A method and device for constructing a chained accumulator, a membership proof method and system

By building chain accumulators and designing self-certified member proof methods, the problems of low storage efficiency and slow operation of accumulators in the prior art are solved, and efficient member proof and evidence verification are achieved.

CN115242375BActive Publication Date: 2025-05-30BEIJING INFORMATION SCI & TECH UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210759129.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-30
Publication Date
2025-05-30
Estimated Expiration
2042-06-30

AI Technical Summary

Technical Problem

The existing password accumulator model has the shortcomings of low storage efficiency, slow operation execution, and the need for a trusted administrator.

Method used

By building a chain accumulator, the hash chain structure is used to dynamically add and delete accumulated elements, and a keyless and key-based member proof method is designed to generate self-verified member proof.

Benefits of technology

Improves the storage efficiency and operation speed of the accumulator, realizes self-certified member proof, and does not require update of the evidence.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115242375B_ABST
    Figure CN115242375B_ABST
Patent Text Reader

Abstract

The present invention provides a method and apparatus for constructing a chained accumulator, a method and system for member authentication. Among them, the method for constructing a chained accumulator includes: obtaining an element X to be accumulated i , and performing a hash calculation on the element X to be accumulated i and the current accumulated value H i‑1 to obtain a new accumulated value H i . Then, taking the new accumulated value H i as the current accumulated value. When i = 1, the current accumulated value H i‑1 is the initial value H0, and i is a positive integer greater than or equal to 1. Construct a chained accumulator, where the sequence of accumulated values in the chained accumulator includes: H0, ……, H i connected in sequence. A new type of chained accumulator is constructed based on the hash chain structure, which can dynamically add and delete accumulated elements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular, to a method and device for constructing a chained accumulator, a method and system for member authentication. Background Art

[0002] The password accumulator scheme can compress a large-scale value set into a short value that can represent the entire set, and can efficiently give the (non)-member authentication of any element. From the perspective of existing security assumptions, accumulators can be divided into RSA-based password accumulators, bilinear mapping-based password accumulators, and hash function-based password accumulators.

[0003] Existing accumulator models have defects such as low storage efficiency, slow operation execution, and the need for a trusted administrator. Summary of the Invention

[0004] The present invention aims to provide a method and device for constructing a chained accumulator, a method and system for member authentication that overcome or at least partially solve the above problems.

[0005] To achieve the above object, the technical solution of the present invention is specifically implemented as follows:

[0006] The first aspect of the present invention provides a method for constructing a chained accumulator, including: obtaining an element X to be accumulated i , and performing a hash calculation on the element X to be accumulated i and the current accumulated value H i-1 to obtain a new accumulated value H i , and using the new accumulated value H i as the current accumulated value. When i = 1, the current accumulated value H i-1 is the initial value H 0 , where i is a positive integer greater than or equal to 1; constructing a chained accumulator, where the accumulated value sequence in the chained accumulator includes: H 0 , ……, H i .

[0007] Among them, performing a hash calculation on the element X to be accumulated i and the current accumulated value H i-1 includes: concatenating and combining the hash value of the element X to be accumulated i or the element X to be accumulated i with the current accumulated value H i-1 , and performing a hash calculation on the concatenated and combined value.

[0008] The second aspect of the present invention provides a method for member authentication, including: the administrator groups the accumulated element set X at an interval d to obtain a grouped accumulated element set X = {[x 1,x 2 ,…,x d ,…,[x i·d+1 ,x i·d+2 ,…x n}, where n is the number of accumulated elements and i is the number of groups; The administrator constructs a chained accumulator according to the above method for constructing a chained accumulator; The administrator obtains the accumulated element x t , and generates a membership proof w for the accumulated element x t . The membership proof w = (w 1 , w 2 ), w 1 = [H(x i*d ), H(x (i+1)*d )], w 2 = [x i*d , x i*d+1 ,..., x t ,..., x (i+1)d , where d represents the grouping interval, and w 1 represents the evidence node value of the accumulated value sequence at an interval of d on the accumulated value sequence, and w 2 is the set of elements between two evidence nodes of the accumulated value sequence containing the element x; The administrator sends the membership proof w of the accumulated element x t to the participant; The participant receives the membership proof w of the accumulated element x t and verifies it according to a preset algorithm.

[0009] Among them, the preset algorithm includes: the Belongs algorithm.

[0010] The third aspect of the present invention provides a membership proof method, including: The administrator constructs a chained accumulator using the above method for constructing a chained accumulator, and generates a membership evidence w i for the accumulated element x i = H(x i , k); The participant sends a membership proof request req = (x i ’, w i ) to the administrator, where x i ’ is the accumulated element to be verified; After receiving the membership proof request, the administrator constructs a membership proof w i ’ = H(x i ’, k). If w i = w i ’, the membership proof is valid; If w i ≠ w i ’, the membership proof is invalid.

