Privacy enhancement group signature method and device based on symmetric cryptographic primitives

Through the privacy-enhanced group signature method based on symmetric cryptographic primitives, the group administrator generates key pairs, certificates and non-interactive zero-knowledge proofs, the security and privacy issues of EPID signatures in the quantum computing environment are solved, and post-quantum security communication and data protection are achieved.

CN120263422APending Publication Date: 2025-07-04NORTHWESTERN POLYTECHNICAL UNIV +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510606059.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The existing EPID signature scheme does not have post-quantum security when facing quantum computing attacks, resulting in the signer's privacy being unable to be effectively protected and identity is easily forged and tampered.

Method used

The privacy-enhanced group signature method based on symmetric cryptographic primitives is adopted to generate key pairs, send challenges, generate certificates, and generate signatures using PRF functions and non-interactive zero-knowledge proofs to ensure the post-quantum security and privacy of the signature.

Benefits of technology

It realizes the security and privacy protection of signatures in the quantum computing environment, prevents identity forgery and information tampering, ensures the security and reliability of communication, and maintains the confidentiality of messages and the privacy of members within the group.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263422A_ABST
    Figure CN120263422A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy enhancement group signature method and device based on symmetric cryptographic primitives, and the method comprises the steps: a group administrator generates a group administrator key pair based on a safety parameter, and transmits a challenge to a member i in a group; the member i in the group generates an encryption parameter by using a PRF function based on the own private key and the challenge, and returns the encryption parameter; the group administrator generates a signature of the group administrator according to the encryption parameter and a private key of the group administrator, and constructs a certificate for the member i in the group based on the signature; the intra-group member i generates a signature of the intra-group member i by using a signature algorithm based on the encryption parameter and the non-interactive zero-knowledge proof; wherein the non-interactive zero-knowledge proof is generated by an intra-group member i based on a public key, a certificate and a to-be-signed message of a group administrator; the group administrator verifies the validity of the signature of the member i in the group, while the validity of the signature is verified, the confidentiality of the message and the privacy of the member i in the group are maintained, and the post quantum security of the signature is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and particularly relates to a privacy-enhanced group signature method and device based on symmetric cryptographic primitives. Background Art

[0002] The advent of the Internet era has brought great convenience to people's lives while also leading to the emergence of many network security problems. Digital signature is an extremely important branch in modern cryptography research and plays an important role in actual life scenarios. As one of the most important primitives in public key cryptography, digital signature is an important measure to ensure data integrity, reliability, and non-repudiation in the field of information security. In a digital signature system, a user can use their own private key to sign a message, and the generated signature can be verified for validity using the user's public key. Using this mechanism can not only provide data integrity protection for the message but also allow the recipient to verify the authenticity of the signer's identity. In addition, since each user has an independent private key, the sender cannot deny the signature they generated, so digital signature can also provide another security service, namely non-repudiation. Due to its own great potential and excellent characteristics, digital signature has become an indispensable technical measure in network security and plays an extremely important role in actual application scenarios such as electronic contracts, electronic medical care, electronic payment, and e-government.

[0003] However, with the advent of the cloud computing era, emerging requirements such as data sharing, data storage, and data delegation have made a single data security guarantee no longer able to meet the application requirements of individuals and enterprises. The overly simple signer identity is extremely easy to be broken by attackers, and digital signature schemes are facing threats and challenges.

[0004] In an e-commerce environment, it is necessary to provide privacy protection for signers (or users) to protect their privacy. However, in a public key infrastructure environment, the user identity is directly bound to the public key. Therefore, the biggest problem faced by current standard digital signature schemes is that signers cannot hide their own identities. For this reason, it is necessary to enhance and improve the standard digital signature, resulting in many digital signature schemes with special properties. In current cryptography research, special digital signature schemes that can provide privacy protection for users mainly include group signature, blind signature, and direct anonymous authentication schemes in the field of trusted computing, etc.

[0005] Enhanced Privacy ID (EPID) is a Direct Anonymous Attestation (DAA) scheme. Although existing EPIDs can remotely authenticate the signer's hardware device while protecting the signer's privacy, since the currently used EPID signatures are not post-quantum secure, this means that they are at risk of being easily attacked by an attacker with a quantum computer, which may seriously affect the security of digital signatures. Summary of the Invention

[0006] To solve the above problems existing in the prior art, the present invention provides a privacy-enhanced group signature method and apparatus based on symmetric cryptographic primitives.

[0007] The technical problems to be solved by the present invention are achieved through the following technical solutions:

[0008] In a first aspect, the present invention provides a privacy-enhanced group signature method based on symmetric cryptographic primitives, and the privacy-enhanced group signature method includes:

[0009] The group administrator generates a group administrator key pair based on security parameters; the group administrator key pair includes the public key and private key of the group administrator;

[0010] The group administrator sends a challenge to group member i;

[0011] Group member i generates encryption parameters using the PRF function based on the private key of group member i and the challenge, and returns the encryption parameters;

[0012] The group administrator generates a signature of the group administrator according to the encryption parameters and the private key of the group administrator, and constructs a certificate for group member i based on the signature;

[0013] The group administrator sends the certificate to group member i;

[0014] Group member i generates a signature of group member i using the signature algorithm based on the encryption parameters and non-interactive zero-knowledge proof, and returns the signature; wherein, the non-interactive zero-knowledge proof is generated by group member i based on the public key of the group administrator, the certificate, and the message to be signed;

[0015] The group administrator verifies the validity of the signature of group member i.

[0016] Optionally, the manner in which group member i generates encryption parameters using the PRF function based on the private key of group member i and the challenge includes:

[0017]

[0018] t ← (f(sk i , r), r);

[0019] where r represents a binary string; ← represents random selection; R represents the set of real numbers; c i represents the challenge; λ represents the security parameter; f(·) represents the PRF function; t represents the encryption parameter; sk i represents the private key of the group member i.

