Traceable multi-signature method supporting distributed aggregator and lightweight setting

By introducing a decentralized signature generation mechanism and verifiable time commitment, the problem of low efficiency and insufficient security of existing multi-signature schemes in cross-chain asset bridges is solved, and the signer can be traced and held accountable, thereby improving the security and efficiency of cross-chain asset bridges.

CN120934772APending Publication Date: 2025-11-11EAST CHINA NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511250913.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-03
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing multi-signature schemes cannot simultaneously satisfy efficiency and security in cross-chain asset bridges. In particular, the reliance on aggregators leads to single point of failure risks and privacy leaks, and the DKG protocol results in high communication overhead.

Method used

It employs methods such as bilinear pairing, linear homomorphic time lock, cryptographic hash function, and BLS signature to implement a decentralized signature generation mechanism, allowing signers to generate key pairs locally, and introduces verifiable time commitments to restrict aggregation functions, supporting distributed aggregation and signature traceability.

Benefits of technology

It improves the security and efficiency of cross-chain asset bridges, enables signer traceability and accountability, reduces communication and computational overhead, and is suitable for efficient and secure applications of cross-chain asset bridges.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934772A_ABST
    Figure CN120934772A_ABST
Patent Text Reader

Abstract

The invention discloses a traceable multi-signature method supporting a distributed aggregator and lightweight setting, which is characterized in that a decentralized signature generation mechanism is realized by adopting a cryptographic method comprising bilinear pairing, a linear homomorphic time lock, a cryptographic hash function and a BLS signature; the method specifically comprises the steps of system initialization, key generation, authorization generation and aggregation, prompt generation, partial signature and verification, authorization verification, signature aggregation, authorization revocation, signature verification and the like. Compared with the prior art, the method has a decentralized key generation mechanism, a distributed aggregator mechanism and a signature accountability function, so that high communication overhead caused by the use of a distributed key generation protocol and a single-point fault possibly caused by excessive dependence on a single aggregator are avoided; and meanwhile, a strong association mechanism between the signer and the final multiple signatures is established, and the signer is responsible for the signature behavior of the signer, so that the problems of low efficiency and high centralization of aggregators caused by dependence on a DKG protocol are effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cross-chain asset bridges and multi-signature technology, and in particular to a traceable multi-signature scheme that supports distributed aggregators and lightweight setup. Background Technology

[0002] The characteristics of blockchain have driven the development of cross-chain technology. As a core channel for value circulation, the security of cross-chain asset bridges is directly related to the ecological foundation of the value internet. Cross-chain asset bridges achieve value mapping and state synchronization between different blockchains through trusted verification mechanisms.

[0003] Currently, while mainstream escrow pool models can achieve inter-chain asset anchoring, they face the structural threat of the "bucket effect." Two solutions exist, both with risks and limitations: centralized solutions, using Distributed Key Generation (DKG) to centrally manage private keys, are prone to single points of failure; fully decentralized solutions are limited by key sharding vulnerabilities in the key sharding management system if a threshold node is compromised. The multi-signature technology used in cross-chain asset bridges balances security and efficiency through a threshold encryption mechanism. For example, in a (6,10) threshold signature scheme, at least six verification nodes in the cross-chain bridge network are required to act as signers in the threshold signature scheme to verify the validity of transactions and collaboratively generate signatures. Its core process includes three stages: 1) Verification nodes verify the validity of source chain transactions and generate partial signatures; 2) Cross-chain credentials are generated through the DKG protocol and aggregate signature technology; 3) The target chain smart contract verifies the validity of the signature and then mints the anchored asset. This design eliminates the risk of a single private key through secret sharing and multi-party computation, increasing the attack cost from breaching a single node to breaching the threshold number of nodes simultaneously.

