Cleanable certificateless signcryption method, device, equipment and system

By using a key generation center to generate public parameters and partial private keys in the UAV-vehicle air-to-ground collaborative network, the data sending end generates signed ciphertext, and the purification end performs re-randomization, the inefficiency and security problems of certificateless signature systems are solved, and efficient data encryption and identity authentication are achieved.

CN120934859APending Publication Date: 2025-11-11BEIHANG UNIV +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511173658.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-21
Publication Date
2025-11-11

Smart Images

  • Figure CN120934859A_ABST
    Figure CN120934859A_ABST
Patent Text Reader

Abstract

The invention provides a cleanable certificateless signcryption method, a cleanable certificateless signcryption device, cleanable certificateless signcryption equipment and a cleanable certificateless signcryption system. Receiving a signcryption ciphertext which is sent by the data sending end and contains signature information and ciphertext information; verifying the signcryption ciphertext according to the public parameter and the key information; and after the verification is passed, re-randomizing signature information and ciphertext information in the signcryption ciphertext in an undecrypted state to obtain a purified signcryption ciphertext, and sending the purified signcryption ciphertext to a data receiving end to trigger the data receiving end to verify and decrypt the purified signcryption ciphertext to obtain plaintext information corresponding to the ciphertext information. According to the method and the device, the signcryption ciphertext can be re-random on the premise that the ciphertext is not unlocked, and meanwhile, the re-random signcryption ciphertext is ensured to still meet confidentiality and integrity and can be verified by a receiving end, so that leakage attack behaviors of a malicious data sender are effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication encryption, specifically to a method, apparatus, device, and system for purifying uncertified signature encryption. Background Technology

[0002] In some communication network scenarios, such as drone-vehicle air-to-ground collaborative networks, attackers can launch attacks on the system through methods such as signal eavesdropping, identity forgery, and data tampering, threatening the system's security and stability. Therefore, it is necessary to provide data encryption, integrity authentication, and identity verification before sharing data with users to prevent data leakage and falsified data.

[0003] Data signature cryptography combines encryption and signing in a public-key cryptosystem, implementing encryption and signing in a single logical step. This reduces the overall computational load and communication cost of encrypting and signing messages, while ensuring data confidentiality, integrity, and authentication. However, overly centralized signature cryptography systems are unsuitable for resource-constrained dynamic networks like UAV-vehicle air-to-ground collaboration due to single points of failure and cross-domain trust synchronization delays. They fail to meet the dynamic topology and distributed authentication requirements of air-to-ground collaborative networks. Furthermore, existing methods struggle to prevent malicious data senders from actively leaking information. For example, a malicious sender could leak part of the secret value to an unauthorized recipient while generating encrypted data, allowing the recipient to recover the plaintext data without the legitimate key.

[0004] Existing research has further proposed certificateless signature encryption systems to address the issues of public key certificate management and key escrow, while avoiding single points of failure. Simultaneously, researchers have proposed sanitization methods to prevent malicious data senders from actively disclosing their data. This involves re-randomizing the ciphertext without decryption, ensuring that the modified ciphertext still maintains confidentiality and integrity. However, certificateless signature encryption systems cannot simultaneously achieve signature encryption and sanitization. Furthermore, the re-randomization process in sanitization alters the original ciphertext data structure, meaning that while the receiver can decrypt the re-randomized ciphertext, they cannot verify the signature. Moreover, existing sanitization methods, such as fully homomorphic encryption and chameleon hashing, are inefficient and introduce security vulnerabilities. Summary of the Invention

[0005] In view of this, the present disclosure provides a method, apparatus, device and system for purifying uncertified signature encryption, which at least partially solves the problems existing in the prior art.

[0006] In a first aspect, embodiments of this disclosure provide a method for purifying certificate-less signature encryption, including:

[0007] Receive public parameters sent by the key generation center;

[0008] Receive the signed and encrypted data sent by the data sender.

