Decentralized traceable ring signature authentication method and system, and storage medium

By adopting decentralized verifiable secret sharing algorithm and ring signature technology in the digital signature solution, the problem of not being able to provide decentralization and traceability in the existing technology is solved, and a digital signature solution with high security and reliability is achieved.

CN120128342AActive Publication Date: 2025-06-10HUBEI UNIV

Patent Information

Application Number
CN202510318882.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-06-10
Estimated Expiration
2045-03-18

AI Technical Summary

Technical Problem

Existing digital signature solutions cannot provide decentralization and traceability, and there is a risk of traceability of user key leakage and malicious users, which seriously threatens the security and reliability of digital signatures.

Method used

Decentralized verified secret sharing algorithm is used to generate traceable public keys and shard traceable private keys, verify the legitimacy of the signature through ring signature results and public key vectors, and trace the identity of the signer through sharded private keys when the consent traceable user reaches the threshold.

Benefits of technology

Decentralization and traceability are achieved, the security and reliability of digital signatures are improved, and the risks of key leakage and malicious users are reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128342A_ABST
    Figure CN120128342A_ABST
Patent Text Reader

Abstract

The invention discloses a decentralized traceable ring signature authentication method and system, and a storage medium, and the method comprises the steps: carrying out the verification of a ring signature result and a public key vector, and verifying the legality of a signer corresponding to the ring signature result; and if the ring signature result passes verification and the number of the users agreeing to trace is greater than or equal to the threshold, obtaining the index of the signer member by tracing the fragment private key of the user, thereby completing the tracing operation. By adopting the technical scheme provided by the invention, the traceability of anonymity and decentralization can be provided for a signer, and the security and reliability of digital signature are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and in particular relates to an authentication method and system for decentralized traceable ring signatures, and a storage medium. Background Art

[0002] Signature is a basic primitive in cryptography, which provides message integrity, authenticity, and non-repudiation. Among them, integrity means that the message cannot be tampered with during transmission; authenticity means that the receiver believes that this signature comes from the signer; non-repudiation means that the signer cannot deny his signature afterwards.

[0003] In the prior art, a digital signature scheme generally has two components, namely a signature method and a verification method. In the signature method, the system inputs a message m and a private key k, and outputs a digital signature of m; in the authentication method, the system inputs m and its corresponding digital signature, and the output is true or false for legitimacy. In the signature method, once the signature private key is stolen, the attacker can forge the signatures of legitimate users at will.

[0004] The defects of the above prior art are that traditional digital signature schemes cannot provide security properties such as decentralization and traceability, and there are risks of tracing user key leakage and malicious users, seriously threatening the security and reliability of digital signatures. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide an authentication method and system for decentralized traceable ring signatures, and a storage medium.

[0006] To achieve the above object, the present invention adopts the following technical solutions:

[0007] An authentication method for decentralized traceable ring signatures includes:

[0008] Construct a group including ring members;

[0009] Select members of the traced user group to run a decentralized verifiable secret sharing algorithm with a threshold of t to generate a traced public key pk open and respective confidential shard traced private keys sk j,open ;

[0010] Obtain the ring signature result R of the ring members' digital signature of the message m S ;

[0011] According to the ring signature result R S and the public key vector Verify the legitimacy of the ring signature to complete the authentication of the digital signature;

[0012] When the number of users who agree to trace is greater than or equal to t, the corresponding shard tracing private key sk is used. j,open and the signature result R S can trace back to the identity of the signer, thus completing the signature tracing operation.

[0013] Preferably, each member M in the group i has an independent identity identifier id i , a confidential private key sk i and a public key vk i .

