A lattice-based revocable ring signature method and system for the Internet of Vehicles

Through the revocable ring signature method based on the grid, the problem of irrevocable ring signature in the Internet of Vehicles is solved, and the anonymity, message integrity and unlinkability of the signature process are realized, and the signature identity is exposed when needed, improving security.

CN116388999BActive Publication Date: 2025-07-22YANTAI JIAGANG ELECTRONIC TECH CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310319324.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-27
Publication Date
2025-07-22
Estimated Expiration
2043-03-27

AI Technical Summary

Technical Problem

The central signature method of the existing Internet of Vehicles technology is irrevocable and irresistible to quantum attacks.

Method used

The revocable ring signature method based on the grid is adopted. By generating public parameters, user public and private keys, signer revocable tags, and sign-verifier verification steps, combined with the difficult problems of the grid, the anonymity, message integrity and non-linkability of the signature process, and the revocable tags are introduced to ensure forced revocability.

Benefits of technology

It realizes anonymity, message integrity and unlinkability in the signature process, and can resist quantum attacks, improves security, and trusted parties can revoke the signature identity at any time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116388999B_ABST
    Figure CN116388999B_ABST
Patent Text Reader

Abstract

The present invention discloses a lattice-based revocable ring signature method and system for the vehicle networking, including a trusted party initializing the system; generating a public-private key pair for users in the system; the signer encrypting the signer's public key using the public key of the trusted party to generate a revocable tag; the signer randomly selecting multiple other users as ring members, signing the message using the signer's private key and the public keys of all ring members, and sending the message, signature and revocable tag to the verifier together; the verifier verifying the signature; the trusted party decrypting the revocable tag using the private key to obtain the signer's public key and outputting the signer's identity. The present invention uses the ring signature method to ensure the anonymity, message integrity and unlinkability of the signer's identity during the signature process, and at the same time introduces a revocable tag to enable the trusted party to expose the signer's identity at any time, achieving forced revocability; by constructing the lattice-based signature and encryption process, the method can resist quantum attacks and improve the security of the method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and relates to a lattice-based revocable ring signature method and system, in particular to a lattice-based revocable ring signature method and system for the Internet of Vehicles (IoV). Background Art

[0002] The Internet of Vehicles (IoV) is a mobile ad hoc network that can intelligently control the entire process of transportation, improving transportation efficiency and safety. However, in practical applications, communications between vehicles can be used by malicious attackers to locate and track vehicles. Therefore, privacy protection is crucial in the IoV. In addition, malicious vehicles may broadcast false messages, and it is necessary for an authoritative agency to be able to disclose the true identities of users in the IoV when necessary. To achieve a conditional privacy protection authentication scheme, Liu et al. proposed the concept of revocable ring signature, and constructed a ring signature based on discrete logarithm and bilinear pair to achieve privacy protection authentication. At the same time, the trusted party in the scheme can expose the signer's identity at any time to achieve mandatory revocability.

[0003] University of Electronic Science and Technology proposed an editable, linkable, and non-repudiable ring signature method in its patent application "An Editable, Linkable, and Non-Repudiable Ring Signature Method" (application number CN201910353137.8, publication number CN110071812B, publication date April 29, 2019), which solves the problems of difficult revocation of ring signatures in the prior art and difficult tracking of the identity information of malicious users. The main modules of this method are: when the signer signs, a linkable tag and a non-repudiable ring signature are generated. When verifying the signature, it is judged whether it is linkable through the linkable tag, and it is judged whether the repudiation is successful by performing a repudiation calculation on the disputed message. The deficiencies of this method are: (1) the message non-linkability is lost and the mandatory revocability cannot be achieved; (2) the scheme is based on the discrete logarithm problem and cannot resist quantum attacks. Summary of the Invention

[0004] The purpose of the present invention is to propose a lattice-based revocable ring signature method and system for the Internet of Vehicles (IoV), which is used to solve the technical problems of non-revocable ring signatures and inability to resist quantum attacks existing in the prior art.