[0004] Existing multi-signature schemes typically rely on a specialized party called the aggregator to aggregate signatures from multiple signers and generate the final multi-signature. This aggregator plays a crucial role in the system, as it is responsible for receiving and aggregating the individual signatures provided by each signer. However, the presence of the aggregator poses a potential risk to the system's privacy and security. An attacked aggregator could access sensitive information belonging to the signers, including their signatures, potentially leading to privacy breaches and the theft of critical data. Furthermore, reliance on a specific aggregator entity introduces a new single point of failure risk. If the aggregator is maliciously attacked, it could disrupt the entire multi-signature process. Meanwhile, these multi-signature schemes effectively avoid reliance on a third-party central authority by utilizing the DKG protocol, generating a shared public key and multiple private keys through the collaboration of multiple participants. However, using DKGs during key generation results in a large number of communication operations, reducing signing efficiency. Some threshold signature schemes implement DKG-free solutions. However, they only have one aggregator, which still presents a single point of failure risk. Additionally, some schemes focus on optimizing the signature generation and verification process but neglect to incorporate accountability mechanisms, making it impossible to effectively trace the actual signers involved when the threshold signature is generated by the aggregator. Therefore, when invalid signatures occur, it becomes impossible to effectively identify a specific set of signers. In blockchain applications, such as cross-chain asset bridges, high efficiency and security are paramount. Not only do the signature schemes used in these applications need to be lightweight and unforgeable, but they also require effective tracking and accountability of the nodes (signers) involved in transactions between the two chains.

[0005] In conclusion, existing multi-signature schemes cannot simultaneously satisfy the efficiency and security requirements of the aforementioned cross-chain asset bridges. Summary of the Invention

[0006] The purpose of this invention is to address the shortcomings of existing technologies by providing a traceable multi-signature method that supports distributed aggregators and lightweight setup. It employs cryptographic methods including bilinear pairing, linear homomorphic time locks, cryptographic hash functions, and BLS signatures to achieve a decentralized signature generation mechanism. This method features a decentralized key generation mechanism, a distributed aggregator mechanism, and signature accountability, effectively avoiding the high communication overhead and single point of failure that can result from over-reliance on a single aggregator inherent in distributed key generation (DKG) protocols. Simultaneously, it establishes a strong correlation mechanism between the signer and the final multi-signature, ensuring that the signer is responsible for their signing actions. This effectively solves the problems of low efficiency and highly centralized aggregator caused by reliance on DKG protocols. This invention allows signers to generate signature key pairs locally, avoiding the use of DKG. Furthermore, it introduces the concept of verifiable time commitment to further limit the aggregator's aggregation function, preventing excessive centralization of aggregation functions. This not only provides better decentralized performance but also implements a tracking algorithm, enabling efficient tracing and accountability of the set of signers involved in the multi-signature process. The method is simple, easy to implement, and more flexible, meeting the requirements of a decentralized signature generation mechanism and making it better suited for cross-chain asset bridges, significantly improving blockchain security. Furthermore, this invention offers superior performance, maintaining low communication and computational overhead while simultaneously implementing distributed aggregators, lightweight setup, and accountability. The verification algorithm of this method outperforms other related schemes, significantly improving efficiency.

[0007] The objective of this invention is achieved as follows: a novel traceable multi-signature scheme supporting distributed aggregators and lightweight setup, characterized by employing cryptographic methods including bilinear pairing, linear homomorphic time locks, cryptographic hash functions, and BLS signatures to implement a decentralized signature generation mechanism, specifically including the following steps:

[0008] (I) System Initialization Phase

[0009] When inputting security parameters, the initialization algorithm generates a common reference string that serves as implicit input for subsequent algorithms. .

[0010] (ii) Key generation stage

[0011] The key generation algorithm generates public and private key pairs for the signer. .

[0012] (III) Authorization Generation Stage

[0013] Each signer runs the authorization generation algorithm to generate an authorization fragment. .

[0014] (iv) Time Lock Commitment Phase

[0015] Each signatory authorizes a segment Generate corresponding commitment and proof pairs within the promised time Afterwards, the authorized fragments are written into a public revocation list, and the aggregator can combine partial signatures before revocation.