[0014] Preferably, obtain the ring signature result R of the ring members' digital signature on the message m S , which specifically includes:

[0015] Prepare the index of the signer using the vector method. The signing user M π generates a vector where b π = 1, and the elements in the remaining positions are all zero. At the same time, let where

[0016] Calculate the hash value corresponding to the public key vector and select a random number

[0017] Calculate six commitment values:

[0018]

[0019] S 1 = γ α H + γ sk G,

[0020]

[0021] where <·,·> represents the inner product of two vectors, Enc pk (m; r) represents encrypting the plaintext m using the public key pk and the random number r with the Elgamal scheme, Enc pk (m; r) = (r·G; m + r·pk);

[0022] Let where || represents the concatenation operation of combining multiple strings into one string and calculate three challenge values:

[0023] y = H 1 (1||str), z = H 1 (2||str), w = H 1 (3||str);

[0024] Calculate two reaction values:

[0025]

[0026] where represents the element-wise multiplication of the components of two vectors;

[0027] Select two random numbers Perform a second-round commitment on the two reaction values and calculate two commitment values:

[0028] T 1 = t 1 G + τ 1 H, T 2 = t 2 G + τ 2 H;

[0029] Calculate the challenge value x for the second round: x = H 2 (w, y, z, T 1 , T 2 , m);

[0030] Calculate the reaction values for the second round:

[0031] τ x = τ 1 ·x + τ 2 ·x 2 ,

[0032] μ = α + β·w + ρ·x,

[0033] z α = γ α + α·x,

[0034] z sk = γ sk + sk π ·x,

[0035] z δ = γ δ + δ·x,

[0036]

[0037] Finally, the ring signature result is

[0038]

[0039] Preferably, according to the ring signature result R S and the public key vector verify the legality of the ring signature to complete the authentication of the digital signature, which specifically includes:

[0040] For a signature The verifier needs to verify four equations. When all the equations are true, the signature is valid; when one of the equations is not true, the signature is invalid:

[0041] calculate y=H 1 (1||str),z=H 1 (2||str),w=H 1 (3||str), x=H 2 (w,y,z,T 1 ,T 2 ,m);

[0042] make Among them, G i ′=y (1-i) G i For all i∈[1,n], the verifier needs to verify whether the following four equations hold:

[0043]

[0044]

[0045]

[0046] z α H+z sk G=S 1 +xA 1 .

[0047] The signature is valid when all the equalities hold; the signature is invalid when there is one equality that does not hold.

[0048] The present invention also provides a decentralized traceable ring signature authentication system, comprising:

[0049] The group module is used to construct a group containing ring members;

[0050] The traceability user group module is used to select traceability user group members to run a decentralized verifiable secret sharing algorithm with a threshold of t to generate a traceability public key pk open And the respective confidential shard traceability private key sk j,open ;

[0051] The signature acquisition module is used to obtain the ring signature result G of the group member's digital signature on the message m S ;

[0052] Verification module, used to verify the result R of the ring signature S , public key vector Verify the legitimacy of the ring signature to complete the authentication of the digital signature;

[0053] The tracing module is used to trace the private key sk of the corresponding shard when the number of users who agree to trace is greater than or equal to t. j,open And the signature result R S The identity of the signer can be traced back, thus completing the signature traceability operation.

[0054] Preferably, each member M in the group i Have an independent identity ID i , the secret private key sk i And the public key vk i .

[0055] The present invention also provides a storage medium, on which a computer program is stored, and the computer program executes an authentication method for a decentralized traceable ring signature when running.

[0056] The present invention converts the ring signature result R S With the public key vector Approve and verify the legitimacy of the signer corresponding to the ring signature result; if the ring signature result R S If the verification is passed and the number of users who agree to trace is greater than or equal to the threshold t, the index of the signer member can be obtained by tracing the user's shard private key, thus completing the tracing operation. This signature can provide decentralization and traceability for the ring group, improving the security and reliability of digital signatures. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0058] Figure 1 The present invention provides a flowchart of a decentralized traceable ring signature authentication method. DETAILED DESCRIPTION

[0059] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0060] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0061] Embodiment 1:

[0062] like Figure 1 As shown, an embodiment of the present invention provides a decentralized traceable ring signature authentication method, including:

[0063] Construct a group containing ring members, where each member M in the group i Have an independent identity ID i , the secret private key sk i And the public key vk i ;

[0064] Select members of the traceability user group to run a decentralized verifiable secret sharing algorithm with a threshold of t to generate a traceability public key pk open And the respective confidential shard traceability private key sk j,open ;

[0065] Get the ring signature result R of the ring member's digital signature on message m S ;

[0066] According to the ring signature result R S , public key vector Verify the legitimacy of the ring signature to complete the authentication of the digital signature;

[0067] When the number of users who agree to trace back is greater than or equal to t, the private key sk is traced by their corresponding shards. j,open And the signature result R S The identity of the signer can be traced back, thus completing the signature traceability operation.

