Unlinkable Ring Signature Method, System, Computer Device, and Storage Medium
By generating unique key pairs and enhancing encryption with random numbers, the method ensures each ring signature is unlinkable, addressing linkability issues and maintaining signer anonymity.
Patent Information
- Application Number
- CN202410642065.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-22
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2044-05-22
AI Technical Summary
In some cases, existing ring signature technology has linkability, resulting in reduced anonymity and inability to effectively protect the signer's privacy.
Generate the key pair of each ring member, and randomly enhance the encryption of the signature content through the key pair and the pre-generated random number, generate verification parameters, determine the ring signature using the public key and verification parameters, and perform validation verification.
It realizes non-linkable ring signatures, improves anonymity, ensures the anonymity of the signers among ring members, prevents signatures from being linked, and enhances privacy protection.
Smart Images

Figure CN118631465B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and particularly to an unlinkable ring signature method, system, computer device, and storage medium. Background Art
[0002] Ring signature is a special digital signature technology that allows a member in a set of members to create a signature without providing specific signer information. This signature scheme has no trusted center and no group establishment process. For verifiers, the signer is completely anonymous, ensuring the validity and anonymity of the signature. This feature of ring signature makes it very useful in special environments where information needs to be protected for a long time and anonymity needs to be maintained.
[0003] Although ring signature itself has unlinkability, in some specific cases, ring signature also has a certain degree of linkability, which is usually related to the private key of the signature. Specifically, if the same private key is used to sign different messages and the algorithm can determine that these two signatures are from the same private key, then it can be verified that these two signatures are generated by the same signer, and the signatures can be linked together, thus failing to achieve good privacy protection and reducing the anonymity of the ring signature.
[0004] Regarding the problem that linkable ring signatures in related technologies lead to reduced anonymity, no effective solution has been proposed yet. Summary of the Invention
[0005] Based on this, in view of the above technical problems, it is necessary to provide an unlinkable ring signature method, system, computer device, and storage medium that can improve the anonymity of ring signatures.
[0006] In the first aspect, an unlinkable ring signature method is provided in this embodiment, including:
[0007] Generating a key pair for each ring member; the key pair includes a public key and a private key;
[0008] Based on the key pair and a pre-generated random number, performing encryption processing with enhanced randomness on the signature content to generate verification parameters for validity verification;
[0009] Determining a ring signature according to the public key, the random number, and the verification parameters;
[0010] Verifying the validity of the ring signature through the public key and the verification parameters.
[0011] In some of these embodiments, the generating a key pair for each ring member includes:
[0012] Selecting the private key;
[0013] Encrypt the private key of each of the ring members using a multiplicative cyclic group to generate the public key.
[0014] In some embodiments, performing a randomness-enhanced encryption process on the signature content based on the key pair and a pre-generated random number to generate verification parameters for validity verification, including:
[0015] Generate a first intermediate variable using a multiplicative cyclic group based on a first random number, a second random number, and the public key;
[0016] Generate a second intermediate variable using a hash function based on the public key, the signature content, and the first intermediate variable;
[0017] Convert the private key based on the second intermediate variable, the first random number, and the second random number to obtain the verification parameters.
[0018] In some embodiments, performing validity verification on the ring signature through the public key and the verification parameters, including:
[0019] Establish a preset equation based on the public key, the random number, the signature content, and the verification parameters;
[0020] Perform validity verification on the ring signature based on whether the preset equation holds.
[0021] In some embodiments, further including:
[0022] If the preset equation holds, it indicates that the ring signature passes the verification;
[0023] If the preset equation does not hold, it indicates that the ring signature fails the verification.
[0024] In some embodiments, after performing validity verification on the ring signature, further including:
[0025] Record the random number and the verification parameters in the ring signature;
[0026] Filter the ring signatures that have passed validity verification based on the random number and the verification parameters.
[0027] In some embodiments, further including:
[0028] In the scenario of anonymous voting, generate a ring signature through an unlinkable ring signature method and perform validity verification on the ring signature.
[0029] Second aspect, in this embodiment, a linkable ring signature system is provided, including:
[0030] A key generation module, configured to generate a key pair for each ring member; the key pair includes a public key and a private key;
[0031] A ring signature signing module, configured to perform encryption processing with enhanced randomness on the signature content based on the key pair and a pre-generated random number to generate verification parameters for validity verification; determine the ring signature according to the public key, the random number, and the verification parameters;
[0032] A ring signature verification module, configured to perform validity verification on the ring signature through the public key and the verification parameters.
[0033] Third aspect, in this embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the unlinkable ring signature method described in the first aspect above is implemented.
[0034] Fourth aspect, in this embodiment, a storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the unlinkable ring signature method described in the first aspect above is implemented.
[0035] Compared with the related art, the unlinkable ring signature method, system, computer device, and storage medium provided in this embodiment generate a key pair for each ring member; the key pair includes a public key and a private key; perform encryption processing with enhanced randomness on the signature content based on the key pair and a pre-generated random number to generate verification parameters for validity verification; determine the ring signature according to the public key, the random number, and the verification parameters; perform validity verification on the ring signature through the public key and the verification parameters. By enhancing the randomness during the encryption processing of the signature content in this embodiment, the ring signatures generated by the same private key each time are not related, achieving unlinkable ring signatures, which can improve the anonymity of ring signatures and solve the problem of reduced ring anonymity caused by linkable ring signatures.
[0036] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more comprehensible. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments and descriptions thereof of the present application are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0038] Figure 1 It is a hardware structure block diagram of a terminal of a non-linkable ring signature method in an embodiment;
[0039] Figure 2 It is a flowchart of a non-linkable ring signature method in an embodiment;
[0040] Figure 3 It is a schematic diagram of the process of ring signature generation and validity verification in an embodiment;
[0041] Figure 4 It is a structure block diagram of a non-linkable ring signature system in an embodiment.
[0042] In the figure: 102, a processor; 104, a memory; 106, a transmission device; 108, an input / output device; 10, a key generation module; 20, a ring signature signing module; 30, a ring signature verification module. Specific implementation manners
[0043] To understand the purpose, technical solution and advantages of the present application more clearly, the present application will be described and illustrated below in conjunction with the accompanying drawings and embodiments.
[0044] Unless otherwise defined, the technical terms or scientific terms involved in the present application shall have the general meanings understood by those with ordinary skills in the technical field to which the present application belongs. In the present application, words such as "a", "one", "a kind of", "the", "these" and the like do not indicate a limitation in quantity, and they can be singular or plural. The terms "including", "comprising", "having" and any variants thereof involved in the present application are intended to cover non-exclusive inclusion; for example, a process, method, system, product or device including a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent in these processes, methods, products or devices. The terms "connected", "coupled" and the like involved in the present application do not limit to physical or mechanical connections, but may include electrical connections, whether directly or indirectly connected. The term "plurality" involved in the present application means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" may represent: A exists alone, A and B exist simultaneously, and B exists alone. Usually, the character " / " indicates that the objects before and after are in an "or" relationship. The terms "first", "second", "third" and the like involved in the present application are only used to distinguish similar objects and do not represent a specific sorting for the objects.
[0045] The method embodiments provided in this embodiment may be executed on a terminal, a computer, or a similar computing device. For example, when running on a terminal, Figure 1 is a hardware structure block diagram of the terminal of the unlinkable ring signature method of this embodiment. As Figure 1 shown, the terminal may include one or more ( Figure 1 only one is shown in the figure) processors 102 and a memory 104 for storing data. Among them, the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA. The above terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above terminal. For example, the terminal may further include more or fewer components than Figure 1 shown in the figure, or have a different configuration from Figure 1 shown.
[0046] The memory 104 may be used to store computer programs. For example, software programs and modules of application software, such as the computer program corresponding to the unlinkable ring signature method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories may be connected to the terminal through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0047] The transmission device 106 is used to receive or send data via a network. The above network includes a wireless network provided by the communication provider of the terminal. In one instance, the transmission device 106 includes a network adapter (abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0048] Ring signatures evolved from group signatures and are a special digital signature technology that allows a member within a set of members to create a signature without providing specific signer information. This signature scheme has no trusted center and no group establishment process. For verifiers, the signer is completely anonymous, ensuring the validity and anonymity of the signature. This characteristic of ring signatures makes them very useful in special environments where information needs to be protected for a long time and anonymity needs to be maintained.
[0049] Although ring signatures themselves have unlinkability, in certain specific cases, ring signatures also have a certain degree of linkability, which is usually related to the private key of the signature. Specifically, if the same private key is used to sign different messages, and the algorithm can determine that these two signatures are from the same private key, then it can be verified that these two signatures are generated by the same signer, and the signatures can be linked together. In this way, it is difficult to achieve good privacy protection and the anonymity of ring signatures is reduced.
[0050] In this embodiment, an unlinkable ring signature method is provided. Figure 2 It is the flowchart of the unlinkable ring signature method of this embodiment, as Figure 2 shown, and this method includes the following steps:
[0051] Step S210, generate a key pair for each ring member; the key pair includes a public key and a private key.
