector space Summation on; Step 3.3: Let Where vector Define matrix Calculate vectors make in Represents a collision-resistant hash function, sampling ring elements. in Indicates definition in the ring Above, a discrete Gaussian distribution with r as the Gaussian parameter and centered at -c / 2; Step 3.4: Calculation judge The function checks whether the condition is true, where γ is a positive real number. If true, proceed to step 3.5; otherwise, return to step 3.2 and repeat until... Step 3.5: Output As a signature of message μ.
5. The identity-based signature method as described in claim 1, characterized in that, Step 4 specifically includes the following steps: Step 4.1: Calculation Step 4.2: If and Outputting 1 indicates that the signature has passed verification; otherwise, outputting 0 indicates that the signature has failed verification.
6. An identity-based signature system, characterized in that, include: The initial generation module is used for initializing the key generation center and generating the master public key mpk and the master private key msk. The private key generation module is used to generate private keys for any user identity id∈{0,1}. * The key generation center uses the master private key msk to generate the user ID's private key sk. id ; The signature module is used to utilize the master public key mpk, the user identity ID, and the private key sk. id Generate a signature for the message μ∈{0,1}; The verification module is used to verify the signature using the master public key mpk and the user identity ID.
7. A computer device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the steps of the method as described in any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, It stores a computer program that is executed by a processor to implement the method as described in any one of claims 1-5.