[0005] The technical solution adopted by the method of the present invention is: a lattice-based revocable ring signature method for the Internet of Vehicles (IoV), including the following steps:

[0006] Step 1: Generate public parameters The public key PK of the trusted party TA TA and the private key sk TA ;

[0007] According to the security parameter λ, the trusted party TA generates a random matrix and outputs the public parameters where and are cyclotomic polynomial rings, R q is an ideal lattice, is a ring of polynomials with integer coefficients, q is the modulus, denotes the ring consisting of all polynomials with coefficients taken from , I represents the identity matrix, and || is the concatenation symbol; represents an h×v matrix, and the elements in q all belong to the ring R i ; the values of q, d, h, and v depend on the security parameter λ; Step 2: User i generates the public key PK i and the private key sk

[0008] Step 3: Signer π generates the revocable tag C π , and it is part of the final signature;

[0009] Step 4: Signer π generates a ring signature z for the message m, and sends the message-signature pair (m, z), the timestamp T, the number of ring members n, the set of public keys PK1, K2,..., K n of all members in the ring, and the public key PK TA of the trusted party TA to the verifier V;

[0010] Step 5: The verifier verifies the signature.

[0011] The technical solution adopted by the system of the present invention is: A lattice-based revocable ring signature system for the Internet of Vehicles, including the following modules:

[0012] Module 1, used to generate the public parameters the public key PK TA and the private key sk TA of the trusted party TA;

[0013] According to the security parameter λ, the trusted party TA generates a random matrix and outputs the public parameters where and are cyclotomic polynomial rings, R q is an ideal lattice, is a ring of polynomials with integer coefficients, q is the modulus, denotes the ring consisting of all polynomials with coefficients taken from , I represents the identity matrix, and || is the concatenation symbol; represents an h×v matrix, and the elements in q; The values of q, d, h, and v depend on the security parameter λ;

[0014] Module 2, used to generate the public key PK i , and the private key sk i ;

[0015] Module 3, used by the signer π to generate the revocable tag C π , and use it as part of the final signature;

[0016] Module 4, used by the signer π to generate the ring signature z of the message m, and send the message-signature pair (m, z), timestamp T, the number of ring members n, the set of public keys PK1, K2,..., K n , and the public key PK of the trusted party TA TA to the verifier V;

[0017] Module 5, used by the verifier to verify the signature.

[0018] Compared with the existing very few, the present invention has the following advantages:

[0019] First, since the present invention introduces a revocable tag in the signature process, the trusted party can revoke the signature at any time, and other users do not know the identity of the signer, achieving forced revocability;

[0020] Second, since the present invention uses lattice-based hard problems, the method has quantum resistance and improves the security of the ring signature method. Description of the Drawings

[0021] Att Figure 1 is the implementation flowchart of the present invention. Detailed Implementation Manner

[0022] To facilitate the understanding and implementation of the present invention by those of ordinary skill in the art, the following will describe in detail the specific implementation manner of the present invention and its simplification and deformation with reference to the accompanying drawings. It should be understood that the implementation examples described herein are only used to illustrate and explain the present invention, and are not used to limit the protection scope of the present invention.

[0023] Refer to Att Figure 1 , One A lattice-based revocable ring signature method for the Internet of Vehicles, and the implementation steps are as follows:

[0024] (1) The trusted party initializes the system:

[0025] (1a) According to the input security parameter λ, the trusted party TA generates a random matrix and outputs the public parameter where and are cyclotomic polynomial rings, Rq is an ideal lattice, is the ring of polynomials with integer coefficients, q is the modulus, denotes the ring consisting of all polynomials whose coefficients are taken from , I represents the identity matrix, || is the concatenation symbol; represents an h×v matrix, and the elements in it all belong to the ring R q ; the values of q, d, h, and v depend on the security parameter λ

[0026] (1b) TA randomly and uniformly selects where, is an element in, is an element in, S β denotes satisfying ||f|| ∞ ≤β; and respectively represent v-dimensional and h-dimensional column vectors, and the elements in the column vectors all belong to S β , and the value of β depends on the security parameter λ; calculate Output the TA public key private key

[0027] (2) The user generates a public-private key pair:

[0028] User i in the system randomly and uniformly selects as its private key sk i , and calculates y i = Ax i + x i ′ as its public key PK i , and generates the identity id i = H′(PK i ), where, H′: {0,1} * → D′, H′ is a cryptographic hash function, Let PK i = (y i , d i ) as the public key of i; where, x represents a variable, c j is the variable coefficient.