[0052] Specifically, there is a group of members in the ring signature. This group of members is called ring members. There is no cooperation among ring members, and the signature process does not require the participation of a trusted third party. Ring signatures allow the signer to arbitrarily select a group of ring members and hide themselves among them, making it possible for all members to appear as potential actual signers.
[0053] For each ring member, through encryption algorithms such as elliptic curves and discrete logarithms, generate the private key and public key required for the ring signature. The private key of each ring member is held by the ring member itself, but the public key is public in the ring. Simply put, ring signatures are spontaneous, that is, a user in the ring arbitrarily selects the public keys of other users to jointly form a ring required for a signature to hide the public key of this user, thereby achieving the anonymity of the signer's identity.
[0054] In blockchain, ring signature technology has a wide range of application scenarios, which usually involve transactions or operations that require privacy and anonymity protection. The following are some specific application scenarios:
[0055] (1) Anonymous transactions:
[0056] In cryptocurrency transactions, users may wish to maintain the anonymity of their transactions. Ring members may include a group of random public key holders unrelated to the transaction, as well as the public key of the user who actually conducts the transaction (i.e., the signer). By hiding their public key within such a ring, traders can conceal their identity.
[0057] (2) Anonymous voting:
[0058] In a decentralized voting system on a blockchain, participants may wish to vote anonymously without revealing their identities. Ring members may include the public keys of all registered users participating in the vote. The voter (i.e., the signer) uses their own private key and the public keys of other members in the ring to generate a signature, thus voting without disclosing their identity.
[0059] (3) Anonymous data sharing:
[0060] In blockchain applications where sensitive data (such as medical records, financial information) needs to be shared, ring signatures can ensure that the source of the data is not disclosed. Ring members may include the original provider of the data, data processors, and a group of randomly selected public key holders unrelated to the data. Through ring signatures, the integrity and authenticity of the data can be ensured while protecting the privacy of the data provider.
[0061] (4) Access control:
[0062] In blockchain applications where access permissions need to be restricted, ring signatures can be used to verify whether a user has permission to access specific resources. Ring members may include the public keys of all users with access permissions. When a user attempts to access a resource, they can use their own private key and the public keys of other members in the ring to generate a signature to prove that they have access permission.
[0063] Step S220, based on the key pair and the pre-generated random number, perform encryption processing with enhanced randomness on the signature content to generate verification parameters for validity verification.
[0064] Specifically, two random numbers are pre-generated in a cyclic group of integers of order q, where one random number corresponds to the public key of the ring member. The signer uses their own private key and the public keys of all ring members, combined with the pre-generated random number, to perform encryption processing with enhanced randomness on the signature content to generate verification parameters. Among them, the signer uses the private key for encryption processing, ensuring that only the entity knowing the private key can generate valid verification parameters. The verification parameters are used to construct ring signatures and to verify the validity of ring signatures.
[0065] In the above encryption processing, some cryptographic processes are also included, such as in order to obfuscate or hide certain information, or to generate a new value related to the original data but more difficult to trace as an intermediate variable.
[0066] Step S230: Determine the ring signature based on the public key, random number, and verification parameter.
[0067] Specifically, after the signer generates the verification parameter, assemble all the public keys of the ring members, the above-mentioned random number, and the verification parameter to determine the ring signature. Since the public key is public in the ring, the actual length of the ring signature is determined by the length of the random number and verification parameter corresponding to the public key, which can effectively shorten the length of the ring signature, improve the computing efficiency, as well as the storage and transmission efficiency.
[0068] After determining the ring signature, pack the generated ring signature into a data packet or message format. This can be a simple binary format or a more complex structure, depending on the requirements of the communication protocol. The signer sends the packed ring signature to the verifier by choosing an appropriate data transmission method. This can be a point-to-point communication, or a broadcast or multicast communication, depending on the requirements of the application scenario.
[0069] Step S240: Verify the validity of the ring signature through the public key and verification parameter.
[0070] Specifically, the verifier can receive the ring signature through network transmission or other means, perform data parsing, and verify the validity of the ring signature through the public key, verification parameter, and corresponding verification algorithm in the ring signature. The validity verification is to check whether the ring signature is valid and determine whether the ring signature is signed by a certain member in the ring. After the verifier verifies the ring signature, it is impossible to determine which member in the ring is the actual signer, but it can be confirmed that the signer must be in the ring members, thus ensuring the anonymity of the signer.
[0071] It should be noted that in the application of ring signature, the identity of the verifier is flexible. The verifier can be any member in the ring or a third party outside the ring, as long as they can access the public keys of the ring members, they can perform the validity verification of the ring signature.
