Identity Authentication-based RSA Multiple Blind Signature Method and System

The signature initiator is authenticated through the RSA algorithm and the CA authentication center mechanism, which solves the problem of impersonation signature and aggregate signature invalidity in multiple blind signatures, realizes the traceability of identity authentication and signatures, and reduces the time complexity.

CN118337392BActive Publication Date: 2025-07-22SHANXI TENGSHI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410374316.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-29
Publication Date
2025-07-22
Estimated Expiration
2044-03-29

AI Technical Summary

Technical Problem

The existing multi-blind signature technology cannot authenticate the signature initiator, which poses the risk of impersonating the signature. If a certain signature in the aggregate signature is incorrect, the overall signature will be invalid and the incorrect signature cannot be traced.

Method used

The RSA algorithm is used to encrypt the information, authenticate through RSA public key encryption and private key decryption, and use the CA authentication center mechanism to share the public key locally to ensure that the signature initiator is successful after the authentication of the signature initiator is successful, and the shortcomings of aggregated signatures are solved using an authentication-based method.

Benefits of technology

It effectively prevents impersonating signatures, reduces the time complexity from 1 to O(n), realizes identity verification and signature traceability of signature initiator, and avoids the problem of aggregation signature failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118337392B_ABST
    Figure CN118337392B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of information security, and specifically refers to an RSA multiple blind signature method and system based on identity authentication. The method includes RSA initialization, CA public key certificate registration, public key certificate exchange, public key acquisition and verification, information encryption, signature initiation and multiple signatures, signature reception and verification, information sending, and information reception. The present invention uses the RSA algorithm to encrypt information, and at the same time adopts the CA authentication and local public key sharing mechanism to realize the authentication of message signatures, preventing impersonation of signature initiation and impersonation of signatures; the present invention adopts a scatter-type signature and identity authentication mechanism to realize the traceability of incorrect signatures and prevent the overall signature from failing due to a single incorrect signature, which can effectively replace the aggregate signature, and the time complexity only changes from 1 to O(n); the system includes a key generation tool, a data encryption and decryption module, a data signature and verification module, a trusted certification authority CA, an information storage device, and a transaction processor.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security, and specifically relates to an RSA multiple blind signature method and system based on identity authentication. Background Art

[0002] Multiple blind signature is a digital signature scheme extended on the basis of blind signature. Blind signature is a special digital signature that allows the signer to sign the user's information without knowing the specific content of the information. This property is very useful for protecting user privacy and achieving anonymity. The goal of multiple blind signature is that in the case of multi-party participation, each signer can sign the blinded information and finally return the signature result to the signature initiator; multiple blind signature is of great significance in protecting user privacy and achieving anonymity, and is particularly suitable for scenarios that require multi-party participation and involve privacy protection, such as anonymous voting systems, signatures for multi-party cooperation agreements, etc.; however, the existing multiple blind signature technology cannot authenticate the signature initiator, which will pose a risk of impersonating the initiator of the signature. In order to improve efficiency, the existing multiple blind signature adopts the form of aggregate signature. When there is an error in a certain signature in the aggregate signature, the aggregate signature will become invalid and it is impossible to trace the incorrect signature. Summary of the Invention

[0003] In view of the above situation, in order to overcome the defects of the existing technology, the present invention provides an RSA multiple blind signature method and system based on identity authentication. Aiming at the problem that the existing multiple blind signature technology cannot authenticate the signature initiator and there is a risk of impersonating the initiator of the signature, the present invention uses the RSA algorithm to encrypt information, adopts the method of encrypting with the RSA public key and decrypting with the private key to prevent information from being stolen by others, and uses the form of signing with the private key and verifying the signature with the public key to authenticate the signature initiator and all signers, preventing impersonation of the initiator of the signature and impersonation of the signature. The CA certification center mechanism is adopted to realize the local sharing of the public key, further preventing impersonation of the signature; aiming at the problem that in order to improve efficiency, the existing multiple blind signature adopts the form of aggregate signature, and when there is an error in a certain signature in the aggregate signature, the aggregate signature will become invalid and it is impossible to trace the incorrect signature, the present invention adopts a method based on identity authentication. After all signers successfully authenticate the identity of the signature initiator, they each sign the encrypted information and send their respective signatures to the signature initiator, effectively solving the shortcoming of aggregate signature, and at the same time the processing time complexity only changes from 1 to O(n).

