Group signature-based partner information sharing method and device, and electronic device
By setting identity identifiers and certificates for partners, generating signature private keys, and using revocation tokens and group public keys for verification, the shortcomings of group signature schemes in resisting quantum attacks and dynamic management are solved, realizing the authenticity and integrity of information and improving the trust and efficiency of partners.
Patent Information
- Application Number
- CN202411802572.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2044-12-09
AI Technical Summary
Existing group signature technologies are inadequate in resisting quantum attacks and dynamic management, making it difficult to ensure the authenticity and integrity of information, thus affecting the trust and cooperation efficiency of partners.
By setting identity identifiers and identity certificates for new partners, generating private keys for group member signatures, and using revocation tokens and token certificates for dynamic management, combined with the group public key to verify the signature results, dynamic nature and forward security are achieved.
Ensuring the authenticity and integrity of information while supporting the anonymity of partners improves trust and collaboration efficiency, enabling secure information sharing even in scenarios with frequent member changes.
Smart Images

Figure CN119728119B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of financial technology or other related fields, and more specifically, to a method, apparatus, and electronic device for sharing information among partners based on group signatures. Background Technology
[0002] The rapid development of the digital age has spurred various industries to accelerate their digital transformation, particularly in the financial sector, where transactions and collaborations between financial institutions and their partners are becoming increasingly frequent. To address this trend, financial institutions are transforming from single payment service providers to comprehensive solution providers, aiming to offer partners more comprehensive business support. This deep collaboration often involves multiple parties, sharing customer data and credit rating information, becoming an indispensable part of the collaborative ecosystem.
[0003] For the same project, financial institutions may collaborate with multiple partners. These partners can form a group to share information and achieve mutual benefit throughout the project. When sharing information, partners may not want to expose relevant resources and information they possess, and hope to maintain anonymity. Currently, information sharing mainly uses real-name authentication or simple anonymous posting. While real-name authentication ensures the source and credibility of information, it lacks protection for the privacy of the information sender and may expose sensitive data of partners. Simple anonymous posting, while protecting the privacy of the information sender, lacks an effective verification mechanism, making it difficult to ensure the authenticity and completeness of the information, thus impacting the trust between partners and the efficiency of the collaboration.
[0004] While existing group signature technologies offer a degree of anonymity and information verification, they suffer from significant shortcomings in resistance to quantum attacks and dynamic management (member joining and revocation). With the development of quantum computers, traditional encryption techniques based on complex mathematical problems may no longer be secure; therefore, quantum-resistant group signature schemes have become a research hotspot. Simultaneously, the dynamic changes in members during project collaborations, such as temporary withdrawals or rejoins, require group signature schemes to be dynamic and flexible. Existing solutions often face a trade-off between efficiency and security when implementing these functions.
[0005] Currently, there is no effective solution to the problem that group signature schemes in related technologies lack effective verification mechanisms, making it difficult to ensure the authenticity and integrity of information and affecting the trust and cooperation efficiency of partners. Summary of the Invention
[0006] This invention provides a method, apparatus, and electronic device for sharing information among partners based on group signatures, in order to at least solve the technical problem in related technologies that group signature schemes lack effective verification mechanisms, making it difficult to ensure the authenticity and integrity of information, and affecting the trust and cooperation efficiency of partners.
[0007] To achieve the above objectives, according to one aspect of this application, a method for sharing partner information based on group signature is provided, applied to a group sharing system deploying multiple partners. The partners included in the group at least include: a financial head office, multiple financial branches, and partners with business cooperation with the financial branches. The method for sharing partner information based on group signature includes: responding to a group joining request initiated by a new partner; the financial branch setting an identity identifier and identity certificate for the new partner based on partner information, and generating a group member signature private key for the new partner; the financial branch calculating a revocation token and token certificate corresponding to the current time period based on the identity identifier and identity certificate of the new partner, and updating the group member registration list; the new partner signing its own customer credit rating information using the group member signature private key, and sharing the signature result to the group; other partners in the group verifying the signature result using the group's public key, and confirming the validity of the own customer credit rating information and the correctness of the new partner's anonymous identity based on the verification result.
[0008] Optionally, the group may also include a cloud server and a key generation center, and the method for sharing information among the partners may further include: inputting security parameters to the key generation center; based on the security parameters, the key generation center uses a dynamic group key generation algorithm to generate public and private key pairs for the head office of the financial institution and each of the branches of the financial institution respectively, and outputs the group public key.
[0009] Optionally, the method for sharing information between partners based on group signatures further includes: when it is detected that the current time period has ended, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period; or, when it is detected that there is a revocation partner in the group, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period; or, when it is detected that there is a new partner in the group, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period.
[0010] Optionally, the method for sharing partner information based on group signatures further includes: setting a tracking public key and a tracking private key, and sending the tracking private key to the financial branch, which then sends the tracking private key to each partner; initializing a partner registration counter, a revocation list, and a token key list, wherein the partner registration counter is used to record the number of partners that have project cooperation with each of the financial branches, the signature result of the terminated partner corresponding to each revocation token in the revocation list cannot pass authentication, and the token key list is used to store the revocation token key corresponding to the terminated partner who has added the revocation token.
[0011] Optionally, the method for sharing partner information based on group signatures further includes: if any partner in the group suspends or terminates project cooperation with the financial branch, confirming that partner as a terminated partner; the financial branch adding the revocation token of the terminated partner to the revocation list and adding the revocation token key of the terminated partner to the token list.
[0012] Optionally, the method for sharing partner information based on group signatures further includes: after receiving an identity restoration request initiated by the terminating partner, the financial branch audits the project cooperation information of the terminating partner; if the audit is successful, the financial branch removes the revocation token corresponding to the terminating partner from the revocation list.
[0013] Optionally, the method for sharing information between partners based on group signatures further includes: if the verification result indicates that other partners have objections to the credit rating information of the newly added partner's own customers, the head office of the financial institution in the group finds the identity information of the objecting partner by tracing the private key; the head office of the financial institution outputs a penalty factor to the partner that uploaded the credit rating information of its own customers, and the penalty factor is used to handle the violation.
[0014] To achieve the above objectives, according to another aspect of this application, a group signature-based partner information sharing device is provided, applied to a group sharing system deploying multiple partners. The partners included in the group at least include: a financial head office, multiple financial branches, and partners with business cooperation with the financial branches. The group signature-based partner information sharing device includes: a partner private key generation unit, used to respond to a group joining request initiated by a new partner; the financial branch sets an identity identifier and identity certificate for the new partner based on the partner information, and generates a group member signature private key for the new partner. The system includes: a key; a registration list update unit, used by the financial branch to calculate the revocation token and token certificate corresponding to the current time period based on the identity identifier and identity certificate of the newly added partner, and update the group member registration list; a signature unit, used by the newly added partner to sign its own customer credit rating information using the group member signing private key, and share the signature result to the group; and a signature verification unit, used by other partners in the group to verify the signature result using the group's group public key, and to confirm the validity of the own customer credit rating information and the correctness of the newly added partner's anonymous identity based on the verification result.
[0015] Optionally, the group may also include a cloud server and a key generation center, and a virtual device for sharing information among partners. The group may also include: a parameter input unit for inputting security parameters to the key generation center; and a dynamic key generation unit for generating dynamic public-private key pairs for the head office and each branch office of the financial institution based on the security parameters using a dynamic group key generation algorithm, and outputting the group public key.
[0016] Optionally, the virtual device for sharing information among partners further includes: a time period detection unit, used to trigger a group signature private key update when the current time period has ended; a group signature private key update unit, used to update the group signature private key of the financial branch and each partner in the group according to the signal from the time period detection unit; a revocation token update unit, used to update the revocation tokens corresponding to each partner in the previous time period to the revocation tokens corresponding to the current time period; and a dynamic partner detection unit, used to notify the group signature private key update unit and the revocation token update unit to update when a revocation or addition of a partner is detected in the group.
[0017] Optionally, the virtual device for sharing information among partners further includes: a tracking key setting unit, used to set a tracking public key and a tracking private key, and send the tracking private key to the financial branch; a tracking key distribution unit, used by the financial branch to send the tracking public key to each partner; and a dynamic management initialization unit, used to initialize a partner registration counter, a revocation list, and a token key list, wherein the partner registration counter is used to record in real time the number of partners with whom the financial branch has project cooperation, the revocation list is used to store partner revocation tokens with unverifiable signature results, and the token key list is used to store the revocation token keys corresponding to terminated partners who have added revocation tokens.
[0018] Optionally, the virtual device for sharing information among partners further includes: a project cooperation status detection unit, used to confirm that any partner in the group is a terminating partner when the project cooperation with the financial branch is suspended or terminated; and a revocation management unit, used to add the revocation token of the terminating partner to the revocation list and add the revocation token key of the terminating partner to the token key list after the project cooperation status detection unit confirms the terminating partner, to ensure the unverifiable nature of the terminating partner's signature.
[0019] Optionally, the virtual device for sharing information among partners further includes: an identity restoration request receiving unit, used to receive an identity restoration request initiated by the terminating partner; a project cooperation information review unit, used to review the project cooperation information of the terminating partner after receiving the identity restoration request; and an identity restoration processing unit, used to delete the revocation token corresponding to the terminating partner from the revocation list if the review result is satisfactory.
[0020] Optionally, the virtual device for sharing information among partners further includes: a violation detection unit, used to trigger a tracking mechanism when the verification result indicates that the other partners have objections to the new partner's proprietary customer credit rating information; a tracking unit, used by the financial head office to find the identity information of the objecting partner through a tracking private key; and a penalty processing unit, used by the financial head office to output a penalty factor to the partner that uploaded the proprietary customer credit rating information based on the result of the tracking unit, wherein the penalty factor is used to process the violation.
[0021] To achieve the above objectives, according to another aspect of this application, an electronic device is provided, comprising: a memory storing an executable program; and a processor for running the program, wherein the program, when running, executes the group signature-based collaborator information sharing method described in any one of the preceding claims.
[0022] To achieve the above objectives, according to another aspect of this application, a computer program product is provided, including computer instructions that, when executed by a processor, implement the steps of the group signature-based collaborator information sharing method described in any one of the preceding claims.
[0023] According to another aspect of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute any of the above-described group signature-based collaborator information sharing methods.
[0024] According to another aspect of the present invention, an electronic device is also provided, including one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the group signature-based collaborator information sharing method described above.
[0025] According to another aspect of the present invention, a computer program product is also provided, including a computer program that, when executed by a processor, implements the steps of the group signature-based collaborator information sharing method described above.
[0026] In this disclosure, the partners included in the group include at least: the head office of a financial institution, multiple branch offices of a financial institution, and partners with whom the branch offices have business cooperation. In response to a new partner's request to join the group, the branch office sets an identity identifier and identity certificate for the new partner based on the partner's information, and generates a group member signing private key for the new partner; the branch office calculates a revocation token and token certificate corresponding to the current time period based on the new partner's identity identifier and identity certificate, and updates the group member registration list; the new partner uses the group member signing private key to sign its own customer credit rating information and shares the signature result with the group; other partners in the group verify the signature result using the group's public key, and confirm the validity of their own customer credit rating information and the correctness of the new partner's anonymous identity based on the verification result.
[0027] In this disclosure, the system supports partners in using group member signature private keys to sign their own customer credit rating information and share the signature results to the group. It can dynamically authorize partners to join the group for information sharing, and update the key at certain time intervals and when partners are added or removed from the group. This achieves dynamism and forward security, ensuring the security of the signature before the key is leaked. It solves the technical problem in related technologies where group signature schemes lack effective verification mechanisms, making it difficult to ensure the authenticity and integrity of information, which affects the trust of partners and the efficiency of cooperation. Attached Figure Description
[0028] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:
[0029] Figure 1 This is a flowchart of an optional group signature-based method for sharing information among collaborators according to an embodiment of the present invention;
[0030] Figure 2 This is a schematic diagram of a forward-secure dynamic group signature system according to an embodiment of the present invention;
[0031] Figure 3 This is a schematic diagram of an optional group signature-based collaborator information sharing device according to an embodiment of the present invention;
[0032] Figure 4 This is a hardware structure block diagram of an electronic device (or mobile device) that performs a group signature-based collaborator information sharing method according to an embodiment of the present invention. Detailed Implementation
[0033] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0034] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0035] It should be noted that the information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, and displayed data) collected in this public disclosure are information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with the relevant laws, regulations, and standards of the relevant regions, necessary confidentiality measures have been taken, and they do not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse. For example, this system has interfaces with relevant users or organizations. Before obtaining relevant information, a request to obtain the information needs to be sent to the aforementioned user or organization through the interface, and the relevant information is obtained only after receiving consent from the aforementioned user or organization.
[0036] The present invention will now be described in detail with reference to various embodiments.
[0037] Example 1
[0038] According to an embodiment of the present invention, an embodiment of a collaborator information sharing method based on group signature is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0039] According to one aspect of this application, a method for sharing information among partners based on group signatures is provided, applied to a group sharing system deploying multiple partners. The partners included in the group at least include: a financial head office, multiple financial branches, and partners with business cooperation with the financial branches. The number of financial branches corresponding to one financial head office can be determined according to actual needs. The financial head office can act as a manager within the group, overseeing all partners and branches.
