Distributed anonymous communication method and system based on threshold ECDSA signature

By adopting a distributed anonymous communication method based on threshold ECDSA signature and zero-knowledge proof in the electronic service system, the privacy leakage problem caused by single point failure in anonymous credential management is solved, and the protection of user privacy and the security of identity authentication are achieved.

CN119583210BActive Publication Date: 2025-10-17NORTHWESTERN POLYTECHNICAL UNIV +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411969948.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-10-17
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

In the authentication system of electronic services, anonymous credentials are managed by a central authority, resulting in a single point of failure that may lead to the leakage of user privacy data. When the plaintext certificate is stolen or lost, it will cause losses to users and service providers, making identity privacy protection difficult to solve.

Method used

A distributed anonymous communication method based on threshold ECDSA signature is adopted. The first private key is distributed and stored among multiple committee members to generate an anonymous pass. Zero-knowledge proof is used for identity authentication to avoid privacy leakage caused by single point failure.

Benefits of technology

Even if a committee member fails, the attacker cannot infer the anonymous pass, and the electronic service provider cannot obtain the user's identity information, protecting the user's privacy from being leaked, thus achieving anonymity, unforgeability and unlinkability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583210B_ABST
    Figure CN119583210B_ABST
Patent Text Reader

Abstract

The application discloses a kind of distributed anonymous communication method and system based on threshold ECDSA signature, method includes: committee member carries out security authentication to user according to the commitment value and attribute information sent by user;And based on threshold ECDSA signature algorithm, the anonymous pass of safe user is generated;Electronic service provider carries out identity authentication to user according to verification information to provide service to user.Due to committee is based on threshold ECDSA signature algorithm to generate the anonymous communication certificate of user, and the first private key used when the algorithm generates anonymous pass is distributed in multiple committee members, so even if a member appears single point failure, attacker cannot only speculate anonymous pass by single fault member;Since electronic service provider is authenticated to user identity by zero-knowledge proof, so electronic service provider cannot obtain the identity information of user from verification information;Therefore, the method provided by the application can protect the privacy of user from being leaked.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of data encryption, and particularly relates to a distributed anonymous communication method and system based on a threshold ECDSA signature. BACKGROUND

[0002] In an authentication system for electronic services, when an anonymous credential is used, the information disclosed by a user is minimized, and the problem of excessive disclosure of information in the current information flow process can be solved. However, the anonymous credential is usually issued and managed by a central authority, and therefore a single point of failure can occur, resulting in problems such as leakage of user privacy data. On the other hand, before providing an electronic service, the certificate of a user needs to be verified, but if a plaintext certificate is stolen or lost in a transaction, it will cause great losses to the user and the service provider, and therefore the problem of protecting the privacy of the identity of a user authenticated in an electronic service is difficult to solve. SUMMARY

[0003] The embodiments of the present application provide a distributed anonymous communication method and system based on a threshold ECDSA signature, which can solve the problem of leakage of user privacy caused by a single point of failure and loss of a certificate in the current authentication system.

[0004] In a first aspect, the embodiments of the present application provide a distributed anonymous communication method based on a threshold ECDSA signature, which is applied to a distributed anonymous communication system based on a threshold ECDSA signature, the system includes a committee and an electronic service provider, the committee includes a plurality of committee members, and the method includes:

[0005] The committee members perform security verification on a user according to a commitment value sent by the user and attribute information of the user;

[0006] The committee members generate an anonymous pass of a secure user based on a threshold ECDSA signature algorithm according to the attribute information of the secure user, wherein the threshold ECDSA signature algorithm distributes a first private key in the committee members, the first private key is used to generate the anonymous pass, and the secure user is a user who passes the security verification;

[0007] The electronic service provider performs identity verification on the user according to verification information sent by the user to provide a service to the user who passes the identity verification, wherein the verification information is zero-knowledge proof generated by the user according to the anonymous pass.

[0008] In a second aspect, the embodiments of the present application provide a distributed anonymous communication system based on a threshold ECDSA signature, which includes:

[0009] A committee, the committee includes a plurality of committee members, and the committee members are used to perform security verification on a user according to a commitment value sent by the user and attribute information of the user;

[0010] The committee member is also used for generating an anonymous pass of the secure user according to attribute information of the secure user based on a threshold ECDSA signature algorithm, wherein the threshold ECDSA signature algorithm distributes a first private key in the committee member, and the first private key is used for generating the anonymous pass, and the secure user is a user who passes the security verification;

[0011] The electronic service provider is used for verifying the identity of the user according to the verification information sent by the user, so as to provide a service to the user who passes the identity verification, wherein the verification information is zero-knowledge proof generated by the user according to the anonymous pass.

