Heterogeneous Aggregate Signature System for Verification Center

By setting the signature code in the verification center, efficient aggregate verification of signature terminals of heterogeneous cryptographic systems is achieved, the verification overhead problem of homogeneous cryptographic systems is solved, and a unified signature and authentication service is provided.

CN116647333BActive Publication Date: 2025-10-03THE SECOND RES INST OF CIVIL AVIATION ADMINISTRATION OF CHINA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310371578.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-10
Publication Date
2025-10-03
Estimated Expiration
2043-04-10

AI Technical Summary

Technical Problem

Existing aggregate signature protocols are mainly applicable to homogeneous cryptographic systems and are difficult to effectively verify the signatures of heterogeneous cryptographic systems, resulting in high overhead for verifiers during system initialization and signature verification.

Method used

A heterogeneous aggregate signature system is designed. By setting the feature code at the verification center, signature terminals of different cryptographic systems can sign based on their own systems. The verification center then performs aggregate verification in a unified manner, reducing the system initialization and signature verification overhead of the verifier.

Benefits of technology

It achieves efficient aggregate verification of signature terminals of heterogeneous cryptographic systems, reduces the system initialization and signature verification overhead of the verifier, and provides unified signature and authentication services for users of different cryptographic systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116647333B_ABST
    Figure CN116647333B_ABST
Patent Text Reader

Abstract

The present invention provides a heterogeneous aggregate signature system for a verification center, comprising: the verification center obtains a signature sequence (ID i ,m i ,R i ,S i ,T i ), calculate the ID i is the identity information of each signing terminal; m i is the message to be encrypted; T i is the timestamp; S i is the characteristic code of each signature terminal; R i =r i P, r i The parameter is randomly selected by each signing terminal; the equation is calculated and verified based on the signature code of each signing terminal type. If true, the signatures of n user terminals are verified successfully. This invention provides a system that, by rationally setting signature codes for aggregated verification, enables heterogeneous signing terminals to sign based on their respective public key systems, with the verification center then performing unified aggregated verification. This reduces the verifier's system initialization and signature verification overhead, and provides signature and authentication services for users of different cryptographic systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security data processing, and in particular to a heterogeneous aggregate signature system applied to a verification center. Background Art

[0002] Aggregate signatures are a key cryptographic signature method. An aggregate signature protocol allows any number of users to send their digital signatures to the same verifier over a public, insecure channel. The verifier can aggregate the signatures of any number of users and verify the validity of all signatures using a single signature verification algorithm. Aggregate signatures can significantly improve signature verification efficiency.

[0003] Existing public key cryptography systems fall into three categories: 1. Certificate-based public key systems, which use certificates to securely link user identities to their keys, typically employing Public Key Infrastructure (PKI) technology. 2. Identity-based public key systems (IBCs), in which a user's private key is generated by a trusted third party (a key generation center (KGC)) using an identity-based private key generation algorithm. 3. Certificateless public key cryptography (CLCs), in which a user's private key is determined by two secret factors: a key associated with the user's identity, extracted from the KGC, and a key generated by the user. Since one secret element cannot be calculated from the other, the KGC cannot determine the user's partial key, and the user cannot determine the partial key generated by the KGC. Therefore, certificateless cryptography systems lack key escrow.

[0004] If all participants in a cryptographic protocol belong to the same cryptographic system, then the protocol is a homogeneous cryptographic protocol. Otherwise, the protocol is a heterogeneous cryptographic protocol.

[0005] Currently, aggregate signature protocols based on isomorphic cryptographic protocols are relatively mature, mainly including the following:

[0006] In 2008, Wen and Ma [Y. Wen, J. Ma, An aggregate signature scheme with constant pairing operations, 2008 International Conference on Computer Science and Software Engineering, 2008, pp. 830-833.] proposed an aggregate signature protocol that requires only a fixed number of bilinear pairings. This protocol allows any number of PKI users to sign, and the verifier can aggregate and verify all the users' signatures at once. However, this method is only applicable to PKI.

