A group signature method and a signature center group administrator node
By using the SM2 digital signature algorithm and a distributed multi-group administrator approach, users generate their own identifier private keys, which solves the problems of high computational overhead and vulnerability of single-group administrators in existing group signature schemes. This achieves efficient signature verification and signer privacy protection, and is suitable for scenarios such as blockchain, anonymous certificates, electronic cash, and electronic voting.
Patent Information
- Application Number
- CN202211279860.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-09-19
- Filing Date
- 2022-10-19
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2042-10-19
AI Technical Summary
Existing group signature schemes suffer from high computational overhead and trust issues due to the vulnerability of single group administrators to malicious attacks. They cannot effectively protect the privacy of signers and achieve efficient signature verification in a large-scale open network environment.
Employing the SM2 digital signature algorithm and a distributed multi-group administrator approach, users generate their own identifier private keys. The SM2 elliptic curve public key cryptography algorithm avoids bilinear pairing operations, thereby building a multi-group administrator system that reduces communication bandwidth and computational overhead, and allows for rapid tracing of the signer's identity in the event of a dispute.
It improves signature verification efficiency, protects signer privacy, and solves the problem of signer identity leakage caused by attacks on single-group administrators. It is suitable for scenarios that require strong privacy protection, such as blockchain, anonymous certificates, electronic cash, and electronic voting.
Smart Images

Figure CN115765983B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data encryption, and particularly relates to a group signature method and a signature center group administrator node. BACKGROUND
[0002] In the current digital economy era, new generation information technology such as blockchain, while reducing costs and improving data security, also faces problems of low operation efficiency and serious privacy leakage, which has attracted extensive attention of researchers. Digital signature is one of the key technologies to solve the above problems. Among them, group signature is more suitable for scenarios that need to be supervised, so in addition to being applied to scenarios such as electronic voting, digital currency systems and protecting user privacy, group signature can also be used in many fields such as electronic cash, trusted computing and vehicle ad hoc networks.
[0003] At present, the existing group signature method can usually realize certificateless signature, avoiding the huge certificate management overhead under the PKI system, and protecting the privacy of the signer by using group signature. However, the existing group signature scheme all adopts bilinear pair operation, which has high computational overhead. And most of the existing identity-based group signature schemes adopt single group administrator mode design scheme, and the private key of the group user is generated by the group administrator, without considering the trust problem caused by the fact that the group administrator is easy to be attacked maliciously in the current large-scale open network environment. The identity-based group signature algorithm scheme still needs further research in efficiency and privacy security. SUMMARY
[0004] In view of this, the embodiments of the present application provide a group signature method and a signature center group administrator node to eliminate or improve one or more defects in the prior art.
[0005] A first aspect of the present application provides a group signature method, comprising:
[0006] sending a unique identity identifier ID of itself in a distributed system and a first identifier L determined based on a random private key factor l to each group administrator node in a distributed group signature system, so that all group administrator nodes generate a second identifier h based on the unique identity identifier ID and the first identifier L by applying an SM2 digital signature algorithm, and each group administrator node generates a respective third sub-identifier d' i ;
[0007] generating a corresponding third identifier d based on each third sub-identifier d' i to obtain an identifier private key isk of itself containing the first identifier L, the second identifier h and the third identifier d, so as to sign and verify a target message based on the identifier private key isk and a master public key mpk of the group signature system.
[0008] In some embodiments of the present application, the unique identifier ID of the self in the distributed system and the first identifier L determined based on the random private key factor l are sent to each group administrator node in the distributed group signature system, so that all group administrator nodes generate a second identifier h based on the unique identifier ID and the first identifier L by applying the SM2 digital signature algorithm, and each group administrator node generates a respective third sub-identifier d' i , comprising:
[0009] Selecting a random private key factor l of the self, and generating a first identifier L based on the random private key factor l and a preset system parameter of the group signature system;
[0010] The unique identifier ID of the self in the distributed system and the first identifier L are sent to each group administrator node in the distributed group signature system, so that all group administrator nodes determine a random number ts based on the SM2 digital signature algorithm, and generate a corresponding second identifier h based on the random number ts, the first identifier L and the unique identifier ID, and each administrator node generates a respective third sub-identifier d' i based on the second identifier h and the respective master private key x i .
[0011] In some embodiments of the present application, the corresponding third identifier d is generated based on each third sub-identifier d' i , to obtain the identification private key isk of the self containing the first identifier L, the second identifier h and the third identifier d, so as to sign and verify the target message based on the identification private key isk and the master public key mpk of the group signature system, comprising:
[0012] Receiving the second identifier h and the respective third sub-identifier d' i of each group administrator node;
[0013] Generating a corresponding third identifier d based on the random private key factor l and each third sub-identifier d' i ;
[0014] Generating the identification private key isk of the self according to the first identifier L, the second identifier h and the third identifier d;
[0015] Constructing zero-knowledge proof of the identification private key isk for each administrator node to generate a verification identifier tH corresponding to the unique identifier ID according to the zero-knowledge proof, the first identifier L, the second identifier h and the random number ts, and each administrator node stores the corresponding relationship between the unique identifier ID and the verification identifier tH;
[0016] If a target message to be group signed is currently received, the target message is signed and verified based on the identity private key isk, a master public key mpk of the group signature system, and preset system parameters of the group signature system, to obtain a signature σ of the target message.
[0017] In some embodiments of the present application, the group signature system is constructed in advance according to security parameters λ, system parameters, and a plurality of hash functions, and the group signature system includes a plurality of group administrator nodes, each of which selects a master private key x i and publishes a sub-public key P pub-i to determine a master public key mpk of the group signature system based on the respective sub-public key P pub-i of each of the group administrator nodes.
[0018] In some embodiments of the present application, before the unique identity identifier ID of the distributed system and the first identity L determined based on the random private key factor l are sent to each group administrator node in the distributed group signature system, the method further includes:
[0019] sending the unique identity identifier ID of the distributed system and the verifiable claim IVC of the identity of the distributed system to the group administrator node in the group signature system through a secure channel, so that the group administrator node verifies the unique identity identifier ID based on the verifiable claim IVC, and issues a notification message of agreeing to join the group signature system if the verification is passed;
[0020] receiving the notification message to complete the member node registration in the group signature system.
[0021] In some embodiments of the present application, the first aspect provides a group signature method further including:
[0022] sending the signature σ of the target message and the target message to the verification node in the group signature system, so that the verification node verifies the validity of the signature σ of the target message based on the target message, the system parameters of the group signature system, and the master public key mpk, and outputs the corresponding verification result.
[0023] The second aspect of the present application provides a group signature method, including:
[0024] receiving, in a distributed group signature system, a unique identity identifier ID of a registered signature center member node in a distributed system and a first identity L of the signature center member node determined based on a random private key factor l;
[0025] generate a second identity h based on the unique identity identifier ID and the first identity L together with other group administrator nodes in the group signature system, and generate a third sub-identity d' corresponding to itself alone i ;
[0026] send the second identity h and the third sub-identity d' to the signature center member node, so that the signature center member node generates a corresponding third identity d based on each received third sub-identity d' i i to obtain an identity private key isk of the signature center member node containing the first identity L, the second identity h and the third identity d, so as to sign and verify a target message based on the identity private key isk and a master public key mpk of the group signature system.
