A certificateless aggregate signature method and system
The security of signatures is improved by generating part of the user's private key and calculating the target user's private key and public key in the certificate-free aggregation signature scheme. At the same time, the calculation of fixed-length aggregate signatures through hash value combination solves the problem of unfixed signature length in the existing solution, and achieves more efficient signature verification and storage.
Patent Information
- Application Number
- CN202410525003.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-29
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2044-04-29
AI Technical Summary
The existing certificate-free aggregation signature scheme has problems such as low security and unfixed aggregate signature length, resulting in high computing, communication and storage overhead.
The user's private key is generated through the key generation center, and the user terminal calculates the target user's private key and public key to improve the security of the user's public key. At the same time, a fixed-length aggregate signature is used to calculate a fixed-length aggregate signature by combining hash values.
Improve the security and efficiency of the certificate-free aggregation signature method, and reduce the storage and communication overhead of aggregation signatures.
Smart Images

Figure CN118540065B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of digital signatures, and more specifically, to a certificateless aggregate signature method and system. Background Art
[0002] Digital signatures can provide authentication, integrity, and non-repudiation and other security services for data transmission, and are one of the core technologies of information security. With the emergence of new network forms and network services, the study of digital signatures with special properties and their applications has become one of the research hotspots in cryptography. In 2003, Boneh et al. first proposed the concept of aggregate signatures. In an aggregate signature scheme, different users sign different messages separately, and these signatures can be aggregated into one signature. The verifier only needs to verify the aggregated signature to confirm whether the signature comes from the specified user, thereby reducing the workload of signature verification and the storage space of the signature. Aggregate signatures can be said to be a "batch processing" and "compression" technology in the field of digital signatures, which is very suitable for scenarios with limited bandwidth and resources.
[0003] Al-Riyami and Paterson proposed the concept of Certificateless Public Key Cryptography (CL-PKC) in 2003. Since the certificateless cryptographic system avoids the certificate management problem in the traditional public key cryptographic system and solves the key escrow problem in the identity-based cryptographic system, it has established a good balance between the traditional public key cryptographic system and the identity-based cryptographic system. In view of the many advantages of aggregate signatures and certificateless cryptographic systems, many scholars have conducted extensive research on certificateless aggregate signature algorithms.
[0004] However, the existing certificateless aggregate signature scheme has two main problems. First, the scheme is not secure. When performing security proof, the simulation of the impersonator is not complete enough. Specifically, when performing security proof, the impersonator will choose a challenge identity ID. * With the challenge message m * During the simulation process of the simulator, the adversary cannot ask for the challenge ID * Challenge message m * Signature, but can ask for challenge ID * For other non-challenge messages m(m≠m * ) signature, and the impersonator must be able to answer the query correctly. However, many schemes currently do not simulate the signature query of the challenge identity to the non-challenge message when performing security proof, resulting in low security of the scheme. Second, the length of the scheme's aggregate signature is not fixed, and the length of the aggregate signature increases linearly with the increase in the number of aggregated users, and its calculation, communication and storage overhead are all large. Summary of the invention
[0005] In response to at least one defect or improvement need in the prior art, the present invention provides a certificateless aggregate signature method and system, which will improve the security of the certificateless aggregate signature method, and the aggregate signature length is fixed, thereby also being able to improve the efficiency of the certificateless aggregate signature method.
[0006] To achieve the above object, according to a first aspect of the present invention, a certificateless aggregate signature method is provided, the method comprising:
[0007] The key generation center obtains security parameters, executes the system parameter establishment algorithm, generates the system master private key and the system master public key, secretly stores the system master private key, and discloses the system master public key;
[0008] Each user terminal obtains a user identity identifier, executes a user secret value generation algorithm, generates a user secret value and a first user public key, secretly stores the user secret value, discloses the user identity identifier, and sends the first user public key to a key generation center;
[0009] The key generation center executes a partial private key generation algorithm according to the system master private key, the user identity identifier and the corresponding first user public key to generate a user partial private key, and sends the user partial private key to the corresponding user terminal;
[0010] Each user terminal calculates the target user private key and the target user public key based on the system master public key, the corresponding user partial private key and the user secret value, executes the signature algorithm based on the target user private key and the target user public key, generates a user signature, and obtains an aggregate signature based on the user signatures generated by all user terminals, and verifies the aggregate signature.
[0011] Furthermore, the key generation center executes a partial private key generation algorithm based on the system master private key, the user identity identifier and the corresponding first user public key to generate a user partial private key, and sends the user partial private key to the corresponding user terminal, including the key generation center randomly selecting a prime number, and calculating the second user public key based on the product of the generator of the cyclic group and the prime number; performing an initial hash operation on the user identity identifier and the corresponding first user public key and second user public key to obtain a joint user public key calculated by the key generation center; performing a product operation on the joint user public key and the system master private key, summing the obtained product with the prime number to generate the user partial private key; and sending the second user public key and the user partial private key to the corresponding user terminal.