[0009] The signed ciphertext is verified based on the public parameters and key information; the key information includes the key information of the data sender and the key information of the data receiver.

[0010] After successful verification, the signature information and ciphertext information in the signed ciphertext are re-randomized in the undecrypted state to obtain purified signed ciphertext, which is then sent to the data receiving end to trigger the data receiving end to verify and decrypt the purified signed ciphertext to obtain plaintext information corresponding to the ciphertext information. The signature information and ciphertext information in the signed ciphertext are independent of each other before and after re-randomization, so that the signature information can be verified by the data receiving end after re-randomization.

[0011] Secondly, embodiments of this disclosure provide a method for purifying certificate-free signature encryption, comprising:

[0012] The key generation center generates public parameters, a first part of the sender's private key corresponding to the data sender, and a first part of the receiver's private key corresponding to the data receiver. The public parameters and the first part of the sender's private key are sent to the data sender, the public parameters and the first part of the receiver's private key are sent to the data receiver, and the public parameters are sent to the purification end.

[0013] The data sending end uses its own sender public key PK. s The sender's complete private key SK s Public parameters, the receiver's public key PK. r and identity ID r The data M to be sent is signed and encrypted to generate a signed and encrypted message containing signature information and ciphertext information, and the signed and encrypted message is sent to the purification end; wherein, the complete private key SK of the sending end is... s Generate based on the first part of the sender's private key and the second part of the sender's private key generated by the data sender itself;

[0014] After receiving the signed ciphertext, the purification terminal uses the common parameters, PK... s The identity ID of the data sender s PK r ID r The identity of the data sender is verified. After the verification is successful, the signature information and ciphertext information in the signed ciphertext are re-randomized in the undecrypted state to obtain the purified signed ciphertext, which is then sent to the data receiver.

[0015] After receiving the cleaned and signed ciphertext, the data receiving end uses the public parameters and the receiving end's complete private key SK. r Verification and decryption are performed on it; wherein, the complete private key SK of the receiving end is used. r It is generated based on the first part of the receiver's private key and the second part of the receiver's private key generated by the data receiver itself.

[0016] Thirdly, embodiments of this disclosure provide a device capable of purifying certificate-free signature encryption devices, comprising:

[0017] At least one processor; and,

[0018] The memory is communicatively connected to the at least one processor; wherein,

[0019] The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the cleanable certificate-free signature method of claim 1.

[0020] Fourthly, embodiments of this disclosure provide a cleanupable certificate-free signature and encryption system, comprising:

[0021] A key generation center is used to generate public parameters, a first part of the sender's private key corresponding to the data sender, and a first part of the receiver's private key corresponding to the data receiver. The center then sends the public parameters and the first part of the sender's private key to the data sender, sends the public parameters and the first part of the receiver's private key to the data receiver, and sends the public parameters to the purification end.

[0022] The data sending end is used to send data based on its own sender public key PK. s The sender's complete private key SK s Public parameters and the receiver's public key PK. r and identity ID r The data M to be sent is signed and encrypted to generate a signed and encrypted message containing signature information and ciphertext information, and the signed and encrypted message is sent to the purification end; wherein, the complete private key SK of the sending end is... s Generate based on the first part of the sender's private key and the second part of the sender's private key generated by the data sender itself;

[0023] The purification terminal is used to, upon receiving the signed ciphertext, determine the PK value based on common parameters. s The identity ID of the data sender s PK r ID rThe identity of the data sender is verified. After the verification is successful, the signature information and ciphertext information in the signed ciphertext are re-randomized in the undecrypted state to obtain the purified signed ciphertext, which is then sent to the data receiver.

[0024] The data receiving end is used, after receiving the cleaned and signed ciphertext, to determine the appropriate parameters based on the public parameters and the receiver's complete private key SK. r Verification and decryption are performed on it; wherein, the complete private key SK of the receiving end is used. r It is generated based on the first part of the receiver's private key and the second part of the receiver's private key generated by the data receiver itself.