[0012] Compared with the prior art, the embodiment of the present application has the beneficial effects that: since the committee is used for generating the anonymous pass of the user based on the threshold ECDSA signature algorithm, and the threshold ECDSA signature algorithm distributes the first private key used for generating the anonymous pass in the plurality of committee members, even if a single point failure occurs in a certain committee member, an attacker cannot only speculate the anonymous pass of the user through the single committee member with the failure; since the electronic service provider verifies the identity of the user through the zero-knowledge proof, the electronic service provider cannot obtain the identity information of the user from the verification information; therefore, the method provided by the present application can protect the privacy of the user from being leaked. BRIEF DESCRIPTION OF DRAWINGS

[0013] Figure 1 A scene schematic diagram of a distributed anonymous communication method based on a threshold ECDSA signature provided by the present application;

[0014] Figure 2 A structure schematic diagram of a distributed anonymous communication system based on a threshold ECDSA signature provided by the embodiment of the present application;

[0015] Figure 3 A flow schematic diagram of a distributed anonymous communication method based on a threshold ECDSA signature provided by the embodiment of the present application;

[0016] Figure 4 A process schematic diagram of anonymous pass application and issuance provided by the embodiment of the present application;

[0017] Figure 5 A schematic diagram of a display process of the anonymous pass provided by the embodiment of the present application;

[0018] Figure 6 A schematic diagram of an anonymity proof process provided by the embodiment of the present application;

[0019] Figure 7 A schematic diagram of a non-forgery proof process provided by the embodiment of the present application. DETAILED DESCRIPTION

[0020] The present invention will be further described in detail below with reference to specific examples, but the embodiments of the present invention are not limited thereto.

[0021] Figure 1 The figure shows a scenario diagram of communication using a distributed anonymous communication method based on threshold ECDSA signature provided by the present invention.

[0022] Illustratively, the distributed anonymous communication method based on threshold ECDSA signature provided by the present invention can also be called a distributed anonymous communication protocol based on threshold ECDSA signature, and can be applied to a distributed anonymous communication system based on threshold ECDSA signature.

[0023] For example, see Figure 1 In the overall protocol, there are three parties involved in the interaction: the user, the electronic service provider (SP), and the committee. Figure 1 After the system is initialized, users register by uploading their identity information to the committee. Committee members perform a threshold ECDSA signature on the user's information, generate an anonymous pass, and return it to the user. Based on the anonymous pass, the user generates a zero-knowledge proof (i.e., verification information) and sends it to the electronic service provider. The electronic service provider verifies the user's verification information and, if the identity verification is successful, provides services to the user.

[0024] As an example, the system can complete initialization through the following steps S11-S14, generating a first public-private key pair (i.e., first public key, first private key) used by the committee, a second public-private key pair (i.e., second public key, second private key) used by the user, and system global parameters. The second public key is then made public to the electronic service provider and the user for use in generating verification information in the form of a zero-knowledge proof. Simultaneously, a slice of the first private key is distributed to each committee member using a secret sharing scheme.

[0025] Exemplarily, only when the number of valid committee members participating in recovering the first private key is greater than or equal to the key recovery threshold value t, can the committee members perform the signing function to generate the user's anonymous pass.

[0026] S11, params←Setup(1 λ ), which represents the generation of system global parameters (p,F p ,q,G1,G). Among them, E is the 2 =x 3 +ax+b(4a 3 +27b 2≠ 0), a, b∈F p An elliptic curve E is defined as E: y2= x3+ ax2+ b, G1 is a cyclic additive group containing all the points on the elliptic curve E and an infinite point O, p is a large prime number, G is a generator of G1, q is the order of G1, F p is a prime field containing p elements, λ is a security parameter. Meanwhile, a hash function H() is defined.

[0027] S12, (sk, pk) <- KeyGen (params), indicates generating a first public-private key pair.

[0028] Exemplarily, the first public-private key pair satisfies: (sk1 = x u , pk1 = x u · G), x u <- Z q , where sk1 is the first private key, pk1 is the first public key, Z q is a residue class ring with a prime number q as a modulus.