[0012] Further, each user terminal calculates the target user private key and the target user public key according to the system master public key, the corresponding user partial private key and the user secret value, including each user terminal receiving the second user public key and the user partial private key; performing an initial hash operation on its user identity identifier, the first user public key and the second user public key to obtain a joint user public key calculated by the user terminal; and verifying whether the first equation is established, the first equation is: d i P=Y i +P pub Q i , where d i represents the user's partial private key, P represents the generator of the cyclic group G, and Y i represents the second user's public key, P pub Represents the system master public key, Q i represents the joint user public key calculated by the user terminal; if the first equation holds, it means that the user partial private key is valid; when the user partial private key is valid, the combination of the user secret value and the user partial private key is used as the target user private key, and the combination of the first user public key and the second user public key is used as the target user public key.
[0013] Furthermore, a signature algorithm is executed according to the target user private key and the target user public key to generate a user signature, including each user terminal obtaining a message to be signed; randomly selecting a user prime number, and calculating the user random number according to the product of the generator of the cyclic group and the user prime number; performing a first hash operation on the message to be signed, the user identity identifier, the target user public key, and the user random number to obtain a first hash value calculated by the user terminal; performing a second hash operation on the message to be signed, the user identity identifier, the target user public key, and the system master public key to obtain a second hash value calculated by the user terminal; performing a third hash operation on the message to be signed, the user identity identifier, and the target user public key to obtain a third hash value calculated by the user terminal; calculating a comprehensive hash value according to the user prime number, the first hash value, the second hash value, the third hash value, and the target user private key; using a combination of the user random number and the comprehensive hash value as a user signature, and sending the user signature, the signed message corresponding to the user signature, and the target user public key to the aggregation terminal.
[0014] Furthermore, the certificateless aggregate signature method also includes the aggregation terminal receiving user signatures of all user terminals, signed messages corresponding to the user signatures, and target user public keys, executing a signature verification algorithm, and generating a signature tag for each user terminal, where the signature tag is 0 or 1, 0 indicates that the signature verification fails, and 1 indicates that the signature verification passes; calculating a first aggregate value based on the product of a first hash value calculated by the aggregation terminal for all user terminals whose signature tags are 1 and a user random number; calculating a second aggregate value based on a comprehensive hash value of all user terminals whose signature tags are 1; using a combination of the first aggregate value and the second aggregate value as an aggregate signature, and sending the aggregate signature, all signed messages, and the target user public keys corresponding to each signed message to the verification terminal.
[0015] Further, the aggregation terminal receives the user signatures of all user terminals, the signed messages corresponding to the user signatures, and the target user public key, executes the signature verification algorithm, and generates the signature tags of each user terminal, including the aggregation terminal receiving the user signatures of all user terminals, the signed messages corresponding to the user signatures, and the target user public key; performing an initial hash operation on the user identity identifier of each user terminal and the target user public key to obtain a joint user public key calculated by the aggregation terminal; performing a first hash operation on the signed message, the user identity identifier, the target user public key, and the user random number to obtain a first hash value calculated by the aggregation terminal; performing a second hash operation on the signed message, the user identity identifier, the target user public key, and the system master public key to obtain a second hash value calculated by the aggregation terminal; performing a third hash operation on the signed message, the user identity identifier, and the target user public key to obtain a third hash value calculated by the aggregation terminal; and verifying whether the second equation is established, the second equation is: S i P=h i R i +X i f i +g i (Y i +P pub Q i ), where S i represents the comprehensive hash value, P represents the generator of the cyclic group G, R i Indicates the user's random number, X i represents the first user's public key, Y i represents the second user's public key, P pub Represents the system master public key, Q i represents the joint user public key calculated by the aggregation terminal, h i represents the first hash value calculated by the aggregation terminal, f i represents the second hash value calculated by the aggregation terminal, g irepresents the third hash value calculated by the aggregation terminal; if the second equation holds, the user signature is determined to be a legal signature and 1 is output as the signature label; otherwise, the user signature is determined to be an illegal signature and 0 is output as the signature label.
[0016] Furthermore, the certificateless aggregate signature method further includes obtaining, by a verification terminal, an aggregate signature, all signed messages, and a target user public key corresponding to each signed message; performing an initial hash operation on a user identity identifier and a target user public key of each user terminal to obtain a joint user public key calculated by the verification terminal; performing a second hash operation on the signed message, the user identity identifier, the target user public key, and the system master public key to obtain a second hash value calculated by the verification terminal; performing a third hash operation on the signed message, the user identity identifier, and the target user public key to obtain a third hash value calculated by the verification terminal; and verifying whether a third equation holds, the third equation being: Where S represents the second aggregate value, R represents the first aggregate value, P represents the generator of the cyclic group G, and X i represents the first user's public key, Y i represents the second user's public key, P pub Represents the system master public key, Q i represents the joint user public key calculated by the verification terminal, f i represents the second hash value calculated by the verification terminal, g i represents the third hash value calculated by the verification terminal; if the third equation holds, the aggregate signature is determined to be a legal signature.