[0011] Among them, before the participant sends a membership proof request to the administrator, the method further includes: the participant receives the evidence corresponding to the cumulative element sent by the administrator and saves it locally.

[0012] The fourth aspect of the present invention provides a membership proof method, including: the administrator uses the above-mentioned chained accumulator construction method to construct a chained accumulator, and generates a cumulative element x according to the preset key parameter k and single authentication parameter r i and the membership evidence w i of i =H(x i ,H(k,r i )); the participant sends a membership proof request req=(x i ’,r i ,w i ) to the administrator, where x i ’ is the cumulative element to be verified; after receiving the membership proof request, the administrator constructs the membership proof w i ’=H(x i ’,H(k,r i )); if w i =w i ’, the membership proof is valid; if w i ≠w i ’, the membership proof is invalid.

[0013] Among them, the single authentication parameter includes: a random number or a timestamp.

[0014] Among them, before the participant sends a membership proof request to the administrator, the method further includes: the participant receives the evidence corresponding to the cumulative element sent by the administrator, the random number and / or the timestamp sent by the administrator, and saves them locally.

[0015] The fifth aspect of the present invention provides a chained accumulator construction device, including: a calculation module, configured to obtain the element X to be accumulated i , perform a hash calculation on the element X to be accumulated i and the current cumulative value H i-1 to obtain a new cumulative value H i , use the new cumulative value H i as the current cumulative value, when i = 1, the current cumulative value H i-1 is the initial value H 0 , and i is a positive integer greater than or equal to 1; a construction module, configured to construct a chained accumulator, where the cumulative value sequence in the chained accumulator includes: H 0 , ……, H i .

[0016] Among them, the calculation module uses the following method to accumulate the element X to be accumulated i ​With the current accumulated value H i-1 Perform a hash calculation: For the element X to be accumulated i Or the element X to be accumulated i The hash value of and the current accumulated value H i-1 Are concatenated and combined, and a hash calculation is performed on the concatenated and combined value.

[0017] The sixth aspect of the present invention provides a membership proof system, including: an administrator, used to group the set of accumulated elements X at an interval d to obtain a grouped set of accumulated elements X = {[x 1 , x 2 , …, x d , …, [x i·d+1 , x i·d+2 , … x n}, where n is the number of accumulated elements and i is the number of groups; construct a chained accumulator through the chained accumulator construction device according to any one of claims 10 to 11; obtain the accumulated element x t sent by the participant, and generate a membership proof w of the accumulated element x t , the membership proof w = (w 1 , w 2 ), w 1 = [H(x i*d ), H(x (i+1)*d )], w 2 = [x i*d , x i*d+1 ,..., x t ,..., x (i+1)d , where d represents the grouping interval, w 1 represents the accumulated value sequence evidence node value at an interval of d on the accumulated value sequence, and w 2 is the set of elements between two accumulated value sequence evidence nodes containing the element x; send the membership proof w of the accumulated element x t to the participant; the participant is used to receive the membership proof w of the accumulated element x t and perform verification according to a preset algorithm.

[0018] Among them, the preset algorithm includes: the Belongs algorithm.

[0019] The seventh aspect of the present invention provides a membership proof system, including: an administrator, used to construct a chained accumulator using the above-mentioned chained accumulator construction device, and generate a membership evidence w i of the accumulated element x according to the preset key parameter k i = H(x i , k); the participant is used to send a membership proof request req = (x i ’, w i), where x i ’ is the accumulative element to be verified; the administrator is also used to construct the membership proof w after receiving the membership proof request i ’ = H(x i ’, k),, if w i = w i ’, then the membership proof is valid; if w i ≠ w i ’, then the membership proof is invalid.

[0020] Among them, the participant is also used to receive the evidence corresponding to the accumulative element sent by the administrator and save it locally before sending the membership proof request to the administrator.

[0021] The eighth aspect of the present invention provides a membership proof system, including: an administrator, used to construct a chained accumulator by using the above-mentioned chained accumulator construction device, and generate the membership evidence w of the accumulative element x according to the preset key parameter k and the single authentication parameter r i = H(x i , H(k, r i )); a participant, used to send a membership proof request req = (x i ’, r i , w i ), where x i ’ is the accumulative element to be verified; the administrator is also used to construct the membership proof w i ’ = H(x i ’, H(k, r i )); if w i = w i ’, then the membership proof is valid; if w i ≠ w i ’, then the membership proof is invalid. i ≠w i ’, then the membership proof is invalid.

[0022] Among them, the single authentication parameter includes: a random number or a time stamp.

[0023] Among them, the participant is also used to receive the evidence corresponding to the accumulative element sent by the administrator, the random number and / or the time stamp sent by the administrator and save them locally before sending the membership proof request to the administrator.

