An authenticable high-efficient n-of-k oblivious transfer method and system

By employing a bilinear pairing operation based on identity identifiers and an inadvertent transmission scheme using hash functions, the problems of high computational overhead and insufficient security in existing technologies are solved, achieving identity authentication and anti-attack capabilities while reducing computational and transmission overhead.

CN116015658BActive Publication Date: 2026-02-17NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211432672.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-16
Publication Date
2026-02-17
Estimated Expiration
2042-11-16

AI Technical Summary

Technical Problem

Existing k-out-of-n unintentional transmission schemes have high computational overhead, lack authentication and anti-attack capabilities, and are vulnerable to man-in-the-middle attacks and replay attacks.

Method used

It employs identity-based bilinear pairing operations, generates public-private key pairs through a trusted authority (KGC), and achieves identity authentication between the sender and receiver. It also utilizes bilinear mapping and hash functions for information encryption and signing, reducing the number of encryption steps required by the sender.

Benefits of technology

It achieves identity authentication, protects communication privacy, resists man-in-the-middle attacks and replay attacks, and reduces computation and transmission overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015658B_ABST
    Figure CN116015658B_ABST
Patent Text Reader

Abstract

The application discloses an authentic high-efficiency n-taken-k careless transmission method and system, and the method comprises the following steps: S1, a system establishment step, wherein a trusted authority KGC outputs system public parameters mpk and a secret master private key msk based on input security parameters; S2, a key generation step, wherein the trusted authority KGC outputs a public-private key pair corresponding to the identity of the sender and the receiver to the sender and the receiver based on the identity information of the accepted sender and receiver; S3, a careless transmission step, wherein the receiver encrypts k own keys and sends them to the sender; the sender converts the k keys and encrypts n information to generate n ciphertexts, and then sends the k converted keys and the n ciphertexts to the receiver; and S4, a decryption step, wherein the receiver uses the k converted keys to decrypt the n ciphertexts to obtain k desired information. The identity authentication problem of the sender and the receiver in the careless transmission process is solved, and efficient encryption and decryption are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security technology, and in particular relates to an efficient and authentic method for unintentionally transmitting n to k. Background Technology

[0002] Unintentional transmission is a type of protocol in cryptography that allows the sender to transmit one of many potential messages to the receiver while remaining unaware of the received message. In 1981, Rabin first proposed an interactive unintentional transmission scheme, where the receiver's ability to decrypt the sender's message has a 1 / 2 probability. In 1985, Even et al. proposed a more generalized 1-out-of-2 unintentional transmission scheme, where the sender sends two encrypted messages to the receiver, only one of which the receiver can decrypt. In 1986, Brassard et al. further extended the scheme, proposing a 1-out-of-n unintentional transmission scheme, in which the receiver can only receive one of n sent messages. In 1999, Naor and Pinkas proposed a k-out-of-n unintentional transmission scheme, which is mainly implemented by repeatedly calling 1-out-of-2 unintentional transmissions, but this scheme only works when... It is only effective when the time is right. In 2002, Mu et al. proposed three k-out-of-n stealth transmission schemes, constructed using RSA encryption, Nyberg-Rueppel signatures, and ElGamal encryption schemes, respectively. Between 2002 and 2022, many adaptive, efficient, and highly secure k-out-of-n stealth transmission schemes were continuously proposed. Chu and Tzeng proposed an efficient k-out-of-n stealth transmission scheme that requires only two message transmissions. The overhead from the receiver to the sender is 1024*k bits, while the overhead from the sender to the receiver is 1024*(k+1)+n*msg bits. Ma et al. proposed a highly secure k-out-of-n stealth transmission scheme, but it requires k calls to zero-knowledge proofs to obtain k of the n sent messages, which makes their protocol less efficient.

[0003] Research and analysis of current interactive k-out-of-n stealth transmission schemes reveal that the main idea is for the receiver to send k keys to the sender. The sender uses these k keys to encrypt all information and sends it to the receiver. The receiver can only decrypt the information using the keys, resulting in the sender needing to perform k*n encryption operations, leading to high computational overhead. Furthermore, existing k-out-of-n stealth transmission schemes lack consideration for enhanced security features. The absence of authentication and integrity verification between the sender and receiver makes them vulnerable to man-in-the-middle and replay attacks during stealth transmission. Summary of the Invention

[0004] The purpose of this invention is to overcome the problems of the prior art by disclosing an efficient and authenticable method and system for unintentional transmission of n-k. The method and / or system of this invention are based on identity identification and utilize bilinear pairing operations to protect the privacy of the sender and receiver during communication, realize the identity authentication of the information sender and receiver, resist man-in-the-middle attacks and replay attacks, and improve computational efficiency.