[0017] According to a second aspect of the present invention, there is also provided a certificateless aggregate signature system, which includes a key generation center and a plurality of user terminals, wherein the key generation center and the plurality of user terminals are communicatively connected;
[0018] The key generation center is used to obtain security parameters, execute the system parameter establishment algorithm, generate the system master private key and the system master public key, secretly store the system master private key, and disclose the system master public key;
[0019] Each user terminal is used to obtain a user identity identifier, execute a user secret value generation algorithm, generate a user secret value and a first user public key, secretly store the user secret value, disclose the user identity identifier, and send the first user public key to a key generation center;
[0020] The key generation center is further used to execute a partial private key generation algorithm according to the system master private key, the user identity identifier and the corresponding first user public key, generate a user partial private key, and send the user partial private key to the corresponding user terminal;
[0021] Each user terminal is also used to calculate the target user private key and the target user public key based on the system master public key, the corresponding user partial private key and the user secret value, execute the signature algorithm according to the target user private key and the target user public key, generate a user signature, so as to obtain an aggregate signature based on the user signatures generated by all user terminals, and verify the aggregate signature.
[0022] Furthermore, the certificateless aggregate signature system also includes an aggregate terminal, which is communicatively connected to a plurality of user terminals, and is used to receive user signatures of all user terminals, signed messages corresponding to the user signatures, and target user public keys, execute a signature verification algorithm, and generate a signature tag for each user terminal, where the signature tag is 0 or 1, 0 indicates that the signature verification fails, and 1 indicates that the signature verification passes; based on the user signatures of all user terminals with a signature tag of 1, an aggregate signature is obtained, and the aggregate signature, all signed messages, and the target user public keys corresponding to each signed message are sent to the verification terminal.
[0023] Furthermore, the certificateless aggregate signature system also includes a verification terminal, which is communicatively connected to the aggregation terminal and is used to execute an aggregate signature verification algorithm to verify the aggregate signature according to the user identity identifier of each user terminal and the target user public key, the system master public key, and the signed message.
[0024] In general, the above technical solutions conceived by the present invention can achieve the following beneficial effects compared with the prior art:
[0025] (1) The certificateless aggregate signature method provided by the present invention executes a partial private key generation algorithm according to the system master private key, the user identity identifier and the corresponding first user public key by the key generation center to generate a user partial private key, and sends the user partial private key to the corresponding user terminal, so that each user terminal calculates the target user private key and the target user public key according to the system master public key, the corresponding user partial private key and the user secret value, thereby improving the security of the user public key used for signing, thereby being able to improve the security of the certificateless aggregate signature method.
[0026] (2) With the certificateless aggregate signature method provided by the present invention, since only the first hash value calculated by each user terminal is related to the user random number, while the second hash value and the third hash value calculated by each user terminal are not related to the user random number, the first aggregate value can be calculated according to the product of the first hash value calculated by the aggregate terminal and the user random number of all user terminals that have passed the signature verification; further, the second aggregate value is calculated according to the comprehensive hash value of all user terminals that have passed the signature verification; the combination of the first aggregate value and the second aggregate value is used as the aggregate signature, so that the length of the aggregate signature obtained in this way is fixed and does not increase with the increase in the number of user terminals. Therefore, the communication and storage overheads of the aggregate signature are relatively small, thereby improving the efficiency of the certificateless aggregate signature method. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0028] Figure 1 A flow chart of a certificateless aggregate signature method provided in an embodiment of the present application;
[0029] Figure 2 A schematic diagram of the operation principle of a certificateless aggregate signature system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0030] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0031] The terms "first", "second", "third", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices.
[0032] This embodiment provides a certificateless aggregate signature method, which involves a system parameter establishment algorithm Setup, a user secret value generation algorithm Secc, a partial private key generation algorithm PPK, a signature algorithm Sign, a signature verification algorithm Verify, an aggregate signature generation algorithm AggSign, and an aggregate signature verification algorithm AggVerify. The following describes the definition of each algorithm.
[0033] Setup(1 λ )→(mpk,msk,pp): Input security parameter λ, the system parameter establishment algorithm outputs the system's master public key mpk, master private key msk and the system's public parameter pp. In particular, the public parameter pp is also the input of the subsequent six algorithms. For ease of description, it is not explicitly written in the following algorithm definition.