[0068] As an implementation method of the present invention, the system public parameters are set in the group including the ring members, specifically including: the maximum number of users N in the ring, the large prime number p, the elliptic curve group group The N+1 generators G and Map to The secure hash function H 1 , H 2 and mapped to the group The secure hash function H 3 .

[0069] As an implementation of the present invention, the ring member M i Have an independent identity ID i , each generates a confidential private key sk i And the public key vki , which specifically include:

[0070] Each member of the ring M i Random Selection As the private key, generate the verification public key vk i =sk i G, the total number of all public keys is denoted by

[0071] As an implementation method of the embodiment of the present invention, select the traceability user group members to run a decentralized verifiable secret sharing algorithm with a threshold of t to generate a traceability public key pk open And the respective confidential shard traceability private key sk j,open , which specifically include:

[0072] Choose one from arrive An encryption and decryption algorithm in Indicates using the public key pk to encrypt the plaintext x into ciphertext. Indicates using the private key sk to decrypt the ciphertext y into plaintext;

[0073] Each traceability user group member T i Generate their respective public and private key pairs {sk i ,pk i}, and publish the public key pk i ;

[0074] For members of the retroactive user group T i , randomly select a random number a i,0 ,a i,1 ,...,a i,t-1 , generates a polynomial of order t-1

[0075] f i (x) = a i,0 +a i,1 x+...+a i,t-1 x t-1

[0076] Where t≤m-1. And announce A i,0 =a i,0 G,A i,1 =a i,1 Ω,...,A i,t-1 =a i,t-1 G;

[0077] Tracing user group members T i Use User T j The public key pk j Encryption i (j) Get And send it to user T j ;

[0078] When user T j Receive all T from other traceable users i Sent First use your own private key sk j Decryption Get f i (j)', then verify the equation

[0079] f i (j)'G=A i,0 +A i,1 j+...+A i,t-1 j t-1 .

[0080] Only when all verification equations are established, can you trust the shard private key you get. is correct;

[0081] At the same time, all users can get the public key

[0082] As an implementation method of the embodiment of the present invention, the ring signature result R of the ring member digitally signing the message m is obtained. S , which specifically include:

[0083] Prepare the signer's index using the vector method. Signing user M π Generate vector where b π =1, the remaining position elements are all zero, and in

[0084] Calculate the hash value corresponding to the public key vector and choose a random number

[0085] Calculate the six commitment values:

[0086]

[0087] S 1 =γ α H+γ sk G,

[0088]

[0089] Where <·,·> represents the inner product of two vectors, Enc pk (m; r) means using the public key pk and the random number r to encrypt the plaintext m using the Elgamal scheme, Encpk (m; r) = (r·G; m + r·pk);

[0090] make Where || represents the concatenation operation of concatenating multiple strings into one string and calculating three challenge values:

[0091] y=H 1 (1||str),z=H 1 (2||str),w=H 1 (3||str);

[0092] Calculate two reaction values:

[0093]

[0094] in Indicates the multiplication of the corresponding components of two vectors;

[0095] Pick two random numbers Perform a second round of commitment on the two reaction values ​​and calculate two commitment values:

[0096] T 1 =t 1 G+τ 1 H,T 2 =t 2 G+τ 2 H;

[0097] Calculate the challenge value x = H for the second round 2 (w,y,z,T 1 ,T 2 ,m);

[0098] Calculate the reaction value for the second round:

