Decentralization anonymous voucher method for post-quantum security
By adopting the technology of promise conversion signature and zero-knowledge proof in the anonymous credential system, the problem of inefficient signature voucher verification by multiple credential issuers in the decentralized environment is solved, and efficient and secure signature voucher verification is achieved.
Patent Information
- Application Number
- CN202510393673.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-24
AI Technical Summary
The existing anonymous credential system is difficult to efficiently verify the signed credentials of multiple credential issuers in a decentralized environment, and cannot resist quantum attacks.
The system is initialized using the method of promise conversion of signatures and zero-knowledge proof to generate public and private keys. Users realize batch verification of signature vouchers through the steps of registering signature vouchers, issuing signature vouchers, proving individual vouchers and aggregating signature vouchers.
It improves the verification efficiency of signature credentials, reduces user operation burden and communication costs, reduces system complexity, and has post-quantum security.
Smart Images

Figure CN120200818A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security, and particularly relates to a post-quantum secure decentralized anonymous credential method. Background Art
[0002] Digital identity is extremely crucial in the network virtual world. At the same time, identity authentication and authorization are vital security foundations in the digital world. Their role is to verify that the communicating party is indeed the identity it claims to be and to strengthen access control over digital resources (such as services). Anonymous credentials are an identity authentication tool that uses modern cryptographic techniques to achieve privacy protection. It can assert the user's identity while maintaining the user's privacy. By providing minimal information disclosure, users can still meet various verification requirements while protecting their privacy. It can solve problems such as privacy protection, identity tracking, and data minimization. Anonymous credentials have two core security features: Firstly, unlinkability, which ensures that no verifier can link multiple uses of the same credential; Secondly, unforgeability, meaning that a valid credential cannot be generated without the issuer's consent. By using pseudonyms, users do not have to disclose their real identities when applying for and presenting credentials to the credential issuer and the verifier, which provides strong protection for user privacy.
[0003] Most existing anonymous credential systems are in a centralized environment setting, that is, only consider the case where one credential issuer issues credentials to users, and mainly conduct research in terms of security, bandwidth, and computing costs. With the increasing demand of real-world applications and the development of decentralization, this centralized identity management is gradually turning to distributed identity management. In a decentralized environment, when relying on existing anonymous credential systems, when a user wants to prove that they have credentials from multiple credential issuers, they usually need to provide multiple independent certificates. At this time, the size of the credential will increase linearly with the number of issuers, which not only increases the user's operation burden, increases communication costs, but also affects the efficiency and accuracy of the authentication process. In addition, even considering the case of multiple credential issuers, most of these studies are based on the pre-quantum hypothesis and cannot resist quantum attacks. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to overcome the above-mentioned disadvantages of the prior art and provide a post-quantum secure decentralized anonymous credential method with high security, wide application range, higher efficiency, and correct signature.
[0005] The technical solution for solving the above technical problem consists of the following steps:
[0006] System Initialization
[0007] Use the initialization method of commitment conversion signature and zero-knowledge proof to obtain its corresponding parameters. An honest user in the message Select a message m as its own private key usk, and K honest credential issuers respectively generate their own public keys pk using the key generation method of commitment-converted signature i , private key sk i , where i is a positive integer less than or equal to K, and K is a finite positive integer.
[0008] (2) User registers signature credentials
[0009] The user selects randomness R in the randomness space , uses the commitment method of commitment-converted signature to commit its own private key usk, obtains the commitment comm, and generates the evidence π of the zero-knowledge proof about this commitment. The user takes the commitment and the evidence of the zero-knowledge proof as pseudonyms and registers with K credential issuers in the form of pseudonyms respectively. The credential issuers verify whether the pseudonyms are correct through the verification method of zero-knowledge proof.
[0010] (3) Credential issuers issue signature credentials
[0011] The user's pseudonym passes the verification of K credential issuers, and K credential issuers respectively generate signature credentials σ for the user using the signature method of commitment-converted signature i .
[0012] (4) User proves a single credential
[0013] The user selects another randomness R′, randomizes the commitment comm using the randomization method of commitment-converted signature, obtains the commitment comm′ after randomizing the same message, and the user uses the conversion method of commitment-converted signature to obtain the converted signature credential σ i from the signature credential σ i ′. The user forms a pseudonym by combining the randomized commitment comm′ and the evidence π′, and sends the converted signature credential σ i ′ and the pseudonym to the verifier for verification, where the evidence π′ is the evidence of the zero-knowledge proof about the randomized commitment comm′.
[0014] (5) Verifier verifies a single credential
[0015] The verifier uses the verification method of commitment-converted signature to verify each converted signature credential σ i ′, and verifies whether the pseudonym is correct through the verification method of zero-knowledge proof.
[0016] (6) User proves aggregated signature credentials
[0017] The user selects another randomness R' and randomizes the commitment comm using the randomization method of the commitment conversion signature to obtain the randomized commitment comm'; the user uses the aggregate signature generation method to aggregate the signature vouchers σ1, σ2, …, σ K issued by K credential issuers to obtain the aggregate signature voucher σ' of the randomized commitment comm' agg-t , and forms a pseudonym with the randomized commitment comm' and the proof π', and sends the aggregate signature voucher σ' agg-t and the pseudonym to the verifier for verification, where the proof π' is the proof of the zero-knowledge proof regarding the randomized commitment comm'.
[0018] (7) The verifier verifies the aggregate signature voucher
[0019] The verifier uses the aggregate signature verification method to verify the aggregate signature voucher σ' agg-t and verifies whether the pseudonym is correct through the verification method of the zero-knowledge proof.