[0004] The technical solution adopted by the present invention is as follows: The RSA multiple blind signature method based on identity authentication specifically includes the following steps:

[0005] Step S1: RSA initialization. The information receiver uses a key generation tool to generate an RSA public key, an RSA private key, the modulus n of RSA, the exponent e of the public key, and the exponent d of the private key according to the RSA algorithm.

[0006] Step S2: CA public key certificate registration. The information receiver, the information sender, and all signers designate a certification authority as the trusted certification authority CA, and define fingerprint and iris scans as the identity proof. The information receiver uses the identity proof of the information receiver and the RSA public key of the information receiver to register for the CA public key certificate at the trusted certification authority CA. The trusted certification authority CA initializes the private key and the public key of the trusted certification authority CA.

[0007] Step S3: Public key certificate exchange. The information sender and all signers use a key generation tool to generate their respective RSA public keys and RSA private keys according to the RSA algorithm, and conduct CA public key certificate registration. After the registration is completed, the information sender, the information receiver, and all signers share the CA public key certificate through a secret channel.

[0008] Step S4: Public key acquisition and verification. The information sender decrypts and authenticates the public key certificates of the information receiver and all signers according to the public key of the trusted certification authority CA to obtain the public keys of the information receiver and all signers. The information receiver decrypts and authenticates the public key certificates of the information sender and all signers according to the public key of the trusted certification authority CA to obtain the public keys of the information sender and all signers. All signers decrypt and authenticate the public key certificate of the information sender according to the public key of the trusted certification authority CA to obtain the public key of the information sender.

[0009] Step S5: Information encryption. Define the information a to be sent by the information sender as the information to be encrypted. The information sender converts the information to be encrypted into a digital form m, ensuring that the digital m is within the range of 0 to n - 1, and uses the RSA public key of the information receiver to encrypt the information to be encrypted, calculating the ciphertext c = m^e mod n, where m is the information to be encrypted and c is the encrypted ciphertext.

[0010] Step S6: Signature initiation and multi-signature. The information sender initiates a signature request, and all signers perform a multi-signature on the information to obtain a re-signed ciphertext and send it to the information sender. The number of all signers is y, and the information sender sets the signature number threshold as x.

[0011] Step S7: Signature reception and verification. The information sender receives the re - signed ciphertext from the signer and verifies the identity of the re - signed ciphertext according to the RSA public key corresponding to the signer. If the verification is successful, the signature count is incremented by 1; if the verification fails, the signature count remains unchanged. And corresponding signer identity tags are attached to all the re - signed ciphertexts.

[0012] Step S8: Information sending. When the final signature count z is between the threshold x and the number y of all signers, the information sender sends the ciphertext c, the signed ciphertext C, and all the re - signed ciphertexts to the information receiver.

[0013] Step S9: Information reception. The information receiver receives the ciphertext c, the signed ciphertext C, and all the re - signed ciphertexts, uses the identity tag to select the corresponding signer's RSA public key to verify the identity of the re - signed ciphertext, uses the information sender's RSA public key to authenticate the signed ciphertext C. After all the identity authentications are successful, the information receiver uses its private key to decrypt the ciphertext c to obtain the digital form m, and converts the digital form m into information to get the information a.

[0014] Further, step S1 specifically includes the following steps:

[0015] Step S11: The key generation tool selects two different large prime numbers p and q, calculates the product n = pq of p and q, and calculates the Euler's totient function φ(n)=(p - 1)(q - 1).

[0016] Step S12: Randomly select an integer e and define e as the exponent of the public key, where 1 < e < φ(n) and e is relatively prime to φ(n).

[0017] Step S13: Calculate the inverse element d of e in the φ(n) domain and define d as the exponent of the private key, such that ed = 1 mod φ(n).

[0018] Step S14: Key generation. Define (e, n) as the RSA public key of the information receiver and (d, p, q) as the RSA private key of the information receiver.

