信息网络安全 ›› 2026, Vol. 26 ›› Issue (6): 886-898.doi: 10.3969/j.issn.1671-1122.2026.06.004

• 学术研究 • 上一篇    下一篇

基于TUOV数字签名算法的可否认环签名方案

张艳硕(), 严梓洋, 李柏衡, 陈辉焱, 刘冰   

  1. 北京电子科技学院密码科学与技术系北京 100070
  • 收稿日期:2025-11-14 出版日期:2026-06-10 发布日期:2026-07-27
  • 通讯作者: 张艳硕 E-mail:zhang_yanshuo@163.com
  • 作者简介:张艳硕(1979—),男,陕西,副教授,博士,CCF高级会员,主要研究方向为密码理论及其应用|严梓洋(2001—),男,湖南,硕士研究生,主要研究方向为多变量公钥密码|李柏衡(2000—),男,山东,硕士研究生,主要研究方向为后量子公钥密码|陈辉焱(1968—),男,山东,正高级工程师,博士,主要研究方向为后量子密码、公钥密码|刘冰(1976—),男,河北,副教授,博士,主要研究方向为密码编码、量子密码
  • 基金资助:
    国家密码科学基金(2025NCSF02028);中央高校基本科研业务(3282024001)

Deniable Ring Signature Scheme Based on TUOV Digital Signature Algorithm

ZHANG Yanshuo(), YAN Ziyang, LI Baiheng, CHEN Huiyan, LIU Bing   

  1. Department of Cryptography Science and Technology, Beijing Electronic Science and Technology Institute, Beijing 100070, China
  • Received:2025-11-14 Online:2026-06-10 Published:2026-07-27
  • Contact: ZHANG Yanshuo E-mail:zhang_yanshuo@163.com

摘要:

可否认环签名是一种在无可信第三方的情况下,允许环成员确认或否认自身为签名者的签名方案,能够有效平衡隐私保护与可控监管,具有广泛的应用前景。为完善和拓展多变量后量子密码体系,文章提出一种基于三角非平衡油醋(TUOV)数字签名算法的可否认环签名方案,实现了对签名的可验证与可否认。通过形式化证明实验,验证该方案在正确性、不可伪造性、匿名性、可追踪性及不可诽谤性等5个方面的安全性和有效性。此外,文章通过与基于格的可否认环签名(RRS)方案和基于商用密码算法系列2号标准(SM2)的可否认环签名方案在通信开销和计算开销方面进行对比分析,验证该方案具有良好的实用性。

关键词: 后量子密码, 多变量公钥密码, TUOV数字签名算法, 环签名, 可否认环签名

Abstract:

Deniable ring signature is a signature scheme that allows ring members to confirm or deny their identity as the signer in the absence of a trusted third party. It effectively balances privacy protection and controllable supervision, and has broad application prospects. To improve and expand the multivariable post-quantum cryptosystem, this paper proposed a denial-of-service ring signature scheme based on the triangular unbalanced oil and vinegar (TUOV) digital signature algorithm, which achieved verifiability and deniability of signatures. Through formal proof, the security and effectiveness of the scheme in terms of correctness, unforgeability, anonymity, traceability, and non-defamation were verified. Furthermore, this paper conducted a comparative analysis with the reputation ring signature (RRS)scheme based on lattices and the Denial-of-Service ring signature scheme based on the Shangyong mima 2 (SM2) standard in terms of communication and computational overhead, demonstrating good practicality.

Key words: post-quantum cryptography, multivariate public key cryptography, TUOV digital signature algorithm, ring signature, deniable ring signature

中图分类号: