Identity-hidden post-quantum identity-based ciphertext signcryption method
By introducing identity hiding and post-quantum security into the traditional identity-based cryptographic system, combined with the lattice-based post-quantum symmetric encryption algorithm, the security problems of traditional cryptographic systems in the face of quantum computing attacks are solved, and stronger privacy protection and communication efficiency are achieved.
Patent Information
- Application Number
- CN202510092633.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-27
AI Technical Summary
Traditional public key cryptography systems are difficult to resist when facing quantum computing attacks, resulting in serious threats to cryptographic infrastructure. A new cryptographic solution that can resist quantum computing attacks is needed.
A post-quantum identity-based ciphertext signature method for identity hiding is proposed. Through a grid-based post-quantum symmetric encryption algorithm, combined with identity-based cipher and signature technology, the functions of identity hiding and resisting quantum computing attacks are realized.
This method not only provides stronger privacy protection and simplified key management, but also improves communication efficiency, can effectively resist quantum computing attacks and ensure communication security.
Smart Images

Figure CN120050020A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of cryptography, and in particular relates to a post-quantum identity-based ciphertext signcryption method with identity hiding. Background Art
[0002] Identity-Based Cryptography (IBC) is an important branch of public key cryptography. It allows users to use any string (such as an email address) as a public key, simplifying the key management process. The identity-based hidden signcryption (IBHC) scheme is an important extension of traditional identity-based cryptography. This scheme not only provides encryption and signing functions, but also hides the identity of the sender during the encryption process, thereby providing stronger privacy protection. The signcryption scheme has significant advantages over separate encryption and signature schemes.
[0003] The invention patent with the prior art application publication number CN112436942A discloses a revocable signcryption method with heterogeneous attribute-based / identity-based signatures. It is characterized in that the attribute-based encryption and the identity-based signature are combined in the same algorithm in the construction, thereby solving the problem of huge computational complexity and communication cost required by the traditional "sign first and then encrypt" method, and introducing the construction of the revocation list, thereby solving the risk of key leakage. When executing the signcryption, the signer uses the attribute strategy, revocation list, public key and the private key corresponding to his own identity to sign the plaintext; the decryptor decrypts the signcrypted text with the corresponding private key and public key. When the identity of the decryptor is not in the revocation list, the decryptor can restore the plaintext, otherwise the decryptor cannot restore the plaintext. The present invention can be used in a cloud-based Internet of Vehicles environment to provide confidentiality, integrity, authentication, non-repudiation and access control services for users of the cloud-based Internet of Vehicles environment, and also supports the revocation of users. Summary of the invention
[0004] With the rapid development of quantum computing technology, traditional cryptographic systems are facing unprecedented challenges. Quantum computers, with their powerful parallel computing capabilities, can crack public key cryptographic systems based on integer factorization and discrete logarithm problems, such as RSA and ECC, in polynomial time. This poses a serious threat to the existing cryptographic infrastructure, making it urgent to find new cryptographic schemes that can resist quantum computing attacks.
[0005] In order to solve the above technical problems, the present invention provides a technical solution: a post-quantum identity-based ciphertext signcryption method with identity hiding, comprising the following steps: S1. The Key Generation Center (PKG) runs the initialization algorithm and outputs the public parameters par and the master secret key msk of the signcryption system according to the input security parameter κ; S2. Run the key generation algorithm and assign private keys sk to different identities id according to the master secret key msk and the public parameters par; S3. Run the identity-based signcryption algorithm, input the identity ID of the sender s and the identity ID of the receiver r , encrypt the unencrypted message M and its associated data H according to the public parameters par and the private key sk of the sender s and output the identity-based signcryption ciphertext C; S4. Run the identity-based unsigncryption algorithm, input the public parameters par, the private key sk of the receiver r , the identity ID of the receiver r and a ciphertext C, verify whether it can be decrypted. If the verification is successful, output the identity ID of the sender s and the unencrypted message M.
