Block chain-based trusted data sharing certificateless proxy signature method and system
By using a blockchain-based certificateless proxy signature method for trusted data sharing, the problems of unsupervised proxy permissions and centralized risks are solved, thereby achieving the security and reliability of the data sharing system and meeting the needs of decentralization.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHENGZHOU UNIVERSITY OF LIGHT INDUSTRY
- Filing Date
- 2026-01-12
- Publication Date
- 2026-05-01
AI Technical Summary
Existing certificateless proxy signature technology suffers from issues such as unmonitorable proxy permissions, single point of failure risks in centralized models, abuse of power, and key leakage, resulting in insufficient security and reliability of data sharing systems and failing to meet the needs of decentralization.
A certificateless proxy signature method based on blockchain for trusted data sharing is adopted. A distributed ledger is constructed through blockchain technology, and a proxy signer generates a proxy public and private key for signing. Transactions are recorded on the blockchain to achieve network consensus and ensure the reliability and transparency of the signature.
It enables flexible management of proxy signatures, prevents key escrow issues, improves the security and reliability of data sharing transactions, conforms to the principle of decentralization, and ensures data privacy and full-process supervision of permissions.
Smart Images

Figure CN121966969A_ABST
Abstract
Description
A Certificate-Free Proxy Signature Method and System for Trusted Data Sharing Based on Blockchain Technical Field
[0001] This invention relates to the field of information security technology, and in particular to a blockchain-based trusted data sharing certificateless proxy signature and system. Background Technology
[0002] With the widespread application of blockchain technology in cross-domain data interaction scenarios, identity authentication and privacy protection in trusted data sharing have become fundamental and critical requirements for ensuring the security of data flow.
[0003] To ensure the legitimacy of data transmission and verification operations in authorized data sharing scenarios while protecting the privacy of data owners, Certificateless Proxy Signature (CLPS) technology has been introduced into trusted data sharing scenarios. CLPS allows the original signer to delegate signing authority to a proxy signer. The proxy signer generates a signature based on their private key and the delegated authorization information. Verifiers can confirm that the signature was generated by a legitimate proxy signer and has obtained the original authorization, but cannot obtain additional privacy information about the original signer or the proxy signer. Simultaneously, they can verify the integrity and legitimacy of the shared data's source. Although CLPS balances the needs for authorized legitimacy and identity privacy protection in data sharing, its inherent unmonitorable proxy authority means that it cannot effectively constrain unauthorized signing, duplicate signing, or other violations by proxy signers, making it difficult to hold malicious operations accountable during data sharing. Furthermore, the reliability of the entire trusted data sharing signature system depends entirely on the normal operation of a single centralized authorizing entity. If this entity encounters technical failures, cyberattacks, operational interruptions, or policy changes that prevent it from functioning properly, the signature verification and accountability functions of the entire data sharing system will completely fail. Furthermore, this centralized model requires all data-sharing participants (including enterprises, research institutions, and individual users) to place absolute trust in the centralized authorizing body. This body holds the decision-making power to verify data-sharing signatures, posing a risk of power abuse, such as unauthorized access to original shared data or misjudging signature validity. More importantly, this centralized architecture contradicts the core principles of decentralized and trustless blockchain technology, weakening its advantages in distributed ledger and immutability for trusted data sharing, and failing to fully guarantee the credibility and security of data sharing.
[0004] In summary, the centralized oversight mechanisms commonly used in existing, oversightable certificateless proxy signature schemes inherently suffer from a series of serious problems, including single points of failure, trust bottlenecks, risks of power abuse, and systemic security collapses caused by key leaks. These deficiencies severely limit the applicability of existing CLPS technology in building truly secure, reliable, and trustworthy data sharing systems that align with the decentralized spirit of blockchain, and fail to meet the advanced requirements of cross-domain data sharing for identity privacy protection and end-to-end access control. Therefore, designing a more secure, reliable, transparent, and decentralized blockchain-based certificateless proxy signature method and system that can simultaneously protect the privacy of data sharing participants and ensure end-to-end access control is crucial. Summary of the Invention
[0005] To address the shortcomings of the aforementioned background technologies, this invention proposes a blockchain-based trusted data sharing certificateless proxy signature and system. It utilizes blockchain technology to establish a trusted data sharing transaction system, employs certificateless proxy signature technology to protect data and user privacy during data sharing transactions, promotes secure and efficient data sharing across departments, regions, and industries, provides security technology support for realizing the potential value of data, and drives the healthy and sustainable development of the digital economy.
