Elliptic curve aggregation ring signature method
Through the elliptic curve aggregation ring signature method, the problem of low efficiency of ring signature verification is solved, efficient signature verification and anonymity protection is achieved, and it is suitable for blockchain, Internet of Things and other fields.
Patent Information
- Application Number
- CN202510261384.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-06-03
AI Technical Summary
Ring signatures encounter the efficiency of verifying large amounts of signatures in blockchain, Internet of Things and other fields, resulting in excessive computing resources and time consumption.
The elliptic curve aggregation ring signature method is adopted to achieve aggregation and efficient verification of signatures through parameter generation algorithm, key generation algorithm, ring signature generation and verification algorithm, as well as aggregate ring signature generation and verification algorithm.
It significantly reduces the time and computing resources required for signature verification, improves the anonymity and efficiency of transactions, and is suitable for a variety of scenarios where anonymous signature is required.
Smart Images

Figure CN120090805A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of cryptography, and particularly relates to an elliptic curve aggregate ring signature method. Background Art
[0002] The concept of ring signature was first proposed by Rivest et al. in 2001. Ring signature is a special group signature. Compared with group signature, ring signature has stronger user anonymity. When signing, the signer does not need the help of other members in the member ring and can even keep other members in the ring unaware. It only needs to use its own private key and the public keys of other members to achieve the signature. When verifying the signature, the verifier can only verify that the signature comes from a member of a certain group, but cannot distinguish which specific member it comes from. The anonymity of ring signature makes it applicable to many scenarios where users need identity privacy protection, such as cryptocurrency, anonymous voting, anonymous reporting, anonymous communication, etc. Since it was proposed in 2001, ring signature has quickly become a research hotspot in the field of cryptography. Ring signature schemes based on various mathematical problems have been successively proposed. These problems include the large integer factorization problem, the finite field discrete logarithm problem, and the elliptic curve discrete logarithm problem, etc.
[0003] Compared with the large integer factorization problem and the finite field discrete logarithm problem, the elliptic curve discrete logarithm problem has more advantages. For example, the large integer factorization problem has a long history and wide application. The security of the famous public key encryption algorithm RSA is based on the large integer factorization problem. However, when relatively high security is required, a longer key length is needed and the calculation is relatively complex, resulting in an increase in the cost of key storage and transmission. While for the elliptic curve discrete logarithm problem, under the same security strength, the encryption, decryption, and signature speeds are faster and the required key length is shorter. In addition, the elliptic curve discrete logarithm problem is more difficult to solve than the large integer factorization problem and the discrete logarithm problem. For the elliptic curve cryptosystem based on the elliptic curve discrete logarithm problem, the attacker needs to face more challenging mathematical problems to break the elliptic curve cryptosystem.
[0004] Aggregate signatures were first proposed by Boneh et al. in 2003. Through aggregate signatures, different signatures of different users can be aggregated into one aggregate signature. When transmitting, there is no need to transmit each individual signature, only one aggregate signature needs to be transmitted; when verifying, there is no need to verify each individual signature one by one, and the validity of each individual signature can be determined by verifying only one aggregate signature. Aggregate signatures can not only improve the efficiency of signature transmission, save bandwidth resources, but also improve the efficiency of the signature verification stage. Ordinary digital signature schemes only include a parameter generation algorithm, a signature generation algorithm, and a signature verification algorithm, while aggregate signature schemes add two algorithms on the basis of ordinary digital signature schemes: an aggregate signature algorithm and an aggregate signature verification algorithm. The aggregate signature algorithm can be executed by any user to aggregate each individual signature into one aggregate signature; the aggregate signature verification algorithm can also be executed by any user to determine whether an aggregate signature is valid. If it is valid, it means that each individual signature is valid; if it is invalid, it means that there are invalid signatures among the individual signatures. Aggregate signatures have significant advantages. In scenarios such as blockchain, e-government and contract signing, cloud computing, and federated learning that require batch transmission and verification of digital signatures, they can greatly improve the transmission and verification efficiency of signatures, effectively save bandwidth resources, and reduce the consumption of computing resources. In 2011, in order to overcome the deficiencies of the public key certificate system, Wang Yongbing et al. proposed an identity-based proxy aggregate signature scheme. In 2015, Cao Suzhen et al. proposed an efficient certificateless aggregate signature scheme, reducing the computational overhead problem of signature verification. In 2019, Lunzhi Deng et al. proposed a certificateless short aggregate signature scheme suitable for mobile devices, solving the certificate management problem and facilitating the application of the signature scheme to resource-constrained devices. In 2023, in order to solve the problems of easy leakage of user privacy data and possible tampering of gradient data by the aggregation server in federated learning, Wang Hao et al. proposed a secure federated learning scheme based on secret sharing and aggregate signatures. In 2024, Jiang Lin et al. proposed an identity-based aggregate signature algorithm supporting invalid signature determination, solving the problems of heavy node computing and transmission burdens and low data verification efficiency in current vehicular ad hoc networks.