[0034] Secv(ID i )→(sv i ,X i ): Enter the user's ID i , the user secret value generation algorithm outputs the user ID i The secret value sv i and its corresponding public key X i .
[0035] PPK(ID i ,msk,X i )→(ppk i ,Y i ): Enter the user's ID i and public key X i , and the master private key msk, the partial private key generation algorithm outputs the user's partial private key ppk i and the user's other public key Y i .
[0036] Sign(ID i ,pk i ,m i ,sv i ,ppk i )→σ i :Enter user ID i and public key pk i =(X i ,Y i ), the user's secret value sv i and partial private key ppk i , and the message m to be signed i , the signature algorithm outputs the user's signature σ on the message i .
[0037] Verify(ID i,pk i ,m i ,σ i )→T / F: Enter user ID i and public key pk i , signed message m i and its signature σ i , the signature verification algorithm outputs T (i.e. true) or F (i.e. false).
[0038] AggSign({ID 1 ,ID 2 ,...,ID n},{pk 1 ,pk 2 ,...,pk n},{m 1 ,m 2 ,...,m n},{σ 1 ,σ 2 ,...,σ n})→σ Agg :Enter the identity IDs of n users i and public key pk i =(X i ,Y i ) and the message signature pairs of n users (m i ,σ i ), the aggregate signature generation algorithm outputs the aggregate signature σ of n users Agg .
[0039] AggVerify{ID 1 ,ID 2 ,…,ID n},{pk 1 ,pk 2 ,…,pk n},{m 1 ,m 2 ,…,m n},σ Agg )→T / F: Enter the identity IDs of n users i and public key pk i and the aggregate signature σ Agg , the aggregate signature verification algorithm outputs T (i.e. true) or F (i.e. false).
[0040] like Figure 1 As shown, in one embodiment, a certificateless aggregate signature method is provided, the method comprising the following steps:
[0041] Step 101, the key generation center obtains security parameters, executes the system parameter establishment algorithm, generates a system master private key and a system master public key, secretly stores the system master private key, and discloses the system master public key;
[0042] Step 102, each user terminal obtains a user identity identifier, executes a user secret value generation algorithm, generates a user secret value and a first user public key, secretly stores the user secret value, discloses the user identity identifier, and sends the first user public key to a key generation center;
[0043] Step 103: The key generation center executes a partial private key generation algorithm according to the system master private key, the user identity identifier and the corresponding first user public key to generate a user partial private key, and sends the user partial private key to the corresponding user terminal;
[0044] In step 104, each user terminal calculates the target user private key and the target user public key according to the system master public key, the corresponding user partial private key and the user secret value, executes the signature algorithm according to the target user private key and the target user public key, generates a user signature, obtains an aggregate signature based on the user signatures generated by all user terminals, and verifies the aggregate signature.
[0045] In this embodiment, the key generation center executes a partial private key generation algorithm according to the system master private key, the user identity identifier and the corresponding first user public key to generate a user partial private key, and sends the user partial private key to the corresponding user terminal, so that each user terminal calculates the target user private key and the target user public key according to the system master public key, the corresponding user partial private key and the user secret value, thereby improving the security of the user public key used for signing, thereby improving the security of the certificateless aggregate signature method.
[0046] The present application also provides a certificateless aggregate signature system, including a key generation center, multiple user terminals (i.e., the terminals used by signer i), an aggregation terminal (i.e., the terminal used by the aggregator) and a verification terminal (i.e., the terminal used by the verifier), the key generation center and the multiple user terminals are communicatively connected, the aggregation terminal and the multiple user terminals are communicatively connected, and the verification terminal and the aggregation terminal are communicatively connected.
[0047] like Figure 2 As shown in the figure, the operation steps of each execution subject in the certificateless aggregate signature system include:
[0048] Step 1: The key generation center (KGC) executes the system parameter establishment algorithm Setup to generate the system master public key P pub , system master private key s and public parameter pp, secret storage of system master private key, public system master public key P pub And public parameters pp, that is, the system master public key P puband the public parameter pp are disclosed to other terminals in the system including each user terminal, aggregation terminal and verification terminal;
[0049] Step 2: The user terminal (the terminal used by signer i) executes the user secret value generation algorithm Secv to generate its own user secret value x i and the corresponding public key (i.e. the first user's public key) X i , secretly save your own user secret value x i , disclose your user ID i , and the public key X i Send to KGC;
[0050] Step 3: KGC executes the partial private key generation algorithm PPK and uses the system master private key s to generate a user partial private key d for each user terminal. i and public key (i.e., the second user's public key) Y i , the user's partial private key d i and the corresponding public key Y i Send to the user terminal;
[0051] Step 4: The user terminal verifies the user's partial private key d i Is it valid? If valid, accept the user's partial private key d i Otherwise, the user terminal continues to apply to KGC for the user's partial private key d i ;
[0052] Step 5: The user terminal executes the signature algorithm Sign, generates a signature of the message and sends it to the aggregation terminal;
[0053] Step 6: The aggregation terminal executes the signature verification algorithm Verify to verify the received single user signature. If the verification passes, the aggregation signature generation algorithm AggSign is run to aggregate the single user signatures of multiple signing terminals to generate an aggregate signature.