[0027] In some embodiments of the present application, the group signature system further comprises a signature center member node, wherein the signature center member node comprises: i , comprising:
[0028] determining a random number ts based on the SM2 digital signature algorithm together with other group administrator nodes in the group signature system, and generating a corresponding second identity h based on the random number ts, the first identity L and the unique identity identifier ID;
[0029] generating a third sub-identity d' corresponding to itself according to a master private key x i of itself and the second identity h. i .
[0030] Another aspect of the present application also provides a signature center member node, comprising:
[0031] An identity application module is configured to send a unique identity identifier ID of itself in a distributed system and a first identity L determined based on a random private key factor l to each group administrator node in a distributed group signature system, so that all group administrator nodes generate a second identity h based on the unique identity identifier ID and the first identity L by applying an SM2 digital signature algorithm, and each group administrator node generates a third sub-identity d' corresponding to itself respectively i ;
[0032] A private key generation module is configured to generate a corresponding third identity d based on each third sub-identity d' i Generate a corresponding third identifier d, and obtain your own identifier private key isk containing the first identifier L, the second identifier h and the third identifier d, so as to sign and verify the target message based on the identifier private key isk and the master public key mpk of the group signature system.
[0033] Another aspect of this application also provides a signature center group administrator node, including:
[0034] The data receiving module is used to receive the unique identifier ID of the registered signature center member node in the distributed system and the first identifier L determined by the signature center member node based on the random private key factor l in the distributed group signature system.
[0035] The identifier generation module is used to work with other group administrator nodes in the group signature system to generate a second identifier h based on the unique identifier ID and the first identifier L, using the SM2 digital signature algorithm, and to independently generate its own corresponding third sub-identifier d′. i ;
[0036] The data transmission module is used to transmit the second identifier h and the third sub-identifier d′. i Send to the signature center member node, so that the signature center member node, based on the received third sub-identifiers d′, i Generate a corresponding third identifier d, and obtain the identifier private key isk of the signature center member node containing the first identifier L, the second identifier h and the third identifier d, so as to sign and verify the target message based on the identifier private key isk and the master public key mpk of the group signature system.
[0037] Another aspect of this application provides a group signature system, including:
[0038] The signature center member nodes are used to implement the group signature method provided in the first aspect mentioned above;
[0039] The signature center group administrator node is used to implement the group signature method provided in the second aspect mentioned above.
[0040] Another aspect of this application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the group signature method provided in the first aspect above, or to implement the group signature method provided in the second aspect above.
[0041] Another aspect of the present application also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the group signature method provided by the first aspect or the group signature method provided by the second aspect.
[0042] The group signature method provided by the present application adopts an identity-based signature, generates a user private key by using an identity, and avoids a huge certificate management cost under a PKI system. Compared with a digital signature scheme using a bilinear pair, the present application uses a national secret SM2 elliptic curve public key cryptography algorithm design scheme, avoids a high-time bilinear pair operation, and greatly improves the efficiency of signature verification. The present application designs a group signature scheme based on an SM2 identity digital signature algorithm to protect the privacy of a signer, and uses a distributed multi-group administrator mode to solve the problem that a single group administrator is attacked and the identity of a signer is leaked.
[0043] Additional advantages, objects, and features of the application will be set forth in part by the description that follows, and will become apparent to those skilled in the art upon examination of the following detailed description and drawings in which
[0044] Those skilled in the art will appreciate that the objects and advantages of the application can not be realized by the specific described above, and the above and other objects realized by the present application will be more clearly understood according to the following detailed description. BRIEF DESCRIPTION OF DRAWINGS
[0045] The drawings described herein are intended to provide further understanding of the present application, form a part of the present application, and do not constitute a limitation of the present application. The components in the drawings are not drawn to scale, but only to show the principles of the present application. In order to facilitate the illustration and description of some parts of the present application, the corresponding parts in the drawings can be enlarged, that is, they can become larger than other components in the exemplary device actually manufactured according to the present application. In the drawings:
[0046] Figure 1 The total flowchart of the first group signature method in an embodiment of the present application.
[0047] Figure 2 The total flowchart of the first group signature method in an embodiment of the present application.
[0048] Figure 3 The total flowchart of the second group signature method in an embodiment of the present application.
[0049] The total flowchart of the second group signature method in an embodiment of the present application.Figure 4 Structure diagram of a signature center member node in another embodiment of the present application.
[0050] Figure 5 Structure diagram of a signature center group administrator node in another embodiment of the present application.
[0051] Figure 6 Overall flow chart of a group signature scheme provided in an application example of the present application. DETAILED DESCRIPTION
[0052] In order to make the purpose, technical scheme and advantages of the present application clearer, the present application will be further described in detail below with reference to the embodiments and drawings. Herein, the illustrative embodiments of the present application and their descriptions are used to explain the present application, but not as a limitation to the present application.
[0053] It should be noted that, in order to avoid the present application being obscured by unnecessary details, only the structures and / or processing steps closely related to the scheme according to the present application are shown in the drawings, and other details not closely related to the present application are omitted.
[0054] It should be emphasized that the term "comprise / comprising" as used herein means the presence of stated features, elements, steps or components, but does not preclude the presence or addition of one or more other features, elements, steps or components.
[0055] It should be noted that, if not specifically stated, the term "connected" as used herein can not only mean direct connection, but also indirect connection with an intermediate.
[0056] In the following, the embodiments of the present application will be described with reference to the drawings. In the drawings, the same reference signs represent the same or similar parts, or the same or similar steps.
[0057] In today's era, data has become the most important production factor, and the sharing and circulation of data resources have become an important trend. How to protect user privacy as much as possible in the process of ensuring data security sharing and value is a key problem. The traditional digital signature algorithm does not take privacy as a security goal, and the identity of the signer is visible to the verifier, which cannot meet the privacy protection needs in some scenarios. For example, in the electronic voting system, the voter wants his vote to be legally verified without revealing his identity; in the digital currency system, the user wants the currency he spends to be verified by the system, but he does not want to explicitly point out the account address of the currency he spends. These scenarios require both identity authentication and protection of user privacy. Group signature and ring signature algorithms focus on user privacy protection and are proposed. They form a group of signers, and anyone in the group can generate a legal signature. The verifier can only verify that the signature is legal, but cannot confirm which user in the group generated the signature. However, the group in the ring signature is completely self-organized, and there is no third party to trace the identity of the signer in case of dispute. Although it provides a higher level of privacy protection, it is not suitable for scenarios that require supervision. For example, in 2016, Shen et al. proposed a blockchain secret transaction method based on ring signature. This method randomly selects an unrelated address and performs ring signature with the transaction initiator to achieve the purpose of confusing the identity of the transaction user. However, this method and the zero coin method both have the problem of poor traceability due to the disconnection of transaction association, making it difficult to apply in practical scenarios. In addition, the amount of information in a single transaction is too large, and the anonymity of the method depends on the number of addresses participating in the ring signature. To reduce the amount of transaction information, reducing the number of addresses will also face the risk of de-anonymization. The group signature system has a group administrator, and only the group administrator with the key can open the signature to trace the identity of the signer. Due to the good characteristics of privacy protection and traceability, group signature is not only applied to electronic voting, digital currency systems to protect user privacy, but also used in electronic cash, trusted computing, and vehicular ad hoc networks.
