Group signature method supporting distributed tracking and linking
By adopting distributed tracking and linking methods in group signature schemes and combining cryptography technology, the problem of large computing and communication overhead in the existing technology is solved, and the flexible balance of user privacy protection and supervision needs is achieved, and the security and reliability of the system are enhanced.
Patent Information
- Application Number
- CN202510110756.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-06
AI Technical Summary
When implementing distributed tracking and linking, the existing group signature scheme has high computing and communication overhead, and it is difficult to meet user privacy protection and supervision needs at the same time.
A group signature method that supports distributed tracking and linking is adopted, and distributed tracking agencies are used to achieve distributed tracking and linking through the steps of generating system public parameters, generating key pairs from various rights institutions, user registration, signature generation and verification, interaction between regulatory agencies and linking agencies, and distributed tracking agencies tracking user identities, combined with cryptography technologies such as bilinear mapping, ElGamal encryption and zero-knowledge proofs.
It enhances privacy protection and system security, reduces computing and communication overhead, improves the system's aggressiveness and reliability, and adapts to large-scale user groups and high-frequency signature operations.
Smart Images

Figure CN119945685A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security technology, and in particular relates to a group signature method supporting distributed tracing and linking. Background Art
[0002] Group signature is an important cryptographic technology, first proposed by Chaum and van Heyst in 1991, for anonymous signature within a group. Its core idea is to allow any member of a group to sign in the name of the group, and the outside world cannot distinguish the specific source of the signature, but the authorized party can reveal the true identity of the signer when necessary. In many application scenarios, it is necessary to provide anonymity to protect privacy and to regulate malicious behavior. Electronic voting systems and private communications need to hide the identity of users; in financial transactions, e-government and other scenarios, it is required to track the subject of the behavior under legal authorization to prevent the abuse of anonymity. Group signature is proposed to solve this contradiction between privacy and regulation. It combines digital signature and anonymity technology and has become an important research direction in the field of cryptography.
[0003] Traceability and linkability are one of the hot topics in the research of group signature schemes in recent years. These features are designed to solve the problem of anonymity abuse. For example, the traceable group signature proposed by Tsang et al. allows the authorized party to reveal the identity of the signer under certain conditions without affecting the anonymity of other group members. In addition, the linkable group signature proposed by Fujisaki and Suzuki is able to detect repeated signatures of the same member, thereby preventing double-spending attacks. However, a common problem of these schemes is that they introduce high computational and communication overheads, especially in large groups.
[0004] Classic group signature schemes, such as the short group signature proposed by Boneh et al., are known for their fixed signature length and efficient verification. However, these schemes usually rely on centralized group administrators to complete key generation and revocation management. The centralized architecture brings single point failure problems and increases the trust assumption of administrators. With the rise of the demand for decentralized systems, many researchers have begun to explore group signature schemes that do not rely on centralized administrators. Blockchain-based group signature schemes are an important direction. For example, the scheme proposed by Guo et al. uses blockchain as a public ledger and uses smart contracts to achieve decentralized key distribution and revocation. These schemes effectively solve the trust problem in traditional schemes, but due to the inherent computational complexity of blockchain, they often face the challenge of low efficiency. In addition, many schemes based on distributed systems use multi-party computing (MPC) technology, but its implementation complexity is relatively high.
[0005] Recently, Garms and Lehmann proposed the CLS scheme, which extends selective linkability to group signatures. The CLS scheme can collect user signatures in an authenticated manner and supports flexible and privacy-friendly access to data sets. Signature linkability is established in an inadvertent and non-transitive way. The linking process involves a transformer to complete the signature linking of a specific subset of data. However, the verifier cannot detect the correctness of the signature linking, and the CLS scheme does not support the tracking of malicious user identities. However, when users have serious malicious behaviors, it is necessary to reveal the identities of malicious users. On this basis, Garms and Lehmann proposed a selectively linkable group signature scheme, which strengthens security (such as protection against unauthorized linking attacks) and maintains the verifiability of signatures under complex security models. Subsequently, Diaz and Lehmann further extended this concept and proposed a group signature scheme with user control and sequential linkability. The scheme allows signers to dynamically determine the linkability of their signatures and supports the linkability of signatures in chronological order, which is of great significance in complex permission management systems and behavior auditing. However, none of them considers linkability and traceability at the same time, which remains an open challenge.