[0025] In summary, compared with the prior art, this embodiment has the following advantages:

[0026] 1. Simultaneously perform encryption and decryption operations within a single logical step, reducing the total computational load and communication cost of encrypting and signing messages, and ensuring the confidentiality, integrity, and authentication of data.

[0027] 2. Re-randomize the signed ciphertext without decrypting it, while ensuring that the re-randomized signed ciphertext still meets confidentiality and integrity requirements and can be verified by the receiving end, thereby effectively preventing malicious data senders from leaking data. Attached Figure Description

[0028] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0029] Figure 1 This is a schematic diagram of the structure of the purification certificate-free signature system provided in the first embodiment of the present invention;

[0030] Figure 2 This is a flowchart illustrating the purification method for certificate-free signature encryption provided in the second embodiment of the present invention.

[0031] Figure 3 This is a flowchart illustrating the purification method for certificate-free signature encryption provided in the third embodiment of the present invention.

[0032] Figure 4 This is a schematic diagram of the structure of the purification-free signature device provided in the fourth embodiment of the present invention. Detailed Implementation

[0033] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0034] The following specific examples illustrate the implementation of this disclosure. Those skilled in the art can easily understand other advantages and effects of this disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. This disclosure can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this disclosure. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0035] It should be noted that various aspects of embodiments within the scope of the appended claims are described below. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any particular structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using structures and / or functionalities other than one or more of the aspects set forth herein.

[0036] It should also be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of this disclosure. The drawings only show the components related to this disclosure and are not drawn according to the number, shape and size of the components in actual implementation. In actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0037] Furthermore, specific details are provided in the following description to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.

[0038] This invention provides a method, apparatus, device, and system for purifying uncertified signature encryption, aiming to improve communication security and efficiency in some special communication fields. To facilitate understanding of this invention, network communication in the air-ground coordination process will be used as an example to illustrate this invention. However, it should be understood that communication in other fields is also within the protection scope of this invention, and will not be elaborated here.

[0039] Air-to-ground collaboration refers to leveraging the advantages of drones in terms of mobility, coverage, and flexible deployment to complement ground-based vehicle-to-everything (V2X) systems. By providing on-demand aerial connectivity, it significantly enhances the coverage and situational awareness capabilities of V2X networks. However, existing drone-vehicle air-to-ground collaborative networks suffer from overly centralized signature encryption systems. Air-to-ground collaborative networks are characterized by rapid changes in dynamic network topology and distributed authentication; overly centralized signature encryption algorithms suffer from single points of failure and cross-domain trust synchronization delays. Furthermore, air-to-ground collaborative networks involve numerous participants, including malicious data senders who can leak partial secret values ​​to unauthorized recipients, allowing unauthorized recipients to recover the corresponding plaintext data without a legitimate key. For example, virus-infected drones could leak road network data to foreign forces, and malicious nodes in a drone swarm could leak real-time flight data to attackers.

[0040] To improve the above issues, please refer to Figure 1 The first embodiment of the present invention provides a cleanupable certificate-free signature system, comprising:

[0041] The key generation center 10 is used to generate public parameters, a first part of the private key for the data sending end 20, and a first part of the private key for the data receiving end 40. The public parameters and the first part of the private key for the data sending end are sent to the data sending end 20, the public parameters and the first part of the private key for the data receiving end 40 are sent to the data receiving end 40, and the public parameters are sent to the purification end 30.

[0042] In this embodiment, the key generation center 10 can be a semi-trusted third-party organization, which is responsible for providing registration for all participants in the system, generating public parameters in the system, and generating partial private keys for the participants.