[0058] Currently, many identity-based group signature schemes have been proposed. In 2007, a short group signature scheme based on bilinear groups and fixed size in the standard model was proposed. In 2012, a practical identity-based group signature scheme was proposed. In 2012, non-interactive zero-knowledge proof theory was introduced, and a group signature scheme based on the BMW model was constructed using a combined order bilinear group. In 2019, a provably secure blockchain privacy protection scheme based on the SM9 algorithm was proposed, which hides and protects the identity of the transaction sender (signature node) in the highly open environment of the blockchain. These schemes all implement certificateless signature, avoiding the huge certificate management overhead under the PKI system, and protecting the privacy of the signer using group signature.
[0059] However, all the above group signature schemes employ bilinear pairing operations, resulting in high computational overhead. Furthermore, most existing identity-based group signature schemes adopt a single-group administrator design, where group users' private keys are generated by the group administrator. This fails to consider the trust issues arising from the vulnerability of group administrators to malicious attacks in today's large-scale open network environment. Therefore, identity-based group signature algorithms require further research in terms of efficiency and privacy security.
[0060] Based on this, this application studies a group signature algorithm that can protect the privacy of signers and effectively trace signatures in case of disputes. The proposed signature method can simultaneously solve the problems of low signature verification efficiency caused by the use of bilinear parallelism in existing group signature algorithms and the privacy leakage of signers caused by malicious attacks on single group administrators. It further improves the efficiency and privacy of group digital signature methods, making them more suitable for scenarios that require strong privacy protection, such as blockchain, anonymous certificates, electronic cash, and electronic voting.
[0061] The following examples will provide a detailed description.
[0062] In one or more embodiments of this application, the specific meanings of each parameter are shown in Table 1.
[0063] Table 1
[0064]
[0065]
[0066] Based on this, in order to effectively improve the efficiency and privacy of group digital signature schemes, embodiments of this application provide a first group signature method that can be executed by member nodes of a signature center, see [link to relevant documentation]. Figure 1 The first group signature method executed by the signature center member nodes specifically includes the following:
[0067] Step 100: Identify your unique identifier (ID) within the distributed system. a The first identifier L, determined based on the random private key factor l, is sent to each group administrator node in the distributed group signature system, so that all group administrator nodes generate a second identifier h based on the unique identifier ID and the first identifier L using the SM2 digital signature algorithm, and each group administrator node generates its own corresponding third sub-identifier d′. i .
[0068] In one or more embodiments of this application, the signature center member node can also be written as member or center member, for example: member A; correspondingly, the unique identifier ID for signature center member node A can be written as: ID aThe group administrator node can also be written as a group administrator or an administrator, and the identifier can be written as: SCM.
[0069] In step 100, member A selects a first identifier L = lP = (x L , y L ) as a random private key factor of itself and sends it to the SCM. All SCMs first agree on a random number , calculate h = H(ID a || L || ts), and then respectively calculate d′ i = x i h (mod h) and send it to member A.
[0070] Step 200: Based on each of the third sub-identifiers d′ i , a corresponding third identifier d is generated, and the identifier private key isk of itself containing the first identifier L, the second identifier h and the third identifier d is obtained, so as to sign and verify the target message based on the identifier private key isk and the master public key mpk of the group signature system.
[0071] In step 200, member A receives d′ i sent by each SCA, and locally calculates d = l + d′ = l + xh (mod n) to obtain the final identifier private key isk = (L, h, d).
[0072] As can be seen from the above description, the group signature method provided by the embodiments of the present application improves the identity digital signature algorithm based on the national standard SM2, proposes a multi-group administrator identity-based group signature method, avoids the cumbersome certificate management, avoids the high-time-consuming bilinear pair operation, and further reduces the communication bandwidth and the calculation overhead. The present application constructs a multi-group administrator based on a distributed system, and the user generates the identifier private key of himself, which avoids the risk of revealing the privacy of the signer due to the malicious attack on the single-group administrator, and solves the trust problem of the group administrator. Compared with the ring signature method, the signature method proposed in the present application can quickly trace the identity of the signer when a dispute occurs while protecting the privacy of the signer. Therefore, the present application has stronger practicability and can better meet the privacy protection requirements in various highly open scenarios such as blockchains and electronic cashes.
[0073] In order to further improve the efficiency of the group signature, in the first group signature method executed by the signature center member node provided in an embodiment of the present application, referring to Figure 2 , step 100 in the first group signature method executed by the signature center member node further specifically contains the following contents:
[0074] Step 110: select a random private key factor l of itself, and generate a first identifier L based on the random private key factor l and preset system parameters of the group signature system.
[0075] Step 120: send a unique identity identifier ID of itself in the distributed system and the first identifier L to each group administrator node in the distributed group signature system, so that all group administrator nodes determine a random number ts based on the SM2 digital signature algorithm first, and generate a corresponding second identifier h based on the random number ts, the first identifier L and the unique identity identifier ID, and each of the administrator nodes generates a corresponding third sub-identifier d' according to the respective master private key x i and the second identifier h. i .
[0076] In order to further improve the security, credibility and traceability of the group signature, in the first group signature method executed by the signature center member node provided in the embodiment of the application, referring to Figure 2 , the step 200 of the first group signature method executed by the signature center member node further specifically contains the following contents:
[0077] Step 210: receive the second identifier h and the respective third sub-identifier d' of each of the group administrator nodes i .
[0078] Step 220: generate a corresponding third identifier d based on the random private key factor l and each of the third sub-identifier d' i .
[0079] Step 230: generate the identity private key isk of itself according to the first identifier L, the second identifier h and the third identifier d;
[0080] Step 240: construct the zero-knowledge proof of the identity private key isk for each of the administrator nodes to generate the verification identifier tH corresponding to the unique identity identifier ID according to the zero-knowledge proof first identifier L, the second identifier h and the random number ts, and each of the administrator nodes stores the corresponding relationship between the unique identity identifier ID and the verification identifier tH.
[0081] Among them, the verification identifier tH of the signature center member node A can be written as: tH a .
[0082] Step 250: if a target message to be group signed is currently received, sign and verify the target message based on the identity private key isk, the master public key mpk of the group signature system and the preset system parameters of the group signature system, to obtain the signature σ of the target message.
[0083] To further improve the application reliability and effectiveness of the group signature method, in a first group signature method executed by a signature center member node provided in an embodiment of the present application, the group signature system is constructed in advance according to a security parameter λ, system parameters and a plurality of hash functions, and the group signature system contains a plurality of group administrator nodes, each of the group administrator nodes selects a master private key x i and publishes a sub-public key P pub-i , so as to determine a master public key mpk of the group signature system based on the respective sub-public keys P pub-i corresponding to each of the group administrator nodes.
[0084] To further improve the application reliability and effectiveness of the group signature method, in a first group signature method executed by a signature center member node provided in an embodiment of the present application, referring to Figure 2 , the first group signature method executed by the signature center member node further specifically contains the following content before step 100:
[0085] Step 010: sending a unique identity identifier ID of itself in the distributed system and a verifiable statement IVC of the identity of itself to a group administrator node in the group signature system through a secure channel, so that the group administrator node verifies the unique identity identifier ID based on the verifiable statement IVC, and issues a notification message of agreeing to join the group signature system if the verification is passed.
[0086] Among them, the verifiable statement IVC of the signature center member node A can be written as: IVC a .
[0087] Step 020: receiving the notification message to complete the member node registration of itself in the group signature system.
