Safety time-limited verifiable and traceable threshold signature system and method
By introducing notary management tracking permissions and homomorphic time lock puzzle mechanisms, the problems of complex tracking process and waste of resources in the existing technology are solved, and the security and privacy of threshold signatures are improved, and the joint evil of signers and aggregators are effectively fought against.
Patent Information
- Application Number
- CN202510782702.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-07-25
AI Technical Summary
The existing privacy accountable threshold signature technology has problems such as complex tracking process, single point failure of the aggregator leads to waste of resources and inefficiency, and difficult to identify joint cooperation between the aggregator and the signature.
The notary management tracking permission was introduced, and the homomorphic time lock puzzle and homomorphic commitment mechanism was used to restore the signature when the signature was not aggregated within the specified time. Combined with the restriction of tracking capabilities based on attribute encryption technology, non-interactive zero-knowledge proof is used to verify the validity of the signature.
Simplifies the tracking process, reduces resource waste, improves the security and privacy of the signature process, and effectively fights against the joint evil of aggregators and signers.
Smart Images

Figure QLYQS_8 
Figure QLYQS_18 
Figure QLYQS_35
Abstract
Description
Technical Field
[0001] The present invention is a secure time-limited verifiable and traceable threshold signature system and method, belonging to the technical fields of digital signature, privacy protection, and threshold signature in cryptography. Background Art
[0002] Threshold signature is a widely applied technology in the field of cryptography. Its essence is the group application of digital signature. In the context of a group with n signers, when t or more of them participate in the digital signature, the digital signature can be successfully generated, where t is a critical value called the threshold. Threshold signature has a large number of applications in important fields such as blockchain, and there are many derivative technologies for threshold signature. The privacy accountable threshold signature technology, as a mainstream derivative technology, comprehensively realizes accountability and privacy. The threshold signature provided by this technology will not provide any information about the threshold t and the signers participating in the signature, while ensuring the accountability of the signature.
[0003] There are many existing privacy accountable threshold signature technologies, such as privacy and traceable threshold signature supporting secure witness, decentralized privacy and traceable threshold signature supporting witness, etc. The existing technologies focus on practical problems such as the overly powerful function of the tracer and the single point of failure of the aggregator and the tracer. It emphasizes the sensitivity of the tracing process and the privacy of the tracing result, and believes that the tracing process should be carried out under the witness of a relatively fair third-party group, rather than being independently completed only by the tracer.
[0004] However, the existing privacy accountable threshold signature technologies have three deficiencies: First, although the existing technologies notice the need to limit the function of the tracer and introduce the identity of the witness, the overly complex witness process will burden the entire signature process. Second, although the existing technologies notice the single point of failure problem of the aggregator, their solution is to replace the aggregator and restart the signature process, which will consume a large amount of resources and cause resource waste. Moreover, if the aggregator delays giving the digital signature, the system cannot promptly judge it as a failure, which will affect the completion time of the entire signature process and is less efficient in practical applications. Third, if the aggregator colludes with t or more signers to initiate a secondary signature, the tracer will not be able to distinguish which signature is the valid one. Summary of the Invention
[0005] The present invention aims to solve the deficiencies of the existing privacy accountable threshold signature technology, and proposes a secure time-limited verifiable and traceable threshold signature method and system, expecting to achieve message-based tracking, time-limited aggregation, and verifiable aggregation in the process of threshold signature to resist the security threats brought by untrusted trackers and aggregators, and manage and distribute the tracking permissions for threshold signatures through a notary to enhance the security and privacy in the entire threshold signature process.
[0006] The present invention adopts the following technical solutions to achieve the above-mentioned invention objectives:
[0007] The characteristics of a secure time-limited verifiable and traceable threshold signature system of the present invention include: \(n\) signer modules, 1 aggregator module, 1 tracker module, and 1 notary module; among them, \(n\) represents the maximum number of signer modules; selecting \(t\) signer modules from \(n\) signer modules, and combining the identifiers of \(t\) signer modules to obtain a signer sequence \(S\), where \(t\) represents the threshold value of a group of signer modules, \(S_i\) represents the identifier of the \(i\)-th signer module;
[0008] Any \(i\)-th signer module among \(n\) signer modules includes: the \(i\)-th message signature unit, the \(i\)-th time-lock puzzle construction unit, and the \(i\)-th signer encryption unit,
[0009] The aggregator module includes: an aggregation information receiving unit, an aggregation signature unit, an aggregator encryption unit, and a verification generation unit;
[0010] The tracker module includes: a tracking information receiving unit, a verification unit, a decryption token application unit, an aggregation signature decryption unit, and a signer sequence tracking unit;
[0011] The notary module includes: a notary information receiving unit, a decryption token generation unit, and an aggregation signature recovery unit;
[0012] After the \(i\)-th message signature unit signs the message \(m\), it obtains the \(i\)-th signature fragment \(\sigma_i\); where \(m\) represents the The first part of the th signature fragment
[0013] The th time-lock puzzle construction unit obtains the and th fragments of the first time-lock puzzle and the th fragments of the second time-lock puzzle respectively; ;
[0014] The th signer encryption unit constructs the th signature fragment commitment , encrypts the message and the th signer's identifier and obtains the th identifier ciphertext_aggregator . Meanwhile, two different secret keys are used to encrypt separately, and the th identifier ciphertext_notary and the th identifier ciphertext_tracker are obtained respectively;
[0015] The aggregation information receiving unit receives all signature fragments and their corresponding identifier ciphertext_aggregators and forms a set of aggregated ciphertext information pairs , decrypts all and obtains a set of aggregated identifier pairs . Taking as a condition, selects th identifier pairs from and forms an aggregated information set with the corresponding signature fragments; where represents the th aggregated ciphertext information pair, represents the th signature fragment, represents the th identifier ciphertext_aggregator, represents the th aggregated identifier pair, represents the th signer identifier, represents the th decrypted message, Represents the total number of received information pairs;
[0016] The aggregation signature unit aggregates the in the signature fragments to obtain an aggregated signature ; where, represents the first part of the aggregated signature, represents the second part of the aggregated signature;
[0017] The aggregator encryption unit encrypts to obtain the ciphertext of the first part , and encrypts the message to obtain the ciphertext of the message . At the same time, it encrypts the threshold to obtain the ciphertext of the threshold ;
[0018] The verification generation unit generates a zero - knowledge proof , and constructs a commitment of the aggregated signature , thereby , aggregator identifier , , , and are signed to obtain the signature of the aggregator ;
[0019] The tracking information receiving unit receives all the identity ciphertexts_tracker and the corresponding commitments and forms a set of verification ciphertext information pairs , and decrypts all the to obtain a set of signer identifiers . Taking as a condition, selects signer identifiers from and forms a verification information set with the corresponding commitments; where, represents the th verification ciphertext information pair, represents the th identity ciphertext_tracker, represents the th commitment;
[0020] The verification unit first verifies whether the in commitments correspond to . If they do not correspond, the process ends. Otherwise, it continues to verify the zero - knowledge proof Whether it passes; if not, end the process, otherwise, for After decryption, the message is obtained for verifying the signature of the aggregator Whether it passes; if it passes, continue to execute, otherwise, terminate the process;
[0021] The decryption token application unit makes an application for a decryption token according to to the decryption token generation unit;
[0022] The decryption token generation unit receives the application from the decryption token application unit and generates a decryption token according to the message and then sends it to the decryption token application unit; After that, it is sent to the decryption token application unit;
[0023] The aggregated signature decryption unit uses the decryption token to decrypt and obtains the first part of the aggregated signature , combines with to obtain the aggregated signature ;
[0024] The signer sequence tracking unit tracks the aggregated signature and obtains the signer sequence ;
[0025] The notarization information receiving unit receives all the fragments of the time-lock puzzle one, the fragments of the time-lock puzzle two, and the identity ciphertext_notary to form a set of notarized ciphertext information pairs ; and decrypts all to obtain the set of signer identities , and with as the condition, filters out from signer identities and combines them with the corresponding fragments of the time-lock puzzle one and the fragments of the time-lock puzzle two to form a set of notarization information ; where represents the th notarized ciphertext information pair, represents the th fragment of the time-lock puzzle one, represents the th fragment of the time-lock puzzle two, represents the th identity ciphertext_notary;
[0026] The aggregated signature recovery unit processes the in After aggregating the fragments of the first time-lock puzzle, the first time-lock puzzle is obtained. Then, after solving the first time-lock puzzle the first part of the aggregated signature is obtained. Similarly, after aggregating the fragments of the second time-lock puzzle in the second time-lock puzzle is obtained. Then, after solving the second time-lock puzzle the second part of the aggregated signature is obtained. Thus, after combining and the aggregated signature is obtained. .