[0072] For the members within the ring, they can confirm that the message is signed by a certain member in the ring by verifying the signature, but due to the anonymity of the ring signature, they cannot determine who the specific signer is. This feature makes ring signature very useful in scenarios where the privacy of the signer needs to be protected.
[0073] For third parties outside the ring, they can also confirm the validity and source of the message by verifying the signature. Although they cannot determine who the specific signer is, they can confirm that the signature is generated by a member of the ring and that the signature has not been tampered with during transmission. This makes ring signatures very useful in scenarios where the source of the message needs to be verified, such as anonymous voting, anonymous data sharing, etc.
[0074] Through the above steps, the randomness is enhanced when encrypting the signature content, and valid verification parameters are generated by the private key of the signer. Accordingly, the ring signature is determined by assembling the verification parameters, so that the ring signatures generated by the same private key each time are not related, that is, the ring signatures cannot be linked to the same private key by comparing multiple ring signatures, realizing unlinkable ring signatures, which can improve the anonymity of ring signatures and solve the problem that linkable ring signatures lead to reduced ring anonymity, thereby being able to better protect privacy.
[0075] Furthermore, in the method provided in this embodiment, the ring members generate ring signatures using fixed key pairs. Compared with the method of generating ring signatures using one-time public keys (temporary public keys), it is more suitable for stable collectives, without the need to generate one-time public keys each time, and at the same time reduces the complexity of key management and the computational cost. In addition, since the public key is public in the ring, the actual length of the ring signature is determined by the length of the random number corresponding to the public key and the verification parameters, which can effectively shorten the length of the ring signature and improve the computational efficiency, as well as the storage and transmission efficiency.
[0076] In some of the embodiments, generating the key pair for each ring member in step S210 above includes the following steps:
[0077] Step S211, select a private key.
[0078] Step S212, encrypt the private key of each ring member using a multiplicative cyclic group to generate a public key.
[0079] Specifically, the private key is randomly selected or generated based on a certain secure random process. The private key is used in the signature process to ensure that only the holder of the private key can generate valid verification parameters, thereby obtaining the ring signature. The public key is obtained by encrypting the private key through a certain mathematical function (such as elliptic curve cryptography (ECC), discrete logarithm encryption, etc.) and calculating using a multiplicative cyclic group. Assuming the private key is d, the following gives an expression for the public key pk:
[0080] pk = g d ;
[0081] where g represents the generator of the multiplicative cyclic group G. For each ring member i, there is a key pair (di , pk i )。
[0082] Elliptic curve encryption is based on the theory of elliptic curves and uses a cyclic group composed of points on the elliptic curve. Its elements (i.e., the points on the elliptic curve) are combined through the point addition operation on the elliptic curve. Discrete logarithm encryption is an asymmetric encryption algorithm based on the discrete logarithm problem, and its computational difficulty increases sharply with the increase of the parameter scale. Therefore, discrete logarithm encryption has high security.
[0083] Optionally, a key pair for each ring member is generated by a probabilistic polynomial time (PPT) algorithm, which inputs a security parameter and outputs a key pair consisting of a public key and a private key.
[0084] By generating the private key and public key of each ring member in this embodiment, the signer can generate a valid ring signature through the private key, and the verifier can verify the validity of the ring signature through the public key.
[0085] In some of these embodiments, in step S220 above, based on the key pair and a pre-generated random number, a randomness-enhanced encryption process is performed on the signature content to generate verification parameters for validity verification, including the following steps:
[0086] Step S221, based on the first random number, the second random number, and the public key, a first intermediate variable is generated using a multiplicative cyclic group.
[0087] Step S222, based on the public key, the signature content, and the first intermediate variable, a second intermediate variable is generated using a hash function.
[0088] Step S223, based on the second intermediate variable, the first random number, and the second random number, the private key is transformed to obtain the verification parameter.
[0089] Specifically, in the above encryption process, by enhancing randomness, confusing or hiding certain information, or generating a new value related to the original data but more difficult to trace as an intermediate variable, the private key is finally transformed to obtain the verification parameter, ensuring that only the entity knowing the private key can generate a valid verification parameter. The verification parameter is used to construct the ring signature and to verify the validity of the ring signature.
[0090] The following gives an encryption method for generating the verification parameter s:
[0091] (1) Randomly select the first random number k and the second random number c in the integer cyclic group Z q q i 。
[0092] k, c i ← Z q, Let c j = 0;
[0093] Among them, the second random number c i corresponds to the public key pk of the ring member i ; Let c j = 0 means that the random number c corresponding to signer j in ring member i j is assigned the value 0, that is, the public key pk of the signer j is assigned the value 0.