[0024] It can be seen that through the chained accumulator construction method and device provided by the present invention, a new type of chained accumulator is constructed based on the hash chain structure, which can dynamically add and delete accumulative elements. After that, the membership proof can be generated.

[0025] Through the membership proof method and system provided by the embodiments of the present invention, a keyless membership proof scheme is designed. This scheme groups the cumulative set elements and reconstructs some nodes in the chained accumulator model, thereby proving that an element is a member of the cumulative set. This method has self-certification, and the generated evidence can be authenticated by a third party without relying on the authority of the administrator; the drawback of this method is that the evidence needs to be updated as the cumulative set is updated.

[0026] Through the membership proof method provided by the embodiments of the present invention, another membership proof method based on a key is designed. The membership proof based on a key introduces a secret parameter, which can verify the existence of an element simply and efficiently, improving the efficiency of membership proof, and this evidence does not need to be updated.

[0027] On this basis, a random number (or timestamp) is also added, which can be used as an auxiliary parameter in the proof process, enabling the administrator to allow the evidence to be verified by a third party without exposing the key information. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following described drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0029] Figure 1 It is a flowchart of the chained accumulator construction method provided by the embodiments of the present invention;

[0030] Figure 2 It is a schematic structural diagram of the chained accumulator construction device provided by the embodiments of the present invention;

[0031] Figure 3 It is a schematic structural diagram of the chained accumulator provided by the embodiments of the present invention;

[0032] Figure 4 It is a schematic diagram of the membership proof system provided by the embodiments of the present invention;

[0033] Figure 5 It is a flowchart of the membership proof method provided by Embodiment 1 of the present invention;

[0034] Figure 6 It is a specific flowchart of the membership proof method provided by Embodiment 1 of the present invention;

[0035] Figure 7 It is a schematic diagram of the membership proof system provided by Embodiment 1 of the present invention;

[0036] Figure 8Flowchart of the membership proof method provided in Embodiment 2 of the present invention;

[0037] Figure 9 Specific flowchart of the membership proof method provided in Embodiment 2 of the present invention;

[0038] Figure 10 Schematic diagram of the membership proof system provided in Embodiment 2 of the present invention;

[0039] Figure 11 Flowchart of the membership proof method provided in Embodiment 3 of the present invention;

[0040] Figure 12 Specific flowchart of the membership proof method provided in Embodiment 3 of the present invention;

[0041] Figure 13 Schematic diagram of the membership proof system provided in the embodiment of the present invention. Detailed implementation manners

[0042] The exemplary embodiments of the present disclosure will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.

[0043] Figure 1 The flowchart of the chained accumulator construction method provided in the embodiment of the present invention is shown. Refer to Figure 1 , the chained accumulator construction method provided in the embodiment of the present invention includes:

[0044] S101. Obtain the element X to be accumulated i , and perform a hash calculation on the element X to be accumulated i and the current accumulated value H i-1 to obtain a new accumulated value H i , and use the new accumulated value H i as the current accumulated value. When i = 1, the current accumulated value H i-1 is the initial value H 0 , and i is a positive integer greater than or equal to 1;

[0045] S102. Construct a chained accumulator, where the sequence of accumulated values in the chained accumulator includes, connected in sequence: H 0 , ……, H i .

[0046] As an alternative implementation manner of the embodiment of the present invention, performing a hash calculation on the element Xi to be accumulated and the current accumulated value Hi-1 includes: performing a hash calculation on the element X to be accumulatedi or the element X to be accumulated i and concatenate the hash value of the element X with the current accumulated value H i-1 Then perform a hash calculation on the concatenated value.

[0047] Specifically, the chained accumulator of the present invention combines the message hash chain data structure. It concatenates each current element to be accumulated or the hash value of the accumulated element in the accumulation set with the value of the previous hash chain node, and after calculating through the collision-resistant hash function H, a new hash chain node value is obtained and added to the hash chain set to form a chained accumulator. This hash chain combination is the accumulated value sequence in the chained accumulator. The selection of the hash function includes algorithms such as SHA-1, SHA-256, MD5, and SM3, which are not specifically limited in the present invention.

[0048] In specific implementation, the accumulator can be initialized first. The accumulator administrator generates the initial parameters of the accumulator (security parameter k, hash function H, etc.), and randomly generates the initial value Acc of the accumulator 0 ; the participant sends the accumulated element x to the administrator; the accumulator administrator concatenates the received accumulated element x or the hash value of the element with the current accumulated value Acc 0 and calculates Acc through the hash function H (such as SHA-256, SM3, etc.) selected during initialization 1 =H(Acc 0 ,x), and uses Acc 1 as the new accumulated value for subsequent operations.

