Government affair block chain application scene-oriented traceable aggregation signature method
By improving RSA algorithm and traceability technology, an aggregation signature method that does not rely on bilinear pairing is designed, which solves the problems of inefficiency and verification difficulties in blockchain transactions, realizes efficient traceability verification of government data, and expands blockchain application scenarios.
Patent Information
- Application Number
- CN202510632566.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-07-11
AI Technical Summary
In existing blockchain transactions, the aggregation signature is inefficient, high verification costs, and incorrect signatures lead to overall verification failure, especially in resource-constrained mobile devices.
Using the improved RSA algorithm with a power-exponent product structure of the small prime factor, combined with hash function and traceable technology, an aggregate signature method that does not rely on bilinear pairing and user interaction is designed. The hash function generates a digest and signs. The receiver only needs to verify it once to judge the validity of all signatures and tracks invalid signatures.
It improves signature and verification efficiency, enhances the reliability of signature verification, expands the application scenarios of blockchain in the government affairs field, and realizes traceable and efficient aggregation verification of government affairs data.
Smart Images

Figure CN120301577A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of blockchain and digital signature, and particularly relates to a traceable aggregate signature method for a government affairs blockchain application scenario. Background Technique
[0002] At present, precisely because of the characteristics of blockchain (traceability, open source, decentralization, etc.), new development opportunities are being brought to all walks of life. For example, decentralized search, vehicular networks, smart contracts, and smart healthcare, etc. With the development of Internet of Things technology, smart healthcare provides people with more efficient and high-quality medical services. In order to provide more accurate and timely diagnoses for patients, different medical institutions need to share a large amount of medical data information from wireless medical sensor networks in real time. While paying attention to high-quality services, more attention also needs to be paid to the security and performance issues of data during transmission. Due to the limited resources of medical sensor nodes, when a large amount of medical data of patients is transmitted, a large number of signatures and verifications will inevitably be increased, resulting in continuous increase in communication and computing costs. Therefore, it is particularly important to combine the aggregate signature technology with the smart healthcare application scenario of blockchain on the premise of ensuring security.
[0003] Blockchain technology was initially known in the form of virtual currency and was regarded as a distributed ledger for recording transactions between different nodes. In the article "A Peer-to-Peer Electronic Cash System", the transactions described therein regard virtual currency as a signed string. In blockchain transactions, usually, a transaction can be sent by multiple users to a specific recipient, or a transaction can be sent by one user to multiple recipients. Since the development of blockchain transactions to date, some problems have still been found. It is mentioned in the literature that in the initial blockchain transactions, it took 10 minutes for workers to mine a block, and it took at least 1 hour to ensure the irreversibility of transactions. Blockchain transactions are particularly slow. Therefore, the research on transaction speed and blockchain verification in blockchain is very meaningful.
[0004] The present invention is a traceable aggregation signature method based on the RSA algorithm; aggregation signatures can improve the efficiency of blockchain transactions, and the traceable technology enables the tracing of incorrect signatures in the aggregation signature verification environment of blockchain transactions, allowing blockchain transactions to be applied more widely. In the method proposed in the present invention, the digital signature uses the most typical and influential representative at present: the RSA algorithm. The RSA algorithm was proposed in 1978 and named after Ronald Rivest, Adi Shamir, and Len Adleman. Since its initial proposal, the RSA algorithm has been widely applied. With the development of technology, more and more new attack methods have emerged. As early as 1990, the 512-bit RSA public key encryption algorithm was broken by a supercomputer. In the following decade, in 2019, the 786-bit RSA public key encryption algorithm was also cracked. In 2010, three scientists in Michigan, USA, also cracked the 1024-bit RSA public key encryption algorithm. So far, Baidu Search uses the 2048-bit RSA public key encryption algorithm. To increase the security of the RSA algorithm, the most effective way mentioned in past research is to continuously increase the number of bits of the encryption key. Although increasing the number of bits of the key will enhance the security of the RSA algorithm, it will reduce the efficiency during the encryption and decryption processes. This is also one of the major problems affecting the development of the RSA algorithm. Therefore, the present invention improves the traditional RSA double-prime form and adopts the structure of the product of small prime factor power exponents to improve the efficiency of the RSA algorithm by reducing the modulus while ensuring security. In a blockchain transaction system, when multiple transaction senders conduct transactions with the same receiver, each sender needs to generate a corresponding digital signature for their respective transactions and then send it to the receiver, and the receiver needs to verify the validity of each signature one by one. If the traditional digital signature method is used, as