[0027] The feature of a secure time-limited verifiable traceable threshold signature method of the present invention is that it is applied to a network environment composed of signers, 1 aggregator, 1 tracer, and 1 notary. The threshold signature method is carried out according to the following steps:
[0028] Step 1. Initialization:
[0029] Step 1.1. Define relevant parameters, including:
[0030] Set the security parameter to , , where is the length of the security parameter, and is the degree of the polynomial;
[0031] Set the time spent on solving the homomorphic time-lock puzzle;
[0032] Define the size of the signer set as , and the threshold value of the accountable threshold signature as , ;
[0033] Use the initialization algorithm of the homomorphic time-lock to generate the homomorphic time-lock parameter ;
[0034] Use the initialization algorithm of the homomorphic commitment algorithm to generate the homomorphic commitment parameter ;
[0035] Use the initialization algorithm of attribute-based encryption to generate the attribute-based encryption parameter and the master key of attribute-based encryption ;
[0036] Step 1.2: Generate the relevant keys of the accountable threshold signature algorithm, asymmetric encryption algorithm, and digital signature algorithm, as well as the public key 's cryptographic commitment ;
[0037] Step 1.3: After combining the relevant parameters and keys respectively, obtain the system parameters , the total public key , the aggregator's total private key , the notary's total private key ;
[0038] Step Two: Message Signing:
[0039] Step 2.1: Randomly select signers, sign the message respectively to obtain signature fragments; encrypt the message with the identities of signers respectively to obtain identity ciphertexts_aggregator, and send them to the aggregator together with signature fragments;
[0040] Step 2.2: Generate time-lock puzzles with the first part of the signature fragment as the answer, generate time-lock puzzles with the second part of the signature fragment as the answer. At the same time, encrypt the identities of signers to obtain identity ciphertexts_notary, and send them to the notary together with time-lock puzzles:
[0041] The th signer constructs the th time-lock puzzle fragment one using the additive construction algorithm of the homomorphic time-lock puzzle with the first part in as the answer according to the homomorphic time-lock parameters ; at the same time, constructs the th signature puzzle fragment two using the multiplicative construction algorithm of the homomorphic time-lock puzzle with the second part in as the answer according to the homomorphic time-lock parameters ; at the same time, according to the notary's encryption public key , use the encryption algorithm of asymmetric encryption After encrypting , the th identity ciphertext_notary is obtained; thus , and are sent to the notary;
[0042] Step 2.3, the th signer uses the construction algorithm of the homomorphic commitment algorithm to generate 's commitment , and according to the encryption public key verified by the tracer, uses the encryption algorithm of asymmetric encryption to encrypt the th signer's identity , and the th identity ciphertext_tracer is obtained; thus and are sent to the tracer;
[0043] Step Three, aggregate signature:
[0044] Step 3.1, the aggregator receives the aggregate ciphertext information pair , filters out signature fragments therefrom under certain conditions, and then aggregates the signature fragments to obtain the aggregate signature ;
[0045] Step 3.2, the aggregator encrypts the aggregate signature , constructs the commitment , and then encrypts to obtain the ciphertext of the message ;
[0046] The aggregator encrypts according to the message using the encryption algorithm of attribute-based encryption to obtain the ciphertext of ; meanwhile, uses the construction algorithm of the homomorphic commitment algorithm to generate the commitment of the aggregate signature ;
[0047] The aggregator uses the encryption algorithm of asymmetric encryption according to the encryption public key verified by the tracer to encrypt the message After encryption, the ciphertext of the message is obtained ;
[0048] Step 3.3: The aggregator constructs a non-interactive zero-knowledge proof ;
[0049] Step 3.4: The aggregator generates the signature of the aggregator , thus obtaining a secure time-limited verifiable and traceable threshold signature and sends it to the tracer;
[0050] Step Four: The tracer traces the aggregated signature and obtains the signer sequence ;
[0051] Step 4.1: Verify the signature, including: digital signature verification, non-interactive zero-knowledge proof verification, and homomorphic commitment verification. If all verifications pass, execute Step 4.1; otherwise, end the process;
[0052] Step 4.2: After the tracer interacts with the notary, obtain the decryption key for attribute-based encryption :
[0053] The tracer sends a request for the decryption key to the notary;
[0054] After receiving the request, the notary, according to the master key for attribute-based encryption and the message , uses the key extraction algorithm for attribute-based encryption to generate the decryption key with the message as the attribute and sends it to the tracer;
[0055] Step 4.3: The tracer uses the decryption key to decrypt the ciphertext of the first part of the aggregated signature , obtains the aggregated signature , and thus, after tracing , obtains the signer sequence :
[0056] The tracer receives the decryption key with the message as the attribute, uses the decryption algorithm for attribute-based encryption to decrypt the ciphertext of the first part of the aggregated signature and obtains the first part of the aggregated signature ; thus, after combining and , obtains the aggregated signature ;
[0057] The tracker, according to the public key and the message , uses the tracing algorithm of accountable threshold signature to trace the aggregated signature and obtains the signer sequence ;
[0058] Step Five: The notary aggregates the time-lock puzzle fragments sent by the signers, and then opens the puzzle to recover the aggregated signature ;
[0059] Step 5.1: After the notary receives all the fragments of Time-lock Puzzle One, the fragments of Time-lock Puzzle Two, and the identity ciphertext_notary, it forms a set of notarized ciphertext information pairs ; and according to the private key of the notary , uses the decryption algorithm of asymmetric encryption to decrypt the identity ciphertext_notary and obtains the signer identity set ;
[0060] The notary takes as a condition and filters out from signer identities, and jointly forms a notarized information set with the corresponding fragments of Time-lock Puzzle One and the fragments of Time-lock Puzzle Two ;
[0061] Step 5.2: The notary aggregates the fragments of Time-lock Puzzle One and the fragments of Time-lock Puzzle Two respectively to obtain Time-lock Puzzle One and Time-lock Puzzle Two, and then solves the two time-lock puzzles to finally obtain the aggregated signature .