[0005] Ring signatures can only guarantee the anonymity of transactions, while aggregate signatures can ensure the efficiency of multi-party signature verification. When ring signatures are applied in fields such as blockchain and the Internet of Things, it is often necessary to verify a large number of signatures in a short period of time. For verifiers, this undoubtedly requires a large amount of computing resources and time costs, and it is also easy to cause untimely verification, affecting the efficiency of the entire system. One of the problems encountered by ring signatures in practical applications is how to ensure anonymous and efficient transactions, and aggregate ring signatures can well solve this technical problem. However, there is still little research on aggregate ring signatures at home and abroad, and aggregate ring signatures have great research space and value. Summary of the Invention
[0006] The objective of the present invention is to provide an elliptic curve aggregate ring signature method to ensure the authenticity, efficiency, non-repudiation, and confidentiality of the signer's identity during data transmission, storage, and processing.
[0007] The technical solution adopted by the present invention is an elliptic curve aggregate ring signature method, which is specifically implemented according to the following steps:
[0008] Step 1, parameter generation algorithm;
[0009] Step 2, key generation algorithm
[0010] Step 3, ring signature generation algorithm and ring signature verification algorithm;
[0011] Step 4, aggregate ring signature generation algorithm and aggregate ring signature verification algorithm.
[0012] The present invention is further characterized in that
[0013] Step 1 is specifically implemented according to the following steps:
[0014] The input is the security parameter λ. In practical applications, users can set the security level of the encryption system through λ. Generate a λ-bit prime number p, generate an elliptic curve E over the finite field F p Select a base point P of the elliptic curve E. The order of P is t. Select a subgroup G of (E, +), where + is the point addition operation on the elliptic curve. Select a subgroup G of the multiplicative group of F 1 , where e is a bilinear mapping from G p to G 2 , that is, e: G 1 ×G 2 →G 1 ×G 1 →G 2 Select a secure cryptographic hash function H: {0, 1} * →G 1 , and output the public parameter pp = {p, E, P, t, G 1 , G 2 , e, H}.
[0015] Step 2 is specifically implemented according to the following steps:
[0016] The input is the public parameter pp, and the ring member index i ∈ {1,..., n}, where n is the number of members in the ring. Randomly and uniformly select the private key Calculate the public key pk i = x i ·P, where · is the point multiplication operation on the elliptic curve. Save the private key x i , and output the public key pk i .
[0017] Step 3 is specifically implemented according to the following steps:
[0018] Step 3.1, Ring Signature Generation Algorithm: The inputs are public parameters pp, message m, ring L, and signer's private key x s , for each i, 1 ≤ i ≤ n, randomly select For i, 1 ≤ i ≤ n and i ≠ s, calculate R i = a i ·P; for s, then calculate For each i, 1 ≤ i ≤ n, use the hash function H to calculate h i = H(m, L, R i ), calculate Output the signature σ = (R 1 ,...., R n , r s );
[0019] Step 3.2, Ring Signature Verification Algorithm: The inputs are public parameters pp, message m, ring L, and signature σ. For each i, 1 ≤ i ≤ n, calculate h i = H(m, L, R i ). Verify whether If the equation holds, the signature is valid, output 1; otherwise, the signature is invalid, output 0.