the number of senders and receivers increases, there will be senders and receivers, and it is necessary to When signing a message, the length of the digital signature and the overhead required for signature verification increase sharply. Therefore, after the concept of aggregate signature was first proposed in 2003, with the emergence of aggregate signature, multiple signatures generated by multiple senders can be aggregated into one signature. The recipient only needs to perform one verification. If it passes, it means that all the signatures generated by the buyers are valid, which can save the computational overhead of verification. Aggregate signature can significantly improve the transmission efficiency and verification efficiency, making it more and more concerned by people. Most current aggregate signatures use bilinear pairing, and some also require signers to interact in a sequential chain or cooperate in other ways during signature creation or verification. In terms of computational complexity and memory overhead, bilinear pairing is considered a very time-consuming and energy-consuming operation. Therefore, there are great deficiencies in the bilinear pairing algorithm in terms of computational overhead and communication overhead, which is not conducive to the performance requirements of mobile devices in resource-constrained situations in the blockchain. Therefore, the present invention proposes an aggregate signature method that does not use bilinear pairing and does not require interaction, which can effectively solve the existing problems.
[0005] In the process of aggregating signatures for data, if there is an invalid digital signature participating in the aggregation, it will cause the verification of all the digital signatures participating in the aggregation to fail. Since multiple digital signatures are aggregated together to generate an aggregate signature, there is no way to find out which signature is invalid. To overcome this difficulty, traceability technology has been proposed. Traceability technology is applied to the verification link of aggregate signature. Hartung proposed a fault-tolerant aggregate signature scheme, which can be used to verify aggregate signatures and find out invalid individual signatures. However, when applying the scheme of Hartung et al., it is necessary to pre-evaluate the number of invalid individual signatures. If in actual application, the number of invalid individual signatures exceeds the pre-estimated value, then this fault-tolerant aggregate scheme can only identify a small part of the valid individual signatures. Therefore, the exploration of traceability technology is also a major direction of aggregate signature. The present invention is based on the predecessors and can find the digital signature that causes invalidation in the aggregate signature verification link without pre-evaluating the number of invalid individual signatures.
[0006] Due to the characteristics of blockchain transactions, verification is frequent among different nodes. Moreover, there are multiple inputs and multiple outputs in blockchain transactions, making the verification data relatively large. Currently, many scholars have proposed using various aggregate signatures to solve the problems of frequent verification and large amounts of data. However, the more commonly used methods are those based on bilinear pairings or aggregate signatures that require interaction with users. Based on the actual applications of blockchain transactions, the practicality of using bilinear pairings and user-interactive aggregate signatures is very low. Furthermore, if there is an incorrect individual signature in a valid aggregate signature during the aggregate signature verification process, the entire aggregate signature will be invalid, which brings great difficulties to the batch verification of different nodes in blockchain transactions. Summary of the Invention
[0007] The purpose of the present invention is to provide a traceable aggregate signature method for the application scenario of government affairs blockchain to overcome the deficiencies in the prior art.
[0008] To achieve the above object, the present invention provides the following technical solutions: The present invention provides a traceable aggregate signature method for the application scenario of government affairs blockchain, which is applied to the government affairs scenario in blockchain and specifically includes the following steps: S1. System initialization stage: The system outputs public parameters given security parameters and time period ; S2. Key generation stage: Input the public parameters to output a key pair ; S3. Signing stage: Input the public parameters , the key , the message and the current time period to output a signature ; S4. Aggregation stage: Input the public parameters , the time period , and in the case of , the sequence group of public keys , the sequence group of messages , and the sequence group of digital signatures to be aggregated ; Within the time period : Construct a set representing the consistent set of the digital signature sequence group such that ; Aggregate in each subset The signature inside, and then use the aggregation algorithm to output an aggregated signature or an error message ; within the time period a series of corresponding aggregated signatures can be obtained according to different ; ; S5. Traceable Aggregation Verification Phase: Input the public parameters , time period , sequence group of public keys , sequence group of messages and the aggregated signature , if and only if this aggregated signature is valid, and in this case, the algorithm outputs 1, otherwise it outputs 0, and outputs the users with invalid signatures; S6. Data Sharing Phase: Record the government affairs data on the blockchain. The nodes that receive the message verify the correctness of the data according to the consensus algorithm. If it is correct, the message is passed to other nodes; each government department is granted the corresponding access rights through the access control protocol to access the original and complete government affairs data.