[0006] Specifically, the security parameter κ and the set of identity IDs of the senders and receivers permitted by the system in S1 are implicitly encoded in par.
[0007] Specifically, the initialization function in S1 selects two multiplicative bilinear mapping groups G 1 = <g>and G T , having the same prime order q, construct a bilinear pairing e: G 1 ×G 1 →G T , and select Select a one-way collision-resistant cryptographic hash function h: {0, 1} * →G 1 , and finally output the public parameters par = (q, G 1 , G T , e, g, h) and the master secret key msk = s of the PKG.
[0008] Specifically, the key generation algorithm in S2 inputs the public parameters par of the system, the master secret key msk of the key generation center PKG, and the identity id of the user ∈ {0, 1} * , and the PKG calculates sk = h(id) msk = h(id) s , and outputs sk id as the private key associated with the identity id.
[0009] Specifically, the identity-based signcryption algorithm in S3 is a lattice-based post-quantum symmetric encryption algorithm with quantum-resistant properties and is a probabilistic polynomial-time algorithm. During the encryption process, the associated data H, the sender's identity ID s , the unencrypted message M, the first encryption parameter x, and the derived key K 1 are input into the encryption function to obtain the encrypted ciphertext C AE ; finally, the signcryption ciphertext C = (H, X, C AE ) containing the associated data H, the second encryption parameter X, and the encrypted ciphertext C AE is sent to the recipient ID r .
[0010] Specifically, the derived key K 1 is calculated through the key derivation function KDF by inputting the pre-shared key PS, the second encryption parameter X, and the recipient's identity ID r .
[0011] Specifically, the pre-shared key PS is calculated according to the bilinear pairing e in the initialization algorithm by inputting the sender's private key and sk s and the recipient's ID r .
[0012] Specifically, the second encryption parameter X is first selected by the system as the first encryption parameter and then the second encryption parameter X = h(ID s ) x ∈G 1 。
[0013] Specifically, after the identity-based signcryption algorithm in S3 encrypts successfully, the associated data H appears in the identity-based signcryption ciphertext C in plaintext form.
[0014] Specifically, when running the identity-based unsigncryption algorithm in S4, after the receiver receives C = (H, X, C AE ), the receiver ID r first calculates the pre-shared key PS = e(X, sk r ) ∈ G T , and derives the key K 1 = KDF(PS, X|ID r ) ∈ K; then runs the decryption function If the decryption verification fails, abort; otherwise, the receiver obtains ID s , M, x; if the sender's identity ID s belongs to the legitimate ID in the signcryption system identity library, the first encryption parameter x belongs to the encryption parameter library and the second encryption parameter X = h(ID s ) x , then output (ID s , M); otherwise, output an error and abort. Different from traditional identity-based signcryption, the identity-based unsigncryption algorithm does not require the sender's public identity ID s as input, thus enabling identity hiding.
[0015] The beneficial effects of the present invention are as follows: The present invention proposes a post-quantum identity-based ciphertext signcryption method with identity hiding. This method introduces the identity hiding feature on the basis of the traditional identity-based signcryption scheme, and at the same time considers post-quantum security, organically combines identity hiding, identity-based encryption, and signature functions, and resists quantum computing attacks by adopting post-quantum secure cryptographic primitives. The identity-based ciphertext signcryption method of the present invention not only provides stronger privacy protection, but also simplifies key management and improves communication efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 is a flowchart of the method of the present invention.
[0017] Figure 2 is a schematic diagram of the algorithm of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] The present invention will be described in detail below with reference to the drawings and embodiments.
[0019] Embodiment 1: A post-quantum identity-based ciphertext signcryption method with identity hiding, as Figure 1 As shown, it includes the following steps: S1. The Key Generation Center (PKG) runs the initialization algorithm and outputs the public parameters par and the master secret key msk of the signcryption system according to the input security parameter κ; S2. Run the key generation algorithm and allocate private keys sk to different identities id according to the master secret key msk and the public parameters par; S3. Run the identity-based signcryption algorithm, input the identity ID of the sender s and the identity ID of the receiver r , and encrypt the unencrypted message M and its associated data H according to the public parameters par and the private key sk of the sender s to output the identity-based signcryption ciphertext C; S4. Run the identity-based unsigncryption algorithm, input the public parameters par, the private key sk of the receiver r , the identity ID of the receiver r and a ciphertext C, verify whether it can be decrypted. If the verification is successful, output the identity ID of the sender s and the unencrypted message M.
