An SM9 Ring Signature Method and System with Constant-Level Signature Size
Through the SM9 ring signature method, based on the identity password system and password accumulator structure, the problem of low signature efficiency is solved, constant-level signature size is realized, and signature and verification efficiency is improved. It is suitable for electronic cash, electronic voting and anonymous communication.
Patent Information
- Application Number
- CN202310243785.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-09
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2043-03-09
AI Technical Summary
The signature method in the prior art is not efficient, especially with the large-scale user base, certificate management is complicated.
The SM9 ring signature method is adopted, based on the identity password system, and the password accumulator structure is used. The signer does not need other users to cooperate. The signature size is independent of the number of ring members, achieving constant-level signature size and verification efficiency.
It improves the efficiency of signature and verification operations, eliminates the certificate management problem in the traditional public key cryptography system, and is suitable for scenarios such as electronic cash, electronic voting and anonymous communication.
Smart Images

Figure CN116405217B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to an SM9 ring signature method and system with a constant signature size. Background Art
[0002] Ring signatures were first proposed by Rivest, Shami, and Tauman. A ring signature scheme allows users to form a temporary group and sign messages on behalf of the group without a central authority. A user may not even know that he has been included in a group, and even a party with infinite computing resources cannot find out who the signer is.
[0003] Traditional digital signature technology requires a third-party certificate authority CA to issue a public key certificate to prove the trusted binding relationship between the public key and the identity. However, this leads to complex certificate management problems when the number of users is too large. To solve this problem, Shamir proposed an identity-based public key cryptosystem, in which the user identity serves as the public key, and the user's private key is generated by the key generation center KGC according to the user identity. Zhang and Kim first proposed an identity-based ring signature scheme. Subsequently, many ring signature schemes based on bilinear pairs emerged. In an identity-based ring signature scheme, the participation of the central authority is limited to setting the initial public parameters and generating private keys from identities, rather than for forming groups.
[0004] The signature methods in the prior art have the technical problem of low efficiency. Summary of the Invention
[0005] The present invention provides an SM9 ring signature method and system with a constant signature size to solve or at least partially solve the technical problem of low efficiency existing in the signature methods in the prior art.
[0006] The first aspect of the present invention provides an SM9 ring signature method with a constant signature size, including:
[0007] Initialization step: The key generation center generates system public parameters;
[0008] Key generation step: The key generation center calculates the private key of the user and sends it to the corresponding user;
[0009] Ring signature step: The signer generates a signature value σ, x1, 2, …, according to the user's identity, the user's private key, the set of n member public keys n which respectively represent the identification hash values of the first user, the second user, …, the nth user as the member public keys;
[0010] Signature verification step: Based on the message m' to be verified, the signature value σ' to be verified, and the set of n member public keys Verify whether the signature passes.
[0011] In one embodiment, the initialization step specifically includes:
[0012] a) The key generation center inputs the security parameter λ. The parameter selection is the same as that of the national cryptography standard SM9 digital signature algorithm. A 256-bit BN curve is used to implement the bilinear pairing operation, and an N-order cyclic subgroup and its generator P1, the N-order cyclic subgroup and its generator P2, the bilinear pairing e: The cryptographic hash function chip(·):
[0013] b) Select
[0014] c) Randomly select as the master key and calculate the master public key P pub =[d]P2;
[0015] d) Create an instance of the dynamic accumulator, randomly select The accumulator value is initialized to V0 = [u]P1;
[0016] e) Randomly select where q is the maximum upper limit that can be accumulated by the accumulator;
[0017] f) The generated public parameters are
[0018] where, is the accumulator public key.
[0019] In one embodiment, the calculation method of the private key of user A in the key generation step is:
[0020]
[0021] where, ID A represents the identity identifier of user A, chip represents the cryptographic function derived from the cryptographic hash function, and is is the private key of user A.