[0040] This application provides, as follows: Figure 1 The method for sharing information among partners based on group signatures is shown. Figure 1 This is a flowchart of an optional group signature-based collaborator information sharing method according to an embodiment of the present invention, such as... Figure 1 As shown, it includes:
[0041] In step S101, in response to the group joining request initiated by the new partner, the financial branch sets an identity identifier and identity certificate for the new partner based on the partner information, and generates a group member signature private key for the new partner.
[0042] When a new partner (e.g., a payment service provider or data service provider) wishes to join an information-sharing group managed by a financial branch, it first initiates a formal group join request. This request includes the partner's basic information, such as the institution's name, business scope, and contact information, for the financial branch to conduct an initial qualification review. Upon approval, the financial branch assigns a unique anonymous identifier to the new partner. This identifier is used to anonymously identify and track the partner within the group without revealing their true identity. Typically, the identifier is a randomly generated string of numbers or letters, but here it is combined with group signature technology for a higher level of anonymity and security. The financial branch uses a specific algorithm of the group signature scheme to generate an identity certificate for the new partner. The identity certificate is a credential proving the partner's right to send signed information within the group. It may contain the partner's identifier and a digital certificate signed by the group administrator (i.e., the financial branch) to ensure its legitimacy and credibility.
[0043] It should be noted that in this embodiment, the financial branch also generates a group member signature private key for the newly added partner. This signature private key will be used for subsequent signature operations. The generation process of the signature private key must ensure that it is tightly bound to the identity identifier and certificate. At the same time, considering the dynamic nature of the group, the signature private key is only valid within a specified time period to support subsequent revocation and update mechanisms.
[0044] In step S102, the financial branch calculates the revocation token and token certificate corresponding to the current time period based on the identity identifier and identity certificate of the newly added partner, and updates the group member registration list.
[0045] Financial branches first determine the current time period, which is usually based on a preset period length, such as weekly, monthly, or a portion of a project cycle. The setting of the time period is crucial for member revocation and key updates in dynamic group signature schemes.
[0046] Based on the identity certificate of the new partner and the current time period, the financial branch calculates a revocation token. The revocation token is used to revoke the partner's signing authority under specific conditions, ensuring that once the partner's service is terminated or suspended, its previous signatures will no longer be considered valid. The calculation of the revocation token must consider forward security and dynamism, ensuring that even if the private key is compromised, signatures from previous time periods remain valid.
[0047] Simultaneously, corresponding to the revocation token, the financial branch generates a token certificate to prove the validity of the revocation token. This token certificate is also calculated based on the identity certificate and the current time period, and for other members in the group, the token certificate serves as the basis for verifying the legitimacy of the revocation token.
[0048] After completing the above steps, the financial branch updates the group member registration list, adding the identity identifier, identity certificate, signature private key digest information, revocation token, and token certificate information of the newly added partner to the list. This synchronizes the member status and token information of the entire group, supporting subsequent member management operations.
[0049] In step S103, the newly added partner uses the group member's signature private key to sign its own customer credit rating information and shares the signature result with the group.
[0050] It should be noted that the new partners in this embodiment need to prepare customer credit rating information to be shared in advance. This information may include credit scores, transaction history, risk assessment, etc., but any sensitive data that may directly expose the customer's identity should be removed.
[0051] Using the group member signing private key generated in step S101, the new partner signs the customer credit rating information. This signing process not only ensures the integrity and authenticity of the information but also protects the anonymity of the partner, preventing the disclosure of their true identity while sharing information.
[0052] After signing, the new partner uploads the signature result (including the information following the signature and the signature itself) to the information sharing platform, which is a group sharing area hosted by a cloud server. Here, the signature result will be made public to all other partners in the group, promoting information exchange and trust building among partners.
[0053] In step S104, other partners in the group verify the signature result using the group's public key, and confirm the validity of their own customer credit rating information and the correctness of the anonymous identity of the newly added partner based on the verification result.
[0054] In this embodiment, other collaborators in the group use the group public key to verify the received signature result. The group public key is generated by a key generation center and shared among all collaborators, used to verify the validity of any group member's signature.
[0055] It should be noted that the signature verification process in this embodiment includes checking whether the signature correctly corresponds to the customer's credit rating information and confirming whether the signer is still authorized to sign in the group within the current time period. This step relies on the verification algorithm of the group signature scheme to ensure that only legitimate and unrevoked signatures can pass verification. After verifying the validity of the signature, the partner further confirms whether the signer's anonymity is correct, that is, whether the signer is a legitimate member of the group. This is achieved through a unique anonymity verification mechanism in the verification algorithm, ensuring that even if a signature is known to be valid, the signer's specific identity cannot be traced. Once the signature result passes verification, the partner can confirm the authenticity of the customer's credit rating information and the correctness of the partner's anonymity, thereby adopting this information for its own business decisions, such as risk assessment for new customer acquisition. This not only accelerates information sharing but also enhances trust and cooperation in the broader financial ecosystem. It effectively maintains the anonymity of partners while ensuring the authenticity and integrity of information, providing a secure and efficient information sharing platform for business cooperation in financial scenarios.
[0056] Through the above implementation steps, the system supports partners in signing their own customer credit rating information using the group member's signature private key and sharing the signature result to the group. It can dynamically authorize partners to join the group for information sharing, and update the key at certain time intervals and when a partner user is added or removed from the group. This achieves dynamism and forward security, ensuring the security of the signature before the key is leaked. It solves the technical problem in related technologies where group signature schemes lack an effective verification mechanism, making it difficult to ensure the authenticity and integrity of information, which affects the trust of partners and the efficiency of cooperation.
[0057] Optionally, the group may also include cloud servers and key generation centers as partners. The method for sharing information among partners may also include: inputting security parameters to the key generation center; based on the security parameters, the key generation center uses a dynamic group key generation algorithm to generate public and private key pairs for the head office and each branch of the financial institution, and outputs the group public key.
[0058] In this embodiment's broader financial scenario, besides the direct information sharing among the head office, branches, and partners of financial institutions, a cloud server and a key generation center are also included. The cloud server is responsible for storing and distributing signed information, providing a unified information exchange platform for all partners. The key generation center is responsible for the core key management of the entire group signature scheme, including but not limited to the generation of dynamic group keys.
[0059] By inputting necessary security parameters, such as encryption algorithm type and key length, into the key generation center, the center can generate public and private key pairs for the head office and individual branches of the financial institution using a dynamic group key generation algorithm. These key pairs not only ensure secure transmission and verification of information but also, through a dynamic update mechanism, ensure that even if a key is leaked within a certain period, it will not affect the security of information in subsequent periods. The group public key is publicly available and used to verify signatures generated by any member of the group, while the group private key is securely stored by the key generation center and used for administrative operations, such as generating revocation tokens and updating keys.