[0007] In 2019, Yang et al. [X. Yang, R. Liu, M. Wang and G. Chen, Identity-based aggregate signature scheme in vehicle ad-hoc network, 2019 4th International Conference on Mechanical, Control and Computer Engineering, 2019, pp. 1046-1049.] proposed an aggregate signature protocol suitable for connected vehicles. This protocol allows any number of IBC users to sign, and the verifier can aggregate and verify all the signatures at once. However, this method is only applicable to IBC.

[0008] In 2021, Kar et al. [J. Kar, X. Liu and F. Li, CL-ASS: An efficient and low-cost certificateless aggregate signature scheme for wireless sensor networks, Journal of Information Security and Applications, 2021, 61, p. 102905.] proposed an aggregate signature protocol for wireless sensor networks. This protocol allows any number of CLC users to sign, and the verifier can aggregate and verify all the signatures at once. However, this method is only applicable to CLCs. Summary of the Invention

[0009] In order to solve the above technical problems, the present invention aims to provide a system that enables multiple signature terminals belonging to heterogeneous cryptographic protocols to obtain parameters from broadcast system parameters, sign based on the public key system to which they belong, and the verification center to uniformly perform aggregate verification. By reasonably setting the feature code for aggregate verification, a verifier can verify the legitimacy of any number of user signatures from different cryptographic systems, thereby reducing the verifier's system initialization overhead and signature verification overhead, and providing signature and authentication services for users from different cryptographic systems.

[0010] In order to achieve the above-mentioned purpose, the technical solution provided by the present invention includes:

[0011] The heterogeneous aggregate signature system used in the verification center includes:

[0012] A certificate authority and signing terminal A that belong to a certificate-based public key system and communicate with each other; a private key generation center and signing terminal B that belong to an identity-based public key system and communicate with each other; a key generation center and signing terminal C that belong to a certificateless public key system and communicate with each other; and a verification center that communicates with signing terminals A, B, and C respectively;

[0013] The verification center is configured to broadcast system parameters to signing terminals A, B, and C. Where p is a large prime number; G is a p-order additive cyclic group; G T is a p-order multiplicative cyclic group; is a bilinear map; H0, H1 and H2 are collision-resistant hash functions, and H0 is a * Mapping to {0,1} n , H1 from {0,1} * Mapping to G, H2 from {0,1} * Map to is a binary sequence of arbitrary bit length; is the p-order integer field obtained by removing zero elements; P and Q are generators of G;

[0014] The verification center is configured to obtain the signature sequence (ID i ,m i ,R i ,S i ,T i ),calculate Where ID i is the identity information of each signing terminal; m i is the message to be encrypted; T i is the timestamp; S i is the characteristic code of each signature terminal; R i =r i P, ri For each signing terminal Randomly selected parameters in ;

[0015] The verification center calculates the signature code of each type of signature terminal separately and

[0016] Verify the equation Is it true? If so, the signature verification of n user terminals is successful; otherwise, the verification fails.

[0017] In some preferred embodiments, the method for the verification center to obtain the characteristic code of the signing terminal A belonging to the certificate-based public key system includes:

[0018] Get the signature code S of the signature terminal A belonging to the certificate-based public key system a , S a =(r a +h a sk a )Q; where h a =H2(ID a ,m i ,T i ,R a );sk a For signing terminal A The first private key randomly selected from sk a =x a ; R a =r a P.

[0019] In some preferred embodiments, the method for the verification center to obtain the characteristic code of the signing terminal B belonging to the identity-based public key system includes:

[0020] Obtain the signature code S of the signature terminal B belonging to the identity-based public key system b , in h b =H2(ID b ,m i ,T i ,R b ); s1H1(ID b );P pub1 is the public key corresponding to the master key s1 provided by the private key generation center and P pub1 =s1P;R b =r b P;

[0021] In some preferred embodiments, the method for the verification center to obtain the characteristic code of the signing terminal C based on the certificateless public key system includes:

[0022] Get the signature code S of the signature terminal C based on the certificateless public key system c , S c =psk c +h c r c P pub2 +(r c +h c usk c )Q; where psk c =s2H1(ID c );h c =H2(ID c ,m i ,T i ,R c ); P pub2 is the public key corresponding to the master key s2 provided by the key generation center and P pub2 =s2P;R c =r c P; the third private key usk c For the signature terminal C from The randomly selected private key and usk c =x c .