[0020] Step 4 is specifically implemented according to the following steps:
[0021] Step 4.1, Aggregate Ring Signature Generation Algorithm: The inputs are public parameters pp, l signatures σ 1 , σ 2 , σl, where σ i = (R i1 , R i2 ,, R in , r is ), 1 ≤ i ≤ l. Calculate r = r 1s + r 2s +... + rl s . Output the aggregate ring signature as σ = (R 11 ,..., R 1n , R 21 ,..., R 2n ... R l1 ,..., R ln , r).
[0022] Step 4.2, Aggregate Ring Signature Verification Algorithm: The inputs are public parameters pp, message m 1 ,..., m l , ring L 1 ,..., L l , aggregate signature σ. Calculate hij = H(m i , L i , R ij ), 1 ≤ i ≤ l, 1 ≤ j ≤ n;
[0023] Verify whether If the equation holds, all l signatures are valid, output 1; otherwise, there are invalid signatures among the l signatures, output 0.
[0024] The beneficial effects of the present invention are as follows. The elliptic curve aggregate ring signature method: (1) is a signature method constructed based on the elliptic curve ring signature. In terms of security, the security of the scheme can be reduced to the elliptic curve discrete logarithm problem, with strong anti-forgery ability and good anonymity, effectively protecting user privacy. (2) The present invention is an aggregate ring signature method based on elliptic curves and bilinear maps, eliminating the low efficiency problem of multi-user verification of previous ring signatures, and greatly reducing the time and computing resources required for verification. (3) The present invention is a new type of elliptic curve aggregate signature method with a wide range of application scenarios, which can be flexibly compatible and applied to various fields such as electronic voting, electronic cash, and anonymous authentication. Brief Description of the Drawings
[0025] Figure 1 is the flowchart of the elliptic curve aggregate ring signature method of the present invention. Detailed Embodiments
[0026] The present invention will be described in detail below in conjunction with the drawings and specific embodiments.
[0027] The present invention combines elliptic curve cryptography and ring signatures, aiming to optimize the transmission cost and verification efficiency of batch ring signatures. The elliptic curve ring signature is constructed based on the elliptic curve discrete logarithm problem, specifically using point addition and point multiplication operations on elliptic curves, and flexible and efficient bilinear map operations are used during signature verification. In the ring signature process, the confidentiality of the private key and the integrity of the signature are strengthened. Through the encryption transformation of the elliptic curve cryptosystem, the private key of the signer is more securely protected during the generation and verification stages of the ring signature, greatly increasing the difficulty threshold for attackers to break the private key. The traditional ring signature verification process often involves complex calculation steps, requiring one-by-one comparison and verification of multiple signature elements, which is time-consuming. This method uses bilinear maps to efficiently verify aggregate ring signatures, enabling the verifier to complete the validity judgment of multiple ring signatures with just one operation on the aggregated information, greatly reducing the time and computing resources required for verification. Thus, this method can fully play its role in scenarios such as high-security e-government and privacy-sensitive financial transactions, providing better data privacy and reliable security guarantees. The specific basic technologies required for the present invention are as follows:
[0028] An elliptic curve is an infinite number of points defined over a finite field \(F\) of prime order \(q\). q All of these points lie on the Weierstrass curve equation \(E: y\) 2 \(= x\) 3 \(^3+ax + b\), where \(a,b\in F\) q and \(4a\) 3 \(^3+27b\) 2 \(\neq 0\). There exists a generator \(G\in E\) such that \(nG = O\) (\(n\) is a positive integer and \(O\) is the point at infinity).
[0029] A hash function is a mapping from an input domain \(M\) (usually a set of messages of arbitrary length) to an output domain \(Y\) (usually a set of binary sequences of fixed length), i.e., \(H:M\rightarrow Y\). Thus, for any message data as input, mapping the output in this way can ensure the integrity and non - forgeability of the message data.