[0043] Specifically, the steps for the key generation center 10 to generate public parameters are as follows:

[0044] Set a safety parameter λ, and select two prime-order multiplicative groups G and G'. T The generator of group G is g, and its prime order is p; G × G → G T It is a bilinear mapping;

[0045] Here, a bilinear mapping e: G×G→G is defined. T It satisfies the following properties:

[0046] (1) Bilinear: For all g, h ∈ G, e(g a ,h b )=e(g,h) ab .

[0047] (2) Non-degeneracy: There exist g, h∈G such that

[0048] (3) Computability: For all g,h∈G, e(g,h) can be solved in polynomial time.

[0049] Randomly select master private key Calculate g1 = g α , g2∈G;

[0050] Choose a hash function H. The hash function has the following definition:

[0051] H:{0,1} * →G

[0052] Generate common parameters params = {G, G T ,e,g,g1,g2,H};

[0053] The key generation center 10 generates a portion of the user's private key d. user The steps are as follows:

[0054] Get the user's identity ID u ∈{0,1} n ;

[0055] Random selection Calculate part of the user's private key d user :

[0056]

[0057] Then correspondingly:

[0058] Part 1: Sender's Private Key

[0059] Part 1: Receiver's Private Key

[0060] The data sending end 20 is used to send data based on its own sending end public key PK. s The sender's complete private key SK s Public parameters and the receiver's public key PK. r and identity ID r The data M to be sent is signed and encrypted to generate a signed and encrypted message containing signature information and ciphertext information, and the signed and encrypted message is sent to the purification end; wherein, the complete private key SK of the sending end is... s It is generated based on the first part of the sender's private key and the second part of the sender's private key generated by the data sender 20 itself.

[0061] In this embodiment, the data sending end 20 mainly includes drones with sensing capabilities, intelligent connected vehicles, and roadside equipment, etc. The data sending end 20 provides the collected information or data services provided by the cloud center to the data receiving end 40; wherein, in order to ensure the confidentiality and integrity of the data, it is necessary to sign the data.

[0062] Specifically, in order to achieve encrypted signature, the data sending end 20 first needs to generate its own key information, including a public key and a private key. Specifically, the data sending end 20 generates a sending end public key PK. s and the sender's complete private key SK s The steps are as follows:

[0063] Random selection but:

[0064]

[0065] Similarly, the data receiver 40 generates a receiver public key PK. r and the receiver's complete private key SK r The steps are as follows:

[0066] Random selection but:

[0067]

[0068] At this point, after obtaining its own key information and the public key information of the data receiving end 40, the data sending end 20 can encrypt the plaintext information M to be sent to obtain the signed ciphertext. The specific calculation process is as follows:

[0069] Random selection calculate

[0070] calculate:

[0071] calculate:

[0072] set up:

[0073] calculate:

[0074] Generate the ciphertext σ = (σ1, σ2, σ3, σ4, σ5).

[0075] In this process, the plaintext M is mapped into σ1 by multiplying with the bilinear mapping, thus achieving encryption. Among the subsequent parameters, σ4 and σ5 are used to verify the validity of the signed message, and σ2 and σ3 are used to decrypt and obtain the plaintext message.

[0076] Furthermore, in this embodiment, the unique identifiers of the sender and receiver, such as ID card numbers, can be used as public key information to generate a public key for verifying the signature. Therefore, this system does not require certificate binding and is a de facto certificate-free system. The generation of the user's private key includes two parts. First, the key generation center 10 generates a first part of the private key. Then, the data sending end 20 and the data receiving end 40 respectively generate a second part of the private key locally. The two parts of the private key are combined to obtain the complete private key and stored on the user's side, ensuring that the key generation center 10 cannot obtain the complete private key and avoiding single point of failure.

[0077] The purification terminal 30 is used to, upon receiving the signed ciphertext, determine the PK value based on common parameters. s The identity ID of the data sender s PK r ID r The identity of the data sender is verified. After the verification is successful, the signature information and ciphertext information in the signed ciphertext are re-randomized in the undecrypted state to obtain the purified signed ciphertext, which is then sent to the data receiver 40.