[0016] (v) Authorization Aggregation Phase

[0017] Extract the set of signers who trust it. The authorization fragment sent to it The aggregator runs the authorization aggregation algorithm and computes the complete authorization. .

[0018] (vi) Prompt generation stage

[0019] Enter key and the number of signers At that time, each signer runs the hint generation algorithm and outputs hints for the following calculations. .

[0020] (vii) Signature preparation stage

[0021] Enter all pairs The signature preparation algorithm calculates the hint key. and verification key .

[0022] (viii) Partial Signature Stage

[0023] Enter key and messages The partial signature algorithm outputs a partial signature. .

[0024] (ix) Partial Verification Phase

[0025] Input message Partial signature of the signatory and the corresponding public key This verifies the validity of the signer's partial signature.

[0026] (x) Authorization Verification Phase

[0027] Inspection Commitment and proof Whether the specific equality conditions are met.

[0028] (xi) Signature aggregation stage

[0029] Given a set of partial signatures The aggregator combines all signatures into a compact signature. This is the final output multi-signature.

[0030] (xii) Authorization revocation stage

[0031] The signer runs a commitment to open the algorithm and will authorize it. Add it to the revocation list; any party other than the signer who generated the authorization can rescind it. Obtain authorization The forced open commitment algorithm must be run and in time. Only after that can you obtain This is determined by the nature of time locks.

[0032] (xiii) Signature Verification Stage

[0033] Input message Multi-signature Signer Collection , verification key and the set of signers who send authorized fragments to the aggregator This verifies the validity of the multi-signature.

[0034] The specific operations during the system initialization phase are as follows:

[0035] 1) Let , It is a group of prime order. , As their respective generators; let... for and The order; let It is a finite field;

[0036] 2) Randomly select one and select a hash function. Then, we get ;in: , Indicates the total number of signatories;

[0037] 3) Run the zero-knowledge initialization algorithm to generate a common reference string. Run the linear homomorphic time lock initialization algorithm to generate common parameters. Output common reference string Final output . It serves as the implicit input for subsequent algorithms.

[0038] The specific operations of the key generation stage are as follows:

[0039] 1) Participating parties Choose your own secret key And publish the corresponding public key. .

[0040] The specific operations of the authorization generation phase are as follows:

[0041] 1) Participating parties Select an authorized fragment , Through the safe passage Send to a participant it trusts .

[0042] The specific operations of the time lock commitment phase are as follows:

[0043] 1) For a given authorization Calculate the commitment and proof according to the following steps: Let and ; ,choose ,calculate ;

[0044] 2) For all ,calculate in For the first One Lagrange base;

[0045] 3) For ,for The fragments calculate the corresponding puzzles and proofs, where : , .

[0046] 4) Calculation , , Finally, output .

[0047] The specific operations of the authorization aggregation phase are as follows:

[0048] 1) By other parties One of the chosen ones Receive a collection Authorization;

[0049] 2) Let set What is collected is its Not satisfied All parties;

[0050] 3) Settings , Calculate the full authorization .

[0051] The specific operations during the prompt generation phase are as follows:

[0052] 1) Each party Calculate the following:

[0053] , , , Output .

[0054] The specific operations of the signature preparation stage are as follows:

[0055] 1) Calculate the auxiliary polynomial And the validity of the results was determined through a series of bilinear pairwise tests. For example, for It should satisfy .

[0056] 2) For It should satisfy the following formula:

[0057] ;

[0058] for The rest can be verified in a similar way.

[0059] 3) According to Calculate the hint key All Set as ,in the case of Set as ,in the case of Set as The prompt key It contains the following elements: That is .

[0060] 4) Calculate the verification key Calculate the private key polynomial Obtain the verification key .

[0061] The specific operations of the partial signature stage are as follows:

[0062] 1) Each signer uses their own key. Regarding the message Sign it;

[0063] 2) Output part signature .