[0006] The technical solution of this invention is implemented as follows: A certificateless proxy signature method and system for trusted data sharing based on blockchain, comprising the following steps: S100, constructing a trusted data sharing system and a distributed ledger using blockchain technology; S200, the user (signer) obtains the transaction address of the transaction object (verifier) from the trusted data sharing system and authorizes a proxy signer to sign the data sharing transaction on their behalf and with the verifier; S300, the proxy signer generates a proxy public and private key using a proxy certificate, then signs the transaction using the proxy private key and sends the transaction to the trusted data sharing system; S400, the verifier verifies the correctness of the signature of the relevant data sharing transaction; S500, the verified data transaction and related records are uploaded to the trusted data sharing system for network-wide consensus and registered in the ledger.
[0007] Preferably, the shared transaction is formed during the data transfer between different transaction entities; the signer authorizes the agent to sign the shared transaction on their behalf; the verifier verifies the shared transaction containing the agent's signature, and the legitimate transaction that passes the signature verification is uploaded to the trusted data sharing system and recorded in the blockchain ledger.
[0008] Preferably, the certificateless proxy signing process includes five steps: partial key extraction, key generation, proxy authorization, proxy key generation, proxy signing, and verification.
[0009] Preferably, the partial key extraction and key generation process includes: partial key extraction step: the key generation center first randomly selects... ,calculate , ,in It is a hash function; it utilizes the Gaussian sampling algorithm. Generate a short vector As part of the user's private key, and satisfying ,as well as ,in It is the system master private key, Represents Gaussian parameters, It is a linear mapping. These are system parameters.
[0010] Key generation steps: The signer first uses a Gaussian distribution. Select vectors above ,Will and Combined into a private key And calculate the public key .
[0011] Preferably, the proxy authorization and proxy key generation process includes: Proxy authorization step: The signer first calculates... as well as ,in It is a hash function. It is a certificate. It is the agent's public key. It's a commitment; then the authorization token is calculated. ,in It is the signer's private key; sending proxy certificates For the proxy signer; Proxy key generation steps: Proxy signer checks , as well as Whether the application is valid or not, if valid, the agency certificate will be accepted; otherwise, it will be rejected. It is the signer's public key. It's a hash function; then, the proxy signer calculates the proxy private key. ,in It is a short vector.
[0012] Preferably, the proxy signature process includes: the proxy signer first applies a Gaussian distribution... Select vectors above Calculate commitment and challenges ,in It is a message; a calculation ,in It is the private key of the proxy signer; the generated signature is and check If the condition is not met, the vector is resampled. .
[0013] Preferably, the signature verification process includes: the verifier receiving the signature. Then, calculate ,like , Accept signature Otherwise, refuse.
[0014] Preferably, the blockchain-based trusted data sharing certificateless proxy signature system comprises: a system initialization and key distribution module, used to generate global parameters through the system initializer and generate key pairs for the signing user, proxy user, and verifier respectively; a certificateless signature generation module, where the signer authorizes a proxy signer, and the proxy signer uses a proxy certificate to generate public and private keys to sign the data sharing transaction on behalf of the signer; and a signature verification and on-chain registration module, where the verifier verifies the correctness of the generated certificateless proxy signature and registers the verified data sharing transaction to the blockchain ledger.
