Attribute-based Verifiable Signature Scheme with Strongly Designated Verifiers and Its System

By designing a strong attribute base for a strongly designated verifier, the signature can be purified, which solves the problem that signatures are maliciously spread and sensitive information cannot be hidden, and the signature is specified verification and purification is realized, which improves the security of data authentication and privacy protection.

CN115189889BActive Publication Date: 2025-07-25FUJIAN NORMAL UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210766035.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-01
Publication Date
2025-07-25
Estimated Expiration
2042-07-01

AI Technical Summary

Technical Problem

The existing attribute-based signature method cannot implement the specified verification of signatures and the purification of sensitive information, resulting in the signatures that may be maliciously propagated and the sensitive information cannot be hidden.

Method used

Design an attribute-based purifying signature method with a strongly designated verifier. Through the coordinated work of the attribute authorization end, the signature end, the purification end and the verification end, the designated verification of signatures and the purification of sensitive information are realized.

Benefits of technology

Effectively prevent the signature from being maliciously spread, and can modify the sensitive information in the signature to generate a purified signature, ensuring the privacy protection and data security of the signature.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115189889B_ABST
    Figure CN115189889B_ABST
Patent Text Reader

Abstract

The present invention relates to an attribute-based verifiable sanitizable signature method and system with a strong designated verifier. The method includes the following steps: The attribute authorization end inputs security parameters, outputs a master key and public parameters, and combines the attribute sets of the signature end and the verification end to output the keys of the signature end and the verification end; The signature end inputs the public parameters, a message, the signature end key, and the attribute sets of the signature end, the sanitization end, and the verification end, and outputs a signature and a set of secret values; The sanitization end inputs a set of sanitizable message indices, a message, public parameters, a signature, a set of secret values, and the attribute sets of the signature end, the sanitization end, and the verification end, and outputs a sanitized message and a sanitized signature; The verification end inputs the public parameters, the sanitized message, the sanitized signature, the verification end key, and the attribute sets of the signature end, the sanitization end, and the verification end, verifies the validity of the signature, and outputs a simulated signature. The method and system are beneficial to avoiding malicious dissemination of signatures and modifying sensitive information in the signatures to generate sanitized signatures.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of Internet security technology, and particularly relates to an attribute-based purifiable signature method and system with a strong designated verifier. Background Art

[0002] Internet technology has penetrated all walks of life and has been widely applied in electronic medical care, e-government, and e-finance. In these application scenarios, physical devices inevitably collect and analyze user data, including some sensitive data information such as the user's real identity, medical health status of patients, and details of personal financial transfers, which inevitably involves the problem of user privacy leakage. Attribute-based signature (ABS) is an important method to solve the above problems, and it plays an important role in privacy protection, access control, and data authentication. However, in the ABS scheme, on the one hand, any verifier can verify the signature generated by the signer. When it is necessary to avoid the malicious spread of the signature, the traditional ABS scheme cannot enable the signer to designate the verifier. On the other hand, when it is necessary to modify the sensitive information in the signature to hide the sensitive information in the signature, the traditional ABS scheme cannot provide purifiability. Summary of the Invention

[0003] The purpose of the present invention is to provide an attribute-based purifiable signature method and system with a strong designated verifier, which is beneficial to avoiding the malicious spread of the signature and modifying the sensitive information in the signature to generate a purified signature.

[0004] To achieve the above purpose, the technical solution adopted by the present invention is: an attribute-based purifiable signature method with a strong designated verifier, including the following steps:

[0005] Step S1: The attribute authorization end inputs a security parameter λ and outputs a master secret key msk and public parameters params;

[0006] Step S2: The attribute authorization end inputs the public parameters params, the master secret key msk, the signer attribute set ω a and the verifier attribute set ω v , and outputs the signer key and the verifier key

[0007] Step S3: The signer inputs the public parameters params, the message M, the signer attribute set ω a and the key the purifier attribute set ω b and the verifier attribute set ω v , and outputs a signature σ v ; the signer simultaneously generates a set of secret values SI and sends them to the purifier;

[0008] Step S4: The purification end inputs the set I of message indexes to be purified, message M, public parameters params, signature σ, signature end attribute set ω, purification end attribute set ω, verification end attribute set ω, and set SI of secret values, and outputs the purified message M' and the purified signature σ'. N , message M, public parameters params, signature σ v , signature end attribute set ω a , purification end attribute set ω b , verification end attribute set ω v and set SI of secret values, and outputs the purified message M' and the purified signature σ' v ;