[0029] (3) The signer generates a revocable tag:

[0030] The signer π generates a revocable tag C π = (C1, C2), and uses it as part of the final signature. The implementation steps are as follows:

[0031] (3a) The signer π randomly and uniformly generates a vector

[0032] (3b) Randomly generate ∈2 ← S β , calculate If ∈2 is irreversible, re - execute step (3b);

[0033] (3c) The signer π calculates the revocable tag C according to the following formula π :

[0034]

[0035] where, 「」 represents the rounding operation, represents the public key of the trusted party.

[0036] (4) The signer signs the message:

[0037] The signer π generates a ring signature z = (e1, r1, …, r n , t1, …, t n , ρ1, …, ρ n , ∈, C π ) of the message m, and sends the message - signature pair (m, z), timestamp T, the number of ring members n, the set of public keys PK1, PK2, …, PK n , and the TA public key PK TA to the verifier V. The specific implementation steps are as follows:

[0038] (4a) Generate the challenge value e of the member π + 1 in the ring according to the following formula π+1 :

[0039]

[0040] where, H is a cryptographic hash function, H: {0, 1} * → D, D is the challenge space, D = {d ∈ R q , ||d|| ∞ ≤ q, ||d||1 ≤ κ}, T represents the timestamp; L represents the set of partial public keys y i of all ring members, L = {y1, y2, …, y n}; n represents the number of ring members, m represents the message; u, w are v + h - dimensional and h - dimensional vectors respectively, uniformly taken from S γ-1 , that is κ, γ depend on the security parameter λ;

[0041] (4b) Generate the challenge values e i+1 = H(T, L, m, α i , Ω i , σi ), and the specific steps are as follows:

[0042] (4b.1) Randomly and uniformly generate ρ i ←S β , and calculate ρ i =e i ·v i ;

[0043] (4b.2) Calculate the intermediate parameter α according to the following formula i :

[0044]

[0045] (4b.3) Calculate the intermediate parameter Ω according to the following formula i :

[0046] Ω i =A T t i +∈·ρ i -e i ·C1

[0047] (4b.4) Calculate the intermediate parameter σ according to the following formula i :

[0048]

[0049] (4b.5) Generate the challenge value e of user i according to the following formula i+1 :

[0050] e i+1 =H(T,L,m,α i ,Ω i ,σ i )

[0051] (4c) Calculate the response value r according to the following formula π :

[0052]

[0053] (4d) Calculate the response value t according to the following formula π :

[0054] t π =w+e π ·s

[0055] (4e) Calculate the response value ρ according to the following formula π :

[0056] ρ π =e π ·∈2

[0057] (4f) If ||r π || ∞ ≥γ - κ·β or ||t π || ∞ ≥γ - κ·β, then abort the process and restart from i = π - 1 in step (4b);

[0058] (4g) Output the signature value z of message m = (e1, r1, …, r n , t1, …, t n , ρ1, …, ρ n , ∈, C π ).

[0059] (5) The verifier verifies the signature:

[0060] (5a) The verifier V checks whether ||r i || ∞ ≤γ - κ·β and ||t i || ∞ ≤γ - κ·β hold. If not, abort the signature verification; if so, continue with the following step 5b;

[0061] (5b) Parse the signature value z to obtain the revocable tag C π = (C1, C2);

[0062] (5c) Calculate the challenge value e i+1 , where i = 1, …, n - 1:

[0063]

[0064] (5d) After obtaining e n , check whether the following equation holds:

[0065]

[0066] If the equation holds, accept the signature; otherwise, reject the signature; output the signature verification result and end the process;

[0067] For the ring signature in this embodiment, e2 is calculated from e1, e3 is calculated from e2, …, and finally e1 is calculated from en. If the calculated e1 is equal to the e1 sent in the signature, it proves that the signature verification is successful. Therefore, only e1 needs to be compared, and only e1 is sent in the signature.