[0049] After constructing the chained accumulator, a membership proof can be generated for the accumulated element x. If the participant requests a membership proof of the accumulated element x from the administrator, the administrator sends the evidence w to the participant, so as to prove that the accumulated element x presented by the participant is a set member.

[0050] It can be seen that through the chained accumulator construction method provided by the embodiments of the present invention, a new type of chained accumulator is constructed based on the hash chain structure, which can dynamically add and delete accumulated elements. After that, a membership proof can be generated.

[0051] Figure 2 FIG. shows the structural schematic diagram of the chained accumulator construction device provided by the embodiments of the present invention. This chained accumulator construction device applies the above method. Only a simple description of the structure of the chained accumulator construction device is given below. For other matters not covered, please refer to the relevant descriptions in the above chained accumulator construction method. See Figure 2 , the chained accumulator construction device provided by the embodiments of the present invention includes:

[0052] A calculation module, which is used to obtain the element X to be accumulated i, the element X to be accumulated i and the current accumulated value H i-1 are subjected to hash calculation to obtain a new accumulated value H i , and the new accumulated value H i is used as the current accumulated value. When i = 1, the current accumulated value H i-1 is the initial value H 0 , where i is a positive integer greater than or equal to 1;

[0053] A building block for constructing a chained accumulator, wherein the sequence of accumulated values in the chained accumulator includes: H 0 , ……, H i .

[0054] As an alternative implementation of the embodiment of the present invention, the calculation module calculates the hash of the element X to be accumulated i and the current accumulated value H i-1 in the following way: The hash value of the element X to be accumulated i or the element X to be accumulated i is concatenated with the current accumulated value H i-1 , and the concatenated value is subjected to hash calculation.

[0055] It can be seen that through the chained accumulator construction device provided by the embodiment of the present invention, a new chained accumulator is constructed based on the hash chain structure, which can dynamically add and delete accumulated elements. After that, a membership proof can be generated.

[0056] Specifically, when implemented, Figure 3 the chained accumulator provided by the embodiment of the present invention is further described:

[0057] Definition: Let M be the set of all values. For any set of elements to be accumulated (stored), the strong universal accumulator model can be represented by a five-tuple: Acc=(Setup, Witness, Belongs, Update, Checkupdate), where:

[0058] Setup: Randomly select a hash function from the set of hash functions H and denote it as H. Set the set of elements to be accumulated X to an empty set, and randomly select (or perform multi-party secure calculation) an initial value a. After calculation by the function H, use H(a) as the initial value Acc of the hash chain 0 .

[0059] Witness: Given an input x∈M and stored m, output a proof w. The proof w 1 =[H(x i*d ), H(x (i+1)*d )], w 2= [x i*d , x i*d+1 ,..., x,..., x (i+1)d , where d is the storage interval of hash chain nodes, and w 1 represents the hash chain evidence node value at interval d on the hash chain, and w 2 is the set of elements between two hash chain evidence nodes containing element x If then w 1 = [H(x i*d ), H(x (i+1)*d )], w 2 = [x i*d , x i*d+1 ,..., x j , x k ,..., x (i+1)d , where x j < x < x k and (x j , x k ) are consecutive elements in the set.

[0060] Belongs: Given input x ∈ M, evidence w = (w 1 , w 2 ), and accumulator value Acc, where w 1 = [H(x i*d ), H(x (i+1)*d )], w 2 = [x i*d , x i*d+1 ,..., x (i+1)d . The verifier needs to verify that H(x (i+1)*d ) = H(...(H(H(x i*d ), x i*d+1 ))..., x (i+1)d ). If this equation holds and x ∈ w 2 , then it is proven that x is a member of the accumulator, and the algorithm returns 1; if then the algorithm returns 0.

[0061] Update: Given input x ∈ M, accumulator value Acc bf and storage m bf . There are two update states: add and del.

[0062] If op = add and then that is, X = {x 1 , x 2 ,..., x n , x}, and the accumulator value is updated to Acc af=H(Acc bf , x). The updated evidence can be expressed as: w add =(add, [A bf , Acc af , [x]).

[0063] If op = del and x ∈ X, the algorithm first needs to locate the element x in the set X and delete it from the set. Due to the one-wayness and collision-freeness of the hash algorithm selected in the present invention, to ensure the correctness of the hash chain accumulator model, the algorithm needs to recalculate the chain nodes after the element x in the hash chain and construct a new hash chain HC': Acc af = Acc bf / x.

[0064] CheckUpdate: Input x ∈ M, the updated evidence w, and the accumulator values Acc bf , Acc af before and after the update. The specific steps are as follows:

[0065] If w = (add, w 1 , w 2 ), then the algorithm calculates Acc' = H(Acc bf , x). If Acc' = Acc af , it proves that the operation is valid, and the algorithm outputs 1; if Acc' ≠ Acc af , it means that the added element x is incorrect, the operation is invalid, and the algorithm outputs 0.