[0009] Step S5: The verification end inputs the public parameters params, the purified message M', the purified signature σ', the verification end key, signature end attribute set ω, verification end attribute set ω, and purification end attribute set ω; if σ' is a valid signature for M', output accept; otherwise, output reject; v , verification end key , signature end attribute set ω a , verification end attribute set ω v and purification end attribute set ω b ; if σ' v is a valid signature for M', output accept; otherwise, output reject;

[0010] Step S6: The verification end inputs the public parameters params, the purified message M', signature end attribute set ω, verification end attribute set ω, purification end attribute set ω, and verification end key, and outputs the simulated signature a , signature end attribute set ω v , verification end attribute set ω b , purification end attribute set ω and verification end key, and outputs the simulated signature

[0011] Furthermore, the specific steps of the step S1 include the following steps:

[0012] Step S11: The attribute authorization end inputs the security parameter λ, generates two p-order bilinear multiplicative cyclic groups G1 and G2, where p is a large prime number, |p| = λ; e: G1×G1→G2 is a bilinear mapping; the attribute authorization end selects a default attribute set where Z p ={0, 1, …, p - 1};

[0013] Step S12: The attribute authorization end defines the threshold access policy where k∈{a, b}, is defined as follows: if then otherwise it is False; set the access policy that the signature end needs to satisfy as and the access policy that the verification end needs to satisfy as

[0014] Step S13: The attribute authorization end randomly selects a generator g of G1, randomly selects and calculates g1 = gα ;

[0015] Step S14: The attribute authorization end randomly selects \(g_2\in G_1\) and a vector \(H=(h_1,h_2,\cdots,h\) n+d-1 ) where \(h\) i \(\in G_1, 1\leq i\leq n + d - 1\), where \(n\) represents the length of the message;

[0016] Step S15: The attribute authorization end randomly selects \(u'\in G_1\) and a vector \(U=(u_1,u_2,\cdots,u\) n ) where \(u\) i \(\in G_1, 1\leq i\leq n\); randomly selects \(d\) a -1 degree polynomials \(Q\) a (x), \(d\) v -1 degree polynomials \(Q\) v (x), satisfying \(Q\) a (0)=Q v (0)=1;

[0017] Step S16: The attribute authorization end outputs the master secret key \(msk = \alpha\) and the public parameters \(params=(G_1,G_2,e,h,g_1,g_2,u',H,\Omega,U,Q\) a (x),Q v (x)).

[0018] Furthermore, step S2 specifically includes the following steps:

[0019] Step S21: The attribute authorization end inputs the master secret key \(msk = \alpha\), the public parameters \(params=(G_1,G_2,e,g,g_1,g_2,u',H,\Omega,U,Q\) a (x),Q v (x)), the signature end attribute set \(\omega\) a and the verification end attribute set \(\omega\) v , where

[0020] Step S22: The attribute authorization end randomly selects Calculate

[0021] Step S23: The attribute authorization end randomly selects \(d\) a -1 degree polynomials \(q\) a (x), \(d\) v -1 degree polynomials \(q\) v (x), satisfying \(q\) a (0)=q v (0)=\(\beta\) sv ;

[0022] Step S24: For \(i\in\omega\)a , the attribute authorization end randomly selects r i ∈Z p , and calculates the signature end key where Similarly, for j ∈ ω v , the attribute authorization end randomly selects r j ∈Z p , and calculates the verification end key where

[0023] Step S25: The attribute authorization end outputs the signature end key and the verification end key

[0024] Furthermore, the specific steps of the step S3 are as follows:

[0025] Step S31: The signature end inputs the signature end attribute set ω a , the purifier attribute set ω b , and the verification end attribute set ω v , the message M = (m1 m2 … m n ), where, m i ∈ {0, 1}, i ∈ {1, 2, …, n};

[0026] Step S32: The signature end randomly selects satisfying Randomly select satisfying Randomly select r a,i , r v,j , r b,k , r s , r' a,i , r' b,k , r' v,j , r' s ∈Z p , where i ∈ ω a , j ∈ ω v , k ∈ ω b , and calculates σ v = (σ v0 , σ v1 , σ v2 , σ v3 , σ v4 ); The specific steps are as follows:

[0027]

[0028]

[0029]

[0030]

[0031] Step S33: The signing end calculates the secret value where \(i\in I\) N ; Let denote the set of secret values, denote the set of message indices that the signer allows to be purified, where \(1\leq N\leq n\);

[0032] Step S34: The signing end outputs the signature \(\sigma\) v , and sends \(SI\) to the purification end.