[0029] S13, indicates calling a decentralized Shamir secret sharing scheme to share the first private key sk1 in the committee, into n sub-keys (i.e. private key fragments); and setting a key recovery threshold value t.

[0030] S14, output params, indicates publishing the first public key and distributing the private key fragments to each member in the committee. Wherein, params is the implicit input of the algorithm.

[0031] Figure 2 The structure of a distributed anonymous communication system based on a threshold ECDSA signature provided by an embodiment of the application is shown. As an example but not limitation, the system 200 can include a committee 210, and an electronic service provider 220, the committee 210 can include a plurality of committee members 211.

[0032] The committee member 211 can be used to securely verify the user according to the commitment value sent by the user and the attribute information of the user; the committee member 211 can also be used to generate an anonymous pass of the secure user according to the attribute information of the secure user based on the threshold ECDSA signature algorithm.

[0033] The electronic service provider 220 can be used to authenticate the identity of the user according to the verification information sent by the user, to provide services to the user who passes the identity authentication.

[0034] Exemplarily, the threshold ECDSA signature algorithm distributes the first private key in the committee members, the first private key is used to generate an anonymous pass, and the secure user is a user who passes the security verification.

[0035] For example, the verification information is a zero-knowledge proof generated by the user according to the anonymous pass.

[0036] Since the committee generates the anonymous pass of the user based on the threshold ECDSA signature algorithm, and the threshold ECDSA signature algorithm distributes the first private key used when generating the anonymous pass in the plurality of committee members, even if a single point failure occurs in a certain committee member, an attacker cannot infer the anonymous pass of the user only through the single committee member with the failure; since the electronic service provider verifies the identity of the user through the zero-knowledge proof, the electronic service provider cannot obtain the identity information of the user from the verification information; therefore, the system provided by the present application can protect the privacy of the user from being leaked.

[0037] Figure 3 A flowchart of a distributed anonymous communication method based on a threshold ECDSA signature provided by an embodiment of the present application is shown. As an example but not limitation, the method 300 can include steps S301-S307, and the method 300 can be applied to the system 200 described above, and each step will be described below.

[0038] S301, the user commits the attribute information for registration.

[0039] In one example, the user can commit the attribute information about his / her identity according to the Pedersen commitment algorithm, generate a commitment value, and register.

[0040] Specifically, referring to Figure 4 , the user can run the U.Request(·) algorithm to send a certificate application to the committee with his / her commitment value, and the committee receives the commitment value and verifies it.

[0041] S302, the user sends the commitment value to the committee.

[0042] Correspondingly, the committee receives the commitment value.

[0043] S303, the committee verifies the user according to the commitment value sent by the user and the attribute information of the user.

[0044] In one example, if the user passes the security verification, the user can be determined as a secure user and step S304 is performed.

[0045] Specifically, referring to Figure 4 , the committee can call the verification algorithm (0, 1) <- C.Verify(v, C) to verify the commitment value to ensure that the information has not been tampered with.

[0046] Exemplarily, the user can be considered to pass the security verification when the commitment value of the user satisfies the following formula:

[0047] C = r1 · G + v · H

[0048] wherein C is the commitment value, r1 is the first random number, v is the attribute information of the user, H is a point on an elliptic curve, and G is a generator of a cyclic additive group.

[0049] In another example, if the user fails to pass the security verification, the protocol can be terminated and user error information can be returned.

[0050] In S304, the committee members generate the anonymous pass of the secure user based on the threshold ECDSA signature algorithm and the attribute information of the secure user.

[0051] In a possible implementation, the ith committee member can recover the ith private key shard held by the member, and then generate the ith first pass parameter and the ith second pass parameter according to the generator G, the key recovery threshold t, the order q of the cyclic additive group, the message hash value and the second random number. Any committee member can generate the third pass parameter according to the message hash value, the order q of the cyclic additive group, the second random number and the third random number selected by each committee member. Then any committee member can generate the anonymous pass according to the order of the cyclic additive group, the third pass parameter and the third random number of each committee member, the private key shard, the first pass parameter and the second pass parameter.

[0052] Specifically, referring to Figure 4 , the committee can run the C.Authenticate(·) algorithm to generate the anonymous pass of the secure user.