[0054] Step 7: The verification terminal executes the aggregate signature verification algorithm AggVerify based on the public keys and identities of multiple users to verify the aggregate signature. If the signature verification passes, T is output; otherwise, F is output.
[0055] In one embodiment, specific implementation steps of each algorithm are as follows.
[0056] Setup(1 λ ): Input the security parameter λ (the larger the security parameter λ, the higher the security of the system), and KGC runs the system parameter establishment algorithm:
[0057] 1) Choose an elliptic curve whose points form an additive cyclic group G of order prime number q, and P is the generator of the cyclic group G.
[0058] 2) Random selection As the system master private key, the system master public key is calculated as P pub =sP. It should be noted that s← R S means to select an element uniformly randomly from the set S and assign it to s.
[0059] 3) Select four secure hash functions H 0 ~H 3 , map the corresponding values to the prime number domain superior.
[0060] Among them, l 1 Is the user ID i The length, l 2 For message m i It should be noted that in the following description, the hash function H 0 It is called the initial hash operation. 1 It is called the first hash operation, and the hash function H 2 It is called the second hash operation, and the hash function H 3 This is called the third hash operation.
[0061] 4) Public parameters pp = (G, q, P, P pub ,H 0 ~H 3 ) and the system master public key P pub , secretly save the system master private key s.
[0062] Secv(ID i ): Enter the user's ID i , the user terminal runs the user secret value generation algorithm: randomly select As its secret value, and calculate its corresponding public key (i.e. the first user's public key) X i =x i P.
[0063] PPK(ID i ,s,X i ): User's ID i , system master private key s and first user public key X i As input, KGC runs part of the private key generation algorithm:
[0064] 1) Randomly pick Calculate the second user public key Y i =y i P and joint user public key Q i =H0 (ID i ,X i ,Y i ), and calculate the user's partial private key as d i =y i +sQ i KGC will use the second user's public key Y i And the user's partial private key d i Send to user.
[0065] 2) The user terminal receives the second user public key Y sent by KGC i And the user's partial private key d i After that, you need to verify the user's partial private key d i Is it valid? Verify the user's partial private key d i The steps of determining whether the second user's public key Y is valid include: i , perform an initial hash operation on its user identity identifier, the first user public key and the second user public key, that is, calculate Q i =H 0 (ID i ,X i ,Y i ), and obtain the joint user public key Q calculated by the user terminal i , and the joint user public key Q calculated by the user terminal i Substitute into the first equation and verify the first equation d i P=Y i +P pub Q i If the first equation is true, it means that the received user partial private key d i Valid, in the user's private key d i If valid, set its private key (that is, the target user's private key) to sk i =(x i ,d i ), the public key (i.e. the target user's public key) is pk i =(X i ,Y i ). If the equation does not hold, the user continues to apply to KGC for the user's partial private key d i .
[0066] Sign(ID i ,pk i ,m i ,sk i ): Enter the user's ID i 、Public key pk i =(X i ,Y i ), private key ski =(x i , d i ) and the message m to be signed i , the user terminal runs the signature algorithm:
[0067] 1) Randomly select Calculate R i = r i P, where r i represents the user prime number, and R i represents the user random number; calculate the first hash value h i = H 1 (m i , ID i , X i , Y i , R i ), the second hash value f i = H 2 (m i , ID i , X i , Y i , P pub ), and the third hash value g i = H 3 (m i , ID i , X i , Y i ), and finally calculate the comprehensive hash value S i = h i r i + x i f i + d i g i .
[0068] 2) The user terminal outputs the user signature σ i for the message m i = (R i , S i ).
[0069] AggSign({ID 1 , ID 2 , …, ID n}, {pk 1 , pk 2 , …, pk n}, {m 1 , m 2 , …, m n}, {σ 1 , σ 2 , …, σ n}): Input the identity identifiers ID i、Public key pk i =(X i ,Y i ) and the message signature pair (m i ,σ i ), where 1≤i≤n, the aggregation terminal runs the aggregation signature generation algorithm to generate the aggregation signature of n users:
[0070] 1) The aggregation terminal first runs the signature verification algorithm Verify to verify the user signature of each user, and marks each user's signature with a label c based on the verification result. i If the signature verification passes, set c i =1; otherwise, set c i =0.