[0020] Optionally, the way for the group member i to generate the signature of the group member i based on the encryption parameter and non-interactive zero-knowledge proof using the signature algorithm includes:

[0021] π ← P(public(λ, m, gpk, t, SIG-RL, KEY-RL), private(sk i , cert i ), R1);

[0022] sig ← (t, π);

[0023] where sk i represents the private key of the group member i; π represents non-interactive zero-knowledge proof; m represents the message to be signed; gpk represents the public key of the group administrator; SIG-RL represents the signature revocation list; the signature revocation list is used to record the revoked signatures; KEY-RL represents the key revocation list; the key revocation list is used to record the revoked private keys; cert i represents the certificate; R1 represents the predefined correspondence between sk i and cert i ; sig represents the signature of the group member i; P represents the set of group members; public(·) represents the public access permission function; private(·) represents the private access permission function.

[0024] Optionally, the group administrator verifies the validity of the signature of the group member i, including:

[0025] Verify((λ, m, gpk, t, SIG-RL, KEY-RL), π) = 1 is verified; where Verify(·) represents the verification algorithm for the general signature;

[0026] If Verify((λ, m, gpk, t, SIG-RL, KEY-RL), π) = 1 holds, then for each sk j ∈ KEY-RL, verify whether t = (f(sk j , r), r) holds;

[0027] If for each skj ∈KEY-RL, t = (f(sk j , r), r) holds for all, verify whether it holds;

[0028] When holds, determine the validity of the signature of the group member i.

[0029] Optionally, the privacy-enhanced group signature method further includes:

[0030] After the identity of the group member i is compromised, the group administrator executes the key revocation algorithm and the signature revocation algorithm, adds the private key of the group member i to the key revocation list, and adds the signature of the group member i to the signature revocation list by executing the signature revocation algorithm.

[0031] Optionally, the security parameter satisfies the following relational expression:

[0032] Pr[FORGE[A,λ] = 1] ≤ negl(λ);

[0033] where A represents the adversary; λ represents the security parameter; negl(·) represents the negligible function; Pr[FORGE[A,λ] = 1] represents the probability that FORGE[A,λ] = 1; FORGE represents the forgery function.

[0034] In a second aspect, the present invention provides a privacy-enhanced group signature device based on symmetric cryptographic primitives. The privacy-enhanced group signature device includes:

[0035] A group administrator key pair generation module, configured at the group administrator side, for generating a group administrator key pair based on a security parameter; the group administrator key pair includes the public key and private key of the group administrator;

[0036] A challenge module, configured at the group administrator side, for sending a challenge to the group member i,

[0037] An encryption parameter generation module, configured at the group member side, for generating encryption parameters using the PRF function based on the private key of the group member i and the challenge, and returning the encryption parameters;

[0038] A certificate construction module, configured at the group administrator side, for generating a signature of the group administrator according to the encryption parameters and the private key of the group administrator, and constructing a certificate for the group member i based on the signature;

[0039] A sending module, configured at the group administrator side, for sending the certificate to the group member i;

[0040] The signature generation module, configured at the end of the group member, is used to generate the signature of group member i based on the encryption parameters and non-interactive zero-knowledge proof by using a signature algorithm, and return the signature; wherein, the non-interactive zero-knowledge proof is generated by group member i based on the public key of the group administrator, the certificate and the message to be signed.

[0041] The verification module, configured at the end of the group administrator, is used to verify the validity of the signature of group member i.

[0042] A privacy-enhanced group signature method based on symmetric cryptographic primitives provided by the present invention. The group administrator generates a group administrator key pair based on security parameters; the group administrator key pair includes the public key and private key of the group administrator; challenges are sent to group member i, and group member i generates encryption parameters by using a PRF function based on the private key of group member i and the challenge, and returns the encryption parameters; the group administrator generates the signature of the group administrator based on the encryption parameters and the private key of the group administrator, and constructs a certificate for group member i based on the signature; the group administrator sends the certificate to group member i, and group member i generates the signature of group member i by using a signature algorithm based on the encryption parameters and non-interactive zero-knowledge proof; wherein, the non-interactive zero-knowledge proof is generated by group member i based on the public key of the group administrator, the certificate and the message to be signed; the group administrator verifies the validity of the signature of group member i.

[0043] Group member i can generate encryption parameters based on its own private key and the challenge sent by the group administrator by using a PRF function, so as to achieve secure communication and data protection. Generating encryption parameters by using a PRF function can further ensure the randomness and security of the encryption parameters, and the participation of the private key can ensure that the encryption parameters are generated by legitimate group members. In this way, the generation and transmission of encryption parameters can be completed under the premise of security.

[0044] By the group administrator sending the certificate to group member i, it can be ensured that group member i can communicate and exchange data with the group administrator securely, while ensuring the security and reliability of the communication. The use of the certificate can effectively prevent security problems such as identity forgery and information tampering, and improve the security level of intra-group communication.

[0045] Through non-interactive zero-knowledge proof, the group administrator can verify the validity of the signature of group member i while maintaining the confidentiality of the message and the privacy of group member i. This verification method does not disclose the signature algorithm and specific details, protects the confidentiality and integrity of the data, and ensures the post-quantum security of the signature.

[0046] The following will further describe the present invention in detail with reference to the accompanying drawings. Description of the Drawings

[0047] Figure 1It is a schematic flowchart of a privacy-enhanced group signature method based on symmetric cryptographic primitives provided by an embodiment of the present invention;

[0048] Figure 2 It is a schematic flowchart of the EPID signature provided by an embodiment of the present invention;

[0049] Figure 3 It is a schematic structural diagram of a privacy-enhanced group signature device based on symmetric cryptographic primitives provided by an embodiment of the present invention. Detailed implementation manners

[0050] The present invention will be further described in detail below in conjunction with specific embodiments, but the implementation manners of the present invention are not limited thereto.