[0066] If w = (del, w 1 , w 2 ), it is equivalent to the algorithm calculating the non-membership proof of the element x, which will not be elaborated here.

[0067] It can be seen that the present invention designs a general chained accumulator function. The chained accumulator model consists of a five-tuple, including the generation algorithm Setup of the initial parameters and the initial accumulator value, the witness generation algorithm Witness, the update algorithm Update of the accumulator value, and the check update algorithm CheckUpdate.

[0068] See Figure 4 , the present invention also provides a membership proof system, which includes at least one participant and an administrator. The administrator constructs a chained accumulator by applying the above-mentioned chained accumulator construction method. At the same time, the administrator can include the above-mentioned chained accumulator construction device.

[0069] Among them,

[0070] The administrator is used to receive the element X to be accumulated sent by the participant iAfter that, store it in the set X to be accumulated. According to the values in the set X to be accumulated and the randomly generated initial value H 0 Construct a chained accumulator. If a participant requests the administrator to verify whether a certain value is a member of the accumulated set X, generate a corresponding proof W and send it to the participant.

[0071] Participant, used to send the value X to be accumulated i to the administrator, and can prove that the element presented is a set member according to the proof distributed by the administrator.

[0072] The following further describes the membership proof method and system provided by the embodiments of the present invention through Embodiment 1 to Embodiment 3.

[0073] Embodiment 1

[0074] Based on the above chained accumulator construction method, Embodiment 1 of the present invention provides a membership proof method, which is a key-free membership proof method. See Figure 5 , the membership proof method provided by the embodiments of the present invention includes:

[0075] S201. The administrator groups the accumulated element set X at an interval d to obtain a grouped accumulated element set X = {[x 1 , x 2 , …, x d , …, [x i·d+1 , x i·d+2 , … x n}, where n is the number of accumulated elements and i is the number of groups;

[0076] S202. The administrator constructs a chained accumulator according to the above chained accumulator construction method;

[0077] S203. The administrator obtains the accumulated element x t sent by the participant and generates a membership proof w for the accumulated element x t . The membership proof w = (w 1 , w 2 ), w 1 = [H(x i*d ), H(x (i+1)*d )], w 2 = [x i*d , x i*d+1 ,..., x t ,..., x (i+1)d , where d represents the grouping interval, w 1 represents the evidence node value of the accumulated value sequence at an interval of d on the accumulated value sequence, and w 2 is the set of elements between two evidence nodes of the accumulated value sequence containing the element x;

[0078] S204, the administrator adds the cumulative element x t 's membership proof w to the participants;

[0079] S205, the participant receives the cumulative element x t 's membership proof w and performs verification according to a preset algorithm.

[0080] As an alternative implementation of the embodiment of the present invention, the preset algorithm includes: the Belongs algorithm.

[0081] Next, in combination with Figure 6 , the membership proof method provided in Embodiment 1 of the present invention will be further described:

[0082] The administrator groups the cumulative element set at an interval d, that is, the cumulative element set X = {[x 1 , x 2 , …, x d , …, [x i·d+1 , x i·d+2 , … x n};

[0083] The administrator sends the membership proof of the element x t to the participant. The evidence w = (w 1 , w 2 ), w 1 = [H(x i*d ), H(x (i+1)*d )], w 2 = [x i*d , x i*d+1 ,..., x t ,..., x (i+1)d , where d represents the grouping interval, w 1 represents the hash chain evidence node value at an interval of d on the hash chain, and w 2 is the element set between two hash chain evidence nodes containing the element x. Since the cumulative set X sorts the elements by timestamp (or other means), when the administrator receives the cumulative element x t sent by the participant, it can quickly locate the element and generate the corresponding evidence.

[0084] After receiving the evidence w, the participant uses the Belongs algorithm for verification. If the verification is correct, it proves that the element is a member of the set and outputs 1; if the verification fails, it outputs 0.

[0085] It can be seen that through the membership proof method provided in Embodiment 1 of the present invention, a membership proof method without a secret key is designed. This method groups the cumulative set elements and reconstructs some nodes in the chained accumulator model to prove that an element is a member of the cumulative set. This method has self-authentication, and the generated evidence can be authenticated by a third party without relying on the authority of the administrator; the defect of this method is that the evidence needs to be updated as the cumulative set is updated.