[0005] The objective of this invention is achieved through the following technical solution:

[0006] A verifiable and efficient method for unintentional transmission of n with k values, the method comprising:

[0007] S1: System establishment steps: The trusted authority KGC outputs the system's public parameters mpk based on the input security parameters and keeps the master private key msk confidential.

[0008] S2: Key generation step, the trusted authority KGC outputs the corresponding public and private key pairs to the sender and receiver based on the identity information of the sender and receiver;

[0009] S3: Inadvertent transmission step, the receiver encrypts its k keys and sends them to the sender; the sender converts the k keys and encrypts n pieces of information to generate n ciphertexts, and then sends the k converted keys and n ciphertexts to the receiver;

[0010] S4: Decryption step, the receiver uses k converted keys to decrypt n ciphertexts and obtain k desired information.

[0011] According to a preferred embodiment, step S1 specifically includes:

[0012] S11: Select a generator of order P. The additive group G and the multiplicative group G T = e(P, P), where e is a bilinear mapping e: G×G→G T ;

[0013] S12: Random selection Calculate P pub =sP;

[0014] S13: Choose a hash function H: {0, 1} * →{0,1} l , H2: {0, 1} * →G,H3:G→{0,1} l ;

[0015] S14: Output system public parameters And keep the master private key msk={s} confidential.

[0016] According to a preferred embodiment, step S2 includes: S21: The sender sends an identity ID. s The trusted authority KGC is given the information, and the trusted authority KGC performs calculations. and And return it to the sender.

[0017] According to a preferred embodiment, step S2 further includes: S22: The receiver sends an identity ID. r Give it to KGC, KGC calculates and And return it to the recipient.

[0018] According to a preferred embodiment, step S3 includes:

[0019] S301: The sender possesses m1, m2, ... m n The receiver receives k messages, where 1 ≤ k < n.

[0020] S302: The receiver randomly selects... calculate Where γ j Let γ be the number of the k messages the sender wants to obtain. j ∈{1, 2, ..., n};

[0021] S303: The receiver selects randomly. Calculate ρ r =H3(ID) r K, K1, K2, ..., K k ),calculate h r =H1(ρ r U r ), Signature σ r =(U r V r );

[0022] S304: The receiver sends a message to the sender: msg r ={ID r K, K1, K2, ..., K k , σ r};

[0023] S305: After receiving the message, the sender calculates... And verify If the verification passes, proceed to the next step; otherwise, terminate.

[0024] S306: The sender randomly selects... calculate

[0025] S307: Sender calculates Until Where ψ n Let ψ be the number of the n messages sent by the sender. n ∈{1, 2, ..., n};

[0026] S308: The sender calculates Msg1' = H(m1), Msg2' = H(m2), and so on, until Msg n '=H(m n );

[0027] S309: The sender randomly selects... Calculate ρ s =H3(ID) s A1, A2, ..., A k Calculate Msg1, Msg2, ..., Msgn) h s =H1(ρ s U s ), Signature σ s =(U s V s );

[0028] S310: The sender sends to the receiver:

[0029] msg s ={ID s A1, A2, ..., A k Msg1, Msg2, ..., Msg n ,Msg1',Msg2',…,,Msg n ',σ s}

[0030] According to a preferred embodiment, step S4 includes:

[0031] S41: After receiving the message msgs, the receiver calculates... And verify If the verification passes, proceed to the next step; otherwise, terminate.

[0032] S42: Receiver calculation t∈{1, 2, ..., n}, b∈{1, 2, ..., k}, the receiver computes H(Y) bIf H(Y) b )∈{Msg1',Msg2',…,,Msg n The decryption was successful.

[0033] S43: Repeat step S42 until the traversal is complete, and decrypt to obtain all the k messages selected by the receiver.

[0034] On the other hand, the present invention also discloses:

[0035] An authenticable and efficient unintentional transmission system for selecting n and k, the unintentional transmission system comprising a sender, a receiver, and a trusted authority (KGC), the unintentional transmission system being implemented according to the aforementioned unintentional transmission method.