[0051] In order to solve the problem that the EPID signature is not post-quantum secure, an embodiment of the present invention provides a privacy-enhanced group signature method and device based on symmetric cryptographic primitives.

[0052] First, an introduction to EPID is given. EPID is a cryptographic scheme that can remotely authenticate hardware devices while protecting device privacy. EPID can be regarded as a DAA scheme with enhanced revocation capabilities. DAA is a scheme that realizes remote authentication of a Trusted Platform Module (TPM) while protecting user privacy. The TPM can prove to a remote party that it is a valid TPM without disclosing its identity and unlinkability. However, in the DAA scheme, a hardware device can only be revoked when the private key embedded in the hardware device has been extracted and widely published so that the revocation manager can find the damaged private key. Therefore, if an attacker compromises a hardware device and obtains its private key but never publishes the private key, the key cannot be revoked in DAA. If, at a certain time after the TPM has been published, the publisher discovers that the TPM has been compromised, but the DAA private key issued to the compromised TPM cannot be revoked in the DAA scheme, which poses a security risk. The proposed EPID scheme can solve the above limitations. In EPID, if the private key embedded in a hardware device has been extracted and widely published, the revocation manager can smoothly find the damaged private key for revocation operations. In addition, if the private key of a device is unknown, the revocation manager can revoke the device based on the signatures signed by the device. Therefore, the EPID scheme has wider applicability in practical application scenarios such as authentication and trusted computing organizations.

[0053] The EPID can solve two problems in the PKI (Public Key Infrastructure) security solution, namely anonymity and member revocation. Its first improvement to PKI is to provide "direct anonymous attestation" for users or devices: EPID allows the private keys of a group of members to be linked together and linked to a group public key, rather than performing a 1:1 public and private key distribution for individual users. The second security improvement provided by EPID is the ability to revoke a single device by detecting a compromised signature or key: if the private key used by a device is compromised or stolen, EPID can identify and revoke the device after detection, and can prevent any possible forgery behavior in the future; during the secure exchange process, the EPID protocol requires group members to perform a mathematical proof to show that it is impossible for them to create any signature that has been marked in the signature revocation list. This built-in revocation function allows anonymous devices to be revoked based solely on the signature, enabling the issuer to ban a specific device from a group without knowing which device is banned.

[0054] A privacy-enhanced group signature method based on symmetric cryptographic primitives provided by an embodiment of the present invention will be described in detail below. Refer to Figure 1 , Figure 1 which is a schematic flowchart of a privacy-enhanced group signature method based on symmetric cryptographic primitives provided by an embodiment of the present invention, specifically including the following steps:

[0055] Step S101, the group administrator generates a group administrator key pair based on security parameters; the group administrator key pair includes the public key and private key of the group administrator.

[0056] Key pairs play a crucial role in cryptography. They can be used for encrypting and decrypting data, generating and verifying digital signatures, performing identity authentication and other key operations. Therefore, the security of key pairs is of utmost importance. In a key pair, the public key is used for encryption, and the private key is used for decryption. The public key can be publicly shared with anyone, while the private key must be kept secret.

[0057] In this embodiment, before the group administrator generates the key pair, it is first necessary to select security parameters, which can be selected according to encryption requirements and security requirements. Based on the given security parameters, the group administrator can obtain the group administrator key pair by running a key generation function.

[0058] Specifically, the group administrator can obtain the key pair (gpk, gsk) by running the key generation function Keygen(1 λ ), where gpk is publicly disclosed as the public key of the group administrator, and gsk is secretly stored by the group administrator as the private key of the group administrator, and λ represents the security parameter.

[0059] Step S102, the group administrator sends a challenge to group member i.

[0060] In this embodiment, the group administrator generates a random challenge and then sends it to group member i.

[0061] Step S103: Based on the private key of group member i and the challenge, group member i generates encryption parameters using the PRF function and returns the encryption parameters.

[0062] In an embodiment of the present invention, after receiving the challenge, group member i uses its private key and the challenge to generate encryption parameters through the PRF (Pseudo-Random Function) function. After generating the encryption parameters, group member i returns them to the group administrator, and the group administrator can use the encryption parameters to perform corresponding operations.

[0063] In this embodiment, the PRF function is a key-related pseudo-random function used in the process of generating encryption parameters, and it is also a collision-resistant hash function.

[0064] Step S104: The group administrator generates a signature of the group administrator based on the encryption parameters and the private key of the group administrator, and constructs a certificate for group member i based on the signature.

[0065] In this embodiment, to ensure the integrity and authenticity of the certificate, the group administrator can use the group management private key and the encryption parameters to generate a signature, and then construct a certificate for group member i based on the signature.

[0066] In this embodiment, the certificate constructed by the group administrator can be used as the identity identifier of the group administrator.

[0067] Step S105: The group administrator sends the certificate to group member i.

[0068] In this embodiment, during the process of the group administrator sending the certificate to group member i, to ensure the security of the certificate transmission, encryption communication or other security mechanisms can be used to protect the confidentiality and integrity during the certificate transmission process. The certificate sent by the group administrator to group member i can be a copy of the certificate.

[0069] Step S106: Based on the encryption parameters and non-interactive zero-knowledge proof, group member i generates a signature of group member i using the signature algorithm and returns the signature; wherein, the non-interactive zero-knowledge proof is generated by group member i based on the public key of the group administrator, the certificate, and the message to be signed.

[0070] In this embodiment, after receiving the certificate, group member i can use the public key of the group administrator to verify the signature in the certificate, thereby confirming the validity and authenticity of the certificate.

[0071] In addition, if the certificate has a limited validity period, the group members need to regularly check the validity of the certificate and obtain a new copy of the certificate when necessary.