[0020] To address the security challenges posed by quantum computing, the cryptographic community has begun to study post-quantum cryptography (PQC). Post-quantum cryptography aims to design cryptographic algorithms that can be efficiently implemented on classical computers and can resist attacks from quantum computers. Currently, the main post-quantum cryptography schemes include lattice-based cryptography, code-based cryptography, multivariate polynomial-based cryptography, etc. These schemes rely on mathematical problems that are considered difficult to solve even in the quantum computing model.
[0021] The post-quantum identity-based cryptography provided in this embodiment aims to apply the idea of post-quantum cryptography to the identity-based cryptosystem to construct an identity-based cryptography scheme that can resist quantum attacks. Therefore, it becomes particularly necessary to develop a post-quantum identity-based cryptosystem. First of all, post-quantum identity-based cryptography can protect long-term data security. Many sensitive information needs to be kept confidential for a long time, and the emergence of quantum computers may break the current encryption methods within the next few years. Adopting post-quantum identity-based cryptography can ensure that the data encrypted today remains secure in the future. Secondly, it helps to maintain the existing communication infrastructure. Identity-based cryptosystems are widely used in various communication protocols. If these systems are broken, it will have a huge impact on the global communication infrastructure. Post-quantum solutions can ensure that these systems remain secure and reliable in the quantum era. In addition, post-quantum identity-based cryptography can also address the threat of "collect now, decrypt later". An adversary may collect currently encrypted communications and decrypt them when quantum computers become available. Adopting post-quantum technology can effectively prevent this future threat. Finally, post-quantum identity-based cryptography can maintain the advantages of identity-based cryptography. Identity-based cryptography simplifies key management and improves system usability. Combining it with post-quantum technology can provide quantum resistance while maintaining these advantages.
[0022] This embodiment provides a post-quantum identity-based ciphertext signcryption method with identity hiding, which is specifically composed of a specific architecture based on Type1 bilinear pairing, as Figure 2 shown. The scheme includes four algorithms.
[0023] Initialization algorithm Setup(1 κ )→(par, msk): This algorithm is run by the Private Key Generator (PKG). Given the security parameter κ as input, this function outputs the public parameters par and the master secret key msk of the system. Finally, the Private Key Generator (PKG) outputs par and keeps the master secret key msk confidential. It is assumed that the security parameter κ and an acceptable identity space ID are always implicitly encoded in par.
[0024] In S1, the initialization function selects two multiplicative bilinear mapping groups G 1 = <g>and G T with the same prime order q, construct a bilinear pairing e: G 1 × G 1 → G T and choose Choose a one-way collision-resistant cryptographic hash function h: {0, 1} * → G 1 , and finally output the public parameters par = (q, G 1 , G T , e, g, h) and the master secret key msk = s of the PKG.
[0025] In S1, this algorithm is run by the PKG to generate the public parameters and the master secret key of the system. Given the security parameter κ, this algorithm selects two multiplicative bilinear mapping groups G 1 = <g>and G T with the same prime order q such that the discrete logarithm problem in G 1 and G T is intractable. The algorithm constructs a bilinear pairing e: G 1 × G 1 → G T and selects In addition, a one-way collision-resistant cryptographic hash function h: {0, 1} * → G 1 is selected. Finally, the algorithm outputs the public parameters par = (q, G 1 , G T , e, g, h), and the master secret key msk = s of the PKG. The PKG discloses par to the users in the system but keeps msk secret. For simplicity, assume that the acceptable identity space ID = {0, 1} * .
