A calculation method for signature information of OFD files based on ring signature technology
Generating OFD file signatures through ring signature technology solves the problem of insufficient security of RSA algorithms and the inability of traditional PKI technology to protect user privacy, and realizes identity protection of OFD files in anonymous scenarios.
Patent Information
- Application Number
- CN202211462436.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-22
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-11-22
AI Technical Summary
The security of existing RSA signature algorithms in PDF files is threatened by the growth of computer computing power, and traditional PKI technology is difficult to protect user identity privacy in OFD files, especially in scenarios such as electronic anonymous voting and anonymous bidding.
Using ring signature technology, the signature information of the OFD file is generated by the joint calculation of the public keys of multiple legal users and their own public and private keys. The signature verifier cannot untie the real identity of the signature user, and the signature information is stored in the signature data structure of the OFD file.
It realizes user identity privacy protection in special OFD file circulation scenarios, meeting the needs of electronic anonymous voting and anonymous bidding scenarios.
Smart Images

Figure CN115834081B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security, and particularly relates to an anonymous signature system for domestic OFD format files. Background Art
[0002] Electronic signature is developed from traditional paper signature technology and is an important part of applications such as e-commerce, e-government, e-bidding, and e-contracts. It can be used to detect data security issues in the transmission of information such as government-issued documents, e-contracts signed by commercial institutions, and bidding tender documents over the network.
[0003] Table 1. Electronic signature data structure of OFD files
[0004] Version number Electronic seal Signature time Original text hash value Original text attribute information Signer's certificate Signature algorithm Signature information
[0005] The "Electronic Signature Law" signed in 2004 recognizes that signature and seal have the same legal endorsement as paper stamping, providing legal protection for the application and promotion of electronic signature technology. The current mainstream electronic file format is the PDF file standard proposed by Adobe Systems Incorporated. The RSA file signature technology supported by this standard is formulated by foreign institutions and cannot face the increasingly complex international Internet environment. Moreover, with the continuous growth of computer computing power, the RSA signature algorithm has been greatly threatened by cryptanalysis, so the security of the PDF files signed by it cannot be well guaranteed.
[0006] Currently, electronic signature systems based on digital signature technology are all based on traditional PKI technology. This technology began in the 1990s and has formed a relatively complete cryptographic infrastructure after years of development, providing services such as CA certificates, encryption, and signature. With the rapid development of electronic signature technology, more and more digital signature schemes with good performance and special properties have been proposed and formally proven secure.
[0007] Ring signature technology was first proposed by Rivest et al. in 2001, who is also the proposer of the RSA algorithm. Ring signature technology is a signature technology that can protect identity privacy and has been applied in the field of cryptocurrencies such as Monero. Ring signature protects the identity privacy of users by hiding the user's personal signature key in a set of public keys of multiple legitimate users. However, due to the setting of its trapdoor, the signature verifier can still verify the legitimacy of the signature.
[0008] The present invention adopts ring signature technology to generate signature information for OFD files in special scenarios of OFD files, such as electronic anonymous voting, anonymous bidding, etc., so as to protect the identity privacy of the original file generator. Summary of the Invention
[0009] The object of the present invention is to propose a method for calculating the signature information of an OFD file based on ring signature technology. This method does not rely on the generation of signature information by the public-private key pair of a user in a traditional signature scheme. Instead, the signature user jointly calculates and generates a legal signature based on the public keys of multiple legitimate users and his own public-private key. The signature verifier cannot decrypt the true identity of the signature user while verifying the legality of the file.