[0072] In this embodiment, zero - knowledge proof (ZKP, Zero—Knowledge Proof) means that the prover (group member) can make the verifier believe that a certain assertion is correct without providing any useful information to the verifier. Non - interactive zero - knowledge proof is one of the most important variants of zero - knowledge proof, which is characterized by the fact that the two communicating parties do not need to exchange information multiple times. Due to its simplicity and few communication exchanges, non - interactive zero - knowledge proof is widely used in fields such as digital signatures, blockchains, and identity authentication.

[0073] In this embodiment, group member i uses the public key, certificate, and message to be signed of the group administrator as inputs, and combines with encryption parameters to generate a non - interactive zero - knowledge proof. In this proof, group member i does not need to directly interact with the group administrator, but can prove that it knows the private key corresponding to the certificate and has correctly signed the message to be signed.

[0074] Step S107, the group administrator verifies the validity of the signature of group member i.

[0075] In this embodiment, the group administrator can verify the validity of the signature. If the verification is successful, it indicates that the signature is authenticated by the corresponding group member i.

[0076] Specifically, the group administrator verifies the knowledge of the validity of the signature of group member i through non - interactive zero - knowledge proof, but does not need to know the signature generation process or specific details. If the verification is successful, the group administrator can confirm the validity of the signature and that the message content is complete and unchanged.

[0077] In this embodiment, group member i can generate encryption parameters based on its own private key and the challenge sent by the group administrator and using the PRF function, so as to achieve secure communication and data protection. Generating encryption parameters using the PRF function can further ensure the randomness and security of the encryption parameters, and the participation of the private key can ensure that the encryption parameters are generated by legitimate group members. In this way, the generation and transmission of encryption parameters can be completed under the premise of security.

[0078] By the group administrator sending the certificate to group member i, it can ensure that group member i can communicate and exchange data with the group administrator securely, while ensuring the security and reliability of the communication. The use of the certificate can effectively prevent security problems such as identity forgery and information tampering, and improve the security level of group communication.

[0079] Through non-interactive zero-knowledge proofs, the group administrator can verify the validity of the signature of group member i while maintaining the confidentiality of the message and the privacy of group member i. This verification method does not disclose the signature algorithm and specific details, protects the confidentiality and integrity of the data, and ensures the post-quantum security of the signature.

[0080] In an embodiment of the present invention, the method for generating encryption parameters by group member i based on the private key of group member i and a challenge using a PRF function includes:

[0081]

[0082] t←(f(sk i ,r),r);

[0083] where r represents a binary string; ← represents randomly selecting; R represents the set of real numbers; c i represents the challenge; λ represents the security parameter; f(·) represents the PRF function; t represents the encryption parameter; sk i represents the private key of group member i.

[0084] In this embodiment, the generated security parameter is combined with the challenge to obtain a binary string for PRF function calculation. The encryption parameter includes the output of the PRF function for the private key and the binary string, as well as the generated binary string itself. The generated encryption parameter can be used for subsequent encryption and authentication processes. Among them, represents randomly selecting a set of real numbers for r in {0,1} λ / c i .

[0085] In this embodiment, group member i generates encryption parameters based on the private key and the challenge using the PRF function, ensuring the security and randomness of the generated encryption parameters, and further improving the confidentiality of the encryption parameters through the use of the PRF function.

[0086] In an embodiment of the present invention, the method for generating the signature of group member i by group member i based on the encryption parameter and non-interactive zero-knowledge proof using a signature algorithm includes:

[0087] π←P(public(λ,m,gpk,t,SIG - RL,KEY - RL),private(sk i ,cert i ),R1);

[0088] sig←(t,π);

[0089] Among them, r represents a binary string; ← represents randomly selecting; f(·) represents a PRF function; π represents a non-interactive zero-knowledge proof; m represents a message; gpl represents the public key of the group administrator; t represents an encryption parameter; SIG-RL represents a signature revocation list; the signature revocation list is used to record revoked signatures; KEY-RL represents a key revocation list; the key revocation list is used to record revoked private keys; cert i represents a certificate; R1 represents a predefined sk i and cert i correspondence; sig represents the signature of group member i; P represents the set of group members; public(·) represents a public access permission function; private(·) represents a private access permission function. The signature revocation list stores the signatures revoked by the compromised group members, and the key revocation list stores the private keys revoked by the compromised group members.

[0090] In this embodiment, it is defined that the relationship in the knowledge proof π is R1, and R1 is true when the following statement holds:

[0091]

[0092] and for each sig j ∈SIG-RL,

[0093] means that r has not been selected; means that the verification algorithm of the general signature holds; Verify(·) represents the verification algorithm of the general signature.

[0094] Among them, represents a specific sk i ; represents a specific c i ; represents a specific represents a specific σ i ; σ i represents a group signature.

[0095] In the embodiment of the present invention, the group administrator verifies the validity of the signature of group member i, including:

[0096] Verify((λ, m, gpk, t, SIG-RL, KEY-RL), π) = 1; where λ represents a security parameter; gpk represents the public key of the group administrator; t represents an encryption parameter; SIG-RL represents a signature revocation list; KEY-RL represents a key revocation list; π represents a non-interactive zero-knowledge proof.

[0097] In this embodiment, verifying Verify((λ, m, gpk, t, SIG-RL, KEY-RL), π) = 1 indicates verifying whether the relationship holds according to the zero-knowledge proof.

[0098] If Verify((λ, m, gpk, t, SIG-RL, KEY-RL), π) = 1 holds, then for each sk j ∈ KEY-RL, verify whether t = (f(sk j , r), r) holds; where sk j represents the private key of group member j; t represents the encryption parameter; f(·) represents the PRF function; r represents a binary string;

[0099] If for each sk j ∈ KEY-RL, t = (f(sk j , r), r) all hold, verify whether it holds; where sig represents the signature of group member i;

[0100] In this embodiment, verifying is to determine that the signature of group member i does not belong to the signature revocation list.

[0101] When holds, determine that the signature of group member i is valid.