[0062] The feature of a secure time-limited verifiable and traceable threshold signature method described in the present invention also lies in that the said Step 1.2 includes:
[0063] Using the key generation algorithm of accountable threshold signature to generate the key and related parameters of accountable threshold signature, including: the key generation algorithm parameters of accountable threshold signature , the private key set , and the public key , where represents the private key of the th signer, represents the public key of the th signer;
[0064] Using the key generation algorithm of asymmetric encryption to generate the encryption private key of the aggregator , the encryption public key of the aggregator , the encryption private key of the tracker , the encryption public key of the tracker , the encryption private key of the notary , the encryption public key of the notary , the encryption private key verified by the tracker , the encryption public key verified by the tracker ;
[0065] The key generation algorithm using digital signature Generate the signature private key of the aggregator , the signature public key of the aggregator ;
[0066] Select a random number from the real number group with a security parameter length of , and use the generation algorithm of homomorphic commitment to generate the cryptographic commitment of the public key . .
[0067] Furthermore, the step 1.3 includes:
[0068] Combine the key generation algorithm parameters of the accountable threshold signature , the homomorphic time lock parameters , the homomorphic commitment parameters , and the attribute-based encryption parameters to obtain the system parameters ;
[0069] Combine the encryption public key of the aggregator , the signature public key of the aggregator , the encryption public key of the tracker , the encryption public key of the notary , the encryption public key verified by the tracker , and the cryptographic commitment to obtain the total public key ;
[0070] Combine the public key , the encryption private key of the aggregator , the signature private key of the aggregator , the threshold value , the cryptographic commitment of the public key , and the random number to obtain the total private key of the aggregator ;
[0071] The public key The encrypted private key of the tracker After combination, the total private key of the tracker is obtained ;
[0072] The encrypted private key of the notary , the master key of attribute-based encryption After combination, the total private key of the notary is obtained .
[0073] Furthermore, the step 2.1 includes:
[0074] The key generation algorithm parameters of the accountable threshold signature , the homomorphic time lock parameters , the homomorphic commitment parameters , the attribute-based encryption parameters After combination, the system parameters are obtained ;
[0075] The encrypted public key of the aggregator , the signature public key of the aggregator , the encrypted public key of the tracker , the encrypted public key of the notary , the encrypted public key for tracker verification , the cryptographic commitment After combination, the total public key is obtained ;
[0076] The public key , the encrypted private key of the aggregator , the signature private key of the aggregator , the threshold value , the public key The cryptographic commitment of , the random number After combination, the total private key of the aggregator is obtained ;
[0077] The public key , the encrypted private key of the tracker After combination, the total private key of the tracker is obtained ;
[0078] The encrypted private key of the notary , the master key of attribute-based encryption After combination, the total private key of the notary is obtained .
[0079] Furthermore, the step 3.1 includes:
[0080] After receiving all signature fragments and identity ciphertexts, the aggregator forms an aggregated ciphertext information pair set. , uses the decryption algorithm of asymmetric encryption to decrypt all identity ciphertexts of the aggregator and obtains an aggregated identity pair set ; taking , as the condition, filters out of them, and forms an aggregated information set with the corresponding signature fragments ; where represents the th aggregated ciphertext information pair, represents the th signature fragment, represents the th identity ciphertext of the aggregator, represents the th aggregated identity pair, represents the th signer identity, represents the th decrypted message, represents the total number of received information pairs;
[0081] The aggregator uses the aggregation algorithm of accountable threshold signature and the message to aggregate the signature fragments in the aggregated information set and obtains an aggregated signature ; where represents the first part of the aggregated signature,
[0082] represents the second part of the aggregated signature.
[0082] Furthermore, step 3.3 includes:
[0083] The aggregator encrypts the threshold value using the encryption algorithm of asymmetric encryption with the encrypted public key verified by the tracker and obtains the ciphertext of the threshold value ; ;
[0084] The aggregator constructs a set according to the construction rule, and the construction rule is: when , set the th signer participation identity to , otherwise, let the The identification involves multiple signers For ;
[0085] The aggregator constructs a non - interactive zero - knowledge proof , including: the verification algorithm of accountable threshold signature , the verification algorithm of homomorphic commitment algorithm and the encryption algorithm based on attribute - based encryption for non - interactive zero - knowledge proof
[0086] Furthermore, step 3.4 includes:
[0087] The aggregator, according to the private key of the aggregator , uses the signature algorithm of digital signature to sign the message , the aggregator identification , the commitment of the aggregated signature , the ciphertext of the first part of the aggregated signature , the ciphertext of the threshold value and the zero - knowledge proof to obtain the signature of the aggregator ;
[0088] Combining the aggregator identification , the commitment of the aggregated signature , the ciphertext of the message , the second part of the aggregated signature , the ciphertext of the first part of the aggregated signature , the ciphertext of the threshold value , the zero - knowledge proof and the signature of the aggregator to obtain a secure time - limited verifiable and traceable threshold signature , and send it to the tracker module
[0089] Furthermore, step 4.1 includes:
[0090] The tracker, according to the encrypted private key verified by the tracker , uses the decryption algorithm of asymmetric encryption to decrypt the ciphertext of the message to obtain the message ;
[0091] The tracker, according to the encrypted public key of the aggregator , the message , the aggregator identification , the commitment of the aggregated signature , the ciphertext of the first part of the aggregated signature The ciphertext of the threshold value and the zero - knowledge proof , use the verification algorithm of digital signature to verify the signature of the aggregator ; if the verification passes, continue the process, otherwise, terminate the process;
[0092] The tracer verifies the zero - knowledge proof ; if the verification passes, continue the process, otherwise, terminate the process;
[0093] After the tracer receives all the identity ciphertexts_tracer and commitments, a set of verification ciphertext information pairs is formed, and according to the encryption private key verified by the tracer , use the decryption algorithm of asymmetric encryption to decrypt all the identity ciphertexts_tracer, and obtain the set of signer identities , and with as the condition, filter out from signer identities, and form a verification information set with the corresponding commitments ; thus verifying the correspondence between the commitment of the aggregated signature and the set ; if the verification passes, continue the process, otherwise, terminate the process; where represents the th verification ciphertext information pair, represents the th identity ciphertext_tracer, represents the th commitment.
[0094] Furthermore, the step 5.2 includes:
[0095] The notary uses the aggregation algorithm of the homomorphic time - lock puzzle according to the parameters of the homomorphic time - lock puzzle to aggregate the in fragments of the time - lock puzzle one to obtain the time - lock puzzle one ; where represents the addition operation;
[0096] At the same time, according to the parameters of the homomorphic time - lock puzzle , use the aggregation algorithm of the homomorphic time - lock puzzle to aggregate the in the set fragments of the time - lock puzzle two After aggregation, the time-lock puzzle two is obtained. , where represents the exponentiation method;
[0097] The notary uses the parameters of the homomorphic time-lock puzzle and uses the homomorphic time-lock puzzle addition puzzle-solving algorithm to solve the time-lock puzzle one and obtains the first part of the aggregated signature ; at the same time, according to the parameters of the homomorphic time-lock puzzle , uses the homomorphic time-lock puzzle multiplication puzzle-solving algorithm to solve the time-lock puzzle two and obtains the second part of the aggregated signature , so that and are combined to obtain the aggregated signature .