[0020] In the system initialization of step (1) of the present invention, the initialization method of the commitment conversion signature is as follows:
[0021] 1) Construct the underlying algebraic structure ring and the ring
[0022]
[0023] f(X) = X N + 1
[0024] where q1 and q2 are prime moduli, q1 and q2 are large prime numbers that meet the security requirements, and q1 is less than q2, represents that the highest coefficient of the polynomial in the ring is q2, N represents the number of the highest degree of the polynomial x in the ring, N is a finite integer, and generate the public matrix A required for the commitment:
[0025]
[0026] A2 = (I l , A'2)
[0027] where,
[0028] 2) Set the message space and the randomness space
[0029] Construct the message space according to the following formula and the randomness space
[0030]
[0031] Among them, is a ring with a subset consisting of 2 ξ non - zero binary polynomial elements, and ξ takes values as finite positive integers. is a subset of elements on the ring with an infinite norm less than 1.
[0032] 3) Select a random matrix and Gaussian parameters
[0033] Select a random matrix D and Gaussian parameter α according to the following formula
[0034]
[0035] Among them, α takes values as finite real numbers.
[0036] 4) Determine the challenge space
[0037] Determine the challenge space according to the following formula
[0038]
[0039] Among them, κ represents the maximum value of the 1 - norm of the elements in the challenge space, and κ is a finite positive integer.
[0040] 5) Set the number K of credential issuers;
[0041] 6) Generate the common reference string crs i
[0042] Adopt the initialization method of the zero - knowledge proof system Π 1 to generate the common reference string crs i , and the zero - knowledge proof system Π 1 is a non - interactive zero - knowledge proof system for the language challenge space . The language is shown in Equation (1):
[0043]
[0044] Among them, l, τ, k, n represent dimensions and take values as finite positive integers, γ1 represents the norm bound of the transformed signature and takes values as finite real numbers. is the set composed of the differences (except 0) of two elements in the challenge space .
[0045] 7) Generate the common reference string crs
[0046] Adopt the initialization method of the zero - knowledge proof system Π 2 to generate the common reference string crs, and the zero - knowledge proof system Π2 is a zero - knowledge proof system for a language The challenge space is for the language as shown in Equation (2):
[0047]
[0048] where γ represents the norm bound of the transformed aggregated signature, and γ takes a finite positive real number value.
[0049] 8) Output the public parameters
[0050] Output the public parameters params according to the following formula:
[0051]
[0052] In the system initialization step (1) of the present invention, the key generation method is as follows:
[0053] 1) Generate the private key
[0054] K credential issuers generate the private key sk in the following manner i :
[0055] Select
[0056] 2) Generate the public key
[0057] The public key pk i consists of the matrix A 0,i , the matrix B, and the non - zero vector u.
[0058] 2 - 1) A 0,i = D·T i + G (3)
[0059]
[0060]
[0061]
[0062] where is an identity matrix, and τ takes a finite positive integer value.
[0063] 2 - 2) Select the matrix
[0064] 2 - 3) Select the non - zero vector
[0065] In the signature - issuing step (3) of the present invention by the credential issuer, the signature method is as follows:
[0066] 1) Parse the commitment comm,
[0067] Obtained by the commitment generation method:
[0068]
[0069] Parse the commitment comm into C1, C2:
[0070]
[0071] Wherein,
[0072] 2) Generate the verification matrix
[0073] Generate the verification matrix F according to the following formula comm,i :
[0074] F comm,i =[[D|A 0,i |B comm |A2],
[0075] B comm =B + C2;
[0076] 3) Generate the signature
[0077] Generate the signature Sign by the sampling method comm,i :
[0078]
[0079] Output the signature Sign comm,i .
[0080] In step (4) of the user proving a single credential of the present invention, the conversion method is as follows:
[0081] 1) Parse the signature
[0082] Parse the signature Sign according to the following formula comm,i :
[0083]
[0084] Wherein,
[0085] 2) Parse the commitment
[0086] Obtain the commitment comm by the commitment method, and parse the commitment comm into C1, C2;
[0087] 3) Parse the randomized commitment
[0088] Select a randomness \(R'\) in the randomness space and obtain the randomized commitment \(comm'\) using the randomization method.
[0089]
[0090] Parse the randomized commitment \(comm'\) into \(C'_1, C'_2\):
[0091]
[0092] where,
[0093] 4) Generate the transformed temporary signature
[0094] Generate the transformed temporary signature \(Sign\) according to the following formula comm′,i :
[0095] s' 4,i = s 4,i - R'^2 · s 3,i ,
[0096] With probability assign to \(Sign\) comm′,i , if \(Sign\) comm′,i is not assigned, execute step 3) to parse the randomized commitment.
[0097] where, M is the parameter of rejection sampling representing the transformation cost, and are two distributions on.
[0098] 5) Generate the verification matrix
[0099] Generate the verification matrix \(F\) according to the following formula comm′,i :
[0100] F comm′,i = [[D|A 0,i |B comm′ |A2],
[0101] B comm′ = B + C'_2.
[0102] 6) Generate the signature
[0103] Use the proof method of the zero - knowledge proof system \(\Pi\) 1 to obtain the evidence \(Sign'\) comm′,i , and prove through the zero - knowledge proof system \(\Pi\) 1 that \(Sign\) comm′,i has a small \(l_2\) norm and satisfies \(F\) comm′, i · Signcomm′,i = u,
[0104] where F comm′,i represents the verification matrix, Sign comm′,i represents the transformed signature, and u represents the public key.
[0105] In step (5) of the present invention, when the verifier verifies a single credential, the signature verification method is as follows:
[0106] 1) Parse the commitment
[0107] Use the commitment method to obtain the commitment comm, and parse the commitment comm into C1 and C2.
[0108] 2) Generate the verification matrix
[0109] Generate the verification matrix F according to the following formula comm,i :
[0110] F comm,i = [[D|A 0,i |B comm |A2],
[0111] 3) Verify the signature type
[0112] The signature type verification method is divided into the following two types.
[0113] 3-1) The signature is a short vector with an l2 norm less than γ1. Check whether the product of the verification matrix F comm,i and the signature σ i is equal to u.
[0114] 3-2) The signature is the evidence of the zero-knowledge proof system Π 1 . Use the verification method of the zero-knowledge proof system Π 1 to verify the signature.