[0102] In the embodiment of the present invention, the privacy-enhanced group signature method further includes:

[0103] After the identity of group member i is compromised, the group administrator executes the key revocation algorithm and the signature revocation algorithm to add the private key of group member i to the key revocation list, and adds the signature of group member i to the signature revocation list by executing the signature revocation algorithm.

[0104] In this embodiment, it is possible to identify whether the identity of group member i is compromised at a fixed period. After identifying that the identity of group member i is compromised, execute the key revocation algorithm and the signature revocation algorithm.

[0105] After executing the key algorithm, the union of the private key of group member i and the current key revocation list can be taken to update the current key revocation list, and the updated key revocation list is used as the new key revocation list. Similarly, after executing the signature revocation algorithm, the union of the signature of group member i and the current signature revocation list can be taken to update the current signature revocation list, and the updated signature revocation list is used as the new signature revocation list.

[0106] In the embodiment of the present invention, the key revocation algorithm is expressed as:

[0107] RevokeKey(gpk, KEY-RL, sk i );

[0108] where the return value obtained by executing the key revocation algorithm is KEY-RL ∪ {sk i}; where gpk represents the public key of the group administrator; KEY-RL represents the key revocation list; sk i represents the private key of group member i; RevokeKey represents the key revocation operation algorithm.

[0109] In the embodiments of the present invention, the signature revocation algorithm is expressed as:

[0110] RevokeSig(gpk, KEY-RL, SIG-RL, m, sig);

[0111] where, when GPVerify(gpk, m, KEY-RL, SIG-RL, sig) = 1, the obtained return value is SIG-RL ∪ {sig}; where GPVerify(·) represents the group administrator verification algorithm; SIG-RL represents the signature revocation list; m represents the message; sig represents the signature of group member i; RevokeSig represents the signature revocation operation.

[0112] In the embodiments of the present invention, the security parameter satisfies the following relational expression:

[0113] Pr[FORGE[A, λ] = 1] ≤ negl(λ);

[0114] where A represents the adversary; λ represents the security parameter; negl(·) represents the negligible function; Pr[FORGE[A, λ] = 1] represents the probability that FORGE[A, λ] = 1; FORGE represents the forgery function.

[0115] In this embodiment, if within a polynomial time, the probability that the adversary A wins in the unforgeability game is negligible, that is, Pr[FORGE[A, λ] = 1] ≤ negl(λ), then it is considered that the signature has unforgeability. The unforgeability game FORGE[A, λ] with security parameter λ is carried out between the adversary A and the challenger C, and the specific process is as follows:

[0116] a) System setup: The challenger C calculates (gok, gsk) ← Init(1 λ ), and sends the public key gok to the adversary A. C creates a corrupted party set U and initializes it to representing the empty set.

[0117] b) Query Phase: Allow the adversary \(A\) to make any number of the following queries to the challenger \(C\):

[0118] 1b) Join: \(A\) requests to create a new group member \(P\). i , and there are two possible cases: First, \(C\) internally runs the join algorithm to add the group member \(P\) i to the group, retaining the private key \(sk\) i , the certificate \(cert\) i information, and sending the certificate \(cert\) i to \(A\); Second, \(C\) and \(A\) jointly run with the adversary \(A\) playing the role of \(P\) i , causing \(C\) to obtain \(cert\) i , and \(A\) to get \((sk\) i , \(cert\) i ). After that, \(A\) sends \(sk\) i to \(C\), and \(C\) adds \(i\) to the set \(U\);

[0119] 2b) Sign: According to the signature revocation list \(SIG - RL\) it selects, the adversary \(A\) requests \(P\) i to sign the message \(m\), and the signature revocation list consists of a subset of all signatures it has received so far in the game. \(C\) computes the signature \(sig\leftarrow GPSign(gpk,sk\) i , \(cert\) i \(m,SIG - RL)\), and sends it to \(A\);

[0120] 3b) Compromise: \(A\) requests to obtain the key of the group member \(P\) i , \(C\) appends \(i\) to the set \(U\), and sends \(sk\) i to \(A\).

[0121] c) Forge: \(A\) outputs the message \(m\) * , the key revocation list \(KEY - RL\) * , the signature revocation list \(SIG - RL\) * and the signature \(sig\) * .

[0122] If \(GPVerify(gpk,m\) * , \(KEY - RL\) * , \(SIG - RL\) * , \(sig\) * ) = 1, and for every \(i\in U\), there is \(sk\) i \(\in KEY - RL\) * or \(sig\) * is in \(SIG - RL\) * and signs a message, then the game \(FORGE[A,\lambda]\) outputs 1 (\(A\) wins the unforgeability game), otherwise, the result outputs 0.

[0123] If adversary A does not obtain a signature on t := f(sk, c) from the group administrator, then according to the unforgeability of the group administrator's signature scheme and the soundness of the proof of knowledge, it cannot produce a valid proof of knowledge of a signature on t. Secondly, if A does not know the signed sk on some t = f(sk, c), then even if it has obtained signatures on many (f(sk, r), r), due to the security of the PRF, A still cannot generate f(sk, c * on a new c * ). Finally, the collision resistance of the PRF ensures that A with a signature on f(sk, c) cannot recognize sk' ≠ sk and r for a revoked sk, and thus cannot determine f(sk', c) = t and f(sk', r) ≠ f(sk, r).

[0124] In the embodiment of the present invention, the complete EPID signature scheme is defined as:

[0125] G := (Init, Join, GPSign, GPVerify, RevokeKey, RevokeSig);

[0126] where Init represents the initialization algorithm; Join represents the joining algorithm; GPSign represents the group member signature algorithm; GPVerify represents the group member verification algorithm; RevokeKey represents the revocation key operation; RevokeSig represents the revocation signature operation; the signature scheme S = (Keygen, Sign, Verify), and the proof system Π = (P, V).