[0030] The bilinear mapping Weil pairing: For the torsion point group \(E[m]\) of order \(m\) on the elliptic curve \(E\), there exist \(s,t\in E[m]\). \(e\) m \((s,t)\) can be defined as a point \(t\) on the elliptic curve 0 such that \(mt\) 0 \(= t\). Let \(g\) t be a rational function whose divisor is \(\tau\) s which is the translation mapping determined by \(s\). Then it can be proved that \(e\) m \((s,t)\) is an \(m\) - th root of unity, i.e., \(e\) m : \(E[m]\times E[m]\rightarrow\mu\) m , where \(\mu\) m is the group of \(m\) - th roots of unity. The Weil pairing satisfies the bilinear property, i.e., for \(s,t\) 1 , \(t\) 2 \(\in E[m]\), we have \(e\) m \((s,t\) 1 \(+t\) 2 ) \(= e\) m \((s,t\) 1 ) \(e\) m \((s,t\) 2 ) and \(e\) m \((s,t)=e\) m \((t,s)\) -1 .
[0031] The elliptic curve aggregate ring signature method of the present invention, as shown in the process Figure 1 is specifically implemented according to the following steps:
[0032] Step 1: Parameter generation algorithm;
[0033] Step 1 is specifically implemented according to the following steps:
[0034] The input is the security parameter λ, where λ is the security level of the encryption system. Generate a λ-bit prime number p and generate an elliptic curve E over the finite field F p Select a base point P of the elliptic curve E, where the order of P is t, and select a subgroup G of (E, +), where + is the point addition operation on the elliptic curve 1 , and select a subgroup G p of the multiplicative group of F 2 , where e is a bilinear mapping from G 1 to G 2 , that is, e: G 1 ×G 1 →G 2 .
[0035] Select a secure cryptographic hash function H: {0, 1} * →G 1 , and output the public parameters pp = {p, E, P, t, G 1 , G 2 , e, H}.
[0036] Step 2: Key Generation Algorithm;
[0037] Step 2 is specifically implemented according to the following steps:
[0038] The input is the public parameter pp, the ring member index i ∈ {1,..., n}, where n is the number of members in the ring. Randomly and uniformly select the private key Calculate the public key pk i = x i ·P, where · is the point multiplication operation on the elliptic curve, and save the private key x i , and output the public key pk i .
[0039] Step 3: Ring Signature Generation Algorithm;
[0040] Step 3 is specifically implemented according to the following steps:
[0041] The input is the public parameter pp, the message m, the ring L, and the signer's private key x s , and for each i, 1 ≤ i ≤ n, randomly select For i, 1 ≤ i ≤ n and i ≠ s, calculate R i = a i ·P; for s, then calculate For each i, 1 ≤ i ≤ n, use the hash function H to calculate h i = H(m, L, R i ), and calculate Output the signature σ = (R 1 ,...., Rn , r s );
[0042] Step 4, Ring Signature Verification Algorithm;
[0043] Step 4 is specifically implemented according to the following steps:
[0044] The input is the public parameter pp, the message m, the ring L, the signature σ. For each i, 1 ≤ i ≤ n, calculate h i = H(m, L, R i ), and verify whether
[0045] In Step 4, if the equation holds, the signature is valid, output 1; otherwise, the signature is invalid, output 0.
[0046] Step 5, Aggregate Ring Signature Generation Algorithm;
[0047] Step 5 is specifically implemented according to the following steps:
[0048] The input is the public parameter pp, l signatures σ 1 , σ 2 , σl, where σ i = (R i1 , R i2 ,, R in , r is ), 1 ≤ i ≤ l. Calculate r = r 1s + r 2s +... + r ls . Output the aggregate ring signature as σ = (R 11 ,..., R 1n , R 21 ,..., R 2n ... R l1 ,..., R ln , r).
[0049] Step 6, Aggregate Ring Signature Verification Algorithm.
[0050] Step 6 is specifically implemented according to the following steps:
[0051] The input is the public parameter pp, the messages m 1 ,..., m l , the rings L 1 ,..., L l , and the aggregate signature σ. Calculate h ij = H(m i , L i , R ij ), 1 ≤ i ≤ l, 1 ≤ j ≤ n;
[0052] Verify whether If the equation holds, all l signatures are valid and output 1; otherwise, there are invalid signatures among the l signatures and output 0.
