基于无证书的属性门限签名方案
网络出版日期: 2026-06-01
基金资助
河南省重点研发专项(231111211900)
版权
Certificateless attribute based threshold signature
Online published: 2026-06-01
Copyright
属性签名便于隐匿签名者隐私,能够为电子医疗等网络的匿名认证提供密码原语支撑。然而,现有大多数属性签名方案通过集中式授权的方式管理用户属性密钥。如果属性授权机构被敌手控制,敌手可以伪造任意用户属性密钥,代替用户生成合法签名以牟取非法利益。因此,属性密钥托管问题已经成为限制属性签名应用和发展的安全瓶颈。综上,本文首先提出基于无证书的属性门限签名方案的定义和安全模型;然后,本文采用无证书思想,移除集中式可信属性授权机构,将用户属性密钥的分发和管理权限分别交由系统授权机构与属性授权机构共同承担,提出能够有效克服属性密钥托管问题的属性签名方案;最后,通过形式化安全分析证明提出的属性签名方案能够实现无条件匿名性,并且在随机预言机模型下,针对无证书体制的两类攻击者,签名具有不可伪造性。
凡云华 , 贾洪勇 . 基于无证书的属性门限签名方案[J]. 网络空间安全科学学报, 2026 . DOI: 10.20172/j.issn.2097-3136.260533
Attribute-based signatures facilitate the privacy hiding of signers and can provide cryptographic primitive support for anonymous authentication in networks such as electronic healthcare systems. However, most of the existing attribute-based signature schemes manage the user's attribute key by means of centralized authorization. If the attribute authorization authority is controlled by an adversary, the adversary can forge any user's attribute key and generate legitimate signatures instead of the user in order to gain illegal benefits. Therefore, the attribute key escrow problem has become a security bottleneck limiting the application and development of attribute-based signatures. In view of the above deficiencies, we first present the definition and security model of our certificateless attribute-based threshold signature; Then, we propose a key-escrow-free attribute-based threshold signature scheme, which removes the centralized honest attribute authorization authority and entrusts the management authority of the user's attribute key to the system authorization authority and the attribute authorization authority respectively by adopting the idea of certificateless; Finally, formal security analysis proves that the proposed scheme not only achieves unconditional anonymity, but also ensures that the signature is existentially unforgeable against two types of attackers in the certificateless cryptosystem under the random oracle model.
表 1 相关符号定义Table 1 Definition of relevant symbols |
| 符号 | 定义 |
| A | 系统属性集合数量 |
| B | 用户属性集合数量 |
| C | 声明属性集合数量 |
| D | 签名属性集合数量 |
| E | AA数量 |
| t | LSSS矩阵列数 |
| Tp | 双线性对运算耗时 |
| Te |
表 2 ABS方案通信开销对比结果Table 2 Communication cost comparison results of ABS schemes |
| 1 |
Khan M A, Ullah I, Kumar N, et al. An improvised certificate-based proxy signature using hyperelliptic curve cryptography for secure UAV communications[J]. IEEE Transactions on Intelligent Transportation Systems, 2025, 26(4): 5264-5275.
|
| 2 |
唐长虹, 赵艳琦, 杨晓艺, 等. 加权门限SM2签名方案[J]. 软件学报, 2025, 36 (8): 3883- 3895.
Tang C H, Zhao Y Q, Yang X Y, et al. Weighted threshold SM2 signature scheme[J]. Journal of Software, 2025, 36 (8): 3883- 3895.
|
| 3 |
Niu S, Zhou X, Wang N, et al. Privacy-preserving and efficient verifiable federated learning scheme based on proxy re-signature[J]. Expert Systems with Applications, 2025, 290, 128422.
|
| 4 |
Chen X J, Huang J Y, Xiao K F, et al. A non-interactive identity-based multi-signature scheme on lattices with public key aggregation[J]. IEEE Transactions on Dependable and Secure Computing, 2025, 22 (4): 4189- 4199.
|
| 5 |
Ouyang M D, Sun Q S, Li F G. Subversion-resistant identity-based aggregate signature with reverse firewalls for IoV[J]. IEEE Transactions on Vehicular Technology, 2025, 74 (7): 10841- 10852.
|
| 6 |
Guo H, Tian K, Liu F X, et al. Identity-based linearly homomorphic proxy signature scheme[J]. Computer Networks, 2025, 272, 111703.
|
| 7 |
Liu X D, Tong X J, Wang Y H. Escrow-free attribute based signature with constant-size for the Internet of Things[J]. Information Sciences, 2026, 723, 122679.
|
| 8 |
Guo C, Gong B, Li Z, et al. FORT: a forward secure and threshold authorized multi-authority attribute-based signature scheme for multimedia IoT[J]. IEEE Transactions on Multimedia, 2025, 27, 8859- 8874.
|
| 9 |
Guo C, Lu Y, Xia N, et al. User-friendly and expressive forward-secure attribute-based signature with server-aided signature and outsourced verification[J]. IEEE Transactions on Knowledge and Data Engineering, 2025, 37 (6): 3794- 3809.
|
| 10 |
Huang Z J, Lin Z W. Secure server-aided attribute-based signature with perfect anonymity for cloud-assisted systems[J]. Journal of Information Security and Applications, 2022, 65, 103066.
|
| 11 |
李继国, 朱留富, 刘成东, 等. 标准模型下证明安全的可追踪属性基净化签名方案[J]. 计算机研究与发展, 2021, 58 (10): 2253- 2264.
