A time-limited key and message-dependent open group signature method based on lattice cryptography

Through the time-limited key and message-dependent open group signature method based on lattice cryptography, the problems of low signature efficiency and invalid revocation function in the existing technology are solved, and a revocable group signature with high efficiency and enhanced anonymity is realized, which is suitable for the field of cryptography technology.

CN119324784BActive Publication Date: 2025-09-30HUAZHONG NORMAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411123775.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-15
Publication Date
2025-09-30
Estimated Expiration
2044-08-15

AI Technical Summary

Technical Problem

The revocable message-opening group signature scheme in the existing technology requires the signer to interact with the entrant during signing, resulting in low signing efficiency and affecting the signer's anonymity. At the same time, the time-limited key group signature scheme cannot correctly match the revocation list, resulting in the failure of the revocation function.

Method used

A time-limited key and message-dependent open group signature method based on lattice cryptography is adopted. Parameters are generated by the system server. Users interact with group administrators to join the group, generate private keys for the authorized time period set, and record revocation marks in the revocation list. Group administrators track the identity of the signer. The open authority tracks the signer after obtaining the message mark generated by the entrant, thus realizing non-interactive and revocable message-dependent open group signature.

Benefits of technology

It improves signature efficiency, enhances the anonymity of the signer, and implements a highly granular revocation function to ensure the correct matching of the revocation list and the validity of the signature.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119324784B_ABST
    Figure CN119324784B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of cryptography technology, and discloses a time-limited key and message-dependent open group signature method based on lattice cryptography. The steps involved in the method are: the user interacts with the group administrator and joins the group, and the private key of each group member is associated with an authorized time period set; the group member can generate a group signature on behalf of the entire group during the authorized time period; the group administrator can add a revocation element to the revocation list to revoke the signing authority of the group member for the corresponding authorized time period; the verifier can verify the group signature through the revocation list; the group administrator can track all group signatures; the open authority can track the group signature of the corresponding message after obtaining the mark on the message generated by the entrant. The present invention realizes a non-interactive and revocable message-dependent open group signature method by combining the modified time-limited key method, thereby enhancing the anonymity of the signer and the signature efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cryptography, and in particular to a time-limited key and message-dependent open group signature method based on lattice cryptography. Background Art

[0002] In recent years, group signatures have garnered increasing attention as an important privacy-preserving technology. In a group signature scheme, group members can generate a group signature on behalf of the entire group, protecting the privacy of the signer. Furthermore, group signatures introduce accountability, allowing public authorities to track the identity of the signer if they engage in misconduct.

[0003] In order to prevent signers from abusing their signing rights after joining the group, group signature schemes that can implement user revocation functions also need to be considered. The time-limited key group signature scheme is an efficient revocable group signature scheme. In this scheme, when a user joins the group, their key is associated with a set of authorized time periods. Member keys that exceed the authorized time period will be automatically revoked. In addition, the group administrator will also maintain a revocation list that can be accessed by validators. The group administrator can add the revocation mark of the user corresponding to the time period to the revocation list to implement active revocation.

[0004] In traditional group signatures, an open authority can arbitrarily track all signatures, including those without misconduct, which compromises the privacy of signers. Message-based group signatures are an innovative group signature scheme in which the open authority's tracking capabilities are limited. Only after obtaining a message marker generated by an entrant can the open authority track the signature of a specific message.

[0005] The main idea of ​​the revocable message-opening-based group signature scheme in the existing technology is that when signing, the signer needs to interact with the entrant so that the entrant can generate the corresponding mark about the message. This will significantly reduce the efficiency of signing in practical applications and will also affect the anonymity of the signer to the entrant, so that the entrant can know the message that the signer needs to sign, and thus know the identity of the signer of the group signature.

[0006] In addition, in actual applications of the time-limited key group signature scheme of the prior art, the group signature cannot correctly match the corresponding revocation element in the revocation list, thereby rendering the revocation function of the group administrator invalid and preventing the group administrator from exercising the revocation function. Summary of the Invention

[0007] (1) Technical problems solved

[0008] In view of the shortcomings of the existing technology, the present invention provides a time-limited key and message-dependent open group signature method based on lattice password, which has the function of running the parameter generation algorithm through the system server to generate all the parameters required in the system. User k joins the group and becomes a group member by interacting with the group administrator. Each group member will have a corresponding authorized time period set. The private keys of group members who exceed the authorized time period will be automatically revoked, and the revocation marks and It will be added to the registry, and group members will generate corresponding authorization time periods on behalf of the entire group. The group signature hides the specific identity of the signer. The group administrator adds the revocation element corresponding to the time period t generated by the revocation mark corresponding to the current group member to the revocation list to realize the revocation of the group member corresponding to the time period t. The verifier verifies the validity of the group signature corresponding to the time period t by accessing the revocation list. The group administrator is used to track the identity of the signer of the group signature. The open authority has the mark t generated by the admitter about the message. M Finally, the identity of the signer of the group signature of the corresponding message is tracked. By combining the modified time-limited key method, a non-interactive and revocable message-dependent open group signature method is realized, which enhances the anonymity of the signer and the signing efficiency, and solves the above problems.

[0009] (2) Technical solution

[0010] To achieve the above object, the present invention provides the following technical solution: a time-limited key and message-dependent open group signature method based on lattice cryptography, characterized in that it includes the following steps:

[0011] S1, the system server is used to run the parameter generation algorithm to generate all the parameters required in the system;

[0012] S2. User k joins the group and becomes a member by interacting with the group manager. Each group member will have a corresponding authorized time period set. The private keys of group members who exceed the authorized time period will be naturally revoked, and the revocation tokens (Revocation Token) and will be added to the registry;

[0013] S3. Group members generate corresponding authorization time periods on behalf of the entire group. Group signatures hide the specific identity of the signer;

[0014] S4. The group administrator adds the revoking element (Revoction Element) corresponding to time period t generated by the revoking token (Revoction Token) corresponding to the current group member to the revocation list, thereby revoking the group member corresponding to time period t;

[0015] S5. The verifier verifies the validity of the group signature corresponding to time period t by accessing the revocation list;

[0016] S6, used by group administrators to track the identities of signatories of group signatures;

[0017] S7, the Opening Authority has the message tag generated by the Admitter (t M ) is used to track the identity of the signer of the group signature of the corresponding message.

[0018] Preferably, in S1, the designated server runs the parameter generation algorithm Keygen(n) to generate the system public parameter gpk, the group administrator's private key is gsk, the open authority's private key is ok, the entrant's private key is msk, and all keys are distributed to the corresponding participants, where n represents the total number of all authorized time periods.

[0019] Preferably, in said S2, the group administrator completes two different unlinkable redactable signatures on the message related to the member's private key, then uses the original image sampling algorithm to link one of the signatures to the member's private key and sends it to the group member to complete the registration. The other signature is added to the registration table as a revocation mark to complete the subsequent revocation operation.

[0020] Preferably, in said S3, two commitments are made to the user's identity k, and the committed open tool (Opener) is divided into two parts, one of which is encrypted with the public key (PKE) system of the open authority, and the other is encrypted with the identity-based encryption system (IBE) of the entrant's message, and finally a non-interactive zero-knowledge proof is completed. The proof relationship includes that the signer has completed the correct commitment steps, the signer is a legal group member who has completed registration, the signer has completed the correct public key encryption and identity-based encryption steps, and the edited signature generated by the editable signature granted to the signer is legal and represents the authorized time period.

[0021] Preferably, in said S4, in order to revoke the signing authority of group member k in time period t, the group administrator first restores the revocation mark of member k, then uses the group administrator's private key to complete a signature on the revocation element corresponding to the time period t, and finally adds the corresponding revocation element and signature to the revocation list to implement the revocation operation.

[0022] Preferably, in S5, the verifier verifies the validity of the group signature corresponding to time period t by accessing the revocation list, and the validity verification is as follows:

[0023] If it has not been added to the revocation list and the non-interactive zero-knowledge proof of the group signature is verified, it returns valid; otherwise, it returns invalid.

[0024] Preferably, in S6, the group administrator is used to track the identity of the signer of the group signature; the group administrator acts as a verifier and verifies the validity of the signature according to the method of S5. When the verification fails, the group administrator cannot track the signature; otherwise, the registry is traversed and the revocation list is individually set to the revocation element of member k corresponding to the group signature time t, and the validity of the signature is verified again according to the method of S5. When the verification is successful, the next element in the registry is traversed. Once the verification fails, it means that the signature belongs to member k.

[0025] Preferably, in said S7, the entrant uses its private key msk to generate a message tag t through the original sampling algorithm. M .

[0026] Preferably, in said S7, the open authority has the mark t about the message M After that, use its private key ok to decrypt the public key encrypted part of the group signature, and then use t M Decrypt the identity-based encrypted part of the group signature, combine the decrypted results of the two parts to get the opening tool of the complete commitment, and finally open the commitment to know the identity of the members.

[0027] Compared with the prior art, the present invention provides a time-limited key and message-dependent open group signature method based on lattice cryptography, which has the following beneficial effects:

[0028] 1. The present invention can implement a non-interactive and revocable message-dependent open group signature method, which can significantly improve the efficiency of signature and enhance the anonymity of the signer to the entrant.

[0029] 2. The present invention can implement a highly fine-grained, revocable, time-limited key message-dependent open group signature method. This method can divide the authorization time into a set of non-continuous time periods. When generating a signature, the signer can generate a signature for the corresponding authorization time period, and the group administrator can also generate a revocation element for the corresponding authorization time period, thereby realizing a highly fine-grained revocation function.

[0030] 3. The present invention can modify the previous time-limited key group signature method. When a user joins a group, the group administrator completes two different unlinkable editable signatures for the message related to the member's private key. One signature is sent to the group member as a credential, and the other signature is added to the registry as a revocation mark to complete the subsequent revocation operation, achieving the correct match between the group signature and the corresponding revocation element in the revocation list. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 This is a diagram of a time-limited key and message-dependent open group signature framework based on lattice cryptography of the present invention.

[0032] Figure 2 Schematic diagram of the steps of the method of the present invention. DETAILED DESCRIPTION

[0033] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0034] First, a detailed description of the existing technology used in this implementation is given;

[0035] Cryptography related concepts

[0036] 1. Grid password

[0037] Lattice cryptography has received increasing attention due to its quantum-resistant properties and efficient arithmetic structure. Unlike traditional number theory-based difficult problems such as the large integer factorization problem and the discrete logarithm problem, lattice cryptography is based on difficult problems on lattices, such as SIS and LWE. This invention is based on variants of SIS and LWE problems, namely MSIS and MLWE.

[0038] MSIS: Given an n*m-dimensional polynomial quotient ring matrix A with a modulus of q, find an m-dimensional ring vector z such that Az = 0 and the maximum value of all components of z does not exceed β;

[0039] MLWE: Distinguish between the following two examples:

[0040] 1)(A,As+e), where A is an n*m-dimensional polynomial quotient ring matrix with module q, s and e are polynomial ring vectors with dimensions m and n respectively, and the absolute value of each component of the ring is not greater than 1;

[0041] 2)(A,b) where A is an n*m-dimensional polynomial quotient ring matrix with a modulus of q, and b is an n-dimensional polynomial quotient ring vector with a modulus of q;

[0042] 2. Rejection Sampling Theorem

[0043] In order to eliminate the correlation between the vector z=b+y and the secret vector b, the rejection sampling algorithm can be used: Rej(z,b,σ):u←[0,1), if Returns 0, otherwise, returns 1;

[0044] According to the rejection sampling theorem, if each component of y follows a Gaussian distribution with Gaussian parameter σ, and σ ≥ 11∥b∥, and if Rej(z, b, σ) returns 1, then z and a vector whose components each follow a Gaussian distribution with Gaussian parameter σ are statistically indistinguishable, thus eliminating the correlation between the vector z = b + y and the secret vector b.

[0045] 3. Original Image Sampling Algorithm

[0046] Given a random vector a, a is a 2D polynomial quotient ring vector with a modulus of q, R is a 2×2 polynomial ring matrix, and the absolute value of each component of the ring is not greater than 1, set b = (a T R) T , there exists a random u, u is a polynomial quotient ring with a modulus of q, according to the original image sampling algorithm Sample([a T |b T +i*g T ],u,R,σ), we can get s, s is a 4-dimensional vector whose components follow the Gaussian distribution with Gaussian parameter σ, so that [a T |b T +i*g T ]s=u;

[0047] 4. Unlinkable editable signature

[0048] The signature scheme consists of the following algorithms:

[0049] (1) Key generation algorithm KeyGen(n), which generates all the parameters required in the scheme;

[0050] (2) Signature algorithm In n messages Generate signature sig;

[0051] (3)Edit Edit the original signature sig into The edited signature sig′ on

[0052] (4) Verification Verify the validity of the signature sig, output 1 if the verification passes, and output 0 if it fails;

[0053] See also Figure 1 The present invention provides the following technical solution: a time-limited key and message-dependent open group signature method based on lattice cryptography, which mainly includes the following steps:

[0054] S1, the system server is used to run the parameter generation algorithm to generate all the parameters required in the system;

[0055] S2. User k joins the group and becomes a member by interacting with the group manager. Each group member will have a corresponding authorized time period set. The private keys of group members who exceed the authorized time period will be naturally revoked, and the revocation tokens (Revocation Token) and will be added to the registry;

[0056] S3. Group members generate corresponding authorization time periods on behalf of the entire group. Group signatures hide the specific identity of the signer;

[0057] S4. The group administrator adds the revoking element (Revoction Element) corresponding to time period t generated by the revoking token (Revoction Token) corresponding to the current group member to the revocation list, thereby revoking the group member corresponding to time period t;

[0058] S5. The verifier verifies the validity of the group signature corresponding to time period t by accessing the revocation list;

[0059] S6, used by group administrators to track the identities of signatories of group signatures;

[0060] S7, the Opening Authority has the message tag generated by the Admitter (t M ) is used to track the identity of the signer of the group signature of the corresponding message;

[0061] Before running the group signature system, S1 sets the parameters used by the system. The ring dimension is d, where d is a power of 2, n represents the total number of authorized time periods, σ represents the Gaussian sampling parameter, the prime modulus q, q′, Q, p, the challenge boundary κ>0, and the rejection sampling parameter The specified server runs the parameter generation algorithm KeyGen(n) to generate the system public parameters gpk=(a1,a2,a3,a4,a5,a,b1,b2,b3,g,u), the group administrator's private key is gsk=(R1,s1), the open authority's private key is ok=s2, and the entrant's private key is msk=R2, where s1 and s2 are 3D polynomial ring vectors, and the absolute value of each component of the ring is not greater than 1, R1 and R2 are 2×2 polynomial ring matrices, and the absolute value of each component of the ring is not greater than 1, a1 is a 3D polynomial quotient ring vector with a module of q′, a2 is a 3D polynomial quotient ring vector with a module of q, a3 is a 2D polynomial quotient ring vector with a module of q, a4 is a 2D polynomial quotient ring vector with a module of Q, and a5=[a 5,1 a 5,2 a 5,3 a 5,4 ] T =[a4 T |b3 T +i*·g T ] T , where b3 T =a4 T R2, g T is [1,δ] and δ is i * belong And i * Not equal to 0, a is a polynomial quotient ring modulo Q, b1 T =a3 T R1,b2=[b 2,1 b 2,2 b 2,3 ] T =s2a+e, where e is a 3D polynomial ring vector, and the absolute value of each component of the ring is not greater than 1, g=ax T s1, Among them, s 0,1 ,s 0,2 ,s 0,3 are polynomial ring vectors with dimensions of 2, 2, and 3, respectively, and each component of the ring follows a Gaussian distribution with Gaussian parameter σ;

[0062] S2. User k joins the group by interacting with the group administrator and becomes a group member. Each group member will have a corresponding authorized time period set. The private keys of group members who exceed the authorized time period will be naturally revoked; the revocation marks and will be added to the registry; the specific method mainly involves the group administrator completing two unlinkable editable signatures, one for the message The signature of the message The specific steps are as follows: before the interaction, user k and the group administrator first negotiate an authorized time period set. User k generates his private key s k,3 , s k,3 is a 3-dimensional polynomial ring vector, the absolute value of each component of the ring is not greater than 1, for all Generate y i ,y i are polynomial ring vectors of dimension 3, each component of the ring follows a Gaussian distribution with Gaussian parameter ξ2. User k sends To group administrators; Group administrator generates y i ,y i are polynomial ring vectors with dimensions of 3, and each component of the ring follows a Gaussian distribution with a Gaussian parameter of ξ2. Generate y, y is a polynomial ring vector with dimensions of 3, and each component of the ring follows a Gaussian distribution with a Gaussian parameter of ξ1. Set For 1≤i≤n, generate Where H() is a collision-resistant hash function, and its output is a polynomial ring. The absolute value of each component of the ring is not greater than 1, and the sum of the absolute values ​​of all components is not greater than κ. Send c os To the user; the user receives c os Afterwards, for Set z″ i =s k,3 c os +y i , and perform rejection sampling algorithm If the result is 0, the interaction ends, otherwise Set z i =s k,3 c os c os +y i , and perform rejection sampling algorithm If the result is 0, the interaction ends, otherwise send To group administrator; group administrator receives Afterwards, for Set z i =y i , set z = s1c os+y, and perform the rejection sampling algorithm Rej(z,s1c os ,ξ1), if the result is 0, then end the interaction and check Where d is the dimension of the polynomial ring, ∥A∥ represents the result of taking the square root of the sum of the squares of all components of A. Check and in For collection If the equality does not hold, the interaction ends. Execute the original image sampling algorithm Get(s k,1 ,s k,2 ), (s k,1 ,s k,2 ) are all 2-dimensional polynomial ring vectors, such that The group administrator will generate the parameters k is sent to user k through a secure channel to complete the registration; the user checks and If the equation does not hold, the registration fails. After the registration is completed, the group administrator will mark the user k as revoked. Add to the registry Reg[k] to complete the subsequent undo operation;

[0063] S3. Group members can generate corresponding authorized time periods on behalf of the entire group. The specific method mainly involves completing two commitments to the user's identity k and dividing the committed open tool into two parts, one of which is encrypted with the public key system of the open authority and the other with the identity-based encryption system of the entrant's message. Finally, a non-interactive zero-knowledge proof is completed. The proof relationship includes that the signer completed the correct commitment steps, the signer is a legal group member who has completed the registration, the signer completed the correct public key encryption and identity-based encryption steps, the edited signature generated by the signer is legal, and the message is where m t =s k,3 , t is the signing time period; the specific steps are to generate (r1, r′1, r2, r′2), (r1, r′1, r2, r′2) are all 3D polynomial ring vectors, the absolute value of each component of the ring is not greater than 1, and the commitment promise The steps of public key encryption are to generate s B ,e1,e2,s B, e1, e2 are polynomial ring vectors with dimensions of 1, 1, and 3 respectively. The absolute value of each component of the ring is not greater than 1. The calculation results show that h = p (as B +e1), d=p(b2s B +e2)+r1, the steps of identity-based encryption of the message are to generate b4=[b 4,1 b 4,2 b 4,3 ] T =H′(M), where H′() is a collision-resistant hash function whose output is a 3D polynomial quotient ring vector with a modulus of Q, generating s′ B ,e′1,e′2,s′ B , e′1, e′2 are polynomial ring vectors with dimensions of 1, 4, and 3 respectively. The absolute value of each component of the ring is not greater than 1. The calculation results show that h′=p(a5s′ B +e′1), d′=p(b4s′ B +e′2)+r2, the conversion process between non-interactive zero-knowledge proof and unlinkable editable signature is, set Make set up y=[hd T h′ T d′ T t1] makes Br B =y, generate y r ,y r′ ,y B ,y r ,y r′ ,y B is a polynomial ring vector with dimensions of 6, 6, and 19, and each component of the ring follows a Gaussian distribution with Gaussian parameter ξ5, generating are all polynomial ring vectors with a dimension of 2. Each component of the ring follows a Gaussian distribution with a Gaussian parameter of ξ6, generating is a polynomial ring vector with a dimension of 6, each component of the ring follows a Gaussian distribution with a Gaussian parameter of ξ7, generating y′, y′ is a polynomial ring vector with a dimension of 3, each component of the ring follows a Gaussian distribution with a Gaussian parameter of ξ3, for 1≤i≤n, generating y′ i , y′ i is a polynomial ring vector of dimension 3, each component of the ring follows a Gaussian distribution with Gaussian parameter ξ4, set