[0086] Based on the above-mentioned chained accumulator construction device, Embodiment 1 of the present invention also provides a membership proof system. This membership proof system applies the membership proof method of Embodiment 1 above. Only a simple description of the structure of the membership proof system in Embodiment 1 is given below. For other matters not covered, please refer to the relevant descriptions in the membership proof method of Embodiment 1 above. See Figure 7 , the membership proof system provided in Embodiment 1 of the present invention includes:

[0087] An administrator, used to group the cumulative element set X at an interval d to obtain a grouped cumulative element set X = {[x 1 , x 2 , …, x d , …, [x i·d+1 , x i·d+2 , … x n}, where n is the number of cumulative elements and i is the number of groups; construct a chained accumulator through the above-mentioned chained accumulator construction device; obtain the cumulative element x t sent by the participant, and generate a membership proof w for the cumulative element x t . The membership proof w = (w 1 , w 2 ), w 1 = [H(x i*d ), H(x (i+1)*d )], w 2 = [x i*d , x i*d+1 ,..., x t ,..., x (i+1)d , where d represents the grouping interval, w 1 represents the evidence node value of the cumulative value sequence at an interval of d on the cumulative value sequence, and w 2 is the element set between two evidence nodes of the cumulative value sequence containing the element x; send the membership proof w of the cumulative element x t to the participant;

[0088] A participant, used to receive the membership proof w of the cumulative element x t and perform verification according to a preset algorithm.

[0089] As an alternative implementation of the embodiment of the present invention, the preset algorithm includes: the Belongs algorithm.

[0090] It can be seen that through the membership proof system provided in Embodiment 1 of the present invention, a membership proof scheme without a secret key is designed. This scheme groups the cumulative set elements and reconstructs some nodes in the chained accumulator model, thereby proving that an element is a member of the cumulative set. This method has self-authentication, and the generated evidence can be authenticated by a third party without relying on the authority of the administrator; the defect of this method is that the evidence needs to be updated as the cumulative set is updated.

[0091] Embodiment 2

[0092] Based on the above-mentioned chained accumulator construction method, Embodiment 2 of the present invention provides a membership proof method, which is a case without a single authentication parameter in the membership proof method based on a secret key. Refer to Figure 8 , the membership proof method provided in this Embodiment 2 includes:

[0093] S301. The administrator constructs a chained accumulator using the above-mentioned chained accumulator construction method, and generates a cumulative element x i 's membership evidence w i = H(x i , k);

[0094] S302. The participant sends a membership proof request req = (x i ', w i ) to the administrator, where x i ' is the cumulative element to be verified;

[0095] S303. After receiving the membership proof request, the administrator constructs a membership proof w i ' = H(x i ', k). If w i = w i ', the membership proof is valid; if w i ≠ w i ', the membership proof is invalid.

[0096] As an alternative implementation provided in the embodiment of the present invention, before the participant sends a membership proof request to the administrator, the membership proof method provided in Embodiment 2 of the present invention further includes: the participant receives the evidence corresponding to the cumulative element sent by the administrator and saves it locally.

[0097] Next, in combination with Figure 9 , the membership proof method provided in Embodiment 2 of the present invention will be further described:

[0098] 1. Initialize the accumulator. The administrator generates initial parameters (security parameters, hash function, and key k), collects the cumulative elements x sent by each participant, and constructs a chained accumulator model. i , and constructs a chained accumulator model;

[0099] 2. Send evidence. After a participant sends its cumulative element x to the administrator, it will receive the evidence w sent by the administrator. i = H(x i , k) and save it locally. i

[0100] 3. Construct a membership proof request. A participant sends a verification request req = (xi’, wi) to the administrator, where xi’ is the cumulative element to be verified and wi is the evidence held by the participant.

[0101] 4. Evidence comparison. After receiving the request, the administrator constructs a membership proof wi’ = H(xi’, k), where xi’ is the cumulative element sent by the participant. If wi = wi’, the membership proof is valid; if wi ≠ wi’, the membership proof is invalid.

[0102] It can be seen that through the membership proof method provided in Embodiment 2 of the present invention, a key-based membership proof method is designed according to the characteristics of the accumulator. The key-based membership proof introduces secret parameters, which can verify the existence of elements simply and efficiently, improve the efficiency of membership proof, and the evidence does not need to be updated.

[0103] Based on the above chained accumulator construction device, Embodiment 2 of the present invention further provides a membership proof system. This membership proof system applies the membership proof method of Embodiment 2 above. Only a simple description of the structure of the membership proof system in Embodiment 2 is given below. For other matters not covered, please refer to the relevant descriptions in the membership proof method of Embodiment 2 above. See Figure 10 , the membership proof system provided in Embodiment 2 of the present invention includes:

[0104] An administrator, used to construct a chained accumulator using the above chained accumulator construction device, and generate a membership evidence w of the cumulative element x according to the preset key parameter k. i = H(x i , k); i

[0105] A participant, used to send a membership proof request req = (x i ’, w i ) to the administrator, where x i ’ is the cumulative element to be verified;

[0106] The administrator is also used to construct a membership proof w i ’ = H(xi ’, k), if w i = w i ’, then the member proof is valid; if w i ≠ w i ’, then the member proof is invalid.