[0088] To further improve the application reliability and effectiveness of the group signature method, in a first group signature method executed by a signature center member node provided in an embodiment of the present application, referring to Figure 2 , the first group signature method executed by the signature center member node further specifically contains the following content after step 200:
[0089] Step 300: sending the signature σ of the target message and the target message to a verification node in the group signature system, so that the verification node verifies the validity of the signature σ of the target message based on the target message, the system parameters of the group signature system and the master public key mpk, and outputs the corresponding verification result.
[0090] To effectively improve the efficiency and privacy of the group digital signature scheme, a second group signature method executable by a signature center group administrator node is provided in an embodiment of the present application, referring to Figure 3The second group signature method executed by the signature center group administrator node specifically includes the following:
[0091] Step 400: In the distributed group signature system, receive the unique identifier ID of the registered signature center member node in the distributed system and the first identifier L determined by the signature center member node based on the random private key factor l;
[0092] Step 500: Together with other group administrator nodes in the group signature system, generate a second identifier h using the SM2 digital signature algorithm based on the unique identifier ID and the first identifier L, and independently generate its own corresponding third sub-identifier d′. i .
[0093] Step 600: Combine the second identifier h and the third sub-identifier d′ i Send to the signature center member node, so that the signature center member node, based on the received third sub-identifiers d′, i Generate a corresponding third identifier d, and obtain the identifier private key isk of the signature center member node containing the first identifier L, the second identifier h and the third identifier d, so as to sign and verify the target message based on the identifier private key isk and the master public key mpk of the group signature system.
[0094] The second group signature method executed by the signature center group administrator node provided in this application has a data interaction process with the first group signature method executed by the signature center member node. Specifically, from the overall interaction flow, steps 400 to 600 can be executed between steps 100 and 200. The second group signature method executed by the signature center group administrator node has the same function as the first group signature method executed by the signature center member node mentioned above. Its function will not be repeated here, but can be referred to the detailed description of the above group signature method embodiment.
[0095] From a software perspective, in order to effectively improve the efficiency and privacy of group digital signature schemes, this application also provides a signature center member node for executing all or part of the first group signature method, see [link to relevant documentation]. Figure 4 The signature center member node specifically includes the following:
[0096] The identification application module 10 is used to send its unique identifier ID in the distributed system and a first identifier L determined based on a random private key factor l to each group administrator node in the distributed group signature system, so that all group administrator nodes generate a second identifier h based on the unique identifier ID and the first identifier L using the SM2 digital signature algorithm, and each group administrator node generates its own corresponding third sub-identifier d′.i ;
[0097] The private key generation module 20 is configured to generate a corresponding third identifier d based on each third sub-identifier d' i The private key generation module 20 is configured to generate a corresponding third identifier d based on each third sub-identifier d'
[0098] The signature center member node provided in the embodiments of the present application can be specifically used to execute the processing procedure of the first group signature method in the above-mentioned embodiments, and the functions thereof will not be repeated here, and the detailed description can be referred to the detailed description of the first group signature method.
[0099] As can be known from the above description, the signature center member node provided in the embodiments of the present application improves the identity digital signature algorithm based on the national standard SM2, and proposes a multi-group administrator identity-based group signature method, which avoids the cumbersome certificate management and the high-time-consuming bilinear pair operation, and further reduces the communication bandwidth and the calculation cost. The present application constructs a multi-group administrator based on a distributed system, and the user generates his own identity private key by himself. This way avoids the risk of revealing the privacy of the signer due to malicious attacks on the single-group administrator, and solves the trust problem of the group administrator. Compared with the ring signature method, the method proposed in the present application can quickly trace the identity of the signer when a dispute occurs while protecting the privacy of the signer. Therefore, the present application has stronger practicability and can better meet the privacy protection needs in various highly open scenarios such as blockchains and electronic cash.
[0100] From the software level, in order to effectively improve the efficiency and privacy of the group digital signature scheme, the present application further provides a signature center group administrator node for executing all or part of the second group signature method, as shown in Figure 5 , the signature center group administrator node specifically includes the following contents:
[0101] The data receiving module 40 is configured to receive, in the distributed group signature system, a unique identity identifier ID of a registered signature center member node in the distributed system and a first identifier L determined by the signature center member node based on a random private key factor l;
[0102] The identity generation module 50 is configured to generate a second identifier h based on the unique identity identifier ID and the first identifier L together with other group administrator nodes in the group signature system, and to generate a corresponding third sub-identifier d' of itself i ;
[0103] The data sending module 60 is configured to send the second identifier h and the third sub-identifier d'i to the signature center member node, so that the signature center member node generates a corresponding third identifier d based on the received each third sub-identifier d' i generates a corresponding third identifier d, and obtains an identifier private key isk of the signature center member node containing the first identifier L, the second identifier h and the third identifier d, to sign and verify a target message based on the identifier private key isk and a master public key mpk of the group signature system.
[0104] The embodiment of the signature center group administrator node provided in the application can be specifically used to execute the processing flow of the embodiment of the second group signature method in the above-described embodiment, and the function thereof will not be repeated here. Please refer to the detailed description of the above-described embodiment of the second group signature method.
[0105] The part of the signature center group administrator node for group signature can be executed in a server, and in another actual application scenario, all operations can also be completed in a client device. Specifically, the processing capacity of the client device and the limitation of the user's use scenario can be selected. The application does not limit this. If all operations are completed in the client device, the client device can also include a processor for specific processing of group signature.
[0106] The above-mentioned client device can have a communication module (i.e. a communication unit), which can be connected with a remote server to realize data transmission with the server. The server can include a server of the task scheduling center side, and the server of other implementation scenarios can also include a server of an intermediate platform, such as a server of a third-party server platform which is communicatively linked with the server of the task scheduling center. The server can include a single computer device, or a server cluster composed of multiple servers, or a server structure of a distributed device.
[0107] The server and the client device can use any suitable network protocol for communication, including a network protocol which has not been developed at the filing date of the application. The network protocol can include TCP / IP protocol, UDP / IP protocol, HTTP protocol, HTTPS protocol, etc. Of course, the network protocol can also include RPC protocol (Remote Procedure Call Protocol) and REST protocol (Representational State Transfer) used on the above-mentioned protocols.
[0108] From the above description, the signature center group administrator node provided by the embodiment of the application improves the identification digital signature algorithm based on the national secret SM2, proposes an identity-based group signature method of multiple group administrators, avoids the high-time-consuming bilinear pair operation while avoiding the cumbersome certificate management, and further reduces the communication bandwidth and the calculation overhead. The application constructs multiple group administrators based on a distributed system, and the user generates the own identification private key by oneself. This way avoids the risk that the privacy of the signer is leaked due to the malicious attack on the single group administrator, and solves the trust problem of the group administrator. Compared with the ring signature method, the method proposed in the application can quickly trace the identity of the signer when a dispute occurs while protecting the privacy of the signer. Therefore, the application has stronger practicability and can better meet the privacy protection requirements in various highly open scenarios such as blockchains and electronic cashes.
[0109] Based on the foregoing embodiments of the first group signature method and the second group signature method, the application further provides a group signature system, which specifically includes the following contents:
[0110] The signature center member node is used to implement the foregoing first group signature method.
[0111] The signature center group administrator node is used to implement the foregoing second group signature method.
