A probabilistic verification method applied to hash and sign signature paradigm
By randomly combining the lattice base matrix and message hash value, the verification computation of the Hash and Sign lattice signature paradigm is reduced, efficiency is improved and security is guaranteed, and it is applicable to a wide range of lattice signature schemes.
Patent Information
- Application Number
- CN202411744186.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-30
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-11-30
AI Technical Summary
In the traditional Hash and Sign lattice signature verification process, the multiplication of the public key matrix and the signature vector takes a long time, affecting verification efficiency.
A new verification matrix is formed by randomly selecting row vectors of the lattice basis matrix and combining them, and a new message hash vector is formed by selecting corresponding components from the message hash value. This probabilistic verification method reduces computational overhead.
It effectively reduces the number of matrix multiplications in the verification process, improves verification efficiency, and ensures security under the classical probabilistic model. It is applicable to all hash and sign lattice signature schemes.
Smart Images

Figure CN119483981B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the field of information security and data protection, and particularly relates to a probability verification method applied to Hash and Sign signature paradigm. BACKGROUND
[0002] Digital signature technology can verify the integrity and source of information, ensure that data is not tampered with during transmission, and confirm the identity of the sender of information. Whether in e-government, e-commerce, or in the fields of finance, law, etc., digital signature plays an indispensable role, ensuring the authenticity, reliability and legality of digital information.
[0003] With the increasing development of quantum computing technology, Shor [1] (P.W. Shor, "Algorithms for quantum computation; discrete logarithms and factoring," in Proceedings 35th Annual Symposium on Foundations of Computer Science, Santa Fe, NM, USA; IEEE Comput. Soc. Press, 1994, pp. 124-134.) and Grover [2] (L.K. Grover, "Quantum Mechanics Helps in Searching for a Needle in a Haystack," Phys. Rev. Lett., vol. 79, no. 2, pp. 325-328, Jul. 1997.) discovered quantum algorithms that can effectively solve classical difficult problems, bringing serious security challenges to traditional signature schemes. Lattice-based cryptography is considered an effective means to resist quantum computing attacks. The security of lattice-based signature is based on the difficult problems in high-dimensional lattices, which remain difficult in the quantum computing environment, thus providing strong protection for data security.
[0004] Ajtai[3](M. Ajtai, "Generating hard instances of lattice problems (extended abstract)," in Proceedings of the twenty-eighth annual ACM symposium on Theory of computing - STOC '96, Philadelphia, Pennsylvania, United States; ACM Press, 1996, pp. 99-108.) proved that the difficulty of lattice problems in the average state is equivalent to the difficulty in the worst state, which laid a solid foundation for the development of lattice public key cryptography. This feature is a unique advantage that other post-quantum cryptography does not have. In addition, lattice cryptography is based on existing security proof technology, which can reduce the scheme security to the lattice difficult problem. Moreover, the algebraic structure of lattice cryptography is simple and easy to implement in software and hardware, with low computational complexity and suitable for parallel operation. In addition, with the continuous development of cloud computing technology, cloud computing platforms have become the preferred data storage and processing method for many enterprises and individuals. However, the security problem of cloud computing platforms has become increasingly prominent. The application of homomorphic cryptography technology can effectively enhance the security of cloud computing platforms and protect users' sensitive data from being leaked and misused. The rapid development of cloud computing technology increases the demand for the design of quantum-resistant homomorphic cryptography. Lattice cryptography is a linear cryptosystem, and its special geometric structure can be better applied to the design of homomorphic cryptography.
[0005] In summary, lattice signature, as a post-quantum signature algorithm, has significant advantages in security, efficiency, practicality, and scalability, and is expected to play an important role in future cryptography. In 2008, Gentry et al.[4] creatively proposed the hash-and-sign signature paradigm based on the difficult lattice trapdoor, and designed the classic GPV (Gentry, Peikert, and Vaikuntananathan[GPV08]) signature based on the hash-and-sign signature paradigm. This signature paradigm is the first recognized secure and efficient lattice trapdoor scheme, which greatly promotes the development of lattice digital signature technology. Gentry's work brings new vitality and direction to the field of lattice-based cryptography, and also inspires more exploration and innovation of lattice-based cryptography by subsequent researchers. Since then, lattice-based digital signature schemes have flourished, not only making numerous breakthroughs in theory, but also showing strong potential and value in practical applications.
