Blind Signature System and Method Using Grid-Based Encryption
By employing a secret trapdoor function to derive a short vector that solves a lattice problem, the proposed method addresses the inefficiencies and security concerns in existing lattice-based blind signature schemes, resulting in a more efficient and quantum-resistant solution.
Patent Information
- Application Number
- JP2024572458
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-06-09
- Filing Date
- 2023-06-09
- Publication Date
- 2025-06-26
AI Technical Summary
Existing lattice-based blind signature schemes face challenges in efficiently proving complex relationships due to the need for non-interactive zero-knowledge (NIZK) proofs, which are inefficient and lack formal security proofs due to the requirement for an explicit description of the hash function.
The proposed method uses a secret trapdoor function to derive a target vector and a short vector that solves a lattice problem, allowing the user device to verify the short vector and generate a signature that proves knowledge of the short vector based on the message and public data.
This approach results in a more efficient and secure blind signature scheme that is resistant to attacks by quantum computers, with a reduced number of messages required between the user and signer devices, and supports an unlimited number of signatures.
Smart Images

Figure 2025519581000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to systems and methods for generating blind signatures using lattice-based cryptography.
Background Art
[0002] A blind signature is an interactive protocol between a user and a signer that enables the user to obtain a signature on a message from the signer without revealing the message to the signer. At the end of the protocol, the user obtains a valid signature on the message under the signer's private key. To be secure, a blind signature scheme should be such that the signer does not recognize the message and the private key remains secret to the signer. Application examples of blind signatures include electronic cash, anonymous credentials, and electronic voting.
[0003] Digital signature schemes generally consist of three functions, · Skeygen that generates a signing key sk and a verification key vk, · Sign that generates a signature using the signing key sk, and · Verify that enables a signature to be verified using the verification key vk.
[0004] Blind signature schemes may utilize commitments and non-interactive zero-knowledge (NIZK) proofs.
[0005] Commitment schemes generally consist of a tuple of three functions, · Ckeygen that generates public parameters, · Com(m,r) that outputs a commitment c to a message m using random data r, and · Open(c,r) that reveals a commitment c to a message m using random data r.
[0006] The commitment scheme has a binding property that ensures that the commitment c = com(m,r) cannot be revealed for any message other than m, and a hiding property that ensures that the commitment c appears completely randomly even if the message m corresponding to the commitment c is known.
[0007] A non-interactive zero-knowledge (NIZK) proof of knowledge is a non-interactive proof of knowledge that can be used to prove knowledge of a secret without revealing the secret. For security purposes, an NIZK proof of knowledge scheme must be zero-knowledge in the sense that the scheme does not leak any information about the secret, and must be sound in the sense that only a prover who knows the secret can output a valid proof.
[0008] As an example, a blind signature scheme is shown below.
Number
[0009] User U knows the message m and the verification key vk, and signer S knows the signing key sk. User U randomly samples random data r and random data u. Next, the user generates a commitment c using Com(m,r) and sends the commitment to signer S. Following the receipt of the commitment c, signer S signs the commitment c using the signing key sk to generate a signature σ. Signer S then sends the signature σ to user U. User U then verifies that the signature is a valid signature for the commitment c using Verify(vk,c,σ), and after successful verification, encrypts the commitment c, the signature σ, and the random data u using the public key pk to generate a ciphertext c. Next, user U generates a proof π, by which anyone who knows the message, the ciphertext ct, and the proof π can prove that user U has knowledge of a valid signature σ for the commitment of message m.
[0010] Lattice-based encryption refers to a family of cryptographic schemes whose security is based on the intractability of solving mathematical problems on lattices. Most lattice-based cryptographic schemes are considered post-quantum because they are conjectured to be resistant to attacks by malicious parties with access to a hypothetical large-scale quantum computer. Therefore, lattice-based cryptographic schemes are attracting increasing interest as a safeguard for when such large-scale quantum computers become a reality.