[0036] The aforementioned main solution of the present invention and its various further alternative solutions can be freely combined to form multiple solutions, all of which are solutions that can be adopted and are claimed by the present invention. Those skilled in the art, after understanding the solution of the present invention, will realize that there are many combinations based on existing technology and common knowledge, all of which are technical solutions to be protected by the present invention, and will not be exhaustively listed here.

[0037] The beneficial effects of this invention are:

[0038] 1) The unintentional transmission method and / or system of the present invention realizes the identity authentication of both the sender and receiver, which can protect the privacy of the sender and receiver during communication and resist man-in-the-middle attacks and replay attacks.

[0039] 2) Through the inadvertent transmission method and / or system of the present invention, the sender encrypts the information n times, which reduces the computational overhead of the protocol and avoids the sender's k*n encryption calculations, thereby reducing the transmission overhead of the protocol. Attached Figure Description

[0040] Figure 1 This is a flowchart of the efficient, unintentional transmission method for obtaining k from n, which is verifiable by this invention.

[0041] Figure 2 This is a transmission protocol diagram of the efficient, unintentional transmission method for selecting k using the n-value method, which is verifiable by this invention. Detailed Implementation

[0042] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, unless otherwise specified, the following embodiments and features described therein can be combined with each other.

[0043] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0044] Example 1:

[0045] refer to Figure 1 As shown in the figure, an efficient and verifiable method for unintentional transmission of n with k values ​​is illustrated. This unintentional transmission method includes:

[0046] S1: System setup steps. The trusted authority KGC, based on the input security parameter λ, outputs the system's public parameter mpk and keeps the master private key msk confidential.

[0047] Specifically, step S1 includes:

[0048] S11: Select a generator of order P. The additive group G and the multiplicative group G T = e(P, P), where e is a bilinear mapping e: G×G→G T ;

[0049] S12: Random selection Calculate P pub =sP;

[0050] S13: Choose a hash function H: {0, 1} * →{0,1} l , H2: {0, 1} * →G,H3:G→{0,1} l ;

[0051] S14: Output system public parameters And keep the master private key msk={s} confidential.

[0052] S2: Key generation step. The trusted authority (KGC) outputs the corresponding public and private key pairs to the sender and receiver based on the identity information of the sender and receiver.

[0053] Specifically, step S2 includes:

[0054] S21: The sender sends its identity ID. s The trusted authority KGC is given the information, and the trusted authority KGC performs calculations. and And return it to the sender.

[0055] S22: Receiver sends identity ID r Give it to KGC, KGC calculates and And return it to the recipient.

[0056] S3: Unintentional transmission steps. The receiver encrypts its k keys and sends them to the sender; the sender transforms the k keys and simultaneously encrypts n pieces of information to generate n ciphertexts, then sends the k transformed keys and n ciphertexts to the receiver.

[0057] Specifically, step S3 includes:

[0058] S301: The sender possesses m1, m2, ... m n The receiver receives k messages, where 1 ≤ k < n.

[0059] S302: The receiver randomly selects... calculate Where γ j Let γ be the number of the k messages the sender wants to obtain. j ∈{1, 2, ..., n};

[0060] S303: The receiver selects randomly. Calculate ρ r =H3(ID) r K, K1, K2, ..., K k ),calculate h r =H1(ρ r U r ), Signature σ r =(U r V r );

[0061] S304: The receiver sends a message to the sender: msg r ={ID r K, K1, K2, ..., K k , σ r};

[0062] S305: After receiving the message, the sender calculates... And verify If the verification passes, proceed to the next step; otherwise, terminate.

[0063] S306: The sender randomly selects... calculate

[0064] S307: Sender calculates

[0065] Until Where ψn is the number of the n messages sent by the sender, ψn ∈{1, 2, ..., n};

[0066] S308: The sender calculates Msg1' = H(m1), Msg2' = H(m2), and so on, until Msg n '=H(m n );

[0067] S309: The sender randomly selects... Calculate ρ s =H3(ID) s A1, A2, ..., A k Calculate Msg1, Msg2, ..., Msgn) h s =H1(ρ s U s ), Signature σ s =(U s V s );

[0068] S310: The sender sends to the receiver:

[0069] msg s ={ID s A1, A2, ..., A k Msg1, Msg2, ..., Msg n ,Msg1',Msg2',…,,Msg n ',σ s}

[0070] S4: Decryption Steps. The receiver uses k converted keys to decrypt n ciphertexts and obtain the k desired pieces of information.