[0033] Furthermore, step S4 specifically includes the following steps:

[0034] Step S41: The purification end inputs the set of purifiable message indices \(I\) N , the message \(M\), the signature \(\sigma\) v , the set of secret values \(SI\), the signer attribute set \(\omega\) a , the purifier attribute set \(\omega\) b and the verifier attribute set \(\omega\) v ;

[0035] Step S42: The purification end defines the set of message indices to be purified Let the set \(I1 = \{i\in I:m\) i = 0,m' i = 1\}, I2 = \{i\in I:m\) i = 1,m' i = 0\}, where \(m'\) i represents the bit value of the purified message, \(0\leq i\leq n\); at this time \(M'=(m'0m'1\ldots m' n ) represents the purified message;

[0036] Step S43: The purification end randomly selects \(r''\) a,i ,r'' b,k ,r'' v,j ,r'' s \(\in Z\) p , where \(i\in\omega\) a ,j\in\omega\) v ,k\in\omega\) b , and calculates the purified signature \(\sigma'\) v :

[0037]

[0038]

[0039] Step S44: The purification end outputs the purified signature \(\sigma'\) v and the purified message \(M'\).

[0040] Further, the step S5 specifically includes the following steps:

[0041] Step S51: The verification end inputs the purified message signature pair (M', σ' v ), the public parameters params, the verification end key the signature end attribute set ω a the purifier attribute set ω b and the verification end attribute set ω v ;

[0042] Step S52: The verification end calculates:

[0043]

[0044]

[0045]

[0046] Step S53: The verification end determines whether the equation:

[0047]

[0048]

[0049]

[0050] holds; if it holds, the verification end outputs accept, otherwise it outputs reject.

[0051] Further, the step S6 specifically includes the following steps:

[0052] Step S61: The verification end inputs the verification end key the purified message M', the signature end attribute set ω a the purifier attribute set ω b and the verification end attribute set ω v ;

[0053] Step S62: The verification end randomly selects and calculates the simulated signature

[0054]

[0055]

[0056] where,

[0057] Step S63: The verification end outputs the simulated signature

[0058] The present invention also provides an attribute - based verifiable signature system with a strong designated verifier for implementing the above - mentioned method, which is characterized by including:

[0059] An attribute authorization end, which is used to generate a master key msk and public parameters params according to a security parameter λ; and is used to output a signature - end key a and a verifier - end key v according to the public parameters params, the master key msk, a signature - end attribute set ω and a verifier - end attribute set ω

[0060] A signature end, which is used to generate a signature σ a and a set of secret values SI according to the public parameters params, a message M, a signature - end attribute set ω a purifier - end attribute set ω b and a verifier - end attribute set ω v v v and a set of secret values SI;

[0061] A purifying end, which is used to generate a purified message M' and a purified signature σ' N according to a set of purifiable message indexes I v , the message M, the public parameters params, the signature σ a , a signature - end attribute set ω b , a purifier - end attribute set ω v , a verifier - end attribute set ω v ; and

[0062] A verifier end, which is used to verify the validity of the signature according to the public parameters params, the purified message M', the purified signature σ' v , a verifier - end key , a signature - end attribute set ω a , a verifier - end attribute set ω v and a purifier - end attribute set ω b ; and is used to generate a simulated signature a according to the public parameters params, the purified message M', a signature - end attribute set ω v , a verifier - end attribute set ω b , a purifier - end attribute set ω and a verifier - end key

[0063] Compared with the prior art, the present invention has the following beneficial effects: Based on attribute-based signature design, on the one hand, the signing end can prevent the signature from being maliciously spread by specifying the verifier, and on the other hand, only when the signer's attributes meet the access policy can a valid signature be generated; the purification end can modify the sensitive information in the signature and regenerate the signature to achieve the hiding of sensitive information. The verification end uses the verification end key to verify the signature, and only when the verification end attribute set meets the access policy can it verify whether the signature is valid. In addition, the verification end can generate a valid simulated signature using the verification end key, thus avoiding the malicious spread of the signature. Therefore, the present invention has strong practicability and broad application prospects in data authentication and privacy protection access control. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] Figure 1 is a system architecture diagram in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0065] The present invention will be further described below in conjunction with the drawings and embodiments.