[0006] Group signatures allow multiple members to sign on behalf of the group without revealing the identity of the specific signer. However, group signatures usually require a central agency to manage member identities and permissions to ensure the legitimacy of participants. If the central agency makes mistakes, is attacked, or abuses its power, it may undermine the security and transparency of the entire system. Summary of the invention
[0007] The technical problem to be solved by the present invention is to overcome the shortcomings of the prior art and provide a group signature method that supports distributed tracking and linking, which has a reasonable design and achieves a flexible balance between protecting user privacy and meeting regulatory requirements.
[0008] The technical solution adopted to solve the above technical problems is: a group signature method supporting distributed tracking and linking, including the following steps:
[0009] Step 1. Generate system public parameters
[0010] The system selects security parameters and generates a Type-3 bilinear mapping group G = (q, G 1 ,G 2 ,G T ,g 1 ,g 2 ,e), where,G 1 , G T , G 2 is a cyclic group of order q, G T is the target group, and randomly selects a generator g1 ∈G 1 and g 2 ∈G 2 , randomly select elements Randomly select collision-resistant hash functions Generate system public parameters
[0011] Step 2. Each authority generates its own key pair
[0012] The registration authority randomly selects the secret value As a private key, is the integer multiplication group modulo p, computing the public key Output (isk, ipk) as the key pair of the registration authority;
[0013] The regulator randomly selects the secret value As the private key, calculate the public key rpk = g rsk , output (rsk, rpk) as the key pair of the regulator;
[0014] The linking mechanism randomly selects the secret value As the private key, calculate the public key lpk = h lsk , output (lsk,lpk) as the key pair of the linking mechanism;
[0015] The distributed tracking agency generates a public key, including the following steps:
[0016] Step S1. The system sets the number of trackers n and the threshold value t for successfully tracking the signer;
[0017] Step S2. Each tracking member DT i Randomly choose a secret value Construct a t-1 degree polynomial f i (x) = s i +a i1 x+a i2 x 2 +...+a i(t-1) x t-1 , a i1 ,a i2 ...a i(t-1) is a randomly selected coefficient that generates the public coefficient U i0 , U i1 , ..., U i(t-1) And broadcast to other tracking members, among which,
[0018] Step S3. Each tracking member DT i DT for other tracking members j Calculate the sub-share Sij =f i (j) and transfer the sub-share S ij Send to tracking member DT j , where j∈{1,...,n};
[0019] Step S4. Tracking member DT j Received sub-shares 1j ,...,S nj}, according to equation Verify the validity. If the equation holds, the sub-share is valid.
[0020] Step S4. All tracking members’ sub-shares are verified, and each tracking member DT j Calculate your own private key
[0021] Step S5. Calculate and publish the public key of the distributed tracking agency
[0022] The system sets the group public key gpk = (ipk, rpk, lpk, DTPK);
[0023] Step 3. User Registration
[0024] Step 3.1. The user with identifier Uid randomly selects his own secret value Generate intermediate value H←h 1 y And zero-knowledge proof π H , send a registration request to the registration authority, the registration request includes the identifier Uid, the intermediate value H, and the zero-knowledge proof π H ;
[0025] Step 3.2. After receiving the registration request from the user Uid, the registration agency verifies the legitimacy of the zero-knowledge proof and generates an intermediate value s = H 0 (Uid), and randomly select Generate group certificate A, the registration authority sends group certificate A and parameter x to user Uid, and stores user Uid registration information in the local registry for subsequent identity tracking;
[0026] Step 3.3. After receiving the group certificate A and parameter x, user Uid generates an intermediate value s' = H 0 (Uid), verify the validity of group certificate A. If the verification is successful, s' is equal to s generated by the registration authority. User Uid sets his own group member private key gsk[Uid]=(A,x,y,s);
[0027] Step 4. The user generates a signature for message m
[0028] User chooses a random number Generate ciphertext D respectively 1 and D 2 and link tag Tag = (T 1 ,T 2 ,T 3 ),in, D 2 =A(DTPK) α ,