[0053] In one example, the anonymous pass can satisfy the following formula:

[0054]

[0055] wherein cred is the anonymous pass, is the third pass parameter, b i is the ith third random number, e i is the ith first pass parameter, sk i is the ith private key shard, c i is the ith second pass parameter, r is the first element of the anonymous pass determined according to the second random number, and q is the order of the cyclic additive group.

[0056] Exemplarily, cred = (r, s), and s is the second element constituting the anonymous pass.

[0057] S305, the user generates verification information according to the anonymous pass.

[0058] For example, referring to Figure 5 The user can call the algorithm U.Prove(·) to generate a non-interactive zero-knowledge proof, i.e., the verification information.

[0059] In one example, the verification information can include a first verification parameter and a second verification parameter.

[0060] For example, the first verification parameter can satisfy the following formula:

[0061] R=r2G

[0062] wherein R is the first verification parameter, r2 is a fourth random number, and G is a generator.

[0063] For example, the second verification parameter can satisfy the following formula:

[0064] z=r2+c·sk2

[0065] wherein z is the second verification parameter, sk2 is a second private key, and c is a third verification parameter.

[0066] S306, the user sends the verification information to the electronic service provider.

[0067] For example, when the user receives the anonymous pass sent by the committee, the user is represented as a legal user. When the user wants to obtain an electronic service, the user can provide the verification information in the form of zero-knowledge proof generated according to the anonymous pass to the corresponding electronic service provider.

[0068] Correspondingly, the electronic service provider receives the verification information.

[0069] S307, the electronic service provider verifies the identity of the user according to the verification information sent by the user, to provide services to the user whose identity verification is passed.

[0070] In one example, the electronic service provider can calculate a third verification parameter according to the second public key and the first verification parameter. Then determine whether the third verification parameter calculated by the electronic service provider, the first verification parameter and the second verification parameter received by the electronic service provider satisfy a verification model. If the verification model is satisfied, the identity verification of the user is passed and the corresponding service is provided to the user, if the verification model is not satisfied, an error information is returned.

[0071] For example, the verification model can satisfy the following formula:

[0072] z·G=R+c·pk2

[0073] wherein pk2 is the second public key.

[0074] Specifically, referring to Figure 5 , the electronic service provider can run the S.Verify(·) algorithm to complete the identity verification of the user.

[0075] Since the committee is used to generate the anonymous communication certificate of the user based on the threshold ECDSA signature algorithm, and the threshold ECDSA signature algorithm distributes the first private key used when generating the anonymous pass in the plurality of committee members, even if a single point failure occurs in a certain committee member, an attacker cannot only speculate the anonymous pass of the user through the single committee member with the failure; since the electronic service provider verifies the identity of the user through zero-knowledge proof, the electronic service provider cannot obtain the identity information of the user from the verification information; therefore, the method provided by the present application can protect the privacy of the user from being leaked.

[0076] Figure 4 An application and issuance process schematic diagram of the anonymous pass provided by the embodiment of the present application is shown.

[0077] Specifically, referring to Figure 4 , the U.Request(·) algorithm can include the following steps:

[0078] S411, (G, H, r1) <- C.Setup(1 λ ), which represents the necessary parameters required when generating the commitment. Wherein G is the generator of the cyclic additive group G1, H is another point on the elliptic curve E, and r1 is the first random number.

[0079] S412, (C) <- Comittment(r, G, H, v), which represents inputting the generated parameters and the attribute information v of the user, and outputting the commitment value.

[0080] Specifically, referring to Figure 4 , the C.Authenticate(·) algorithm can include the following steps:

[0081] S421, ({a i0 ,a i1 ,……,a i(t-1)}, ID i ) <- Setup(1 λ ), which represents that the i-th committee member M i generates its own identity iD i , and then selects t polynomial coefficients {a i0 ,a i1 ,……,a i(t-1)}. Finally, the i-th key share is generated according to the t polynomial coefficients, the order of the cyclic additive group, and the identity of the j-th committee member.

[0082] For example, the jth key share generated by the ith committee satisfies the following formula:

[0083] sk ij = f i (ID j )(j = 1, 2, …, n, j≠i)

[0084] wherein sk ij is the jth key share generated by the ith committee. f i (x) = a i0 + a i1 x + … + a i(t-1) x n- 1 mod q.

[0085] S422, indicates that after each committee member calculates his own n-1 key shares, the committee member sends the jth key share generated by himself to the jth committee member. After receiving the other n-1 valid key shares sk j , the committee member M ij can recover the jth private key shard according to the jth key share generated by the remaining committee members.