[0053] The security and efficiency of the above scheme are analyzed as follows:
[0054] Analysis of correctness: If this scheme is a correct aggregated signature for message m, then:
[0055]
[0056] Since Then For the above formula From the above equations, it can be obtained that if the signature σ is a correct aggregated ring signature for message m, the aggregated signature verification equation holds. Therefore, this scheme has correctness.
[0057] Analysis of anonymity: This scheme is constructed based on ring signature and aggregated signature algorithms. The characteristic of ring signature is anonymity. In addition, in the aggregated signature, it is impossible to determine which specific signer performed the signature, only knowing how many signers there are. Since it is the signature verification of multiple signers, each signer randomly selects parameters when calculating their own signatures, and based on the difficulty of the elliptic curve discrete logarithm problem, external attackers cannot decompose the contributions of each signer from it. Therefore, the scheme has anonymity.
[0058] Analysis of unforgeability: If an attacker wants to forge the aggregated signature, not only does he need to forge the signature of a single signer, but also needs to satisfy the aggregated verification formula This is computationally infeasible because it involves elliptic curve point multiplication operations and the calculation of hash functions, and these operations are difficult to break in cryptography.
[0059] Analysis of efficiency: In terms of signature length, after aggregating l ring signatures, the signature length is |r| + l·n·|R i |, where |·| represents the binary length of the variable, and the sum of the lengths of individual ring signatures is l·|r| + l·n·|R i |. Obviously, |r| + l·n·|R i | ≤ l·|r| + l·n·|R i |, and the aggregated signature is significantly shortened; in terms of computational efficiency, signature aggregation results in an increase of l - 1 elliptic curve point addition operations. Compared with verifying ring signatures one by one, the aggregated signature verification process results in an increase of a multiplication operation on group G 2 However, it should be noted that the aggregated verification process reduces l - 1 bilinear mapping operations. Since group G 2The time consumed by the multiplication operation on it can be ignored, and the complexity of the bilinear mapping operation is obviously higher than that of the point addition operation. Therefore, verifying the aggregate signature is significantly more efficient than verifying the ring signature one by one.
[0060] Through the above specific implementation manners, the security and efficiency of the elliptic curve aggregate ring signature method of the present invention in practical applications can be seen. It can meet the requirement of efficiently performing signature verification operations while ensuring anonymity, and is applicable to various scenarios that require anonymous signatures.
[0061] Example 1
[0062] The elliptic curve aggregate ring signature method of the present invention, the process Figure 1 is shown as follows and is specifically implemented according to the following steps:
[0063] Step 1, Parameter generation algorithm;
[0064] Step 2, Key generation algorithm;
[0065] Step 3, Ring signature generation algorithm;
[0066] Step 4, Ring signature verification algorithm;
[0067] Step 5, Aggregate ring signature generation algorithm;
[0068] Step 6, Aggregate ring signature verification algorithm.
[0069] Example 2
[0070] The elliptic curve aggregate ring signature method of the present invention, the process Figure 1 is shown as follows and is specifically implemented according to the following steps:
[0071] Step 1, Parameter generation algorithm;
[0072] Step 1 is specifically implemented according to the following steps:
[0073] The input is the security parameter λ, where λ is the security level of the encryption system. Generate a λ-bit prime number p, generate an elliptic curve E over the finite field F p Select the base point P of the elliptic curve E, the order of P is t, and select a subgroup G of (E, +) 1 , where + is the point addition operation on the elliptic curve, select a subgroup G p of the multiplicative group of F 2 , e is a bilinear mapping from G 1 to G 2 , that is, e: G 1 ×G 1 →G 2 ,
[0074] Select a secure cryptographic hash function H: {0, 1}* →G 1 , output the public parameters pp = {p, E, P, t, G 1 , G 2 , e, H}.
[0075] Step 2, Key Generation Algorithm;
[0076] Step 3, Ring Signature Generation Algorithm;
[0077] Step 4, Ring Signature Verification Algorithm;
[0078] Step 5, Aggregate Ring Signature Generation Algorithm;
[0079] Step 6, Aggregate Ring Signature Verification Algorithm.