[0022] In one embodiment, the ring signature step specifically includes:
[0023] a) For i ∈ [1, n], calculate x i =H(ID i );
[0024] b1 For the set n is at most q - 1, calculate
[0025] c) Calculate the proof
[0026] d) The knowledge signature consists of two parts. ① The proof W of user A proves x A = H(ID A ) in V, ② the private key of user A is legal,
[0027] Non - interactive zero - knowledge proof
[0028] The process of zero - knowledge proof is as follows: Select a random value Calculate A1 = [r1]G1+[r2]G2+[r3]G3; A2 = W+[r1]G2; α1 = [r1]x A ; α2 = [r2]x A ; α3 = [r3]x A ; π is equivalent to π′,
[0029]
[0030] Select a random value Calculate T1 = [k1]G1+[k2]G2+[k3]G3; T2 = [k4]G1+[k5]G2+[k6]G3 - [k7]A1; ch = H(Params||A1,..., A3||T1,..., T4||m); s1 = k1+ch·r1; s2 = k2+ch·r2; s3 = k3+ch·r3; s4 = k4+ch·α1; s5 = k5+ch·α2; s6 = k6+ch·α3; s7 = k7+ch·x A ;
[0031] e) Output the signature σ of message m = (ch, s1,..., s7, A1,..., A3, T1,..., T4, V);
[0032] where, x i is the hash value of the identifier of user i, V is the accumulator value in the ring signature phase, A1, A2, A3 respectively represent the commitment values of random numbers r1,..., r3, the commitment value of the proof W, the commitment value of the private key of user A ; T1, T2, T3, T4 respectively represent the commitment values of random numbers k1,..., k3, the commitment values of random numbers k4,..., k7, e(W, [x A P2+Ppub ) = e(V, P pub )'s commitment value, The commitment value, ch represents the challenge value, and s1, s2, s3, s4, s5, s6, s7 respectively represent the random values used to calculate the commitment.
[0033] In one implementation, the signature verification step specifically includes:
[0034] The verifier inputs the message m to be verified, the signature value σ' to be verified, and the set of n member public keys Verify whether the following equation holds: T′2? = [s4]G1 + [s5]G2 + [s6]G3 - [s7]A1;
[0035] If it holds, the signature is valid and accept is output; otherwise, the signature is invalid and reject is output;
[0036] Wherein, V′ is the accumulator value in the signature verification phase, and T′1, T′2, T′3, T′4 respectively represent opening the commitment T1, opening the commitment T2, opening the commitment T3, and opening the commitment T4.
[0037] Based on the same inventive concept, the second aspect of the present invention provides an SM9 ring signature system with a constant - level signature size, including:
[0038] An initialization module, used to generate system public parameters through a key generation center;
[0039] A key generation module, used to calculate the private key of the user through the key generation center and send it to the corresponding user;
[0040] A ring signature module, used by the signer to generate the signature value σ, x1, x2,..., x according to the user's identity, the user's private key, the set of n member public keys and the message m to be signed, n respectively represent the identity hash values of the first user, the second user,..., the nth user, as the member public keys;
[0041] A signature verification module, used by the verifier to verify whether the signature passes according to the message m′ to be verified, the signature value σ′ to be verified, and the set of n member public keys Verify whether the signature passes.
[0042] Based on the same inventive concept, the third aspect of the present invention provides a computer - readable storage medium, on which a computer program is stored, and when the program is executed, it implements the method described in the first aspect.
[0043] Based on the same inventive concept, a fourth aspect of the present invention provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method described in the first aspect is implemented.
[0044] Compared with the prior art, the advantages and beneficial technical effects of the present invention are as follows:
[0045] On the one hand, the present invention provides an SM9 ring signature method and system with a constant signature size. The method includes an initialization step, a key generation step, a ring signature step, and a signature verification step. Based on the signature structure of the SM9 digital signature algorithm, it eliminates the problem of certificate management in traditional public key cryptosystems. In this scheme, the signer generates a group signature without the cooperation of other users. On the other hand, it provides a structure based on a cryptographic accumulator, achieving a constant signature size and improving the efficiency of signature and verification operations. This scheme can be used in application scenarios such as electronic cash, electronic voting, and anonymous communication.