[0015] Compared with existing technologies, the beneficial effects of this invention are as follows: 1) It utilizes blockchain technology to construct a data sharing transaction system involving different data trading centers or entities, and establishes a distributed ledger to record the data sharing transactions that occur; 2) It designs a certificateless proxy signature method, and the certificateless mechanism can avoid key custody issues and prevent privacy theft that may occur in key generation centers; 3) The proxy signature mechanism can securely delegate the signing right to the signer, ensuring the authenticity and integrity of transaction data while improving the flexibility of the signing right. Attached Figure Description
[0016] Figure 1 is a flowchart of the present invention; Figure 2 is a structural diagram of the trusted data sharing system of the present invention; Figure 3 is a flowchart of the trusted data sharing certificateless proxy signature process of the present invention; Figure 4 is a block diagram of the trusted data sharing certificateless proxy signature system based on blockchain of the present invention. Detailed Description of Embodiments The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0017] As shown in Figure 1, this embodiment of the invention provides a certificateless proxy signature method for trusted data based on blockchain, with the following steps: S100, constructing a trusted data sharing system and a distributed ledger using blockchain technology; S200, the user (signer) obtains the transaction address of the transaction object (verifier) from the trusted data sharing system and authorizes a proxy signer to sign the data sharing transaction on their behalf and with the verifier; S300, the proxy signer generates a proxy public and private key using a proxy certificate, then signs the transaction using the proxy private key and sends the transaction to the trusted data sharing system; S400, the verifier verifies the correctness of the signature of the relevant data sharing transaction; S500, the verified data transaction and related records are uploaded to the trusted data sharing system for network-wide consensus and registered in the ledger.
[0018] As shown in Figure 2, the data forms the shared transaction during the transmission between different transaction entities; the signer authorizes the agent to sign the shared transaction on their behalf; the verifier verifies the shared transaction containing the agent's signature, and the legitimate transaction that passes the signature verification is uploaded to the trusted data sharing system and recorded in the blockchain ledger.
[0019] The data trust-sharing system is a distributed trading platform built on blockchain technology, consisting of different data trading centers or entities.
[0020] The blockchain ledger is an essential component of the data sharing transaction system, used to record the data sharing transactions that occur.
[0021] The trusted data sharing system has a trusted key generation center that generates public and private keys for signers and verifiers.
[0022] The user (signer) is the initiator of the data sharing transaction; the proxy signer is the user's authorized agent who signs the sharing transaction on behalf of the signer; the transaction object (verifier) is the recipient of the data sharing transaction, and its transaction address is generated based on its public key; the data sharing transaction is a transaction initiated by the user and the transaction object on the data sharing transaction system for sharing data.
[0023] As shown in Figure 3, the certificateless proxy signing process includes five steps: partial key extraction, key generation, proxy authorization, proxy key generation, proxy signing, and verification.
[0024] The partial key extraction and key generation process includes: S201, Partial key extraction step: The key generation center first randomly selects... ,calculate , ,in It is a hash function; it utilizes the Gaussian sampling algorithm. Generate a short vector As part of the user's private key, and satisfying ,as well as ,in It is the system master private key, Represents Gaussian parameters, It is a linear mapping. These are system parameters.
[0025] S202, Key Generation Steps: The signer first uses a Gaussian distribution... Select vectors above ,Will and Combined into a private key And calculate the public key .
[0026] The proxy authorization and proxy key generation process includes: S301, Proxy authorization step: The signer first calculates... as well as ,in It is a hash function. It is a certificate. It is the agent's public key. It's a commitment; then the authorization token is calculated. ,in It is the signer's private key; sending proxy certificates For the proxy signer; S302, Proxy key generation steps: Proxy signer checks , as well as Whether the application is valid or not, if valid, the agency certificate will be accepted; otherwise, it will be rejected. It is the signer's public key. It's a hash function; then, the proxy signer calculates the proxy private key. ,in It is a short vector.
[0027] The proxy signature process includes: the proxy signer first uses a Gaussian distribution. Select vectors above Calculate commitment and challenges ,in It is a message; a calculation ,in It is the private key of the proxy signer; the generated signature is and check If the condition is not met, the vector is resampled. .
[0028] The signature verification process includes: the verifier receiving the signature. Then, calculate ,like , Accept signature Otherwise, refuse.
[0029] As shown in Figure 4, the blockchain-based trusted data sharing certificateless proxy signature system includes three modules, as follows: System initialization and key distribution module: used to generate global parameters through the system initializer, and generate key pairs for the signing user, proxy user, and verifier respectively; Certificateless signature generation module: the signer authorizes the proxy signer, and the proxy signer uses the proxy certificate to generate public and private keys to sign the data sharing transaction on behalf of the signer; Signature verification and on-chain registration module: the verifier verifies the correctness of the generated certificateless proxy signature and registers the verified data sharing transaction to the blockchain ledger.