[0080] Embodiment 3
[0081] The elliptic curve aggregate ring signature method of the present invention has a process Figure 1 as shown, and is specifically implemented according to the following steps:
[0082] Step 1, Parameter Generation Algorithm;
[0083] Step 1 is specifically implemented according to the following steps:
[0084] The input is the security parameter λ, where λ is the security level of the encryption system. Generate a λ-bit prime number p, generate an elliptic curve E over the finite field F p Select a base point P of the elliptic curve E, the order of P is t, select a subgroup G of (E, +) 1 , where + is the point addition operation on the elliptic curve, select a subgroup G of the multiplicative group of F p , e is a bilinear mapping from G 2 to G 1 , that is, e: G 2 ×G 1 →G 1 , 2 ,
[0085] Select a secure cryptographic hash function H: {0, 1} * →G 1 , output the public parameters pp = {p, E, P, t, G 1 , G 2 , e, H}.
[0086] Step 2, Key Generation Algorithm;
[0087] Step 2 is specifically implemented according to the following steps:
[0088] The input is the public parameters pp, the ring member index i ∈ {1,..., n}, where n is the number of members in the ring, and randomly and uniformly select a private key Calculate the public key pk i = x i ·P, where · is the point multiplication operation on the elliptic curve, save the private key x i and output the public key pk i .
[0089] Step 3, Ring signature generation algorithm;
[0090] Step 4, Ring signature verification algorithm;
[0091] Step 5, Aggregate ring signature generation algorithm;
[0092] Step 6, Aggregate ring signature verification algorithm.
[0093] Embodiment 4
[0094] The elliptic curve aggregate ring signature method of the present invention has a process Figure 1 as shown, and is specifically implemented according to the following steps:
[0095] Step 1, Parameter generation algorithm;
[0096] Step 1 is specifically implemented according to the following steps:
[0097] The input is the security parameter λ, where λ is the security level of the encryption system, generate a λ-bit prime number p, generate an elliptic curve E over the finite field F p select the base point P of the elliptic curve E, the order of P is t, select a subgroup G of (E, +) 1 , where + is the point addition operation on the elliptic curve, select a subgroup G of the multiplicative group of F p , e is a bilinear mapping from G 2 to G 1 , that is, e: G 2 × G 1 → G 1 , 2 ,
[0098] Select a secure cryptographic hash function H: {0, 1} * → G 1 , output the public parameters pp = {p, E, P, t, G 1 , G 2 , e, H}.
[0099] Step 2, Key generation algorithm;
[0100] Step 2 is specifically implemented according to the following steps:
[0101] The input is the public parameters pp, the ring member index i ∈ {1,..., n}, where n is the number of members in the ring, randomly and uniformly select the private key Calculate the public key pk i =x i ·P, where · is the point multiplication operation on the elliptic curve, saving the private key x i , output the public key pk i .
[0102] Step 3: Ring signature generation algorithm;
[0103] Step 3 is implemented as follows:
[0104] Input is public parameter pp, message m, ring L, signer private key x s , for each i, 1≤i≤n, randomly select For i, 1≤i≤n and i≠s, calculate R i =a i ·P; for s, calculate For each i, 1≤i≤n, use the hash function H to calculate h i =H(m,L,R i ),calculate Output signature σ=(R 1 ,....,R n ,r s );
[0105] Step 4: Ring signature verification algorithm;
[0106] Step 5: Aggregate ring signature generation algorithm;
[0107] Step 6: Aggregate ring signature verification algorithm.
[0108] Example 5
[0109] The elliptic curve aggregate ring signature method of the present invention has the following process: Figure 1 As shown, the specific implementation steps are as follows:
[0110] Step 1: Parameter generation algorithm;
[0111] Step 1 is implemented according to the following steps:
[0112] The input is the security parameter λ, λ is the security level of the encryption system, generates the λ-bit prime number p, and generates the finite field F p On the elliptic curve E, select the base point P of the elliptic curve E, the order of P is t, and select a subgroup G of (E, +) 1 , where + is the point addition operation on the elliptic curve, select an F p The subgroup G of the multiplicative group 2 , e is from G 1 To G 2 The bilinear mapping of e:G 1 ×G1 →G 2 ,
[0113] Select a secure cryptographic hash function H: {0, 1} * →G 1 , and output the public parameters pp = {p, E, P, t, G 1 , G 2 , e, H}.