[0026] The security parameter κ in S1 and the set of identities ID of the senders and receivers permitted by the system are implicitly encoded in par.
[0027] In S2, the key generation algorithm takes as input the public parameters par of the system, the master secret key msk of the key generation center PKG, and the identity id of the user ∈ {0, 1} * . The PKG computes sk = h(id) msk = h(id) s and outputs sk id as the private key associated with the identity id.
[0028] Specifically, the key generation algorithm in S2 is KeyGen(par, msk, id): taking as input the public parameters par of the system, the master secret key msk of the PKG, and the identity id of the user ∈ {0, 1} * . The PKG computes sk = h(id) msk = h(id) s and outputs sk id as the private key associated with the identity id. The public identity and its private key are used for the identity-based signcryption algorithm and the identity-based unsigncryption algorithm respectively.
[0029] The identity-based signcryption algorithm in S3 is a lattice-based post-quantum symmetric encryption algorithm with anti-quantum properties and is a probabilistic polynomial-time algorithm. During the encryption process, the associated data H, the sender's identity ID s , the unencrypted message M, the first encryption parameter x, and the derived key K 1 are input into the encryption function to obtain the encrypted ciphertext C AE ; finally, the one containing the associated data H, the second encryption parameter X, and the encrypted ciphertext C AE The signed and encrypted ciphertext C = (H, X, C AE ) is sent to the recipient ID r .
[0030] The identity-based signcryption algorithm in S3 is specifically the identity-based signcryption algorithm: IBHC(par, sk s , ID s , ID r , H, M) → (C, ⊥): This algorithm is a probabilistic polynomial-time algorithm. The input is the public parameter par of the system, the private key sk of the sender s and its public identity ID s ∈ ID, the public identity ID of the recipient r ∈ ID, the message M ∈ {0, 1} to be identity-based signcrypted * and its associated data H ∈ {0, 1} * , and this function outputs an identity-based signcryption ciphertext C ∈ {0, 1} * , or ⊥ indicating identity-based signcryption failure. When C ≠ ⊥, the associated data H appears in the identity-based signcryption ciphertext C in plaintext form. Among them, M ∈ {0, 1} * is the message to be identity-hidden in identity-based signcryption, and the associated data is H ∈ {0, 1} * , and the key derivation function KDF: G T × {0, 1} * → {0, 1} * is a key derivation function modeled as a random oracle, where K is the key space of K se .
[0031] For simplicity, use id s to represent the public identity of the sender, and its private key is sk s = h(id s ) s , and use id r to represent the public identity of the recipient, and its private key is sk r = h(id r ) s . To perform identity-hidden identity-based signcryption on the message M ← {0, 1} * , while hiding the identity ID of the sender s , the sender ID s performs the following steps: Select the first encryption parameter and calculate the second encryption parameter X = h(ID s ) x ∈ G 1 through the one-way collision-resistant cryptographic hash function h in the initialization algorithm; Calculate the pre-shared key PS = e(sk s , h(ID r )) x ∈G T ; Calculate the derived key K according to the key derivation function KDF 1 = KDF(PS, X|ID r ) ∈ K; Use the encryption function Enc to calculate Send the signed ciphertext C = (H, X, C AE ) to the recipient ID r .
[0032] Among them, the encryption function Enc is a lattice-based post-quantum symmetric encryption algorithm with anti-quantum characteristics. The parameters include the vector dimension n, the number of samples m, and the modulus q. The calculation process is as follows: Private key: The private key is a vector s selected from ; Public key: The public key is m LWE samples where b i = a i s i + e i , e i is noise; Encryption: For each bit m of the message m i , select a uniformly random set S from 2 m subsets of the set [m] generated from m. The encryption method is Decryption: Calculate m i ' = b - <a, s>. If m_i' is closer to 0, the result is 0. If m i ' is closer to , the result is 1.