[0107] As an alternative implementation of the embodiment of the present invention, the participant is further configured to receive the evidence corresponding to the accumulative element sent by the administrator and save it locally before sending a member proof request to the administrator.

[0108] It can be seen that through the member proof system provided in Embodiment 2 of the present invention, a key-based member proof scheme is designed according to the characteristics of the accumulator. The key-based member proof introduces secret parameters, can verify the existence of elements simply and efficiently, improves the efficiency of member proof, and the evidence does not need to be updated.

[0109] Embodiment 3

[0110] Based on the above method for constructing a chained accumulator, Embodiment 3 of the present invention provides a member proof method, which is a case where a single authentication parameter participates in a key-based member proof method. See Figure 11 , the member proof method provided in this Embodiment 3 includes:

[0111] S401, the administrator constructs a chained accumulator by using the above method for constructing a chained accumulator, and generates a member evidence w i for the accumulative element x i according to the preset key parameter k and single authentication parameter r i = H(x i , H(k, r i ));

[0112] S402, the participant sends a member proof request req = (x i ’, r i , w i ) to the administrator, where x i ’ is the accumulative element to be verified;

[0113] S403, after receiving the member proof request, the administrator constructs a member proof w i ’ = H(x i ’, H(k, r i )); if w i = w i ’, then the member proof is valid; if w i ≠ w i ’, then the member proof is invalid.

[0114] As an alternative implementation of the embodiment of the present invention, the single authentication parameter includes: a random number or a timestamp.

[0115] As an alternative implementation of the embodiment of the present invention, before the participant sends a membership proof request to the administrator, the membership proof method provided by Embodiment 3 of the present invention further includes: the participant receives the evidence corresponding to the accumulative element sent by the administrator, and the random number and / or timestamp, and saves them locally.

[0116] Next, in combination with Figure 12 , the membership proof method provided by Embodiment 3 of the present invention will be further described:

[0117] 1. Initialize the accumulator. The administrator generates initial parameters (security parameters, hash function, and key k), collects the accumulative elements x sent by each participant i , and constructs a chained accumulator model.

[0118] 2. Send evidence. After the participant sends its accumulative element x i to the administrator, the participant will receive the "evidence - random number (or timestamp)" pair (w i , r i ) sent by the administrator, where w i = H(x i , H(k, r)) and saves it locally.

[0119] 3. Construct a membership proof request. The participant sends a verification request req = (x i ’, r i , w i ) to the administrator, where x i ’ is the accumulative element to be verified, r i is the random number (or timestamp) sent by the administrator, and w i is the evidence held by the participant.

[0120] 4. Evidence comparison. After receiving the request, the administrator constructs a membership proof w i ’ = H(x i ’, H(k, r i ))), where x i ’ is the accumulative element sent by the participant. If w i = w i ’, the membership proof is valid; if w i ≠ w i ’, the membership proof is invalid.

[0121] The significance of adding a random number (or timestamp) is that the administrator or the participant can publish val = H(k, r), enabling a third party to authenticate the validity of the evidence while avoiding exposing the information of the key.

[0122] It can be seen that through the membership proof method provided in Embodiment 3 of the present invention, a membership proof method based on a key is designed according to the characteristics of the accumulator. The membership proof based on the key introduces a secret parameter, which can verify the existence of elements simply and efficiently, improve the efficiency of membership proof, and the evidence does not need to be updated. On this basis, a random number (or timestamp) is added, which can be used as an auxiliary parameter in the proof process, enabling the administrator to let the evidence be verified by a third party without exposing the key information.

[0123] Based on the above chain accumulator construction device, Embodiment 3 of the present invention further provides a membership proof system. This membership proof system applies the membership proof method of Embodiment 3 above. Only a simple description of the structure of the membership proof system in Embodiment 3 is given below. For other matters not covered, please refer to the relevant descriptions in the membership proof method of Embodiment 3 above. See Figure 13 The membership proof system provided in Embodiment 3 of the present invention includes:

[0124] An administrator, who is used to construct a chain accumulator by using the above chain accumulator construction device, and generate a membership evidence w i of the accumulated element x i according to the preset key parameter k and single authentication parameter r i =H(x i , H(k, r i ));

[0125] A participant, who is used to send a membership proof request req=(x i ’, r i , w i ) to the administrator, where x i ’ is the accumulated element to be verified;

[0126] The administrator is also used to construct a membership proof w i ’=H(x i ’, H(k, r i )) after receiving the membership proof request. If w i =w i ’, the membership proof is valid; if w i ≠w i ’, the membership proof is invalid.

[0127] As an alternative implementation manner of an embodiment of the present invention, the single authentication parameter includes: a random number or a timestamp.