[0127] The following will further describe the complete EPID signature scheme:

[0128] (1) Initialization algorithm Init(1 λ ):

[0129] The group administrator M runs the key generation function Keygen(1 λ ) to obtain the key pair (gpk, gsk), where gpk is publicly disclosed as the public key of the group administrator M, and gsk is secretly stored by the group administrator M as the private key of the group administrator M, and λ represents the security parameter.

[0130] (2) Joining algorithm

[0131] First, the group administrator M sends a challenge c i to the group member P i ;

[0132] The group member P i based on Generate the private key sk of group member P i and send it back to the group administrator; where i , represents the joining algorithm.

[0133] The group administrator M generates a signature and constructs a certificate and sends a copy of the certificate to P i . If the selected signature scheme is stateful, then the joining algorithm must include a counter for counting each member joining the group.

[0134] Group member P i obtains the private key sk i , and both the group member and the administrator obtain a copy of the certificate cert i .

[0135] (3) Signature algorithm GPSign(gpk, sk i , cert i , m, SIG-RL): During the execution of the signature algorithm, the group member generates a signature sig:

[0136]

[0137] t ← (f(sk i , r), r) #

[0138] π ← P(public(λ, m, gpk, t, SIG-RL, KEY-RL), private(sk i , cert i ), R1) # sig ← (t, π) #

[0139] Define the relationship in the proof of knowledge π as R1, and R1 is true when the following statement holds:

[0140]

[0141] And for each sig j ∈ SIG-RL,

[0142] (4) Verification algorithm GPVerify(gpk, m, KEY-RL, SIG-RL, sig):

[0143] 1) Verify the proof of knowledge π: Check whether V((λ, m, gpk, t, SIG-RL, KEY-RL), π) = 1;

[0144] 2) For each sk j ​∈KEY-RL, check if t = (f(sk j , r), r);

[0145] 3) Check if

[0146] 4) If all the above checks return 1, the final result outputs 1, indicating successful verification; otherwise, it outputs 0, indicating verification failure.

[0147] (5) Key revocation algorithm RevokeKey(gpk, KEY-RL, sk i ):

[0148] Get the return value KEY-RL ∪ {sk i};

[0149] (6) Signature revocation algorithm RevokeSig(gpk, KEY-RL, SIG-RL, m, sig):

[0150] If GPVerify(gpk, m, KEY-RL, SIG-RL, sig) = 1, at this time get the return value SIG-RL ∪ {sig}, otherwise, return the signature revocation list SIG-RL.

[0151] In this embodiment, the group member i can generate encryption parameters based on its own private key and the challenge sent by the group administrator and use the PRF function, so as to achieve secure communication and data protection. Using the PRF function to generate encryption parameters can further ensure the randomness and security of the encryption parameters, and the participation of the private key can ensure that the encryption parameters are generated by legitimate group members. In this way, the generation and transmission of encryption parameters can be completed under the premise of security. Use a unique PRF key to replace the signature key to publish the EPID signature to reduce the size of the non-interactive zero-knowledge proof statement in the signature.

[0152] By sending the certificate to the group member i, it can be ensured that the group member i can communicate and exchange data with the group administrator securely, while ensuring the security and reliability of the communication. The use of the certificate can effectively prevent security problems such as identity forgery and information tampering, and improve the security level of intra-group communication.

[0153] Through non-interactive zero-knowledge proof, the group administrator can verify the validity of the signature of the group member i while maintaining the confidentiality of the message and the privacy of the group member i. This verification method does not disclose the signature algorithm and specific details, protecting the confidentiality and integrity of the data.

[0154] In this embodiment, by interacting with the group administrator through the signature verification process to ensure that group member i has not been revoked, and moving some heavy verification steps outside the non-interactive zero-knowledge proof statement, an efficient EPID digital signature design is achieved. At the same time, by introducing a post-quantum signature algorithm, the scheme has post-quantum security. Based on the scheme design, the ZKB++, LowMC, and SPHINCS signature algorithms are selected for instantiation implementation. Using the above instantiation algorithms can reduce the zero-knowledge proof time, and a post-quantum signature with a smaller size is implemented using a secure and efficient PRF function. This embodiment can ensure post-quantum security on the basis of high efficiency, and can avoid the destruction of the authentication process in a quantum computer environment.

[0155] For further illustration of the privacy-enhanced group signature method, see Figure 2 , Figure 2 which is a schematic flow diagram of the EPID signature provided by an embodiment of the present invention.

[0156] The verifier sends the message to be signed to the member (group member), and the member signs it using the EPID key, and then sends the signed message to the verifier so that the verifier can verify the signature. For a compromised device (group member), the verifier sends a revocation request to the issuer, so that the issuer checks the revocation request, and after updating the revocation list according to the revocation request, sends GROUP_RL, SIG_RL, and PRIV_RL to the verifier. Among them, GROUP_RL represents the group member revocation list, and PRIV_RL represents the group private key revocation list.

[0157] Based on the same inventive concept, an embodiment of the present invention also provides a privacy-enhanced group signature device based on symmetric cryptographic primitives, see Figure 3 , Figure 3 which is a schematic structural diagram of a privacy-enhanced group signature device based on symmetric cryptographic primitives provided by an embodiment of the present invention. The privacy-enhanced group signature device includes:

[0158] A group administrator key pair generation module 301, configured at the group administrator side, for generating a group administrator key pair based on security parameters; the group administrator key pair includes the public key and private key of the group administrator;

[0159] A challenge module 302, configured at the group administrator side, for sending a challenge to group member i,

[0160] An encryption parameter generation module 303, configured at the group member side, for generating encryption parameters using the PRF function based on the private key of group member i and the challenge, and returning the encryption parameters;

[0161] The certificate construction module 304, configured at the group administrator side, is used to generate a signature of the group administrator according to the encryption parameters and the private key of the group administrator, and construct a certificate for the group member i based on the signature;

[0162] The sending module 305, configured at the group administrator side, is used to send the certificate to the group member i;

[0163] The signature generation module 306, configured at the group member side, is used to generate a signature of the group member i based on the encryption parameters and the non-interactive zero-knowledge proof by using a signature algorithm, and return the signature; wherein, the non-interactive zero-knowledge proof is generated by the group member i based on the public key of the group administrator, the certificate and the message to be signed;

[0164] The verification module 307, configured at the group administrator side, is used to verify the validity of the signature of the group member i.