[0064] The specific operations for the verification phase are as follows:

[0065] 1) Input partial signature Public key and messages If they satisfy the equation If the condition is met, output 1; otherwise, output 0.

[0066] The specific operations of the authorization verification phase are as follows:

[0067] 1) Input ,prove and public reference strings ,in Output 0 if any of the following conditions are met. Otherwise, output 1:

[0068] a, , making ;

[0069] b、 Make ;

[0070] c. Make or ;

[0071] d、 .

[0072] The specific operations of the signature aggregation stage are as follows:

[0073] 1) Subgroup Signing Message and partial signature Send to trusted combiner Perform aggregation;

[0074] 2) Calculate the aggregated public key and signature as follows: , ,

[0075] The final multi-signature is .

[0076] Because the combiner, representing the verifier, calculated... In order to verify To ensure the validity of the proof and prevent forgery by the combiner, the combiner needs to generate a certificate. To convince the verifier, to prove The calculation is correct.

[0077] For all ,let ,if ; It consists of the following: ; quotient polynomial and The commitment can be calculated as and They satisfy the equation ;calculate For inspection The degree of, among which ; Computational part and polynomial and ; Calculate polynomials and Used for inspection status and exist The value is 0.

[0078] Or 1;

[0079] and Intuitively, the first check Is the format good? Check the second identity. exist Whether the value is 0 or 1. It is dedicated to calculating... Using a hash function Generate one

[0080] A random ,in

[0081] .

[0082] The specific operations of the authorization revocation phase are as follows:

[0083] 1) Signer runs The algorithm will Add to the undo list;

[0084] 2) Other fragments where the signatory wishes to revoke authorization. Previously obtained Users can execute The algorithm operates as follows:

[0085] enter ,right implement , obtain All fragments. Because The puzzle has been opened by the submitter, which means... Just need to solve Puzzle. Output Finally, we got .

[0086] The specific operations of the signature verification stage are as follows:

[0087] 1) Verify authorization: Retrieve from the revocation list And calculate ;

[0088] 2) Verification and proof Verify all proofs of the polynomial and check and At point Does the following equation hold true at this point:

[0089] ;

[0090] 3) In upper inspection ;

[0091] 4) Verify aggregate signature : .

[0092] Compared with the prior art, the present invention has the following beneficial technical effects and significant technical progress:

[0093] 1) Greater Decentralization: This invention allows signers to generate signature key pairs locally, avoiding the use of a Data Key Generation (DKG) through lightweight setup, thereby improving the efficiency of the scheme. Building on this, the concept of Verifiable Time Commitment (VTC) is introduced, using a linear homomorphic time lock method to further restrict the aggregation function of aggregators, avoiding the centralization of aggregation functions and achieving distributed aggregation.

[0094] 2) Better application in cross-chain asset bridges: This invention is not only decentralized but also features a tracking algorithm, enabling efficient tracing and accountability of the set of signers who generate multi-signatures. These two features make this invention better applicable to cross-chain asset bridges, significantly improving blockchain security.

[0095] 3) Higher performance: This solution achieves three features simultaneously: distributed aggregator, lightweight setup, and accountability, while maintaining low communication and computational overhead. The verification algorithm outperforms other related solutions and significantly improves efficiency. Attached Figure Description

[0096] Figure 1 This is a schematic diagram of the system structure constructed according to the present invention;

[0097] Figure 2 This is a flowchart of the present invention. Detailed Implementation

[0098] The mathematical theory applied in this invention is explained as follows:

[0099] 1. Bilinear pairing

[0100] Bilinear pairing is a mathematical tool commonly used by cryptographers when constructing cryptographic schemes using elliptic curve cyclic groups, and is defined as follows:

[0101] set up and A cyclic group whose order is a large prime number q is called a mapping. For bilinear pairing, if It satisfies the following properties:

[0102] 1) Bilinear: For any and any They all .