[0098] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0099] 1. In the present invention, attribute-based encryption technology is introduced to restrict the tracking process, and a notary is introduced. The tracker needs to apply to the notary for a decryption key to carry out the tracking process. The process of restricting the capabilities of the tracker is simplified while ensuring the function.
[0100] 2. In the present invention, homomorphic time-lock puzzle technology is introduced, so that the signer constructs a homomorphic time-lock puzzle while generating a signature. If the aggregator does not give the signature within the specified time, the notary can restore the signature by aggregating and opening the time-lock puzzle, reducing the waste of resources caused by repeated processes.
[0101] 3. Through the homomorphic commitment mechanism in the present invention, the signer gives relevant commitments while generating a signature, and the aggregator also gives relevant commitments and non-interactive zero-knowledge proofs after aggregating the signatures. The tracker judges whether the signature is a valid signature through the relevance of the commitments and the non-interactive zero-knowledge proofs, effectively combating the collusion of the aggregator and the signer and enhancing the security and privacy in the signature process. Specific embodiments
[0102] In this embodiment, a secure time-limited verifiable traceable threshold signature system includes: signature signer modules, aggregator modules, tracker modules, and 1 notary module; where represents the maximum number of signature signer modules; select from signature signer modules, The identification combinations of the signer modules are combined to obtain a signer sequence , where represents the threshold value of a group of signer modules , represents the th identification of the signer module
[0103] Any th signer module among the signer modules includes: the th message signature unit, the th time-lock puzzle construction unit, and the th signer encryption unit .
[0104] The aggregator module includes: an aggregation information receiving unit, an aggregation signature unit, an aggregator encryption unit, and a verification generation unit
[0105] The tracer module includes: a tracing information receiving unit, a verification unit, a decryption token application unit, an aggregation signature decryption unit, and a signer sequence tracing unit
[0106] The notary module includes: a notarization information receiving unit, a decryption token generation unit, and an aggregation signature recovery unit
[0107] The th message signature unit signs the message to obtain the th signature fragment ; where represents the first part of the th signature fragment represents the second part of the th signature fragment
[0108] The th time-lock puzzle construction unit respectively obtains the fragment and of the th time-lock puzzle one and the fragment and the th time-lock puzzle two according to ;
[0109] The th signer encryption unit constructs the commitment of the th signature fragment , and encrypts the message and the identification of the th signer to obtain the One identification ciphertext_aggregator , meanwhile, using two different secret keys to separately encrypt individually, and correspondingly obtaining the th identification ciphertext_notary and the th identification ciphertext_tracker .
[0110] The aggregation information receiving unit receives all signature fragments and their corresponding identification ciphertext_aggregator and forms a set of aggregated ciphertext information pairs , and after decrypting all , obtains a set of aggregated identification pairs , taking as a condition, screening out identification pairs from and forming an aggregated information set with the corresponding signature fragments; among them, represents the th aggregated ciphertext information pair, represents the th signature fragment, represents the th identification ciphertext_aggregator, represents the th aggregated identification pair, represents the th signer identification, represents the th decrypted message, represents the total number of received information pairs.
[0111] The aggregation signature unit aggregates the signature fragments in the aggregated information set to obtain an aggregated signature ; among them, represents the first part of the aggregated signature, represents the second part of the aggregated signature;
[0112] The aggregator encryption unit encrypts to obtain the ciphertext of the first part , and encrypts the message to obtain the ciphertext of the message , meanwhile, encrypts the threshold to obtain the ciphertext of the threshold ;
[0113] The verification generation unit generates a zero-knowledge proof , and construct a commitment for the aggregated signature , thus , aggregator identifier , , , and are signed to obtain the signature of the aggregator .
[0114] The tracking information receiving unit receives all the encrypted identity _ trackers and the corresponding commitments and forms a set of verification ciphertext information pairs , and after decrypting all , obtains the set of signer identifiers , and using as a condition, filters out from signer identifiers and combines them with the corresponding commitments to form a set of verification information ; among them, represents the th verification ciphertext information pair, represents the th encrypted identity _ tracker, represents the th commitment.
[0115] The verification unit first verifies whether the in commitments correspond to ; if not, the process ends, otherwise, continue to verify whether the zero - knowledge proof passes; if not, the process ends, otherwise, after decrypting , obtain the message for verifying whether the signature of the aggregator passes; if it passes, continue to execute, otherwise, terminate the process.
[0116] The decryption token application unit makes an application for a decryption token to the decryption token generation unit according to ;
[0117] The decryption token generation unit receives the application from the decryption token application unit and generates a decryption token according to the message and then sends it to the decryption token application unit;
[0118] The aggregated signature decryption unit uses the decryption token to decrypt and obtains the first part of the aggregated signature , and combines with After combination, an aggregated signature is obtained .
[0119] Signature-sequence tracing for single-pair aggregated signature After tracing, a signature-sequence is obtained ;
[0120] The notarization information receiving unit receives all the fragments of time-lock puzzle 1, the fragments of time-lock puzzle 2, and the identity ciphertext_notary, and forms a set of notarized ciphertext information pairs ; and decrypts all to obtain a set of signer identities , and, taking as a condition, filters out from signer identities, and jointly forms a notarization information set with the corresponding fragments of time-lock puzzle 1 and the fragments of time-lock puzzle 2 ; where represents the th notarized ciphertext information pair, represents the th fragment of time-lock puzzle 1, represents the th fragment of time-lock puzzle 2, represents the th identity ciphertext_notary.
[0121] The aggregated signature recovery unit aggregates the fragments of time-lock puzzle 1 in to obtain time-lock puzzle 1 , and then solves time-lock puzzle 1 to obtain the first part of the aggregated signature ; similarly, aggregates the fragments of time-lock puzzle 2 in to obtain time-lock puzzle 2 , and then solves time-lock puzzle 2 to obtain the second part of the aggregated signature ; thus, combines and to obtain the aggregated signature .
[0122] In this embodiment, a secure time-limited verifiable and traceable threshold signature method is applied to a network environment composed of signers, aggregators, trackers, and notaries. The threshold signature method is performed according to the following steps:
[0123] Step 1. Initialization:
[0124] Step 1.1. Define relevant parameters, including:
[0125] Set the security parameter to 、 , where is the length of the security parameter, and is the degree of the polynomial;
[0126] Set the time required to solve the homomorphic time-lock puzzle to ;
[0127] Define the size of the signer set as , and the threshold value of the accountable threshold signature as , ;
[0128] Use the initialization algorithm of the homomorphic time-lock to generate homomorphic time-lock parameters ;
[0129] Use the initialization algorithm of the homomorphic commitment algorithm to generate homomorphic commitment parameters , select the multiplicative group , is a randomly generated large prime number, randomly select 、 as the generators of the multiplicative group, and the homomorphic commitment parameters are composed of the generators 、 , that is ;
[0130] Use the initialization algorithm of attribute-based encryption to generate attribute-based encryption parameters and the master key of attribute-based encryption , where , and are polynomials of degree .
[0131] Step 1.2. Generate the relevant keys of the accountable threshold signature algorithm, asymmetric encryption algorithm, digital signature algorithm, and the cryptographic commitment of the public key :
[0132] Use the key generation algorithm of the accountable threshold signature to generate the keys and related parameters of the accountable threshold signature, including: the key generation algorithm parameters 、the private key set , and the public key , where represents the private key of the th signer, represents the public key of the th signer.
