The present application relates to the technical field of identity
authentication, and relates to a traceable
blind signature data
protection system based on SM9. A
server initializes data protection parameters and discloses them. The
server determines a private key of a first terminal and a data tracking
label according to the data protection parameters, and sends them to the first terminal. The first terminal blinds
transaction data according to the data protection parameters, the private key of the first terminal and the data tracking
label, and determines blinded data. The blinded data is blindly signed through an SM9
algorithm. A deblinding key of the blindly signed blinded data is generated. The blindly signed blinded data is sent to the
server. A second terminal purchases the blinded data through the server. The second terminal sends a decryption request and a purchase
voucher to the first terminal and receives the deblinding key sent by the first terminal. The blindly signed blinded data is recovered according to the deblinding key. It can be ensured that the server and the second terminal cannot know the
original data content before obtaining the deblinding key.