[0115] In step (6) of the present invention, when the user proves the aggregated credential, the aggregated signature generation method is as follows:
[0116] 1) Determine the weight
[0117] Determine the weight e of each signature S 2,i part according to formula (4) i :
[0118]
[0119]
[0120] where is that the random oracle requires its value range |F| to be exponential in the security parameter, The random oracle machine is required to output a small polynomial with a definite Hamming weight ω, where ω ∈ {0, ±1, ±2}, that is
[0121] 2) Generate the original aggregated signature
[0122] Aggregate K original signatures according to the following formula to generate the original aggregated signature sig agg :
[0123] sig agg =(s1, s 2,i , s3, s4),
[0124]
[0125] 3) Generate the transformed aggregated signature
[0126] Transform the original aggregated signature sig agg using the randomness R′ according to the following formula to obtain the transformed temporary aggregated signature sig corresponding to the randomized commitment comm′ agg-t :
[0127] sig agg-t =(s1, s 2,i , s3, s′4)
[0128] s′4 = s4 - R′2s3,
[0129] 4) Generate the aggregated verification matrix and the aggregated verification vector
[0130] Generate the aggregated verification matrix F agg and the aggregated verification vector u agg :
[0131] F agg =[D|A 0,1 |A 0,2 |,...,|A 0,k |B + C′2|A2],
[0132]
[0133] 5) Generate the aggregated signature
[0134] Adopt the proof method of the zero - knowledge proof system Π 2 to obtain the evidence Sign′ agg-t , as the final aggregated signature, through the zero - knowledge proof system Π for the language 2 , prove that is small in l2 - norm and satisfies
[0135] Among them, F agg represents an aggregation verification matrix, represents a transformed aggregation signature, and u agg represents an aggregation verification vector.
[0136] In step (7) of the present invention where the verifier verifies the aggregation credential, the method for verifying the aggregation signature is as follows:
[0137] 1) Determine the weight
[0138] Determine the weight e according to the following formula i :
[0139]
[0140] 2) Generate the aggregation verification matrix and the aggregation verification vector
[0141] Generate the aggregation verification matrix F according to the following formula agg and the aggregation verification vector u agg :
[0142] F agg = [d|A 0,1 |A 0,2 |,...,|A 0,K |B + C′2|A2],
[0143]
[0144] 3) Verify the aggregation signature
[0145] Adopt the verification method of the zero - knowledge proof system Π 2 to verify whether the aggregation signature is correct.
[0146] Since the present invention adopts the aggregation signature, it realizes the batch verification of signature credentials, aggregates multiple signature credentials into a single signature credential, and ensures the correctness of multiple signature credentials by verifying the correctness of the aggregation signature credential. The norm of the signature credential is at a sub - linear level of the number of issuers, improving the verification efficiency of the signature credential, reducing the operation burden and communication cost of users, and lowering the complexity of the system. The present invention has the advantages of high correctness, high verification efficiency of signature credentials, low communication cost, and low system complexity, and can be used for post - quantum - secure decentralized anonymous credentials. Brief Description of the Drawings
[0147] Figure 1 is a schematic flow diagram of Example 1 of the present invention. Detailed Embodiment
[0148] The present invention will be further described in detail below with reference to the drawings and embodiments, but the present invention is not limited to the following embodiments.
[0149] Example 1
[0150] In Figure 1 , the post - quantum - secure decentralized anonymous credential method of this example consists of the following steps:
[0151] (1) System initialization
[0152] Use the initialization method of commitment - conversion signature and zero - knowledge proof to obtain its corresponding parameters. An honest user selects a message m in the message space as its private key usk, and K honest credential issuers respectively use the key generation method of commitment - conversion signature to generate their respective public keys pk i , private key sk i , where i is a positive integer less than or equal to K, and K ranges from 2 to 50. In this example, K is taken as 20.
[0153] The initialization method of the commitment - conversion signature in this example is as follows:
[0154] 1) Construct the underlying algebraic structure rings and rings
[0155]
[0156] f(X)=X N + 1
[0157] where q1, q2 are prime moduli, q1, q2 are large prime numbers that meet the security requirements, and q1 is less than q2. In this example, q1 is taken as 2 24 - 75, q2 is taken as 2 79 - 67, represents that the highest coefficient of the polynomial in the ring is q2, N represents the number of the highest degrees of the polynomial x in the ring, and N is at least 2 7 In this example, N is taken as 2 11 , and generate the public matrix A required for commitment:
[0158]
[0159] A2=(I l , A′2)
[0160] where,
[0161] 2) Set the message space and randomness space
[0162] Construct the message space according to the following formula and randomness space
[0163]
[0164] Among them, is a subset of the ring consisting of 2 ξ non-zero binary polynomial elements, and ξ takes values from 2 5 to 2 10 . In this embodiment, the value of ξ is 2 7 . is a subset of the elements on the ring whose infinity norm is less than 1.
[0165] 3) Select a random matrix and Gaussian parameters
[0166] Select a random matrix D and Gaussian parameter α according to the following formula:
[0167]
[0168] Among them, α takes values from 2 7 to 2 30 . In this embodiment, the value of α is 2 20.14 .
[0169] 4) Determine the challenge space
[0170] Determine the challenge space according to the following formula
[0171]
[0172] Among them, κ represents the maximum value of the 1-norm of the elements in the challenge space, k takes values from 2 to 20, and in this embodiment, the value of k is 14.
[0173] 5) Set the number K of credential issuers.
[0174] Set the number of credential issuers to K, where K takes values from 20 to 50, and in this embodiment, the value of K is 20.