[0046] Traditional digital signature technologies require a third-party certificate authority (CA) to issue public key certificates to prove the trusted binding relationship between public keys and identities. However, this leads to complex certificate management problems when the number of users is large. To solve this problem, this scheme is based on the identity-based cryptosystem. The signer generates a group signature without the cooperation of other users. Based on the cryptographic accumulator structure, the size of the signature value is independent of the number of ring members, achieving a constant signature size and improving the efficiency of signature and verification operations. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0048] Figure 1 It is a flowchart of system initialization and user registration in the SM9 ring signature method with a constant signature size provided by the embodiment of the present invention;
[0049] Figure 2 It is a flowchart of ring signature and signature verification in the SM9 ring signature method with a constant signature size provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0050] The present invention discloses an SM9 ring signature method with a constant signature size, including a ring signature generation and verification method. Based on the signature structure of the SM9 digital signature algorithm, it eliminates the certificate management problem in the traditional public key cryptosystem. In this solution, the signer can generate the group signature without the cooperation of other users. Based on the structure of the cryptographic accumulator, it achieves a constant signature size and improves the efficiency of signature and verification operations. This solution can be used in application scenarios such as electronic cash, electronic voting, and anonymous communication.
[0051] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0052] Embodiment 1
[0053] The embodiment of the present invention provides an SM9 ring signature method with a constant signature size, including:
[0054] Initialization step: The key generation center generates system public parameters;
[0055] Key generation step: The key generation center calculates the private key of the user and sends it to the corresponding user;
[0056] Ring signature step: The signer generates a signature value σ, x1, x2,..., x according to the user's identity, the user's private key, the set of n member public keys and the message m to be signed, where n x1, x2,..., xn respectively represent the identity hash values of the first user, the second user,..., the nth user and are used as member public keys;
[0057] Signature verification step: According to the message m′ to be verified, the signature value σ′ to be verified, and the set of n member public keys verify whether the signature passes.
[0058] The SM9 identity-based cryptographic algorithm is an identity-based cryptographic standard released by the State Cryptography Administration on March 28, 2016 (Standard No.: GM / T 0044-2016 SM9 Identity-Based Cryptographic Algorithm), which mainly includes three parts: digital signature algorithm, public key encryption algorithm, and key exchange protocol. The SM9 standard meets the application requirements of electronic authentication service systems and other applications and fills the gap in the domestic identity-based cryptographic system.
[0059] The specific symbols adopted and involved in this application are described as follows:
[0060] q: A large prime number.
[0061] KGC: Key Generation Center.
[0062] The set of integers consisting of 1, 2,...., q - 1.
[0063] An additive cyclic group of order N.
[0064] A multiplicative cyclic group of order N.
[0065] P1, P2: Generators of the groups and respectively.
[0066] G1, G2, G3: Generators of the groups respectively.
[0067] λ: Security parameter.
[0068] [k]P: The k - multiple point of point P on the elliptic curve, where k is a positive integer.
[0069] e: A bilinear pairing mapping from to respectively.
[0070] Hash(·): A cryptographic function derived from a cryptographic hash function, for
[0071] d: The master secret key held secretly by KGC.
[0072] P pub : The public master key published by KGC, calculated as P pub = [d]P2.
[0073] ID i : The identity identifier of user i.
[0074] The private key of user i.
[0075] x i : The hash value of the identifier of user i, calculated as x i = H(ID i ).
[0076] m: The message to be signed.
[0077] π, π′: Non - interactive zero - knowledge proofs.
[0078] σ: The signature value of the message.
[0079] mod q: modular arithmetic modulo q. For example, 31 mod 5 ≡ 1.
[0080] x||y: the concatenation of x and y, where x and y can be bit strings or byte strings.
[0081] V: accumulator value.
[0082] u, r1, ..., r3, k1, ..., k7: random elements in the group
[0083] W: the signer's witness.
[0084] SOK: short for signature of knowledge.
[0085] ?=: determine whether the two sides of the equation are equal.
[0086] Params: public parameters
[0087] An SM9 ring signature method with a constant signature size proposed by the present invention mainly includes ring signature generation and verification, and involves three roles: a key generation center, a signer, and a verifier.