[0011] The following notations are used in this specification. · Vectors are represented by lowercase boldface (e.g., t), · Matrices are represented by uppercase boldface (e.g., A), · R q is a base ring, which is commutative. It can be, for example,
Number
Number
[0012] Lattice-based cryptographic schemes generally require the computation of the matrix-vector product A·x, where x is subject to some constraints. The Short Integer Solution (SIS) problem and the Learning With Errors (LWE) problem are the basis of lattice-based cryptography. Briefly stated, · Given A and t, the SIS problem consists of finding a short secret vector s such that A·s = t, · Given A and t, the LWE problem consists of finding vectors s and e such that A·s + e = t, where the error vector e is short and the secret vector s need not be constrained (uniform secret LWE), or needs to be short (short secret LWE).
[0013] There are various problems associated with using lattice-based encryption schemes in blind signature schemes like the one described above. In particular, the required proof of knowledge is specific and needs to prove complex relationships, and this problem is exacerbated by the fact that all efficient lattice-based signature schemes first generate a hash of the message and then sign it, so that the relationship being proven is no longer σ = sign(sk, c), but rather σ = sign(sk, H(c)). This means that security requires modeling the hash function H as a random oracle, but since the non-interactive zero-knowledge (NIZK) proof of knowledge requires an explicit description of the hash function, the security of the scheme cannot be formally proven. Furthermore, and perhaps more importantly, proving the properties of the hash function in zero knowledge is very complex, leading to a very inefficient scheme. Summary of the Invention Means for Solving the Problems
[0014] According to a first aspect of the present invention, a computer-implemented method for generating a signature for a message is provided. A user device processes a message and random data to generate a commitment for the message and transmits the commitment to a signer device. The signer device uses a secret trapdoor function to derive a target vector and a short vector that solves a lattice problem including the target vector from the commitment and a sample. Next, the signer device transmits the short vector to the user device, and the user device verifies that the short vector solves the lattice problem. After successful verification of the short vector, the user device generates a signature that proves knowledge of the short vector based on the message and public data.
[0015] According to a second aspect of the present invention, there is provided a user device including a processor that processes a message and random data to generate a commitment for the message. The user device further includes a transmitter for transmitting the commitment to a signer device, and a receiver for receiving a short vector from the signer device in response to the transmission of the commitment. Next, the processor is configured to verify that the short vector solves a lattice problem, and after successful verification of the short vector, generate a signature that proves knowledge of the short vector based on the message and public data.
[0016] According to a third aspect of the present invention, there is provided a device for signing a message, the device having access to a secret trapdoor function. The device is a receiver for receiving a commitment from a user device, the commitment corresponding to the message to be signed, and a processor configured to derive a target vector from the commitment and use the secret trapdoor function to sample a short vector that solves a lattice problem including the target vector. The device further includes a transmitter for transmitting the short vector to the user device.
[0017] Further features and advantages of the present invention will become apparent from the following description of the preferred embodiments of the present invention, given by way of example only, made with reference to the accompanying drawings.
Brief Description of the Drawings
[0018]
Figure 1
Figure 2
Mode for Carrying Out the Invention
[0019] Figure 1 shows a computing system including a user device 1, a recipient device 3, and a signer device 5. Figure 1 also shows the messaging executed to send a message m with a blind signature given by the signer device 5 from the user device 1 to the recipient device 3.
[0020] The user device 1 includes a processor 7, a transmitter 9, and a receiver 11 configured to execute an encryption function. Similarly, the signer device 5 includes a processor 13, a transmitter 15, and a receiver 17 configured to execute an encryption function. The signer device 5 also has access to a secret trapdoor function 19.
[0021] As shown in the figure, the user device 1 uses the transmitter 9 to transmit a first message M1 to the receiver 17 of the signer device 5, which conveys a commitment c to the message m and a first non-interactive zero-knowledge (NIZK) proof π1. As discussed below, the commitment c is generated by the user device 1 based on the message m, a publicly available gadget vector g, and some random data r, and the user device 1 also generates the first NIZK proof π1, which proves that the commitment c is public with respect to the message m.
[0022] Commitment c is a commitment that conforms to trapdoor sampling and the signer device 5. In this way, the signer device 5 can solve lattice problems that are difficult to solve in other ways using the secret trapdoor function 19. Lattice problems are difficult to solve without knowledge of the secret trapdoor function 19. Therefore, the blind signature scheme functions based on the assumption that an effective solution to the lattice problem must have been generated using the secret trapdoor function 7. In this regard, it should be noted that lattice problems are resistant to attacks using either or both conventional computing systems and quantum computing systems. Thus, the solution to the lattice problem is also resistant to attacks by malicious parties with access to large-scale quantum computers. Due to this property, the blind signature scheme in this example can be considered "post-quantum."