[0006] The hash-and-sign signature paradigm of Gentry et al. has become an important basis in lattice signature schemes. The core idea is to use a one-way trapdoor function on a lattice to construct a digital signature. The message digest is hashed into a shorter hash value by a hash function, and then the signature value is obtained by using the trapdoor base to sample the inverse of the hash value. Many subsequent lattice-based signature schemes are designed and optimized based on the hash-and-sign signature paradigm.
[0007] In the traditional hash-and-sign signature paradigm, the complete public key matrix needs to be multiplied with the signature vector, and the multiplication result needs to be verified to be equal to the complete message hash value, which is a relatively time-consuming process. SUMMARY
[0008] The purpose of the present application is to provide a probability verification method applied to the Hash and Sign lattice signature paradigm. The core idea of the present application is to reduce the computational overhead by reducing the amount of data verified. After analyzing the improved probability verification scheme, we conclude that if the signature itself is not legal, the probability of the signature passing the verification is negligible, and the possibility of the enemy forging the signature passing the verification is still not negligible, provided that the process of randomly selecting the public key matrix and the message hash value is random enough. In addition, multiple random verifications can also increase confidence in the authenticity of the signature. The GPV signature scheme is the most classic lattice signature scheme constructed using the Hash and Sign lattice signature paradigm. The present application improves the verification signature process of the GPV signature scheme to describe the probability verification method applied to the Hash and Sign lattice signature paradigm.
[0009] The present application is implemented by adopting the following technical solutions:
[0010] A probability verification method applied to the Hash and Sign lattice signature paradigm, comprising:
[0011] Step 1: initialization step Setup(n)→(params): the trusted party inputs a security parameter λ, and outputs public parameters params=(m,q,s,H), wherein m≥6nlogq is the dimension of the signature vector, q is a prime number Gaussian parameter is a real number; let be a secure hash function;
[0012] Step 2: key generation step KeyGen(params)→(sk,pk): the signer inputs the public parameters params=(n,m,q,s,H), and runs the TrapGen(n,m,q) algorithm to generate the matrix and the lattice a trapdoor basis T, output public key pk←(A), private key sk←(T);
[0013] Step 3: Signature step Sign(sk, pk, params, M)→e: Let the message be M∈{0,1} * , the signer calculates h=H(M), which is the "Hash" process of the Hash and Sign lattice signature paradigm; the signer calculates the vector t satisfying At=hmodq, outputs t' using the SamplePre(T, s, -t) algorithm, and calculates e=t+t'modq as the signature of the message M;
[0014] Step 4: Random combination step RanCombine(pk, h)→pk', h': the verifier randomly selects k rows from the lattice basis matrix A and records the index of the selected rows; the k row vectors are combined into a new lattice basis public key matrix from top to bottom according to the randomly selected order; then the hash value h of the message M is calculated, the corresponding components are selected from the vector h according to the same randomly selected index, and a new message hash vector h' is constructed according to the same combination method;
[0015] Step 5: Verification step Verify(params, pk', e, h')→0 / 1: the verifier calculates whether the signature e, the combined public key A' and the combined message vector h' satisfy the verification relationship, that is, A'e=h'modq and when and only when, output 1, representing accepting the signature e, otherwise output 0, representing rejecting the signature e.
[0016] Further improvement of the application is that in step 2, the public key and private key used in the Hash and Sign lattice signature paradigm are generated, the public key is an n-row m-column matrix , n and m define the rank and dimension of the lattice with the public key matrix as the lattice basis, and the private key is a trapdoor basis matrix of the dual lattice with the public key matrix as the lattice basis.
[0017] Further improvement of the application is that in step 3, it is the "Sign" process of the Hash and Sign lattice signature paradigm.
[0018] Further improvement of the application is that in step 4, the verification parameters of the trivial Hash and Sign lattice signature paradigm, that is, the lattice basis matrix A and the message vector h, are randomly combined, and the size is reduced.
[0019] Further improvement of the application is that in step 5, according to the signature verification method of the normal Hash and Sign lattice signature paradigm, the verification parameters randomly combined in step 4 are used for verification.