[0099] τ x =τ 1 ·x+τ 2 ·x 2 ,

[0100] μ=α+β·w+ρ·x,

[0101] z α =γ α +α·x,

[0102] z sk =γ sk +sk π ·x,

[0103] z δ =γ δ +δ·x,

[0104]

[0105] The final ring signature result is

[0106]

[0107] As an implementation method of the embodiment of the present invention, according to the ring signature result R S , public key vector Verify the legitimacy of the ring signature to complete the authentication of the digital signature, which specifically includes:

[0108] For a signature The verifier needs to verify four equations. When all the equations are true, the signature is valid; when one of the equations is not true, the signature is invalid:

[0109] calculate y=H 1 (1||str),z=H 1 (2||str),w=H 1 (3||str), x=H 2 (w,y,z,T 1 ,T 2 ,m);

[0110] make Among them, G i ′=y (1-i) G i For all i∈[1,n], the verifier needs to verify whether the following four equations hold:

[0111]

[0112]

[0113]

[0114] z α H+z sk G=S 1 +xA 1 ,

[0115] The signature is valid when all the equalities hold; the signature is invalid when there is one equality that does not hold.

[0116] As an implementation method of the present invention, when the number of users who agree to trace back is greater than or equal to t, the corresponding shard traces the private key sk j,open And the signature result R S And the plaintext m can be traced back to the identity of the signer, thereby completing the signature traceability operation, which specifically includes:

[0117] If the number of users who agree to trace is less than t, it cannot be traced;

[0118] If the number of users who agree to be traced is greater than or equal to t, first use the ring signature result RS and the public key vector Verify the legitimacy of the ring signature. If the signature verification is invalid, it cannot be traced;

[0119] If the signature verification is valid, let the set of traceable user indexes be T'∈[1,n], and calculate the recovery private key

[0120] By recovering the private key sk open Decrypt to get the signer's verification public key Then compare vk in the public key vector The location can be traced back to the corresponding index of the signing user.

[0121] The present invention has the following advantages:

[0122] Decentralization: The signature does not have a central manager. Through ring signatures and verifiable secret sharing, both the signing process and the tracing process are decentralized.

[0123] Traceability: By adding a label item to the zero-knowledge proof of the ring signature, the traceability of the signature is achieved.

[0124] Embodiment 2:

[0125] The embodiment of the present invention also provides a decentralized traceable ring signature authentication system, including:

[0126] The group module is used to construct a group containing ring members;

[0127] The traceability user group module is used to select traceability user group members to run a decentralized verifiable secret sharing algorithm with a threshold of t to generate a traceability public key pk open And the respective confidential shard traceability private key sk j,open ;

[0128] The signature acquisition module is used to obtain the ring signature result G of the group member's digital signature on the message m S ;

[0129] Verification module, used to verify the result R of the ring signature S , public key vector Verify the legitimacy of the ring signature to complete the authentication of the digital signature;

[0130] The tracing module is used to trace the private key sk of the corresponding shard when the number of users who agree to trace is greater than or equal to t. j,open And the signature result R SThe identity of the signer can be traced back, thus completing the signature traceability operation.

[0131] As an implementation method of the present invention, each member M in the group i Have an independent identity ID i , the secret private key sk i And the public key vk i .

[0132] Embodiment 3:

[0133] An embodiment of the present invention further provides a storage medium, on which a computer program is stored, and the computer program executes an authentication method for a decentralized traceable ring signature when running.

[0134] The embodiments described above are only descriptions of the preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Without departing from the design spirit of the present invention, various modifications and improvements made to the technical solutions of the present invention by ordinary technicians in this field should all fall within the protection scope determined by the claims of the present invention.

Claims

1. A decentralized traceable ring signature authentication method, characterized in that: include: Construct a group containing the ring members; Select members of the traceability user group to run a decentralized verifiable secret sharing algorithm with a threshold of t to generate a traceability public key pk open And the respective confidential shard traceability private key sk j,open ; Get the ring signature result R of the ring member's digital signature on message m S ; According to the ring signature result R S , public key vector Verify the legitimacy of the ring signature to complete the authentication of the digital signature; When the number of users who agree to trace back is greater than or equal to t, the private key sk is traced by their corresponding shards. j,open And the signature result R S The identity of the signer can be traced back, thus completing the signature traceability operation.