[0019] Further, step S2 specifically includes the following steps:

[0020] Step S21: Create a certificate signing request. The information receiver uses the RSA public key and the RSA private key to create a certificate signing request, where the certificate signing request includes the public key and the identity information of the information receiver.

[0021] Step S22: Submit the certificate signing request. Submit the certificate signing request to the trusted certification authority CA.

[0022] Step S23: Identity verification. The trusted certification authority CA verifies the identity of the information receiver.

[0023] Step S24: Issue a certificate. After authentication is passed, the trusted Certification Authority (CA) uses its private key to sign the certificate signing request to obtain the CA public key certificate, where the certificate contains the RSA public key.

[0024] Further, step S6 specifically includes the following steps:

[0025] Step S61: The information sender uses its own private key to sign the ciphertext c to obtain the signed ciphertext C, and broadcasts the signed ciphertext C to all signers. At the same time, a signature count threshold x is set, where the signature threshold is between 0 and the number y of all signers.

[0026] Step S62: The signer uses the RSA public key of the information sender to authenticate the signed ciphertext to verify whether the information is sent by the information sender.

[0027] Step S63: After successful authentication and the signer confirms that the information is sent by the information sender, the signer uses its own private key to sign the signed ciphertext again to obtain the re-signed ciphertext.

[0028] Step S64: The signer sends the re-signed ciphertext to the information sender.

[0029] The RSA multi-blind signature system based on authentication provided by the present invention includes a key generation tool, a data encryption and decryption module, a data signature and verification module, a trusted Certification Authority (CA), an information storage device, and a transaction processor.

[0030] The key generation tool uses a specific algorithm to generate a public key and a private key, transmits the specific algorithm to the data encryption and decryption module and the signature and verification module, and transmits all data to the information storage module.

[0031] The data encryption and decryption module encrypts the data to be encrypted using the public key and a specific algorithm, decrypts the encrypted data using the key and a specific algorithm, and transmits all data to the information storage module.

[0032] The data signature and verification module signs the information using the private key and a specific algorithm, and verifies the signature using the public key and a specific algorithm.

[0033] The trusted Certification Authority (CA) binds the public key of the certificate registrant and the real identity information of the certificate registrant, uses its private key to encrypt the public key and identity information of the certificate registrant to obtain the CA public key certificate, and at the same time provides the public key of the Certification Authority (CA). The public key and real identity information of the certificate registrant can be obtained from the CA public key certificate.

[0034] The information storage is used to store all shared public key certificates, the public keys corresponding to all shared public key certificates, the information to be encrypted, ciphertext, signed ciphertext, and re-signed ciphertext;

[0035] The transaction processor is used to initiate signatures, collect re-signed ciphertexts, and is also used to send ciphertexts, signed ciphertexts, and re-signed ciphertexts.

[0036] The beneficial effects achieved by the present invention using the above solution are as follows:

[0037] (1) Aiming at the problem that the existing multi-blind signature technology cannot authenticate the signature initiator, there is a risk of impersonating the initiator of the signature. The present invention uses the RSA algorithm to encrypt information, adopts the method of encrypting with the RSA public key and decrypting with the private key to prevent information from being stolen by others, and uses the form of signing with the private key and verifying the signature with the public key to authenticate the signature initiator and all signers, preventing impersonation of the signature initiator and impersonation of signatures. By using the CA certification center mechanism, local sharing of public keys is realized, further preventing impersonation of signatures;

[0038] (2) Aiming at the problem that in order to improve efficiency, the existing multi-blind signature adopts the method of aggregate signature. When there is an error in a certain signature in the aggregate signature, the aggregate signature will become invalid and it is impossible to trace the incorrect signature. The present invention adopts an identity verification-based method. After all signers successfully authenticate the identity of the signature initiator, they each sign the encrypted information and send their respective signatures to the signature initiator, effectively solving the shortcoming of aggregate signatures. At the same time, the time complexity of processing only changes from 1 to O(n). Brief Description of the Drawings

[0039] Figure 1 It is a schematic flowchart of the RSA multi-blind signature method based on identity verification provided by the present invention;

[0040] Figure 2 It is a schematic diagram of public key certificate sharing;

[0041] Figure 3 It is a schematic diagram of the information transfer process;

[0042] Figure 4 It is a schematic diagram of the modules of the RSA multi-blind signature system based on identity verification provided by the present invention;

[0043] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. Detailed Embodiments

[0044] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0045] In the description of the present invention, it should be understood that the terms "upper", "lower", "front", "rear", "left", "right", "top", "bottom", "inner", "outer", etc. indicating the orientation or positional relationship are based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention.