[0175] 6) Generate the common reference string crs i
[0176] Use the initialization method of the zero-knowledge proof system Π 1 to generate the common reference string crs i , and the zero-knowledge proof system Π 1 is a non-interactive zero-knowledge proof system for the language challenge space . The language is shown in Equation (1):
[0177]
[0178] Among them, e, τ, k, and n represent dimensions, l, τ, k, and n take values from 1 to 10. In this embodiment, l and n take the value of 1, τ takes the value of 7, k takes the value of 4, γ1 represents the norm bound of the transformed signature, and γ1 takes a finite positive real number. In this embodiment, γ1 takes the value of 2 28.3 , is the challenge space is the set composed of the differences of two elements in
[0179] 7) Generate the common parameter crs
[0180] Adopt the initialization method of the zero - knowledge proof system Π 2 to generate the common parameter crs. The zero - knowledge proof system Π 2 is a zero - knowledge proof system regarding the language whose challenge space is The language is as shown in Equation (2):
[0181]
[0182] ‖x‖≤γ, B·x = f·u} (2)
[0183] where γ represents the norm bound of the transformed aggregated signature, γ takes a finite positive real number, and in this embodiment, γ takes the value of 5×2 28..3 ;
[0184] 8) Output the common parameter
[0185] Output the common parameter params according to the following formula:
[0186]
[0187] The key generation method of this embodiment is as follows:
[0188] 1) Generate the private key
[0189] K credential issuers generate the private key sk in the following way i :
[0190] Select
[0191] 2) Generate the public key
[0192] The public key pk i consists of the matrix A 0,i , the matrix B, and the non - zero vector u;
[0193] 2 - 1) A 0,i = D·T i + G (3)
[0194]
[0195]
[0196] Among them, is an identity matrix, τ takes values from 1 to 10, and the value of τ is the same as that in step 6) of step (1) of this embodiment.
[0197] 2-2) Select the matrix
[0198] 2-3) Select a non-zero vector
[0199] (2) User registers a signature credential
[0200] The user selects randomness R in the randomness space and uses the commitment method of commitment conversion signature to commit his private key usk, obtaining a commitment comm, and generating an evidence π of zero-knowledge proof for this commitment. The user takes the commitment and the evidence of zero-knowledge proof as pseudonyms and registers with K credential issuers in the form of pseudonyms respectively. The credential issuers verify whether the pseudonyms are correct through the verification method of zero-knowledge proof.
[0201] The commitment method of this step has been disclosed in the paper "Lattice-based Commit-Transferrable Signatures and Applications to Anonymous Credentials" in IACR Cryptol. ePrint Arch.
[0202] (3) The credential issuer issues a signature credential
[0203] The user's pseudonym passes the verification of K credential issuers, and the K credential issuers respectively use the signature method of commitment conversion signature to generate a signature credential σ for the user i .
[0204] The signature method of this embodiment is as follows:
[0205] 1) Parse the commitment comm
[0206] Obtained by using the commitment generation method:
[0207]
[0208] Parse the commitment comm into C1, C2:
[0209]
[0210] Among them,
[0211] 2) Generate a verification matrix
[0212] Generate a verification matrix F according to the following formula comm,i :
[0213] F comm,i = [[D|A 0,i |B comm |A2],
[0214] B comm = B + C2.
[0215] 3) Generate a signature
[0216] Generate a signature Sign using the sampling method comm,i :
[0217]
[0218] Output the signature Sign comm,i .
[0219] (4) User proves a single credential
[0220] The user selects another randomness R', randomizes the commitment comm using the randomization method of commitment conversion signature, obtains the commitment comm' after randomizing the same message, and the user uses the conversion method of commitment conversion signature to obtain the converted signature credential σ i from the signature credential σ i '. The user forms a pseudonym by combining the randomized commitment comm' and the evidence π', and sends the converted signature credential σ i ' and the pseudonym to the verifier for verification, where the evidence π' is the evidence of zero-knowledge proof regarding the randomized commitment comm'.
[0221] The conversion method of this embodiment is as follows:
[0222] 1) Parse the signature
[0223] Parse the signature Sign according to the following formula comm,i :
[0224]
[0225] Among them,
[0226] 2) Parse the commitment
[0227] Obtain the commitment comm using the commitment method, and parse the commitment comm into C1, C2.
[0228] 3) Parse the randomized commitment
[0229] Select a randomness \(R'\) in the randomness space and obtain the randomized commitment \(comm'\) using the randomization method:
[0230]
[0231] Parse the randomized commitment \(comm'\) into \(C'_1, C'_2\):
[0232]
[0233] where
[0234] 4) Generate the transformed temporary signature
[0235] Generate the transformed temporary signature \(Sign\) according to the following formula comm′,i :
[0236] \(s'\) 4,i \(= s\) 4,i \(- R'^2\cdot s\) 3,i ,
[0237] With probability assign to \(Sign\) comm′,i . If \(Sign\) comm′,i is not assigned, execute step 3) to parse the randomized commitment.
[0238] where \(M\) is the parameter of rejection sampling representing the transformation cost, and are two distributions on
[0239] 5) Generate the verification matrix
[0240] Generate the verification matrix \(F\) according to the following formula comm′,i :
[0241] \(F\) comm′,i \(= [[D|A\) 0,i |B\) comm′ |A2],
[0242] \(B\) comm′ \(= B + C'_2\).
[0243] 6) Generate the signature
[0244] Obtain the proof \(Sign'\) 1 using the proof method of the zero - knowledge proof system \(\Pi\) comm′,i , and prove through the zero - knowledge proof system \(\Pi\) 1 that \(Sign\) comm′,i has a small \(l_2\) norm and satisfies \(F\)comm′,i · Sign comm′,i = u,
[0245] where F comm′,i represents the verification matrix, Sign comm′,i represents the transformed signature, and u represents the public key.
[0246] (5) The verifier verifies a single credential
[0247] The verifier verifies each transformed signature credential σ i ′ using the verification method of the committed transformed signature and verifies whether the pseudonym is correct through the verification method of zero - knowledge proof.
[0248] The signature verification method of this embodiment is as follows:
[0249] 1) Parse the commitment
[0250] Obtain the commitment comm using the commitment method and parse the commitment comm into C1, C2.