[0165] In this embodiment, the group member i can generate encryption parameters based on its own private key and the challenge sent by the group administrator and by using the PRF function, so as to achieve secure communication and data protection. Generating encryption parameters by using the PRF function can further ensure the randomness and security of the encryption parameters, and the participation of the private key can ensure that the encryption parameters are generated by legitimate group members. In this way, the generation and transmission of the encryption parameters can be completed under the premise of security.

[0166] By sending the certificate to the group member i, it can be ensured that the group member i can communicate and exchange data with the group administrator securely, and at the same time ensure the security and reliability of the communication. The use of the certificate can effectively prevent security problems such as identity forgery and information tampering, and improve the security level of group communication.

[0167] Through the non-interactive zero-knowledge proof, the group administrator can verify the validity of the signature of the group member i while maintaining the confidentiality of the message and the privacy of the group member i. This verification method does not disclose the signature algorithm and specific details, protects the confidentiality and integrity of the data, and ensures the post-quantum security of the signature.

[0168] Optionally, the encryption parameter generation module is specifically used for:

[0169]

[0170] t←(f(sk i ,r),r);

[0171] wherein, r represents a binary string; ← represents randomly selecting; R represents the set of real numbers; c i represents the challenge; λ represents the security parameter; f(·) represents the PRF function; t represents the encryption parameter; ski Represents the private key of the group member i.

[0172] Optionally, the signature generation module is specifically configured to:

[0173] π ← P(public(λ, m, gpk, t, SIG-RL, KEY-RL), private(sk i , cert i ), R1);

[0174] sig ← (t, π);

[0175] Where sk i Represents the private key of the group member i; π represents a non-interactive zero-knowledge proof; m represents the message to be signed; gpk represents the public key of the group administrator; SIG-RL represents a signature revocation list; the signature revocation list is used to record revoked signatures; KEY-RL represents a key revocation list; the key revocation list is used to record revoked private keys; cert i Represents the certificate; R1 represents the predefined correspondence between sk i and cert i ; sig represents the signature of the group member i; P represents the set of group members; public(·) represents a public access permission function; private(·) represents a private access permission function.

[0176] Optionally, the verification module is specifically configured to:

[0177] Verify whether Verify((λ, m, gpk, t, SIG-RL, KEY-RL), π) = 1 holds; where Verify(·) represents a verification algorithm for general signatures;

[0178] If Verify((λ, m, gpk, t, SIG-RL, KEY-RL), π) = 1 holds, then for each sk j ∈ KEY-RL, verify whether t = (f(sk j , r), r) holds;

[0179] If for each sk j ∈ KEY-RL, t = (f(sk j , r), r) all hold, verify Whether it holds;

[0180] When Holds, determine that the signature of the group member i is valid.

[0181] Optionally, the privacy-enhanced group signature device further includes a revocation module, and the revocation module is specifically configured to:

[0182] After the identity of the group member i is compromised, the group administrator adds the private key of the group member i to the key revocation list by executing the key revocation algorithm and the signature revocation algorithm, and adds the signature of the group member i to the signature revocation list by executing the signature revocation algorithm.

[0183] Optionally, the security parameter satisfies the following relational expression:

[0184] Pr[RORGE[A,λ] = 1] ≤ negl(λ);

[0185] where A represents an adversary; λ represents the security parameter; negl(·) represents a negligible function; Pr[FORGE[A,λ] = 1] represents the probability that FORGE[A,λ] = 1; and FORGE represents a forgery function.

[0186] It should be noted that for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, please refer to the partial description of the method embodiments.

[0187] It should be noted that the terms "first", "second", etc. are used to distinguish similar objects and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are only examples of devices and methods consistent with some aspects of the present invention.

[0188] In the description of this specification, the description referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.

[0189] Although the present invention has been described in connection with various embodiments, those skilled in the art can understand and implement other variations of the disclosed embodiments by viewing the accompanying drawings and the disclosure during the implementation of the claimed invention. In the description of the present invention, the term "comprising" does not exclude other components or steps, the indefinite article "a" or "an" does not exclude a plurality, and the meaning of "plurality" is two or more, unless otherwise specifically defined. In addition, certain measures are described in different embodiments, but this does not mean that these measures cannot be combined to produce good effects.

[0190] It should be noted that the device of the embodiment of the present invention is a device applying the above-mentioned privacy-enhanced group signature method based on symmetric cryptographic primitives. Then all embodiments of the above-mentioned privacy-enhanced group signature method based on symmetric cryptographic primitives are applicable to this device and can achieve the same or similar beneficial effects.

[0191] The above content is a further detailed description of the present invention in combination with specific preferred embodiments. It cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should all be regarded as belonging to the protection scope of the present invention.

Claims

1. A privacy-enhanced group signature method based on symmetric cryptographic primitives, characterized in that, The privacy-enhanced group signature method includes: The group administrator generates a group administrator key pair based on security parameters; the group administrator key pair includes the public key and private key of the group administrator; The group administrator sends a challenge to group member i; Group member i generates encryption parameters using the PRF function based on the private key of group member i and the challenge, and returns the encryption parameters; The group administrator generates a signature of the group administrator according to the encryption parameters and the private key of the group administrator, and constructs a certificate for group member i based on the signature; The group administrator sends the certificate to group member i; Group member i generates a signature of group member i using the signature algorithm based on the encryption parameters and non-interactive zero-knowledge proof, and returns the signature; wherein, the non-interactive zero-knowledge proof is generated by group member i based on the public key of the group administrator, the certificate and the message to be signed; The group administrator verifies the validity of the signature of group member i.