[0046] Embodiment 1, refer to Figure 1 , Figure 2 , Figure 3 , the RSA multiple blind signature method based on identity authentication provided by the present invention specifically includes the following steps:

[0047] Step S1: RSA initialization. The information receiver uses a key generation tool to generate an RSA public key, an RSA private key, the modulus n of RSA, the exponent e of the public key, and the exponent d of the private key according to the RSA algorithm.

[0048] Step S2: CA public key certificate registration. The information receiver, the information sender, and all signers designate a certification authority as the trusted certification authority CA, and define fingerprint and iris scans as the identity proofs. The information receiver uses the identity proof of the information receiver and the RSA public key of the information receiver to perform CA public key certificate registration at the trusted certification authority CA. The trusted certification authority CA initializes the private key and the public key of the trusted certification authority CA.

[0049] Step S3: Public key certificate exchange. The information sender and all signers use a key generation tool to generate their respective RSA public keys and RSA private keys according to the RSA algorithm, and perform CA public key certificate registration. After the registration is completed, the information sender, the information receiver, and all signers share the CA public key certificates through a secret channel.

[0050] Step S4: Public key acquisition and verification. The information sender decrypts and authenticates the public key certificates of the information receiver and all signers using the public key of the trusted Certification Authority (CA), and obtains the public keys of the information receiver and all signers. The information receiver decrypts and authenticates the public key certificates of the information sender and all signers using the public key of the trusted Certification Authority (CA), and obtains the public keys of the information sender and all signers. All signers decrypt and authenticate the public key certificate of the information sender using the public key of the trusted Certification Authority (CA), and obtain the public key of the information sender;

[0051] Step S5: Information encryption. Define the information a to be sent by the information sender as the information to be encrypted. The information sender converts the information to be encrypted into digital form m, ensuring that the digital m is within the range of 0 to n - 1. Use the RSA public key of the information receiver to encrypt the information to be encrypted, and calculate the ciphertext c = m^e mod n, where m is the information to be encrypted and c is the encrypted ciphertext;

[0052] Step S6: Signature initiation and multi-signature. The information sender initiates a signature request, and all signers perform multi-signature on the information to obtain the re-signed ciphertext and send it to the information sender. The number of all signers is y, and the information sender sets the signature number threshold as x;

[0053] Step S7: Signature reception and verification. The information sender receives the re-signed ciphertext from the signers, and based on the corresponding RSA public key of the signers, authenticates the re-signed ciphertext. If the verification is successful, the signature number is incremented by 1; if the verification fails, the signature number remains unchanged, and corresponding signer identity tags are attached to all the re-signed ciphertexts;

[0054] Step S8: Information sending. When the final signature number z is between the threshold x and the number y of all signers, the information sender sends the ciphertext c, the signature ciphertext C, and all the re-signed ciphertexts to the information receiver;

[0055] Step S9: Information reception. The information receiver receives the ciphertext c, the signature ciphertext C, and all the re-signed ciphertexts, uses the identity tags to select the corresponding RSA public keys of the signers to authenticate the re-signed ciphertexts, uses the RSA public key of the information sender to authenticate the signature ciphertext C. After all the identity authentications are successful, use the private key of the information receiver to decrypt the ciphertext c to obtain the digital form m, and convert the digital form m into information to obtain the information a.