[0023] In this example, the lattice problem is to sample the following vector
Number
Number
Number
Number
[0024] Next, the signer device 5 uses the transmitter 15 to send a second message M2 that conveys the short vector e to the receiver 11 of the user device 1. Next, if the user device 1 can determine that the target vector t is publicly available using the function ParseCom(c) and the remaining data of the lattice problem, the user device 1 can verify that the short vector e is a valid solution to the lattice problem. After the user device 1 verifies that the short vector e is valid, the knowledge of the short vector e by the user device 1 can be used as evidence that the short vector e of the commitment c was determined by the signer device 5.
[0025] In this example, the signer device 5 then generates a second NIZK proof π2 that serves as a blind signature of the message m. In this respect, it is important for security purposes that the second NIZK proof π2 only requires publicly available information, such that the second NIZK proof π2 does not rely on any information specific to this execution of the protocol, such that when revealed, the information cannot be linked to the protocol. Thus, the second NIZK proof π2 should not disclose information about the random data used to generate the commitment, or about the target vector used to generate the short vector e. To achieve this, the signer device 5 solves the lattice problem
number
number
number
number
number
number
[0026] Those skilled in the art will understand that the form of the second NIZK proof π2 is straightforward and does not require information on how the hash function generates the hash h of the message m. In fact, based on the knowledge of public vectors (e.g., vector [Number] ) and polynomials (e.g., random data u), there are known proofs to prove the knowledge of the secret vector (e.g., the modified short vector [Number] ).
[0027] Next, the user device 1 sends a third message M3 that conveys the message and the second NIZK proof π2 to the recipient device 3. Next, the recipient can verify the second NIZK proof π2 to confirm the message m.
[0028] The blind signature scheme described above with reference to FIG. 1 includes a single message M1 sent from the user device 1 to the signer device 5 and a single message M2 sent from the signer device 5 to the user device 1. Therefore, the blind signature scheme involves a minimum number of messages between the user device 1 and the signer device 5 and can be called "round-optimal".
[0029] Another advantage of the blind signature scheme described above with reference to FIG. 1 is that the signature size is approximately 100 KB and it supports an unlimited number of signatures.
[0030] Further details of the blind signature scheme described above with reference to FIG. 1 are provided here with reference to FIG. 2.
[0031] As shown in Figure 1, to generate a blind signature of message m, user device 1 first, at S1, calculates the cryptographic hash h of message m using hash function H and uniformly samples random data r. Next, at S3, user device 1 generates a commitment based on hash h and random data r. In particular, the commitment is generated using function Com(m,r) with publicly available parameters a1, a2, b1…b k , publicly available gadget vector g, and
Number
Number
Number
[0032] . The Com(m,r) function can be expressed as follows.
Number
Number
[0033] . Next, at S5, user device 1 determines the first NIZK proof π1 using zero-knowledge protocol π1, which
Number
Mathematics
[0034] Next, the user device 1 sends, at S7, the commitment c and the first NIZK proof π1 to the signer device 5 (see message M1 in Figure 1).
[0035] Following the reception of the commitment c and the first NIZK proof π1 at S9, the signer device 5 verifies, at S11, the first NIZK proof π1 to confirm that the commitment c is valid. If the verification fails, no further action is taken. If the verification passes, the signer device 5 samples, at S13, a short vector e that satisfies the above - mentioned lattice problem. This involves using the function ParseCom(c) to generate the target vector t and then using the secret trapdoor function 19 to determine the short vector e as described above.
[0036] Any vector a1 for which there exists a small (hidden) basis of the lattice orthogonal to a1 can be used as a trapdoor vector by using a pre - image sampling algorithm as disclosed in the paper “Trapdoors for hard lattices and new cryptographic constructions,” Gentry et al, 40th ACM STOC, pp. 197 - 206”. In this example, the so - called NTRU trapdoor is used. In the case of this trapdoor, the matrix a1 takes the form [1|h]. Where
Mathematics
[0037] Next, the signer device 5 sends a short vector e to the user device 1 (see message M2 in Figure 1).