[0066] It should be noted that the following detailed description is exemplary and is intended to provide further description of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present application belongs.

[0067] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application. As used herein, unless otherwise clearly specified in the context, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0068] This embodiment provides an attribute-based purifiable signature method with a strong designated verifier, including the following steps:

[0069] Step S1: The attribute authorization end inputs the security parameter λ and outputs the master key msk and the public parameter params.

[0070] In this embodiment, the step S1 specifically includes the following steps:

[0071] Step S11: The attribute authorization end inputs the security parameter λ, generates two p-order bilinear multiplicative cyclic groups G1 and G2, where p is a large prime number, |p| = λ; e: G1×G1→G2 is a bilinear mapping; the attribute authorization end selects a default attribute set where Z p ={0, 1,..., p - 1}.

[0072] Step S12: The attribute authorization end defines a threshold access policy Wherein k ∈ {a, b}, It is defined as follows: If Then Otherwise it is False; Set the access policy that the signature end needs to meet as The access policy that the verification end needs to meet is

[0073] Step S13: The attribute authorization end randomly selects a generator g of G1 and randomly selects Calculate g1 = g α .

[0074] Step S14: The attribute authorization end randomly selects g2 ∈ G1 and a vector H = (h1, h2,..., h n+d-1 ), where h i ∈ G1, 1 ≤ i ≤ n + d - 1, where n represents the length of the message.

[0075] Step S15: The attribute authorization end randomly selects u' ∈ G1 and a vector U = (u1, u2,..., u n ), where u i ∈ G1, 1 ≤ i ≤ n; Randomly select d a -order polynomial Q a (x), d v -order polynomial Q v (x), satisfying Q a (0) = Q v (0) = 1.

[0076] Step S16: The attribute authorization end outputs the master secret key msk = α and the public parameters params = (G1, G2, e, g, g1, g2, u′, H, Ω, U, Q a (x), Q v (x)).

[0077] Step S2: The attribute authorization end inputs the public parameters params, the master secret key msk, the signature end attribute set ω a and the verification end attribute set ω v , and outputs the signature end key and the verification end key

[0078] In this embodiment, the step S2 specifically includes the following steps:

[0079] Step S21: The attribute authorization party inputs the master secret key msk = α, the public parameters params = (G1, G2, e, g, g1, g2, u', H, Ω, U, Q a (x), Q v (x)), the signature party's attribute set ω a and the verifier's attribute set ω v , where

[0080] Step S22: The attribute authorization party randomly selects and calculates

[0081] Step S23: The attribute authorization party randomly selects d a -degree polynomial q a (x), d v -degree polynomial q v (x), satisfying q a (0) = q v (0) = β sv .

[0082] Step S24: For i ∈ ω a , the attribute authorization party randomly selects r i ∈ Z p , and calculates the signature party's secret key where Similarly, for j ∈ ω v , the attribute authorization party randomly selects r j ∈ Z p , and calculates the verifier's secret key where

[0083] Step S25: The attribute authorization party outputs the signature party's secret key and the verifier's secret key

[0084] Step S3: The signature party inputs the public parameters params, the message M, the signature party's attribute set ω a and the secret key the purifier's attribute set ω b and the verifier's attribute set ω v , and outputs the signature σ v ; The signature party also generates a set of secret values SI and sends them to the purifier.

[0085] In this embodiment, the specific steps of step S3 include the following steps:

[0086] Step S31: The signature party inputs the signature party's attribute set ω a , the purifier's attribute set ω b and the verifier's attribute set ωv , the message M = (m1m2…m n ), where m i ∈ {0,1}, i ∈ {1,2,…,n}.

[0087] Step S32: The signing end randomly selects satisfying Randomly select satisfying Randomly select r a,i , r v,j , r b,k , r s , r' a,i , r' b,k , r' v,j , r' s ∈ Z p , where i ∈ ω a , j ∈ ω v , k ∈ ω b , and calculate σ v = (σ v0 , σ v1 , σ v2 , σ v3 , σ v4 ); The specific steps are as follows:

[0088]

[0089]

[0090]

[0091]

[0092] Step S33: The signing end calculates the secret value where i ∈ I N ; Let represent the set of secret values, represent the set of message indices that the signer allows to be purified, where 1 ≤ N ≤ n.