[0060] In addition, the group signature-based partner information sharing method of this embodiment further includes: when it is detected that the current time period has ended, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period; or, when it is detected that there is a revocation partner in the group, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period; or, when it is detected that there is a new partner in the group, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period.
[0061] This invention supports the automatic updating of group signature private keys by financial branches and partners in the group upon detecting the end of the current time period, to adapt to the new time period. The update process involves not only generating the private key but also updating the revocation token of each partner from the previous time period to the revocation token corresponding to the current time period. This time period management mechanism is the core of the dynamic group signature scheme. It ensures forward security; even if the private key is leaked within a certain time period, signatures generated in previous time periods remain valid and cannot be traced back to the specific signer.
[0062] When a collaborator in the group changes, whether through revocation or addition, the group key is updated. This dynamism ensures the group's flexibility and security, effectively managing group signatures and anonymity even in scenarios with frequent member changes.
[0063] It should be noted that this embodiment also allocates a tracking key to the head office of the financial institution. The tracking key is used to track the information of each partner. The partner information sharing method based on group signature also includes: setting a tracking public key and a tracking private key, and sending the tracking private key to the branch of the financial institution, which then sends the tracking private key to each partner; initializing a partner registration counter, a revocation list, and a token key list. The partner registration counter is used to record the number of partners that have project cooperation with each branch of the financial institution. The signature result of the terminated partner corresponding to each revocation token in the revocation list cannot pass the identity verification. The token key list is used to store the revocation token key corresponding to the terminated partner who has added the revocation token.
[0064] To further enhance the security of the group signature scheme, this invention establishes a tracking public key and a tracking private key in the initial stage. The tracking public key is public, while the tracking private key is held by the financial institution's headquarters and used to track the identity of anonymous signers when necessary. Through this tracking mechanism, the authenticity and integrity of information can be ensured even in an anonymous environment.
[0065] This embodiment provides a partner registration counter, a revocation list, and a token key list, whose initialization is the starting point for dynamic management. The registration counter records the number of partners in the group for monitoring and management. The revocation list contains the revocation tokens of all revoked members, while the token key list stores the revocation token keys corresponding to the revocation tokens. This design ensures that only legitimate partners can share information in the group, effectively preventing partners whose services have been terminated or suspended from continuing to participate.
[0066] Optionally, the group signature-based method for sharing information among partners further includes: in the event that any partner in the group suspends or terminates its project cooperation with the financial branch, confirming that partner as the terminated partner; and having the financial branch add the terminated partner's revocation token to the revocation list and add the terminated partner's revocation token key to the token list.
[0067] In other words, when any partner in the group suspends or terminates its project cooperation with the financial branch for any reason, that partner will be considered a terminated partner. Upon confirming this status, the financial branch will add the terminated partner's revocation token to the revocation list, and simultaneously add the revocation token key to the token key list. This ensures that the terminated partner loses its ability to make valid signatures within the group. This step is the core of the revocation mechanism in the dynamic group signature scheme; it guarantees that even if a partner leaves, its previous signatures cannot be properly verified, thus maintaining the overall security and legitimacy of the group.
[0068] In another optional implementation, this embodiment also provides a recovery mechanism for partners who have lost their group identity. The partner information sharing method based on group signature further includes: after receiving an identity recovery request initiated by a terminating partner, the financial branch reviews the project cooperation information of the terminating partner; if the review result is passed, the financial branch removes the revocation token corresponding to the terminating partner from the revocation list.
[0069] Under certain circumstances, a party terminating its partnership can initiate an identity restoration request, which will be received and reviewed by the financial branch. The review process may involve reassessing the partner's business performance, credit rating, etc., to ensure the legitimacy of its identity restoration. If the review is successful, the financial branch will remove the terminated partner's revocation token from the revocation list, restoring its signing privileges in the group. This mechanism demonstrates the flexibility of a dynamic group signature scheme, allowing partners to rejoin under certain conditions without requiring complete re-registration and setting new keys.
[0070] Furthermore, this embodiment also provides a violation penalty mechanism. The collaborator information sharing method based on group signature further includes: when the verification result indicates that other collaborators have objections to the credit rating information of the newly added collaborator's own customers, the head office of the financial institution in the group finds the identity information of the objecting collaborator by tracking the private key; the head office of the financial institution outputs a penalty factor to the collaborator that uploaded its own customer credit rating information, and the penalty factor is used to handle the violation.
[0071] This embodiment provides a method for handling objections from other partners in a group regarding credit rating information of newly added partners' own customers. When the verification results show that a partner has questioned the authenticity or completeness of the information, the head office of the financial institution can use the tracking private key to find the real identity of the objecting partner for further investigation. This tracking mechanism provides a means of tracking violations while ensuring anonymity.
[0072] Once a violation is confirmed, the head office of the financial institution will assign a penalty factor to the partner who uploaded the violation information. The penalty factor is a quantitative indicator used to measure the severity of the violation and determine the corresponding punitive measures. This may include, but is not limited to, temporarily or permanently revoking the partner's group signature privileges, removing them from the group, or imposing financial penalties. In this way, the present invention not only achieves anonymous information sharing but also establishes an effective regulatory mechanism to maintain the authenticity of group information and the healthy operation of the collaborative ecosystem.
[0073] The following describes in detail another optional implementation method.
[0074] This invention provides a method for sharing information among collaborators based on dynamic group signatures. Figure 2 This is a schematic diagram of a forward-secure dynamic group signature system according to an embodiment of the present invention, such as... Figure 2 As shown, the system includes the bank's head office 201, partner users 202, and branch offices 203. Of course, in addition to the aforementioned units, the group signature scheme system may also include a cloud server 204 and a key generation center 205.
[0075] Among them, the key generation center 205 generates public and private key pairs for the bank's head office 201 and branch offices 203 respectively, and outputs the group public key.
[0076] Branch institution 203 interacts with partner user 202. Branch institution 203 sets identity information and identity certificate for partner user 202, generates signature private key for partner user 202, calculates revocation token and token certificate for time period t, and finally updates the registration list.
[0077] Partner user 202 can sign their own customer credit rating information M using their private key, share it, and upload it to cloud server 204. Other partner users can verify the validity of the information by checking the signature Σ using the group public key, which is used for new customers to obtain risk ratings. When a new partner user joins the group, branch office 203 generates a group member signing private key for them. When a partner's project cooperation period expires or the partner chooses to suspend or terminate the service according to their own needs, branch office 203 can add the partner's revocation token and revocation token key to the revocation list and token list, respectively. Signatures made by the revoked partner using the original signing private key will fail verification, ensuring the legitimacy of the group. When the partner needs to restore their legitimate identity, they only need to remove their revocation token from the revocation list. This also means that a partner can be revoked in time period t1 and regain legitimate identity in time period t2 (t1>t2) without needing to reset their public and private keys. When partners dispute shared information, the bank's head office can trace the key to identify the signer and impose appropriate penalties on partners who violate regulations by uploading shared information, thus ensuring the authenticity of the shared information. Branch office 203 and partner user 202 update their keys at regular intervals and when partner users are added or removed from groups, achieving dynamic and forward security to ensure the security of signatures before key leakage.