[0033] The identity-based unsigncryption algorithm UnIBHC in S4 (par, sk r , ID r , C) → ((ID s , M), ⊥): This algorithm is a deterministic algorithm. Input the public parameters par of the system, the private key sk r of the recipient, the public identity ID r ∈ ID of the recipient, and a ciphertext C. If the verification is successful, output (ID s , M), otherwise output ⊥ to indicate an error, where ID s ∈ ID is the public identity of the sender, and M ∈ {0, 1} * is the message signed and encrypted by ID s . Different from traditional identity-based signcryption, UnIBHC does not require the public identity ID s of the sender as input, thus hiding the identity.
[0034] The specific steps of UnIBHC are as follows: After receiving C = (H, X, C AE ), the recipient ID r performs the following operations: calculates the pre-shared key PS = e(X, sk r ) ∈ G T , and derives the key K 1 = KDF(PS, X|ID r ) ∈ K; runs the decryption function If the decryption function returns ⊥, then abort; otherwise, the recipient obtains ID s , M, x. If ID s ∈ ID, and X = h(ID s ) x , then outputs (ID s , M). Otherwise, outputs ⊥ and aborts.
[0035] Derives the key K 1 through the key derivation function KDF, with the input of the pre-shared key PS, the second encryption parameter X, and the recipient identity ID r for calculation.
[0036] The pre-shared key PS is calculated according to the bilinear pairing e in the initialization algorithm, with the input of the sender's private key and sk s and the recipient ID r for calculation.
[0037] The second encryption parameter X is first selected by the system as the first encryption parameter and then the second encryption parameter X = h(ID s ) x ∈ G 1 is calculated through the one-way collision-resistant cryptographic hash function h in the initialization algorithm.
[0038] After the identity-based signcryption algorithm in S3 encrypts successfully, the associated data H appears in the identity-based signcryption ciphertext C in plaintext form.
[0039] When running the identity-based unsigncryption algorithm in S4, after the recipient receives C = (H, X, C AE ), the recipient ID r first calculates the pre-shared key PS = e(X, sk r ) ∈ G T , and derives the key K 1 = KDF(PS, X|ID r ); then runs the decryption function If the decryption verification fails, then abort; otherwise, the recipient obtains ID s , M, x; If the sender's identity ID s A legitimate ID belonging to the identity repository of the signcryption system, and the first encryption parameter x belongs to the encryption parameter repository and the second encryption parameter X = h(ID s ) x , then output (ID s , M); otherwise, output an error and abort. Different from traditional identity-based signcryption, the identity-based unsigncryption algorithm does not require the public identity ID of the sender s as an input, thus enabling identity hiding.
[0040] The algorithm of this embodiment has smaller public parameters in the setup phase and actually does not need to perform exponentiation to generate the master public key. IBHC is simpler in the setup phase, especially omitting the master public key, bringing the following advantages: 1. The computational complexity and space complexity of generating and storing system parameters are reduced; 2. Reduce the attack vectors used to recover the master key; 3. Facilitate the deployment and compatibility with existing identity-based cryptosystems. Specifically, when actually deploying the IBHC scheme of the present invention, used together with other existing identity-based cryptosystems, the system parameters, especially the master public key, can remain unchanged.
[0041] Embodiment 2: An identity-hiding post-quantum identity-based ciphertext signcryption method, including the following steps: S1. The key generation center PKG runs the initialization algorithm and outputs the public parameters par and the master secret key msk of the signcryption system according to the input security parameter κ; S2. Run the key generation algorithm and assign a private key sk to different identities id according to the master secret key msk and the public parameters par; S3. Run the identity-based signcryption algorithm, input the identity ID of the sender s and the identity ID of the receiver r , and encrypt the unencrypted information M and its associated data H according to the public parameters par and the private key sk of the sender s to output the identity-based signcryption ciphertext C; S4. Run the identity-based unsigncryption algorithm, input the public parameters par, the private key sk of the receiver r , the identity ID of the receiver r and a ciphertext C, verify whether it can be decrypted. If the verification is successful, then output the identity ID of the sender s and the unencrypted information M.
[0042] The security parameter κ in S1 and the set of identity IDs of the senders and receivers permitted by the system are implicitly encoded in par.