[0071] 2) For all labels c i =1, the aggregation terminal first calculates the first hash value h i =H 1 (m i ,ID i ,X i ,Y i ,R i ), where R i Included in the user signature σ i =(R i ,S i ) in; then calculate the first aggregate value respectively and the second aggregate value Finally, the aggregation terminal outputs the aggregation signature σ Agg =(R,S), the aggregate signature σ Agg Sent to the verification terminal.
[0072] The aggregation terminal first runs the signature verification algorithm Verify to verify the user signature of each user, including:
[0073] 1) The aggregation terminal receives the user signatures σ of all user terminals i And get the signed message m corresponding to the user's signature i , User Identifier ID i 、Target user public key pk i =(X i ,Y i ).
[0074] 2) Enter the user's ID i 、Public key pk i =(X i ,Y i ) and the message signature pair (m i ,σi ), the aggregation terminal runs the signature verification algorithm to determine whether the user signature is valid: calculate the joint user public key Q i =H 0 (ID i ,X i ,Y i ), the first hash value h i =H 1 (m i ,ID i ,X i ,Y i ,R i ), the second hash value f i =H 2 (m i ,ID i ,X i ,Y i ,P pub ) and the third hash value g i =H 3 (m i ,ID i ,X i ,Y i ) ; Verify the second equation S i P=h i R i +X i f i +g i (Y i +P pub Q i ) is true, if so, the user signature is determined to be a legal signature and T is output; if not, the user signature is determined to be not a legal signature and F is output.
[0075] AggVerify({ID 1 ,ID 2 ,…,ID n},{pk 1 ,pk 2 ,…,pk n},{m 1 ,m 2 ,…,m n},σ Agg ): Enter the ID of n users i 、Public key pk i =(X i ,Y i ), all signed messages m i and the aggregate signature σ Agg , where 1≤i≤n, the verification terminal runs the aggregate signature verification algorithm to determine the aggregate signature σAgg Is it effective:
[0076] 1) Verify that the terminal receives the aggregate signature σ Agg , messages m from all user terminals i , User Identifier ID i 、Public key pk i =(x i ,Y i ), a first aggregate value R and a second aggregate value S;
[0077] 2) Verify the terminal uses the user's ID i 、Public key pk i =(X i ,Y i ) and all user terminal messages m i , respectively calculate the joint user public key Q i =H 0 (ID i ,X i ,Y i ), the second hash value f i =H 2 (m i ,ID i ,X i ,Y i ,P pub ), the third hash value g i =H 3 (m i ,ID i ,X i ,Y i ) ; Verify the third equation Is it true? If so, the aggregate signature is determined to be a legal signature and T is output; if not, the aggregate signature is determined to be not a legal signature and F is output.
[0078] For certificateless aggregate signature schemes, two types of adversaries A are generally considered: I and A II Since there is no certificate to guarantee the correctness of the user's public key, a class of adversaries A I The user's public key can be replaced to characterize the behavior of malicious users; the second type of adversary A II The adversary has the master private key of the system but cannot replace the user's public key, which is used to carry out forgery attacks against malicious KGC.
[0079] The certificateless aggregate signature method provided in this embodiment uses two public keys of the user (i.e., the first user public key X i and the second user's public key Y i , and the public key X iis generated by the user terminal, the public key Y i is generated by KGC) in calculating the joint user public key Q i , thus effectively avoiding a class of adversaries A I And, calculate the comprehensive hash value S in the Sign algorithm i When the user prime number r i 、User secret value x i and the user's partial private key d i Multiply them by a hash value h calculated by the hash function before i 、f i and g i , thereby destroying the user prime number r i 、User secret value x i and the user's partial private key d i The linear relationship between them can effectively avoid the second type of adversary A II Therefore, the certificateless aggregate signature method provided in this embodiment is I and A II It is safe under all attacks, thereby achieving the purpose of improving the security of the certificateless aggregate signature method.
[0080] In addition, in the Sign algorithm, since only h i With R i Related, and f i and g i Both with R i Therefore, when calculating the comprehensive hash value S i By i With r i Multiply, so that in the AggSign algorithm, by It is possible to calculate the first aggregate value R, and the aggregate signature σ Agg is a combination of the first aggregation value R and the second aggregation value S, so that the purpose of fixing the length of the aggregate signature can be achieved. The length of this aggregate signature is fixed and does not increase linearly with the increase in the number of aggregated user terminals n, so that the communication and storage overheads are relatively small. At the same time, the AggSign algorithm does not use bilinear pairing operations, but only includes point multiplication operations on elliptic curves. Therefore, the computational overhead is also relatively small, so the certificateless aggregate signature method provided by this embodiment can achieve the purpose of improving the efficiency of the certificateless aggregate signature method.
