高级搜索

留言板

尊敬的读者、作者、审稿人, 关于本刊的投稿、审稿、编辑和出版的任何问题, 您可以本页添加留言。我们将尽快给您答复。谢谢您的支持!

姓名
邮箱
手机号码
标题
留言内容
验证码

LBAC:基于格的zk-creds范式匿名凭证方案

郭显 顾腾飞 贾文娟 成玉丹 方君丽 冯涛

郭显, 顾腾飞, 贾文娟, 成玉丹, 方君丽, 冯涛. LBAC:基于格的zk-creds范式匿名凭证方案[J]. 电子与信息学报. doi: 10.11999/JEIT260718
引用本文: 郭显, 顾腾飞, 贾文娟, 成玉丹, 方君丽, 冯涛. LBAC:基于格的zk-creds范式匿名凭证方案[J]. 电子与信息学报. doi: 10.11999/JEIT260718
GUO Xian, GU Tengfei, JIA Wenjuan, CHENG Yudan, FANG Junli, FENG Tao. LBAC: Lattice-based Anonymous Credential Based on the zk-creds Paradigm[J]. Journal of Electronics & Information Technology. doi: 10.11999/JEIT260718
Citation: GUO Xian, GU Tengfei, JIA Wenjuan, CHENG Yudan, FANG Junli, FENG Tao. LBAC: Lattice-based Anonymous Credential Based on the zk-creds Paradigm[J]. Journal of Electronics & Information Technology. doi: 10.11999/JEIT260718

LBAC:基于格的zk-creds范式匿名凭证方案

doi: 10.11999/JEIT260718 cstr: 32379.14.JEIT260718
基金项目: 国家自然科学基金(61461027),甘肃省自然科学基金项目(26JRRA528,20JR5RA467)
详细信息
    作者简介:

    郭显:男,教授,博士,研究方向为密码学基础理论与应用等,邮箱: iamxg@163.com

    顾腾飞:男,研究生,研究方向为网络与信息安全

    贾文娟:女,讲师,博士,研究方向格密码等

    成玉丹:女,副教授,博士,研究方向为信息安全与隐私保护等

    方君丽:女,讲师,博士,研究方向为工业互联网安全

    冯涛:男,研究员,博士,研究方向为密码学,安全协议设计与分 析等

    通讯作者:

    郭显 iamxg@163.com

  • 中图分类号: TN918; TP309

LBAC: Lattice-based Anonymous Credential Based on the zk-creds Paradigm

Funds: The National Natural Science Foundation of China (61461027), The Natural Science Foundation of Gansu Province (26JRRA528, 20JR5RA467)
  • 摘要: 基于通用零知识证明技术构造隐私保护匿名凭证,已成为学术界和企业界广泛关注的焦点。zk-creds范式匿名凭证构造机制,允许凭证持有者利用通用零知识证明技术将现有的长效凭证直接转化为匿名凭证,无需依赖可信第三方颁发机构。作为该范式的代表性方案,Crescent继承zk-creds的思想,并通过“准备-展示”两阶段解耦机制,实现了更加高效的凭证展示。然而,Crescent基于传统数论困难假设,不具备抵抗量子计算攻击的能力。因此,该文借鉴Crescent方案的思想,采用基于格密码的交互式证明系统LaBRADOR,提出一种抗量子攻击的zk-creds范式匿名凭证新方案LBAC (Lattice-Based Anonymous Credentials)。该方案首先引入随机掩码机制和Fiat-Shamir变换,将LaBRADOR系统改造为非交互的零知识证明系统;其次,针对LaBRADOR在处理复杂算术电路时面临的性能瓶颈,引入Sumcheck协议将庞大的算术电路验证问题归约为极小规模的证明任务,有效降低证明开销;第三,将改进后的LaBRADOR证明生成流程解耦,使其能够与Crescent的思想相契合;最后,该文在随机预言机模型中对LBAC方案的安全属性(如匿名性与不可伪造性)进行全面分析。此外,理论与实验分析表明LBAC与相关方案相比具有一定的优势,凭证展示耗时约为5.27 毫秒,证明大小约为50.17 KB,兼具轻量性和实用性。
  • 图  1  系统模型图

    图  2  方案时序图

    图  3  交互流程

    图  4  本方案与已有方案凭证展示时间对比

    图  5  本方案与已有方案证明大小对比

    表  1  本文方案与已有方案的理论性能对比

    可信设置IssueShowVerify
    文献[12]O(q)O(q)
    文献[11]O(Ci)O($ k \cdot V_{g} $)O(k)
    文献[24]O(1)O(N log2 N)O($ \sqrt{N} $)
    本文O(poly(log2 C))O(n)
    下载: 导出CSV

    表  2  本文所用LaBRADOR与其他证明系统理论性能对比

    证明大小生成证明时间验证时间
    LaBRADORO(log2 n)O(n)O(n)
    LigeroO($ \sqrt{n} $)O(nlog2 n)O($ \sqrt{n} $)
    AuroraO(log22 n)O(nlog2 n)O(n)
    BrakedownO($ {n}^{\frac{1}{t}} $)O(n)O($ {n}^{\frac{1}{t}} $)
    下载: 导出CSV