[0086] For example, the jth private key shard can satisfy the following formula:

[0087]

[0088] wherein sk j is the jth private key shard.

[0089] S423, indicates that the committee member generates a preliminary preparation parameter for subsequent signature.

[0090] Specifically, the ith committee member can select the ith second random number k i between [1, q-1], (i = 1, 2, …, t); then select the ith third random number b i . Any committee member can calculate in turn according to all the second random numbers: wherein is obtained by rounding x i , and r is the first element of the anonymous pass, which is part of the anonymous pass. Any committee member generates the third pass parameter according to all the second random numbers, the third random numbers, the message hash value and the order of the cyclic additive group. The attribute information of the user is subjected to hash operation to obtain the message hash value.

[0091] For example, the third pass parameter can satisfy the following formula:

[0092]

[0093] wherein, is a third credential parameter.

[0094] S424, represents that the ith committee member generates the ith first credential parameter and the ith second credential parameter according to the generator, the key recovery threshold value, the order of the cyclic additive group, the message hash value and the second random number.

[0095] In one example, the ith committee member can generate the ith first credential parameter according to the message hash value, the order of the cyclic additive group and the key recovery threshold value.

[0096] Exemplarily, the ith first credential parameter can satisfy the following formula:

[0097] e i = (et -1 ), od q

[0098] wherein, e i is the ith first credential parameter, e = H(v) is the message hash value.

[0099] In one example, the ith committee member can generate the ith second credential parameter according to the second random number, the order of the cyclic additive group and the key recovery threshold value.

[0100] Exemplarily, the ith second credential parameter can satisfy the following formula:

[0101]

[0102] wherein, c i is the ith second credential parameter.

[0103] S425, represents that the anonymous credential is calculated and generated according to the third random number, the private key shard, the order of the cyclic additive group, the first credential parameter, the second credential parameter and the third credential parameter based on the threshold ECDSA signature function.

[0104] Exemplarily, the anonymous credential can satisfy the following formula:

[0105]

[0106] wherein, cred is the anonymous credential, is the third credential parameter, b i is the ith third random number, e i is the ith first credential parameter, ski is the i-th private key shard, c i is the i-th second pass parameter, r is the first element of the anonymous pass determined according to the second random number, and q is the order of the cyclic additive group.

[0107] Optionally, q i = (e i + sk i · c i · r) mod q can be further simplified to

[0108] Finally, the committee can send the anonymous pass cred = (r, s) to the user.

[0109] Figure 5 The schematic diagram of the display process of the anonymous pass provided by the embodiment of the application is shown.

[0110] Specifically, referring to Figure 5 , the U.Prove(·) algorithm can include the following steps:

[0111] S511, (a, pk, r) <- U.Keygen(1 λ ), which means that the user generates a second public-private key pair. The second private key a can be the anonymous pass cred of the user, and the second public key pk2 = aG. Meanwhile, a fourth random number r2 can be selected.

[0112] S512, (R, c, z) <- U.Show(r), which means that the user calculates the first verification parameter, the third verification parameter and the second verification parameter in turn, and sends the first verification parameter and the second verification parameter to the electronic service provider.

[0113] For example, the third verification parameter can satisfy the following formula:

[0114] c = Hash(pk2, R)

[0115] Wherein, Hash() represents a hash function.

[0116] Specifically, referring to Figure 5 , the S.Verify(·) algorithm can include the following steps:

[0117] S521, (c) <- S.Counter(pk2, R), which means that the electronic service provider calculates the third verification parameter according to the second public key and the first verification parameter.

[0118] S522, (0, 1) <- S.Verify(c, z, R), which means that the electronic service provider verifies whether the calculated third verification parameter and the received first verification parameter and second verification parameter satisfy the verification model, and returns the verification result.

[0119] Since the committee is used to generate the anonymous communication certificate of the user based on the threshold ECDSA signature algorithm, and the threshold ECDSA signature algorithm distributes the first private key used when generating the anonymous pass in the plurality of committee members, even if a single point failure occurs in a certain committee member, an attacker cannot only speculate the anonymous pass of the user through the single committee member with a single point failure; since the electronic service provider verifies the identity of the user through zero-knowledge proof, the electronic service provider cannot obtain the identity information of the user from the verification information; therefore, the method provided by the present application can protect the privacy of the user from being leaked.