[0081] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
[0082] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0083] The above is only an exemplary embodiment of the present disclosure, and the scope of the present disclosure cannot be limited thereto. That is, any equivalent changes and modifications made according to the teachings of the present disclosure are still within the scope of the present disclosure. After considering the specification and practicing the disclosure here, those skilled in the art will easily think of the implementation scheme of the present disclosure. This application is intended to cover any modification, use or adaptation of the present disclosure, which follows the general principles of the present disclosure and includes common knowledge or customary technical means in the technical field not recorded in the present disclosure. The description and examples are only regarded as exemplary, and the scope and spirit of the present disclosure are defined by the claims.
[0084] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0085] It will be easily understood by those skilled in the art that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A certificateless aggregate signature method, characterized in that: include: The key generation center obtains security parameters, executes the system parameter establishment algorithm, generates a system master private key and a system master public key, secretly stores the system master private key, and discloses the system master public key; Each user terminal obtains a user identity identifier, executes a user secret value generation algorithm, generates a user secret value and a first user public key, secretly stores the user secret value, publishes the user identity identifier, and sends the first user public key to the key generation center; The key generation center executes a partial private key generation algorithm according to the system master private key, the user identity identifier and the corresponding first user public key to generate a user partial private key and a second user public key, and sends the user partial private key and the second user public key to the corresponding user terminal; When the received user partial private key is valid, each user terminal calculates a target user private key and a target user public key according to the system master public key, the corresponding user partial private key, the second user public key and the user secret value, wherein the target user private key is a combination of the user secret value and the user partial private key, and the target user public key is a combination of the first user public key and the second user public key; Each user terminal executes a signature algorithm according to the target user private key and the target user public key to generate a user signature, including: obtaining a message to be signed; calculating a user random number: ,in, represents a randomly selected user prime number, Represents a cyclic group The generator of Represents a user random number; perform a first hash operation, a second hash operation, and a third hash operation respectively to obtain a first hash value calculated by the user terminal: , Second hash value: 、Third hash value: ,in, represents the message to be signed, Represents the user identifier, represents the first user public key, represents the second user's public key, Represents the system master public key; calculates the comprehensive hash value: ,in, , , represent the first hash value, the second hash value, and the third hash value calculated by the user terminal, respectively, Represents the user secret value, Represents the user's partial private key; the user random number and the comprehensive hash value are combined to obtain the user signature: ; Sending the user signature, the signed message corresponding to the user signature, and the target user public key to the aggregation terminal; The aggregation terminal receives the user signatures of all user terminals, the signed message corresponding to the user signature, and the target user public key, executes the signature verification algorithm, and verifies each received user signature, including: performing an initial hash operation to obtain the joint user public key calculated by the aggregation terminal: ; Perform the first hash operation, the second hash operation, and the third hash operation respectively to obtain the first hash value calculated by the aggregation terminal: , Second hash value: 、Third hash value: ; Verify whether the second equation is true, the second equation is: ,in, , , , represent the joint user public key, the first hash value, the second hash value, and the third hash value calculated by the aggregation terminal respectively; if the second equation holds, it is determined that the user signature verification is successful; The aggregation terminal obtains an aggregate signature based on all verified user signatures, and sends the aggregate signature, all signed messages, and the target user public key corresponding to each signed message to the verification terminal; The verification terminal verifies the aggregate signature.
2. The method according to claim 1, characterized in that The key generation center executes a partial private key generation algorithm according to the system master private key, the user identity identifier and the corresponding first user public key to generate a user partial private key and a second user public key, and sends the user partial private key and the second user public key to the corresponding user terminal, including: The key generation center randomly selects a prime number, and calculates the second user public key according to the product of the generator of the cyclic group and the prime number; Performing an initial hash operation on the user identity identifier and the corresponding first user public key and the second user public key to obtain a joint user public key calculated by the key generation center; Performing a product operation on the joint user public key and the system master private key, summing the obtained product with the prime number, and generating a user partial private key; The second user public key and the user partial private key are sent to the corresponding user terminal.
3. The method according to claim 2, characterized in that The method further comprises: Each user terminal receives the second user public key and the user partial private key; Performing an initial hash operation on the user identity identifier, the first user public key and the second user public key to obtain a joint user public key calculated by the user terminal; Verify whether the first equation is true, the first equation is: ,in, Represents the user's partial private key, Represents a cyclic group The generator of represents the second user's public key, Represents the system master public key, represents the joint user public key calculated by the user terminal; If the first equation holds true, it means that the user's partial private key is valid.
4. The method according to claim 1, characterized in that The aggregation terminal obtains an aggregate signature based on all verified user signatures, including: The aggregation terminal generates a signature tag for each user terminal, where the signature tag is 0 or 1, 0 indicates that the signature verification fails, and 1 indicates that the signature verification passes; Calculate a first aggregate value according to the product of the first hash value calculated by the aggregation terminal and the user random number of all user terminals whose signature tags are 1; Calculate a second aggregate value according to the comprehensive hash value of all user terminals whose signature tags are 1; A combination of the first aggregate value and the second aggregate value is used as an aggregate signature.