[0078] In this embodiment, the purification terminal 3 is mainly a roadside unit, located in the network structure between the data sending terminal 20 and the data receiving terminal 40. Its main function is to verify the legitimacy of the data sending terminal 20, and to prevent data leakage attacks by malicious senders, to re-randomize the signed data. Specifically:

[0079] The process by which the purification terminal 30 verifies the identity and legitimacy of the data sending terminal 20 is as follows:

[0080] judge:

[0081]

[0082] If the condition is met, the verification passes; otherwise, the verification fails.

[0083] The process of re-randomizing the signed and encrypted text at the purification terminal 30 is as follows:

[0084] Random selection

[0085] calculate:

[0086] calculate:

[0087] calculate:

[0088] calculate:

[0089] calculate:

[0090] calculate:

[0091] Output the cleaned signature ciphertext after re-randomization: σ'=(σ'1,σ'2,σ'3,σ'4,σ'5).

[0092] In this embodiment, based on the structure of the original ciphertext, T1, T2, T3, T4, and T5 are designed according to the common parameters. The original ciphertext σ1, σ2, σ3, σ4, and σ5 are multiplied by T1-T5 respectively. This enables the re-randomization of σ1, the signature, and other related parameters. Finally, the signed ciphertext can still be decrypted and verified by the receiving end using the purified signature, other parameters, its own private key, and the sender's public key.

[0093] As can be seen, the signed ciphertext is not decrypted during the cleanup process. At the same time, the algorithm's data structure ensures that the re-randomized signed ciphertext still meets confidentiality and integrity requirements and can be verified by the receiving end, thus effectively preventing malicious data senders from leaking data.

[0094] The data receiving end 40 is used, after receiving the cleaned and signed ciphertext, to determine the appropriate parameters based on the public parameters and the receiver's complete private key SK. r Verification and decryption are performed on it; wherein, the complete private key SK of the receiving end is used. r It is generated based on the first part of the receiver's private key and the second part of the receiver's private key generated by itself.

[0095] In this embodiment, the data receiving end 40 mainly includes legitimate intelligent connected vehicles that have subscribed to data services. After receiving the purified signature and ciphertext from the purification end 30, the receiving end 40 verifies and decrypts the purified signature and ciphertext to obtain the data service.

[0096] Specifically: the process by which the data receiving end 40 verifies the received cleaned signature ciphertext is as follows:

[0097] judge:

[0098]

[0099] If the condition is met, the verification passes; otherwise, the verification fails.

[0100] The process by which the data receiving end 40 decrypts the received cleaned signature ciphertext is as follows:

[0101] Based on the receiver's complete private key SK r Perform decryption calculation:

[0102] The verification process for this decryption calculation is as follows:

[0103]

[0104] In summary, based on this embodiment, one or more of the following beneficial effects can be achieved:

[0105] 1. Simultaneously perform encryption and decryption operations within a single logical step, reducing the total computational load and communication cost of encrypting and signing messages, and ensuring the confidentiality, integrity, and authentication of data.

[0106] 2. Certificate-free cryptography. In this embodiment, the user's public key is generated from the identity identifier and the system's public parameters, without the need for certificate binding. The user's private key consists of two parts: one part is generated by the key generation center 10, and the other part is generated locally by the user. Together, they constitute the complete private key and are secretly stored on the user's side, ensuring that the key generation center 10 cannot obtain the complete private key. The user can fully control a portion of the private key, avoiding single points of failure, making it suitable for distributed, resource-constrained dynamic systems such as UAV-vehicle air-to-ground collaboration.

[0107] 3. By adding a purification terminal (30), the ciphertext is re-randomized without decryption, while ensuring that the modified ciphertext still meets confidentiality and integrity requirements. This effectively prevents malicious data senders from leaking or attacking the ciphertext.