    表  3  本方案与已有方案的实际耗时比较(ms)

    抗量子安全性凭证展示耗时验证耗时
    文献[12]14.937.05
    文献[11]216.076.88
    文献[24]122.0075.31
    本文5.27621.28
    下载: 导出CSV
  • [1] CHAUM D. Security without identification: Transaction systems to make big brother obsolete[J]. Communications of the ACM, 1985, 28(10): 1030–1044. doi: 10.1145/4372.4373.
    [2] CAMENISCH J and LYSYANSKAYA A. A signature scheme with efficient protocols[C]. Proceedings of the 3rd International Conference on Security in Communication Networks, Amalfi, Italy, 2002: 268–289. doi: 10.1007/3-540-36413-7_20.
    [3] BONEH D, BOYEN X, and SHACHAM H. Short group signatures[C]. Proceedings of the 24th Annual International Cryptology Conference on Advances in Cryptology–CRYPTO 2004, Santa Barbara, USA, 2004: 41–55. doi: 10.1007/978-3-540-28628-8_3.
    [4] CAMENISCH J and VAN HERREWEGHEN E. Design and implementation of the idemix anonymous credential system[C]. Proceedings of the 9th ACM Conference on Computer and Communications Security, Washington, USA, 2002: 21–30. doi: 10.1145/586110.586114.
    [5] SONNINO A, AL-BASSAM M, BANO S, et al. Coconut: Threshold issuance selective disclosure credentials with applications to distributed ledgers[C]. Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, USA, 2019. doi: 10.14722/ndss.2019.23272.
    [6] POINTCHEVAL D and SANDERS O. Short randomizable signatures[C]. Proceedings of the Topics in Cryptology–CT-RSA 2016, San Francisco, USA, 2016: 111–126. doi: 10.1007/978-3-319-29485-8_7.
    [7] 赵陆天禹, 王化群. 基于SM2的去中心化匿名凭证方案[J]. 计算机研究与发展, 2025, 62(12): 3093–3105. doi: 10.7544/issn1000-1239.202440756.

    ZHAO Lutianyu and WANG Huaqun. SM2-based decentralized anonymous credential scheme[J]. Journal of Computer Research and Development, 2025, 62(12): 3093–3105. doi: 10.7544/issn1000-1239.202440756.
    [8] 李威翰, 张宗洋, 周子博, 等. 简洁非交互零知识证明综述[J]. 密码学报, 2022, 9(3): 379–447. doi: 10.13868/j.cnki.jcr.000525.

    LI Weihan, ZHANG Zongyang, ZHOU Zibo, et al. An overview on succinct non-interactive zero-knowledge proofs[J]. Journal of Cryptologic Research, 2022, 9(3): 379–447. doi: 10.13868/j.cnki.jcr.000525.
    [9] DESMOULINS N, DUMANOIS A, KANE S, et al. Making BBS anonymous credentials eIDAS 2.0 compliant[C]. Proceedings of the 10th International Conference on Security Standardisation Research, Passau, Germany, 2026: 26–45. doi: 10.1007/978-3-032-19567-8_2.
    [10] W3C. Verifiable credentials data model v2.0: W3C recommendation[EB/OL]. https://www.w3.org/TR/vc-data-model-2.0/, 2025.
    [11] ROSENBERG M, WHITE J, GARMAN C, et al. zk-creds: Flexible anonymous credentials from zkSNARKs and existing identity infrastructure[C]. Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP), San Francisco, USA, 2023: 790–808. doi: 10.1109/SP46215.2023.10179430.
    [12] PAQUIN C, POLICHARLA G V, and ZAVERUCHA G. Stronger privacy for existing credentials[C/OL]. https://rwc.iacr.org/2025/program.php, 2025.
    [13] 俞惠芳, 党宁泽. 车联网环境下去中心化抗量子计算数据共享方案[J]. 电子与信息学报, 2025, 47(10): 3838–3846. doi: 10.11999/JEIT250144.

    YU Huifang and DANG Ningze. Decentralized anti-quantum internet of vehicles data sharing scheme[J]. Journal of Electronics & Information Technology, 2025, 47(10): 3838–3846. doi: 10.11999/JEIT250144.
    [14] 赵毅强, 孔金笛, 付玉成, 等. 面向模块化格基密钥封装机制算法多项式乘法的侧信道安全防护关键技术研究[J]. 电子与信息学报, 2025, 47(9): 3126–3136. doi: 10.11999/JEIT250292.

    ZHAO Yiqiang, KONG Jindi, FU Yucheng, et al. Research on key technologies of side-channel security protection for polynomial multiplication in ML-KEM/Kyber algorithm[J]. Journal of Electronics & Information Technology, 2025, 47(9): 3126–3136. doi: 10.11999/JEIT250292.
    [15] 刘媛, 王励成, 周永彬. TTRC-ABE: 可追踪可撤销的基于循环代数带误差学习问题的格基属性加密方案[J]. 电子与信息学报, 2025, 47(6): 1911–1926. doi: 10.11999/JEIT240997.