[0133] Use the key generation algorithm of EIGamal to generate the encrypted private key of the aggregator , the encrypted public key of the aggregator , the encrypted private key of the tracer , the encrypted public key of the tracer , the encrypted private key of the notary , the encrypted public key of the notary , the encrypted private key for tracer verification , the encrypted public key for tracer verification ;
[0134] Use the key generation algorithm of digital signature to generate the signature private key of the aggregator , the signature public key of the aggregator ;
[0135] Select a random number from the real number group with a security parameter length of , and use the generation algorithm of homomorphic commitment to generate the cryptographic commitment of the public key ; The process of the generation algorithm of homomorphic commitment is: calculate .
[0136] Step 1.3, After combining the relevant parameters and keys respectively, obtain the system parameters , the total public key , the total private key of the aggregator , the total private key of the notary :
[0137] Combine the key generation algorithm parameters of accountable threshold signature , the homomorphic time lock parameters , the homomorphic commitment parameters , the attribute-based encryption parameters to obtain the system parameters ;
[0138] Combine the encrypted public key of the aggregator , the signature public key of the aggregator , the encrypted public key of the tracer , the encrypted public key of the notary , the encrypted public key verified by the tracker , cryptographic commitment After combination, the total public key is obtained .
[0139] Combining the public key , the encrypted private key of the aggregator , the signature private key of the aggregator , threshold value , public key 's cryptographic commitment , random number After combination, the aggregator's total private key is obtained ;
[0140] Combining the public key , the encrypted private key of the tracker After combination, the tracker's total private key is obtained ;
[0141] Combining the encrypted private key of the notary , the master key of attribute-based encryption After combination, the notary's total private key is obtained .
[0142] Step 2. Message signature:
[0143] Step 2.1. Randomly select signers to sign the message respectively, obtaining signature fragments; Encrypt the message respectively with the identities of signers to obtain identity ciphertexts_aggregator, and send them to the aggregator together with signature fragments:
[0144] Randomly select signers to form a signer sequence .
[0145] The th signer, according to its own private key , signer sequence , uses the signature algorithm of accountable threshold signature to sign the message , obtaining the th signature fragment , where represents the first part of the th signature fragment, represents the The second part of a signature fragment, ;
[0146] The th signer uses the encryption algorithm of the ElGamal algorithm based on the public key of the aggregator to encrypt the message and its own identity to obtain the th identity ciphertext_aggregator ;
[0147] The th signer sends the th signature fragment and the th identity ciphertext_aggregator to the aggregator.
[0148] Step 2.2, Generate time-lock puzzles with the first part of the signature fragment as the answer, generate time-lock puzzles with the second part of the signature fragment as the answer. At the same time, after encrypting the identity of the signers, obtain identity ciphertext_notary, and send it to the notary together with time-lock puzzles;
[0149] The th signer constructs the fragment of the first part of the homomorphic time-lock parameter as the answer using the addition construction algorithm of the homomorphic time-lock puzzle ; At the same time, construct the fragment of the second part of the homomorphic time-lock parameter as the answer using the multiplication construction algorithm of the homomorphic time-lock puzzle ; At the same time, encrypt using the encryption algorithm of the ElGamal algorithm based on the encryption public key of the notary to obtain the th identity ciphertext_notary ; Thus, ; , Sent to the notary.
[0150] Step 2.3, the th signer uses the construction algorithm of the homomorphic commitment algorithm to generate commitment , and according to the encrypted public key verified by the tracer, uses the encryption algorithm of the EIGamal algorithm to encrypt the identity of the th signer, and after encryption, obtains the th identity ciphertext_tracer , thereby sending and to the tracer; among them, the process of the generation algorithm of the homomorphic commitment is: calculate .
[0151] Step Three, aggregate signatures:
[0152] Step 3.1, the aggregator receives the aggregate ciphertext information pair, , screens out signature fragments therefrom under certain conditions, and after aggregating the signature fragments, obtains the aggregate signature :
[0153] After the aggregator receives all the signature fragments and the identity ciphertext_aggregator, it constitutes the aggregate ciphertext information pair set , uses the decryption algorithm of the EIGamal algorithm to decrypt all the identity ciphertext_aggregator, and obtains the obtained aggregate identity pair set ; with , as the condition, screens out of them, and forms the aggregate information set with the corresponding signature fragments; among them, represents the th aggregate ciphertext information pair, represents the th signature fragment, represents the th identity ciphertext_aggregator, represents the th aggregate identity pair, represents the th signer identity, represents the th decrypted message, represents the total number of received information pairs.
[0154] The aggregator, according to the public key and the message , uses the aggregation algorithm of accountable threshold signature to aggregate the signature fragments in the aggregation information set to obtain the aggregated signature ; among them, represents the first part of the aggregated signature, represents the second part of the aggregated signature.
[0155] Step 3.2. The aggregator encrypts the aggregated signature , and constructs a commitment . Subsequently, after encrypting , the ciphertext of the message is obtained:
[0156] The aggregator, according to the message , uses the encryption algorithm based on attribute encryption to encrypt and obtains the ciphertext of ; at the same time, uses the construction algorithm of the homomorphic commitment algorithm to generate the commitment of the aggregated signature ; among them, the process of the homomorphic commitment generation algorithm is: calculate ;
[0157] The aggregator, according to the encryption public key verified by the tracer, uses the encryption algorithm of the EIGamal algorithm to encrypt the message and obtains the ciphertext of the message.
[0158] Step 3.3. The aggregator constructs a non-interactive zero-knowledge proof::
[0159] The aggregator, according to the encryption public key verified by the tracer, uses the encryption algorithm of the EIGamal algorithm to encrypt the threshold value and obtains the ciphertext of the threshold value ;
[0160] The aggregator constructs a set according to the construction rule. The construction rule is: when , set the corresponding th signer's participation identifier to , otherwise, let the th signer participate in the identification as ;
[0161] The aggregator constructs a non-interactive zero-knowledge proof , including: the verification algorithm of accountable threshold signature , the verification algorithm of homomorphic commitment algorithm and the encryption algorithm based on attribute encryption of non-interactive zero-knowledge proof.
[0162] Step 3.4. The aggregator generates the signature of the aggregator , so as to obtain a threshold signature that is securely time-limited verifiable and traceable , and then send it to the tracer:
[0163] The aggregator uses the private key of the aggregator , and uses the signature algorithm of digital signature to sign the message , the aggregator identification , the commitment of the aggregated signature , the ciphertext of the first part of the aggregated signature , the ciphertext of the threshold value and the zero-knowledge proof to obtain the signature of the aggregator ;
[0164] Combine the aggregator identification , the commitment of the aggregated signature , the ciphertext of the message , the second part of the aggregated signature , the ciphertext of the first part of the aggregated signature , the ciphertext of the threshold value , the zero-knowledge proof and the signature of the aggregator to obtain a threshold signature that is securely time-limited verifiable and traceable , and send to the tracer module.
[0165] Step Four. The tracer traces the aggregated signature to obtain the signer sequence ;
[0166] Step 4.1. Verify the signature, including: digital signature verification, non-interactive zero-knowledge proof verification, and homomorphic commitment verification;
[0167] The tracer uses the decryption algorithm of the EIGamal algorithm according to the encrypted private key verified by the tracer After decrypting the ciphertext of the message the message is obtained ;
[0168] Based on the aggregator's encryption public key the message the aggregator identifier the commitment of the aggregated signature the ciphertext of the first part of the aggregated signature the ciphertext of the threshold value and the zero - knowledge proof the tracer uses the verification algorithm of digital signature to verify the signature of the aggregator ; if the verification passes, continue the process, otherwise, terminate the process.