[0030] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A certificateless proxy signature method and system for trusted data sharing based on blockchain, comprising the following steps: S100, constructing a trusted data sharing system and a distributed ledger using blockchain technology; S200, the user (signer) obtains the transaction address of the transaction object (verifier) from the trusted data sharing system and authorizes a proxy signer to sign the data sharing transaction on their behalf and with the verifier; S300, the proxy signer generates a proxy public and private key using a proxy certificate, then signs the transaction using the proxy private key and sends the transaction to the trusted data sharing system; S400, the verifier verifies the correctness of the signature of the relevant data sharing transaction; S500, the verified data transaction and related records are uploaded to the trusted data sharing system for network-wide consensus and registered in the ledger.
2. The certificateless proxy signature method and system for trusted data sharing based on blockchain according to claim 1, characterized in that, During the transmission of data between different transaction entities, the shared transaction is formed; the signer authorizes the agent to sign the shared transaction on their behalf; the verifier verifies the shared transaction containing the agent's signature, and the legitimate transaction that passes the signature verification is uploaded to the trusted data sharing system and recorded in the blockchain ledger.
3. The certificateless proxy signature method for trusted data sharing based on blockchain according to claim 2, characterized in that, The certificateless proxy signing process includes five steps: partial key extraction, key generation, proxy authorization, proxy key generation, proxy signing, and verification.
4. The certificateless proxy signature method for trusted data sharing based on blockchain according to claim 3, characterized in that, The partial key extraction and key generation process includes: Partial key extraction step: The key generation center first randomly selects... ,calculate , ,in It is a hash function; it utilizes the Gaussian sampling algorithm. Generate a short vector As part of the user's private key, and satisfying ,as well as ,in It is the system master private key, Represents Gaussian parameters, It is a linear mapping. These are system parameters. Key generation steps: The signer first uses a Gaussian distribution... Select vectors above ,Will and Combined into a private key And calculate the public key 。 5. The certificateless proxy signature method for trusted data sharing based on blockchain according to claim 3, characterized in that, The proxy authorization and proxy key generation process includes: Proxy authorization step: The signer first calculates... as well as ,in It is a hash function. It is a certificate. It is the agent's public key. It's a commitment; then the authorization token is calculated. ,in It is the signer's private key; sending proxy certificates For the proxy signer; Proxy key generation steps: Proxy signer checks 、 as well as Whether the application is valid or not, if valid, the agency certificate will be accepted; otherwise, it will be rejected. It is the signer's public key. It's a hash function; then, the proxy signer calculates the proxy private key. ,in It is a short vector.
6. The certificateless proxy signature method for trusted data sharing based on blockchain according to claim 3, characterized in that, The proxy signature process includes: the proxy signer first uses a Gaussian distribution. Select vectors above Calculate commitment and challenges ,in It is a message; a calculation ,in It is the private key of the proxy signer; the generated signature is and check If the condition is not met, the vector is resampled. 。 7. The certificateless proxy signature method for trusted data sharing based on blockchain according to claim 3, characterized in that, The signature verification process includes: the verifier receiving the signature. Then, calculate ,like 、 Accept signature Otherwise, refuse.
8. A blockchain-based trusted data sharing certificateless proxy signature system, used to implement the blockchain-based trusted data sharing certificateless proxy signature method as described in claims 1-7, characterized in that, The blockchain-based trusted data sharing certificateless proxy signature system comprises: a system initialization and key distribution module, used by the system initializer to generate global parameters and generate key pairs for the signing user, proxy user, and verifier respectively; a certificateless signature generation module, where the signer authorizes a proxy signer, who uses the proxy certificate to generate public and private keys to sign the data sharing transaction on behalf of the signer; and a signature verification and on-chain registration module, where the verifier verifies the correctness of the generated certificateless proxy signature and registers the verified data sharing transaction to the blockchain ledger.