[0112] In order to further illustrate the scheme, the application further provides a specific application example of a group signature method, specifically a group signature algorithm method based on a distributed system and a national secret SM2 identification signature, which includes system establishment, a signature algorithm, a verification algorithm, and an opening algorithm, as shown in Figure 6 The system establishment includes system initialization Setup, master key generation MKeyGen, and key center member registration Join, which are used to establish a group signature system. The key center member key extraction process is used to generate an identification key for the key center member, and the signature Sign algorithm is used to generate a message signature. The verification Verify algorithm is used to verify the correctness of the message signature, and the opening Open algorithm is used for the group administrator to trace the identity of the signer by tracing the key when a dispute occurs. The application also provides the correctness proof of the algorithm and the proofs of the several security features of the algorithm, including unforgeability, resistance to malicious SCM attacks, anonymity, inalienability, traceability, and resistance to conspiracy attacks. The specific descriptions are as follows:
[0113] (I) System establishment SysGen
[0114] (1) Initialization Setup: input the security parameter λ, and output the system parameter (q, F q , a, b, n, G, P), wherein q is a large prime number randomly selected, F q is a finite field containing q elements; a and b are F qElements in the middle are used to define F q An elliptic curve E in the above G is a cyclic group of prime order n (n>2 191 And n>4p 1 / 2 ), P is the generator of G, that is, a base point on the elliptic curve E, and satisfies nP=O (O is the point at infinity). At the same time, select three secure hash functions:
[0115]
[0116]
[0117]
[0118] (2) Master key generation MKeyGen: Suppose the system has M signature center managers (Signature Center Managers, SCM), and each SCM randomly selects Calculate P pub-i =x i P (mod n). Where i represents the ith SCA, i∈[1, M], each SCM secretly holds its own x i And P pub-i is publicly known, and the signature verification master public key is mpk:
[0119] (3) Key center member registration Join: Joining the signature center (Signature Center, SC) requires member registration. User A sends the unique identifier ID a On the blockchain together with the verifiable statement IVC a Of its identity to the SCM through a secure channel, and the SCM verifies the identity ID a Of user A based on IVC a , and agrees to join if there is no error.
[0120] (II) Center member key analysis Extract
[0121] The algorithm input group master public key mpk, master private key x and user identity information ID a . First, member A selects As his own random private key factor, calculate L=lP=(x L , y L ) and send it to the SCM. All SCMs first agree on a random number Calculate h=H(ID a ||L||ts), then calculate d′ i =x i h (mod n) and send it to member A.
[0122] Member A receives d' from each SCA i , at the local computer d = 1 + d' = 1 + xh (mod n), and the final identity private key isk = (L, h, d). The center member A constructs zero-knowledge proof of identity private key by non-interactive Sigma protocol Anyone can verify the correctness of his isk. The SCM calculates Each SCM stores (ID a , tH a ).
[0123] (Three) Signature Sign
[0124] Suppose member A needs to sign a message m, the algorithm input is the group's master public key mpk, user identity private key isk = (L, h, d) and message m. Calculate and where ENTLA is the bit length of ID a (x P , y P ) and (x L , y L ) are the horizontal and vertical coordinates of P and L respectively. Randomly select Calculate K = kP = (x K , y K ) and r = (e + x K ) (mod n). If r = 0 or r + k = n, then reselect k and recalculate, otherwise calculate s = (1 + d) -1 (k - rd) (mod n). If s ≠ 0, output the signature σ = (L, h, r, s) of the message m.
[0125] (Four) Verification Verify
[0126] The verifier receives the message m, the center master public key mpk he holds, and the signature σ = (L, h, r, s) to be verified, and judges:
[0127] (1) If , output 0;
[0128] (2) Otherwise, calculate t = r + s (mod n). If t = 0, output 0;
[0129] (3) Otherwise, calculate K' = sP + t (L + hP pub ) = (x' K , y' K ) and r' = (e' + x' K). If r' = r, output 1, otherwise output 0. Output 1 means the signature is valid, otherwise invalid.
[0130] (V) Open Open
[0131] When a member joins the signature center, the SCM needs to jointly verify the identity and bind the member's key pair with the identity ID, which is convenient for tracking the user's identity and checking whether the user's key is updated / revoked in case of disputes. When the identity of the signer needs to be verified, the SCM first verifies whether the signature is valid, and if it is valid, inputs L, h and the tracking private key ts, which can find the matching ID in ((ID, tH)) saved during the key generation process. If the matching ID exists, the user's identity can be determined.
[0132] (VI) Security Proof
[0133] (1) Correctness
[0134] Theorem 1: The signature method proposed in this application is correct.
[0135] Correctness, that is, to ensure that the honestly generated signature can be correctly verified and tracked.
[0136] If all algorithms are performed according to the steps, the verifier outputs that the signature is valid, because:
[0137] r = (e + x K ) (mod n)
[0138] s = (1 + d) -1 (k - rd) (mod n)
[0139] t = r + s (mod n)
[0140] L = lP = (x L , y L )
[0141]
[0142]
[0143] K = kP
[0144] To prove that the signature is valid, only need to prove r' = r, only need to prove x' = x K K , and only need to prove:
[0145]
[0146] That is,
[0147] (x' = x K , y' = y K ) = (xK , y K ), x' K = x K , y' K = y K
[0148] So
[0149] r' = r, correctness is proved.
[0150] (2) Unforgeability
[0151] Definition 1. If the adversary A has at least advantage ∈ in the simulated attack game, the running time is at most t, and the maximum number of extraction queries and signature queries are q E and q S respectively, it is called (∈, t, q E , q S )-forgeable based on identity signature method. If there is no (∈, t, q E , q S ), the method is called (∈, t, q E , q S )-secure.
[0152] Theorem 2. Assuming that the hash function H is a random oracle, if the ECDLP (Elliptic Curve Discrete Logarithm Problem) is difficult, our signature method is (∈, t, q E , q S )-secure, which can resist EU-CM-IDB-A (Existential Unforgeability under Adaptive Chosen Message and Identity Based Attack).
[0153] Proof: We will assume that our method has a PPT (Probabilistic Polynomial Time) adversary We will construct an algorithm to simulate the challenger. Our method is to define as the adversary attacking EU-CMA (Existential Unforgeability under Adaptive Chosen Message Attack) in the simulation game of the scheme. Control the random oracle and execute the request of , his working principle is as follows:
[0154] Establish: Randomly select x' ∈ [1, n-1], calculate msk = P' pub Then return to
[0155] Query: The running adversary can make queries including extraction and signature. The following is the way to answer.
[0156] Extract query: consider querying the hash value of the user identity ID i and the private key. From randomly select a number, then calculate L i (here it is assumed that SCM is 1, and the case of multiple SCMs will be analyzed below, in fact, multiple SCMs will make the difficulty of the attacker's attack multiplied) based on L i and calculate h i = H(ID i || L i || r), and then calculate d i , (h i , L i , d i ) is returned to
[0157] Sign query: consider the signature query of ID i about the message m i , randomly select then execute the signature query in the method simulation attack game, calculate r i = h(Z i || m i ) + x k mod n, and s i = (k-r i d i ) / (1+d i ) mod n, where Z i is other related information known to be determined in the signature algorithm. Finally, (ID i , m i , σ i ) is returned to
[0158] Forgery: after querying the above two types for a polynomial time, the adversary selects user ID *
[0159] ( i∈[q E ]) generates (h * , L * , d * ), and then selects a message m * ( i∈[q S ]) and executes Output a fake signature σ in the challenge phase of the game * = (r * , s * ). Next, we prove that the advantage of a fake signature being valid can be ignored under the assumption that the hash function h is unique and collision-resistant.
