ConceptioArchiveNCBI PubMed Central
NCBI PubMed Centralopen access

A multi-authority attribute ring signature supporting dynamic policies and dual anonymity for zero-trust networks.

Chen J et al. · ncbi_pmc
NCBI PubMed Central · Papers · License: Open Access
Open Source ↗Direct PDF ↓
cryptographysecurity
cryptography security

Skip to main content An official website of the United States government Here's how you know Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Log in Dashboard Publications Account settings Log out Search… Search NCBI Primary site navigation Search Logged in as: Dashboard Publications Account settings Log in Search PMC Full-Text Archive Search in PMC Journal List User Guide PERMALINK Copy As a library, NLM provides access to scientific literature. Inclusion in an NLM database does not imply endorsement of, or agreement with, the contents by NLM or the National Institutes of Health. Learn more: PMC Disclaimer | PMC Copyright Notice Sci Rep . 2026 Feb 17;16:9441. doi: 10.1038/s41598-026-40089-2 Search in PMC Search in PubMed View in NLM Catalog Add to search A multi-authority attribute ring signature supporting dynamic policies and dual anonymity for zero-trust networks Jinhong Chen Jinhong Chen 1 Naval University of Engineering, Wuhan, 430033 China 2 College of Economics and Trade, Jiangxi Vocational College of Finance and Economics, Jiujiang, 332000 China Find articles by Jinhong Chen 1, 2 , Xueguang Zhou Xueguang Zhou 1 Naval University of Engineering, Wuhan, 430033 China Find articles by Xueguang Zhou 1 , Wei Fu Wei Fu 1 Naval University of Engineering, Wuhan, 430033 China Find articles by Wei Fu 1, ✉ , Yihuan Mao Yihuan Mao 1 Naval University of Engineering, Wuhan, 430033 China Find articles by Yihuan Mao 1 , Jiaqi Wang Jiaqi Wang 3 Jiujiang Shuangfeng Primary School, Jiujiang, 332000 China Find articles by Jiaqi Wang 3 Author information Article notes Copyright and License information 1 Naval University of Engineering, Wuhan, 430033 China 2 College of Economics and Trade, Jiangxi Vocational College of Finance and Economics, Jiujiang, 332000 China 3 Jiujiang Shuangfeng Primary School, Jiujiang, 332000 China ✉ Corresponding author. Received 2025 Sep 1; Accepted 2026 Feb 10; Collection date 2026. © The Author(s) 2026 Open Access This article is licensed under a Creative Commons Attribution 4.0 International License, which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons.org/licenses/by/4.0/ . PMC Copyright notice PMCID: PMC13004895  PMID: 41699394 Abstract The advent of Decentralized Identity (DID) technology is fundamentally changing the way digital identity is managed, allowing user-controlled, privacy-preserving authentication across trust domains a fundamental requirement if zero trust architectures are to be realized, in which continuous verification and least-privilege access are inherent properties. Under traditional ABS (attribute-based signature) schemes, these are difficult to achieve as fine-grained access control is not always possible in practice and anonymity may not be straightforward when policy is evolving dynamically and different authorities may be involved. In this paper, we present a new multi-authority attribute ring signature scheme, which leverages DID philosophy and anonymous credential techniques, enabling users to mix attributes dynamically according to the policies of veriers without disclosing their pseudonyms or partial attributes. The proposed scheme enables distributed key generation by multiple authorities and is shown to be secure in the random oracle model, achieving existential unforgeability against adaptive chosen-message, identity, and attribute attacks (EUF-CMIAA) as well as full signer and attribute anonymity. Based on the SM9 cryptographic standard, our approach reduces the number of exponentiations and scalar multiplications during signing by approximately 30% compared to existing ring signatures, offering a practical and efficient authentication solution for emerging DID-driven zero-trust networks. Keywords: Decentralized identity, Zero trust, Attribute-based signature, Anonymous signature, Multi-authority Subject terms: Mathematics and computing, Physics Introduction With the progression of digital transformation in enterprises, the network structures of numerous companies have grown increasingly intricate and are progressively transitioning to the cloud 1 , 2 . Nevertheless, border-based gateway identity and access control systems struggle to address emerging threats, resulting in escalating security risks 3 . When enterprises employ traditional security paradigms to tackle these challenges, the zero-trust concept offers a novel security perspective 4 . The Jericho Forum introduced the initial iteration of zero trust 5 . Meanwhile, John Kindvag, a former analyst at Forrester Research, officially coined the term “zero trust” and articulated the zero-trust architecture principle with the mantra “never trust, always verify” 6 .This principle mandates that every access request must come with the minimum necessary privileges and verifiable identity or attribute credentials 4 . The rapid emergence of Decentralized Identity (DID) technologies has re-defined digital identity management by shifting control from centralized authorities to individual users 7 , 8 .Meanwhile DID has aligned perfectly with the identity management and granular access control requirements of zero-trust networks 9 , 10 .Leveraging distributed ledgers, DID systems enable privacy-preserving, cross-domain authentication without relying on a single trusted third party 11 . Despite this paradigm shift, two intertwined challenges remain open: enforcing fine-grained access control and providing anonymous authentication in a fully decentralized setting. Recent breakthroughs in succinct non-interactive zero-knowledge proofs (zk-SNARKs) have inspired new privacy-preserving credential systems. Notably, the zk-creds framework 7 transforms existing identity documents into unlinkable credentials while supporting dynamic policy composition. Yet, these benefits come at the cost of computationally expensive generic zero-knowledge proofs, which limits practical adoption. Attribute-Based Signatures (ABS) offer an alternative that natively supports fine-grained access control and signer anonymity 12 , 13 . In an ABS scheme, a signer can create a valid signature only if the attributes embedded in her private key satisfy a predicate specified by the verifier. Although conceptually aligned with DID requirements, traditional ABS constructions suffer from two major limitations: ( i ) policy rigidity caused by linear secret-sharing mechanisms 14 – 17 , and ( ii ) signature bloat that arises when strong security guarantees are required 18 – 20 . These drawbacks become critical bottlenecks in real-world deployments involving multiple, mutually distrusting authorities. Motivation: In a zero-trust network, a gateway (verifier) may require a user to prove they hold “Manager” AND “Finance” attributes today, but “Director” OR “Auditor” tomorrow. Traditional ABS requires re-issuing keys for every policy change. Furthermore, standard ring signatures hide the identity but not the attributes. There is a critical lack of a solution that combines dynamic policy enforcement (verifier chooses the policy on the fly) with dual anonymity (hiding both who signed and which attributes were used) while maintaining efficiency suitable for mobile clients.In this paper, we present a new multi-authority attribute ring signature scheme. Related work The evolution of anonymous authentication for zero-trust networks can be categorized into three developmental stages: Traditional Attribute-Based Signatures, Decentralized variants, and SM9-specific adaptations. Traditional and attribute-based signatures (ABS) The concept of ABS was developed to provide fine-grained access control with signer privacy. Early works, such as Maji et al. 12 and Guo et al. 15 , established the foundational security requirements. Li and Kim 14 and Toluee et al. 16 extended this to attribute-based ring signatures to enhance anonymity, while Li et al. 17 applied it to personal health records. However, these traditional schemes rely heavily on linear secret-sharing schemes (LSSS) or monotone span programs embedded in the keys. Limitation: This results in “policy rigidity.” While Ling et al. 13 attempted to achieve dynamic policies, most constructions fix the access structure at issuance. Furthermore, works like Herranz et al. 18 and Okamoto et al. 19 , 20 focused on constant-size signatures but often at the cost of high computational overhead in the standard model. Decentralized and multi-authority schemes To address the single-point-of-failure in centralized authorities, multi-authority schemes were introduced. Guo et al. 21 proposed a multi-authority ABS resilient to collusion, and Hou et al. 22 explored designated-combiner signatures. Various functional extensions have also been proposed to address specific needs: Ma et al. 23 , 24 introduced blind and designated-verifier ABS for privacy; Zhang et al. proposed Verifier-Policy ABS 25 and Registered ABS 26 to shift policy control; and others developed puncturable 27 , forward-secure 28 , and proxy signatures 29 for specific scenarios. Tao et al. 30 and Kang et al. 31 focused on lightweight or outsourced designs to reduce client burden. Limitation: Despite these functional rich variants, they often fail to provide “dual anonymity” in a fully distributed setting. They typically hide the identity but leak the attributes, or lack