[0251] 2) Generate the verification matrix
[0252] Generate the verification matrix F according to the following formula comm,i :
[0253] F comm,i = [[D|A 0,i |B comm |A2],
[0254] 3) Type - verify the signature
[0255] The type - verification signature method is divided into the following two types:
[0256] 3 - 1) The signature is a short vector with an e2 norm less than γ1. Check whether the product of the verification matrix F comm,i and the signature σ i is equal to u.
[0257] 3 - 2) The signature is the evidence of the zero - knowledge proof system Π 1 . Use the verification method of the zero - knowledge proof system Π 1 to verify the signature.
[0258] (6) The user proves the aggregated signature credential
[0259] The user selects another randomness R′ and randomizes the commitment comm using the randomization method of the committed transformed signature to obtain the randomized commitment comm′; the user aggregates the signature credentials σ1, σ2, …, σ K issued by K credential issuers using the aggregated signature generation method to obtain the aggregated signature credential σ′ agg-t, form a pseudonym by combining the randomized commitment comm′ and the proof π′, and aggregate the signature credential σ′ agg-t and send the pseudonym to the verifier for verification, where the proof π′ is the proof of the zero - knowledge proof regarding the randomized commitment comm′.
[0260] The method for generating the aggregate signature in this embodiment is as follows:
[0261] 1) Determine the weight
[0262] Determine the weight e of each signature S part according to Equation (4) 2,i : i :
[0263]
[0264]
[0265] where is that the random oracle requires its range |F| to be exponential in the security parameter is that the random oracle requires its output to be a small polynomial and have a definite Hamming weight ω, ω ∈ {0, ±1, ±2}, and in this embodiment, ω takes the value of 1, that is
[0266]
[0267] 2) Generate the original aggregate signature
[0268] Aggregate K original signatures according to the following formula to generate the original aggregate signature sig agg :
[0269] sig agg =(s1, s 2,i , s3, s4),
[0270]
[0271] 3) Generate the transformed aggregate signature
[0272] Transform the original aggregate signature sig agg with randomness R′ according to the following formula to obtain the transformed temporary aggregate signature sig agg-t corresponding to the randomized commitment comm′:
[0273] sig agg-t =(s1, s 2,i , s3, s′4)
[0274] s′4 = s4 - R′2s3,
[0275] 4) Generate the aggregate verification matrix and the aggregate verification vector
[0276] Generate the aggregated verification matrix F according to the following formula agg and the aggregated verification vector u agg :
[0277] F agg = [D|A 0,1 |A 0,2 |,...,|A 0,k |B + C′2|A2],
[0278]
[0279] 5) Generate the aggregated signature
[0280] Obtain the proof Sign′ through the proof method of the knowledge proof system Π 2 as the final aggregated signature. Through the zero - knowledge proof system Π agg-t about the language of the knowledge proof system Π 2 , prove that is small in l2 - norm and satisfies where F agg represents the aggregated verification matrix, represents the transformed aggregated signature, and u agg represents the aggregated verification vector.
[0281] (7) The verifier verifies the aggregated signature credential
[0282] The verifier uses the aggregated signature verification method to verify the aggregated signature credential σ′ agg-t and verifies whether the pseudonym is correct through the verification method of zero - knowledge proof.
[0283] The aggregated signature verification method of this embodiment is as follows:
[0284] 1) Determine the weight
[0285] Determine the weight e according to the following formula i :
[0286]
[0287] 2) Generate the aggregated verification matrix and the aggregated verification vector
[0288] Generate the aggregated verification matrix F according to the following formula agg and the aggregated verification vector u agg :
[0289] F agg = [D|A 0,1 |A 0,2 |,...,|A 0,K |B + C′2|A2],
[0290]
[0291] 3) Verify the aggregated signature
[0292] Adopt the verification method of the zero - knowledge proof system Π 2 to verify whether the aggregated signature is correct.
[0293] Since the present invention adopts the aggregated signature, batch verification of signature vouchers is realized. Multiple signature vouchers are aggregated into a single signature voucher. By verifying the correctness of the aggregated signature voucher, the correctness of multiple signature vouchers is ensured. The norm of the signature voucher is at a sub - linear level of the number of issuers, improving the verification efficiency of the signature voucher, reducing the operation burden and communication cost of users, and lowering the complexity of the system.
[0294] Complete the post - quantum - secure decentralized anonymous credential method.
[0295] Example 2
[0296] The post - quantum - secure decentralized anonymous credential method of this example consists of the following steps:
[0297] (1) System initialization
[0298] Adopt the initialization method of commitment - conversion signature and zero - knowledge proof to obtain its corresponding parameters. An honest user selects a message m in the message space as its own private key usk. K honest credential issuers respectively adopt the key generation method of commitment - conversion signature to generate their own public keys pk i , private keys sk i , where i is a positive integer less than or equal to K, and K ranges from 2 to 50. In this example, K is taken as 2.
[0299] The initialization method of the commitment - conversion signature in this example is as follows:
[0300] 1) Construct the underlying algebraic structure ring and ring
[0301]
[0302] f(X)=X N +1
[0303] where q1, q2 are prime moduli, q1, q2 are large prime numbers meeting the security requirements, and q1 is less than q2. In this example, q1 is taken as 2 24 - 75, q2 is taken as 2 79 - 67, represents that the highest coefficient of the polynomial in the ring is q2, and N represents the highest degree of the polynomial x in the ring. N is at least 27 , in this embodiment, N takes the value of 2 7 , generate the public matrix A required for the commitment:
[0304]
[0305] A2 = (I l , A′2)
[0306] where
[0307] 2) Set the message space and the randomness space
[0308] Construct the message space according to the following formula and the randomness space
[0309]
[0310] where is a subset of the ring consisting of 2 ξ non-zero binary polynomial elements, and ξ takes the value of 2 5 ~2 10 , in this embodiment, ξ takes the value of 2 5 , is a subset of the elements on the ring with an infinite norm less than 1.
[0311] 3) Select the random matrix and the Gaussian parameter
[0312] Select the random matrix D and the Gaussian parameter α according to the following formula:
[0313]
[0314] where α takes the value of 2 7 ~2 30 , in this embodiment, α takes the value of 2 7 .