[0160] Analysis: The randomness of the simulation includes all random numbers in key generation and query responses, and is independent of the adversary's point of view. Therefore, the simulation is indistinguishable from the actual attack. Next, we analyze the proof that the advantage of a fake signature being valid and the time cost t can be ignored under this assumption.
[0161]
[0162]
[0163] The time consumption it takes is t = t0+ q E t E + q S t S , where t E and t S are the times for B to simulate a single extraction query and signature, respectively. Because scholars have proven in the literature that the SM2 digital signature algorithm satisfies EUF-CMA, this application also satisfies EU-CMA. In fact, because ID * = ID i , it means that A needs to find a collision of the hash function (ID i || L i || ts i , ID * || L || ts). Under the assumption that h is a random oracle and the ECDLP problem is difficult, this can only occur with negligible probability. Therefore, this application also satisfies EUF-CM-IDB-A.
[0164] Theorem 3. This scheme can resist strong malicious SCM attacks.
[0165] In the signature method of this application, the number of SCMs k >= 1, and in general case there are multiple k. This way can effectively resist malicious SCM attacks. Assume that the enemy is a malicious SCM in this method, which knows the center member's key factor ts and its own possession x i . In this scheme, because the system parameters required by the method are maintained by multiple SCMs, ts is agreed by all SCMs, while x iOnly himself knows, by user signature private key, each SCM in the case of not getting user private key and user random private key factor, only can solve with own hold x i Related d' i = x i h(modn), there is a one-way algorithm of the hash function and the double difficulty of solving discrete logarithm on the elliptic curve, so that the enemy can get ts and any one x i It is difficult to get the user private key. Therefore, this method can resist strong malicious SCM attack.
[0166] (3) Other security features
[0167] Anonymity: since l is randomly generated by SCMs and SC members. h = H(ID a || L || ts), L = IP, the algorithm for user identity ID processing contains one-way algorithm of the hash function and discrete logarithm problem on the elliptic curve, that is, without the help of SCM, the attacker cannot restore the identity of the signer after signing the message.
[0168] Traceability: SCM can open any valid group signature based on the tracking key ts, prove that the signer indeed produced the signature, and match the corresponding ID from the list. In addition, from theorem 3, as long as there is any trusted SCM, it can ensure that all signatures, even those created by multiple users and SCMs, can be traced to the member who forged the signature as long as any trusted SCM exists.
[0169] Non-associativity: in the signature algorithm, because the signature center member uses the public key mpk of SCM to sign the message, when signing, r = (e + x K )(modn), s = (1 + d) -1 (k-rd)(modn), where x K : K = kP = (x K , y K ), Given k i P and k j P, it is difficult to determine that they correspond to the same kP in calculation without knowing k i and k j . It is difficult for the enemy to determine whether two different signatures are signed by the same center member without knowing the tracking key, realizing the non-associativity of the signature.
[0170] Anti-collusion attack: the identification private key of the center member is only held by the member himself, he only publicly proves the zero-knowledge proof of his own identification private key to everyone, and multiple SCMs jointly endorse the SC signature list, and any one SCM (or colludes with other members) cannot tamper with the ID of a member and the corresponding signature information. Combined with theorem 3, we can infer that the set of the member subset of the SC (even if it is composed of the entire SC member) cannot produce valid signatures that cannot be tracked by the SCM.
[0171] (Seven) beneficial effects brought by the present application
[0172] The signature method of the present application is improved based on the SM2 algorithm. Except for the initialization parameter and key generation, the signature and verification steps are basically the same, so the calculation cost is basically the same as the SM2 digital signature algorithm. In order to protect the identity information of the signer, the present application designs an ID-based SM2 group signature method, which realizes anonymous signature under the premise of maintaining efficiency, and can effectively protect the privacy of the signer.
[0173] Specifically, the following (1) and (2) mainly compare the communication cost and calculation overhead of the existing group signature method and the signature method designed by the present application. In order to achieve a security level of lamda=128, for the existing group signature method, the bilinear pair operation on the elliptic curve is used, and the present application uses the BN (Barreto Naehrig) curve on the elliptic curve GF(p) (256-bit coefficient p, k=12) (uses the third type of bilinear pair G2*G1=GT) to test and evaluate it; for the signature method proposed by the present application, according to the SM2 national secret algorithm standard suggestion, a 256-bit GF(p) elliptic curve (p has no special form) is used.
[0174] Among them, the existing group signature method refers to the improvement of the SM9 identity-based encryption algorithm by Yang et al. in 2019, which proposes a multi-KGC group signature method based on identity authentication. This application protects the identity of the signature user through multi-KGC group signature, realizes identity authentication between nodes, protects the privacy of the signer, and can avoid the leakage of the information of the signer due to malicious KGC attack. Although this application improves the operation efficiency, it still uses the time-consuming bilinear pair operation, which is difficult to effectively deal with the scene with large number of signatures.
[0175] (1) Calculation overhead analysis
[0176] To compare the computational overhead of the existing group signature method protocol and the protocol designed in this application, the time consumption of the relevant operations of the protocol is first tested. The test environment is: on a 2.4 GHz Intel i5 520 single-core processor, using GCC compilation, using standard / O2 compiler optimization. The running time of each operation is calculated by the number of iterations within 1s using the Miracl library, and the unit is millisecond. The corresponding symbols and running times are shown in Table 2.
[0177] Table 2 Execution time benchmark of different encryption operations
[0178]
[0179]
[0180] (2) The types and numbers of operations of the two comparative protocol designs are first counted, and then the computational overhead of each stage and each role is calculated (as shown in Table 3) in combination with the time consumption of each operation in Table 2. The key generation stage includes group key generation and user identification key generation. The total time consumption of the protocol of the existing group signature method is 0.6707 milliseconds, and the time consumption of the protocol of this application is 2.1256 milliseconds; in the signature stage, the time consumption of the protocol of the existing group signature method is 1.6203 milliseconds, and the time consumption of the protocol of this method is 1.0655 milliseconds; in the signature verification stage, the time consumption of the protocol of the existing group signature method is 7.9512 milliseconds, and the time consumption of the protocol of this method is 1.4087 milliseconds. It can be seen that, compared with the literature, the computational overhead of the protocol of this method is still high in the key generation stage, and since the key generation stage is only performed once, this cost can be accepted; however, the algorithm has a great improvement in the signature stage, especially in the verification stage, which is reduced by about 34.24% in the signature stage and by 82.28% in the verification stage. This is mainly because the protocol designed in this application does not involve high-time-consuming bilinear pair operations. In addition, the protocol designed in this application, like the protocol of the existing group signature method, is an identity-based signature protocol, which avoids the huge certificate management overhead under the PKI system and has stronger practicability.