[0120] Therefore, in one or more of the following scenarios, the protocol provided by the present application has anonymity, unforgeability and unlinkability: the committee members may be bribed, but the members with malicious behavior do not exceed the key recovery threshold value t; there are malicious electronic service providers trying to guess the identity of the user, and there are collusions of multiple malicious electronic service providers; there are dishonest users trying to cheat the electronic service provider to obtain services without anonymous passes, but cannot collude with other users.

[0121] Illustratively, anonymity means that two verification information generated by the same anonymous pass used by the same user should be indistinguishable by an adversary. The present application guarantees the unlinkability of the anonymous pass while ensuring anonymity.

[0122] Unforgeability means that the electronic service provider can only generate a valid and trusted proof of identity verification by the user when the user has a valid anonymous pass and the information contained in the pass meets the security policy. For potential attackers, they cannot forge a legitimate anonymous pass and pass the identity verification.

[0123] Unlinkability includes the unlinkability of the presentation of the anonymous pass and the unlinkability between the anonymous passes.

[0124] The unlinkability of the presentation of the pass means that when the same user uses the same anonymous pass to present multiple times, the verifier (the electronic service provider) and the issuer (the committee) cannot infer the correlation between the presentation processes from the multiple presentations.

[0125] The unlinkability between credentials means that if the same user uses the same attribute information to obtain multiple anonymous credentials, the electronic service provider and the committee cannot determine whether the multiple displays of the credentials originate from the same attribute information.

[0126] Optionally, the unlinkability can ensure that the use of different credentials cannot be easily associated, thereby providing better privacy protection, which is usually used to prevent the electronic service provider from associating the user's access records. However, in some association scenarios, such as a user point system, in order to provide more services, whether to implement this attribute can be selected according to the requirements of specific scenarios.

[0127] In order to better illustrate the beneficial effects of the protocol provided by the present application, the following security analysis is performed:

[0128] For example, in the process of security analysis, the following oracles and lists can also be included in the system:

[0129] Honest user list H_U: using variable id to identify users.

[0130] Corrupted user list C_U: using variable id to identify users, recording the identification of users corrupted by the adversary.

[0131] Credential query list Q_Show: recording the queries and responses of the adversary to the Show algorithm.

[0132] Registration record list reg: recording the registration information of users.

[0133] Certificate oracle O.List_ssk(): the adversary queries the certificate of the user identified by id, the oracle performs table lookup and response, and adds id to C_U.

[0134] Certificate request oracle O.Request(): the oracle executes the honest Request protocol. The adversary acts as a corrupted certificate authority, and the challenger interacts with the adversary as an honest user. At the end of the protocol, the certificate ssk[id] of the user is returned.

[0135] Certificate distribution oracle O.Issue(): the oracle executes the honest Issue protocol. The adversary acts as a corrupted user id, and the challenger interacts with the adversary as an honest certificate authority. At the end of the protocol, id is added to C_U, and the registration information reg[id] of the user is returned.

[0136] O.Show() : The adversary calls the Show oracle, and asks for a valid show proof of the honest user id. If id does not belong to H_U, return. Otherwise, the oracle executes the Show algorithm, and the adversary acts as a malicious verifier. The oracle adds id to the list Q_Show.

[0137] Figure 6 Fig. 1 shows a schematic diagram of the anonymity proof process provided by the embodiment of the present application.

[0138] In particular, referring to Figure 6 The anonymity of the protocol provided by the present application can be proved by the following process.

[0139] The simulator S interacts with the adversary A, and executes the distributed anonymous credential protocol based on threshold ECDSA signature. The simulator S initializes the system and generates all system parameters, and the adversary A calls the key generation algorithm as a corrupted committee to generate the first public-private key pair (sk1, pk1). The adversary A can make the following oracle inquiries.

[0140] O.Request(k) : The simulator S and the adversary A interact to execute the <Request, Issue> protocol, add k to the H_U list, and the simulator acts as an honest user k to generate an anonymous credential cred. The adversary A holds sk to interact, and returns ssk[k] = (r, s).

[0141] O.Show(k) : The adversary A inquires about the anonymous credential of the user identified as i. If k ∈ H_U, the simulator executes the U.Show algorithm and generates θ = (c, z, R) to answer, and adds (k, θ) to Q_Show.