5. The method according to claim 4, characterized in that The verification terminal verifies the aggregate signature, including: The verification terminal obtains the aggregate signature, all signed messages, and the target user public key corresponding to each signed message; Performing an initial hash operation on the user identity identifier of each user terminal and the target user public key to obtain a joint user public key calculated by the verification terminal; Performing a second hash operation on the signed message, the user identity identifier, the target user public key, and the system master public key to obtain a second hash value calculated by the verification terminal; Performing a third hash operation on the signed message, the user identity identifier, and the target user public key to obtain a third hash value calculated by the verification terminal; Verify whether the third equation is true, the third equation is: ,in, represents the second aggregate value, represents the first aggregate value, Represents a cyclic group The generator of represents the first user public key, represents the second user's public key, Represents the system master public key, represents the joint user public key calculated by the verification terminal, represents a second hash value calculated by the verification terminal, represents a third hash value calculated by the verification terminal; If the third equation holds true, the aggregate signature is determined to be a legal signature.
6. A certificateless aggregate signature system, characterized in that: It comprises a key generation center, a plurality of user terminals, an aggregation terminal and a verification terminal, wherein the key generation center is communicatively connected to the plurality of user terminals, the aggregation terminal is communicatively connected to the plurality of user terminals, and the verification terminal is communicatively connected to the aggregation terminal; The key generation center is used to obtain security parameters, execute the system parameter establishment algorithm, generate a system master private key and a system master public key, secretly store the system master private key, and disclose the system master public key; Each user terminal is used to obtain a user identity identifier, execute a user secret value generation algorithm, generate a user secret value and a first user public key, secretly store the user secret value, publish the user identity identifier, and send the first user public key to the key generation center; The key generation center is further used to execute a partial private key generation algorithm according to the system master private key, the user identity identifier and the corresponding first user public key, generate a user partial private key and a second user public key, and send the user partial private key and the second user public key to the corresponding user terminal; Each user terminal is further configured to calculate a target user private key and a target user public key according to the system master public key, the corresponding user partial private key, the second user public key and the user secret value if the received user partial private key is valid, wherein the target user private key is a combination of the user secret value and the user partial private key, and the target user public key is a combination of the first user public key and the second user public key; Each user terminal is also used to execute a signature algorithm according to the target user private key and the target user public key to generate a user signature, including: obtaining a message to be signed; calculating a user random number: ,in, represents a randomly selected user prime number, Represents a cyclic group The generator of Represents a user random number; perform a first hash operation, a second hash operation, and a third hash operation respectively to obtain a first hash value calculated by the user terminal: , Second hash value: 、Third hash value: ,in, represents the message to be signed, Represents the user identifier, represents the first user public key, represents the second user's public key, Represents the system master public key; calculates the comprehensive hash value: ,in, , , represent the first hash value, the second hash value, and the third hash value calculated by the user terminal, respectively, Represents the user secret value, Represents the user's partial private key; the user random number and the comprehensive hash value are combined to obtain the user signature: ; Sending the user signature, the signed message corresponding to the user signature, and the target user public key to the aggregation terminal; The aggregation terminal is used to receive the user signatures of all user terminals, the signed message corresponding to the user signature, and the target user public key, execute the signature verification algorithm, and verify each received user signature, including: performing an initial hash operation to obtain the joint user public key calculated by the aggregation terminal: ; Perform the first hash operation, the second hash operation, and the third hash operation respectively to obtain the first hash value calculated by the aggregation terminal: , Second hash value: 、Third hash value: ; Verify whether the second equation is true, the second equation is: ,in, , , , represent the joint user public key, the first hash value, the second hash value, and the third hash value calculated by the aggregation terminal respectively; if the second equation holds, it is determined that the user signature verification is successful; The aggregation terminal is further used to obtain an aggregate signature based on all verified user signatures, and send the aggregate signature, all signed messages, and the target user public key corresponding to each signed message to the verification terminal; A verification terminal is used to verify the aggregate signature.
7. The system according to claim 6, characterized in that The aggregation terminal is also used to generate a signature tag for each user terminal, where the signature tag is 0 or 1, 0 indicates that the signature verification fails, and 1 indicates that the signature verification passes.
8. The system according to claim 6, characterized in that The verification terminal is also used to execute an aggregate signature verification algorithm according to the user identity identifier and target user public key of each user terminal, the system master public key, and the signed message to verify the aggregate signature.
Citation Information
Patent Citations
Lightweight online and offline certificateless signature method
CN110808833A
Pairing-free certificateless aggregation signature data security protection method and system
CN116743431A