[0094] (2) Based on the first random number k, the second random number c i and the public key pk i , use the multiplicative cyclic group to generate the first intermediate variable R.
[0095]
[0096] Among them, g represents the generator of the multiplicative cyclic group G. By performing exponentiation and consecutive multiplication operations on the public key in the multiplicative cyclic group G, the randomness in the encryption process is enhanced to generate the first intermediate variable R.
[0097] (3) Based on the public key pk i , the signature content m and the first intermediate variable R, use the hash function to generate the second intermediate variable h.
[0098] h = H1(pk i ∥m∥R);
[0099] Among them, H1 represents the hash function, mapping to the q-order integer cyclic group Z q ; The "‖" operation means concatenating pk i , m and R, and then applying the hash function H1 to the concatenated data to generate the second intermediate variable h. By performing hash processing on the signature content m, collisions are prevented, and malicious attacks such as forging signatures or tampering with data can be effectively resisted.
[0100] (4) Based on the second intermediate variable h, the first random number k and the second random number c i , convert the private key d of the signer to obtain the verification parameter s.
[0101] c j = h - ∑c i ;
[0102] s = k - c j d;
[0103] Among them, c i is obtained by subtracting the sum of a series of random numbers c j from the second intermediate variable h, and the signer uses its private key d for the hash value c jPerform a transformation and then combine it with the first random number k to generate the verification parameter s.
[0104] Further, based on the above embodiments, the following gives an expression of ring signature: (pk i , c i , s), where pk i represents the public keys of all ring members i, c i represents the second random number corresponding to the public key pk i ; s represents the verification parameter. Since the public keys are public in the ring, the actual length of the ring signature is determined by the length of the random number and the verification parameter corresponding to the public key. It can be understood that the length of the ring signature in this embodiment is the number of all ring members plus the verification parameter, which can effectively shorten the length of the ring signature.
[0105] Through the encryption process of enhancing the randomness of the signature content in this embodiment, the verification parameter is generated. Among them, the signer uses the private key for encryption processing, ensuring that only the entity knowing the private key can generate a valid verification parameter to construct the ring signature and verify the validity of the ring signature, so that each generated ring signature is uncorrelated, that is, the ring signatures cannot be linked to the same private key by comparing multiple ring signatures, realizing an unlinkable ring signature and improving the anonymity of the ring signature.
[0106] In some of the embodiments, in step S240 above, the validity of the ring signature is verified through the public key and the verification parameter, including the following steps:
[0107] Step S241, establish a preset equation based on the public key, random number, signature content, and verification parameter.
[0108] Specifically, in the verification stage, the verifier will verify the received ring signature using the public keys of all members in the ring. Among them, a preset equation is established based on the public key, random number, signature content, and verification parameter, and this preset equation can ensure that the preset equation holds only when the ring signature is generated by a certain member in the ring using its private key.
[0109] Step S242, verify the validity of the ring signature based on whether the preset equation holds.
[0110] Among them, if the preset equation holds, it means that the ring signature passes the verification; if the preset equation does not hold, it means that the ring signature fails the verification.
[0111] Specifically, based on the verification output result, it is determined whether the ring signature is valid. If the signature is valid, it indicates that the message is signed by a certain member in the ring and the signature has not been tampered with during transmission. If the ring signature is invalid, it indicates that the signature may be forged by an illegal user or the signature has been tampered with during transmission.
[0112] Based on the encryption process and ring signature in the above embodiments, the following provides a method for verifying the validity of a ring signature:
[0113] (1) The verifier disassembles the ring signature (pk i , c i , s).
[0114] (2) Based on the public key pk i , the second random number c i , the signature content m, and the verification parameter s, a preset equation is established.
[0115] ∑c i = H1(pk i ∥ m ∥ R′);
[0116] Among them, the left side of the equation represents the sum of the second random number c i , and the right side of the equation represents that the "‖" operation means concatenating pk i , m, and R together, and then applying the hash function H1 to the concatenated data.
[0117] By verifying the validity of the ring signature in this embodiment, it is checked whether the ring signature is valid and it is determined whether the ring signature is signed by a certain member in the ring. After the verifier verifies the ring signature, it is impossible to determine which member in the ring is the actual signer, but it can be confirmed that the signer must be in the ring members, thus ensuring the anonymity of the signer.
[0118] In some of these embodiments, after verifying the validity of the ring signature, the above method further includes the following steps:
[0119] Record the random number and verification parameter in the ring signature; based on the random number and verification parameter, filter the ring signatures that have passed the validity verification.