    LIU Yuan, WANG Licheng, and ZHOU Yongbin. TTRC-ABE: Traitor traceable and revocable CLWE-based ABE scheme from lattices[J]. Journal of Electronics & Information Technology, 2025, 47(6): 1911–1926. doi: 10.11999/JEIT240997.
    [16] BEULLENS W and SEILER G. LaBRADOR: Compact proofs for R1CS from module-SIS[C]. Proceedings of the 43rd Annual International Cryptology Conference on Advances in Cryptology–CRYPTO 2023, Santa Barbara, USA, 2023: 518–548. doi: 10.1007/978-3-031-38554-4_17.
    [17] LYUBASHEVSKY V, SEILER G, and STEUER P. The LaZer library: Lattice-based zero knowledge and succinct proofs for quantum-safe privacy[C]. Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, Salt Lake City, USA, 2024: 3125–3137. doi: 10.1145/3658644.3690330.
    [18] NGUYEN N K and SEILER G. Greyhound: Fast polynomial commitments from lattices[C]. Proceedings of the 44th Annual International Cryptology Conference on Advances in Cryptology–CRYPTO 2024, Santa Barbara, USA, 2024: 243–275. doi: 10.1007/978-3-031-68403-6_8.
    [19] HWANG I, SEO J, and SONG Y. Concretely efficient lattice-based polynomial commitment from standard assumptions[C]. Proceedings of the 44th Annual International Cryptology Conference on Advances in Cryptology–CRYPTO 2024, Santa Barbara, USA, 2024: 414–448. doi: 10.1007/978-3-031-68403-6_13.
    [20] ARGO S, GÜNEYSU T, JEUDY C, et al. Practical post-quantum signatures for privacy[C]. Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, Salt Lake City, USA, 2024: 1523–1537. doi: 10.1145/3658644.3670297.
    [21] BOOTLE J, LYUBASHEVSKY V, NGUYEN N K, et al. A framework for practical anonymous credentials from lattices[C]. Proceedings of the 43rd Annual International Cryptology Conference on Advances in Cryptology–CRYPTO 2023, Santa Barbara, USA, 2023: 384–417. doi: 10.1007/978-3-031-38545-2_13.
    [22] MASSIMO J, KAMPANAKIS P, TURNER S, et al. RFC 9881: Internet X. 509 public key infrastructure -- algorithm identifiers for the module-lattice-based digital signature algorithm (ML-DSA)[EB/OL]. https://www.rfc-editor.org/rfc/rfc9881.html, 2025.
    [23] DELIGNAT-LAVAUD A, FOURNET C, KOHLWEISS M, et al. Cinderella: Turning shabby X. 509 certificates into elegant anonymous credentials with the magic of verifiable computation[C]. Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP), San Jose, USA, 2016: 235–254. doi: 10.1109/SP.2016.22.
    [24] FRIGO M and SHELAT A. Anonymous credentials from ECDSA[J]. IACR Communications in Cryptology, 2026, 3(1): 7. doi: 10.62056/a3qjmpgxq.
    [25] AMES S, HAZAY C, ISHAI Y, et al. Ligero: Lightweight sublinear arguments without a trusted setup[C]. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, USA, 2017: 2087–2104. doi: 10.1145/3133956.3134104.
    [26] TEAM P Z. Plonky2: Fast recursive arguments with PLONK and FRI[EB/OL]. https://docs.rs/crate/plonky2/latest/source/plonky2.pdf, 2022.
    [27] BEN-SASSON E, BENTOV I, HORESH Y, et al. Scalable, transparent, and post-quantum secure computational integrity[EB/OL]. https://eprint.iacr.org/2018/046, 2018.
    [28] GOLOVNEV A, LEE J, SETTY S, et al. Brakedown: Linear-time and field-agnostic SNARKs for R1CS[C]. Proceedings of the 43rd Annual International Cryptology Conference on Advances in Cryptology–CRYPTO 2023, Santa Barbara, USA, 2023: 193–226. doi: 10.1007/978-3-031-38545-2_7.
    [29] DE SANTIS A, DI CRESCENZO G, OSTROVSKY R, et al. Robust non-interactive zero knowledge[C]. Proceedings of the 21st Annual International Cryptology Conference on Advances in Cryptology–CRYPTO 2001, Santa Barbara, USA, 2001: 566–598. doi: 10.1007/3-540-44647-8_33.
    [30] FRIEDRICHS K, HARDING F, LEHMANN A, et al. Device-bound anonymous credentials with(out) trusted hardware[EB/OL]. https://eprint.iacr.org/2025/1995, 2025.
  • 加载中
图(5) / 表(3)
计量
  • 文章访问数:  18
  • HTML全文浏览量:  4
  • PDF下载量:  2
  • 被引次数: 0
出版历程
  • 收稿日期:  2026-06-01
  • 修回日期:  2026-09-15
  • 录用日期:  2026-09-15
  • 网络出版日期:  2026-09-22

目录

    /

    返回文章
    返回