[0043] In S1, the initialization function selects two multiplicative bilinear mapping groups G 1 = <g>and G T with the same prime order q, construct a bilinear pairing e: G 1 ×G 1 →G T , and select Select a one-way collision-resistant cryptographic hash function h: {0, 1} * →G 1 , and finally output the public parameters par = (q, G 1 , G T , e, g, h) and the master secret key msk = s of the PKG.
[0044] In S2, the key generation algorithm inputs the public parameters of the system par, the master secret key msk of the key generation center PKG, and the identity id of the user ∈ {0, 1} * , and the PKG calculates sk = h(id) msk = h(id) s , and outputs sk id as the private key associated with the identity id.
[0045] The identity-based signcryption algorithm in S3 is a lattice-based post-quantum symmetric encryption algorithm with quantum-resistant properties and is a probabilistic polynomial-time algorithm. During the encryption process, the associated data H, the sender's identity ID s , the unencrypted message M, the first encryption parameter x, and the derived key K 1 are input into the encryption function to obtain the encrypted ciphertext C AE ; finally, the signed ciphertext C = (H, X, C AE ) containing the associated data H, the second encryption parameter X, and the encrypted ciphertext C AE is sent to the recipient ID r .
[0046] Among them, the encryption function Enc is a lattice-based post-quantum symmetric encryption algorithm with quantum-resistant properties. The parameters include the vector dimension n, the number of samples m, the modulus q, and the calculation process is as follows: Private key: The private key is a vector s selected from ; Public key: The public key is m LWE samples where b i = a i s i + e i , and e i is noise; Encryption: For each bit m i of the message m, a uniformly random set S is selected from the 2 m subsets of the set [m] generated from m, and the encryption method is Decryption: Calculate m i ′ = b - <a, s>. If m_i' is closer to 0, the result is 0. If m i ′ is closer to then the result is 1.
[0047] Derive the key K 1 Through the key derivation function KDF, input the pre-shared key PS, the second encryption parameter X, and the recipient identity ID r Calculate.
[0048] The pre-shared key PS is calculated according to the bilinear pairing e in the initialization algorithm, inputting the sender's private key sk s and the recipient ID r Calculate.
[0049] The second encryption parameter X is first selected by the system as the first encryption parameter and then the second encryption parameter X = h(ID s ) x ∈ G 1 .
[0050] After the identity-based signature encryption algorithm in S3 is successfully encrypted, the associated data H appears in the identity-based signature ciphertext C in plaintext form.
[0051] When running the identity-based signature decryption algorithm in S4, after the recipient receives C = (H, X, C AE ), the recipient ID r first calculates the pre-shared key PS = e(X, sk r ) ∈ G T , and derives the key K 1 = KDF(PS, X|ID r ) ∈ K; then runs the decryption function If the decryption verification fails, abort; otherwise, the recipient obtains ID s , M, x; if the sender identity ID s belongs to the legitimate ID of the signature encryption system identity library, the first encryption parameter x belongs to the encryption parameter library and the second encryption parameter X = h(ID s ) x , then output (ID s , M); otherwise, output an error and abort. Different from traditional identity-based signature encryption, the identity-based signature decryption algorithm does not require the sender's public identity ID s as input, thus hiding the identity.
[0052] The specific instantiation methods of the four algorithms in this embodiment based on Type 2 bilinear pairing are as follows.
[0053] Initialization algorithm Setup(1 κ ) The specific process includes: Input the security parameter κ. This algorithm selects three multiplicative bilinear mapping groups G 1 、G 2 and G T , with the same prime order q, a generator g 1 ∈ G 1 , g 2 = ψ(g 1 ) ∈ G 2 , and a bilinear pairing e: G 1 × G 2 → G T , such that the discrete logarithm problem in G 1 , G 2 and G T is intractable, where ψ: G 1 → G 2 is an efficient and publicly computable isomorphism. This algorithm selects a master key In addition, select a one-way collision-resistant cryptographic hash function h: {0, 1} * → G 1 . Finally, this algorithm outputs the public parameters par = (q, G 1 , G 2 , G T , e, g 1 , g 2 , ψ, h), and the master key msk = s of the PKG. The PKG discloses par to the users in the system but keeps msk secret.