2. The privacy-enhanced group signature method according to claim 1, wherein The manner in which group member i generates encryption parameters using the PRF function based on the private key of group member i and the challenge includes: t ← (f(sk i , r), r); where r represents a binary string; ← represents random selection; R represents the set of real numbers; c i represents the challenge; λ represents the security parameter; f(·) represents the PRF function; t represents the encryption parameter; sk i represents the private key of the group member i.

3. The privacy-enhanced group signature method according to claim 2, wherein The manner in which group member i generates a signature of group member i using the signature algorithm based on the encryption parameters and non-interactive zero-knowledge proof includes: π ← P(public(λ, m, gpk, t, sIG-RL, KEY-RL), private(sk i , cert i ), R1); sig←(t,π); Among them, sk i represents the private key of the group member i; π represents a non-interactive zero-knowledge proof; m represents the message to be signed; gpk represents the public key of the group administrator; SIG-RL represents a signature revocation list; the signature revocation list is used to record the revoked signatures; KEY-RL represents a key revocation list; the key revocation list is used to record the revoked private keys; cert i represents the certificate; R1 represents the predefined correspondence between sk i and cert i ; sig represents the signature of the group member i; P represents the set of group members; public(·) represents a public access permission function; private(·) represents a private access permission function.

4. The privacy-enhanced group signature method according to claim 3, characterized in that, The group administrator verifies the validity of the signature of group member i, including: Verifying whether Verify((λ,m,gpk,t,SIG-RL,KEY-RL),π) = 1 holds; where Verify(·) represents the verification algorithm of the general signature; If Verify((λ,m,gpk,t,SIG - RL,KEY - RL),π) = 1 holds, then for each sk j ∈ KEY - RL, verify whether t = (f(sk j ,r),r) holds; If for each sk j ∈ KEY-RL, t = (f(sk j , r), r) holds, verify whether it holds; When is established, determine the validity of the signature of the group member i.

5. The privacy-enhanced group signature method according to claim 1, characterized in that, The privacy-enhanced group signature method further includes: After the identity of group member i is compromised, the group administrator adds the private key of group member i to the key revocation list by executing the key revocation algorithm and the signature revocation algorithm, and adds the signature of group member i to the signature revocation list by executing the signature revocation algorithm.

6. The privacy-enhanced group signature method according to claim 1, wherein The security parameters satisfy the following relational expression: Pr[RORGE[A,λ] = 1] ≤ negl(λ); Where A represents the adversary; λ represents the security parameter; negl(·) represents the negligible function; Pr[FORGE[A,λ] = 1] represents the probability that FORGE[A,λ] = 1; FORGE represents the forgery function.

7. A privacy-enhanced group signature device based on symmetric cryptographic primitives, characterized in that The privacy-enhanced group signature device includes: The group administrator key pair generation module, configured at the group administrator side, for generating a group administrator key pair based on security parameters; the group administrator key pair includes the public key and private key of the group administrator; The challenge module, configured at the group administrator side, for sending a challenge to group member i, The encryption parameter generation module, configured at the group member side, for generating encryption parameters using the PRF function based on the private key of group member i and the challenge, and returning the encryption parameters; The certificate construction module, configured at the group administrator side, for generating a signature of the group administrator according to the encryption parameters and the private key of the group administrator, and constructing a certificate for group member i based on the signature; The sending module, configured at the group administrator side, for sending the certificate to group member i; A signature generation module, configured at the end of a group member, for generating a signature of group member i based on the encryption parameters and non-interactive zero-knowledge proof using a signature algorithm and returning the signature; wherein the non-interactive zero-knowledge proof is generated by group member i based on the public key of the group administrator, the certificate, and the message to be signed. A verification module, configured at the end of the group administrator, for verifying the validity of the signature of group member i.

8. The privacy-enhanced group signature device according to claim 7, characterized in that, The encryption parameter generation module is specifically used for: t ← (f(sk i , r), r); where \(r\) represents a binary string; \(\leftarrow\) represents random selection; \(\mathbb{R}\) represents the set of real numbers; \(c\) i represents the challenge; \(\lambda\) represents the security parameter; \(f(\cdot)\) represents the PRF function; \(t\) represents the encryption parameter; \(sk\) i represents the private key of the group member \(i\).

9. The privacy-enhanced group signature device according to claim 8, characterized in that, The signature generation module is specifically used for: π ← P(public(λ, m, gpk, t, SIG-RL, KEY-RL), private(sk i , cert i ), R1); sig ← (t, π); Among them, sk i represents the private key of the group member i; π represents a non-interactive zero-knowledge proof; m represents the message to be signed; gpk represents the public key of the group administrator; SIG-RL represents a signature revocation list; the signature revocation list is used to record revoked signatures; KEY-RL represents a key revocation list; the key revocation list is used to record revoked private keys; cert i represents the certificate; R1 represents a predefined correspondence between sk i and cert i ; sig represents the signature of the group member i; P represents the set of group members; public(·) represents a public access permission function; private(·) represents a private access permission function.

10. The privacy-enhanced group signature device according to claim 9, wherein The verification module is specifically used for: Verifying whether Verify((λ, m, gpk, t, SIG-RL, KEY-RL), π) = 1 holds; where Verify(·) represents the verification algorithm for a general signature. If Verify((λ, m, gpk, t, SIG-RL, KEY-RL), π) = 1 holds, then for each sk j ∈ KEY-RL, verify whether t = (f(sk j , r), r) holds; If for each sk j ∈ KEY-RL, t = (f(sk j , r), r) holds, verify whether it holds; When is established, the signature of the group member i is determined to be valid.