[0114] Step 2: Key Generation Algorithm;
[0115] Step 2 is specifically implemented according to the following steps:
[0116] The input is the public parameters pp, the ring member index i ∈ {1,..., n}, where n is the number of members in the ring. Randomly and uniformly select the private key Calculate the public key pk i = x i ·P, where · is the point multiplication operation on the elliptic curve, and save the private key x i , and output the public key pk i .
[0117] Step 3: Ring Signature Generation Algorithm;
[0118] Step 3 is specifically implemented according to the following steps:
[0119] The input is the public parameters pp, the message m, the ring L, and the signer's private key x s , and for each i, 1 ≤ i ≤ n, randomly select For i, 1 ≤ i ≤ n and i ≠ s, calculate R i = a i ·P; for s, calculate For each i, 1 ≤ i ≤ n, use the hash function H to calculate h i = H(m, L, R i ), calculate Output the signature σ = (R 1 ,...., R n , r s );
[0120] Step 4: Ring Signature Verification Algorithm;
[0121] Step 4 is specifically implemented according to the following steps:
[0122] The input is the public parameters pp, the message m, the ring L, the signature σ, and for each i, 1 ≤ i ≤ n, calculate h i = H(m, L, R i ), and verify whether
[0123] In step 4, if the equation holds, the signature is valid, output 1; otherwise, the signature is invalid, output 0.
[0124] Step 5, Aggregate Ring Signature Generation Algorithm;
[0125] Step 6, Aggregate Ring Signature Verification Algorithm.
[0126] Example 6
[0127] The elliptic curve aggregate ring signature method of the present invention has the following Figure 1 flow and is specifically implemented according to the following steps:
[0128] Step 1, Parameter Generation Algorithm;
[0129] Step 1 is specifically implemented according to the following steps:
[0130] The input is the security parameter λ, where λ is the security level of the encryption system. Generate a λ-bit prime number p, generate an elliptic curve E over the finite field F p Select a base point P of the elliptic curve E, the order of P is t, select a subgroup G of (E, +), where + is the point addition operation on the elliptic curve, select a subgroup G 1 of the multiplicative group of F p , e is a bilinear mapping from G 2 to G 1 , that is, e: G 2 ×G 1 →G 1 , 2 Select a secure cryptographic hash function H: {0, 1}
[0131] →G * , output the public parameter pp = {p, E, P, t, G 1 , G 1 , G 2 , e, H}.
[0132] Step 2, Key Generation Algorithm;
[0133] Step 2 is specifically implemented according to the following steps:
[0134] The input is the public parameter pp, the ring member index i ∈ {1,..., n}, where n is the number of members in the ring. Randomly and uniformly select the private key Calculate the public key pk i = x i ·P, where · is the point multiplication operation on the elliptic curve, save the private key x i , output the public key pk i .
[0135] Step 3, Ring Signature Generation Algorithm;
[0136] Step 3 is specifically implemented according to the following steps:
[0137] The inputs are the public parameter pp, the message m, the ring L, and the signer's private key x s , for each i, 1 ≤ i ≤ n, randomly select For i, 1 ≤ i ≤ n and i ≠ s, calculate R i = a i ·P; for s, then calculate For each i, 1 ≤ i ≤ n, use the hash function H to calculate h i = H(m, L, R i ), calculate Output the signature σ = (R 1 ,...., R n , r s );
[0138] Step 4, Ring Signature Verification Algorithm;
[0139] Step 4 is specifically implemented according to the following steps:
[0140] The inputs are the public parameter pp, the message m, the ring L, the signature σ, and for each i, 1 ≤ i ≤ n, calculate h i = H(m, L, R i ), and verify whether
[0141] In Step 4, if the equation holds, the signature is valid, output 1; otherwise, the signature is invalid, output 0.