[0056] Embodiment 2. Based on the above embodiment, the code implementation of the RSA encryption and decryption algorithm is as follows:

[0057] import random

[0058] import math

[0059] def generate_key(p, q):

[0060] # Calculate the modulus

[0061] n = p * q

[0062] # Calculate the Euler's totient function value

[0063] phi = (p - 1) * (q - 1)

[0064] # Select an integer e that is relatively prime to phi, 1 < e < phi

[0065] e = random.randrange(1, phi)

[0066] while math.gcd(e, phi) != 1:

[0067] e = random.randrange(1, phi)

[0068] # Calculate the modular multiplicative inverse d of e

[0069] d = pow(e, -1, phi)

[0070] # Return the public key and private key

[0071] return (e, n), (d, n)

[0072] def encrypt(message, public_key):

[0073] e, n = public_key

[0074] # Encrypt the message using the exponent e and modulus n of the public key

[0075] encrypted_message = [pow(ord(c), e, n) for c in message]

[0076] return encrypted_message

[0077] def decrypt(encrypted_message, private_key):

[0078] d, n = private_key

[0079] # Decrypt the encrypted message using the exponent d and modulus n of the private key

[0080] decrypted_message = [chr(pow(c, d, n)) for c in encrypted_message]

[0081] return ''.join(decrypted_message)

[0082] # Example usage

[0083] # Generate key pair

[0084] public_key, private_key = generate_key(17, 23)

[0085] # Message to be encrypted

[0086] message = "Hello, RSA!"

[0087] # Encrypt the message using the public key

[0088] encrypted_message = encrypt(message, public_key)

[0089] print("Encrypted message:", encrypted_message)

[0090] # Decrypt the message using the private key

[0091] decrypted_message = decrypt(encrypted_message, private_key)

[0092] print("Decrypted message:", decrypted_message)

[0093] Example 3. This example is based on the above example. Step S1 specifically includes the following steps:

[0094] Step S11: The key generation tool selects 2 different large prime numbers p and q, calculates the product n = pq of p and q, and calculates the Euler's totient function φ(n) = (p - 1)(q - 1);

[0095] Step S12: Randomly select an integer e and define e as the exponent of the public key, where 1 < e < φ(n) and e is relatively prime to φ(n);

[0096] Step S13: Calculate the inverse element d of e in the φ(n) domain and define d as the exponent of the private key, ed = 1 mod φ(n);

[0097] Step S14: Key generation. Define (e, n) as the RSA public key of the information receiver, and define (d, p, q) as the RSA private key of the information receiver.

[0098] Example 4. Based on the above example, step S2 specifically includes the following steps:

[0099] Step S21: Create a certificate signing request. The information receiver uses the RSA public key and the RSA private key to create a certificate signing request, where the certificate signing request includes the public key and the identity information of the information receiver.

[0100] Step S22: Submit the certificate signing request. Submit the certificate signing request to a trusted certification authority CA.

[0101] Step S23: Identity verification. The trusted certification authority CA verifies the identity of the information receiver.

[0102] Step S24: Issue a certificate. After the identity verification passes, the trusted certification authority CA uses its own private key to sign the certificate signing request to obtain the CA public key certificate, where the certificate contains the RSA public key.

[0103] Example 5. Based on the above example, step S6 specifically includes the following steps:

[0104] Step S61: The information sender uses its own private key to sign the ciphertext c to obtain the signed ciphertext C, and broadcasts the signed ciphertext C to all signers. At the same time, set the signature count threshold x, where the signature threshold is between 0 and the number y of all signers.

[0105] Step S62: The signer uses the RSA public key of the information sender to authenticate the signed ciphertext to verify whether the information is sent by the information sender.

[0106] Step S63: After the identity verification is successful and the signer confirms that the information is sent by the information sender, the signer uses its own private key to sign the signed ciphertext again to obtain the re-signed ciphertext.

[0107] Step S64: The signer sends the re-signed ciphertext to the information sender.

[0108] Example 6. Refer to Figure 4 , the RSA multi-blind signature system based on identity verification provided by the present invention

[0109] includes a key generation tool, a data encryption and decryption module, a data signature and verification module, a trusted certification authority CA, an information storage, and a transaction processor;

[0110] The key generation tool uses a specific algorithm to generate a public key and a private key, transmits the specific algorithm to the data encryption and decryption module and the signature and verification module, and transmits all data to the information storage module;

[0111] The data encryption and decryption module encrypts the data to be encrypted using the public key and the specific algorithm, decrypts the encrypted data using the private key and the specific algorithm, and transmits all data to the information storage module;

[0112] The data signature and verification module signs the information using the private key and the specific algorithm, and verifies the signature information using the public key and the specific algorithm;