[0093] Step S34: The signing end outputs the signature σ v , and sends SI to the purification end.

[0094] Step S4: The purification end inputs the set of purifiable message indices I N , the message M, the public parameter params, the signature σ v , the attribute set ω of the signing end a , the attribute set ω of the purification end b , the attribute set ω of the verification end vand the set of secret values SI, and outputs the sanitized message M' and the sanitized signature σ' v .

[0095] In this embodiment, step S4 specifically includes the following steps:

[0096] Step S41: The sanitizer inputs the set of sanitizable message indices I N , the message M, the signature σ v , the set of secret values SI, the signer attribute set ω a , the sanitizer attribute set ω b , and the verifier attribute set ω v .

[0097] Step S42: The sanitizer defines the set of message indices to be sanitized Let the set I1 = {i ∈ I: m i = 0, m' i = 1}, I2 = {∈i: m i = 1, m' i = 0}, where m' i represents the bit value of the sanitized message, 0 ≤ i ≤ n; at this time, M' = (m'0m'1…m' n ) represents the sanitized message.

[0098] Step S43: The sanitizer randomly selects r″ a,i , r″ b,k , r″ v,j , r″ s ∈ Z p , where i ∈ ω a , j ∈ ω v , k ∈ ω b , and calculates the sanitized signature σ' v :

[0099]

[0100]

[0101] Step S44: The sanitizer outputs the sanitized signature σ' v and the sanitized message M'.

[0102] Step S5: The verifier inputs the public parameters params, the sanitized message M', the sanitized signature σ' v , the verifier's secret key , the signer attribute set ω a , the verifier attribute set ω v , and the sanitizer attribute set ω b ; if σ' v is a valid signature for M', outputs accept; otherwise, outputs reject.

[0103] In this embodiment, step S5 specifically includes the following steps:

[0104] Step S51: The verification end inputs the purified message signature pair (M', σ' v ), public parameters params, the verification end key the signature end attribute set ω a the purifier attribute set ω b and the verification end attribute set ω v .

[0105] Step S52: The verification end calculates:

[0106]

[0107]

[0108]

[0109] Step S53: The verification end determines whether the equation:

[0110]

[0111]

[0112]

[0113] holds; if it holds, the verification end outputs accept, otherwise it outputs reject.

[0114] Step S6: The verification end inputs the public parameters params, the purified message M', the signature end attribute set ω a the verification end attribute set ω v the purifying end attribute set ω b and the verification end key and outputs the simulated signature

[0115] In this embodiment, step S6 specifically includes the following steps:

[0116] Step S61: The verification end inputs the verification end key the purified message M', the signature end attribute set ω a the purifier attribute set ω b and the verification end attribute set ω v .

[0117] Step S62: The verification end randomly selects and calculates the simulated signature

[0118]

[0119]

[0120] Among them,

[0121] Step S63: The verification end outputs an analog signature

[0122] As Figure 1 shown, this embodiment also provides an attribute-based verifiable signature system with a strong designated verifier for implementing the above method, including an attribute authorization end, a signature end, a purification end, and a verification end.

[0123] The attribute authorization end is used to generate a master key msk and public parameters params according to the security parameter λ; and is used to output a signature end key a and a verification end key v according to the public parameters params, the master key msk, the signature end attribute set ω and the verification end attribute set ω

[0124] The signature end is used to generate a signature σ a and a set of secret values SI according to the public parameters params, the message M, the signature end attribute set ω the purification end attribute set ω b and the verification end attribute set ω v v v and a set of secret values SI.

[0125] The purification end is used to generate a purified message M' and a purified signature σ' N according to the set of purifiable message indices I v the message M, the public parameters params, the signature σ a the signature end attribute set ω b the purification end attribute set ω v the verification end attribute set ω v .

[0126] The verification end is used to verify the validity of the signature according to the public parameters params, the purified message M', the purified signature σ' v the verification end key the signature end attribute set ω a the verification end attribute set ω v and the purification end attribute set ω b ; and is used to verify the validity of the signature according to the public parameters params, the purified message M', the signature end attribute set ω a the verification end attribute set ω v, purification end attribute set ω b and the verification end key generate a simulated signature

[0127] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0128] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0129] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0130] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0131] The above are only the preferred embodiments of the present invention, and are not intended to limit the present invention in any other form. Any person skilled in the art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes. However, any simple modifications, equivalent changes and modifications made to the above embodiments based on the technical essence of the present invention without departing from the technical solution content of the present invention still fall within the protection scope of the technical solution of the present invention.