[0038] In S17, after receiving the short vector e, in S19, the user device 1 verifies that the short vector e satisfies the lattice problem. Next, as discussed in detail above, in S21, the user device 1 corrects the short vector e to obtain the corrected short vector [Number] and generates the second NIZK proof π2. Next, the user device 1 outputs the second NZIK proof π2 to the recipient device 3, together with, for example, the message m (see message M3 in Figure 1).
[0039] The blind signature algorithm described with reference to Figures 1 and 2 can be represented by the following pseudo-code. [Number]
[0040] In this pseudo-code, the function ParseRand uses the above function Expand(r) to determine the vectors r1,..., r k and determines.
[0041] Corrections and further embodiments In the above example, the user device 1 determines the first NIZK proof π1 using a straight-line extractable proof. For example, compared with the Fiat-Shamir of the abort proof, the straight-line extractable proof is relatively complex, the size of the proof becomes large, but the security is also improved. In applications where the loss of security is not an important issue, other protocols, for example, protocols based on the Fiat-Shamir of the abort proof can be used, or the first NIZK proof π1 can even be completely omitted.
[0042] Lattice-based proofs are known to have "slack" in that the proven secret is larger than the actual known secret. Recently, however, lattice-based proofs that remove this slack have been developed instead of increasing the size of the proof. Therefore, there is an interaction between the desired security, the size of the proof, and the complexity of processing that should be considered when selecting the zero-knowledge protocol π1 for the first NIZK proof π1. In contrast, for the second NIZK proof π2, the concern is only the size of the proof, and any NIZK protocol π2 can be used.
[0043] The blind signature scheme described above with reference to FIGS. 1 and 2 can be easily converted into a partially blind signature scheme. A partially blind signature is an extension of a blind signature, and the signer device 5 can include information in the message m, for example, an expiration date or invalidation of an old signature. To bind the signature to a specific message μ, it is only necessary to modify the right side of the lattice problem from u to u - H(μ).
[0044] The public parameters b1,..., b k can be selected as b1 = b2 =... = b k In this way, the signer device 5 can simply sample a short vector e as follows. [a1│a2 + t│b1]·e = u. By doing so, the signature size is reduced at the expense of increasing the complexity of the zero-knowledge protocol π2.
[0045] Further modifications to the lattice problem are possible. For example, the public parameters b1,…,b k are included only to reduce security and can be omitted from the lattice problem so that the signer device 5 samples a prior image of [a1|a2+t]. Even the public parameter a2 can be omitted so that the signer device 5 samples a prior image of [a1|t], but this may make the blind signature scheme vulnerable to attacks.
[0046] To further simplify the blind signature scheme, the NIZK protocol Π2 is such that, for example, the receiver device 3
Number
Number
Number
Number
Number
Number
Number
[0047] In the above blind signature scheme, the public parameters a1, a2, b1, …, b k are all
Number
Number
Number
Number
[0048] The above encryption function can be implemented in software, hardware, or a combination of hardware and software. Therefore, the operations of the above user device 1 and signer device 5 can be implemented as processor-executable instructions that execute their respective functions when executed by a processor. Alternatively, the functions of user device 1 and signer device 5 discussed above can be implemented by, for example, a hardware circuit that executes each function, such as an FPGA or ASIC, or a combination of processor-executable instructions and hardware. Regardless of whether the function is implemented by software, a hardware device, or a mixture of software and a hardware device, it can be said that the function is implemented by modules of user device 1 and signer device 5.
[0049] The above embodiments should be understood as examples for the purpose of explaining the present invention. Further embodiments of the present invention are contemplated. Of course, any feature described in connection with any one embodiment can be used alone or in combination with other features described, and can also be used in combination with one or more features of any other embodiment, or any combination of any other embodiments. Furthermore, equivalents and modifications not described above may be used without departing from the scope of the present invention as defined in the appended claims.