[0020] The further improvement of the present application is that in step 5, the verifier randomly selects row vectors from the lattice basis matrix, and combines the randomly selected row vectors into a new lattice basis public key matrix from top to bottom according to the randomly selected order; the verifier calculates the hash value of the message, selects the corresponding components from the hash vector according to the same randomly selected index, and constructs a new message hash vector according to the same combination mode.
[0021] The further improvement of the present application is that in step 5, the verifier uses the randomly combined lattice basis matrix and the message hash vector generated in step 4 to verify the legality of the signature; specifically, the verifier calculates whether the relationship A'e=h'mod q is satisfied between the signature e, the combined public key A' and the combined message vector h', and verifies whether the norm e of the signature satisfies
[0022] The further improvement of the present application is that the probability verification method in step 5 has potential universality for lattice signature schemes based on the Hash and Sign paradigm, and the verification process of such signature schemes involves multiplication calculation and verification of the public key matrix and the signature vector.
[0023] The present application has at least the following beneficial technical effects:
[0024] 1. The present application proposes the following idea to improve the verification efficiency: randomly selecting a part of row vectors from the original verification matrix, combining these randomly selected row vectors into a new verification matrix with fewer rows. At the same time, selecting the vector components corresponding to the new matrix from the original message hash value to form a shorter vector. Finally, using the new public key matrix and the signature vector to multiply the verification result to see whether it is equal to the new message vector. If it matches, then the signature is considered valid with a probability close to 1. This improved method can reduce the number of matrix multiplication operations in the verification process. Simply put, assuming that k rows are randomly selected from an n*m lattice basis matrix, the number of matrix multiplications required for verification changes from nm to km. The smaller the value of k, the more obvious the efficiency improvement.
[0025] 2. The present application uses the classical probability model to ensure the security of the improved verification process: according to the classical probability model and the related theory of Gaussian distribution, a signature that cannot pass the verification of the trivial Hash and Sign lattice signature paradigm is forged, and the probability of this signature passing the improved verification algorithm is negligible (proven in the security analysis of the algorithm), so the improved verification method can verify the legality of the signature with overwhelming confidence close to 1.
[0026] 3.The probability verification method proposed in the present application has potential universality for lattice signature schemes based on the Hash and Sign paradigm. The verification process of the Hash and Sign lattice signature paradigm involves multiplication calculation and verification of the lattice basis matrix and the signature vector. The probability verification method proposed in the present application can effectively reduce the verification overhead of all Hash and Sign lattice signature paradigms. The advantage of this method is its wide applicability, not limited to specific signature schemes or application scenarios, but can be seamlessly integrated into any system using Hash and Sign lattice signature. By introducing the concept of probability verification, we have achieved a significant reduction in the required computing resources and time in the verification process while maintaining the security of the signature, thereby improving overall efficiency. This universality means that both existing and future Hash and Sign lattice signature schemes can benefit from the method. In short, this method brings a revolutionary verification way to the entire Hash and Sign lattice signature field. BRIEF DESCRIPTION OF DRAWINGS
[0027] Figure 1 is a probability verification schematic diagram.
[0028] Figure 2 is a three-dimensional numerical graph of k, t, P(E) when n = 512.
[0029] Figure 3 is a k, t value schematic diagram of P(E) ≥ 0.01%. DETAILED DESCRIPTION
[0030] The present application will be further described in detail below in combination with specific embodiments, but the embodiments of the present application are not limited thereto. The following content is a further detailed description of the present application in combination with specific preferred embodiments, and cannot be regarded as limiting the specific implementation of the present application to these descriptions. For ordinary skilled persons in the technical field to which the present application belongs, a number of simple deductions or substitutions can be made without departing from the concept of the present application, and all of them should be regarded as falling within the protection scope of the present application.
[0031] As shown in Figure 1 , the probability verification method applied to the Hash and Sign lattice signature paradigm provided by the present application comprises the following steps:
[0032] Step 1: initialization step Setup(n)→(params): the trusted party takes the security parameter λ as input and outputs the public parameter params=(m, q, s, H), wherein m≥6nlogq is the dimension of the signature vector, prime Gaussian parameter is a real number. Let A secure hash function.