[0068] When the identity of the signer needs to be exposed, the trusted party TA uses the private key to decrypt the revocable tag, obtains the public key of the signer, and outputs the identity of the signer;

[0069] The specific implementation includes the following sub - steps:

[0070] Step 6.1: The trusted party TA checks whether z is valid. If so, execute the following process; otherwise, abort the process;

[0071] Step 6.2: Parse the signature value z to obtain the revocable tag C π =(C1, C2);

[0072] Step 6.3: The trusted party TA calculates the identity of the signer π

[0073] Step 6.4: According to id π , the trusted party TA obtains the public key PK of π from the public key group L π , exposing the identity of the signer.

[0074] In this embodiment, the C language is used to fully implement the algorithm, verifying the correctness of the algorithm. For a 32B message, when the ring size n is 1, 2, 4, and 8 respectively, the time for system initialization, key generation, signature generation, signature verification, and signature revocation is shown in Table 1 below (unit: microseconds):

[0075] Table 1

[0076] n System setup and KeyGen SigGen SigVerify SigRevoke 1 338.47 3704.20 592.01 80.93 2 338.47 728825 110236 80.01 4 338.47 16189.36 2128.51 89.92 8 338.47 26390.61 4025.97 82.63

[0077] It can be seen from Table 1 that the signature and signature verification times increase linearly with the number of ring members n, and the signature verification speed is significantly faster than the signature; even in the case of n = 8, the signature verification time is only 4 milliseconds, which has a performance advantage in practical applications.

[0078] The present invention uses the ring signature method to ensure the anonymity, message integrity, and unlinkability of the signer's identity during the signature process. At the same time, a revocable tag is introduced to enable the trusted party to expose the signer's identity at any time, achieving forced revocability; by constructing lattice-based signature and encryption processes, the method can resist quantum attacks and improve the security of the method.

[0079] It should be understood that the above description of the preferred embodiment is relatively detailed, and it should not be considered as a limitation on the protection scope of the present invention patent. Under the inspiration of the present invention, those of ordinary skill in the art can also make substitutions or deformations without departing from the protection scope defined by the claims of the present invention, and all fall within the protection scope of the present invention. The scope of protection requested by the present invention shall be subject to the appended claims.

Claims

1. A lattice-based revocable ring signature method for the vehicle network, characterized in that It includes the following steps: Step 1: Generate common parameters , the public key of the trusted party TA and the private key ; According to the security parameters , the trusted party TA generates a random matrix , and outputs the public parameters , where and are cyclotomic polynomial rings, is a polynomial ring with integer coefficients, q is the modulus, denotes the ring consisting of all polynomials whose coefficients are taken from ; I denotes the identity matrix, is a concatenation symbol; represents the matrix of , and the elements in all belong to the ring ; q, d, h, v 's value depends on the security parameter ;​ Step 2: The user i generates a public key and a private key ; Step 3: The signer generates a revocable tag and includes it as part of the final signature; Step 4: The signer generates a ring signature m for the message , and sends the message-signature pair , timestamp T , the number of ring members n , the set of public keys of all members in the ring , and the public key of the trusted party TA to the verifier V ; Step 5: The verifier verifies the signature; When the signer's identity needs to be exposed, the trusted party TA uses the private key to decrypt the revocable tag, obtains the signer's public key, and outputs the signer's identity; The specific implementation includes the following sub-steps: Step 6.1: The trusted party TA checks the signature value z to see if it is valid. If it is, execute the following process; Otherwise, abort the process; Step 6.2: Parse the signature value z to obtain the revocable label ; Step 6.3: The trusted party TA calculates the identity of the signer wherein the elements in represent a v dimensional column vector; Step 6.4: According to , the trusted party TA obtains L from the public key group 's public key , exposing the identity of the signer.

2. The lattice-based revocable ring signature method for the vehicle networking according to claim 1, wherein: In step 1, the trusted party TA uniformly and randomly selects , where the elements in and denote , satisfying ; and respectively denote v dimensional and h dimensional column vectors, and the elements in the column vectors all belong to , 's value depends on the security parameter ; calculate ; output the public key of the trusted party TA and the private key .