[0023] In some preferred embodiments, the verification center verifies the equation The methods to determine whether it is valid include:

[0024] The feature code S a , Feature Code S b and signature S c Substituting into the verification equation, we can get:

[0025]

[0026] Among them, pk a is the first private key sk a The corresponding public key and pk a =x a P; upk c The third private key usk c The corresponding public key and upk c =x c P;

[0027] Will Set as the verification code CA of signing terminal A a;Will Set as the verification code CA of signing terminal B b ; respectively and Set as the verification code CA of the signature terminal C c2 and CA c1 ;

[0028] Then the above verification equation can be converted to:

[0029]

[0030] Beneficial effects

[0031] The present invention provides a system that can reasonably set feature codes for aggregate verification, so that heterogeneous signature terminals can sign based on their own public key systems and the verification center can uniformly perform aggregate verification, thereby reducing the system initialization overhead and signature verification overhead of the verifier and providing signature and authentication services for users from different cryptographic systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 A schematic diagram of the system structure in a preferred embodiment of the present invention; DETAILED DESCRIPTION

[0033] In order to make the objectives, technical solutions and advantages of the present invention more clear, the present invention is further described below with reference to the accompanying drawings. In the description of the present invention, it should be understood that the terms "upper", "lower", "front", "back", "left", "right", "top", "bottom", "inner", "outer", etc., indicating directions or positional relationships, are based on the directions or positional relationships shown in the accompanying drawings and are only for the convenience of describing the present invention and simplifying the description. They do not indicate or imply that the devices or components referred to must have a specific direction, be constructed and operate in a specific direction. Therefore, they should not be understood as limiting the present invention.

[0034] Example 1

[0035] like Figure 1 As shown, this embodiment provides a heterogeneous aggregate signature system applied to a verification center, including:

[0036] A certificate authority and signing terminal A that belong to a certificate-based public key system and communicate with each other; a private key generation center and signing terminal B that belong to an identity-based public key system and communicate with each other; a key generation center and signing terminal C that belong to a certificateless public key system and communicate with each other; and a verification center that communicates with signing terminals A, B, and C respectively;

[0037] The verification center broadcasts system parameters to signing terminals A, B, and C Where p is a large prime number; G is a p-order additive cyclic group; G T is a p-order multiplicative cyclic group; is a bilinear map; H0, H1 and H2 are collision-resistant hash functions, and H0 is a * Mapping to {0,1} n , H1 from {0,1} * Mapping to G, H2 from {0,1} * Map to {0,1} * is a binary sequence of arbitrary bit length; is the p-order integer field obtained by removing zero elements; P and Q are generators of G. It should be understood that in some preferred embodiments, the disclosure of the system parameter spp can also be broadcast by any signing terminal to all participants in the network, or can be disclosed by a verification center or other trusted third party. Each signing terminal applies for registration with its own public key system and initializes the system based on the system parameter spp.

[0038] Each signing terminal communicates with the authority of its own public key system to obtain identity verification and encryption keys, thereby obtaining permission for encryption operations. This type of step is a standard operation inherent in each public key system and will not be further elaborated in this invention.

[0039] The verification center is configured to obtain the signature sequence (ID i ,m i ,R i ,S i ,T i ),calculate Where ID i is the identity information of each signing terminal; m i is the message to be encrypted; T i is the timestamp; S i is the characteristic code of each signature terminal; R i =r i P, r i For each signing terminal It should be understood that the signature terminals A, B, and C calculate the signature code S according to their own public key system. i ,from Randomly select r i , calculate R i =r i P, the signature sequence (ID i ,m i ,R i ,S i ,T i) is sent to the verification center to complete the signature; i is the signature terminal identity information; m i is the message to be encrypted; T i is the timestamp; the signature code S of the signature terminal A a With the private key sk a About the signature terminal B's feature code S b Related to the master key s1; the signature code S of the signature terminal C c With the private key psk c and master key s2 and private key usk c Where a, b, c are the number of signature terminals A, B, C respectively, and a+b+c=n, n∈{1,2,…,i,…,n}. It should be understood that the feature code S i This system integrates the characteristics of the public key system described in the signing terminal and is designed based on subsequent verification needs. Its purpose is to eliminate the need for the verification center to initialize authentication system parameters for different public key systems when performing aggregate signature authentication. Instead, it verifies the legitimacy of the signature based on the identity information and messages of all signers, thereby reducing the verification center's system initialization and signature authentication overhead and providing authentication services for users from different cryptographic systems. Obviously, when the signing terminal communicates with the respective public key system service providers, it also includes a step to verify the identity and validity of the respective keys and / or public keys. If the verification fails, the aggregate signature process is canceled. Since this part is not the focus of the present invention, those skilled in the art can design it according to conventional methods in the prior art, and the present invention does not further limit it.