Claims

1. An attribute-based sanitizable signature method with strong designated verifiers, characterized in that, Including the following steps: Step S1: The attribute authorization end inputs the security parameter λ and outputs the master secret key msk and the public parameter params; Step S2: The attribute authorization end inputs the public parameters params, the master secret key msk, the attribute set ω of the signing end a and the attribute set ω of the verification end v , and outputs the signing end key and the verification end key Step S3: The signing end inputs the public parameters params, the message M, the signing end attribute set ω a and the secret key the purifying end attribute set ω b and the verifying end attribute set ω v , and outputs the signature σ v ; The signing end simultaneously generates a set of secret values SI and sends them to the purifying end; Step S4: The purification end inputs the set I of message indexes to be purified N , message M, public parameter params, and signature σ v , the signature end attribute set ω a , the purification end attribute set ω b , the verification end attribute set ω v and the set SI of secret values, and outputs the purified message M′ and the purified signature σ′ v ; Step S5: The verification end inputs the public parameter params, the purified message M′, the purified signature σ′ v , the verification end key the signature end attribute set ω a , the verification end attribute set ω v and the purification end attribute set ω b ; If σ′ v is a valid signature of M′, output accept; otherwise, output reject; Step S6: The verification end inputs the public parameters params, the purified message M′, the signature end attribute set ω a , the verification end attribute set ω v , the purification end attribute set ω b and the verification end key and outputs an imitation signature The specific steps of the said Step S1 include the following steps: Step S11: The attribute authorization end inputs a security parameter λ, generates two multiplicative cyclic groups G1 and G2 of order p, where p is a large prime number and |p| = λ; e: G1×G1→G2 is a bilinear mapping; the attribute authorization end selects a default attribute set where Z p ={0, 1, …, p - 1}; Step S12: The attribute authorization end defines a threshold access policy Wherein k ∈ {a, b}, It is defined as follows: If Then Otherwise it is False; Set the access policy that the signature end needs to meet as The access policy that the verification end needs to meet is Step S13: The attribute authorization end randomly selects a generator g of G1 and randomly selects Calculate g1 = g α ; Step S14: The attribute authorization end randomly selects \(G_2\in G_1\) and a vector \(H=(h_1, h_2,\cdots, h\) n+d-1 ), where \(h\) i \(\in G_1, 1\leq i\leq n + d - 1\), where \(n\) represents the length of the message; Step S15: The attribute authorization end randomly selects \(u'\in G_1\) and a vector \(U=(u_1,u_2,\ldots,u\) n ), where \(u\) i \(\in G_1, 1\leq i\leq n\); randomly selects a polynomial \(q\) a of degree \(d - 1\), a polynomial \(q\) a \((x)\), \(d\) v of degree \(d - 1\), a polynomial \(q\) v \((x)\), satisfying \(q\) a (0)=q\) v (0)=1; Step S16: The attribute authorization end outputs the master secret key msk = α and the public parameters params = (G1, G2, e, g, g1, g2, u′, H, Ω, U, q a (x), q v (x)); The specific steps of the said Step S2 include the following steps: Step S21: The attribute authorization end inputs the master secret key msk = α, the public parameters params = (G1, G2, e, g, g1, g2, u′, H, Ω, U, q a (x), q v (x)), the attribute set ω of the signature end a and the attribute set ω of the verification end v , where Step S22: The attribute authorization end randomly selects Calculate Step S23: The attribute authorization end randomly selects a polynomial q(x) of degree d - 1, where the polynomial q(x) of degree d - 1 satisfies q(0) = β; a -1st degree polynomial q a (x), d v -1st degree polynomial q v (x), such that q a (0) = q v (0) = β sv ; Step S24: For i ∈ ω a , the attribute authorization end randomly selects r i ∈ Z p , and calculates the signature end key where Similarly, for j ∈ ω v , the attribute authorization end randomly selects r j ∈ Z p , and calculates the verification end key where Step S25: The attribute authorization end outputs the signature end key and the verification end key 2. The attribute-based sanitizable signature method with a strong designated verifier according to claim 1, characterized in that, The specific steps of the said Step S3 include the following steps: Step S31: The signing end inputs the signing - end attribute set ω a , the purifier attribute set ω b , and the verifier attribute set ω v . The message M=(m1m2…m n ), where m i ∈{0,1}, i∈{1,2,…,n}; Step S32: The signing side randomly selects satisfying Randomly select satisfying Randomly select r a,i , r v,j , r b,k , r s , r' a,i , r' b,k , r' v,j , r' s ∈Z p , where i ∈ ω a , j ∈ ω v , k ∈ ω b , and calculate σ v =(σ v0 , σ v1 , σ v2 , σ v3 , σ v4 ); The specific steps are as follows: Step S33: The signing side calculates the secret value where i ∈ I N ; Let denote the set of secret values, denote the set of message indices that the signer allows to be purified, where 1 ≤ N ≤ n; Step S34: The signing end outputs the signature σ v , and sends SI to the purification end.