[0181] Table 3 Comparison and analysis of the overhead of the signature method
[0182]
[0183]
[0184] In summary, the core improvement content of the application example is as follows:
[0185] The application improves the identity digital signature algorithm based on the national secret SM2 in combination with a distributed system, and proposes a multi-group administrator identity-based group signature method, which avoids the cumbersome certificate management and the high-time-consuming bilinear pair operation, and further reduces the communication bandwidth and the calculation cost. The application constructs a multi-group administrator based on a distributed system, and the user generates his own identity private key by himself. This way avoids the risk of revealing the privacy of the signer due to the malicious attack on the single-group administrator, and solves the trust problem of the group administrator. Compared with the ring signature method, the signature method proposed in the application can quickly trace the identity of the signer when a dispute occurs while protecting the privacy of the signer. Therefore, the application has stronger practicability and can better meet the privacy protection requirements in various highly open scenarios such as blockchains and electronic cash.
[0186] Compared with the certificate-based digital signature method, the application adopts the identity-based signature, generates the user private key by using the identity identifier, and avoids the huge certificate management cost under the PKI system. Compared with the digital signature method using the bilinear pair, the application uses the national secret SM2 elliptic curve public key cryptography algorithm design method, avoids the high-time-consuming bilinear pair operation, and greatly improves the efficiency of signature verification.
[0187] The application designs a group signature method based on the SM2 identity digital signature algorithm to protect the privacy of the signer, and adopts a distributed multi-group administrator mode to solve the trust problem of the group administrator in a large-scale open environment. The user generates his own signature private key by himself, which can effectively solve the problem of revealing the identity of the signer due to the attack on the single-group administrator.
[0188] The electronic device (i.e., an electronic device) provided in the application embodiment can include a processor, a memory, a receiver and a transmitter. The processor is used to execute the first group signature method or the second group signature method mentioned in the above-mentioned embodiments. The processor and the memory can be connected through a bus or other means to be connected through the bus. The receiver can be connected with the processor and the memory through a wired or wireless manner. The electronic device can receive real-time motion data from the sensors in the wireless multimedia sensor network, and receive original video sequences from the video acquisition device.
[0189] The processor can be a central processing unit (CPU). The processor can also be other general-purpose processors, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, or a combination of the above.
[0190] The memory, as a non-transitory computer readable storage medium, can be used to store non-transitory software programs, non-transitory computer executable programs and modules, such as program instructions / modules corresponding to the first group signature method or the second group signature method in the embodiments of the present application. The processor executes various functions and data processing of the processor by running the non-transitory software programs, instructions and modules stored in the memory, that is, implements the first group signature method or the second group signature method in the method embodiments.
[0191] The memory can include a program storage area and a data storage area. The program storage area can store an operating system and application programs required by at least one function; the data storage area can store data created by the processor and the like. In addition, the memory can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory can optionally include a memory remotely arranged with respect to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0192] The one or more modules are stored in the memory and, when executed by the processor, perform the first group signature method or the second group signature method in the embodiments.
[0193] In some embodiments of the present application, a user equipment can include a processor, a memory and a transceiver which can include a receiver and a transmitter, the processor, the memory, the receiver and the transmitter can be connected through a bus system, the memory is used to store computer instructions, and the processor is used to execute the computer instructions stored in the memory to control the transceiver to transceive signals.
[0194] As an implementation manner, the functions of the receiver and the transmitter in the present application can be realized by a transceiving circuit or a dedicated chip for transceiving, and the processor can be realized by a dedicated processing chip, a processing circuit or a general-purpose chip.
[0195] As another implementation manner, the server provided by the embodiments of the present application can be implemented by using a general computer. That is, program codes for implementing the functions of the processor, the receiver and the transmitter are stored in the memory, and the general processor implements the functions of the processor, the receiver and the transmitter by executing the codes in the memory.
[0196] The embodiments of the present application further provide a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the steps of the first group signature method or the second group signature method. The computer readable storage medium can be a tangible storage medium, such as a random access memory (RAM), a memory, a read only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a floppy disk, a hard disk, a removable memory disk, a CD-ROM, or any other form of storage medium known in the art.
[0197] Those skilled in the art should understand that the exemplary components, systems and methods described in connection with the embodiments disclosed herein can be implemented in hardware, software or a combination thereof. The actual implementation depends on the specific application and design constraints imposed on the overall system. Those skilled in the art can use various methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, etc. When implemented in software, the elements of the present application are program or code segments used to perform the required tasks. The program or code segments can be stored in a machine readable medium or transmitted through a data signal carried in a carrier wave in a transmission medium or a communication link.
[0198] It should be noted that the present application is not limited to the specific configurations and processes described above and shown in the drawings. For the sake of brevity, the detailed descriptions of known methods are omitted herein. In the above embodiments, several specific steps are described and shown as examples. However, the method processes of the present application are not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order of the steps, after understanding the spirit of the present application.
[0199] In the present application, the features described and / or illustrated for one embodiment can be used in the same way or in a similar way in one or more other embodiments, and / or in combination with or instead of features of other embodiments.
[0200] The above descriptions are only the preferred embodiments of the present application, and are not intended to limit the present application. The embodiments of the present application can be variously changed and modified by those skilled in the art. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the scope of protection of the present application.
Claims
1. A group signature method characterized by comprising: The method comprises the following steps: Send the unique identity identifier ID of itself in the distributed system and the first identification L determined based on the random private key factor l to each group administrator node in the distributed group signature system, so that all group administrator nodes generate the second identification h based on the unique identity identifier ID and the first identification L by applying the SM2 digital signature algorithm, and each group administrator node generates a respective corresponding third sub-identification d' i ; based on each of the third sub-identifiers d' i generating a corresponding third identifier d, obtaining an identifier private key isk of itself containing the first identifier L, the second identifier h and the third identifier d, to sign and verify a target message based on the identifier private key isk and a master public key mpk of the group signature system; Wherein, the third sub-identifier d′ is used as the basis for each of the above. i Generate a corresponding third identifier d, and obtain your own identifier private key isk containing the first identifier L, the second identifier h, and the third identifier d. Then, based on this identifier private key isk and the master public key mpk of the group signature system, sign and verify the target message, including: receiving the second identity h and a third sub-identity d' corresponding to each of the group administrator nodes i ; based on the random private key factor l and each of the third sub-identifiers d ′ generating a corresponding third identifier d; generating an identity private key isk according to the first identity L, the second identity h and the third identity d; constructing zero-knowledge proof of the identity private key isk for each of the administrator nodes to generate a verification identity tH corresponding to the unique identity identifier ID according to the zero-knowledge proof, the first identity L, the second identity h and a random number ts, and each of the administrator nodes stores the corresponding relationship between the unique identity identifier ID and the verification identity tH; if a target message to be group signed is currently received, signing and verifying the target message based on the identity private key isk, the master public key mpk of the group signature system and the preset system parameters of the group signature system to obtain the signature σ of the target message.
2. The group signature method according to claim 1, characterized by, The unique identifier ID of the self in the distributed system and the first identifier L determined based on the random private key factor l are sent to each group administrator node in the distributed group signature system, so that all group administrator nodes generate a second identifier h based on the unique identifier ID and the first identifier L by applying the SM2 digital signature algorithm, and each group administrator node generates a respective third sub-identifier d' i , comprising: selecting a random private key factor l and generating a first identity L based on the random private key factor l and the preset system parameters of the group signature system; send the unique identity identifier ID and the first identity L to each group administrator node in the distributed group signature system, so that all group administrator nodes first determine a random number ts based on the SM2 digital signature algorithm, and generate a corresponding second identity h based on the random number ts, the first identity L and the unique identity identifier, and then each group administrator node generates a corresponding third sub-identity d' according to the respective master private key x i and the second identity h respectively i .