[0142] Step 5, Aggregate Ring Signature Generation Algorithm;
[0143] Step 5 is specifically implemented according to the following steps:
[0144] The inputs are the public parameter pp, l signatures σ 1 , σ 2 , σl, where σ i = (R i1 , R i2 ,, R in , r is ), 1 ≤ i ≤ l. Calculate r = r 1s + r 2s +... + r ls . Output the aggregate ring signature as σ = (R 11 ,..., R 1n , R 21 ,..., R 2n ...R l1 ,..., R ln, r).
[0145] Step 6, Aggregate Ring Signature Verification Algorithm.
Claims
1. Elliptic curve aggregate ring signature method, characterized in that: Follow the steps below to implement it: Step 1: Parameter generation algorithm; Step 2: Key generation algorithm; Step 3: Ring signature generation algorithm; Step 4: Ring signature verification algorithm; Step 5: Aggregate ring signature generation algorithm; Step 6: Aggregate ring signature verification algorithm.
2. The elliptic curve aggregate ring signature method according to claim 1, characterized in that: The step 1 is specifically implemented according to the following steps: The input is the security parameter λ, λ is the security level of the encryption system, generates the λ-bit prime number p, and generates the finite field F p The elliptic curve E on the elliptic curve is selected. The base point P of the elliptic curve E is selected. The order of P is t. A subgroup G1 of (E, +) is selected, where + is the point addition operation on the elliptic curve. An F p The subgroup G2 of the multiplicative group, e is a bilinear mapping from G1 to G2, that is, e:G1×G1→G2, Choose a secure cryptographic hash function H: {0,1} * →G1, output public parameters pp = {p, E, P, t, G1, G2, e, H}.
3. The elliptic curve aggregate ring signature method according to claim 2, characterized in that: The step 2 is specifically implemented according to the following steps: The input is the public parameter pp, the ring member index i∈{1,...,n}, where n is the number of members in the ring, and the private key is randomly selected uniformly Calculate the public key pk i =x i ·P, where · is the point multiplication operation on the elliptic curve, saving the private key x i , output the public key pk i .
4. The elliptic curve aggregate ring signature method according to claim 3, characterized in that: The step 3 is specifically implemented according to the following steps: Input is public parameter pp, message m, ring L, signer private key x s , for each i, 1≤i≤n, randomly select For i, 1≤i≤n and i≠s, calculate R i =a i ·P; for s, calculate For each i, 1≤i≤n, use the hash function H to calculate h i =H(m,L,R i ),calculate Output signature σ=(R1,....,R n ,r s ).
5. The elliptic curve aggregate ring signature method according to claim 4, characterized in that: The step 4 is specifically implemented according to the following steps: The input is the public parameter pp, the message m, the ring L, the signature σ, and for each i, 1≤i≤n, calculate h i =H(m,L,R i ), verify whether 6. The elliptic curve aggregate ring signature method according to claim 5, characterized in that: In step 4, if The equation holds true, the signature is valid, and the output is 1; Otherwise, the signature is invalid and output is 0.
7. The elliptic curve aggregate ring signature method according to claim 6, characterized in that: The step 5 is specifically implemented according to the following steps: The input is a public parameter pp, l signatures σ1, σ2, … σl, where σ i =(R i1 ,R i2 ,…,R in ,r is ), 1≤i≤l; Calculate r = r 1s +r 2s +...+r ls , The output aggregate ring signature is σ=(R 11 ,...,R 1n ,R 21 ,...,R 2n ...R l1 ,...,R ln ,r).
8. The elliptic curve aggregate ring signature method according to claim 7, characterized in that: The step 6 is specifically implemented according to the following steps: The input is the public parameter pp, the message m1,...,m l , ring L1,...,L l , aggregate signature σ, calculate h ij =H(m i ,L i ,R ij ), 1≤i≤l, 1≤j≤n; Verify whether If the equation holds, then all l signatures are valid, and output 1; Otherwise, there is an invalid signature among the l signatures and output 0.