[0315] 4) Determine the challenge space
[0316] Determine the challenge space according to the following formula
[0317]
[0318] where κ represents the maximum value of the 1-norm of the elements in the challenge space, κ takes the value of 2 to 20, and in this embodiment, κ takes the value of 2.
[0319] 5) Set the number K of credential issuers.
[0320] Set the number of credential issuers to K, where K ranges from 20 to 50, and in this embodiment, K is set to 20.
[0321] 6) Generate the common reference string crs i
[0322] The expression of formula (1) in this embodiment is the same as that in Embodiment 1.
[0323] In formula (1), l, τ, k, n represent dimensions, and the values of l, τ, k, n range from 1 to 10. In this embodiment, the values of l and n are 5, the value of τ is 1, and the value of k is 1. The meanings and value ranges of other parameters and variables are the same as those in Embodiment 1.
[0324] 7) Generate the common reference string crs
[0325] This step is the same as that in Embodiment 1.
[0326] 8) Output the common reference string
[0327] This step is the same as that in Embodiment 1.
[0328] The key generation method in this embodiment is as follows:
[0329] 1) Generate the private key
[0330] This step is the same as that in Embodiment 1.
[0331] 2) Generate the public key
[0332] The public key pk i consists of matrix A 0,i , matrix B, and non-zero vector u;
[0333] 2-1) The expression (3) of matrix A 0,i is the same as that in Embodiment 1.
[0334] In formula (3), the value of τ ranges from 1 to 10, and the value of τ is the same as that in step 6) of step (1) in this embodiment. The meanings of other parameters and variables are the same as those in Embodiment 1.
[0335] Other steps of this step are the same as those in Embodiment 1.
[0336] (2) The user registers and signs the credential
[0337] This step is the same as that in Embodiment 1.
[0338] (3) The credential issuer issues the signed credential
[0339] This step is the same as that in Embodiment 1.
[0340] (4) User proves a single credential
[0341] This step is the same as that in Embodiment 1.
[0342] (5) Verifier verifies a single credential
[0343] This step is the same as that in Embodiment 1.
[0344] (6) User proves an aggregated signature credential
[0345] The method for generating the aggregated signature in this embodiment is as follows:
[0346] 1) Determine the weight
[0347] Determine the weight e of each signature S part according to Equation (4) 2,i The weight e of the part i :
[0348] The expression of Equation (4) is the same as that in Embodiment 1.
[0349] In Equation (4), is a random oracle that requires its output to be a small polynomial and have a definite Hamming weight ω, ω ∈ {0, ±1, ±2}, and ω takes the value of -1 in this embodiment. The meanings represented by other parameters and variables are the same as those in Embodiment 1.
[0350] Other steps of this step are the same as those in Embodiment 1.
[0351] Other steps are the same as those in Embodiment 1. A post - quantum - secure decentralized anonymous credential method is completed.
[0352] Embodiment 3
[0353] The post - quantum - secure decentralized anonymous credential method in this embodiment consists of the following steps:
[0354] (1) System initialization
[0355] Adopt the initialization method of commitment - conversion signature and zero - knowledge proof to obtain its corresponding parameters. An honest user selects a message m as its own private key usk in the message space K honest credential issuers respectively generate their own public keys pk i , private keys sk i , where i is a positive integer less than or equal to K, and K takes values from 20 to 50. K takes the value of 50 in this embodiment.
[0356] The initialization method of the commitment - conversion signature in this embodiment is as follows:
[0357] 1) Construct the underlying algebraic structure ring and the ring
[0358]
[0359] f(X) = X N +1
[0360] Among them, q1 and q2 are prime moduli, q1 and q2 are large prime numbers that meet the security requirements, and q1 is less than q2. In this embodiment, the value of q1 is 2 24 -75, and the value of q2 is 2 79 -67, It means that the highest coefficient of the polynomial in the ring is q2, and N represents the number of the highest degrees of the polynomial x in the ring. N is at least 2 7 , and in this embodiment, the value of N is 2 11 , generate the public matrix A required for the commitment:
[0361]
[0362] A2 = (I l , A′2)
[0363] Among them,
[0364] 2) Set the message space and the randomness space
[0365] Construct the message space according to the following formula and the randomness space
[0366]
[0367]
[0368] Among them, is a subset of the ring consisting of 2 ξ non-zero binary polynomial elements, and the value of ξ is 2 5 ~2 10 , and in this embodiment, the value of ξ is 2 10 , is a subset of the elements on the ring with an infinite norm less than 1.
[0369] 3) Select a random matrix and Gaussian parameters
[0370] Select the random matrix D and the Gaussian parameter α according to the following formula:
[0371]
[0372] Among them, the value of α is 2 7 ~230 , the value of α in this embodiment is 2 30 .
[0373] 4) Determine the challenge space
[0374] Determine the challenge space according to the following formula
[0375]
[0376] where κ represents the maximum value of the element 1-norm of the challenge space, κ ranges from 2 to 20, and the value of κ in this embodiment is 20.
[0377] 5) Set the number K of credential issuers.
[0378] Set the number of credential issuers to K, K ranges from 20 to 50, and the value of K in this embodiment is 50.
[0379] 6) Generate the common reference string crs i
[0380] The expression of formula (1) in this embodiment is the same as that in Embodiment 1.
[0381] In formula (1), l, τ, k, n represent dimensions, and the values of l, τ, k, n range from 1 to 10. In this embodiment, the values of l and n are 10, the value of τ is 10, and the value of k is 10. The meanings and value ranges of other parameters and variables are the same as those in Embodiment 1.
[0382] 7) Generate the common reference string crs
[0383] This step is the same as that in Embodiment 1.
[0384] 8) Output the common reference string
[0385] This step is the same as that in Embodiment 1.
[0386] The key generation method of this embodiment is as follows:
[0387] 1) Generate the private key
[0388] This step is the same as that in Embodiment 1.