[0029] The user uses the proof of knowledge signature SPK to generate proof π σ , prove the correctness of the ciphertext and link tag, and output the signature σ=(D 1 ,D 2 ,π σ ) and link tag Tag;
[0030] Step 5. User signature verification
[0031] The receiver with the group public key parses the signature σ and verifies the proof π σ The validity of the signature is verified and the signature is valid;
[0032] Step 6. The regulator interacts with the linking agency to link multiple signatures to the same user
[0033] The regulator will send a set of signed link tags (Tag 1 ,...,Tag i ,...,Tag n ) is sent to the linking organization, where Tag i =(T 1i ,T 2i ,T 3i );
[0034] The linking mechanism randomly selects an integer For the i-th link label, i=1,...,n, randomly select an integer Calculate the converted link tag CTag i ={CT 1i ,CT 2i},in, The private key of the linking organization is used to tag T 3i Adjustment, It introduces randomness to ensure that the same signature cannot be linked to the previous transformation. It is to randomize the original tag so that the regulator can correctly decrypt it. It introduces additional randomness to ensure unlinkability;
[0035] The link agency will convert all converted link tags (CTag 1 , ..., CTag i , ..., CTag n ) sent to the supervisory authority;
[0036] After receiving the converted link tags, the regulator decrypts them and maps all link tags belonging to the same user in the same conversion batch into a consistent form, thereby achieving linking;
[0037] Step 7. Distributed tracking mechanism tracks user identity
[0038] Each tracker DT involved in the tracking process in the distributed tracking mechanism i Each of them generates a tracking share for the signature σ being tracked i , and will track share i sent to regulatory authorities;
[0039] Regulators use all tracking shares i} i∈[1,n] , extract the signer’s group certificate A from the signature σ, search the registry, and determine the signer’s identity.
[0040] As a preferred technical solution, in step 3.2, the group certificate A is: The registration information reg[Uid]=(s,x,H,A,π H ).
[0041] As a preferred technical solution, the tracking share share i for: is the tracking proof, used to verify the tracking value θ i correctness.
[0042] As a preferred technical solution, the regulatory agency uses all tracking shares {share i} i∈[1,n] , the method to extract the signer's group certificate A from the signature σ is:
[0043] The regulator selects a subset of all tracking shares Where |M|=t, t is the threshold value;
[0044] For each i∈M, the Lagrange coefficient Δ is obtained according to the following formula i,M (0),
[0045]
[0046] Using the selected tracking share subset M and the Lagrangian coefficients, the certificate A is recovered as follows,
[0047]
[0048] In the formula, θ i is the tracking value in each tracking share.
[0049] The beneficial effects of the present invention are as follows:
[0050] 1. Enhanced privacy protection
[0051] The user chooses and holds the secret value by himself, and the registration authority only issues the group certificate and does not have the complete private key information of the user. This method effectively protects the privacy of the user. The linking operation of the signature is completed by the regulatory agency and the linking agency in collaboration, ensuring the privacy of the user's identity. The identity of the signer is only revealed through the distributed tracking agency when necessary. Through the randomization of the link label, signatures of different batches cannot be linked under normal circumstances, thereby protecting the anonymity of the user; at the same time, the linking of signatures can be achieved through the collaboration of the regulatory agency and the linking agency when necessary.
[0052] 2. Improved security
[0053] The identity tracking of the signer is completed by a distributed tracking organization, avoiding single points of failure and power concentration. The identity of the signer can only be revealed when the preset threshold value is reached, which enhances the system's anti-attack and reliability. In the signature generation and verification process, zero-knowledge proof technology is used to prove the signer's knowledge of the secret value without revealing the specific content of the secret value. It effectively prevents the leakage of secret values and enhances the security of the system. By combining cryptographic technologies such as bilinear mapping, ElGamal encryption and zero-knowledge proof, the unforgeability of the signature is ensured to prevent malicious users from forging signatures.