Explanation of Reference Numerals
[0050] 1 User device 3 Receiver device 5 Signer device 9, 15 Transmitter 11, 17 Receiver 13 Processor 19 Secret trapdoor function
Claims
1. A computer-implemented method for generating a signature of a message, comprising: at a user device, processing the message m and random data r to generate a commitment c of the message, and sending the commitment c to a signer device; at the signer device, deriving a target vector t from the commitment c; Using a secret trapdoor function to sample a short vector e that solves the lattice problem A·e T = u A is a matrix in the form of [a 1 │v], where a 1 is a public parameter, and v depends on the target vector t where u is a polynomial, The secret trapdoor function is associated with the public parameter a 1 and is associated with any 【Number 1】 for which the signer device can [Number 2] is smaller than the boundary value B, [a 1 │v]e T = u, a short vector 【Mathematics 3】 sample, the sampling; sending the short vector e to the user device; at the user device, verifying that the short vector e solves the lattice problem; generating a signature that proves knowledge of the short vector e based on the message and public data. The computer-implemented method as described above.
2. The generation of the commitment c comprises: generating a hash h of the message; generating a commitment c based on the hash h and the random data r. The computer-implemented method according to claim 1.
3. The commitment c is in the form of 【Number 4】 where h is the hash of the message, 【Number 5】 The computer-implemented method according to claim 2.
4. The computer-implemented method according to claim 2 or claim 3, further comprising generating a first non-interactive zero-knowledge proof that proves knowledge of the hash h and the random data r.
5. The method according to claim 3 or claim 4, wherein the target vector t corresponds to the minimum k rows of the commitment.
6. The lattice problem is 【Number 6】 is in the form, where a 2 is a public parameter, the method according to any one of claims 1 to 5.
7. The method according to claim 6, wherein the signer device provides information μ to the right side of the lattice problem u = u' - H(μ) to accompany the message m, where u' is a polynomial.
8. Proving knowledge of the short vector e based on the message m and the public data comprises generating a second non-interactive zero-knowledge proof. The method according to any one of claims 1 to 7.
9. Proving the non-interactive zero-knowledge proof comprises reformulating a lattice problem equation into the form of 【Number 7】 where 【Number 8】 can be derived from the message and the public data, The non-interactive zero-knowledge proof proves knowledge of 【Number 9】 from the message m and the public data. The method according to claim 8.
10. A user device, processing a message m and random data r to generate a commitment c for the message m; sending the commitment c to a signer device; receiving a short vector e from the signer device in response to the sending of the commitment c; verifying that the short vector e solves a lattice problem; generating a signature that proves knowledge of the short vector e based on the message m and public data, the user device being configured to perform the above.
11. The generation of the commitment generates a hash (h) of the message; generates a commitment based on the hash and random data, the commitment being 【Number 10】 is in the form, where r 1 …r k is a random parameter derived from the random data (r), h is the hash of the message, g is a gadget vector, and 【Number 11】 including the above generation, where the target vector corresponds to the minimum k rows of the commitment, the user device according to claim 10.
12. The lattice problem is 【Number 12】 is in the form, where a 1 and a 2 are public parameters, e is the short vector, t is the target vector, u is public random data, and B is a fixed boundary value. The user device according to claim 11.
13. Generating the signature includes proving a non-interactive zero-knowledge proof that proves knowledge of the short vector based on the message and public data. Optionally, proving a second non-interactive zero-knowledge proof includes reformulating a lattice problem equation 【Number 13】 in the form of, where in the formula 【Number 14】 can be derived from the message and the public data, the non-interactive zero-knowledge proof proves knowledge of 【Number 15】 from the message and the public data, the user device according to any one of claims 10 to 12.
14. A device for signing a message, the device having access to a secret trapdoor function, receiving a commitment c from a user device, the commitment c corresponding to a message m to be signed; deriving a target vector t from the commitment c; Using the secret trapdoor function, sampling a short vector e that solves the lattice problem A·e T = u, A is a matrix in the form of [a 1 │v], where a 1 is a public parameter, and v depends on the target vector t u is a polynomial, The secret trapdoor function is associated with the public parameter a 1 and is associated with any 【Number 16】 for which the signer device 【Number 17】 is smaller than the boundary value B, [a 1 │v]e T = u, a short vector 【Number 18】 can sample; sending the short vector to the user device, the device being configured to perform the above.
15. The device is configured to provide information μ to accompany the message m, and the right side of the lattice problem is in the form of u - H(μ), the device according to claim 14.