[0103] 2) Non-degenerative: If It is a group The generator, then .

[0104] 3) Computability: For any , It can be efficiently calculated.

[0105] 2. Homomorphic Time Lock Puzzle

[0106] Homomorphic Temporal Lock Puzzle (HTLP) is solved using the quadruplet algorithm.

[0107] It is designed to hide a value for a specific duration and supports homomorphic operations on different time-locked puzzles.

[0108] 1) The initialization algorithm inputs security parameters. and time hardness parameters Output common parameters .

[0109] 2) The puzzle generation algorithm is a probabilistic algorithm, with the input time hardness parameter. ,untie and random numbers Output puzzle .

[0110] 3) The algorithm takes a puzzle as input. Output solution .

[0111] 4) The input commitment for this homomorphic operation algorithm Common parameters and A mystery After performing homomorphic operations on the puzzle set, a new puzzle is output. .

[0112] 3. Generalized summation test

[0113] set up It is a finite field multiplicative subgroups for The generator, let For Lag

[0114] Langerjian polynomials, satisfying when hour , hour . yes polynomials on, i.e. ,and , .

[0115] Define polynomial and If the following two expressions and All times not exceeding The polynomial of, then .

[0116] The present invention will be further described and illustrated in detail below with specific embodiments:

[0117] Example 1

[0118] See Figure 1 User A wants to transact with User B and operates on the source chain. The source chain locks information about User A and itself and sends the event to a cross-chain asset bridge network for verification. Nodes in the cross-chain asset bridge network check the event and sign those that pass verification. They send partial authorizations to nodes they trust. Nodes that receive a certain number of partial signatures are granted signature aggregation rights and become the current aggregator node. This threshold is reasonably set by the system to ensure that only one aggregator node is used for each signature. The aggregator node collects all partial signatures of the event and aggregates them into a multi-signature. The node that generated the signature revokes the authorizations it sent to the aggregator node by publicly disclosing the previously generated partial authorizations, causing the aggregator node to lose its aggregation rights. The aggregator node sends the multi-signature it aggregated at a specific time to the target chain, which verifies the validity of the multi-signature. User B accepts the transaction initiated by User A on the target chain.

[0119] See Figure 2 The traceable implementation process of multi-signature includes the following steps:

[0120] (I) System Initialization Phase

[0121] When inputting security parameters, the initialization algorithm generates a common reference string, which serves as an implicit input for other algorithms.

[0122] (ii) Key generation stage

[0123] The key generation algorithm generates public and private key pairs for the signer. .

[0124] (III) Authorization Generation Stage

[0125] Each signer runs the authorization generation algorithm to generate an authorization fragment. .

[0126] (iv) Time Lock Commitment Phase

[0127] Each signatory authorizes a segment Generate corresponding commitment and proof pairs Within the promised timeframe After that, authorized fragment It is written into the public revocation list, and the aggregator can combine partial signatures before revocation.

[0128] (v) Authorization Aggregation Phase

[0129] Extract the set of signers who trust it. The authorization fragment sent to it The aggregator runs the authorization aggregation algorithm and computes the complete authorization. .

[0130] (vi) Prompt generation stage

[0131] Enter key and the number of signers At that time, each signer runs the hint generation algorithm and outputs hints for subsequent calculations. .

[0132] (vii) Signature preparation stage

[0133] Enter all pairs The signature preparation algorithm calculates the hint key. and verification key .

[0134] (viii) Partial Signature Stage

[0135] Enter key and messages The partial signature algorithm outputs a partial signature. .

[0136] (ix) Partial Verification Phase

[0137] Input message Partial signature of the signatory and the corresponding public key This verifies the validity of the signer's partial signature.

[0138] (x) Authorization Verification Phase

[0139] Inspection Commitment and Whether the specific equality conditions are met.