[0108] 4. Technical Coupling of Sign-encryption and Decryption. During the ciphertext decryption process, the decryption terminal 30 needs to re-randomize the ciphertext, which changes the original ciphertext data structure. This means that although the receiver can decrypt the decrypted ciphertext, they cannot verify the signature. This embodiment, by designing a reasonable data structure for the signed ciphertext, can simultaneously re-randomize both the ciphertext and the signature, ensuring that the decrypted signed ciphertext can still be verified.

[0109] Please participate Figure 2 The second embodiment of the present invention provides a method for purifying certificate-free signature encryption, which is described from the perspective of the purification end 30 and includes the following steps:

[0110] S201, Receive public parameters sent by the key generation center;

[0111] S202, Receive the signed and encrypted information sent by the data sender;

[0112] S203, verify the signed ciphertext according to the public parameters and key information; the key information includes the key information of the data sender and the key information of the data receiver;

[0113] S204, after successful verification, the signature information and ciphertext information in the signed ciphertext are re-randomized in the undecrypted state to obtain purified signed ciphertext, which is then sent to the data receiving end to trigger the data receiving end to verify and decrypt the purified signed ciphertext to obtain plaintext information corresponding to the ciphertext information; wherein, the signature information and ciphertext information in the signed ciphertext are independent of each other before and after re-randomization, so that the signature information can be verified by the data receiving end after re-randomization.

[0114] Please see Figure 3 The second embodiment of the present invention provides a method for purifying certificate-free signature encryption, which is described from the perspective of various ends of the entire system, including:

[0115] The key generation center 10 generates public parameters, a first part of the private key of the sending end corresponding to the data sending end 20, and a first part of the private key of the receiving end corresponding to the data receiving end 40. The public parameters and the first part of the private key of the sending end are sent to the data sending end 20, the public parameters and the first part of the private key of the receiving end are sent to the data receiving end 40, and the public parameters are sent to the purification end 30.

[0116] The data sending end 20 uses its own sending end public key PK. s The sender's complete private key SK s Public parameters, receiver public key PK of data receiver 40 r and identity ID r The data M to be sent is signed and encrypted to generate a signed and encrypted ciphertext containing signature information and ciphertext information, and the signed and encrypted ciphertext is sent to the purification terminal 30; wherein, the complete private key SK of the sending terminal is... s Generate based on the first part of the sender's private key and the second part of the sender's private key generated by the data sender 20 itself;

[0117] After receiving the signed ciphertext, the purification terminal 30 determines the PK based on the common parameters. s Identity ID of data sender 20 s PK r ID r The identity of the data sender 20 is verified. After the verification is successful, the signature information and ciphertext information in the signed ciphertext are re-randomized in the undecrypted state to obtain the purified signed ciphertext, which is then sent to the data receiver 40.

[0118] After receiving the cleaned and signed ciphertext, the data receiving end 40 uses the public parameters and the receiver's complete private key SK. r Verification and decryption are performed on it; wherein, the complete private key SK of the receiving end is used. sIt is generated based on the first part of the receiver's private key and the second part of the receiver's private key generated by the data receiver 40 itself.

[0119] Please see Figure 4 The fourth embodiment of the present invention also provides a purification device for uncertified signatures, which, corresponding to the second embodiment, includes:

[0120] The public parameter receiving unit 410 is used to receive public parameters sent by the key generation center;

[0121] The ciphertext receiving unit 420 is used to receive ciphertext containing signature information and ciphertext information sent by the data sender.

[0122] The verification unit 430 is used to verify the signed ciphertext according to the public parameters and key information; the key information includes key information of the data sending end and key information of the data receiving end.

[0123] The purification unit 440 is used to re-randomize the signature information and ciphertext information in the ciphertext in an undecrypted state after successful verification, to obtain purified ciphertext, and send it to the data receiving end to trigger the data receiving end to verify and decrypt the purified ciphertext to obtain plaintext information corresponding to the ciphertext information; wherein, the signature information and ciphertext information in the ciphertext are independent of each other before and after re-randomization, so that the signature information can be verified by the data receiving end after re-randomization.