[0009] Preferably, step S1 specifically includes the following sub-steps: Algorithm Selection By two parameters , satisfying , , such that ; Let be expressed as the quadratic residue set of order , select , randomly select a function for function , random number and any prime number ; In the random oracle model assume a hash function , let , such that ; Output the public parameters .
[0010] Preferably, step S3 specifically includes the following sub-steps: Input the public parameters and the key pair , the input time period is , where ; Run the following algorithm: The message to be sent , where , perform the calculation: ; ; Obtain prime numbers from the common parameters , and then calculate: . ; ; ; ; Calculate according to the following algorithm to obtain the signature : .
[0011] Preferably, step S5 specifically includes the following sub-steps: After the data receiver on the blockchain receives the aggregated signature sent by the data sender, according to the time period and the aggregated signature , calculate: ; If, under the condition of satisfying , the returned value is 1, then output the multi-set of the successfully verified individual signatures: .
[0012] Preferably, step S6 specifically includes the following sub-steps: Record information such as the hash value of the government affairs data and the aggregated signature on the blockchain. Each block on the chain contains the hash value of the previous block for retrieving the block; The node receiving the message verifies the correctness of the data according to the consensus algorithm. If correct, the message is passed to other nodes; Each government affairs department is granted corresponding access rights through the access control protocol; When authorized by the data owner, search for and obtain the index information of the government affairs data stored in the government affairs server in the blockchain, and access the original complete government affairs data.
[0013] The present invention designs a collusion-resistant autonomous path proxy re-encryption method supporting ciphertext re-randomization under a multi-proxy server model. The proxy re-encryption method using a threshold secret sharing protocol, bilinear pairing, and cryptographic hash functions can, in the scenario of a multi-proxy server model, through the threshold secret sharing technology, manage the re-encryption key in a decentralized manner, resist collusion attacks initiated by the delegate and the server. In addition, it also implements the autonomous path function, realizes access control of ciphertext data and controlled transfer of access rights, and at the same time realizes ciphertext re-randomization, further enhancing security and ensuring the privacy of user data and calculation results to achieve adaptively chosen plaintext security (CPA). Among them, the hash function can adopt different hash digest algorithms according to the input and output length requirements, such as MD5, SHA1, SHA3, SHA256 algorithms, etc.
[0014] The present invention designs a traceable aggregate signature method in the blockchain government affairs scenario. It adopts the structure of the product of small prime factor power exponents to optimize the problem of slow signature speed caused by relying on large modulus factorization. After multiple transaction generators generate signatures and aggregate them, the receiver only needs to verify the aggregate signature once to determine the validity of all signatures. Through the tracing technology, invalid signatures can be effectively traced, with stronger practicability, and it is applied to the blockchain government affairs system to achieve efficient aggregate verification of government affairs data traceability.
[0015] The so-called improvement of signature speed refers to improving the traditional RSA algorithm, adopting the structure of the product of small prime factor power exponents to optimize the problem of slow signature speed caused by relying on large modulus factorization. Based on the improved RSA algorithm, an aggregate signature method that does not rely on bilinear pairing and user interaction is proposed. The hash function is used to generate a digest for the transaction data, and then the improved RSA algorithm is used for signing. After multiple transaction generators sign, the signatures are aggregated through the aggregation algorithm. The receiver only needs to verify the aggregate signature once to determine the validity of all signatures.
[0016] The so-called tracing technology refers to solving the problem in the aggregate signature verification link that an incorrect individual signature causes the entire aggregate signature to be invalid, bringing difficulties to batch verification. Combining the experience of predecessors, a traceable aggregate signature method is proposed, which can effectively trace invalid signatures and has stronger practicability compared with the traditional aggregate signature without tracing technology.
[0017] The so-called blockchain government affairs application refers to applying the above-mentioned efficient aggregate signature algorithm to the blockchain government affairs system to achieve efficient aggregate verification of medical data traceability and verify the applicability of the verification method through security proof.