[0140] (xi) Signature aggregation stage

[0141] Given a set of partial signatures The aggregator combines all signatures into a compact signature. This refers to the final output multi-signature.

[0142] (xii) Authorization revocation stage

[0143] The signer runs a commitment to open the algorithm and will authorize it. Add it to the revocation list; any party other than the signer who generated the authorization can rescind it. Obtain authorization The forced open commitment algorithm must be run and in time. Only after that can you obtain This is determined by the nature of time locks.

[0144] (xiii) Signature Verification Stage

[0145] Input message Multi-signature Signer Collection , verification key and the set of signers who send authorized fragments to the aggregator This verifies the validity of the multi-signature.

[0146] The specific operations for step (I), the system initialization phase, are as follows:

[0147] 1) Let , It is a group of prime order. , As their respective generators; let p be... and The order; let It is a finite field, and a random one is selected. and select a hash function. Then get ,

[0148] Here is This is the maximum number of signers. This indicates the total number of signatories.

[0149] 2) Run the zero-knowledge initialization algorithm to generate a common reference string. Run the linear homomorphic time lock initialization algorithm to generate common parameters. Output common reference string Final output . It serves as the implicit input for subsequent algorithms.

[0150] The specific operations for step (ii) key generation are as follows:

[0151] 1) Participating parties Choose your own secret key And publish the corresponding public key. .

[0152] The specific operations for step (iii) of the authorization generation stage are as follows:

[0153] 1) Participating parties Select an authorized fragment , Through the safe passage Send to a participant it trusts .

[0154] The specific operations for step (iv), the time lock commitment phase, are as follows:

[0155] 1) For a given authorization Calculate the commitment and proof by following these steps:

[0156] set up and . ,choose ,calculate For all ,calculate , .in, For the first Lagrange bases.

[0157] 2) For ,for The fragments calculate the corresponding puzzles and proofs, where : , .calculate , , Finally, output .

[0158] The specific operations for step (v) of the authorization aggregation phase are as follows:

[0159] 1) By other parties One of the chosen ones Receive a collection Authorization.

[0160] 2) Let set What is collected is its Not satisfied All parties, set up . Calculate the full authorization .

[0161] The specific operations for the generation stage in step (vi) are as follows:

[0162] 1) Each party Calculate the following:

[0163] , , ,

[0164] 2) Output .

[0165] The specific operations for step (vii), the signature preparation stage, are as follows:

[0166] 1) Calculate the auxiliary polynomial And the validity of the results was determined through a series of bilinear pairwise tests. For example, for It should satisfy .for It should satisfy .for The rest can be verified in a similar way.

[0167] 2) According to Calculate the hint key All Set as ,in the case of Set as ,in the case of Set as The It contains the following elements:

[0168] That is .

[0169] 3) Calculate the verification key Private key polynomial Obtain the verification key .

[0170] The specific operations for the signature stage in step (viii) are as follows:

[0171] 1) Each signer uses their own key. Regarding the message Perform the signature. Output the partial signature. .

[0172] The specific operations for the verification phase in step (nine) are as follows:

[0173] 1) Input partial signature Public key and messages If they satisfy the equation If the condition is met, output 1; otherwise, output 0.

[0174] The specific operations for step (ten), the authorization and verification phase, are as follows:

[0175] 1) Input ,prove and public reference strings ,in .

[0176] 2) Output 0 if any of the following conditions are met. Otherwise, output 1.

[0177] a, , making ;

[0178] b、 Make ;

[0179] c. Make or ;

[0180] d、 .

[0181] The specific operations of step (xi) signature aggregation stage are as follows:

[0182] 1) Subgroup Signing Message and partial signature Send to trusted combiner Perform aggregation.

[0183] 2) Calculate the aggregated public key and signature as follows: , ,

[0184] The final multi-signature is .

[0185] Because the combiner, representing the verifier, calculated... In order to verify To ensure the validity of the proof and prevent forgery by the combiner, the combiner needs to generate a certificate. To convince the verifier, to prove The calculation is correct.