[0054] 3. Improved computer computing efficiency
[0055] The present invention supports batch linking of multiple signatures, allowing simultaneous verification and association of multiple signatures. This batch processing capability significantly reduces the time complexity of computers in processing large-scale data and improves overall efficiency. The process of tracking the identity of the signer is completed by multiple trackers in collaboration, rather than relying on a single organization. It not only improves the system's anti-attack ability, but also reduces the computing pressure of a single point through parallel processing. The conversion of link tags reduces the system's demand for storage resources. It can adapt to large-scale user groups and high-frequency signature operations, especially for scenarios that require processing large amounts of data, such as electronic voting, financial transactions, etc. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 It is a flow chart of the group signature method supporting distributed tracking and linking of the present invention. DETAILED DESCRIPTION
[0057] The present invention will be further described in detail below in conjunction with the accompanying drawings and examples, but the present invention is not limited to the following embodiments.
[0058] exist Figure 1 In this embodiment, a group signature method supporting distributed tracing and linking includes the following steps:
[0059] Step 1. Generate system public parameters
[0060] The system selects security parameters and generates a Type-3 bilinear mapping group G = (q, G 1 ,G 2 ,G T ,g 1 ,g 2 ,e), where,G 1 , G T , G 2 is a cyclic group of order q, G T is the target group, and randomly selects a generator g 1 ∈G 1 and g 2 ∈G 2 , randomly select elements Randomly select collision-resistant hash functions Generate system public parameters
[0061] Step 2. Each authority generates its own key pair
[0062] The registration authority randomly selects the secret value As a private key, is the integer multiplication group modulo p, computing the public key Output (isk, ipk) as the key pair of the registration authority;
[0063] The regulator randomly selects the secret value As the private key, calculate the public key rsk = g rsk , output (rsk, rpk) as the key pair of the regulator;
[0064] The linking mechanism randomly selects the secret value As the private key, calculate the public key lpk = h lsk , output (lsk,lpk) as the key pair of the linking mechanism;
[0065] The distributed tracking agency generates a public key, including the following steps:
[0066] Step S1. The system sets the number of trackers n and the threshold value t for successfully tracking the signer;
[0067] Step S2. Each tracking member DT i Randomly choose a secret value Construct a t-1 degree polynomial f i (x) = s i +a i1 x+a i2 x 2 +...+a i(t-1) x t-1 , a i1 ,a i2 ...a i(t-1) is a randomly selected coefficient that generates the public coefficient U i0 , U i1 , ..., U i(t-1) And broadcast to other tracking members, among which,
[0068] Step S3. Each tracking member DT i DT for other tracking members j Calculate the sub-share S ij =f i (j) and transfer the sub-share S ij Send to tracking member DT j , where j∈{1,...,n};
[0069] Step S4. Tracking member DT j Received sub-shares 1j ,...,S nj}, according to equation Verify the validity. If the equation holds, the sub-share is valid.
[0070] Step S4. All tracking members’ sub-shares are verified, and each tracking member DT j Calculate your own private key
[0071] Step S5. Calculate and publish the public key of the distributed tracking agency
[0072] The system sets the group public key gpk = (ipk, rpk, lpk, DTPK);
[0073] Step 3. User Registration
[0074] Step 3.1. The user with identifier Uid randomly selects his own secret value Generate intermediate value H←h 1 yAnd zero-knowledge proof π H , send a registration request to the registration authority, the registration request includes the identifier Uid, the intermediate value H, and the zero-knowledge proof π H ;
[0075] Step 3.2. After receiving the registration request from the user Uid, the registration agency verifies the legitimacy of the zero-knowledge proof and generates an intermediate value s = H 0 (Uid), and randomly select Generate group certificate A, The registration authority sends the group certificate A and parameter x to the user Uid, and at the same time sends the user Uid registration information reg[Uid]=(s,x,H,A,π H ) is stored in the local registry for subsequent identity tracking;
[0076] Step 3.3. After receiving the group certificate A and parameter x, user Uid generates an intermediate value s' = H 0 (Uid), verify group certificate A If the validity is verified, s' is equal to s generated by the registration agency, and the user Uid sets his own group member private key gsk[Uid]=(A,x,y,s);
[0077] Step 4. The user generates a signature for message m
[0078] User chooses a random number Generate ciphertext D respectively 1 and D 2 and link tag Tag = (T 1 ,T 2 ,T 3 ),in, D 2 =A(DTPK) α ,