[0113] The trusted Certification Authority (CA) binds the public key of the certificate registrant and the real identity information of the certificate registrant, encrypts the public key and identity information of the certificate registrant using the private key of the trusted Certification Authority (CA) to obtain the CA public key certificate, and at the same time provides the public key of the Certification Authority (CA), and can verify the CA public key certificate to obtain the public key and real identity information of the certificate registrant;

[0114] The information storage is used to store all shared public key certificates, the public keys corresponding to all shared public key certificates, the information to be encrypted, ciphertext, signature ciphertext, and re-signature ciphertext;

[0115] The transaction processor is used to initiate signatures, collect re-signature ciphertext, and is also used to send ciphertext, signature ciphertext, and re-signature ciphertext.

[0116] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device.

[0117] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

[0118] The above description of the present invention and its embodiments is not restrictive. What is shown in the drawings is only one of the embodiments of the present invention, and the actual structure is not limited thereto. In general, if those of ordinary skill in the art are inspired by it and, without departing from the gist of the present invention, design similar structural modes and embodiments to this technical solution without creative efforts, they shall fall within the protection scope of the present invention.

Claims

1. An identity-based RSA multi-blind signature method, characterized in that: It includes the following steps: Step S1: RSA initialization. The information receiver uses a key generation tool to generate an RSA public key, an RSA private key, the modulus n of RSA, the exponent e of the public key, and the exponent d of the private key according to the RSA algorithm; Step S2: CA public key certificate registration. The information receiver, the information sender, and all signers designate a certification authority as the trusted certification authority CA, and set fingerprint and iris scans as the identity proof. The information receiver uses the identity proof of the information receiver and the RSA public key of the information receiver to register the CA public key certificate with the trusted certification authority CA. The trusted certification authority CA initializes the private key and the public key of the trusted certification authority CA; Step S3: Public key certificate exchange. The information sender and all signers use a key generation tool to generate their respective RSA public keys and RSA private keys according to the RSA algorithm, and conduct CA public key certificate registration. After the registration is completed, the information sender, the information receiver, and all signers share the CA public key certificate through a secret channel; Step S4: Public key acquisition and verification. The information sender decrypts and authenticates the public key certificates of the information receiver and all signers according to the public key of the trusted certification authority CA to obtain the public keys of the information receiver and all signers. The information receiver decrypts and authenticates the public key certificates of the information sender and all signers according to the public key of the trusted certification authority CA to obtain the public keys of the information sender and all signers. All signers decrypt and authenticate the public key certificate of the information sender according to the public key of the trusted certification authority CA to obtain the public key of the information sender; Step S5: Information Encryption. Define the information a to be sent by the information sender as the information to be encrypted. The information sender converts the information to be encrypted into digital form m, ensuring that the number m is within the range of 0 to n - 1. Use the RSA public key of the information receiver to encrypt the information to be encrypted, and calculate the ciphertext c = m e mod n, where m is the digital form of the information to be encrypted and c is the encrypted ciphertext; Step S6: Signature initiation and multi-signature. The information sender initiates a signature request, and all signers perform a multi-signature on the information to obtain a re-signed ciphertext and send it to the information sender. The number of all signers is y, and the information sender sets the signature number threshold as x; Step S7: Signature reception and verification. The information sender receives the re-signed ciphertext from the signers, and authenticates the re-signed ciphertext according to the corresponding RSA public key of the signer. If the verification is successful, the signature number is incremented by 1. If the verification fails, the signature number remains unchanged, and corresponding signer identity tags are attached to all the re-signed ciphertexts; Step S8: Information sending. When the final signature number z is between the threshold x and the number y of all signers, the information sender sends the ciphertext c, the signature ciphertext C, and all the re-signed ciphertexts to the information receiver; Step S9: Information reception. The information receiver receives the ciphertext c, the signature ciphertext C, and all the re-signed ciphertexts, uses the identity tag to select the corresponding RSA public key of the signer to authenticate the re-signed ciphertext, uses the RSA public key of the information sender to authenticate the signature ciphertext C. After all the identity authentications are successful, the information receiver decrypts the ciphertext c using the private key of the information receiver to obtain the digital form m, and converts the digital form m into information to obtain the information a.

