Homomorphic ring signature schemes combine the strong anonymity of ring signatures with the computability of homomorphic signatures, demonstrating significant potential in scenarios requiring both anonymous data provenance and verifiable homomorphic computation (e.g., confidential blockchain transactions and secure multi-party computation). However, no feasible homomorphic ring signature scheme currently exists. In this work, we propose the first lattice-based linearly homomorphic ring signature scheme. Proven secure in the standard model under the small integer solution (SIS) assumption, our scheme achieves strong anonymity under full key exposure and unforgeability against insider corruption attacks. As the first unified framework for ring signatures and linear homomorphic signatures, this construction provides a post-quantum-secure solution for the aforementioned applications, advancing the development of privacy-enhanced homomorphic computation.
翻译:同态环签名方案结合了环签名的强匿名性与同态签名的可计算性,在需要匿名数据来源与可验证同态计算的场景中展现出巨大潜力(例如机密区块链交易和安全多方计算)。然而,目前尚无可行的同态环签名方案。本文中,我们提出了首个基于格的线性同态环签名方案。该方案在标准模型下基于小整数解(SIS)假设被证明是安全的,实现了完全密钥暴露下的强匿名性以及抵御内部腐败攻击的不可伪造性。作为环签名与线性同态签名的首个统一框架,该构造为前述应用提供了后量子安全的解决方案,推动了隐私增强同态计算的发展。