[0033] Step 2: Key generation step KeyGen(params)→(sk,pk): The signer takes the public parameters params=(n,m,q,s,H) as input, runs the TrapGen(n,m,q) algorithm to generate the matrix and the trapdoor basis T of the dual lattice of the lattice with the lattice basis , outputs the public key pk←(A) and the private key sk←(T). This step generates the public key and the private key needed for the Hash and Sign lattice signature paradigm, the public key is an n-row m-column matrix over the ring , and n and m define the rank and dimension of the lattice with the public key matrix as the lattice basis, and the private key is the trapdoor basis matrix of the dual lattice with the public key matrix as the lattice basis.
[0034] Step 3: Signature step Sign(sk,pk,params,M)→e: Let the message be M∈{0,1} * , the signer calculates h=H(M), which is the "Hash" process of the Hash and Sign lattice signature paradigm. The signer calculates the vector t satisfying At=hmodq, uses the SamplePre(T,s,-t) algorithm to output t', and calculates e=t+t'modq as the signature of the message M, which is the "Sign" process of the Hash and Sign lattice signature paradigm.
[0035] Step 4: Random combination step RanCombine(pk,h)→pk',h': The verifier randomly selects k rows from the lattice basis matrix A and records the indices of the selected rows. The k row vectors are combined into a new lattice basis public key matrix from top to bottom according to the random selection order. Then calculate the hash value h of the message M, select the corresponding components from the vector h according to the same random selection index, and construct a new message hash vector h' according to the same combination method. This step randomly combines the verification parameters (lattice basis matrix A and message vector h) of the trivial Hash and Sign lattice signature paradigm and reduces its size, which is the key to improving the verification efficiency.
[0036] Step 5: Verification step Verify(params,pk',e,h')→0 / 1: The verifier calculates whether the signature e, the combined public key A', and the combined message vector h' satisfy the verification relationship, and outputs 1 when and only when A'e=h'modq and , which represents accepting the signature e, otherwise outputs 0, which represents rejecting the signature e. This step uses the verification parameters randomly combined in step 4 to verify according to the normal signature verification method of the Hash and Sign lattice signature paradigm.
[0037] In step 4, the verifier is required to randomly select row vectors from the lattice basis matrix and combine them from top to bottom in a random order to form a new lattice basis public key matrix; the verifier is required to calculate the hash value of the message, select the corresponding components from the hash vector according to the same randomly selected index, and construct a new message hash vector in the same combination manner. This step randomly combines the verification parameters (lattice basis matrix and message vector) of the trivial Hash and Sign lattice signature paradigm, reduces the size thereof, and reduces the number of matrix multiplication operations in the verification process, which is the key to improving the verification efficiency.
[0038] In step 5, the verifier needs to use the randomly combined lattice basis matrix and message hash vector generated in step 4 to verify the legality of the signature. Specifically, the verifier calculates whether the relationship A'e=h'mod q is satisfied between the signature e, the combined public key A' and the combined message vector h', and verifies whether the norm e of the signature satisfies Step 5 utilizes the idea of probabilistic verification, and according to the classical probability model, the legality of the signature can be judged with overwhelming confidence.
[0039] The probabilistic verification method in step 5 has potential universality for lattice signature schemes based on the Hash and Sign paradigm. The verification process of such signature schemes usually involves multiplication calculation and verification of the public key matrix and the signature vector, so by adopting a similar probabilistic verification strategy, it is expected to reduce the verification calculation overhead of such signatures.
[0040] Correctness analysis of the algorithm:
[0041] Gentry et al. have proved in the literature [4] (C. Gentry, C. Peikert, and V. Vaikuntanathan, “Trapdoors for hard lattices and new cryptographic constructions,” in Proceedings of the fortieth annual ACM symposium on Theory of computing, Victoria British Columbia Canada; ACM, May 2008, pp. 197-206.) that the Hash and Sign lattice signature paradigm is correct. In the improved signature algorithm, the idea of probabilistic verification is used to randomly select k rows from the public key matrix A and select the corresponding components from the vector h(M) to verify the signature e. If e is a legal signature, it naturally satisfies the conditions A'e=h(M)'mod q and .
[0042] Security analysis of the algorithm:
[0043] To analyze the signature process, for the hash value h(M) of message M, a long vector must first be calculated using the Gaussian elimination method. The condition is satisfied that At = h(M) mod q. Then, the SamplePre(A,T,s,-t) algorithm is used to output the preimage t′ of -t, where t′ is the dual lattice. The grid points on the grid satisfy t′+s=-t, where s is a short perturbation vector extracted from a relatively narrow Gaussian distribution. It has been proven in reference [4] that the process of input t′, perturbation vector s, and output -t can be regarded as a sampleable preimage function with the following properties:
[0044] (1) The perturbation vector s is extracted from a relatively narrow Gaussian distribution, under which the output -t is statistically close to a uniform distribution within the range.
[0045] (2) The process of sampling the preimage is not simply finding any preimage of -t, but actually sampling from all its preimages according to... The discrete Gaussian distribution on the surface is sampled.
[0046] The final signature is e = t' + tmod q. Therefore, even for two identical t1 and t2, preimage sampling of -t1 and -t2 still yields uniformly random t'1 and t'2. In the signature scheme, the hash function... It is safe, meaning that if there are two very close messages M1 and M2, the resulting hash values h(M)1 and h(M)2 are also uniformly random. Therefore, the long vectors t1 and t2 for which At1 = h(M1)modq and At2 = h(M2)modq hold are also uniformly random. In other words, t'1 and t'2 obtained by preimage sampling of -t1 and -t2 are also uniformly random, and consequently, the corresponding signatures e1 and e2 are also uniformly random. Therefore, for two different messages M1 and M2, as long as M1 ≠ M2, the corresponding e1 and e2 are both uniformly random.
[0047] Given a random uniform matrix Integer parameters m, n, q, short vector e1, message vector h, satisfying Ae1 = h mod q, let Let h be the i-th row vector of A. i Let h be the i-th component. Analysis shows that for another invalid signature e2, there exist t rows a1,...a i …a t Make a i e2 = h i The probability mod q. For convenience, let's assume...
[0048] Each row in A is independent, consider a particular row a i and vector e2. Since A is uniformly random, a i is also uniformly random. Given a i e2modq is uniformly distributed in Therefore, for any particular h i , the probability that a i e2≡h i modq is Since each row a i is independent, the probability that t rows all satisfy the condition is the probability that t independent events all occur, i.e. There are C(n,t) ways to choose t rows from n rows, define the probability that there are t rows satisfying the condition as
[0049] In the probabilistic verification method, we need to randomly select k rows (k < n) from A to form a new matrix A', and select the corresponding k components from h to form a vector h'. When n = 4, k = 2, the extraction method is shown in Figure 1
[0050] Define event E as e2 passing the verification, P(E) is the probability that A'e2 = h'modq holds:
[0051]
[0052] Obviously, if t < k, then event E cannot occur. Only when k ≤ t can event E occur.
[0053] In the case of n = 512, Figure 2 shows the relationship between P(E) and different values of k, t, Figure 2 The red part represents the values of k, t that make P(E) ≤ 1 -4 . Figure 3 represents the k, t value plane when P(E) ≥ 1 -4 .
[0054] P(A) decreases exponentially with the increase of t, even when t = 1, P(A) is a probability value close to 0. Obviously, at this time, no matter what k takes, P(E|A) = P(E)P(A) is also a negligible probability value close to 0.
[0055] Therefore, if e2 signature is not a legal signature, then the probability of passing the probability verification is negligible, and the "if and only if" in the verification condition is proved.
[0056] 1. Symbol definitions in this invention:
[0057] In this invention, bold lowercase letters are used to represent vectors, such as vector b. Bold uppercase letters are used to represent matrices, such as matrix A. Representing a number field, Let e1 represent the integer field modulo q. Given two vectors e1 and e2 of the same dimension,<e1,e2> Let ω(f(n)) represent the dot product of vectors. Assume a constant c > 0, and use ω(f(n)) to represent a function whose growth rate exceeds cf(n), and use poly(n) to represent a polynomial function f(n) = O(n^2). c The Euclidean norm (L2 norm) of a vector is represented by ||·||. The norm of a matrix is defined as the norm of its longest column vector, such as matrix S = {s1, ..., s2}. k Let ||S|| denote the length of the longest column vector, i.e., ||S|| = max i ||s i ||, i∈[1,k]. For any matrix S, This represents the matrix after Gram-Schmidt orthogonalization. Let D represent the Gram-Schmidt norm. Λ,s,c This represents a Gaussian distribution centered at c and with Gaussian parameter s on the lattice Λ. All logarithms used in the method are base 2.