3. The attribute-based sanitizable signature method with a strong designated verifier according to claim 2, wherein The specific steps of the said Step S4 include the following steps: Step S41: The purification end inputs the set I of message indexes to be purified, the message M, the signature σ, the set SI of secret values, the signature end attribute set ω, the purifier attribute set ω, and the verifier attribute set ω; N , the message M, the signature σ v , the set SI of secret values, the signature end attribute set ω a , the purifier attribute set ω b and the verifier attribute set ω v ; Step S42: The purification end defines the message index set to be purified Let the set I1 = {i ∈ I: m i = 0, m' i = 1}, I2 = {i ∈ I: m i = 1, m' i = 0}, where m' i represents the bit value of the purified message, 0 ≤ i ≤ n; at this time, M' = (m'0m'1…m' n ) represents the purified message; Step S43: The purification end randomly selects r″ a,i , r″ b,k , r″ v,j , r″ s ∈Z p , where i ∈ ω a , j ∈ ω v , k ∈ ω b , and calculate the purification signature σ′ v : Step S44: The purification end outputs a purified signature σ′ v and a purified message M′.

4. The attribute-based sanitizable signature method with a strong designated verifier according to claim 3, characterized in that The specific steps of the said Step S5 include the following steps: Step S51: The verification end inputs a purification message signature pair (M′, σ′ v ), public parameters params, and a verification end key The signature end attribute set ω a , the purifier attribute set ω b , and the verification end attribute set ω v ; Step S52: The verification end calculates: Step S53: The verification end judges the equation: Whether it holds; if it holds, the verification end outputs accept, otherwise it outputs reject.

5. The attribute-based sanitizable signature method with a strong designated verifier according to claim 4, characterized in that The specific steps of the said Step S6 include the following steps: Step S61: The verification end inputs the verification end key Purify the message M′, the signature end attribute set ω a , the purifier attribute set ω b and the verification end attribute set ω v ; Step S62: Randomly select by the verification end and calculate the simulated signature Among them, Step S63: The verification end outputs an analog signature 6. An attribute-based sanitizable signature system with a strong designated verifier for implementing the method according to any one of claims 1-5, characterized in that, Including: The attribute authorization end is used to generate a master secret key msk and public parameters params according to the security parameter λ; and is used to output a signature end key and a verification end key according to the public parameters params, the master secret key msk, the signature end attribute set ω a and the verification end attribute set ω v ​​ Signature side, which is used to generate a signature σ a and a set of secret values SI according to public parameters params, message M, signature side attribute set ω purification side attribute set ω b and verification side attribute set ω v v ;​ Purification end, for indexing set I according to purifiable message N , message M, public parameter params, signature σ v , signature end attribute set ω a , purification end attribute set ω b , verification end attribute set ω v and secret value set SI, to generate purified message M' and purified signature σ' v ; and Verification end, which is used to verify the validity of a signature according to public parameters params, purified message M′, purified signature σ′ v , verification end key Signature end attribute set ω a , verification end attribute set ω v And purification end attribute set ω b , to verify the validity of the signature; For generating a simulated signature based on public parameters params, sanitized message M′, signature side attribute set ω a , verification side attribute set ω v , sanitization side attribute set ω b and verification side key ​

Citation Information

Patent Citations

  • Traceable attribute-based cleanable signature method and system

    CN113536378A