[0040] In some preferred embodiments, a characteristic code S is given. i Specific acquisition method, used to specifically explain the feature code S i characteristics and internal logic, but is not limited to the characteristic code S i The only way to obtain it.

[0041] The method for the verification center to obtain the characteristic code of the signature terminal A belonging to the certificate-based public key system includes:

[0042] Get the signature code S of the signature terminal A belonging to the certificate-based public key system a , S a =(r a +h a sk a )Q; where h a =H2(ID a ,m i ,T i,R a );sk a For signing terminal A The first private key randomly selected from sk a =x a ; R a =r a P.

[0043] The method for the verification center to obtain the characteristic code of the signature terminal B belonging to the identity-based public key system includes:

[0044] Obtain the signature code S of the signature terminal B belonging to the identity-based public key system b , in h b =H2(ID b ,m i ,T i ,R b ); s1H1(ID b );P pub1 is the public key corresponding to the master key s1 provided by the private key generation center and P pub1 =s1P;R b =r b P;

[0045] The method for the verification center to obtain the characteristic code of the signature terminal C based on the certificateless public key system includes:

[0046] Get the signature code S of the signature terminal C based on the certificateless public key system c , S c =psk c +h c r c P pub2 +(r c +h c usk c )Q; where psk c =s2H1(ID c );h c =H2(ID c ,m i ,T i ,R c ); P pub2 is the public key corresponding to the master key s2 provided by the key generation center and P pub2 =s2P;R c =r c P; the third private key usk c For the signature terminal C from The randomly selected private key and usk c =x c .

[0047] The design of the above signature code is as follows: With this design, the last two addends of the CLC signature code and the PKI signature code have the same form; the first two addends of the IBC signature code and the CLC signature code have the same form. This allows for three types of signature aggregation.

[0048] The verification center is configured to obtain a signature sequence (ID i ,m i ,R i ,S i ,T i ) and then perform aggregate verification. The aggregate verification is the corresponding step of the aggregate signature. In some preferred embodiments, in order to enable a verifier to verify the legitimacy of any number of user signatures from different cryptographic systems, thereby reducing the verifier's system initialization overhead and signature verification overhead, it provides signature and authentication services for users from different cryptographic systems. Calculate the signature and authentication services based on the signature code of each type of signature terminal. and

[0049] Verify the equation Is it true? If so, the signature verification of n user terminals is successful; otherwise, the verification fails.

[0050] It should be understood that when calculating the superposition of the characteristic values ​​of each type of signature terminal one by one, the steps are relatively cumbersome and require high computing power. Therefore, in some preferred embodiments, by reasonably setting the characteristic formula in the formula to the verification code corresponding to each public key system, the verification process can be made more efficient. Specifically, it includes:

[0051] The feature code S obtained in the previous step a , Feature Code S b and signature S c Substituting into the verification equation and simplifying:

[0052]

[0053] Among them, pk a is the first private key sk a The corresponding public key and pk a =x a P; upk c The third private key usk c The corresponding public key and upk c =x c P;

[0054] Will Set as the verification code of signature terminal A; Set as the verification code CA of signing terminal B b ; respectively and Set as the verification code CA of the signature terminal C c2 and CA c1 ;

[0055] Then the above verification equation can be converted to:

[0056]

[0057] The basic principles, main features, and advantages of the present invention are shown and described above. Those skilled in the art should understand that the present invention is not limited to the foregoing embodiments. The foregoing embodiments and descriptions are merely illustrative of the principles of the present invention. Various changes and modifications may be made to the present invention without departing from the spirit and scope of the present invention. Such changes and modifications are intended to fall within the scope of the present invention. The scope of protection claimed in the present invention is defined by the appended claims and their equivalents.

Claims

1. The heterogeneous aggregate signature system applied to the verification center is characterized by: include: A certificate authority and signing terminal A that belong to a certificate-based public key system and communicate with each other; a private key generation center and signing terminal B that belong to an identity-based public key system and communicate with each other; a key generation center and signing terminal C that belong to a certificateless public key system and communicate with each other; and a verification center that communicates with signing terminals A, B, and C respectively; The verification center is configured to broadcast the system parameters spp = {p, G, G T , P, Q, , H0,H1, H2}; where p is a large prime number; G is an additive cyclic group of order p; G T is a p-order multiplicative cyclic group; is a bilinear map; H0, H1 and H2 are collision-resistant hash functions, and H0 is a * Mapping to {0,1} n , H1 from {0,1} * Mapping to G, H2 from {0,1} * Map to ; {0,1} * is a binary sequence of arbitrary bit length; is the p-order integer field obtained by removing zero elements; P and Q are generators of G; The verification center is configured to obtain the signature sequence (ID i , m i , R i , S i , T i ),calculate ; Where ID i is the identity information of each signing terminal; m i is the message to be encrypted; T i is the timestamp; S i is the characteristic code of each signature terminal; R i = r i P, r i For each signing terminal Randomly selected parameters in ; The verification center calculates the signature code of each type of signature terminal separately 、 and ; Verify the equation Is it true? If so, the signature verification of n user terminals is successful; otherwise, the verification fails; where a, b, and c are the number of signature terminals A, B, and C respectively, and ; The method for the verification center to obtain the characteristic code of the signature terminal A belonging to the certificate-based public key system includes: Get the signature code S of the signature terminal A belonging to the certificate-based public key system a , S a = (r a + h a sk a )Q; where r a ;h a = H2(ID a , m i , T i , R a );sk a For signing terminal A The first private key randomly selected from sk a = x a ; R a = r a P.

2. The heterogeneous aggregate signature system for a verification center according to claim 1, characterized in that: The method for the verification center to obtain the characteristic code of the signature terminal B belonging to the identity-based public key system includes: Obtain the signature code S of the signature terminal B belonging to the identity-based public key system b , ; where r b ;h b = H2(ID b , m i , T i , R b ); for ;P pub1 is the public key corresponding to the master key s1 provided by the private key generation center and P pub1 = s1P;R b = r b P.

3. The heterogeneous aggregate signature system for verification center according to claim 2, characterized in that: The method for the verification center to obtain the characteristic code of the signature terminal C based on the certificateless public key system includes: Get the signature code S of the signature terminal C based on the certificateless public key system c , S c = psk c + h c r c P pub2 +(r c + h c usk c )Q; where psk c = s2H1(ID c );h c = H2(ID c , m i , T i , R c );r c ;P pub2 is the public key corresponding to the master key s2 provided by the key generation center and P pub2 = s2P;R c = r c P; the third private key usk c For the signature terminal C from The randomly selected private key and usk c = x c .

4. The heterogeneous aggregate signature system for verification center according to claim 3, characterized in that: The verification center verifies the equation The methods to determine whether it is valid include: The feature code S a , Feature Code S b and signature S c Substituting into the verification equation, we can get: ; Among them, pk a is the first private key sk a The corresponding public key and pk a = x a P; upk c The third private key usk c The corresponding public key and upk c = x c P; Will Set as the verification code CA of signing terminal A a ;Will Set as the verification code CA of signing terminal B b ; respectively and Set as the verification code CA of the signature terminal C c2 and CA c1 ; Then the above verification equation can be converted to: 。

Citation Information

Patent Citations

  • Block chain encryption method based on PKI-CLC heterogeneous aggregation signcryption algorithm

    CN106897879A