[0079] The user uses the proof of knowledge signature SPK to generate proof π σ , prove the correctness of the ciphertext and link tag, and output the signature σ=(D 1 ,D 2 ,π σ ) and link tag Tag;
[0080] Step 5. User signature verification
[0081] The receiver with the group public key parses the signature σ and verifies the proof π σ The validity of the signature is verified and the signature is valid;
[0082] Step 6. The regulator interacts with the linking agency to link multiple signatures to the same user
[0083] The regulator will send a set of signed link tags (Tag 1 ,...,Tag i ,...,Tag n ) is sent to the linking organization, where Tag i =(T 1i ,T 2i ,T 3i );
[0084] The linking mechanism randomly selects an integer For the i-th link label, i=1,...,n, randomly select an integer Calculate the converted link tag CTag i ={CT 1i ,CT 2i},in, The private key of the linking organization is used to tag T 3i Adjustment, It introduces randomness to ensure that the same signature cannot be linked to the previous transformation. It is to randomize the original tag so that the regulator can correctly decrypt it. It introduces additional randomness to ensure unlinkability;
[0085] The link agency will convert all converted link tags (CTag 1 , ..., CTag i , ..., CTag n ) sent to the supervisory authority;
[0086] After receiving the converted link tags, the regulator decrypts them and maps all link tags belonging to the same user in the same conversion batch into a consistent form, thereby achieving linking;
[0087] Step 7. Distributed tracking mechanism tracks user identity
[0088] Each tracker DT involved in the tracking process in the distributed tracking mechanism i Each of them generates a tracking share for the signature σ being tracked i And will track share i sent to regulatory authorities;
[0089] Among them, tracking share is the tracking proof, used to verify the tracking value θ i correctness.
[0090] Regulators use all tracking shares i} i∈[1,n] , extract the signer’s group certificate A from the signature σ, search the registry, and determine the signer’s identity;
[0091] Among them, regulators use all tracking shares {share i} i∈[1,n] , the method to extract the signer's group certificate A from the signature σ is:
[0092] The regulator selects a subset of all tracking shares Where |M|=t, t is the threshold value;
[0093] For each i∈M, the Lagrange coefficient Δ is obtained according to the following formula i,M (0),
[0094]
[0095] Using the selected tracking share subset M and the Lagrangian coefficients, the certificate A is recovered as follows,
[0096]
[0097] In the formula, θ i is the tracking value in each tracking share.
Claims
1. A group signature method supporting distributed tracing and linking, characterized in that: The following steps are involved: Step 1. Generate system public parameters The system selects security parameters and generates a Type-3 bilinear mapping group G = (q, G1, G2, G T ,g1,g2,e), where G1, G T , G2 is a cyclic group of order q, G T is the target group, randomly select generators g1∈G1 and g2∈G2, and randomly select elements Randomly select collision-resistant hash functions Generate system public parameters Step 2. Each authority generates its own key pair The registry randomly selects the secret value As a private key, is the integer multiplication group modulo p, computing the public key Output (isk, ipk) as the key pair of the registration authority; The regulator randomly selects the secret value As the private key, calculate the public key rpk = g rsk , output (rsk, rpk) as the key pair of the regulator; The linking mechanism randomly selects the secret value As the private key, calculate the public key lpk = h lsk , output (lsk,lpk) as the key pair of the linking mechanism; The distributed tracking agency generates a public key, including the following steps: Step S1. The system sets the number of trackers n and the threshold value t for successfully tracking the signer; Step S2. Each tracking member DT i Randomly choose a secret value Construct a t-1 degree polynomial f i (x) = s i +a i1 x+a i2 x 2 +...+a i(t-1) x t-1 , a i1 ,a i2 ...a i(t-1) is a randomly selected coefficient that generates the public coefficient U i0 , U i1 , ..., U i(t-1) And broadcast to other tracking members, among which, Step S3. Each tracking member DT i DT for other tracking members j Calculate the sub-share S ij =f i (j) and transfer the sub-share S ij Send to tracking member DT j , where j∈{1,...,n}; Step S4. Tracking member DT j Received sub-shares 1j ,...,s nj }, according to equation Verify the validity. If the equation holds, the sub-share is valid. Step S4. All tracking members’ sub-shares are verified, and each tracking member DT j Calculate your own private key Step S5. Calculate and publish the public key of the distributed tracking agency The system sets the group public key gpk = (ipk, rpk, lpk, DTPK); Step 3. User Registration Step 3.