[0018] The beneficial effects of the present invention: 1. Improve signature and verification efficiency: The traditional aggregate signature based on bilinear pairing has low efficiency. The RSA-SAS technology proposed by the present invention does not rely on bilinear pairing, reduces the verification overhead, and improves the transmission efficiency; 2. Enhance the reliability of signature verification: In the past, if there was an incorrect signature in aggregated signature verification, the whole verification would be invalid. The T-SAS algorithm can trace invalid signatures, solve the problem of difficult batch verification for different nodes in blockchain transactions, and improve the reliability and practicality of signature verification. 3. Expand the application scenarios of blockchain: Apply the efficient aggregated signature algorithm to blockchain government services, achieve traceable and efficient aggregated verification of government data, provide an effective solution for the application of blockchain in the government field, and expand the application scenarios of blockchain.
[0019] The features and advantages of the present invention will be described in detail through examples in conjunction with the accompanying drawings. Description of the Drawings
[0020] Figure 1 It is a schematic diagram of the system structure of the present invention; Figure 2 It is a flowchart of the present invention. Detailed Embodiments
[0021] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below through the accompanying drawings and examples. However, it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the scope of the present invention. In addition, in the following description, the descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present invention.
[0022] The mathematical theory applied in the present invention is described as follows: 1. Euler's theorem and Fermat's little theorem: Let be a positive integer, be a prime number and relatively prime to , then Fermat's little theorem: ; The operations are all implemented through , and for all integer elements , this theorem always holds, and it can also be expressed as ; This is to find the inverse element of an element in a finite field. Rewriting the original expression as is the definition of the multiplicative inverse element.
[0023] Let be a positive integer, be the number of positive integers less than and relatively prime to , for example , is called the Euler's totient function. If is also a positive integer, and , then: ; that is, Euler's theorem. The following several theorems can be derived from this: If , then there is .
[0024] If and there exists such that , then is called the modulo inverse of .
[0025] If , then there is .
[0026] If is a prime number, and , then it can be deduced that .
[0027] In fact, one of the corollaries of Euler's theorem is Fermat's little theorem. If the prime modulus of Fermat's little theorem is extended to any integer modulus, Euler's theorem can be obtained. The main data theory of the RSA public-key algorithm is jointly composed of Fermat's little theorem and Euler's theorem.
[0028] 2. Factorization: The large integer factorization problem: Given any positive integer , find the prime factors of this positive integer. According to the fundamental theorem of arithmetic, , where are distinct prime numbers, , .
[0029] The factorization hypothesis: Given , for any adversary in polynomial time to factor with an advantage of , there exists a negligible function such that: ; 3. Bilinear pairing: The specific definition of a bilinear mapping is as follows: Let be a cyclic group of prime order . If the mapping satisfies the following properties, it is called a bilinear mapping: Bilinearity: For all and , there is .
[0030] Non-degeneracy: There exists , satisfying: .
[0031] Computability: For all , the mapping is computable.
[0032] Among them, if , the bilinear mapping is symmetric; otherwise, the bilinear mapping is asymmetric.
[0033] 4. Hash function: The Hash function is used to ensure the integrity of data and plays an important role in the construction and proof of encryption and signatures. In the aggregate signature scheme, it is also often necessary to map a single valid signature to a fixed aggregate signature through a secure Hash function.
[0034] (Hash function): The hash function is a reliable function that maps a bit string of any length to a fixed length. That is, the function .
[0035] 5. RSA signature: The RSA signature scheme includes three algorithms, which will be introduced in turn below: : Select two large prime numbers and that meet the requirements; Calculate , then the Euler's totient function ; Select an integer as the public key, and , where is relatively prime to ; , then ; Therefore, and are the public keys, is the private key, and can be destroyed but not leaked.
[0036] : The user signs the message , and calculates: ; And attach to the message .
[0037] : Given , is true if and only if .
[0038] 6. Difficulty problems: In a cryptographic system, the provable security of a scheme is based on many difficulty assumptions. Only in a specific security model generated under these assumptions can a certain level of security strength be achieved. In the study of cryptography, these basic assumptions include the following problems: RSA difficulty problem: The security of RSA is based on the assumption of the difficulty of factoring large integers in number theory. There may exist a polynomial-time factoring algorithm for large integers. It has become clear that large numbers that could not be factored by human computing power until now have been successfully factored. With the development of hardware resources and the continuous improvement of factoring algorithms, to ensure the security of RSA. The most practical way is to continuously increase the modulus quantity. Therefore, when using the RSA algorithm, special attention must be paid to the selection of keys.