2. The RSA multi-blind signature method based on authentication according to claim 1, characterized in that: Step S1 specifically includes the following steps: Step S11: The key generation tool selects two different large prime numbers p and q, calculates the product n = pq of p and q, and calculates the Euler's totient function φ(n) = (p - 1)(q - 1); Step S12: Randomly select an integer e and define e as the exponent of the public key, where 1 < e < φ(n) and e is relatively prime to φ(n); Step S13: Calculate the inverse element d of e in the φ(n) domain and define d as the exponent of the private key, ed = 1 mod φ(n); Step S14: Key generation, define (e, n) as the RSA public key of the information receiver, and define (d, p, q) as the RSA private key of the information receiver.

3. The RSA multi-blind signature method based on identity authentication according to claim 1, wherein: Step S2 specifically includes the following steps: Step S21: Create a certificate signing request. The information receiver uses the RSA public key and the RSA private key to create a certificate signing request, where the certificate signing request includes the public key and the identity information of the information receiver; Step S22: Submit the certificate signing request and submit the certificate signing request to a trusted certification authority CA; Step S23: Identity verification. The trusted certification authority CA verifies the identity of the information receiver; Step S24: Issue a certificate. After the identity verification is passed, the trusted certification authority CA uses the private key of the trusted certification authority CA to sign the certificate signing request to obtain the CA public key certificate, where the certificate contains the RSA public key.

4. The RSA multiple blind signature method based on identity authentication according to claim 1, wherein: Step S6 specifically includes the following steps: Step S61: The information sender uses its own private key to sign the ciphertext c to obtain the signed ciphertext C, and sends the signed ciphertext C to all signers in a broadcast form, and at the same time sets the signature count threshold x, where the signature count threshold x is between 0 and the number y of all signers; Step S62: The signer uses the RSA public key of the information sender to authenticate the signed ciphertext to verify whether the information is sent by the information sender; Step S63: After the identity verification is successful and the signer confirms that the information is sent by the information sender, the signer uses its own private key to sign the signed ciphertext again to obtain the re-signed ciphertext; Step S64: The signer sends the re-signed ciphertext to the information sender.

5. An identity-based RSA multi-blind signature system for implementing the identity-based RSA multi-blind signature method according to any one of claims 1 to 4, characterized in that: The identity authentication-based RSA multi-blind signature system includes a key generation tool, a data encryption and decryption module, a data signature and verification module, a trusted certification authority CA, an information storage device, and a transaction processor; The key generation tool uses the RSA algorithm to generate a public key and a private key, transmits the RSA algorithm to the data encryption and decryption module and the data signature and verification module, and transmits all data to the information storage module; The data encryption and decryption module enables the information receiver, the information sender, and the signer to generate the RSA public key, the RSA private key, the modulus of RSA, and the exponent of the public key according to the RSA algorithm through the key generation tool. The information sender uses the RSA public key of the information receiver to encrypt the information to be encrypted, and enables the information receiver to use the information receiver's private key to decrypt the ciphertext to obtain the information that the information sender wants to send; The data signature and verification module is used by the information sender and signer to sign the ciphertext with their own private keys, and the information receiver uses the public keys of the information sender and signer and the RSA algorithm to verify the signature; The trusted Certification Authority (CA) binds the public key of the certificate registrant and the real identity information of the certificate registrant, encrypts the public key and identity information of the certificate registrant with the private key of the trusted Certification Authority (CA) to obtain the CA public key certificate, and at the same time provides the public key of the Certification Authority (CA) to decrypt and authenticate the identity of the information receiver and the public key certificates of all signers of the CA public key certificate, and obtains the public keys of the information receiver and all signers; The information storage is used to store all shared public key certificates, the public keys corresponding to all shared public key certificates, the information to be encrypted, ciphertext, signed ciphertext, and re-signed ciphertext; The transaction processor is used to initiate signatures, collect re-signed ciphertext, and is also used to send ciphertext, signed ciphertext, and re-signed ciphertext.

Citation Information

Patent Citations

  • RSA multiple blind signature method and device based on identity

    CN116455582A

  • Method and device for certificateless partially blind signature

    WO2018119670A1