摘要
针对代理环签名在对用户身份信息保护要求较高场景中的应用需求,文章基于SM9数字签名算法,提出一种代理环签名方案,包括系统初始化、密钥提取、代理委托、代理验证、签名和验证6个步骤。密钥生成中心使用用户标识计算用户的密钥,原始签名者使用已知信息计算代理授权,然后将代理授权委托给代理签名者。代理签名者验证委托的真实性后,通过签名步骤产生代理环签名,产生的签名可以使用验证算法验证。该方案不仅实现了签名权利的委托,同时通过环签名的匿名性保护签名者的隐私,并在随机预言机模型下证明了其具有适应性选择消息攻击下的不可伪造性。通过效率分析表明,该方案效率较高,有较好的实用性。
In view of the application requirements of proxy ring signature in scenarios requiring high user identity protection,this paper proposed a proxy ring signature scheme based on SM9 digital signature algorithm.The scheme included six steps:setup,extract,proxydelegation,verifyproxy,sign and verify.The Key Generation Center uses the user ID to calculate the user’s key,and the original signer used the known information to calculate the proxy authorization,and then delegated the proxy authorization to the proxy signer.After the proxy signer verified the authentiecity of the authorization,the proxy ring signature was generated through the signature step,and the generated signature can be verified by the authentication algorithm.The scheme not only realizes the entrustment of signature rights,but also protects the privacy of signers through the anonymity of ring signatures.It is also proved that the scheme is unforgeable under adaptive selective message attacks under random prophecy model.The efficiency analysis shows that the proposed scheme has higher efficiency and better practicability.
作者
张雪锋
王柯航
ZHANG Xuefeng;WANG Kehang(School of Cyberspace Security,Xian University of Posts and Telecommunications,Xian 710121,China)
出处
《信息网络安全》
北大核心
2025年第12期1901-1913,共13页
Netinfo Security
基金
国家自然科学基金[2021JQ-722]。
关键词
SM9
数字签名
代理环签名
SM9
digital signature
proxy ring signature