2. The decentralized traceable ring signature authentication method according to claim 1, characterized in that: Each member of the group M i Have an independent identity ID i , the secret private key sk i And the public key vk i .

3. The decentralized traceable ring signature authentication method according to claim 2, characterized in that: Get the ring signature result R of the ring member's digital signature on message m S , which specifically include: Prepare the signer's index using the vector method. Signing user M π Generate vector where b π =1, the remaining position elements are all zero, and in Calculate the hash value corresponding to the public key vector and select a random number Calculate the six commitment values: S1=γ α H+γ sk G, Where <·,·> represents the inner product of two vectors, Enc pk (m; r) means using the public key pk and the random number r to encrypt the plaintext m using the Elgamal scheme, that is, Enc pk (m; r) = (r·G; m + r·pk); make Where || represents the concatenation operation of concatenating multiple strings into one string and calculating three challenge values: y=H1(1||str), z=H1(2||str), w=H1(3||str); Calculate two reaction values: in Indicates the multiplication of the corresponding components of two vectors; Pick two random numbers Perform a second round of commitment on the two reaction values ​​and calculate two commitment values: T1=t1G+τ1H, T2=t2G+τ2H; Calculate the challenge value of the second round x = H2 (w, y, z, T1, T2, m); Calculate the reaction value for the second round: t x =τ1·x+τ2·x 2 , μ=α+β·w+ρ·x, z α =c α +α·x, from sk =γ sk +sk π ·x, z δ =c δ +δ·x, The final ring signature result is 4. The decentralized traceable ring signature authentication method according to claim 3, characterized in that: According to the ring signature result R S , public key vector Verify the legitimacy of the ring signature to complete the authentication of the digital signature, which specifically includes: For a signature The verifier needs to verify four equations. When all the equations are true, the signature is valid; when one of the equations is not true, the signature is invalid: calculate y=H1(1||str), z=H1(2||str), w=H1(3||str), x=H2(w,y,z,T1,T2,m); make Among them, G i ′=y (1-i) G i For all i∈[1,n], the verifier needs to verify whether the following four equations hold: The signature is valid when all the equalities hold; the signature is invalid when there is one equality that does not hold.

5. A decentralized traceable ring signature authentication system, characterized in that: include: The group module is used to construct a group containing ring members; The traceability user group module is used to select traceability user group members to run a decentralized verifiable secret sharing algorithm with a threshold of t to generate a traceability public key pk open And the respective confidential shard traceability private key sk j,open ; The signature acquisition module is used to obtain the ring signature result R of the group member's digital signature on the message m S ; Verification module, used to verify the result R of the ring signature S , public key vector Verify the legitimacy of the ring signature to complete the authentication of the digital signature; The tracing module is used to trace the private key sk of the corresponding shard when the number of users who agree to trace is greater than or equal to t. j,open And the signature result R S The identity of the signer can be traced back, thus completing the signature traceability operation.

6. The decentralized traceable ring signature authentication system according to claim 5, characterized in that: Each member of the group M i Have an independent identity ID i , the secret private key sk i And the public key vk i .

7. A storage medium, characterized in that: The storage medium stores a computer program, which, when running, executes the decentralized traceable ring signature authentication method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Democratic signature method with threshold tracking

    CN101267308A

  • Identity-based traceable ring signature authentication protocol

    CN107835082A

  • A block chain anonymous transport protocol based on ring signature

    CN109104284A

  • Linkable ring signature method based on anonymous broadcast encryption

    CN109257184A

  • Anonymous revocation ring signature based on public chain and generation and revocation method of anonymous revocation ring signature

    CN110190970A

Cited By

  • Decentralized traceable ring signature method and system based on block chain

    CN120498701A

  • Decentralized traceable ring signature method and system based on blockchain

    CN120498701B

  • Traceable ring-type collaborative signature method and device and electronic equipment

    CN121530591A