[0120] Specifically, after verifying the validity of the ring signature, the random number and verification parameter in the ring signature can be stored together with the ring signature for use during the verification process. In the case of having multiple ring signatures, if the verification is successful, the ring signature is marked as valid and added to the list of verified signatures. In this way, for other ring signatures, by checking the stored random number and verification parameter, the ring signatures that have passed the validity verification can be filtered, the valid signatures can be quickly found and processed, and repeated validity verification can be avoided, thereby improving the efficiency.
[0121] By screening ring signatures that have passed validity verification based on random numbers and verification parameters in this embodiment, it is possible to avoid repeated validity verification of processed ring signatures, quickly find verified valid ring signatures, and improve processing efficiency.
[0122] In some of these embodiments, in the scenario of anonymous voting, ring signatures are generated by an unlinkable ring signature method, and the validity of the ring signatures is verified.
[0123] Specifically, assume that n users in a group jointly participate in multiple rounds of voting, and each user has a public key and a corresponding private key, that is, a key pair. The voting system collects the public keys of all participants and forms a public key list or ring, which is publicly available to all participants.
[0124] When a voter (assumed to be the j-th user) wants to vote on a certain voting option, as the signer, using their own private key, the public key list, and the message to be voted on (i.e., the signed content, such as the number of a certain candidate), through the unlinkable ring signature method provided in the above embodiment, the voter's ring signature is generated. The voter submits the generated ring signature to the voting system without submitting any information that can identify their identity.
[0125] After receiving the ring signature, the voting system verifies the validity of the ring signature through the unlinkable ring signature method provided in the above embodiment. Through the unlinkable ring signature method provided in this embodiment, even if a certain voter generates multiple ring signatures in multiple rounds of voting, each generated ring signature is uncorrelated, and it is impossible to link these ring signatures to the same voter, achieving unlinkable ring signatures, thus ensuring the anonymity of the voter, which is very useful for some anonymous voting (such as elections, opinion polls, etc.) that need to protect the privacy of voters.
[0126] The following describes and illustrates this embodiment through preferred embodiments.
[0127] This embodiment provides an unlinkable ring signature method. Figure 3 is a schematic diagram of the ring signature generation and validity verification process in this embodiment, as Figure 3 shown, generating a ring signature in the signer includes:
[0128] Step S310, randomly select a first random number k and a second random number c in the integer cyclic group Z of order q q Randomly select k, c i ,
[0129] Randomly select k, c i ←Z q Let c j= 0;
[0130] Among them, the second random number c i corresponds to the public key pk of the ring member; let c i = 0 means that the random number c corresponding to the signer j in the ring member i j is assigned the value 0, that is, the public key pk of the signer j is assigned the value 0. j
[0131] Step S320, based on the first random number k, the second random number c i and the public key pk i , generate the first intermediate variable R using the multiplicative cyclic group.
[0132]
[0133] Among them, g represents the generator of the multiplicative cyclic group G. By performing exponentiation and consecutive multiplication operations on the public key in the multiplicative cyclic group G, the randomness in the encryption process is enhanced to generate the first intermediate variable R.
[0134] Step S330, based on the public key pk i , the signature content m, and the first intermediate variable R, generate the second intermediate variable h using the hash function.
[0135] h = H1(pk i ‖m‖R);
[0136] Among them, H1 represents the hash function, mapping to the integer cyclic group Z of order q q ; the "‖" operation means concatenating these three elements pk i , m, and R, and then applying the hash function H1 to the concatenated data to generate the second intermediate variable h. By performing hash processing on the signature content m to prevent collisions, it can effectively resist malicious attacks such as forging signatures or tampering with data.
[0137] Step S340, based on the second intermediate variable h, the first random number k, and the second random number c i , convert the private key d of the signer to obtain the verification parameter s.
[0138] c j = h - ∑c i ;
[0139] s = k - c j d;
[0140] Among them, c i is obtained by subtracting the sum of a series of random numbers c j from the second intermediate variable h. The signer uses its private key d for the hash value c jPerform a transformation and then combine it with the first random number k to generate the verification parameter s.
[0141] After sending the ring signature to the verifier, perform a validity verification of the ring signature in the verifier, including the following steps:
[0142] Step S350, calculate
[0143] Step S360, verify whether the preset equation ∑c i = H1(pk i ∥m∥R′) holds, that is, verify whether ∑c i =? H1(pk i ‖m‖R’). Check whether the ring signature is valid and determine whether the ring signature is signed by a certain member in the ring.
