信息网络安全 ›› 2026, Vol. 26 ›› Issue (4): 552-565.doi: 10.3969/j.issn.1671-1122.2026.04.004

• 学术研究 • 上一篇    下一篇

基于国密算法SM9的可否认环签密方案的设计

张艳硕1, 孔佳音1(), 周幸妤1, 秦晓宏1, 胡荣磊2   

  1. 1 北京电子科技学院密码科学与技术系北京 100070
    2 北京电子科技学院电子与通信工程系北京 100070
  • 收稿日期:2025-11-30 出版日期:2026-04-10 发布日期:2026-04-29
  • 通讯作者: 孔佳音 E-mail:jiayin_kong@163.com
  • 作者简介:张艳硕(1979—),男,陕西,副教授,博士,CCF会员,主要研究方向为密码学理论|孔佳音(2001—),女,安徽,硕士研究生,主要研究方向为密码理论及其应用|周幸妤(2000—),女,江苏,硕士研究生,主要研究方向为密码理论及其应用|秦晓宏(1976—),女,内蒙古,讲师,硕士,主要研究方向为信息隐藏、密码技术|胡荣磊(1977—),男,河北,副研究员,博士,主要研究方向为密码芯片安全、隐私保护与隐私计算、网络安全、物联网和区块链
  • 基金资助:
    国家自然科学基金(62002003);北京市自然科学基金(4232034);中央高校基本科研业务费(3282023017)

A Deniable Ring Signcryption Scheme Based on SM9

ZHANG Yanshuo1, KONG Jiayin1(), ZHOU Xingyu1, QIN Xiaohong1, HU Ronglei2   

  1. 1 Department of Cryptology Science and Technology, Beijing Electronic Science & Technology Institute, Beijing 100070, China
    2 Department of Electronic and Communication Engineering, Beijing Electronic Science & Technology Institute, Beijing 100070, China
  • Received:2025-11-30 Online:2026-04-10 Published:2026-04-29

摘要:

标识密码消除了证书,避免了传统公钥密码系统中的证书管理问题,但不能保证用户身份的匿名性。可否认环签名允许环成员对签名行为进行确认或否认,避免非签名者遭受诽谤,但不能确保消息的机密性。环签密结合签名和加密技术,在环签名的基础上保证用户匿名性,但由于缺乏可否认性,其在责任追溯场景下应用受限。为此,文章提出一种基于SM9的可否认环签密方案,支持环成员确认或否认签密行为,有效平衡隐私保护、通信安全与计算高效。文章通过形式化证明方式证明了该方案满足正确性、不可区分性、不可伪造性、匿名性、可追踪性和不可诽谤性。

关键词: SM9, 可否认性, 环签密, 安全性, 可否认环签密

Abstract:

The identity-based signcryption system eliminates certificates and avoids certificate management problems in traditional public key cryptosystems, but it can’t guarantee the anonymity of the user’s identity. The deniable ring signature enables ring members to confirm or deny the act of signing and avoid defamation of non-signers, but it can’t guarantee the confidentiality of the message. The ring signcryption system features signature and encryption techniques and guarantees the anonymity of the user’s identity based on ring signature, but its application is limited in liability tracing scenarios due to the lack of deniability. For this reason, this article proposed a deniable ring signcryption scheme based on SM9, which enables ring members to confirm or deny the act of signcrypting, effectively balancing the privacy protection, communication security and computational efficiency. The article proved that the scheme satisfies correctness, indistinguishability, unforgeability, anonymity, traceability, and defamation by formal proofs.

Key words: SM9, deniability, ring signcryption, security, deniable ring signcryption

中图分类号: