Lattice-based unique ring signature digital signature method

CN117240476BActive Publication Date: 2026-08-14QUFU NORMAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-17
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

验证者使用环中所有成员的公钥集验证签名的有效性,且验证者只能确认签名来自于该环,但无法确认是由哪个成员生成的签名

Benefits of technology

[0004]本发明要解决的技术问题在于,为了抵抗量子计算机的攻击,验证者不必知晓签名者的且能保证同一环中的任一签名者只能对同一个消息签署一次有效的签名,本发明提供了一种基于格的唯一环签名的签名方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117240476B_ABST
    Figure CN117240476B_ABST
Patent Text Reader

Abstract

This invention belongs to the field of cryptography, specifically unique ring signature mechanisms and lattice cryptography. To resist attacks from quantum computers and achieve anonymity in ring signature mechanisms, this invention provides a unique ring signature method based on lattice cryptography. This method generates a secure key pair by randomly selecting a private key and then using the modulo operation to calculate the public key, making the obtained key pair resistant to quantum computer attacks. By using an indistinguishable distribution to generate the ring signature, the signature achieves anonymity, while also containing a unique tag, ensuring that each signer can only use the same ring to validly sign the same message once.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of cryptography, and relates to unique ring signature mechanisms and lattice cryptography. By constructing ring signatures with unique tags, it achieves privacy protection by keeping the signer anonymous. Background Technology

[0002] Ring signatures were first proposed by Rivest et al. to achieve anonymity. In a ring signature scheme, no one except the signer knows who the actual signer is. The ring is dynamically generated autonomously by the signer, who can generate a signature using their own private key and the public keys of other members without their knowledge. The verifier uses the public key set of all members in the ring to verify the validity of the signature, and the verifier can only confirm that the signature comes from the ring, but cannot confirm which member generated the signature. Franklin and Zhang introduced unique ring signatures, proposing for the first time a simple and general method for constructing unique ring signatures. A unique ring signature has a unique tag composed of a list of ring members, the message, and the signer's private key, used to ensure that any signer in the same ring can only sign a valid signature for the same message once.

[0003] With the development of quantum computers, the security of traditional unique ring signatures has been compromised. Finding cryptographic methods resistant to quantum algorithm attacks has become an urgent practical problem in the upcoming quantum computing era. Lattice cryptography possesses excellent resistance to quantum attacks, and operations on lattices are relatively simple and fast. This paper combines unique ring signature schemes with lattice cryptography to design a lattice-based unique ring signature method, improving the anonymity of the signature system. Summary of the Invention

[0004] The technical problem to be solved by this invention is that, in order to resist attacks from quantum computers, the verifier does not need to know the signer and can guarantee that any signer in the same ring can only sign a valid signature for the same message once. This invention provides a signature method based on lattice-unique ring signature.

[0005] The technical method adopted in this invention is as follows: First, by using the Fiat-Shamir lattice signature construction method based on the SIS hard problem to generate the key and signature, the method can resist attacks from quantum computers. Second, by adding a unique tag to the signature, this invention ensures that any signer in the same ring can only sign a valid signature for the same message once, thus guaranteeing the privacy and security of the signing stage.

[0006] A strongly forward-secure signature method based on identity on the grid, which consists of four entities: the requester, the signer, the other members forming the ring, and the verifier. Attached Figure Description

[0007] Figure 1 Key generation and ring signature process; Detailed Implementation

[0008] The signature method based on lattice-based unique ring signatures consists of four algorithms: system initialization algorithm, key generation algorithm, signature algorithm, and verification algorithm. Detailed descriptions are given below.

[0009] (1) System initialization Input security parameters , For positive integers, prime number q = ploy( ), where n and m are positive integers. Random parameters are generated through random sampling. Define hash function , Output common parameters ;

[0010] (2) Key generation algorithm Input system common parameters The signer chooses a random vector Use your own private key, then calculate modq is the paired public key;

[0011] (3) Signature Algorithm In this algorithm, the signer needs to sign a message sent by the requester. Signed using their private key; the actual signer First, select some members S = [1, N]( The public key of ) |i = 1,2,...,N} form a ring R, calculate = (R,M), then obtain the unique label. Randomly select vectors The signer calculates a hash value for the next ring member. Randomly select vectors (where i = , 2,...,N,1,2,..., -1) The signer uses the public key and hash value of the previous ring member to calculate the hash value of the next ring member, i.e., calculates... ,in After all ring member hash values ​​have been calculated, the hash value of the signer is calculated for the last time. Then use calculate Output signature σ=( d 1 , S z,i ϵ [1,N] , );

[0012] (4) Signature verification algorithm After receiving the message M, signature σ, public key list set R, and public parameters PP, the verifier calculates... Where i = 1, 2, ..., N; calculate the hash value. = ( , , ), where i = 1, 2, ..., N; if If the verification passes, the signature is accepted; otherwise, the signature is rejected. Validation of the Invention

[0013] To verify the validity of this invention, this patent provides evidence and analysis from the aspects of correctness and anonymity, which are described in detail below.

[0014] This invention combines lattice cryptography with unique ring signature technology to propose a signature method based on lattice-based unique ring signatures. To verify the correctness of this method, this patent provides a correctness analysis process, as shown below: exist In the case of It can be obtained from the signature algorithm; exist In the case of, there are Therefore, there is always By verifying the signature, it can be confirmed that the signature was indeed made by the private key holder and that the message has not been tampered with or modified during transmission, thus guaranteeing the correctness of the signature.

[0015] This invention proposes a signature method based on lattice-based unique ring signatures, which satisfies anonymity; this patent provides a security analysis model, as shown below: (1) Theorem 1: Under the random oracle model, based on the hardness assumption of the ISIS problem, the unique ring signature scheme based on lattice has anonymity; (2) We prove the anonymity of the scheme through the following game, in which C is the challenger and A is the opponent. The specific game process is as follows: (2.1) Initialization phase Challenger C runs the system initialization algorithm, obtains the public parameters PP and the public key set R that constitutes the ring, and sends the public parameters PP to the adversary A; (2.2) Phase 1 Question: For any i = 1, 2, N, C maintain a List of inquiries ,in express The hash value, the initial list is empty. A pairs conduct Ask, if exist In the middle, C will As a response The response to the query, otherwise C randomly selects one. ,Will As a response The response to the inquiry, and Add to middle; Question: For any i = 1, 2, N, C maintain a List of inquiries ,in express The hash value, the initial list is empty. A pairs conduct Ask, if exist In the middle, C will As a response The response to the query, otherwise C randomly selects one. ,Will As a response The response to the inquiry, and Add to middle; Key query: C maintains a list The initial list is empty. C responds with the following key query: C first browses the list. If a corresponding private key exists, return the corresponding private key directly; otherwise, C randomly selects one. and will Add to middle; Signature Query: Adversary A queries the signature of message m; C first browses the list. If the list The corresponding private key exists in C, and C calculates it. u+ Output signature σ=( , Return it to A; otherwise, C is in the list. and Search vector and randomly select Through calculation get The final output signature σ =( , ); (2.3) Challenge Phase A chooses two numbers. , And a message and a ring ( ), the tuple ( , , , The bit is sent to C, which randomly and uniformly selects a bit b ← {0, 1} and performs the following operations: (2.3.1) Calculate h= ( ), ; (2.3.2) Random selection ,calculate ; (2.3.3) Selection (where i = , 2,...,N,1,2,..., -1), calculate ,in (2.3.4) Calculation ; (2.3.5) Output signature σ=( , ); (2.3.6) After that, C will return σ to A; (2.4) Phase Two After the challenge phase ends, A can continue to perform a finite number of polynomials. ask, Query, key query, and signature query, but A cannot perform a query on A. and Key query and signature query; (2.5) Guessing stage Opponent A's output As a conjecture about b, if b = Then opponent A wins the game, and the advantage of opponent A in overcoming the method described in this article is: |Pr [ b = b'] - 1 / 2| ,in Pr [ b = b'] Indicates b= The probability of; (3) Assume a key is used Perform signature output Using a key Perform signature output To achieve anonymity, proof of the signature is required. and They are indistinguishable. and It is by The function generates hash values ​​that are evenly distributed in the output space, exhibiting uniformity. and Statistically, they are indistinguishable. and All from They have the same distribution structure. and The statistical distance is negligible. and From the same ring For the same message To perform a signature, based on the deterministic nature of the hash function, h= ( The values ​​are consistent. If the adversary can successfully distinguish... and By comparing the two labels, C can find a non-zero vector r = Make With r=y, the simulator C can crack the ISIS problem with a significant advantage. However, since the ISIS problem is unsolvable, it is impossible for such an adversary to break the solution presented in this paper. Therefore, the solution is anonymous.

Claims

1. A lattice-based unique ring signature digital signature method, characterized in that: 1.1 System Initialization Algorithm Input security parameters , For positive integers, prime number q = poly( ), where n and m are positive integers, and random parameters are generated through random sampling. Define a hash function , Output common parameters ; 1.2 Key Generation Algorithm Input system common parameters The signer chooses a random vector Use your own private key, then calculate mod q is the paired public key; 1.3 Signature Algorithm In this algorithm, the signer needs to sign a message sent by the requester. Signed using their private key; the actual signer First, select some members S = [1, N]( The public key { |i = 1,2,...,N} form a ring R, calculate = (R,M), then obtain the unique label. Randomly select vectors The signer calculates a hash value for the next ring member. Randomly select vectors , where i= , 2,...,N,1,2,..., -1, the signer uses the public key and hash value of the previous ring member to calculate the hash value of the next ring member, i.e., calculates... ,in After all ring member hash values ​​have been calculated, the hash value of the signer is calculated for the last time. Then use calculate Output signature σ=( , ); 1.4 Verification Algorithm After receiving the message M, signature σ, public key list set R, and public parameters PP, the verifier calculates... Where i = 1, 2, ..., N; calculate the hash value. = ( , , ), where i = 1, 2, ..., N; if If the verification passes, the signature is accepted; otherwise, the signature is rejected.

Citation Information

Patent Citations

  • Lattice-based forward security certificateless digital signature scheme

    CN112380579A

  • Identity-based forward security ring signature method

    CN113505396A