[0144] Through the method provided in this embodiment, the randomness is enhanced when encrypting the signature content, and valid verification parameters are generated from the private key of the signer. Accordingly, the ring signature is determined by assembling the verification parameters, so that the ring signatures generated by the same private key each time are not related, that is, it is impossible to link the ring signatures to the same private key by comparing multiple ring signatures, realizing an unlinkable ring signature, which can improve the anonymity of the ring signature, solve the problem that the linkable ring signature leads to a reduction in ring anonymity, and thus can better protect privacy.
[0145] Furthermore, in the method provided in this embodiment, the ring members use fixed key pairs to generate ring signatures. Compared with the method of generating ring signatures using one-time public keys (temporary public keys), it is more suitable for stable collectives, without the need to generate one-time public keys each time, and at the same time reduces the complexity of key management and the computational cost. In addition, since the public key is public in the ring, the actual length of the ring signature is determined by the random number corresponding to the public key and the length of the verification parameter, which can effectively shorten the length of the ring signature, improve the computational efficiency, as well as the storage and transmission efficiency.
[0146] It should be noted that the steps shown in the above process or the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0147] In this embodiment, an unlinkable ring signature system is also provided. This system is used to implement the above embodiment and the preferred implementation manners, and those that have been described will not be repeated. The following terms "module", "unit", "sub-unit", etc. can be a combination of software and / or hardware that can achieve a predetermined function. Although the system described in the following embodiments is preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0148] Figure 4 is the structural block diagram of the unlinkable ring signature system of this embodiment. As Figure 4 shown, the system includes:
[0149] A key generation module 10, configured to generate a key pair for each ring member; the key pair includes a public key and a private key.
[0150] A ring signature signing module 20, configured to perform encryption processing with enhanced randomness on the signature content based on the key pair and a pre-generated random number, and generate verification parameters for validity verification; determine the ring signature according to the public key, the random number, and the verification parameters.
[0151] A ring signature verification module 30, configured to perform validity verification on the ring signature through the public key and the verification parameters.
[0152] Through the system provided in this embodiment, when encrypting the signature content, the randomness is enhanced, and valid verification parameters are generated by the private key of the signer. Accordingly, the ring signature is determined by assembling the verification parameters, so that the ring signatures generated each time by the same private key are not related, that is, the ring signatures cannot be linked to the same private key by comparing multiple ring signatures, realizing unlinkable ring signatures, which can improve the anonymity of ring signatures and solve the problem that linkable ring signatures lead to reduced ring anonymity, thereby being able to better protect privacy.
[0153] Furthermore, in the method provided in this embodiment, the ring members use fixed key pairs to generate ring signatures. Compared with the method of generating ring signatures using one-time public keys (temporary public keys), it is more suitable for stable collectives, without the need to generate one-time public keys each time, and at the same time reduces the complexity of key management and the computational cost. In addition, since the public key is public in the ring, the actual length of the ring signature is determined by the length of the random number corresponding to the public key and the verification parameters, which can effectively shorten the length of the ring signature, improve the computational efficiency, as well as the storage and transmission efficiency.
[0154] In some of the embodiments, the above-mentioned key generation module 10 is further configured to select a private key; encrypt the private key of each ring member using a multiplicative cyclic group to generate a public key.
[0155] In some of the embodiments, the above-mentioned ring signature signing module 20 is further configured to generate a first intermediate variable using a multiplicative cyclic group based on a first random number, a second random number, and the public key; generate a second intermediate variable using a hash function based on the public key, the signature content, and the first intermediate variable; convert the private key based on the second intermediate variable, the first random number, and the second random number to obtain the verification parameters.
[0156] In some of these embodiments, the above-mentioned ring signature verification module 30 is further configured to establish a preset equation based on the public key, random number, signature content, and verification parameters; verify the validity of the ring signature based on whether the preset equation holds; and, if the preset equation holds, it indicates that the ring signature passes the verification; if the preset equation does not hold, it indicates that the ring signature fails the verification.
[0157] In some of these embodiments, the above-mentioned ring signature verification module 30 is further configured to record the random number and verification parameters in the ring signature; and screen the ring signatures that have passed the validity verification based on the random number and verification parameters.
[0158] It should be noted that the above-mentioned each module can be a functional module or a program module, and can be implemented either by software or by hardware. For the modules implemented by hardware, the above-mentioned each module can be located in the same processor; or the above-mentioned each module can also be located in different processors in any combined form.
[0159] In this embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above-mentioned method embodiments.