[0088] In one implementation, the initialization step specifically includes:
[0089] a) The key generation center inputs the security parameter λ. The parameter selection is the same as that of the national cryptographic standard SM9 digital signature algorithm. A 256-bit BN curve is used to implement the bilinear pairing operation, and an N-order cyclic subgroup and its generator P1, an N-order cyclic subgroup and its generator P2, and the bilinear pairing e: the cryptographic hash function H(·):
[0090] b) Select
[0091] c) Randomly select as the master key and calculate the master public key P pub = [d]P2;
[0092] d) Create an instance of the dynamic accumulator, randomly select and initialize the accumulator value to V0 = [u]P1;
[0093] e) Randomly select where q is the maximum upper limit value that can be accumulated by the accumulator;
[0094] f) The generated public parameters are
[0095] Among them, is the accumulator public key.
[0096] Please refer to Figure 1 , which is the system initialization and user registration flowchart in the SM9 ring signature method with constant-level signature size provided by the embodiments of the present invention.
[0097] In one implementation, the calculation method of the private key of user A in the key generation step is:
[0098]
[0099] Among them, ID A represents the identity identifier of user A, and the slice represents the cryptographic function derived from the cryptographic hash function. is the private key of user A.
[0100] In one implementation, the ring signature step specifically includes:
[0101] a) For i ∈ [1, n], calculate x i = H(ID i );
[0102] b1 For the set n is at most q - 1, calculate
[0103] c) Calculate the proof
[0104] d) The knowledge signature consists of two parts. ① The proof W of user A proves that x A = H(ID A ) is in V. ② The private key of user A is legal.
[0105] Non-interactive zero-knowledge proof
[0106] The process of zero-knowledge proof is as follows: Select a random value Calculate A1 = [r1]G1 + [r2]G2 + [r3]G3; A2 = W + [r1]G2; α1 = [r1]x A ; α2 = [r2]x A ; α3 = [r3]x A ; π is equivalent to π'.
[0107]
[0108] Select a random value Calculate T1 = [k1]G1 + [k2]G2 + [k3]G3; T2 = [k4]G1 + [k5]G2 + [k6]G3 - [k7]A1; ch = H(Params||A1,..., A3||T1,..., T4||m); s1 = k1 + ch·r1; s2 = k2 + ch·r2; s3 = k3 + ch·r3; s4 = k4 + ch·α1; s5 = k5 + ch·α2; s6 = k6 + ch·α3; s7 = k7 + ch·x A ;
[0109] e) Output the signature σ of message m = (ch, s1,..., s7, A1,..., A3, T1,..., T4, V);
[0110] where, x i is the identity hash value of user i, V is the accumulator value in the ring signature phase, A1, A2, A3 respectively represent the commitment values of random numbers r1,..., r3, the commitment value of evidence W, and the commitment value of the private key of user A ; T1, T2, T3, T4 respectively represent the commitment values of random numbers k1,..., k3, the commitment values of random numbers k4,..., k7, and the commitment value of e(W, [x A P2 + P pub ) = e(V, P pub ) ; ch represents the challenge value, and s1, s2, s3, s4, s5, s6, s7 respectively represent the random values used to calculate the commitment.
[0111] In the specific implementation process, the ring signature step is run by the signer, which can be any user, such as user A or user B. In step b), given , the calculation of the V value does not require knowing s, and V can be calculated in polynomial time.
[0112] In one implementation, the verification step specifically includes:
[0113] The verifier inputs the message m to be verified, the signature value σ' to be verified, and the set of n member public keys Verify whether the following equation holds: T′1? = [s1]G1 + [s2]G2 + [s3]G3 - [ch]A1; T′2? = [s4]G1 + [s5]G2 + [s6]G3 - [s7]A1;
[0114] If it holds, the signature is valid and the output is acceptance; otherwise, the signature is invalid and the output is rejection.
[0115] Among them, V′ is the accumulator value in the signature verification stage, and T′1, T′2, T′3, T′4 respectively represent opening commitment T1, opening commitment T2, opening commitment T3, and opening commitment T4.
[0116] In the specific implementation process, the ring signature step is run by the verifier.
[0117] Please refer to Figure 2 , which is the flow chart of ring signature and signature verification in the SM9 ring signature method with constant-level signature size provided by the embodiment of the present invention.
[0118] The present invention discloses a method for generating and verifying an SM9 ring signature with a constant-level signature size. Based on the signature structure of the SM9 digital signature algorithm, it eliminates the management problem of certificates in the traditional public key cryptosystem. In this solution, the signer generates the group signature process without the cooperation of other users. Based on the password accumulator structure, it realizes a constant-level signature size and improves the operation efficiency of signature and verification. This solution can be used in application scenarios such as electronic cash, electronic voting, and anonymous communication.