Li J G, Zhu L F, Liu C D, et al. Provably secure traceable attribute-based sanitizable signature scheme in the standard model[J]. Journal of Computer Research and Development, 2021, 58 (10): 2253- 2264.
|
| 12 |
Chen B W, Xiang T, Li X G, et al. Efficient attribute-based signature with collusion resistance for Internet of vehicles[J]. IEEE Transactions on Vehicular Technology, 2023, 72 (6): 7844- 7856.
|
| 13 |
Su Y, Zhang X, Qin J, et al. Efficient and flexible multiauthority attribute-based authentication for IoT devices[J]. IEEE Internet of Things Journal, 2023, 10 (15): 13945- 13958.
|
| 14 |
Xiong H, Bao Y Y, Nie X Y, et al. Server-aided attribute-based signature supporting expressive access structures for industrial Internet of Things[J]. IEEE Transactions on Industrial Informatics, 2020, 16 (2): 1013- 1023.
|
| 15 |
Cui H, Deng R H, Wang G L. An attribute-based framework for secure communications in vehicular ad hoc networks[J]. IEEE/ACM Transactions on Networking, 2019, 27 (2): 721- 733.
|
| 16 |
Shi R, Feng H M, Yang Y, et al. Threshold attribute-based credentials with redactable signature[J]. IEEE Transactions on Services Computing, 2023, 16 (5): 3751- 3765.
|
| 17 |
Chen Y, Li J G, Liu C D, et al. Efficient attribute based server-aided verification signature[J]. IEEE Transactions on Services Computing, 2022, 15 (6): 3224- 3232.
|
| 18 |
Kang Z Z, Li J G, Zuo Y T, et al. OABS: efficient outsourced attribute-based signature scheme with constant size[J]. IEEE Internet of Things Journal, 2024, 11 (23): 38167- 38177.
|
| 19 |
Kang Z Z, Li J G, Shen J, et al. TFS-ABS: traceable and forward-secure attribute-based signature scheme with constant-size[J]. IEEE Transactions on Knowledge and Data Engineering, 2023, 35 (9): 9514- 9530.
|
| 20 |
朱留富, 李继国, 陆阳, 等. 前向安全的高效属性基可净化签名方案[J]. 计算机研究与发展, 2023, 60 (12): 2737- 2748.
Zhu L F, Li J G, Lu Y, et al. Efficient and forward-secure attribute-based sanitizable signature scheme[J]. Journal of Computer Research and Development, 2023, 60 (12): 2737- 2748.
|
| 21 |
Li J G, Chen Y, Han J G, et al. Decentralized attribute-based server-aid signature in the Internet of Things[J]. IEEE Internet of Things Journal, 2022, 9 (6): 4573- 4583.
|
| 22 |
Chase M, Chow S S M. Improving privacy and security in multi-authority attribute-based encryption[C]//Proceedings of the 16th ACM Conference on Computer and Communications Security. New York: ACM, 2009: 121-130.
|
| 23 |
唐飞, 包佳立, 黄永洪, 等. 基于属性的多授权中心身份认证方案[J]. 通信学报, 2021, 42 (3): 220- 228.
Tang F, Bao J L, Huang Y H, et al. Multi-authority attribute-based identification scheme[J]. Journal on Communications, 2021, 42 (3): 220- 228.
|
| 24 |
Gennaro R, Jarecki S, Krawczyk H, et al. Secure distributed key generation for discrete-log based cryptosystems[M]//Advances in Cryptology — EUROCRYPT ’99. Berlin, HeidelbergSpringer, 1999: 295-310.
|
| 25 |
Cui H, Wang G L, Deng R H, et al. Escrow free attribute-based signature with self-revealability[J]. Information Sciences, 2016, 367, 660- 672.
|
| 26 |
Guo H, Li W X, Nejad M, et al. A hybrid blockchain-edge architecture for electronic health record management with attribute-based cryptographic mechanisms[J]. IEEE Transactions on Network and Service Management, 2023, 20 (2): 1759- 1774.
|
| 27 |
Oberko P S K, Obeng V K S, Xiong H, et al. A survey on attribute-based signatures[J]. Journal of Systems Architecture, 2022, 124, 102396.
|
| 28 |
Li Y, Chen X, Yin Y Y, et al. SDABS: a flexible and efficient multi-authority hybrid attribute-based signature scheme in edge environment[J]. IEEE Transactions on Intelligent Transportation Systems, 2021, 22 (3): 1892- 1906.
|
| 29 |
Liu X J, Chen W, Xia Y J, et al. TRAMS: a secure vehicular crowdsensing scheme based on multi-authority attribute-based signature[J]. IEEE Transactions on Intelligent Transportation Systems, 2022, 23 (8): 12790- 12800.
|
| 30 |
Su Q Q, Zhang R, Xue R, et al. Distributed attribute-based signature with attribute dynamic update for smart grid[J]. IEEE Transactions on Industrial Informatics, 2023, 19 (9): 9424- 9435.
|
/
| 〈 |
|
〉 |