[0010] The technical solution of the present invention is a method for calculating the signature information of an OFD file based on ring signature technology, including the following steps:
[0011] Step 1: The OFD service institution sets up a CA server and selects any security parameter on the CA server. The system parameters and system keys are generated according to the following steps:
[0012] Select a bilinear mapping function g1 is a generator on, g2 is a generator on and ψ(g2) = g1, define as a one-way function, and the public parameters are i represents a user, 1 ≤ i ≤ n, n represents the number of all legitimate users, and h represents a hash function;
[0013] Step 2: The user communicates with the CA server and registers to generate a key according to the following steps:
[0014] For user i, randomly select as its private key, and the corresponding public key is where
[0015] Step 3: If user t wants to sign the OFD file F, first collect the information of n legitimate users: {(u1, v1),..., (u n , v n )}, and the signer's certificate needs to fill in the legitimate certificates of n users; the user calculates the signature information for the file F according to the following steps:
[0016] S1. For i ∈ {1,..., n}\t, perform operations for other confounding users except user t; the user selects and calculates
[0017] S2. Select represents a random number, For all 1 ≤ i ≤ n, calculate such that:
[0018]
[0019] Among them, m is the MD5 calculated for file F, which can be filled into the original hash field of the OFD signature data structure;
[0020] S3. Use the private key x i , y i to calculate where R i is the random number generated in S2, x t , y t are the public-private key pair of the user, and w is the value obtained in the previous step;
[0021] S4. Output the signature information Sig = {(σ1, R1), …, (σ n , R n )} and fill it into the signature information field of the OFD signature data structure;
[0022] Step Four: The recipient of file F determines the legal identity of the file owner after verifying the following formula, and it is from a certain legal member in {(u1, v1),..., (u n , v n )}:
[0023]
[0024] Beneficial Effects
[0025] The present invention solves the problem of protecting the user identity privacy of the original OFD file in scenarios where special OFD files are circulated and there are user anonymity requirements such as electronic anonymous voting, electronic anonymous bidding, etc. Description of the Drawings
[0026] Figure 1 It is an OFD file anonymous signature system based on ring signature technology Specific Embodiments
[0027] The following further illustrates the present invention in conjunction with embodiments, but the protection scope of the present invention is not limited thereto:
[0028] Combined with Figure 1 , an OFD signature information calculation method based on ring signature technology includes the following steps:
[0029] Step One: The OFD service institution builds a CA server, selects any security parameter on the CA server, and generates system parameters and system keys according to the following steps:
[0030] Select a bilinear mapping function g1 is a generator on, g2 is a generator on and ψ(g2) = g1. Define is a one-way function. The public parameters are
[0031] Step 2: The user communicates with the CA server and registers to generate a key according to the following steps:
[0032] For user i, randomly select as its private key, and the corresponding public key is where
[0033] Step 3: If user t (the file owner) wants to sign the OFD file F, first collect the information of n legal users: {(u1, v1),..., (u n , v n )}, and the signer's certificate needs to fill in the legal certificates of n users and this user. The user can calculate the signature information for file F according to the following steps:
[0034] S1. For i ∈ {1,..., n}\t, the user selects and calculates
[0035] S2. Select For all 1 ≤ i ≤ n, calculate such that:
[0036]
[0037] where m is the MD5 calculated for file F, which can be filled in and filled in the original hash column of the OFD signature data structure.
[0038] Use the private keys x i , y i to calculate where R i is the random number generated by S2, x t , y t are the public and private key pairs of the user, and w is the value obtained in the previous step.
[0039] S4. Output the signature information Sig = {(σ1, R1), …, (σ n , R n )} and fill it in the signature information column of the OFD signature data structure.
[0040] Step 4: The recipient of file F can determine the legal identity of the file owner after verifying the following formula, which is from {(u1, v1),..., (u n , v n)} a legal member in
[0041]
[0042] The specific embodiments described herein are merely illustrative of the spirit of the present invention. Those skilled in the art to which the present invention pertains may make various modifications or supplements to the described specific embodiments or use similar means for substitution, but will not deviate from the spirit of the present invention or exceed the scope defined by the appended claims.
Claims
1. A method for calculating the signature information of an OFD file based on the ring signature technology, characterized in that Including the following steps: Step 1: The OFD service institution sets up a CA server, selects any security parameters on the CA server, and generates system parameters and system keys according to the following steps: Select a bilinear mapping function g1 is a generator on, g2 is a generator on and ψ(g2) = g1, define as a one-way function, the public parameters are i represents the user, 1 ≤ i ≤ n, n represents the number of all legitimate users, and h represents the hash function; Step 2: The user communicates with the CA server and registers to generate a key according to the following steps: For user i, randomly select as its private key, and the corresponding public key is where Step 3: If user t wants to sign the OFD file F, first collect the information of n legal users: {(u1, v1),..., (u n , v n )}, and the signer's certificate needs to fill in the legal certificates of n users; the user calculates the signature information for file F according to the following steps: S1. For i ∈ {1,..., n}\t, it means that other obfuscated users except user t perform operations; the user selects and calculates S2. Select represents a random number, For all 1 ≤ i ≤ n, calculate such that: Where m is the MD5 calculated for the file F and is filled in the original text hash column of the OFD signature data structure; S3. Use the private keys x t , y t to calculate where R t is the random number generated in S2, and x t , y t are the user's private key pair, and w is the value obtained in the previous step; S4. Output the signature information Sig = { (σ1, R1), …, (σ n , R n )} and fill it into the signature information field of the OFD signature data structure; Step 4: The recipient of File F determines the legal identity of the file owner after verification and determines that it comes from a legal member of {(u1, v1),..., (u n , v n )}.
Citation Information
Patent Citations
Linkable ring signature method based on anonymous broadcast encryption
CN109257184A
Efficient anonymous identity authentication method in Internet of Vehicles environment
CN111372248A