[0039] Reduction proof method: In a provably secure cryptographic system, the reduction method is often used to prove the security of a cryptographic scheme. The entire security proof process is to reduce the cryptographic system to a well-known mathematical problem. As long as the feasibility of the scheme is proved by contradiction, it can be concluded that the constructed scheme is secure. The steps are usually as follows: 1) Define and generate an algorithm for the cryptographic format; 2) Specify the type of attack by the adversary; 3) Declare the security objective requirements that the scheme needs to achieve after changing the password; 4) Reduce the successful attack process of the adversary to solving a well-known mathematical problem, and the security of the scheme can be indirectly proved.
[0040] 7. Blockchain foundation: Blockchain technology has risen strongly in industrial applications in recent years. The blockchain network is a decentralized network. Each node in the blockchain is peer-to-peer, and network services are provided jointly by each node, which is both a server and a client. There are three key roles in the blockchain network: (1) Full node; (2) Laborer; (3) Light wallet.
[0041] The following core scenarios exist in the blockchain: (1) New nodes join the network; (2) Laborers synchronize the blockchain, including downloading the latest blocks and transactions; (3) Create a transaction; (4) Accept the transaction; (5) The laborer mines a new block and broadcasts it to the blockchain network; (6) The laborer receives the broadcast block; Blockchain transaction technology is based on cryptography, and the concepts involved are: transactions, blocks, and chains. Among them, a transaction refers to a data block stored in the blockchain; a block refers to all transactions that occur within a certain period of time, and all nodes on the network will package and process it. After a laborer mines a block, the laborer will broadcast this block to the entire network, and then all nodes on the chain will check it. After reaching a consensus, this block will be added to the main chain. A chain refers to a chain block formed by connecting transaction data information blocks in a certain order.
[0042] 8. Knowledge related to security The provable security theory means that some resistance methods can be used to deal with attackers in a specific security model. In the specific reduction proof process, it should be clear that: Hard problem hypothesis: There are many mathematical hard problems nowadays, and many of them are applied in cryptography. In order to prove the security of the solution in this invention, the RSA hard problem hypothesis is used.
[0043] Security models: mainly divided into the random oracle model and the standard model. In the security proof, the random oracle model is often an idealized substitute for the hash function. A solution that is proven to be secure in the random oracle model may not necessarily be secure in actual applications; the standard model is a model that does not rely on the random oracle. If the characteristics that can be achieved by using a real hash function are used, then it can be considered that this solution is based on the standard model. The security theory can prove that the security rules of the encryption program are difficult to solve the problems in the analysis process. It is more scientific and more rigorous, and guarantees the security of the program in mathematical theory. Nowadays, the security theory has been proven to be crucial for cryptography research.
[0044] The following further describes and explains the present invention in detail with specific embodiments: Embodiment 1: Refer to Figure 1 , and an aggregate signature method applied to the government affairs network is constructed by virtue of the distributed recording and tamper-resistant characteristics of the blockchain. The model includes data owners, several government departments, government affairs data aggregators, key generation centers, government affairs servers, government affairs centers, and registration centers and other entities.
[0045] (1) Data owner: Before entering the government affairs system, it needs to register with the key generation center; (2) Government department node: Each data owner faces A number of government department nodes, which are responsible for collecting government affairs data. Since the storage and computing capabilities of each government affairs node are limited, this data will ultimately be transmitted to the data aggregator through Internet of Things intelligent devices; (3) Government affairs data aggregator: The data aggregator collects the signatures of each sensing node from the Internet of Things devices, generates an aggregated signature, and sends it to the government affairs server.
[0046] (4) Government affairs server: Provides government affairs cloud services, responsible for recording and storing the government affairs data in each Internet of Things device. The government affairs center can access the data on the government affairs server. In addition, the government affairs server can also verify the validity of the aggregated signature. If an invalid signature appears, the government affairs server can also trace the invalid individual signature; (5) Government affairs center: After receiving the aggregated signature from the government affairs server, the government affairs center confirms and analyzes the received government affairs data and feedbacks the corresponding government affairs solutions; (6) Key generation center: The key generation center mainly distributes partial private keys to data owners.