[0054] The identity-based signcryption algorithm IBHC(par, msk, ID) specific process includes: Let SE = (K * , Enc, Dec) be an authenticated encryption scheme, M ∈ {0, 1} msk = h(ID) s , and output sk as the private key associated with the identity ID.
[0055] The identity-based signcryption algorithm IBHC(par, sk s , ID s , ID r , H, M) specific process includes: Let SE = (K se , Enc, Dec) be an authenticated encryption scheme, M ∈ {0, 1} * be the message to be identity-based signcrypted with identity hiding, the associated data be H ∈ {0, 1} * , KDF: G T × {0, 1} * ← {0, 1} * is a key derivation function, where K is the key space of K se . For simplicity, use ID s to represent the sender's public identity, whose private key is sk s = h(ID s ) s . Use ID r to represent the receiver's public identity, whose private key is sk r = h(ID r ) s .
[0056] To perform identity-based signcryption with identity hiding for the message M ← {0, 1} * , while hiding the sender's identity ID s , the sender: (1) Select and calculate X = h(ID s ) x ∈ G 1 ; (2) Calculate the pre-shared key PS = e(sk s , ψ, (h(ID r ))) x ; (3) Derive K 1 = KDF(PS, X|ID r ) ∈ K; (4) Calculate (5) Finally, send the ciphertext C = (H, X, C AE ) to the receiver ID r .
[0057] The specific process of the identity-based unsigncryption algorithm UnIBHC(par, sk r , ID r , C) includes: After receiving C = (H, X, C AE ), the receiver: (1) Calculate the pre-shared key PS = e(X, ψ(sk r )) ∈ G T , and derive the key K 1 = KDF(PS, X|ID r ) ∈ K; (2) Run If returns ⊥, then abort; otherwise, the receiver gets ID s , M, x. If and X = h(ID s ) x , then output (ID s , M); Otherwise, output ⊥ and abort.
[0058] The Identity-Based Hiding Signcryption (IBHC) scheme is an important extension of traditional identity-based cryptography. This scheme not only provides the functions of encryption and signature, but also can hide the identity of the sender during the encryption process, thus providing stronger privacy protection. The signcryption scheme has significant advantages compared with separate encryption and signature schemes. First of all, the signcryption scheme significantly improves efficiency. It combines the encryption and signature processes, reducing the computational overhead and communication cost, making the whole process more efficient. Secondly, the signcryption scheme provides stronger security guarantees. By providing confidentiality, integrity and authentication simultaneously, the signcryption scheme provides comprehensive security protection for communication. Another important advantage is that the signcryption scheme reduces the implementation complexity. A single signcryption operation simplifies the system design and implementation, reduces potential errors and vulnerabilities, making the system more reliable and easy to maintain. Finally, the signcryption scheme has strong adaptability. It can be flexibly applied to various secure communication scenarios, meeting different security requirements, and thus has wide applicability in practical applications.
[0059] The post-quantum identity-based hiding signcryption scheme provided in this embodiment is not only a necessary means to cope with the threat of quantum computing, but also an important way to improve the security and efficiency of communication systems. This scheme combines the anti-quantum characteristics of post-quantum cryptography, the convenience of identity-based cryptography, the efficiency advantages of signcryption, and the privacy protection of identity hiding, providing a comprehensive solution for future secure communication.