[0078] The forward-secure dynamic group signature scheme includes the following eight algorithms: 01. Initialization algorithm: Inputs security parameters and outputs system parameters; 02. Group key generation algorithm: Generates the public-private key pair for the group administrator and the public-private key pair for the tracking administrator; the administrator generates a revocation list and a token list for group members; 03. User joining protocol: Generates the user's private key, revocation token, and certificate; 04. Revocation algorithm: Revoks a group member's membership and updates the revocation token list and revocation list; 05. Key update algorithm: Updates the group member's private key, revocation token, and revocation list; 06. Signature algorithm: Inputs the group public key, group member's private key, and message, and outputs a signature of the message; Verification algorithm: 07. Inputs the group public key, revocation list, time period, message, and signature, and verifies whether the signer of the signature has been revoked and the validity of the signature; 08. Tracking algorithm: Outputs the identity of the group member who signed the message through the tracking key. The following describes this embodiment in conjunction with these eight algorithms.
[0079] The forward-secure dynamic group signature scheme proposed in this invention includes 8 algorithms, assuming the expected maximum number of group members is N=2. L The longest time interval is T=2. d , where L, d∈Z + The specific algorithm is as follows.
[0080] Initialization algorithm GSetup(1) λ ): Input security parameter 1 λ Choose parameters n = O(λ), prime number q = poly(n), k = logq, m = 2nk, m′ = 2(n+L)k. For i∈{0,1,...,d}, choose Gaussian parameters. Output system common parameters
[0081] pp={λ,n,m,n′,q,L,d,s0,...,s d}
[0082] Group Key Generation Algorithm GKeyGen GM,TM (pp): The algorithm generates public and private key pairs for the branch GM and the head office TM, and outputs the group public key gpk.
[0083] GKeyGen GM :
[0084] 1) Run the TrapGen algorithm to obtain the matrix. and its trapdoor base Set the branch's public key mpk=A0 and private key msk=S0.
[0085] 2) Uniformly and randomly select vector e, matrices A1, A2, B, and for b∈{0,1} and j∈[d], uniformly and randomly select matrix B.
[0086] GKeyGen TM :
[0087] 1) Uniformly random selection of matrix For i∈{1,2}, a matrix S is uniformly selected. i ←{0,1} L×n E i ←{0,1} L×m′ .
[0088] 2) Calculate matrices D1 = S1·D0 + E1 and D2 = S2·D0 + E2. Set the tracking public key tpk = (D0, D1, D2) and the tracking private key tsk = S1, and send tsk to the branch office GM.
[0089] Finally, the branch office GM initialized the user registration counter c=0 and the cancellation list... Token List And output the group public key
[0090]
[0091] User Join Agreement <GUJoin(token) sk ,t),GIssue(gpk,msk,t)>:Users interact with branch offices through (pupk,pusk) registered in PKI.
[0092] 1) Users are selected uniformly and randomly. Then use pusk to perform a regular digital signature on it (SIG). i =Sig pusk (x i ), and (sig i ,x i Send to the branch office GM.
[0093] 2) The branch office GM received (sig i ,x i ) Verify x i Check if the user has already registered, then verify the signature validity using the corresponding pupk. If verification fails, the joining process terminates; otherwise, continue with the following steps. First, the group administrator (GM) sets the user's identity ID:=c∈[0,2... L -1], then generate the identity certificate cert index =Sign(msk,id) and update c:=c+1. Then determine the set of nodes representing time. For node z∈Nodes (0→T-1) If z = ⊥, then let usk[i][z] = ⊥. Otherwise, use d. z To represent the length of z (d)z <d), and calculate the matrix
[0094]
[0095] If d z = d, then generate vectors
[0096] v i,z ←SampleD(ExtBasis(S0,A i,z ),e,s d ),
[0097] and set usk0[i][z] = v i,z ;
[0098] If 1 ≤ d z < d, then generate the trapdoor basis matrix through the basis extension algorithm and the basis randomization algorithm
[0099]
[0100] and set usk0[i][z] = S i,z .
[0101] The signature private key of the group member is usk0[i] = {usk0[i][z], z ∈ Nodes (0→T-1) , id, x i}. Then update usk0[i] to usk t [i] through the key update algorithm KeyUpdate. Calculate the revocation token token i,t = A i,t ·x i , where A i,t represents A z when d i,z = d, and then generate the token certificate cert token = Sign(msk, token i,t ). Finally, the branch institution GM sends the group member certificate cert i = (cert index , cert token , id, token i,t ) to the group member and updates the registration list.
[0102] Revocation algorithm GRevoke(gpk, RL t(TL, t): The branch office GM updates and publishes the revocation list RL in each time period. For a group member to be revoked, the branch office GM will use the group member's revocation token in time period t. i,t Add to the undo list RL, and its x i Add it to the token list TL. Finally, perform the update operation RL. t =RL t ∪token i,t TL t =TL t ∪x i RL will be released later. t .
[0103] Key update algorithm KeyUpdate(gpk, usk) t [i], token t RL t TL t , t+1): Resolve the group member's private key usk t [i] = {usk t [i][z], z∈Nodes (t→T-1) id, x i}, and determine the node set Nodes (t+1→T-1) .
[0104] For z′∈Nodes (t+1→T-1 If z′=⊥, then let usk t+1 [i][z′] = ⊥. Otherwise, there exists a z ∈ Nodes (t→T-1) It can be used as a prefix for z′, i.e., z′=z||h. There are two possible cases.
[0105] 1) If z′=z, that is, h is empty, then usk t+1 [i][z′]=usk t+1 [i][z].
[0106] 2) If z′=z||h, that is, h is not empty, then there are the following two ways:
[0107] If d z′ =d, then the generated vector v i,z′
[0108] v i,z′ ←SampleD(ExtBasis(S i,z A i,z′ ), e, s d ),
[0109] And set usk t+1 [i][z′]=v i,z′ ;
[0110] If d z′ If <d, then the trapdoor basis matrix S is generated. i,z′
[0111]
[0112] And set usk t+1 [i][z′]=S i,z′ .
[0113] Finally, the updated group member private key is: usk t+1 [i] = {usk t [i][z′],z′∈Nodes (t+1→T-1) id, x i}
[0114] At the same time, all revocation tokens i,t Update to token i,t+1 For x i ∈TL t The group administrator calculates the token. i,t+1 =A i,z′ ·x i , where d z′ =d. Finally, undo the list RL. t Updated to RL t+1 And published.