[0058] 2. Basic Knowledge
[0059] Trapdoor generation algorithm
[0060] TrapGen is a trapdoor generation algorithm. Given matrix parameters n, m, q satisfying q = poly(n) and m ≥ 5nlogq, there exists a probabilistic multinomial-time algorithm TrapGen(m,n,q) that outputs a matrix. and a full-rank set The distribution of matrix A is statistically close to a uniform distribution, and ||S||≤O(nlogq). The set S can be effectively transformed into a lattice. Trapdoor base T.
[0061] Preimage sampling function
[0062] Given an n-dimensional lattice Λ(A), a trapdoor basis T, Gaussian parameters s, and a vector y, there exists a probabilistic multinomial-time algorithm SamplePre(T,s,y) that follows a Gaussian distribution D. Λ(A),s,y Output the vector x∈Λ(A) that is close to y.
[0063] GPV signature
[0064] Setup: Given parameters (n, m, q, s), generate a lattice L by the TrapGen algorithm and its trapdoor basis T. The public key is (n, m, q, s, A) and the private key is T. Define a secure hash function
[0065] Sign: The signer computes the hash value H(M) of the message M, generates a vector satisfying At = H(M) mod q. Using the SamplePre(T, s, -t) algorithm, output t'. Compute e = t' + t mod q as the signature of the message.
[0066] Verify: The verifier computes the hash value H(M) of the message M. Accept the signature e if and only if Ae = H(M) mod q and
[0067] While the present application has been described in terms of the specific embodiments described above, modifications and improvements can be made to the application without departing from the spirit and scope of the application. Accordingly, it is not intended that the application be limited, except as by the appended claims.
Claims
1. A probabilistic verification method applied to the Hash and Sign lattice signature paradigm, characterized in that, Comprising: Step 1: Initialization step : Trusted party takes as input a security parameter and outputs public parameters where is the dimension of the signature vector, a prime number , a Gaussian parameter is a real number; let be a secure hash function; Step 2: Key Generation Step The signer uses public parameters For input, run Algorithm generates matrix with grid trapdoor base Output public key private key ; Step 3: Signature step : Let the message be , the signer computes , this process is the "Hash" process of the Hash and Sign signature paradigm; the signer computes the vector satisfying , outputs using the algorithm , and computes as the signature of the message ; Step 4: Random combination step : The verifier randomly selects rows from the lattice basis matrix , and records the index of the selected rows; the row vectors are combined into a new lattice basis public key matrix , from top to bottom in the order of random selection , , then calculates the hash value of the message , selects the corresponding components from the vector according to the same randomly selected index, and constructs a new message hash vector in the same combination manner ; Step 5: Verification step : The verifier computes the signature , combines the public key matrix and the message hash vector , and checks whether the verification relation holds, i.e. and . If yes, output 1, meaning accepting the signature , otherwise output 0, meaning rejecting the signature .
2. The probabilistic verification method applied to Hash and Sign lattice signature paradigm according to claim 1, characterized in that, In Step 2, the public key and the private key used in the Hash and Sign lattice signature paradigm are generated, the public key is The matrix of row column on and defines the rank and dimension of the lattice with the public key matrix as the lattice basis, and the private key is the trapdoor basis matrix of the dual lattice with the public key matrix as the lattice basis.
3. The method for probabilistic verification applied to Hash and Sign lattice signature paradigm according to claim 1, characterized in that, In Step 3, the signature of the message is computed is the "Sign" procedure of the Hash and Sign signature paradigm.
4. The method for probabilistic verification applied to Hash and Sign lattice signature paradigm according to claim 1, characterized in that, In Step 4, the verification parameter of the traditional Hash and Sign lattice signature paradigm, i.e., the lattice basis matrix is combined randomly with the message vector and its size is reduced.
5. The method for probabilistic verification applied to Hash and Sign lattice signature paradigm as claimed in claim 1, wherein, In step 5, the signature verification method according to the traditional Hash and Sign signature paradigm is used to verify using the verification parameters combined randomly in step 4.
Citation Information
Patent Citations
Identity-based blind signature method on lower lattice of standard model
CN106533699A
On-lattice identity-based proxy blind signature method
CN115529134A