[0119] Embodiment 2
[0120] Based on the same inventive concept, this embodiment provides an SM9 ring signature system with a constant-level signature size, including:
[0121] An initialization module, used to generate system public parameters through a key generation center;
[0122] A key generation module, used to calculate the private key of the user through the key generation center and send it to the corresponding user;
[0123] A ring signature module, used to generate signature values σ, x1, x2,..., x by the signer according to the user's identity, the user's private key, a set of n member public keys and the message m to be signed. n x1, x2,..., x respectively represent the identity hash values of the 1st user, the 2nd user,..., the nth user, and are used as member public keys;
[0124] A signature verification module, used to verify whether the signature passes by the verifier according to the message m′ to be verified, the signature value σ′ to be verified, and a set of n member public keys
[0125] Since the system described in the second embodiment of the present invention is the system adopted by the SM9 ring signature method with a constant signature size in the first embodiment of the present invention, based on the method described in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of the system, so it will not be elaborated here. Any system adopted by the method in the first embodiment of the present invention falls within the scope of protection of the present invention.
[0126] Embodiment Three
[0127] Based on the same inventive concept, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed, it implements the method described in Embodiment One.
[0128] Since the computer-readable storage medium described in the third embodiment of the present invention is the computer-readable storage medium adopted by the SM9 ring signature method with a constant signature size in the first embodiment of the present invention, based on the method described in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of the computer-readable storage medium, so it will not be elaborated here. Any computer-readable storage medium adopted by the method in the first embodiment of the present invention falls within the scope of protection of the present invention.
[0129] Embodiment Four
[0130] Based on the same inventive concept, the present application also provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the above program, it implements the method in Embodiment One.
[0131] Since the computer device described in the fourth embodiment of the present invention is the computer device adopted by the SM9 ring signature method with a constant signature size in the first embodiment of the present invention, based on the method described in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of the computer device, so it will not be elaborated here. Any computer device adopted by the method in the first embodiment of the present invention falls within the scope of protection of the present invention.
[0132] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.
[0133] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices produce a means for realizing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 a means for realizing the functions specified in one block or multiple blocks.
[0134] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made to these embodiments by those skilled in the art once they learn the basic creative concept. Therefore, the appended claims are intended to be interpreted to include the preferred embodiments as well as all changes and modifications falling within the scope of the present invention.
[0135] Obviously, those skilled in the art can make various changes and modifications to the embodiments of the present invention without departing from the spirit and scope of the embodiments of the present invention. Thus, if these modifications and variations of the embodiments of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention also intends to include these changes and modifications.
Claims
1. A SM9 ring signature method with a constant-level signature size, characterized in that, Including: Initialization step: The key generation center generates system public parameters; Key generation step: The key generation center calculates the private key of the user and sends it to the corresponding user; Ring signature steps: The signer generates a signature value σ based on the user's identity, the user's private key, a set of public keys of n members and the message m to be signed, where x1, x2, …, x n represent the hash values of the identities of the first user, the second user, …, the nth user respectively, serving as the public keys of the members. Signature verification step: Based on the message m' to be verified, the signature value σ' to be verified, and the set composed of n member public keys Verify whether the signature passes; The initialization step specifically includes: a) The key generation center inputs the security parameter λ. The parameter selection is the same as that of the national cryptography standard SM9 digital signature algorithm. A 256-bit BN curve is used to implement the bilinear pairing operation, and an N-order cyclic subgroup and its generator P1, the N-order cyclic subgroup and its generator P2, the bilinear pairing cryptographic hash function b) Select c) Randomly select as the master secret key and calculate the master public key P pub = [d]P2; d) Create a dynamic accumulator instance and randomly select Initialize the accumulator value to V0 = [u]P1; e) Random selection where q is the maximum upper limit value that can be accumulated by the accumulator; f) The generated common parameter is Among them, is the accumulator public key; The calculation method of the private key of user A in the key generation step is: Among them, ID A represents the identity identifier of User A, and H represents the password function derived from the password hashing function, which is the private key of User A.