[0047] (7) Registration center: Mainly responsible for receiving and storing the user registration form from the key generation center, and also responsible for establishing a credit list; Refer to Figure 2 , first, in the first step, multiple users have the need to sign different messages within the same time period. Then, in the second step, these users individually sign the messages they need to sign, generating different individual signatures. In the third step, the aggregated signature algorithm aggregates all the individual signatures within the same time period to generate a unified aggregated signature. In the fourth step, there will be a verification algorithm to verify the aggregated signature generated in the previous step. If the returned result is True, the verification passes; otherwise, it fails.
[0048] The implementation process of the present invention specifically includes the following steps: (I) System initialization stage The system, given the security parameter and the value of the maximum time period , outputs the public parameter .
[0049] (II) Key generation stage Input the public parameter , and output the key pair .
[0050] (III) Signature stage Input the public parameter , the key , the message and the current time period , Output signature 。
[0051] (4) Aggregation stage Input common parameters , time period , and in the case of a sequence group of public keys , a sequence group of messages , a sequence group of digital signatures to be aggregated ; Within the period : Construct a set which is the consensus set of the sequence group of digital signatures such that .
[0052] Aggregate the signatures in each subset and then use the aggregation algorithm to output an aggregated signature or an error message . Within the period , a corresponding series of aggregated signatures can be obtained according to different .
[0053] (5) Traceable Aggregation Verification Stage Input common parameters , time period , a sequence group of public keys , a sequence group of messages and the aggregated signature . When and only when this aggregated signature is valid, and in the case of
[0054] this algorithm outputs 1, otherwise it outputs 0. And the invalid signature users are output Record the government affairs data on the blockchain. The nodes that receive the message verify the correctness of the data according to the consensus algorithm. If it is correct, the message is passed to other nodes. After most nodes verify the correctness, the block is added to the blockchain to achieve the permanent storage and sharing function of the government affairs data
[0055] Each government department is granted corresponding access rights through the access control protocol to access the original complete government affairs data
[0056] The symbolic representations and meanings of all the above steps are shown in Table 1 below Table 1 Symbol List The specific operations in the system initialization stage of the traceable aggregate signature in step (1) are as follows: This algorithm selects from two security parameters , satisfying , , such that . Let be denoted as with the order of the set of quadratic residues, select , randomly select one for the function for function , random number and any prime number . In the random oracle model assume a hash function , let . such that . Output the public parameters .
[0057] The specific operations in the key generation stage of the traceable aggregate signature in step (2) are as follows: In this stage, the key generation center generates partial private keys for the data owners. In fact, after receiving the partial private keys, the data owners output the corresponding key pairs for each department during data transmission . After the request from the data owners, the key generation center performs the following operations: Each sender generates the corresponding private key and public key after running this algorithm, and a specific receiver generates the corresponding private key and public key .
[0058] The specific operations in the signature stage of the traceable aggregate signature in step (3) are as follows: In the blockchain government affairs scenario, each department has a signed message bit string. Input the public parameters and the key pair , and the input time period is , where ; Each department runs the following algorithm: (1) The department calculates the message to be sent, where , as follows: (2) The department obtains the prime number from the public parameters , then calculate: (3) Finally, each department calculates according to the following algorithm: The signature can be obtained therefrom .
[0059] The specific operations of the aggregation stage of the traceable aggregate signature in step (iv) are as follows: Run by the government data aggregator. After inputting messages from government departments, the signature is finally published on the blockchain. Under the condition of meeting The specific operations of the traceable aggregate verification stage of the traceable aggregate signature in step (v) are as follows: Within the same time period , the signatures of the data senders each time on the blockchain can be aggregated together. All represent the set of individual signatures. Then it represents a unified set in the set, such that .
[0060] Within the same time period , all signatures converge into . Therefore, for the subsets aggregated in , the corresponding aggregate signature can be obtained.