[0389] 2) Generate the public key
[0390] The public key pk i consists of the matrix A 0,i , the matrix B, and the non-zero vector u;
[0391] 2-1) The matrix A 0,i has the same expression (3) as that in Embodiment 1.
[0392] In formula (3), τ takes values from 1 to 10, and the value of τ is the same as that in step 6) of step (1) of this embodiment. The meanings represented by other parameters and variables are the same as those in Embodiment 1.
[0393] Other steps of this step are the same as those in Embodiment 1.
[0394] (2) User registers a signature credential
[0395] This step is the same as that in Embodiment 1.
[0396] (3) The credential issuer issues a signature credential
[0397] This step is the same as that in Embodiment 1.
[0398] (4) The user proves a single credential
[0399] This step is the same as that in Embodiment 1.
[0400] (5) The verifier verifies a single credential
[0401] This step is the same as that in Embodiment 1.
[0402] (6) The user proves an aggregated signature credential
[0403] The method for generating an aggregated signature in this embodiment is as follows:
[0404] 1) Determine the weight
[0405] Determine each signature S according to formula (4) 2,i The weight e of the part i :
[0406] The expression of formula (4) is the same as that in Embodiment 1.
[0407] In formula (4), is a random oracle that requires its output to be a small polynomial and have a definite Hamming weight ω, ω ∈ {0, ±1, ±2}. In this embodiment, ω takes the value of 2, ω can also take the value of -2, and ω can also take the value of 0. The meanings represented by other parameters and variables are the same as those in Embodiment 1.
[0408] Other steps of this step are the same as those in Embodiment 1.
[0409] Other steps are the same as those in Embodiment 1. After completion, a quantum-secure decentralized anonymous credential method.
Claims
1. A post-quantum secure decentralized anonymous credential method, characterized in that It consists of the following steps: (1) System initialization The corresponding parameters are obtained by using the commitment conversion signature and zero-knowledge proof initialization method. Honest users in the message space Select a message m as its own private key usk, and K honest certificate issuers use the key generation method of commitment conversion signature to generate their own public keys pk i , private key sk i , where i is a positive integer less than or equal to K, and K is a finite positive integer; (2) User registration signature certificate Users in random space Select randomness R, use the commitment conversion signature commitment method to commit to your own private key usk, obtain commitment comm, and generate evidence π of zero-knowledge proof of the commitment. The user uses the commitment and zero-knowledge proof evidence as a pseudonym and registers with K credential issuers in the form of a pseudonym. The credential issuer verifies whether the pseudonym is correct through the verification method of zero-knowledge proof. (3) The certificate issuer issues a signed certificate The user's pseudonym is verified by K credential issuers, and the K credential issuers use the commitment conversion signature method to generate a signed credential σ for the user. i ; (4) User proves a single credential The user selects another randomness R′ and uses the randomization method of commitment conversion signature to randomize the commitment comm to obtain the randomized commitment comm′ of the same message. The user uses the conversion method of commitment conversion signature to convert the signature credential σ i The converted signature certificate σ′ is obtained i , the user will randomize the commitment comm′ and the evidence π′ into a pseudonym, and convert the converted signature credential σ′ i and pseudonym is sent to the verifier for verification, where the evidence π′ is the evidence of the zero-knowledge proof of the randomized commitment comm′; (5) The verifier verifies a single credential The verifier uses the commitment conversion signature verification method to verify each converted signature credential σ′ i Verify whether the pseudonym is correct through zero-knowledge proof verification method; (6) User proof of aggregate signature certificate The user selects another randomness R′ and uses the randomization method of commitment conversion signature to randomize the commitment comm to obtain the randomized commitment comm′; the user uses the aggregate signature generation method to generate the signature certificates σ1,σ2,…,σ K Aggregate and obtain the aggregate signature certificate σ′ of the randomized commitment comm′ agg-t , the randomized commitment comm′ and evidence π′ are combined into a pseudonym, and the aggregate signature certificate σ′ agg-t and pseudonym is sent to the verifier for verification, where the evidence π′ is the evidence of the zero-knowledge proof of the randomized commitment comm′; (7) The verifier verifies the aggregate signature certificate The verifier uses the aggregate signature verification method to verify the aggregate signature certificate σ′ agg-t Verify and verify whether the pseudonym is correct through the zero-knowledge proof verification method.
2. The post-quantum secure decentralized anonymous credential method according to claim 1, characterized in that: In step (1) system initialization, the initialization method of the commitment conversion signature is as follows: 1) Construct the underlying algebraic structure ring and ring f(X)=X N +1 Among them, q1, q2 are prime moduli, q1, q2 are large prime numbers that meet security requirements, and q1 is smaller than q2. The coefficient of the polynomial in the ring is up to q2, N represents the number of the highest degree of the polynomial x in the ring, N is a finite integer, and the public matrix A required for the commitment is generated: A2=(I l ,A′2) in, 2) Set up message space and randomness space Build a message space as follows and randomness space in, It is a ring One by 2 ξ The subset consists of non-zero binary polynomial elements, ξ is a finite positive integer, It is a ring The subset of elements whose upper infinity norm is less than 1; 3) Select random matrix and Gaussian parameters Select the random matrix D and Gaussian parameter α as follows Among them, α is a finite real number; 4) Identify the challenge space Press the formula to determine the challenge space Where k represents the maximum value of the 1-norm of the element in the challenge space, and k is a finite positive integer; 5) Set the number of certificate issuers K; 6) Generate public parameter crs i Adopting zero-knowledge proof system Π 1 Initialization method to generate public parameter crs i , zero-knowledge proof system Π 1 It is about language ,Challenge Space A non-interactive zero-knowledge proof system for language As shown in formula (1): Among them, l, τ, k, n represent the dimension, which are finite positive integers. γ1 represents the norm bound of the transformed signature, which are finite positive real numbers. It is a challenging space The set consisting of the difference between two elements except 0; 7) Generate public parameter crs Adopting zero-knowledge proof system Π 2 Initialization method to generate public parameters crs, zero-knowledge proof system Π 2 It is about language , the challenge space is Zero-knowledge proof system for language As shown in formula (2): Among them, γ represents the norm bound of the transformed aggregate signature, and the value of γ is a finite positive real number; 8) Output common parameters Output the public parameters params as follows:
3. The post-quantum secure decentralized anonymous credential method according to claim 1, characterized in that: In step (1) system initialization, the key generation method is as follows: 1) Generate a private key K certificate issuers generate private keys sk as follows i : Select sk i =T i ; 2) Generate a public key Public key pk i From the matrix A 0,i , matrix B, non-zero vector u; 2-1)A 0,i =D·T i +G (3) in, is an identity matrix, and τ takes a finite positive integer value; 2-2) Select the matrix 2-3) Select a non-zero vector 4. The post-quantum secure decentralized anonymous credential method according to claim 1, characterized in that: In step (3) the certificate issuer issues a signed certificate, the signing method is as follows: 1) Parse the promise comm, Using the promise generation method we get: Parse the promise comm into C1, C2: in, 2) Generate verification matrix Generate the verification matrix F as follows comm,i : F comm,i =[[D|A 0,i ]|B comm |A2], B comm =B+C2; 3) Generate signature Generate a signature using sampling method comm,i : Output Signature comm,i .