[0071] Specifically, step S4 includes:

[0072] S41: The receiver has received the message msg s Then, calculate H3(ID s A1, A2, ..., A k Msg1, Msg2, ..., Msg n ), and verify If the verification passes, proceed to the next step; otherwise, terminate.

[0073] S42: Receiver calculation t∈{1, 2, ..., n}, b∈{1, 2, ..., k}, the receiver computes H(Y) b If H(Y) b )∈{Msg1',Msg2',…,,Msgn The decryption was successful.

[0074] S43: Repeat step S42 until the traversal is complete, and decrypt to obtain all the k messages selected by the receiver.

[0075] Example 2

[0076] This invention also discloses: a certified, efficient, unintentional transmission system for selecting n and k. The unintentional transmission system includes a sender, a receiver, and a trusted authority (KGC), and is implemented according to the unintentional transmission method described in Example 1.

[0077] The unintentional transmission method and / or system of this invention implements authentication of both the sender and receiver, protecting the privacy of both parties during communication and resisting man-in-the-middle attacks and replay attacks. Through this unintentional transmission method and / or system, the sender encrypts the information n times, reducing the computational overhead of the protocol and avoiding k*n encryption calculations by the sender, thus reducing the transmission overhead of the protocol.

[0078] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A verifiable and efficient method for unintentional transmission of n-k, characterized in that, The unintentional transmission method includes: S1: System establishment steps: The trusted authority KGC outputs the system's public parameters mpk based on the input security parameters and keeps the master private key msk confidential. S2: Key generation step, the trusted authority KGC outputs the corresponding public and private key pairs to the sender and receiver based on the identity information of the sender and receiver; S3: Inadvertent transmission step, the receiver encrypts their own... A key is sent to the sender; the sender will... Each key is converted, and at the same time... The information is encrypted and generated. A ciphertext, then... The converted key and A encrypted message is sent to the recipient; S4: Decryption step, the receiver uses k converted keys to decrypt n ciphertexts and obtain k desired pieces of information; Step S1 specifically includes: S11: Select a generator as... Rank addition group Multiplication group ,in It is a bilinear mapping ; S12: Random selection ,calculate ; S13: Choosing a hash function , , , ; S14: Output system public parameters mpk And keep the master private key msk confidential ; Step S2 includes: S21: Sender sends identity The trusted authority KGC is given the information, and the trusted authority KGC performs calculations. and and return it to the sender; Step S2 also includes: S22: Receiver sends identity Give it to KGC, KGC calculates and and return it to the recipient; Step S3 includes: S301: The sender possesses... The recipient obtains the information. strip, ; S302: The receiver randomly selects... ,calculate , , ;in What the sender wants to obtain The number of the message, ; S303: The receiver selects randomly. ,calculate ,calculate , , ,sign ; S304: The receiver sends to the sender: ; S305: After receiving the message, the sender calculates... and verify If the verification passes, proceed to the next step; otherwise, terminate. S306: The sender randomly selects... ,calculate ; S307: Sender calculates , until ,in Let n be the numbers of the n messages sent by the sender. ; S308: Sender calculates , ; S309: The sender randomly selects... ,calculate calculate , , ,sign ; S310: The sender sends to the receiver: 。 2. The unintentional transmission method as described in claim 1, characterized in that, Step S4 includes: S41: The recipient has received the message. Then, calculate and verify If the verification passes, proceed to the next step; otherwise, terminate. S42: Receiver calculation The receiver calculates ,if Decryption was successful; S43: Repeat step S42 until the traversal is complete, and decrypt to obtain all the receiver's selected data. Message.

3. A verifiable, high-efficiency, unintentional transmission system for n-choose-k, characterized in that, The unintentional transmission system includes a sender, a receiver, and a trusted authority (KGC), and the unintentional transmission system is implemented according to the unintentional transmission method as described in any one of claims 1 to 2.

Citation Information

Patent Citations

  • Data sharing method and system based on inadvertent transmission protocol

    CN112671802A

  • Casual transmission method, multi-party security computing platform and device for casual transmission

    CN114301594A