[0061] After receiving the aggregate signature sent by the data sender, the data receiver on the blockchain, since there is an aggregate signature corresponding to each time period , can calculate: If, under the condition of meeting the returned value is 1, then this algorithm outputs the multiset of the successfully verified individual signatures: The specific operations of the data sharing stage of the traceable aggregate signature in step (vi) are as follows: Record the hash values of government affairs data (such as e-government documents, approval data for cross-departmental collaboration, government affairs records, etc.), aggregated signatures and other information on the blockchain. Each block on the chain contains the hash value of the previous block, which can be used to retrieve the block. In addition, the timestamp generated on the chain ensures the timeliness of the block, and the latest generated block will be broadcast to the chain. The nodes that receive the message verify the correctness of the data according to the consensus algorithm. If it is correct, the message will be passed to other nodes. After most nodes verify the correctness, the block is added to the blockchain to achieve the permanent storage and sharing functions of government affairs data.
[0062] Each government department is granted corresponding access rights through the access control protocol. After obtaining the authorization of the data owner, it can search and obtain the index information of the government affairs data stored in the government affairs server in the blockchain before accessing the original complete government affairs data. Finally, this mechanism realizes the secure sharing and efficient collaboration of cross-departmental government affairs data.
[0063] The protection scope of the present invention is not limited to the above embodiments. Without departing from the spirit and scope of the inventive concept, the changes and advantages that can be conceived by those skilled in the art are included in the present invention, and the scope of protection is defined by the claims.
Claims
1. A traceable aggregate signature method for e-government blockchain application scenarios, characterized in that, Applied to the government affairs scenario in the blockchain, specifically including the following steps: S1. System initialization phase: The system outputs public parameters given security parameters and time period ; S2. Key Generation Phase: Input public parameters , and output a key pair ; S3. Signing Phase: Input the public parameters , the secret key , the message and the current time period , and output the signature ; S4. Aggregation stage: Input public parameters , time period , and in the case of , sequence group of public keys , sequence group of messages , sequence group of digital signatures to be aggregated ; During a time period : Construct a set that represents the consensus set of the digital signature sequence groups such that ; Aggregate the signatures in each subset and then use an aggregation algorithm to output an aggregated signature or an error message ; within a time period a corresponding series of aggregated signatures can be obtained according to different ; ; S5. Traceable Aggregation Verification Phase: Input public parameters , time period , sequence group of public keys , sequence group of messages and aggregated signature , if and only if this aggregated signature is valid, and in this case, the algorithm outputs 1, otherwise it outputs 0 and outputs the users with invalid signatures; S6. Data sharing stage: Record the government affairs data on the blockchain. The nodes that receive the message verify the correctness of the data according to the consensus algorithm. If it is correct, the message is passed to other nodes; each government department is granted corresponding access rights through the access control protocol to access the original and complete government affairs data.
2. The traceable aggregate signature method for the application scenario of government affairs blockchain according to claim 1, wherein, Step S1 specifically includes the following sub-steps: algorithm selection by two parameters , satisfying , , such that ; Let be denoted as the quadratic residue set of order , select , randomly select one for the function to give function , random number and any prime number ; Under the random oracle model Assume a hash function , let , such that ; Output the public parameters .
3. The traceable aggregate signature method for a government affairs blockchain application scenario according to claim 2, wherein Step S3 specifically includes the following sub-steps: input public parameters and the key pair , the input time period is , where ; run the following algorithm: Message to be sent , where , perform the calculation: ; ; Retrieve prime numbers from the common parameters and then calculate: ; ; ; ; Calculate according to the following algorithm to obtain the signature : 。 4. A traceable aggregate signature method for e-government blockchain application scenarios according to claim 1, characterized in that Step S5 specifically includes the following sub-steps: After receiving the aggregate signature sent by the data sender, the data receiver on the blockchain calculates according to the time period and the aggregate signature , and calculates: ; If, under the condition that is satisfied and the return value is 1, then output the multiset of individual signatures that have been successfully verified: 。 5. The traceable aggregate signature method for e-government blockchain application scenarios according to claim 4, wherein Step S6 specifically includes the following sub-steps: Record information such as the hash value of the government affairs data and the aggregated signature on the blockchain. Each block on the chain contains the hash value of the previous block for retrieving the block; the nodes that receive the message verify the correctness of the data according to the consensus algorithm. If it is correct, the message is passed to other nodes; each government department is granted corresponding access rights through the access control protocol; when authorized by the data owner, search and obtain the index information of the government affairs data stored in the government affairs server in the blockchain to access the original and complete government affairs data.