[0124] The fifth embodiment of the present invention also provides a purification device for uncertified signature devices, comprising:

[0125] At least one processor; and,

[0126] The memory is communicatively connected to the at least one processor; wherein,

[0127] The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the cleaned-up certificateless signature method described in the second embodiment.

[0128] The sixth embodiment of the present invention also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the cleanable certificate-free signature method described in the second embodiment.

[0129] The seventh embodiment of the present invention also provides a computer program product, which includes a computing program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions that, when executed by a computer, cause the computer to perform the cleanable certificate-free signature method described in the second embodiment.

[0130] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.

Claims

1. A method for purifying certificate-less signature encryption, characterized in that, include: Receive public parameters sent by the key generation center; Receive the signed and encrypted data sent by the data sender. The signed ciphertext is verified based on the public parameters and key information; the key information includes the key information of the data sender and the key information of the data receiver. After successful verification, the signature information and ciphertext information in the signed ciphertext are re-randomized in the undecrypted state to obtain purified signed ciphertext, which is then sent to the data receiving end to trigger the data receiving end to verify and decrypt the purified signed ciphertext to obtain plaintext information corresponding to the ciphertext information. The signature information and ciphertext information in the signed ciphertext are independent of each other before and after re-randomization, so that the signature information can be verified by the data receiving end after re-randomization.

2. A method for purifying certificate-less signature encryption, characterized in that, include: The key generation center generates public parameters, a first part of the sender's private key corresponding to the data sender, and a first part of the receiver's private key corresponding to the data receiver. The public parameters and the first part of the sender's private key are sent to the data sender, the public parameters and the first part of the receiver's private key are sent to the data receiver, and the public parameters are sent to the purification end. The data sending end uses its own sender public key PK. s The sender's complete private key SK s Public parameters, the receiver's public key PK. r and identity ID r The data M to be sent is signed and encrypted to generate a signed and encrypted message containing signature information and ciphertext information, and the signed and encrypted message is sent to the purification end; wherein, the complete private key SK of the sending end is... s Generate based on the first part of the sender's private key and the second part of the sender's private key generated by the data sender itself; After receiving the signed ciphertext, the purification terminal uses the common parameters, PK... s The identity ID of the data sender s PK r ID r The identity of the data sender is verified. After the verification is successful, the signature information and ciphertext information in the signed ciphertext are re-randomized in the undecrypted state to obtain the purified signed ciphertext, which is then sent to the data receiver. After receiving the cleaned and signed ciphertext, the data receiving end uses the public parameters and the receiving end's complete private key SK. r Verification and decryption are performed on it; wherein, the complete private key SK of the receiving end is used. r It is generated based on the first part of the receiver's private key and the second part of the receiver's private key generated by the data receiver itself.

3. The method for purifying certificate-free signature encryption according to claim 2, characterized in that, The steps for the key generation center to generate public parameters are as follows: Set a safety parameter λ, and select two prime-order multiplicative groups G and G'. T The generator of group G is g, and its prime order is p; G × G → G T It is a bilinear mapping; Randomly select master private key Calculate g1 = g α , g2∈G; Represents the real number field; Choose a hash function H. The hash function has the following definition: H:{0,1} * →G Generate common parameters params = {G, G T ,e,g,g1,g2,H};e represents the bilinear mapping operation; The key generation center generates a portion of the user's private key d. user The steps are as follows: Get the user's identity ID u ∈{0,1} n ; Random selection Calculate part of the user's private key d user : but: Part 1: Sender's Private Key Part 1: Receiver's Private Key 4. The method for purifying certificate-free signature encryption according to claim 3, characterized in that, The data sending end generates a sender public key PK. s and the sender's complete private key SK s The steps are as follows: Random selection but: The data receiving end generates a receiver public key PK. r and the receiver's complete private key SK r The steps are as follows: Random selection but:

5. The method for purifying certificate-free signature encryption according to claim 4, characterized in that, The steps for the data sending end to generate the signed ciphertext are as follows: Random selection calculate calculate: calculate: set up: calculate: Generate the ciphertext σ = (σ1, σ2, σ3, σ4, σ5).