[0169] The tracer verifies the zero - knowledge proof ; if the verification passes, continue the process, otherwise, terminate the process;
[0170] After the tracer receives all the identifier ciphertexts_tracer and commitments, it forms a set of verification ciphertext information pairs and based on the encrypted private key verified by the tracer uses the decryption algorithm of asymmetric encryption to decrypt all the identifier ciphertexts_tracer and obtains the set of signer identifiers Taking as the condition, it filters out from signer identifiers and forms a verification information set with the corresponding commitments; thus verifying whether the equation holds. If the verification passes, continue the process, otherwise, terminate the process; where represents the th verification ciphertext information pair, represents the th identifier ciphertext_tracer, represents the th commitment.
[0171] Step 4.2: After the tracer interacts with the notary, it obtains the decryption key for attribute - based encryption:
[0172] The tracer sends a request for the decryption key to the notary;
[0173] After receiving the request, the notary, based on the master key for attribute - based encryption and the message uses the key extraction algorithm for attribute - based encryption to generate a message - based Decryption Key as an Attribute and send it to the tracer; where .
[0174] Step 4.3: The tracer uses the decryption key to decrypt the ciphertext of the first part of the aggregated signature , obtaining the aggregated signature , thereby after tracing, obtaining the signer sequence :
[0175] The tracer receives the decryption key with the message as an attribute , and uses the decryption algorithm of attribute-based encryption to decrypt the ciphertext of the first part of the aggregated signature , obtaining the first part of the aggregated signature ; thereby and are combined to obtain the aggregated signature ;
[0176] The tracer uses the tracing algorithm of accountable threshold signature and the message based on the public key to trace the aggregated signature , obtaining the signer sequence .
[0177] Step Five: The notary aggregates the time-lock puzzle fragments sent by the signers, and then opens the puzzle to restore the aggregated signature ;
[0178] Step 5.1: The notary receives all the fragments of Time-lock Puzzle One, the fragments of Time-lock Puzzle Two, and the identity ciphertext_notary, and forms a set of notarized ciphertext information pairs ; and according to the private key of the notary , uses the decryption algorithm of the EIGamal algorithm to decrypt the identity ciphertext_notary , obtaining the set of signer identities ;
[0179] The notary takes as a condition, and filters out from signer identities, and jointly forms a notarized information set with the corresponding fragments of Time-lock Puzzle One and the fragments of Time-lock Puzzle Two.
[0180] Step 5.2: The notary aggregates the fragments of the time - lock puzzle one and the fragments of the time - lock puzzle two respectively to obtain the time - lock puzzle one and the time - lock puzzle two, and then solves the two time - lock puzzles to finally obtain the aggregated signature ;
[0181] The notary, according to the parameters of the homomorphic time - lock puzzle , uses the aggregation algorithm of the homomorphic time - lock puzzle , and for the in the fragments of the time - lock puzzle one , after aggregation, obtains the time - lock puzzle one ; where represents the addition operation.
[0182] Meanwhile, according to the parameters of the homomorphic time - lock puzzle , uses the aggregation algorithm of the homomorphic time - lock puzzle to aggregate the in the set fragments of the time - lock puzzle two , and after aggregation, obtains the time - lock puzzle two , where represents the multiplication operation.
[0183] The notary, according to the parameters of the homomorphic time - lock puzzle , uses the solution algorithm for the addition puzzle of the homomorphic time - lock puzzle to solve the time - lock puzzle one , and obtains the first part of the aggregated signature ; meanwhile, according to the parameters of the homomorphic time - lock puzzle , uses the solution algorithm for the multiplication puzzle of the homomorphic time - lock puzzle to solve the time - lock puzzle two , and obtains the second part of the aggregated signature , and thus, after combining with , obtains the aggregated signature .
Claims
1. A secure time-limited verifiable and traceable threshold signature system Its features include: 1 signer module, 1 aggregator module, 1 tracer module, 1 notary module; among them, represents the maximum number of signer modules; selected from signer modules to select signer modules, the identification combinations of the signer modules are combined to obtain the signer sequence , among them, represents the threshold value of a group of signer modules, , represents the th signer module identification; Any of the signer modules includes: the message signature unit, the time-lock puzzle construction unit, the signer encryption unit, ; The aggregator module includes: an aggregation information receiving unit, an aggregation signature unit, an aggregator encryption unit, and a verification generation unit; The tracer module includes: a tracing information receiving unit, a verification unit, a decryption token application unit, an aggregation signature decryption unit, and a signer sequence tracing unit; The notary module includes: a notarization information receiving unit, a decryption token generation unit, and an aggregation signature recovery unit; The th message signature unit signs the message and obtains the th signature fragment ; where represents the first part of the th signature fragment, and represents the second part of the th signature fragment; The th time-lock puzzle construction unit respectively obtains the and to get the th fragment of the first time-lock puzzle and the th fragment of the second time-lock puzzle ; The th signer encryption unit constructs the th signature fragment 's commitment , and after encrypting the message and the identity of the th signer , the th identity ciphertext_aggregator is obtained. At the same time, two different secret keys are used to encrypt separately, and the th identity ciphertext_notary and the th identity ciphertext_tracker are obtained respectively; The aggregated information receiving unit receives all signature fragments and their corresponding identity ciphertexts_aggregator and forms a set of aggregated ciphertext information pairs , and after decrypting all , an aggregated identity pair set is obtained. Taking as a condition, is used to screen out from identity pairs, and together with the corresponding signature fragments, an aggregated information set is formed; among them, represents the th aggregated ciphertext information pair, represents the th signature fragment, represents the th identity ciphertext_aggregator, represents the th aggregated identity pair, represents the th signer identity, represents the th decrypted message, represents the total number of received information pairs; The aggregation signature unit aggregates the signature fragments in the aggregation information set to obtain an aggregated signature ; where represents the first part of the aggregated signature, and represents the second part of the aggregated signature; After the aggregator encryption unit encrypts , the ciphertext of the first part is obtained , and after encrypting the message , the ciphertext of the message is obtained . At the same time, after encrypting the threshold , the ciphertext of the threshold is obtained ; The verification generation unit generates a zero-knowledge proof , and constructs a commitment of the aggregate signature , so as to , aggregator identifier , , , and are signed to obtain the signature of the aggregator ; The tracking information receiving unit receives all the ciphertexts of identifiers_tracers and the corresponding commitments, and forms a set of verification ciphertext information pairs , and after decrypting all , obtains the set of signer identifiers . Taking as a condition, filters out from signer identifiers, and forms a set of verification information together with the corresponding commitments ; where represents the th verification ciphertext information pair, represents the th ciphertext of identifier_tracer, represents the th commitment; The verification unit first verifies the promises and to check if they correspond. If they do not correspond, the process ends. Otherwise, continue to verify whether the zero - knowledge proof passes; if it does not pass, the process ends. Otherwise, after decrypting obtain the message for verifying whether the aggregator's signature passes; if it passes, continue to execute, otherwise, terminate the process; The decryption token application unit submits an application for a decryption token to the decryption token generation unit; The decryption token generation unit receives the application from the decryption token application unit and generates a decryption token according to the message and sends it to the decryption token application unit after generating the decryption token; The aggregate signature decryption unit uses a decryption token to perform decryption and obtain the first part of the aggregate signature . After combining with , the aggregate signature is obtained; The single-pair aggregate signature of the signer sequence tracking After tracking, the signer sequence is obtained ; The notarization information receiving unit receives all the fragments of the time-lock puzzle 1, the fragments of the time-lock puzzle 2, and the identity ciphertext_notary to form a set of notarization ciphertext information pairs ; and after decrypting all , a set of signer identities is obtained. Conditional on , is screened to obtain signer identities, which together with the corresponding fragments of the time-lock puzzle 1 and the fragments of the time-lock puzzle 2 form a set of notarization information ; where represents the th notarization ciphertext information pair, represents the th fragment of the time-lock puzzle 1, represents the th fragment of the time-lock puzzle 2, represents the th identity ciphertext_notary; The aggregation signature recovery unit aggregates the fragments of the first time-lock puzzle to obtain the first time-lock puzzle . Then, after solving the first time-lock puzzle , the first part of the aggregation signature is obtained . Similarly, after aggregating the fragments of the second time-lock puzzle, the second time-lock puzzle is obtained. Then, after solving the second time-lock puzzle , the second part of the aggregation signature is obtained . Thus, after combining and , the aggregation signature is obtained.