[0115] Signature algorithm GSign(gpk, usk) t [i], M, t): Based on the node set Nodes (t→T-1) One of z∈Nodes can be found. (t→T-1) Make z = bin(t), and usk t [i][z]=v i,z Group members use the signing private key usk t [i]={v i,z id, x i The message M is signed using the following steps.
[0116] 1) For j∈{1,2}, uniformly and randomly select vector r j ←{0, 1} m′ ,e0←χ m e j,1 ←{0, 1} n e j,2 ←{0, 1} L and calculate
[0117]
[0118] 2) Generate a relation about ξ=(v i,z x i r1, r2, e 1,1 e 1,2 e 2,1 e 2,2 Non-interactive zero-knowledge proofs (NIZKAoK) satisfying the following conditions (id) gs :
[0119] i.(c 1,1 c 1,2 ) and (c 2,1 c 2,2 All of these are valid ciphertexts of the encrypted identity ID;
[0120] ii.A i,z ·v i,z =e mod q and ||v i,z || ∞ ≤β;
[0121] iii.w=B T ·A i,z ·x i +e0 mod q.
[0122] Condition i can generate the corresponding zero-knowledge proof. Let matrix A... i,z Expressed as [A id |A z Then equation A i,z ·v i,z =e can be converted to A id ·v1+A z The form ·v2=e. To ensure the anonymity of group members, A id It cannot be directly exposed. Therefore, this application will disclose A. id =[A0|A1+idA2] converted to Make A in the original equation id v1 can be converted to Therefore, conditions ii and iii can generate corresponding zero-knowledge proofs. These three conditions are then integrated into a form such as the zero-knowledge proof protocol. The equation, in which and It is public. This is a secret value. Then, the protocol is repeated. This allows it to reach a negligible plausibility error, and a non-interactive zero-knowledge proof is obtained through the Fiat-Shamir transformation function. in and The signature is calculated using the commitment scheme aCommit. Finally, the signature is output.
[0123] ∑=(Π gs w, c 1,1 c 1,2 c 2,1 c 2,2 ).
[0124] Verification algorithm GVerify(gpk,RL) t ,M,∑,t):The verifier verifies the signature according to the following steps.
[0125] 1) Verify zero-knowledge proof Π using a verification algorithm based on a zero-knowledge proof protocol. gs The validity of the condition is checked. If any one of the conditions is not met, 0 is returned.
[0126] 2) View the undo list RL t For any token j,t ∈RL t Calculate w′=wB T ·token i,t =B T ·(token i,t -token j,t If token i,t =token j,t And ||w′|| ∞ If the value is less than or equal to β, the signer has been revoked, and the system returns 0; otherwise, it returns 1.
[0127] The tracking algorithm G0pen(gpk, tsk, M, ∑) is as follows: For a valid signature ∑, the bank's head office TM uses the tracking private key tsk to track down the signer's identity through the following steps.
[0128] 1) Use the tracking private key tsk = S1 to decrypt and obtain the string b = bin(id) ∈ {0, 1} L :calculate
[0129] 2) Calculate identity It returns an integer and the id.
[0130] Compared to existing solutions, the forward-secure dynamic group signature scheme proposed in this embodiment offers higher security. While achieving forward security and dynamism, the lengths of the group public key, group member private keys, and group signature are all optimized. Furthermore, the size of group member private keys is independent of the number of members, making it more suitable for expanding the number of partners. Financial and banking institutions can use forward-secure dynamic group signatures for information sharing, addressing the shortcomings of existing solutions in protecting partner privacy, monitoring the authenticity of shared information, and improving efficiency.
[0131] The following is a detailed description with reference to another embodiment.
[0132] Example 2
[0133] The collaborator information sharing device based on group signature provided in this embodiment includes multiple implementation units, each of which corresponds to a specific implementation step in Embodiment 1 above.
[0134] According to another aspect of this application, a group signature-based collaborator information sharing device is provided, which is applied to a group sharing system that deploys multiple collaborators. The collaborators included in the group include at least: a financial head office, multiple financial branches, and collaborators that have business cooperation with the financial branches.
[0135] Figure 3 This is a schematic diagram of an optional group signature-based collaborator information sharing device according to an embodiment of the present invention, such as... Figure 3 As shown, the collaborator information sharing device based on group signature may include: a collaborator private key generation unit 31, a registration list update unit 32, a signature unit 33, and a signature verification unit 34.
[0136] Among them, the partner private key generation unit 31 is used to respond to the group joining request initiated by the new partner. The financial branch sets the identity identifier and identity certificate for the new partner based on the partner information, and generates the group member signature private key of the new partner.
[0137] Registration list update unit 32 is used by financial branch institutions to calculate the revocation token and token certificate corresponding to the current time period based on the identity identifier and identity certificate of the newly added partner, and update the group member registration list.
[0138] Signature unit 33 is used by newly added partners to sign their own customer credit rating information using the group member's signature private key, and to share the signature result with the group.
[0139] The signature verification unit 34 is used to verify the signature result by other partners in the group using the group's public key, and to confirm the validity of the credit rating information of its own customers and the correctness of the anonymous identity of the newly added partners based on the verification result.
[0140] The above-described schematic diagram of the partner information sharing device based on group signature shows that, in response to a group joining request initiated by a new partner, the partner private key generation unit 31 sets an identity identifier and identity certificate for the new partner based on the partner information, and generates a group member signature private key for the new partner. Through the registration list update unit 32, the financial branch calculates the revocation token and token certificate corresponding to the current time period based on the identity identifier and identity certificate of the new partner, and updates the group member registration list. Through the signature unit 33, the new partner signs its own customer credit rating information using the group member signature private key and shares the signature result to the group. Through the signature verification unit 34, other partners in the group verify the signature result using the group's public key, and confirm the validity of the own customer credit rating information and the correctness of the new partner's anonymous identity based on the verification result. In this embodiment, the system supports partners in signing their own customer credit rating information using the group member's signature private key and sharing the signature result to the group. It can dynamically authorize partners to join the group for information sharing, and update the key at certain time intervals and when a partner user is added or removed from the group. This achieves dynamism and forward security, ensuring the security of the signature before the key is leaked. It solves the problem that group signature schemes in related technologies lack an effective verification mechanism, making it difficult to ensure the authenticity and integrity of information, which affects the trust of partners and the efficiency of cooperation.
[0141] Optionally, the group may also include cloud servers and key generation centers, virtual devices for sharing information among partners, and: a parameter input unit for inputting security parameters to the key generation center; and a dynamic key generation unit for generating dynamic public and private key pairs for the head office and branches of the financial institution based on the security parameters using a dynamic group key generation algorithm, and outputting the group public key.