5. The post-quantum secure decentralized anonymous credential method according to claim 1, characterized in that: In step (4) the user proves a single credential, the conversion method is as follows: 1) Parsing the signature Analyze the signature according to the formula comm,i : in, 2) Parsing promises Use the commitment method to obtain commitment comm, and parse the commitment comm into C1, C2; 3) Parse randomized promises Select a randomness R′ in the randomness space and use the randomization method to obtain the randomized commitment comm′: Parse the randomized commitment comm′ into C'1, C'2: in, 4) Generate a temporary signature after conversion Generate the converted temporary signature Sign according to the following formula comm′,i : s′ 4,i =s 4,i -R′2·s 3,i , by The probability will be Assign to Sign comm′,i , if Sign comm′,i If no value is assigned, execute step 3) to resolve the randomized commitment; in, M is the parameter of rejection sampling, which represents the conversion cost. and yes Two distributions on ; 5) Generate verification matrix Generate the verification matrix F as follows comm′,i : F comm′,i =[[D|A 0,i ]|B comm′ |A2], B comm′ =B+C′2; 6) Generate signature Adopting zero-knowledge proof system Π 1 The proof method obtains the evidence Sign′ comm′,i , through the zero-knowledge proof system Π 1 Sign comm′,i It has a small l2 norm and satisfies F comm′,i ·Sign comm′,i =u, Among them, F comm′,i Represents the verification matrix, Sign comm′,i represents the conversion signature and u represents the public key.
6. The post-quantum secure decentralized anonymous credential method according to claim 1, characterized in that: In step (5) the verifier verifies a single credential, the signature verification method is as follows: 1) Parsing promises Use the promise method to obtain the promise comm, and parse the promise comm into C1, C2; 2) Generate verification matrix Generate the verification matrix F as follows comm,i : F comm,i =[[D|A 0,i ]|B comm |A2], 3) Type verification signature There are two types of type verification signature methods: 3-1) The signature is a short vector whose l2 norm is less than γ1, check the verification matrix F comm,i With signature σ i Whether the product is equal to u; 3-2) Signature is a zero-knowledge proof system Π 1 The evidence is based on the zero-knowledge proof system Π 1 The signature is verified using the verification method.
7. The post-quantum secure decentralized anonymous credential method according to claim 1, characterized in that: In step (6) of user proof of aggregated credential, the method for generating the aggregated signature is as follows: 1) Determine the weight Determine each signature S according to formula (4): 2,i The weight of the part i : in, is a random metaphor machine requiring its value range |F| to be the exponential level of the security parameter, It is a random metaphor machine that requires its output to be a small polynomial with a certain Hamming weight ω, ω∈{0,±1,±2}, that is, 2) Generate the original aggregate signature Aggregate K original signatures to generate the original aggregate signature sig according to the following formula agg : say agg =(s1,s 2,i ,s3,s4), 3) Generate conversion aggregation signature The original aggregate signature sig is generated using randomness R′ as follows: agg Convert and obtain the converted temporary aggregate signature sig corresponding to the randomized commitment comm′ agg-t : say agg-t =(s1,s 2,i ,s3,s′4) s′4=s4-R′2s3, 4) Generate aggregate verification matrix and aggregate verification vector Generate the aggregate verification matrix F as follows agg and the aggregated validation vector u agg : F agg =[D|A 0,1 |A 0,2 |,...,|A 0,k |B+C′2|A2], 5) Generate aggregate signature Adopting zero-knowledge proof system Π 2 The proof method obtains the evidence Sign′ agg-t , as the final aggregate signature, through the language Zero-knowledge proof system Π 2 ,prove The e2 norm is small and satisfies Among them, F agg represents the aggregate verification matrix, Indicates the conversion aggregation signature, u agg Represents the aggregated validation vector.
8. The post-quantum secure decentralized anonymous credential method according to claim 1, characterized in that: In step (7) the verifier verifies the aggregated credential, the aggregated signature verification method is as follows: 1) Determine the weight Determine the weight e as follows i : 2) Generate aggregate verification matrix and aggregate verification vector Generate the aggregate verification matrix F as follows agg and the aggregated validation vector u agg : F agg =[D|A 0,1 |A 0,2 |,...,|A 0,K |B+C′2|A2], 3) Verify the aggregate signature Adopting zero-knowledge proof system Π 2 The verification method verifies whether the aggregate signature is correct.
Citation Information
Cited By
A Controllable Exchange Method for Cross-Trust Domain Evidence Based on Decentralized Anonymous Certificates
CN122578323A
Cross-trust domain evidence controllable exchange method based on decentralized anonymous credentials
CN122578323B