[0064] For all 1≤i≤n, set set up set up set up set up z′=zc′1+y′, for i=t, set z′ i =z i c′1+y′ i , for i≠t, set z′ i =y′ i , perform rejection sampling algorithm

[0065] If the result is 0, regenerate the parameters, otherwise, get the output of the zero-knowledge proof The result of the signature is Σ=(t,t′,Π,h,d,h′,d′);

[0066] S4. The group administrator can add the revocation element corresponding to time period t generated by the revocation mark corresponding to the current group member to the revocation list to achieve the revocation of the group member corresponding to time period t; the specific method is that in order to revoke the signing authority of group member k in time period t, the group administrator first restores the revocation mark of member k Then use s1 in z″ t ,w t Generate a signature. The specific steps are to generate y R ,y R It is a polynomial ring vector with a dimension of 3. Each component of the ring follows a Gaussian distribution with a Gaussian parameter of ξ1. z R =s1c R +y R , execute the rejection sampling algorithm Rej(z R ,s1c os ,ξ1), if the result is 0, regenerate the parameters, otherwise, cancel the element (z R ,c R ,z″ t ,w t ) is added to RL[t] to achieve revocation;

[0067] S5. The verifier can verify the validity of the group signature corresponding to time period t by accessing the revocation list. The specific method is that the verifier checks each revoked element (z R ,c R ,z″ t ,w t ), if any and If it holds, it returns invalid; otherwise, the non-interactive zero-knowledge proof part of the signature is verified. The specific steps include calculating If there is

[0068]

[0069]

[0070] If all the equations are true, then return valid, otherwise, return invalid;

[0071] S6. The group administrator can track the identity of the signer of the group signature. The specific method is that the group administrator acts as a verifier and verifies the validity of the signature according to the method in step 5. If the verification fails, the group administrator cannot track the identity of the signer. Otherwise, the group administrator traverses the registry Reg and sets the revocation element (z″) of member k in the revocation list RL[t]. t ,w t ), verify the validity of the signature again according to the method in step 5. If the verification is successful, traverse the next element in the registry. If the verification fails, it means that the signature belongs to member k;

[0072] S7, the Opening Authority has the message tag generated by the Admitter (t M ) is used to track the identity of the signer of the group signature of the corresponding message. First, the entrant can generate a message-based tag. The specific steps are as follows: M =S3=[s 3,1 s 3, 2s 3,3 ] T , t M It is a 3×7 polynomial ring matrix, which is obtained by the original image sampling algorithm. Generates 3,1 Make Through the original image sampling algorithm Generates 3,2 Make Through the original image sampling algorithm Generates 3,3 Make In summary, b3 = S3a5. The open authority has a message-based tag (t M), the identity of the signer of the group signature of the corresponding message can be traced. The specific steps are: open the authority as the verifier and verify the validity of the signature according to the method in step 5. If the verification fails, it cannot be traced; otherwise, execute the loop Loop to generate c′, c′ is a polynomial ring, the absolute value of each component of the ring is not greater than 1, and the sum of the absolute values ​​of all components is not greater than κ. Set set up If there is where ∥A∥ ∞ Indicates the maximum absolute value of all components of A, set End the loop, otherwise, re-execute the loop; after the loop ends, set If k∈[N], return k, otherwise, return invalid;

[0073] The basic principles, main features and advantages of the present invention are shown and described above. It is obvious to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or basic features of the present invention.