[0142] Optionally, the virtual device for sharing information among partners further includes: a time period detection unit, used to trigger a group signature private key update when the current time period has ended; a group signature private key update unit, used to update the group signature private key of the financial branch and each partner in the group according to the signal from the time period detection unit; a revocation token update unit, used to update the revocation tokens corresponding to each partner in the previous time period to the revocation tokens corresponding to the current time period; and a dynamic partner detection unit, used to notify the group signature private key update unit and the revocation token update unit to update when a revocation or addition of a partner is detected in the group.
[0143] Optionally, the virtual device for sharing information among partners further includes: a tracking key setting unit for setting a tracking public key and a tracking private key, and sending the tracking private key to the financial branch; a tracking key distribution unit for the financial branch to send the tracking public key to each partner; and a dynamic management initialization unit for initializing a partner registration counter, a revocation list, and a token key list, wherein the partner registration counter is used to record in real time the number of partners with whom the financial branch has project cooperation, the revocation list is used to store revocation tokens of partners whose signatures cannot be verified, and the token key list is used to store the revocation token keys corresponding to the terminated partners who have added revocation tokens.
[0144] Optionally, the virtual device for sharing information among partners further includes: a project cooperation status detection unit, used to confirm that a partner is a terminating partner when any partner in the group suspends or terminates its project cooperation with a financial branch; and a revocation management unit, used to add the revocation token of the terminating partner to the revocation list and add the revocation token key of the terminating partner to the token key list after the project cooperation status detection unit confirms the terminating partner, so as to ensure the unverifiable nature of the terminating partner's signature.
[0145] Optionally, the virtual device for sharing information among partners further includes: an identity restoration request receiving unit, used to receive an identity restoration request initiated by a terminating partner; a project cooperation information review unit, used to review the project cooperation information of the terminating partner after receiving the identity restoration request; and an identity restoration processing unit, used to remove the revocation token corresponding to the terminating partner from the revocation list if the review result is satisfactory.
[0146] Optionally, the virtual device for sharing information among partners also includes: a violation detection unit, used to trigger a tracking mechanism when the verification result indicates that other partners have objections to the credit rating information of the newly added partner's own customers; a tracking unit, used by the financial head office to find the identity information of the objecting partner through the tracking private key; and a penalty processing unit, used by the financial head office to output a penalty factor to the partner that uploaded its own customer credit rating information based on the result of the tracking unit, and the penalty factor is used to process the violation.
[0147] The aforementioned information sharing device for partners based on group signatures may also include a processor and a memory. The aforementioned partner private key generation unit 31, registration list update unit 32, signature unit 33, signature verification unit 34, etc., are all stored in the memory as program units, and the processor executes the aforementioned program units stored in the memory to realize the corresponding functions.
[0148] The aforementioned processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and adjusting kernel parameters enables a collaborative information-sharing method based on dynamic group signatures.
[0149] The aforementioned memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0150] Example 3
[0151] Embodiments of this application may provide an electronic device. Figure 4 This is a hardware structure block diagram of an electronic device (or mobile device) that implements a group signature-based collaborator information sharing method according to an embodiment of the present invention. Figure 4 As shown, the electronic device may include: one or more ( Figure 4 Only one of the following is shown: processor 402, memory 404, memory controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module and display.
[0152] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the methods and apparatus in the embodiments of this application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby implementing the above-described methods. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0153] The processor can access information and applications stored in memory via a transmission device to execute the following steps: In response to a new partner's request to join a group, the financial branch sets an identity identifier and identity certificate for the new partner based on the partner's information, and generates a group member signature private key for the new partner; the financial branch calculates a revocation token and token certificate corresponding to the current time period based on the new partner's identity identifier and identity certificate, and updates the group member registration list; the new partner signs its own customer credit rating information using the group member signature private key and shares the signature result with the group; other partners in the group verify the signature result using the group's public key, and confirm the validity of their own customer credit rating information and the correctness of the new partner's anonymous identity based on the verification result.
[0154] The processor can also call the information and application programs stored in the memory through the transmission device to perform the following steps: input security parameters to the key generation center; based on the security parameters, the key generation center uses a dynamic group key generation algorithm to generate public and private key pairs for the head office and each branch of the financial institution respectively, and outputs the group public key.
[0155] The processor can also invoke information and applications stored in the memory via the transmission device to perform the following steps: If the current time period has ended, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period; or, if a partner in the group is detected to be revoking, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period; or, if a new partner is detected in the group, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period.
[0156] The processor can also invoke information and applications stored in the memory via a transmission device to perform the following steps: Optionally, the collaborator information sharing method based on group signatures further includes: setting a tracking public key and a tracking private key, and sending the tracking private key to the financial branch, which then sends the tracking private key to each collaborator; initializing a collaborator registration counter, a revocation list, and a token key list, wherein the collaborator registration counter is used to record the number of collaborators that have project cooperation with each financial branch, the signature result of the terminated collaborator corresponding to each revocation token in the revocation list cannot be authenticated, and the token key list is used to store the revocation token key corresponding to the terminated collaborator that has been added to the revocation token.
[0157] The processor can also access information and applications stored in the memory via a transmission device to perform the following steps: in the event that any partner in the group suspends or terminates its project cooperation with the financial branch, the partner is identified as the terminated partner; the financial branch adds the terminated partner's revocation token to the revocation list and adds the terminated partner's revocation token key to the token list.
[0158] The processor can also access information and applications stored in the memory via a transmission device to perform the following steps: upon receiving an identity restoration request initiated by the terminating partner, the financial branch reviews the project cooperation information of the terminating partner; if the review is successful, the financial branch removes the revocation token corresponding to the terminating partner from the revocation list.
[0159] The processor can also access information and applications stored in the memory via the transmission device to perform the following steps: if the verification result indicates that other partners have objections to the credit rating information of the newly added partner's own customers, the head office of the financial institution in the group will find the identity information of the objecting partner by tracing the private key; the head office of the financial institution will output a penalty factor to the partner that uploaded its own customer credit rating information, and the penalty factor will be used to handle the violation.
[0160] The system supports partners in using group member signature private keys to sign their own customer credit rating information and share the signature results to the group. It can dynamically authorize partners to join the group for information sharing, and update the key at certain time intervals and when partners are added or removed from the group. This achieves dynamism and forward security, ensuring the security of the signature before the key is leaked. It solves the problem that group signature schemes in related technologies lack effective verification mechanisms, making it difficult to ensure the authenticity and integrity of information, which affects the trust of partners and the efficiency of cooperation.