[0142] O.List_ssk(k) : The adversary inquires about the credential of the user identified as k, and the simulator retrieves the query list and answers, and finally adds k to C_U.

[0143] According to the above oracle inquiry process, the adversary A outputs the user k0, the user k1, and if k0, k1 ∈ H_U, then the simulator S selects one of the users to generate his anonymous credential, and returns the simulated show credential θ * = (c, z, R) to the adversary A, and the adversary guesses which user the credential comes from and outputs his own guess result b'. Since the zero-knowledge proof is zero-knowledge, it is ensured that no information about the user identification will be leaked to the adversary in the show stage of the credential, so the adversary cannot distinguish. Thus, it can be proved that the distributed anonymous credential protocol based on threshold ECDSA signature has anonymity, and the proof is complete.

[0144] Figure 7A schematic diagram of the non-forgeability proving process provided by the embodiment of the present application is shown.

[0145] Specifically, referring to Figure 7 The non-forgeability of the protocol provided by the present application can be proved by the following process.

[0146] The simulator S interacts with the adversary A and executes the distributed anonymous credential protocol based on the threshold ECDSA signature. During the whole process, the simulator S receives the public key instance y = xG of the threshold ECDSA signature. The specific proof of the protocol is as follows: the simulator S first initializes the system and generates all the system parameters, and then calls the key generation algorithm to send the first public key y to the adversary A as pk1. The adversary as a hatched user interacts with the simulator S and makes the following oracle inquiries:

[0147] O.H(·): Hash oracle inquiry. The adversary A selects a specific string {0,1} * as input, and then the simulator S queries the Q H list. If there is the same value in the list, the simulator S returns the corresponding element. Otherwise, if there is no such value, the simulator S will simulate and select a random number c∈Z q to respond.

[0148] O.Issue(k): The simulator S and the adversary A interact to execute the <Request, Issue> protocol, add k to the C_U list, the adversary starts to inquire, and the simulator as an honest committee member interacts with the adversary. When receiving the inquiry information of the adversary, the simulator S calls the verification link of the zero-knowledge proof. If the verification is valid, the simulator S replays the process, calls the Extract() algorithm, and then extracts the inquiry message H(v). The simulator S internally inquires the threshold ECDSA signature of the message H(v), and the challenger sends the feedback threshold ECDSA signature to the simulator S, and the simulator S sends the signature to the adversary A.

[0149] O.Show(k): The adversary A inquires the anonymous credential of the identifier k. If k∈H_U, the simulator expands to execute the Show algorithm and generates θ = (c, z, R) to respond, and adds (k, θ) to Q_Show.

[0150] O.List_ssk(k): The adversary A inquires the credential of k, the simulator retrieves and queries the list and answers, and finally adds k to C_U.

[0151] According to the above oracle inquiry process, the adversary A forges θ *and output. If the verification algorithm fails, the interaction with the adversary is interrupted. If the adversary's fake credential passes the verification, the identity k is hashed for the kth time, and the output (k, θ * ) is output. Then according to the branching lemma, two fake credentials θ * = (c, z, R) and By unfolding, the simulator extracts (r, s) as a threshold ECDSA signature and sends it to the challenger, thereby winning the experiment.

[0152] In summary, if there exists an adversary A that can forge anonymous passes based on threshold ECDSA signatures with a non-negligible probability ε(λ), then there must exist a simulator that can forge threshold ECDSA signatures, thereby attacking the discrete logarithm problem on elliptic curves. Therefore, the protocol provided by the present application has a proof of non-forgeability, and the proof is complete.

[0153] In the above embodiments, the description of each embodiment has its own focus, and the parts not described or recorded in detail in a certain embodiment can be referred to the related description of other embodiments.