[0160] Optionally, the above-mentioned computer device may further include a transmission device and input / output devices. Among them, the transmission device is connected to the above-mentioned processor, and the input / output devices are connected to the above-mentioned processor.
[0161] It should be noted that the specific examples in this embodiment may refer to the examples described in the above-mentioned embodiments and optional implementation manners, and will not be repeated in this embodiment.
[0162] In addition, in combination with the unlinkable ring signature method provided in the above-mentioned embodiments, a storage medium can also be provided to implement in this embodiment. A computer program is stored on the storage medium; when the computer program is executed by a processor, it implements any one of the unlinkable ring signature methods in the above-mentioned embodiments.
[0163] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0164] It should be understood that the specific embodiments described here are only used to explain this application, rather than to limit it. According to the embodiments provided in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of this application.
[0165] Obviously, the accompanying drawings are only some examples or embodiments of the present application. For those of ordinary skill in the art, the present application can also be applied to other similar situations based on these drawings without creative efforts. Additionally, it can be understood that although the work done during the development process here may be complex and time-consuming, for those of ordinary skill in the art, certain design, manufacturing, or production changes based on the technical content disclosed in the present application are only conventional technical means and should not be regarded as insufficient disclosure of the present application.
[0166] The term "embodiment" in the present application means that the specific features, structures, or characteristics described in connection with the embodiments may be included in at least one embodiment of the present application. The phrase appears in various positions in the specification and does not necessarily mean the same embodiment, nor does it mean being independent or alternative to other embodiments and mutually exclusive. Those of ordinary skill in the art can clearly or implicitly understand that the embodiments described in the present application can be combined with other embodiments without conflict.
[0167] The above-described embodiments only represent several implementation manners of the present application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of patent protection. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. An unlinkable ring signature method, characterized in that, including: generating a key pair for each ring member; the key pair includes a public key and a private key; performing encryption processing with enhanced randomness on the signature content based on the key pair and a pre-generated random number to generate verification parameters for validity verification; wherein it includes: generating a first intermediate variable using a multiplicative cyclic group based on a first random number, a second random number, and the public key; generating a second intermediate variable using a hash function based on the public key, the signature content, and the first intermediate variable; converting the private key based on the second intermediate variable, the first random number, and the second random number to obtain the verification parameters; determining a ring signature based on the public key, the random number, and the verification parameters; performing validity verification on the ring signature through the public key and the verification parameters.
2. The unlinkable ring signature method according to claim 1, characterized in that The generating a key pair for each ring member includes: selecting the private key; performing encryption processing on the private key of each ring member using a multiplicative cyclic group to generate the public key.
3. The unlinkable ring signature method according to claim 1, characterized in that, The performing validity verification on the ring signature through the public key and the verification parameters includes: establishing a preset equation based on the public key, the random number, the signature content, and the verification parameters; performing validity verification on the ring signature based on whether the preset equation holds.
4. The unlinkable ring signature method according to claim 3, characterized in that It also includes: if the preset equation holds, it indicates that the ring signature passes the verification; if the preset equation does not hold, it indicates that the ring signature fails to pass the verification.
5. The unlinkable ring signature method according to claim 1, characterized in that After performing validity verification on the ring signature, it also includes: recording the random number and the verification parameters in the ring signature; screening the ring signatures that have passed validity verification based on the random number and the verification parameters.
6. The unlinkable ring signature method according to claim 1, wherein It also includes: in the scenario of anonymous voting, generating a ring signature through an unlinkable ring signature method and performing validity verification on the ring signature.
7. An unlinkable ring signature system, characterized in that including: a key generation module for generating a key pair for each ring member; the key pair includes a public key and a private key; a ring signature signing module for performing encryption processing with enhanced randomness on the signature content based on the key pair and a pre-generated random number to generate verification parameters for validity verification; wherein it includes: generating a first intermediate variable using a multiplicative cyclic group based on a first random number, a second random number, and the public key; generating a second intermediate variable using a hash function based on the public key, the signature content, and the first intermediate variable; converting the private key based on the second intermediate variable, the first random number, and the second random number to obtain the verification parameters; determining a ring signature based on the public key, the random number, and the verification parameters; a ring signature verification module for performing validity verification on the ring signature through the public key and the verification parameters. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the unlinkable ring signature method according to any one of claims 1 to 6.
8. A computer device, comprising a memory and a processor, characterized in that, When the computer program is executed by the processor, it implements the steps of the unlinkable ring signature method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that,
Citation Information
Patent Citations
Method and device for revoking ring signature certificate on block chain and storage medium
CN110113166A
Threshold ring signature method and system based on national cryptographic algorithm
CN114095181A