[0074] In addition, it should be understood that although this specification is described in terms of implementation methods, not every implementation method contains only one independent technical solution. This narrative method of the specification is only for the sake of clarity. Those skilled in the art should regard the specification as a whole. The technical solutions in each embodiment can also be appropriately combined to form other implementation methods that can be understood by those skilled in the art.

Claims

1. A time-limited key and message-dependent open group signature method based on lattice cryptography, characterized by: The following steps are involved: S1, the system server is used to run the parameter generation algorithm to generate all the parameters required in the system; S2. User By interacting with the group administrator, you can join the group and become a group member. Each group member will have a corresponding authorized time period set. , the private keys of group members who exceed the authorized time period will be naturally revoked, and the revocation marks and will be added to the registry; S3. Group members generate corresponding authorization time periods on behalf of the entire group. Group signatures hide the specific identity of the signer; S4. The group administrator generates the corresponding time period by the revocation mark corresponding to the current group member. The revocation element is added to the revocation list to implement the corresponding time period for group members revocation; S5. The verifier verifies the time period by accessing the revocation list. The validity of the group signature; S6, used by group administrators to track the identities of signatories of group signatures; S7. The open authority has a mark on the message generated by the entrant Then, it is used to track the identity of the signer of the group signature of the corresponding message.

2. The method of claim 1, wherein: In S1, the algorithm is generated by the specified server running parameters. , generate system public parameters , the group administrator's private key is , the public authority's private key is , the entrant's private key is , and assign all keys to the corresponding parties, where Indicates the total number of all authorized time periods.

3. The method of claim 2, wherein: In S2, the group administrator completes two different unlinkable editable signatures on the message related to the member's private key, then uses the original image sampling algorithm to link one of the signatures to the member's private key and sends it to the group member to complete the registration. The other signature is added to the registration table as a revocation mark to complete subsequent revocation operations.

4. The method of claim 3, wherein: The S3 involves the user's identity Complete two commitments and divide the committed open tool into two parts, one of which is encrypted with the public key system of the open authority, and the other is encrypted with the identity-based encryption system of the entrant's message. Finally, complete the non-interactive zero-knowledge proof. The proof relationship includes that the signer completed the correct commitment steps, the signer is a legal group member who has completed registration, the signer completed the correct public key encryption and identity-based encryption steps, and the edited signature generated by the editable signature granted to the signer is legal and represents the authorized time period.

5. The method of claim 4, wherein: In S4, the group administrator cancels the group member In the time period Signature permissions, first restore members The revocation mark is then used to revoke the group administrator's private key in the corresponding time period. Complete a signature on the revocation element, and finally add the corresponding revocation element and signature to the revocation list to implement the revocation operation.

6. The method of claim 5, wherein: In S5, the verifier verifies the corresponding time period by accessing the revocation list The validity of the group signature is verified as follows: If it has not been added to the revocation list and the non-interactive zero-knowledge proof of the group signature is verified, it returns valid; otherwise, it returns invalid.

7. The method of claim 6, wherein: In S6, the group administrator is used to track the identity of the signer of the group signature; The group administrator acts as a verifier and verifies the validity of the signature according to the S5 method. If the verification fails, it cannot be traced; Otherwise, traverse the registry and set the members of the revocation list individually Corresponding to group signature time The revocation element is verified again according to the method of S5. When the verification is successful, the next element in the registry is traversed. Once the verification fails, it means that the signature belongs to the member of.

8. The time-limited key and message-dependent open group signature method based on lattice cryptography according to claim 7, characterized in that: In S7, the entrant uses his private key , generate the mark about the message through the original sampling algorithm .

9. The time-limited key and message-dependent open group signature method based on lattice cryptography according to claim 8, characterized in that: In S7, the open authority has a mark on the message Then, through its private key Decrypt the public key encrypted part of the group signature, and then use Decrypt the identity-based encrypted part of the group signature, combine the decrypted results of the two parts to get the opening tool of the complete commitment, and finally open the commitment to know the identity of the members.

Citation Information

Patent Citations

  • Revocable group signature method with unforgeable expiration time

    CN113609462A

  • Group signature system, device, and program

    WO2009116422A1