2. A secure time-limited verifiable and traceable threshold signature method, characterized in that, It is applied to In a network environment consisting of [[0000171]] signers, 1 aggregator, 1 tracer, and 1 notary, the threshold signature method is carried out according to the following steps: Step 1. Initialization: Step 1.
1. Define relevant parameters, including: Set the security parameter to , , where is the length of the security parameter, is the degree of the polynomial; Set the time taken to solve the puzzle of the homomorphic time lock ; Define the size of the signer set as , and the threshold value of the accountable threshold signature is , ; Initialization Algorithm Using Homomorphic Timelocks Generate Homomorphic Timelock Parameters ; Initialization algorithm using the homomorphic commitment algorithm Generate homomorphic commitment parameters ; Use an initialization algorithm based on attribute encryption Generate attribute-based encryption parameters and a master key for attribute-based encryption ; Step 1.2: Generate the relevant keys of the accountable threshold signature algorithm, asymmetric encryption algorithm, and digital signature algorithm, as well as the public key of the cryptographic commitment ; Step 1.3: After combining the relevant parameters and keys respectively, the system parameters , the total public key , the aggregator's total private key , the notary's total private key ; Step 2. Message signature: Step 2.1: Randomly select signers, and sign the message respectively to obtain signature fragments; encrypt the message and the identities of signers respectively to obtain identity ciphertexts_aggregator, and send them together with signature fragments to the aggregator; Step 2.2, generate time-lock puzzles with the first part of the signature fragment as the answer, and generate time-lock puzzles with the second part of the signature fragment as the answer. At the same time, encrypt the identities of the signers, and after encryption, obtain the identity ciphertexts of the notary, and send them to the notary together with the time-lock puzzles: The th signer, according to the homomorphic time-lock parameter , and using the first part in as the riddle, uses the addition construction algorithm of the homomorphic time-lock puzzle to construct the fragment of the th time-lock puzzle one ; At the same time, according to the homomorphic time-lock parameter , and using the second part in as the riddle, uses the multiplication construction algorithm of the homomorphic time-lock puzzle to construct the fragment of the th signature puzzle two ; At the same time, according to the encryption public key of the notary , uses the encryption algorithm of asymmetric encryption to encrypt , and obtains the th identification ciphertext_notary ; Thus, , and are sent to the notary; Step 2.3, the th signer uses the construction algorithm of the homomorphic commitment algorithm to generate commitments , and according to the encrypted public key verified by the tracker , uses the encryption algorithm of asymmetric encryption to encrypt the identity of the th signer to obtain the th identity ciphertext_tracker , thereby sending and to the tracker; Step 3. Aggregation signature: Step 3.1: The aggregator receives the aggregated ciphertext information pair , and filters out signature fragments therefrom according to certain conditions, so that after aggregating signature fragments, an aggregated signature is obtained; Step 3.2, the aggregator encrypts the aggregated signature , and constructs a commitment , then encrypts to obtain the ciphertext of the message ; The aggregator, according to the message , uses an encryption algorithm based on attribute encryption to perform encryption and obtain the ciphertext of ; meanwhile, uses the construction algorithm of the homomorphic commitment algorithm to generate a commitment of the aggregate signature ; The aggregator uses the encrypted public key verified by the tracker , and uses an encryption algorithm of asymmetric encryption to encrypt the message and obtains the ciphertext of the message ; Step 3.3, the aggregator constructs a non-interactive zero-knowledge proof ; Step 3.4: The aggregator generates a signature of the aggregator , thereby obtaining a secure time-limited verifiable and traceable threshold signature and then sends it to the tracer; Step 4: The tracker tracks the aggregate signature to obtain the signer sequence ; Step 4.
1. Verify the signature, including: digital signature verification, non-interactive zero-knowledge proof verification, and homomorphic commitment verification. If all verifications pass, then execute Step 4.1; otherwise, end the process; Step 4.2: After the tracker interacts with the notary, obtain the decryption key based on attribute encryption : The tracer sends a request for the decryption key to the notary; After receiving the request, the notary generates a decryption key with the message as the attribute using the key extraction algorithm for attribute-based encryption according to the master key for attribute-based encryption and the message , and sends it to the tracker. and the message , uses the key extraction algorithm for attribute-based encryption to generate a decryption key with the message as the attribute and sends it to the tracker; Step 4.
3. The tracker uses the decryption key to decrypt the ciphertext of the first part of the aggregated signature and obtain the aggregated signature , thereby performing tracing on : The tracker receives the decryption key as an attribute , and uses the decryption algorithm based on attribute encryption to decrypt the ciphertext of the first part of the aggregated signature to obtain the first part of the aggregated signature ; thereby, after combining and , the aggregated signature is obtained; The tracker, based on the public key and the message , uses the tracing algorithm of accountable threshold signature to trace the aggregated signature and obtains the signer sequence ; Step 5: The notary aggregates the time-lock puzzle fragments sent by the signer, and then opens the puzzle to restore the aggregated signature ; Step 5.
1. After the notary receives all the fragments of the time-lock puzzle 1, the fragments of the time-lock puzzle 2, and the identity ciphertext_notary, a set of notarized ciphertext information pairs is formed. ; and according to the private key of the notary , using the decryption algorithm of asymmetric encryption to decrypt the identity ciphertext_notary , the signer identity set is obtained; The notary, on the condition that , selects from signer identifiers, and together with the fragments of the time-lock puzzle one and the fragments of the time-lock puzzle two, forms a notarization information set ; Step 5.2: The notary aggregates the fragments of the time-lock puzzle one and the fragments of the time-lock puzzle two respectively to obtain the time-lock puzzle one and the time-lock puzzle two, and then solves the two time-lock puzzles to finally obtain the aggregated signature .
3. A secure time-limited verifiable and traceable threshold signature method according to claim 2, characterized in that Step 1.2 includes: Key Generation Algorithm for Accountable Threshold Signature Generate the key and related parameters for accountable threshold signature, including: the parameters of the key generation algorithm for accountable threshold signature , the set of private keys , and the public key , where represents the private key of the -th signer, represents the public key of the -th signer; Key generation algorithm using asymmetric encryption Generate the encrypted private key of the aggregator , the encrypted public key of the aggregator , the encrypted private key of the tracer , the encrypted public key of the tracer , the encrypted private key of the notary , the encrypted public key of the notary , the encrypted private key for tracer verification , the encrypted public key for tracer verification ; Key generation algorithm using digital signature Generate the signature private key of the aggregator and the signature public key of the aggregator ; Select a random number from the real number group with a security parameter length of and use the homomorphic commitment generation algorithm to generate a public key for the cryptographic commitment of . .
4. A secure time-limited verifiable and traceable threshold signature method according to claim 3, characterized in that Step 1.3 includes: The key generation algorithm parameters of accountable threshold signature , homomorphic time lock parameters , homomorphic commitment parameters , attribute-based encryption parameters After combination, system parameters ; The encryption public key of the aggregator , the signature public key of the aggregator , the encryption public key of the tracer , the encryption public key of the notary , the verified encryption public key of the tracer , the cryptographic commitment are combined to obtain the total public key ; The public key , the encrypted private key of the aggregator , the signature private key of the aggregator , the threshold value , the public key 's cryptographic commitment , the random number are combined to obtain the aggregator's total private key ; Combine the public key and the encrypted private key of the tracker to obtain the total private key of the tracker ; Combine the encryption private key of the notary and the master key of attribute-based encryption to obtain the total private key of the notary .
5. A threshold signature method that is secure, time-limited, verifiable, and traceable according to claim 4, characterized in that Step 2.1 includes: The key generation algorithm parameters of accountable threshold signature , homomorphic time lock parameters , homomorphic commitment parameters , attribute-based encryption parameters After combination, system parameters ; The aggregator's encryption public key , the aggregator's signature public key , the tracer's encryption public key , the notary's encryption public key , the tracer-verified encryption public key , the cryptographic commitment After combining, the total public key ; The public key , the encrypted private key of the aggregator , the signature private key of the aggregator , the threshold value , the public key , the cryptographic commitment , the random number are combined to obtain the aggregator's total private key ; Combine the public key and the encrypted private key of the tracker to obtain the total private key of the tracker ; Combine the encrypted private key of the notary , and the master key for attribute-based encryption to obtain the total private key of the notary .
6. A threshold signature method that is secure, time-limited, verifiable, and traceable according to claim 5, characterized in that Step 3.1 includes: The aggregator receives all signature fragments and identity ciphertexts_aggregator, and forms a set of aggregated ciphertext information pairs , and uses the decryption algorithm of asymmetric encryption to decrypt all the identity ciphertexts_aggregator, and obtains a set of aggregated identity pairs ; With , as the condition, filter out of them, and form an aggregated information set with the corresponding signature fragments ; Among them, represents the th aggregated ciphertext information pair, represents the th signature fragment, represents the th identity ciphertext_aggregator, represents the th aggregated identity pair, represents the th signer identity, represents the th decrypted message, represents the total number of received information pairs; The aggregator, according to the public key and the message , uses the aggregation algorithm of accountable threshold signature to aggregate the in the aggregation information set signature fragments and obtains the aggregated signature ; among them, represents the first part of the aggregated signature, represents the second part of the aggregated signature.
7. A secure time-limited verifiable and traceable threshold signature method according to claim 6, characterized in that, Step 3.3 includes: The aggregator uses the encrypted public key verified by the tracker , and uses the encryption algorithm of asymmetric encryption to encrypt the threshold , and after encryption, obtains the ciphertext of the threshold ; The aggregator constructs a set according to the construction rule , and the construction rule is: when , set the corresponding th signer to participate in the identification as , otherwise, let the th signer participate in the identification as ; The aggregator constructs a non-interactive zero-knowledge proof , including: a verification algorithm for accountable threshold signatures , a verification algorithm for homomorphic commitment algorithms and an encryption algorithm based on attribute encryption of non-interactive zero-knowledge proofs.
8. A threshold signature method that is secure, time-limited, verifiable, and traceable according to claim 7, characterized in that Step 3.4 includes: The aggregator, according to the aggregator's private key , uses the signature algorithm of digital signature to sign the message , aggregator identifier , commitment of the aggregated signature , ciphertext of the first part of the aggregated signature , ciphertext of the threshold value and zero - knowledge proof to obtain the signature of the aggregator ; The aggregator identifier , the commitment of the aggregated signature , the ciphertext of the message , the second part of the aggregated signature , the ciphertext of the first part of the aggregated signature , the ciphertext of the threshold value , the zero-knowledge proof and the signature of the aggregator are combined to obtain a secure time-limited verifiable and traceable threshold signature , and is sent to the tracker module.
9. A secure time-limited verifiable and traceable threshold signature method according to claim 8, characterized in that, Step 4.1 includes: The tracker uses the decryption algorithm of asymmetric encryption based on the encrypted private key verified by the tracker , decrypts the ciphertext of the message using the decryption algorithm of asymmetric encryption, and obtains the message ; ; The tracker, based on the aggregator's encrypted public key , the message , the aggregator identifier , the commitment of the aggregated signature , the ciphertext of the first part of the aggregated signature , the ciphertext of the threshold value and the zero - knowledge proof , uses the verification algorithm of digital signature to verify the signature of the aggregator ; if the verification passes, continue the process, otherwise, terminate the process; The tracker verifies the zero-knowledge proof If the verification passes, the process continues; otherwise, the process is terminated. After the tracker receives all the identity ciphertexts and commitments, it forms a set of verified ciphertext information pairs , and according to the encrypted private key verified by the tracker , using the decryption algorithm of asymmetric encryption to decrypt all the identity ciphertexts of the tracker, and obtain the set of signer identities . Taking as the condition, filter out from signer identities, and form a set of verification information together with the corresponding commitments ; thus verifying the commitment of the aggregated signature and the corresponding relationship of the set . If the verification passes, continue the process; otherwise, terminate the process. Among them, represents the th verified ciphertext information pair, represents the th identity ciphertext of the tracker, represents the th commitment.
10. A threshold signature method that is secure, time-limited, verifiable, and traceable according to claim 9, characterized in that Step 5.2 includes: The notary uses the aggregation algorithm of the homomorphic time-lock puzzle according to the parameters of the homomorphic time-lock puzzle to aggregate the fragments of the time-lock puzzle one in to obtain the time-lock puzzle one ; where denotes the addition operation ; Meanwhile, according to the parameters of the homomorphic time-lock puzzle , using the aggregation algorithm of the homomorphic time-lock puzzle for the set in fragments of the time-lock puzzle two after aggregation, the time-lock puzzle two is obtained, where represents the multiplication form; The notary, according to the parameters of the homomorphic time-lock puzzle , uses the homomorphic time-lock puzzle addition puzzle-solving algorithm to solve the time-lock puzzle one and obtains the first part of the aggregate signature ; at the same time, according to the parameters of the homomorphic time-lock puzzle , uses the homomorphic time-lock puzzle multiplication puzzle-solving algorithm to solve the time-lock puzzle two and obtains the second part of the aggregate signature , and then combines with to obtain the aggregate signature .
Citation Information
Cited By
Traceable ring-type collaborative signature method and device and electronic equipment
CN121530591A