3. The lattice-based revocable ring signature method for vehicle networking according to claim 1, wherein: In Step 2, the user i uniformly and randomly selects as its private key , and calculates , let serve as i 's public key; where represents , satisfying ; and respectively represent v -dimensional and h -dimensional column vectors, and the elements in the column vectors all belong to , 's value depends on the security parameter ; Generate i identity wherein , is a cryptographic hash function ; wherein x represents a variable is the variable coefficient 4. The lattice-based revocable ring signature method for the vehicle networking according to claim 2, wherein The specific implementation of Step 3 includes the following sub-steps: Step 3.1: The signer randomly and uniformly generates a vector , where denotes , satisfying ; and respectively denote v -dimensional and h -dimensional column vectors, and the elements in the column vectors all belong to , 's value depends on the security parameter ; Step 3.2: Randomly generate , calculate . If is irreversible, re - execute Step 3.2: Step 3.3: The signer calculates the revocable tag : Among them, represents a rounding operation, the identity of , represents the public key of the trusted party.

5. The lattice-based revocable ring signature method for the vehicle Internet of Things according to claim 4, wherein The specific implementation of Step 4 includes the following sub-steps: Step 4.1: Generate the challenge values of the members in the ring ;​ Among them, H is a cryptographic hash function, , D is the challenge space, , T represents the timestamp; represents the set of partial public keys of all members of the ring ; ; n represents the number of ring members, represents the message; , that is, ; depends on the security parameter ; Step 4.2: Generate the members in the ring challenge value ; Among them, randomly and uniformly generate , , , and calculate ; Calculate the intermediate parameter ; Calculate the intermediate parameter Calculate the intermediate parameter Step 4.3: Calculate the response value Step 4.4: Calculate the response value Step 4.5: Calculate the response value Step 4.6: If or , then abort the process and restart from in Step 4.2; Step 4.7: Output the message signature value of .

6. The lattice-based revocable ring signature method for the vehicle Internet of Things according to claim 5, characterized in that The specific implementation of Step 5 includes the following sub-steps: Step 5.1: The signature verifier V Checks and Whether it holds. If it does not hold, the signature verification is aborted; if it holds, the following Step 5.2 is continued; Step 5.2: Parse the signature value z to obtain the revocable label ; Step 5.3: Calculate the challenge value wherein ; Step 5.4: Determine whether holds; If the equation holds, accept the signature; otherwise, reject the signature; output the verification result and end the process.

7. A lattice-based revocable ring signature system for the vehicle Internet of Things, characterized in that, It includes the following modules: Module 1, for generating common parameters , the public key of the trusted party TA and the private key ; According to the security parameter , the trusted party TA generates a random matrix , and outputs the public parameter , where and are cyclotomic polynomial rings, is a polynomial ring with integer coefficients, q is the modulus, denotes the ring consisting of all polynomials whose coefficients are taken from ; I denotes the identity matrix, is a concatenation symbol; represents the matrix of , and the elements in all belong to the ring ; q, d, h, v 's value depends on the security parameter ;​​​ Module 2, for users i generate a public key and a private key ; Module 3, for the signer Generate a revocable tag , and use it as part of the final signature; Module 4, for the signer Generate a ring signature for the message m and send the message-signature pair , timestamp , number of ring members T , set of public keys of all members in the ring n , and the public key of the trusted party TA to the verifier ; V ​ Module 5, which is used for the verifier to verify the signature; When the signer's identity needs to be exposed, the trusted party TA uses the private key to decrypt the revocable tag, obtains the signer's public key, and outputs the signer's identity; The specific implementation includes the following sub-modules: Module 6.1, for the trusted party TA to check whether the signature value z is valid. If it is, execute the following process; otherwise, abort the process; Module 6.2, for parsing the signature value z , to obtain a revocable label ; Module 6.3, for the trusted party TA to calculate the identity of the signer of which wherein the elements in denote v a column vector of dimension Module 6.4, for according to , the trusted party TA obtains L from the public key group of the public key , exposing the identity of the signer.

Citation Information

Patent Citations

  • An editable, linkable, and non-repudiable ring signature method

    CN110071812B

  • Signature ring signature method provided with specified revocability

    CN103117858A

  • Schnorr ring signature scheme with specified verifiability

    CN105187212A