1. The user with identifier Uid randomly selects his own secret value Generate intermediate value H←h1 y And zero-knowledge proof π H , send a registration request to the registration authority, the registration request includes the identifier Uid, the intermediate value H, and the zero-knowledge proof π H ; Step 3.
2. After receiving the registration request from the user Uid, the registration agency verifies the legitimacy of the zero-knowledge proof, generates an intermediate value s=H0(Uid), and randomly selects Generate group certificate A, the registration authority sends group certificate A and parameter x to user Uid, and stores user Uid registration information in the local registry for subsequent identity tracking; Step 3.
3. After receiving the group certificate A and parameter x, user Uid generates an intermediate value s'=H0(Uid) to verify the validity of the group certificate A. If the verification is successful, s' is equal to s generated by the registration authority, and user Uid sets his own group member private key gsk[Uid]=(A,x,y,s); Step 4. The user generates a signature for message m User chooses a random number Generate ciphertext D1 and D2 and link tag Tag = (T1, T2, T3) respectively, where: D2=A(DTPK) α , The user uses the proof of knowledge signature SPK to generate proof π σ , prove the correctness of the ciphertext and link tag, and output the signature σ=(D1,D2,π σ ) and link tag Tag; Step 5. User signature verification The receiver with the group public key parses the signature σ and verifies the proof π σ The validity of the signature is verified and the signature is valid; Step 6. The regulator interacts with the linking agency to link multiple signatures to the same user The supervisory authority sends a set of signed link tags (Tag1, ..., Tag i ,...,Tag n ) is sent to the linking organization, where Tag i =(T 1i ,T 2i ,T 3i ); The linking mechanism randomly selects an integer For the i-th link label, i=1,...,n, randomly select an integer Calculate the converted link tag CTag i ={CT 1i ,CT 2i },in, The private key of the linking organization is used to tag T 3i Adjustment, It introduces randomness to ensure that the same signature cannot be linked to the previous transformation. It is to randomize the original tag so that the regulator can correctly decrypt it. It introduces additional randomness to ensure unlinkability; The link mechanism converts all converted link tags (CTag1, ..., CTag i , ..., CTag n ) sent to the supervisory authority; After receiving the converted link tags, the regulator decrypts them and maps all link tags belonging to the same user in the same conversion batch into a consistent form, thereby achieving linking; Step 7. Distributed tracking mechanism tracks user identity Each tracker DT involved in the tracking process in the distributed tracking mechanism i Each of them generates a tracking share for the signature σ being tracked i , and will track share i sent to regulatory authorities; Regulators use all tracking shares i } i∈[1,n] , extract the signer’s group certificate A from the signature σ, search the registry, and determine the signer’s identity.
2. The group signature method supporting distributed tracing and linking according to claim 1, characterized in that: In step 3.2, the group certificate A is: The registration information reg[Uid]=(s,x,H,A,π H ).
3. The group signature method supporting distributed tracing and linking according to claim 1, characterized in that: The tracking share i for: is the tracking proof, used to verify the tracking value θ i correctness.
4. The group signature method supporting distributed tracing and linking according to claim 1, characterized in that: The regulator uses all tracking shares i } i∈[1,n] , the method to extract the signer's group certificate A from the signature σ is: The regulator selects a subset of all tracking shares Where |M|=t, t is the threshold value; For each i∈M, the Lagrange coefficient Δ is obtained according to the following formula i,M (0), Using the selected tracking share subset M and the Lagrangian coefficients, the certificate A is recovered as follows: In the formula, θ i is the tracking value in each tracking share.