3. The group signature method according to claim 1 or 2, characterized by, The group signature system is constructed in advance according to a security parameter λ, system parameters and a plurality of hash functions, and the group signature system comprises a plurality of group administrator nodes, each of the group administrator nodes selects a master private key x i and publishes a sub-public key P pub-i , so as to determine a master public key mpk of the group signature system based on the respective sub-public key P pub-i corresponding to each of the group administrator nodes.
4. The group signature method according to claim 3, characterized by, before the unique identity identifier ID of the self in the distributed system and the first identity L determined based on the random private key factor l are sent to each group administrator node in the distributed group signature system, the method further comprises the following steps: sending the unique identity identifier ID of the self in the distributed system and the verifiable claim IVC of the self identity to the group administrator node in the group signature system through a secure channel, so that the group administrator node verifies the unique identity identifier ID based on the verifiable claim IVC, and sends a notification message of agreeing to join the group signature system if the verification is passed; receiving the notification message to complete the member node registration of the self in the group signature system.
5. The group signature method according to claim 1, wherein, The method further comprises the following steps: sending the signature σ of the target message and the target message to the verification node in the group signature system, so that the verification node verifies the validity of the signature σ of the target message based on the target message, the system parameters of the group signature system and the master public key mpk, and outputs the corresponding verification result.
6. A group signature method characterized by comprising: The method comprises the following steps: receiving the unique identity identifier ID of the registered signature center member node in the distributed system and the first identity L determined by the signature center member node based on a random private key factor l in the distributed group signature system; In conjunction with other group administrator nodes in the group signature system, a second identifier h is generated based on the unique identifier ID and the first identifier L by applying an SM2 digital signature algorithm, and a third sub-identifier d' corresponding to the group administrator node is generated independently i ; the second identifier h and the third sub-identifier d' i to the signature center member node, so that the signature center member node generates a corresponding third identifier d based on each received third sub-identifier d' i corresponding third identifier d, to obtain an identifier private key isk of the signature center member node containing the first identifier L, the second identifier h and the third identifier d, so as to sign and verify a target message based on the identifier private key isk and a master public key mpk of the group signature system. The signature center member node is based on each third sub-identifier d ′ The corresponding third identifier d is generated, and the identifier private key isk containing the first identifier L, the second identifier h, and the third identifier d is obtained, so as to sign and verify the target message based on the identifier private key isk and the main public key mpk of the group signature system. The signature center member node receives the second identity h and the respective third sub-identity d' corresponding to each of the group administrator nodes i ; The signature center member node generates a corresponding third identification d based on the random private key factor l and each third sub-identification d' i generates a corresponding third identification d; the signature center member node generates an identity private key isk according to the first identity L, the second identity h and the third identity d; the signature center member node constructs zero-knowledge proof of the identity private key isk for each of the administrator nodes to generate a verification identity tH corresponding to the unique identity identifier ID according to the zero-knowledge proof, the first identity L, the second identity h and a random number ts, and each of the administrator nodes stores the corresponding relationship between the unique identity identifier ID and the verification identity tH; if the signature center member node currently receives a target message to be group signed, the signature center member node signs and verifies the target message based on the identity private key isk, the master public key mpk of the group signature system and the preset system parameters of the group signature system to obtain the signature σ of the target message.
7. A signing authority member node, characterized by The method comprises the following steps: An identification application module is configured to send a unique identifier ID of itself in a distributed system and a first identification L determined based on a random private key factor l to each group administrator node in a distributed group signature system, so that all group administrator nodes generate a second identification h based on the unique identifier ID and the first identification L by applying an SM2 digital signature algorithm, and each group administrator node generates a respective third sub-identification d' i ; The private key generation module is configured to generate a corresponding third identifier d based on each of the third sub-identifiers d' i generate a corresponding third identifier d, and obtain an identifier private key isk of the self containing the first identifier L, the second identifier h, and the third identifier d, to sign and verify a target message based on the identifier private key isk and a master public key mpk of the group signature system. wherein the third sub-identity d' is based on the first sub-identity d i generate a corresponding third identity d, and obtain an identity private key isk of the self containing the first identity L, the second identity h and the third identity d, to sign and verify a target message based on the identity private key isk and a master public key mpk of the group signature system, comprising: receiving the second identity h and a third sub-identity d' corresponding to each of the group administrator nodes i ; based on the random private key factor l and each of the third sub-identifiers d' i generating a corresponding third identifier d; generating an identity private key isk according to the first identity L, the second identity h and the third identity d; constructing zero-knowledge proof of the identity private key isk for each of the administrator nodes to generate a verification identity tH corresponding to the unique identity identifier ID according to the zero-knowledge proof, the first identity L, the second identity h and a random number ts, and each of the administrator nodes stores a corresponding relationship between the unique identity identifier ID and the verification identity tH; if a target message to be group signed is currently received, signing and verifying the target message based on the identity private key isk, a master public key mpk of the group signature system and preset system parameters of the group signature system to obtain a signature σ of the target message.
8. A signature center group administrator node, characterized by comprising: a data receiving module, configured to receive a unique identity identifier ID of a registered signature center member node in a distributed group signature system and a first identity L determined by the signature center member node based on a random private key factor l in the distributed system; The identity generation module is configured to jointly generate, with other group administrator nodes in the group signature system, a second identity h based on the unique identity identifier ID and a first identity L by applying an SM2 digital signature algorithm, and independently generate a third sub-identity d' corresponding to the identity generation module i ; a data sending module, configured to send the second identifier h and the third sub-identifier d′ to the signature center member node, so that the signature center member node generates a corresponding third identifier d based on the received respective third sub-identifier d′ i a data sending module, configured to send the second identifier h and the third sub-identifier d′ to the signature center member node, so that the signature center member node generates a corresponding third identifier d based on the received respective third sub-identifier d′ i generates a corresponding third identifier d, and obtains an identifier private key isk of the signature center member node containing the first identifier L, the second identifier h and the third identifier d, so as to sign and verify a target message based on the identifier private key isk and a master public key mpk of the group signature system; The signature center member node is based on each third sub-identifier d' i The corresponding third identifier d is generated, and the identifier private key isk containing the first identifier L, the second identifier h and the third identifier d is obtained, so as to sign and verify the target message based on the identifier private key isk and the main public key mpk of the group signature system. The signature center member node receives the second identity h and the respective third sub-identity d' corresponding to each of the group administrator nodes i ; The signature center member node generates a corresponding third identification d based on the random private key factor l and each third sub-identification d i generates a corresponding third identification d; the signature center member node generates an identity private key isk according to the first identity L, the second identity h and the third identity d; the signature center member node constructs zero-knowledge proof of the identity private key isk for each of the administrator nodes to generate a verification identity tH corresponding to the unique identity identifier ID according to the zero-knowledge proof, the first identity L, the second identity h and a random number ts, and each of the administrator nodes stores a corresponding relationship between the unique identity identifier ID and the verification identity tH; if the signature center member node currently receives a target message to be group signed, the signature center member node signs and verifies the target message based on the identity private key isk, a master public key mpk of the group signature system and preset system parameters of the group signature system to obtain a signature σ of the target message.
9. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by a processor to implement the group signature method of any one of claims 1 to 5, or the group signature method of claim 6.