2. The SM9 ring signature method with a constant-level signature size according to claim 1, characterized in that, The ring signature step specifically includes: a) For i ∈ [1, n], compute x i = H(ID i ); b) For the set where n is at most q - 1, calculate c) Calculate evidence d) The knowledge signature consists of two parts. ① The evidence W of user A proves x A = H(ID A ) in V. ② The private key of user A is legal. Non-Interactive Zero-Knowledge Proof The process of zero - knowledge proof is as follows: Select random values Calculate A1 = [r1]G1+[r2]G2+[r3]G3; A2 = W+[r1]G2; α1 = [r1]x A ; α2 = [r2]x A ; α3 = [r3]x A ; π is equivalent to π′, Select random values Calculate T1 = [k1]G1+[k2]G2+[k3]G3; T2 = [k4]G1+[k5]G2+[k6]G3 - [k7]A1; ch = H(Params‖A1,…,A3‖T1,…,T4‖m); s1 = k1+ch·r1; s2 = k2+ch·r2; s3 = k3+ch·r3; s4 = k4+ch·α1; s5 = k5+ch·α2; s6 = k6+ch·α3; s7 = k7+ch·x A ; e) Output the signature σ=(ch, s1, …, s7, A1, …, A3, T1, …, T4, V) of the message m; where x i is the identity hash value of user i, V is the accumulator value in the ring signature phase, A1, A2, A3 represent the commitment values of random numbers r1, …, r3, the commitment value of evidence W, and the private key of user A 's commitment value, T1, T2, t3, T4 represent the commitment values of random numbers k1, …, k3, and the commitment values of random numbers k 44 , …, k7, e(W, [x A P2 + P pub ) = e(V, P pub )'s commitment value, 's commitment value, ch represents the challenge value, and s1, s2, s3, s4, s5, s6, s7 represent the random values used to calculate the commitment respectively.
3. The SM9 ring signature method with a constant-level signature size as described in claim 1, characterized in that, The signature verification step specifically includes: The verifier inputs the message m to be verified, the signature value σ′ to be verified, and the set consisting of n member public keys Verify whether the following equation holds: T′1 = [s1]G1 + [s2]G2 + [s3]G3 - [ch]A1; T′2 = [s4]G1 + [s5]G2 + [s6]G3 - [s7]A1; If it holds, the signature is valid and accept is output; otherwise, the signature is invalid and reject is output; Wherein, V′ is the accumulator value in the signature verification stage, and T′1, T′2, T′3, T′4 respectively represent the opening commitments T1, T2, T3, T4.
4. An SM9 ring signature system with a constant-level signature size, characterized in that, Including: Initialization module, used to generate system public parameters through the key generation center; Key generation module, used to calculate the private key of the user through the key generation center and send it to the corresponding user; Ring signature module, which is used to generate a signature value σ, x1, x2, …, x by a signer according to the identity of a user, the private key of the user, and a set of public keys of n members and a message m to be signed n respectively representing the identity hash values of the first user, the second user, …, the nth user as the public keys of the members Signature verification module, which is used by a verifier to verify whether a signature passes according to a message m' to be verified, a signature value σ' to be verified, and a set composed of n member public keys Verify whether the signature passes; The initialization module is specifically used for: a) The key generation center inputs the security parameter λ. The parameter selection is the same as that of the national cryptographic standard SM9 digital signature algorithm. A 256-bit BN curve is used to implement the bilinear pairing operation, and an N-order cyclic subgroup and its generator P1, the N-order cyclic subgroup and its generator P2, the bilinear pairing the cryptographic hash function b) Select c) Randomly select as the master secret key, and calculate the master public key P pub = [d]P2; d) Create a dynamic accumulator instance and randomly select Initialize the accumulator value to V0 = [u]P1; e) Random selection where q is the maximum upper limit value that can be accumulated by the accumulator; f) The generated common parameter is Among them, is the accumulator public key; The calculation method of the private key of user A in the key generation module is: Among them, ID A represents the identity identifier of User A, and H represents the password function derived from the password hashing function, and is the private key of User A.
5. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method according to any one of claims 1 to 3.
6. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method according to any one of claims 1 to 3.