Claims

1. A distributed anonymous communication method based on threshold ECDSA signature, characterized in that: The method is applied to a distributed anonymous communication system based on threshold ECDSA signatures, the system including a committee and an electronic service provider, the committee including multiple committee members, and the method including: The committee members perform security verification on the user based on the commitment value sent by the user and the user's attribute information; The committee members generate an anonymous pass for the security user based on the attribute information of the security user based on a threshold ECDSA signature algorithm, wherein the threshold ECDSA signature algorithm stores a first private key in a distributed manner among the committee members, the first private key is used to generate the anonymous pass, and the security user is a user who has passed the security verification; The commitment value of the security user satisfies the following formula: in, is the commitment value, is the first random number, is the attribute information of the user, is a point on the elliptic curve, is the generator of the cyclic additive group; The electronic service provider authenticates the user based on the verification information sent by the user, and provides services to the user who has passed the authentication, wherein the verification information is a zero-knowledge proof generated by the user based on the anonymous pass; The committee members generate an anonymous pass for the security user based on the threshold ECDSA signature algorithm and attribute information of the security user, including: No. i Committee members resumed i private key shards, wherein all the private key shards constitute the first private key; The said i The committee members generate the first i The first pass parameters and i a second pass parameter, wherein the message hash value is obtained by performing a hash operation on the attribute information of the security user; The committee member generates a third pass parameter according to the message hash value, the order of the cyclic addition group, the second random number, and the third random number; The committee member generates the anonymous pass based on the third random number, the private key shard, the order of the cyclic additive group, the first pass parameter, the second pass parameter and the third pass parameter.

2. The method according to claim 1, characterized in that The said i Committee members resumed i private key shards, including: The said i Committee members selected t polynomial coefficients, where t A threshold value for recovering the key; The said i The committee members are divided into two groups according to the polynomial coefficients, the order of the cyclic additive group and the j The identity of each committee member generates the j key shares, i, j Both greater than or equal to 1 and less than or equal to n integer, n is the total number of members of the said committee; The said i committee members according to the first i The key shares generate the i private key shards.

3. The method according to claim 1, characterized in that The said i The committee members generate the first i The first pass parameters and i Second pass parameters, including: The said i The committee members generate the first i First pass parameters; The said i The committee members generate the first i A second pass parameter.

4. The method according to claim 1, wherein The anonymous pass satisfies the following formula: in, For the anonymous pass, is the third pass parameter, For the i A third random number, For the i First pass parameters, For the i private key shards, For the i The second pass parameter, is the first element of the anonymous pass determined according to the second random number, is the order of the cyclic additive group.

5. The method according to claim 1, wherein The verification information includes a first verification parameter and a second verification parameter; The first verification parameter satisfies the following formula: in, is the first verification parameter, is the fourth random number, is the generator; The second verification parameter satisfies the following formula: in, is the second verification parameter, is the second private key, is the third verification parameter.

6. The method according to claim 5, characterized in that The electronic service provider verifies the user's identity based on the verification information sent by the user, including: The electronic service provider calculates the third verification parameter based on the second public key and the first verification parameter; The electronic service provider determines whether the first verification parameter, the second verification parameter, and the third verification parameter satisfy a verification model; If the first verification parameter, the second verification parameter, and the third verification parameter satisfy the verification model, the user's identity authentication is passed.

7. The method according to claim 6, characterized in that The verification model satisfies the following formula: in, The second public key.

8. A distributed anonymous communication system based on threshold ECDSA signature, characterized in that: include: A committee, the committee including a plurality of committee members, the committee members being used to perform security verification on the user based on the commitment value sent by the user and the user's attribute information; The committee members are further configured to generate an anonymous pass for the security user based on attribute information of the security user based on a threshold ECDSA signature algorithm, wherein the threshold ECDSA signature algorithm stores a first private key in a distributed manner among the committee members, the first private key being used to generate the anonymous pass, and the security user being a user that has passed security verification; The commitment value of the security user satisfies the following formula: in, is the commitment value, is the first random number, is the attribute information of the user, is a point on the elliptic curve, is the generator of the cyclic additive group; an electronic service provider, configured to authenticate the user based on verification information sent by the user, and provide services to the user who has passed the authentication, wherein the verification information is a zero-knowledge proof generated by the user based on the anonymous pass; The committee members are also specifically used to: No. i Committee members resumed i private key shards, wherein all the private key shards constitute the first private key; The said i The committee members generate the first i The first pass parameters and i a second pass parameter, wherein the message hash value is obtained by performing a hash operation on the attribute information of the security user; The committee member generates a third pass parameter according to the message hash value, the order of the cyclic addition group, the second random number, and the third random number; The committee member generates the anonymous pass based on the third random number, the private key shard, the order of the cyclic additive group, the first pass parameter, the second pass parameter and the third pass parameter.

Citation Information

Patent Citations

  • Distributed threshold signature method based on elliptic curve

    CN106506156A

  • Traceable completely anonymous electronic voting method and system based on block chain

    CN112487468A