[0161] Those skilled in the art will understand that Figure 4 The structure shown is for illustrative purposes only. Electronic devices can also be smartphones, tablets, handheld computers, mobile internet devices (MIDs), PADs, and other terminal devices. Figure 4 This does not limit the structure of the aforementioned electronic device. For example, electronic devices may also include components that are more... Figure 4 The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 4 The different configurations shown.
[0162] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0163] Example 4
[0164] Embodiments of this application also provide a storage medium. Optionally, in this embodiment, the storage medium can be used to store the program code executed by the group signature-based collaborator information sharing method provided in Embodiment 1.
[0165] According to another aspect of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored computer program, wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to execute any of the group signature-based collaborator information sharing methods in Embodiment 1 above.
[0166] Optionally, in this embodiment, the storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.
[0167] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the group signature-based collaborator information sharing method described in various embodiments of this application.
[0168] This application also provides a computer program product, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the group signature-based collaborator information sharing method described in various embodiments of this application.
[0169] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0170] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0171] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0172] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0173] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0174] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0175] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for sharing information among collaborators based on group signatures, characterized in that, A group-sharing system for deploying multiple collaborating entities is provided, wherein the collaborating entities in the group include at least: a financial head office, multiple financial branches, and collaborators with business relationships with the financial branches. The collaborator information sharing method based on group signature includes: In response to a new partner's request to join a group, the financial branch sets an identity identifier and identity certificate for the new partner based on the partner's information, and generates a group member signature private key for the new partner. The financial branch calculates the revocation token and token certificate corresponding to the current time period based on the identity identifier and identity certificate of the newly added partner, and updates the group member registration list accordingly; The newly added partner uses the group member's signature private key to sign its own customer credit rating information and shares the signature result to the group; Other partners in the group verify the signature result using the group's public key, and confirm the validity of the proprietary customer credit rating information and the correctness of the anonymous identity of the newly added partner based on the verification result. Specifically, based on the identity identifier and identity certificate of the newly added partner, the revocation token and token certificate corresponding to the current time period are calculated, and the group member registration list is updated, including: Generate public and private keys for financial branch institutions based on the TrapGen algorithm; Obtain the signature of the newly added partner, which is obtained by the newly added partner signing a randomly selected vector using its own private key; Verify the signature of the newly added partner. If the verification is successful, set an identity identifier for the newly added partner based on the partner registration counter. The identity identifier is signed using the private key of the financial branch, an identity certificate is generated, and the registration counter is updated. Determine the set of nodes representing the time period; The matrix for determining the current time period is based on the node set; The revocation token for the current time period is calculated based on the randomly selected vector and the matrix. Generate a token certificate for the current time period based on the revocation token for the current time period and the private key of the financial branch. During the current time period, the revocation token is added to the revocation list, and the randomly selected vector is added to the token list.
2. The method for sharing information among partners according to claim 1, characterized in that, The group also includes cloud servers and key generation centers as partners, and the method for sharing information among partners further includes: Input security parameters into the key generation center; Based on the security parameters, the key generation center uses a dynamic group key generation algorithm to generate public and private key pairs for the head office and each branch of the financial institution, and outputs the group public key.
3. The method for sharing information among partners according to claim 1, characterized in that, Also includes: Upon detecting that the current time period has ended, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period. or, If a revocation partner is detected in the group, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period. or, If a new partner is detected in the group, the financial branch and each partner in the group update the group signature private key and update the revocation token corresponding to each partner in the previous time period to the revocation token corresponding to the current time period.
4. The method for sharing information among partners according to claim 1, characterized in that, Also includes: Set up a tracking public key and a tracking private key, and send the tracking private key to the financial branch, which then sends the tracking private key to each partner. Initialize a partner registration counter, a revocation list, and a token key list. The partner registration counter is used to record the number of partners that have project cooperation with each of the financial branches. The signature result of the terminated partner corresponding to each revocation token in the revocation list cannot pass the identity verification. The token key list is used to store the revocation token key corresponding to the terminated partner added to the revocation token.
5. The method for sharing information among partners according to claim 4, characterized in that, Also includes: If any partner in the group suspends or terminates its project cooperation with the financial branch, that partner will be identified as the terminated partner. The financial branch will add the revocation token of the terminating partner to the revocation list and add the revocation token key of the terminating partner to the token list.
6. The method for sharing information among partners according to claim 4, characterized in that, Also includes: Upon receiving the identity restoration request initiated by the party terminating the partnership, the financial branch shall review the project cooperation information of the party terminating the partnership. If the review is approved, the financial branch will remove the revocation token corresponding to the terminated partner from the revocation list.
7. The method for sharing information among partners according to claim 4, characterized in that, Also includes: If the verification result indicates that other partners have objections to the credit rating information of the newly added partner's own customers, the head office of the financial institution in the group can find the identity information of the objecting partner by tracing the private key; The head office of the financial institution outputs penalty factors to the partners who upload the credit rating information of their own customers. These penalty factors are used to handle violations.
8. A collaborative information sharing device based on group signature, characterized in that, A group-sharing system for deploying multiple partners is provided, wherein the partners included in the group at least include: a financial head office, multiple financial branches, and partners with business cooperation with the financial branches. The partner information sharing device based on group signature includes: The partner private key generation unit is used to respond to the group joining request initiated by the new partner. The financial branch sets the identity identifier and identity certificate for the new partner based on the partner information, and generates the group member signature private key of the new partner. The registration list update unit is used by the financial branch to calculate the revocation token and token certificate corresponding to the current time period based on the identity identifier and identity certificate of the newly added partner, and update the group member registration list. The signing unit is used by the newly added partner to sign its own customer credit rating information using the group member's signing private key, and to share the signing result to the group; The signature verification unit is used to verify the signature result by other partners in the group using the group's public key, and to confirm the validity of the proprietary customer credit rating information and the correctness of the anonymous identity of the newly added partner based on the verification result; The registration list update unit includes: generating a public key and a private key for a financial branch based on the TrapGen algorithm; obtaining a new partner signature, which is obtained by the new partner signing a randomly selected vector using its own private key; verifying the new partner signature, and if the verification is successful, setting an identity identifier for the new partner based on a partner registration counter; signing the identity identifier based on the financial branch's private key to generate an identity certificate and update the registration counter; determining a node set representing a time period; determining a matrix for the current time period based on the node set; calculating a revocation token for the current time period based on the randomly selected vector and the matrix; generating a token certificate for the current time period based on the revocation token and the financial branch's private key; adding the revocation token to the revocation list and the randomly selected vector to the token list in the current time period.
9. An electronic device, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, executes the collaborator information sharing method based on group signatures as described in any one of claims 1 to 7.
10. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed by the processor, they implement the steps of the collaborator information sharing method based on group signature as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Group signature system, device, and program
CN101978651A
Group signature identifier issuing method based on SM2 digital signature algorithm
CN109600233A