[0128] As an alternative implementation manner of an embodiment of the present invention, the participant is also used to receive the evidence corresponding to the accumulated element sent by the administrator, and the random number and / or timestamp, and save them locally before sending the membership proof request to the administrator.

[0129] It can be seen that through the membership proof system provided in Embodiment 3 of the present invention, a membership proof method based on a key is designed according to the characteristics of the accumulator. The membership proof based on the key introduces a secret parameter, which can verify the existence of elements simply and efficiently, improve the efficiency of membership proof, and the evidence does not need to be updated. On this basis, a random number (or timestamp) is added, which can be used as an auxiliary parameter in the proof process, enabling the administrator to allow the evidence to be verified by a third party without exposing the key information.

[0130] The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A membership proof method, characterized in that, comprising: The administrator groups the cumulative element set X at intervals of d to obtain the grouped cumulative element set X = {[x 1 , x 2 , …, x d , …, [x i·d+1 , x i·d+2 , … x n}, where n is the number of cumulative elements and i is the number of groups; the administrator constructs a chained accumulator according to the chained accumulator construction method; The administrator obtains the cumulative element x sent by the participant t , and generates a membership proof w for the cumulative element x t . The membership proof w = (w 1 , w 2 ), where w 1 = [H(x i*d ), H(x (i+1)*d )], w 2 = [x i*d , x i*d+1 ,..., x t ,..., x (i+1)d , where d represents the grouping interval, and w 1 represents the evidence node value of the cumulative value sequence at intervals of d on the cumulative value sequence, w 2 is the set of elements between two evidence nodes of the cumulative value sequence containing the element x, and H() is the hash calculation; The administrator sends the membership proof w of the cumulative element x t to the participant; The participant receives the accumulated element x t and the membership proof w of t , and performs verification according to a preset algorithm; wherein: The method for constructing a chained accumulator constructs a chained accumulator including: obtaining an element X to be accumulated i , and performing a hash calculation on the element X to be accumulated i and the current accumulated value H i-1 to obtain a new accumulated value H i . Taking the new accumulated value H i as the current accumulated value. When i = 1, the current accumulated value H i-1 is the initial value H 0 , where i is a positive integer greater than or equal to 1; constructing a chained accumulator, wherein the sequence of accumulated values in the chained accumulator includes, connected in sequence: H 0 , ……, H i .

2. The method according to claim 1, characterized in that, The step of hashing the element X to be accumulated i and the current accumulated value H i-1 includes: Hash the element X to be accumulated i or the element X to be accumulated i and splice it with the current accumulated value H i-1 Then perform a hash calculation on the spliced value.

3. The method according to claim 1 or 2, characterized in that, the preset algorithm includes: the Belongs algorithm.

4. A membership proof system, characterized in that, comprising: An administrator is used to group the set X of cumulative elements at an interval d to obtain a grouped cumulative element set X = {[x 1 , x 2 , …, x d , …, [x i·d+1 , x i·d+2 , … x n}, where n is the number of cumulative elements and i is the number of groups; construct a chained accumulator through a chained accumulator construction device; obtain the cumulative element x t sent by a participant, and generate a membership proof w for the cumulative element x t , where the membership proof w = (w 1 , w 2 ), w 1 = [H(x i*d ), H(x (i+1)*d )], w 2 = [x i*d , x i*d+1 ,..., x t ,..., x (i+1)d , where d represents the grouping interval, w 1 represents the cumulative value sequence evidence node value at an interval of d on the cumulative value sequence, w 2 is the set of elements between two cumulative value sequence evidence nodes containing the element x, and H() is a hash calculation; send the membership proof w of the cumulative element x t to the participant; The participant is used to receive the accumulated element x t and verify the membership proof w according to a preset algorithm; wherein: the chained accumulator construction device includes: Calculation module, configured to obtain the element X to be accumulated i , and perform a hash calculation on the element X to be accumulated i and the current accumulated value H i-1 to obtain a new accumulated value H i , and use the new accumulated value H i as the current accumulated value. When i = 1, the current accumulated value H i-1 is the initial value H 0 , where i is a positive integer greater than or equal to 1; A building block for building a chained accumulator, wherein the sequence of accumulated values in the chained accumulator includes, connected in sequence: H 0 , ……, H i .

5. The system according to claim 4, characterized in that, The computing module adds the element X to be accumulated in the following manner i and the current accumulated value H i-1 to perform a hash calculation: Hash the element X to be accumulated i or the element X to be accumulated i with the current accumulated value H i-1 to perform splicing and combination, and then perform hash calculation on the spliced and combined value.

6. The system according to claim 4 or 5, characterized in that, the preset algorithm includes: the Belongs algorithm.

Citation Information

Patent Citations

  • Communication method and device with memory function

    CN114553431A