[0060] Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.< / g> < / g> < / g> < / g>
Claims
1. A post-quantum identity-based ciphertext signcryption method with identity hiding, characterized in that: The following steps are involved: S1, the key generation center PKG runs the initialization algorithm and outputs the public parameter par and the master key msk of the signcryption system according to the input security parameter κ; S2, run the key generation algorithm, and assign private keys sk to different identity ids according to the master key msk and the public parameter par; S3. Run the identity-based signature algorithm and enter the sender’s identity ID s and the recipient's ID r , according to the public parameter par, the sender's private key sk s Encrypt the unencrypted information M and its associated data H, and output the identity-based signature ciphertext C; S4. Run the identity-based decryption and signcryption algorithm, input the public parameter par and the recipient's private key sk r , the recipient's ID r and a ciphertext C to verify whether it can be decrypted. If the verification is successful, the sender's identity ID is output. s and unencrypted information M.
2. The post-quantum identity-based ciphertext signcryption method for identity hiding according to claim 1, characterized in that: The security parameter κ in S1 and the set of identity IDs of senders and receivers permitted by the system are implicitly encoded in par.
3. The post-quantum identity-based ciphertext signcryption method for identity hiding according to claim 1 or 2, characterized in that: The initialization function in S1 selects two multiplicative bilinear mapping groups G1= <g>and G T , with the same prime order q, construct a bilinear pairing e: G1×G1→G T , and select Choose a one-way collision-resistant cryptographic hash function h: {0, 1} * →G1, and finally output the common parameter par=(q,G1,G T , e, g, h) and the master key of PKG msk=s.< / g> 4. The post-quantum identity-based ciphertext signcryption method for identity hiding according to claim 1, characterized in that: The key generation algorithm in S2 inputs the public parameter par of the system, the master key msk of the key generation center PKG, and the user's identity id∈{0,1} * PKG calculates sk = h(id) msk =h(id) s , and output sk id As the private key associated with the identity id.
5. The post-quantum identity-based ciphertext signcryption method for identity hiding according to claim 1, characterized in that: The identity-based signcryption algorithm in S3 is a lattice-based post-quantum symmetric encryption algorithm. During the encryption process, the associated data H and the sender’s identity ID s , the unencrypted information M, the first encryption parameter x and the derived key K1 are input into the encryption function Get the encrypted ciphertext C AE ; Finally, it will contain the associated data H, the second encryption parameter X and the encrypted ciphertext C AE The ciphertext C = (H, X, C AE )Send to the recipient ID r .
6. The identity-hidden post-quantum identity-based ciphertext signcryption method according to claim 5, characterized in that: The derived key K1 is obtained by using the key derivation function KDF, with the input of the pre-shared key PS, the second encryption parameter X and the recipient identity ID. r calculate.
7. The post-quantum identity-based ciphertext signcryption method for identity hiding according to claim 6, characterized in that: The pre-shared key PS is based on the bilinear pairing e in the initialization algorithm, inputting the sender's private key and sk s and recipient ID r calculate.
8. The post-quantum identity-based ciphertext signcryption method for identity hiding according to claim 5, characterized in that: The second encryption parameter X is selected by the system from the first encryption parameter Then, the second encryption parameter X=h(ID s ) x ∈G1.
9. The post-quantum identity-based ciphertext signcryption method for identity hiding according to claim 1 or 5, characterized in that: After the identity-based signcryption algorithm in S3 encrypts successfully, the associated data H appears in the identity-based signcryption ciphertext C in plain text.
10. The identity-hidden post-quantum identity-based ciphertext signcryption method according to claim 1, characterized in that: When the identity-based decryption algorithm is run in S4, the receiver receives C = (H, X, C AE ) after which the recipient ID r First calculate the pre-shared key PS = e(X, sk r )∈G T , and derive the key K1 = KDF(PS, X|ID r )∈K; then run the decryption function If decryption verification fails, abort; otherwise , the receiver gets the ID s , M, x; If the sender ID s The legal ID belongs to the identity library of the signcryption system, and the first encryption parameter x belongs to the encryption parameter library And the second encryption parameter X = h(ID s ) x , then output (ID s , M); otherwise, output an error and terminate.
Citation Information
Patent Citations
Attribute-based / identity-based heterogeneous revocable signcryption method
CN112436942A
Cited By
New energy equipment trusted access and scheduling method and system, storage medium and equipment
CN122764636A