[0186] For all ,let if . It consists of the following: ; quotient polynomial and The commitment can be calculated as ,and They satisfy the equation ;calculate For inspection The degree of, among which ; Computational part and polynomial and ; Calculate polynomials and Used for inspection status and exist The value is 0.

[0187] Or 1;

[0188] and Intuitively, the first check Is the format good? Check the second identity. exist Whether the value is 0 or 1. It is dedicated to calculating... Using hash functions Generate one

[0189] A random .in

[0190] .

[0191] The specific operations for step (twelfth) authorization revocation phase are as follows:

[0192] 1) Signer runs The algorithm will Add to the undo list.

[0193] 2) Other fragments where the signatory wishes to revoke authorization. Previously obtained Users can execute The algorithm operates as follows:

[0194] enter ,right implement , obtain All fragments. Because The puzzle has been opened by the submitter, which means... Just need to solve Puzzle. Output Finally, we got .

[0195] The specific operations for step (thirteen), the signature verification stage, are as follows:

[0196] 1) Verify authorization: Retrieve from the revocation list And calculate ;

[0197] 2) Verification and proof Verify all proofs of the polynomial and check and

[0198] At point Does the following equation hold true at this point:

[0199] ,exist upper inspection .

[0200] 3) Verify aggregate signature : .

[0201] The above embodiments employ cryptographic methods including bilinear pairing, linear homomorphic time locks, BLS signatures, and accountable subgroup multi-signatures to achieve a decentralized signature generation mechanism. In blockchain application scenarios, such as cross-chain asset bridging, high efficiency and high security are required. Not only do the signature schemes used need to be efficient and secure, but they also need to be able to track and hold accountable the nodes (signers in the signature scheme) that confirm transactions between the two chains.

[0202] The scope of protection of this invention is not limited to the above embodiments. Any variations and advantages that can be conceived by those skilled in the art without departing from the spirit and scope of the inventive concept are included in this invention and are protected by the claims.

Claims

1. A traceable multi-signature method supporting distributed aggregators and lightweight setup, characterized in that, A decentralized, traceable multi-signature is achieved using cryptographic methods including bilinear pairing, linear homomorphic time locks, cryptographic hash functions, and BLS signatures. The method specifically includes the following steps: (I) System Initialization Phase When the system inputs security parameters, the initialization algorithm generates a common reference string that serves as implicit input for subsequent algorithms. ; (ii) Key generation stage The key generation algorithm generates public and private key pairs for the signer. ; (III) Authorization Generation Stage Each signer runs the authorization generation algorithm to generate an authorization fragment. ; (iv) Time Lock Commitment Phase Each signatory authorizes a segment Generate corresponding commitment and proof pairs within the promised time After that, authorized fragment The signature is added to the public revocation list, and the aggregator can aggregate partial signatures before revocation. (v) Authorization Aggregation Phase Extract the set of signers who trust it. The authorization fragment sent to it The aggregator runs the authorization aggregation algorithm and computes the complete authorization. ; (vi) Prompt generation stage Enter key and the number of signers Each signer runs a hint generation algorithm and outputs hints for subsequent calculations. ; (vii) Signature preparation stage Enter all prompts and public key pairs The signature preparation algorithm calculates the hint key. and verification key ; (viii) Partial Signature Stage Enter private key and messages The system outputs a partial signature generated by the partial signature algorithm. ; (ix) Partial Verification Phase Input message Partial signature of the signatory and the corresponding public key Verify the signer's partial signature Validity; (x) Authorization Verification Phase Inspection Commitment and the corresponding proof Does it satisfy the set equality relationship? (xi) Signature aggregation stage Given a set of partial signatures The aggregator combines all signatures into a compact signature. This means the final output is multi-signature; (xii) Authorization revocation stage The signer runs the commitment to open the algorithm and authorizes the fragment. Add to the revocation list; any party other than the signer who generated the authorization can withdraw from it. Obtaining authorized fragments The forced open commitment algorithm must be run, and within a certain timeframe. Only after that can authorized segments be obtained. ; (xiii) Signature Verification Stage Input message Multi-signature Signer Collection , verification key and sending authorization fragments to the aggregator Signer set This verifies the validity of the multi-signature.

2. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, The system initialization phase specifically includes: 1) Let , It is a group of prime order. , for and The generator; let for and The order; let For a finite field, randomly select one and select a hash function. ; 2) Based on the above settings, we obtain ,in: ; The total number of signatories; 3) Run the zero-knowledge initialization algorithm to generate a common reference string. Run the linear homomorphic time lock initialization algorithm to generate common parameters. The system outputs a common reference string. Final output This string serves as the implicit input for subsequent algorithms, where: crs1 is a system-defined common reference string; crs2 is a combination of the common reference strings obtained from running two different initialization algorithms, crs2=(crs r ,pp); crs is the common reference string crs=(crs1, crs2) of the final initialization output of the system, that is crs=(crs1,crs2)=(crs1, (crs2) r , pp)).

3. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, Participants in the key generation phase Choose your own secret key and publish the corresponding public key. .

4. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, Participants in the authorization generation phase Select an authorized fragment ,but Authorized fragments via secure channel Send to a participant it trusts .

5. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, The time-lock commitment phase for a given authorization segment Calculate the commitment and proof according to the following steps: 1) Let and ; 2) ,choose ,calculate ; 3) For all ,calculate , ,in For the first One Lagrange base; 4) For ,for The fragments calculate the corresponding puzzles and proofs, where : , ; 5) Calculation , , ; 6) Finally, output the authorization fragment. The result of exponentiation ,promise and corresponding proof 6. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, The authorization aggregation phase specifically includes: 1) By other parties One of the chosen ones Receive a collection Authorization; 2) Let set The collected fragments are authorized segments. Not satisfied All parties; 3) Settings , Calculate the complete authorization .

7. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, Each participant in the prompt generation phase Calculate the following: 1) ; 2) ; 3) , ; Final output prompt .

8. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, The signature preparation stage specifically includes: 1) Calculation And the validity of the results was demonstrated through a series of bilinear pairwise tests; 2) According to calculate ; All Set as ;like Set as ;like Set as The prompt key It contains the following elements: ,Right now ; 3) Calculate the verification key and private key polynomial Participant polynomial Obtain the verification key .

9. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, In the partial signature phase, each signer uses their own key. Regarding the message The system performs a signature check and outputs a partial signature. .

10. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, The partial signature is input during the verification phase. Public key and messages If the equation is satisfied If the condition is met, output 1; otherwise, output 0.

11. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, The authorization verification phase specifically includes: 1) Input ,prove and public reference strings ,in ; 2) Output 0 if the above input satisfies any of the following conditions; otherwise, output 1: a, , making ; b、 , making ; Make or ; d、 。 12. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, The signature aggregation stage specifically includes: 1) Subgroup Signing Message and partial signature Send to trusted combiner Perform aggregation; 2) Calculate the aggregated public key and signature as follows: The final multi-signature is .

13. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, The authorization revocation phase specifically includes: 1) Signer runs The algorithm will authorize fragments Add to the undo list; 2) Other fragments where the signatory wishes to revoke authorization. Previously obtained Users, execute The algorithm, whose operation is: input ,right implement , obtain All segments; 3) Output Finally, the authorized segment was obtained. .

14. The traceable multi-signature method supporting distributed aggregators and lightweight setup according to claim 1, characterized in that, The signature verification stage specifically includes: 1) Verify authorization: Retrieve from the revocation list and calculate ; 2) Verification and proof Verify all proofs of the polynomial and check the polynomial. and polynomial At point Does the following equation hold true at this point? ; 3) In polynomials upper inspection Is it valid? 4) Verify aggregate signature : .