6. The method for purifying certificate-free signature encryption according to claim 5, characterized in that, The process by which the purification terminal verifies the identity and legitimacy of the data sender is as follows: judge: If the condition is met, the verification passes; otherwise, the verification fails. The process by which the purification terminal re-randomizes the signed ciphertext is as follows: Random selection calculate: calculate: calculate: calculate: calculate: calculate: Output the purified signature ciphertext after re-randomization: σ , =(σ,1,σ,2,σ,3,σ,4,σ,5).

7. The method for purifying certificate-free signature encryption according to claim 6, characterized in that, The process by which the data receiving end verifies the received cleaned signature ciphertext is as follows: judge: If the condition is met, the verification passes; otherwise, the verification fails. The process by which the data receiving end decrypts the received cleaned signature ciphertext is as follows: Based on the receiver's complete private key SK r Perform decryption calculation:

8. A purification device for uncertified signatures, characterized in that, include: The public parameter receiving unit is used to receive public parameters sent by the key generation center; The signed and encrypted text receiving unit is used to receive signed and encrypted text containing signature information and encrypted text information sent by the data sender. The verification unit is used to verify the signed ciphertext based on the public parameters and key information; the key information includes key information of the data sender and key information of the data receiver. The purification unit is used to re-randomize the signature information and ciphertext information in the ciphertext after successful verification, in an undecrypted state, to obtain purified ciphertext, and send it to the data receiving end to trigger the data receiving end to verify and decrypt the purified ciphertext to obtain plaintext information corresponding to the ciphertext information; wherein, the signature information and ciphertext information in the ciphertext are independent of each other before and after re-randomization, so that the signature information can be verified by the data receiving end after re-randomization.

9. A purification device for uncertified signatures, characterized in that, include: At least one processor; as well as, The memory is communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the cleanable certificateless signature method according to any one of claims 1 to 2.

10. A purification-enabled certificate-free signature system, characterized in that, include: A key generation center is used to generate public parameters, a first part of the sender's private key corresponding to the data sender, and a first part of the receiver's private key corresponding to the data receiver. The center then sends the public parameters and the first part of the sender's private key to the data sender, sends the public parameters and the first part of the receiver's private key to the data receiver, and sends the public parameters to the purification end. The data sending end is used to send data based on its own sender public key PK. s The sender's complete private key SK s Public parameters and the receiver's public key PK. r and identity ID r The data M to be sent is signed and encrypted to generate a signed and encrypted message containing signature information and ciphertext information, and the signed and encrypted message is sent to the purification end; wherein, the complete private key SK of the sending end is... s Generate based on the first part of the sender's private key and the second part of the sender's private key generated by the data sender itself; The purification terminal is used to, upon receiving the signed ciphertext, perform a PK based on common parameters. s The identity ID of the data sender s PK r ID r The identity of the data sender is verified. After the verification is successful, the signature information and ciphertext information in the signed ciphertext are re-randomized in the undecrypted state to obtain the purified signed ciphertext, which is then sent to the data receiver. The data receiving end is used, after receiving the cleaned and signed ciphertext, to determine the appropriate parameters based on the public parameters and the receiver's complete private key SK. r Verification and decryption are performed on it; wherein, the complete private key SK of the receiving end is used. r It is generated based on the first part of the receiver's private key and the second part of the receiver's private key generated by the data receiver itself.

Citation Information

Cited By

  • Certificateless unmanned aerial vehicle cluster identity authentication method

    CN121619574A