the flexibility to mix attributes from different authorities dynamically. Additionally, recent lattice-based constructions 32 – 34 offer post-quantum security but currently suffer from large signature sizes that hinder deployment on constrained devices. SM9-based cryptographic schemes The SM9 standard 35 , based on bilinear pairings, was designed for high efficiency, with its security formally analyzed by Lai et al. 36 . Recent works have attempted to adapt SM9 for advanced privacy. Tang et al. 37 and Zhu et al. 38 proposed traceable and online/offline attribute signatures based on SM9, while Zhou et al. 39 achieved partial policy hiding. Limitation: While highly efficient, these schemes generally focus on a single authority or lack the ring-signature structure required to hide the signer among a set of potential users completely. Existing SM9 ring signatures, such as the classic ID-based construction by Chow et al. 40 , the standard SM9 scheme by Peng et al. 41 , and the recent work by Xie et al. 42 , achieve identity anonymity but do not natively support dynamic attribute policies. Currently, none of these schemes simultaneously supports multi-authority issuance, dynamic attribute composition, and full anonymity. (see Table 1 ). Table 1. Comparison of existing functionalities. Scheme Multi-authority Dynamic attributes Identity anon. Attribute anon. Lai et al. 36 Tang et al. 37 Zhu et al. 38 Open in a new tab Our contribution Leveraging the SM9 signature algorithm and ring signatures, we design the first multi-authority anonymous attribute ring signature that supports dynamic attribute composition. Our contributions are as follows: Decentralized key issuance. Each authority independently issues attribute-specific keys without further coordination. Dynamic policy enforcement. Signers can combine their attributes on-the-fly to satisfy any access structure chosen by the verifier, without additional interaction with authorities. Dual anonymity. Both the signer’s identity and the subset of attributes used remain unconditionally anonymous within a ring of potential signers. Provable security. Under the random oracle model, the scheme is existentially unforgeable against adaptive chosen-message, identity, and attribute attacks (EUF-CMIAA) and achieves full anonymity. Practical efficiency. Compared with the state-of-the-art SM9 ring signature 42 , our construction reduces exponentiations and scalar multiplications during signing by approximately 30%, yielding significant performance gains for resource-constrained clients. Preliminaries Notation Throughout the paper, we adopt the following conventions. denotes the set ; sampling uniformly at random is written . represents the set of all finite-length binary strings. p and N are large primes with for the 256-bit BN curve used in SM9. is the prime field of order p ; its extension is denoted for . is an elliptic curve over ; are cyclic subgroups of prime order N with fixed generators respectively. Group law is written additively; scalar multiplication is . Bilinear pairings Let and be additive cyclic groups of prime order N , and a multiplicative cyclic group of the same order. Let be generators of , respectively, and an efficiently computable homomorphism such that . A (Type-3) bilinear pairing is a map satisfying Bilinearity: for all . Non-degeneracy: such that . Efficiency: e ( P , Q ) is computable in polynomial time. Security is based on the hardness of the following problems. Definition 1 (q-SDH Problem) Given for unknown , output a pair with . Definition 2 (q-BDHI Problem) Given for unknown , compute . Both problems are assumed hard in the generic group model and underpin the security of SM9. SM9 digital signature scheme SM9 is an identity-based cryptographic suite standardized by the State Cryptography Administration of China (GM/T 0003-2016). For signatures, it employs a 256-bit Barreto–Naehrig curve with embedding degree . Below we summarize the signature component. System setup A Key Generation Centre (KGC) selects a master secret key and publishes the master public key Private-key extraction For identity , the KGC computes where is a cryptographic hash. Signature generation To sign a message M , the signer chooses and computes with . The signature is . Signature verification Given , the verifier computes and accepts if and only if . Under the q-BDHI assumption, SM9 signatures are existentially unforgeable against adaptive chosen-message attacks in the random oracle model. Methods System overview We consider three distinct entities: Attribute Authorities (AAs): Trust domains within zero trust networks (such as HR domain, health domain, and finance domain). After collectively generating common parameters, they can independently issue attribute private keys to signers. Signers: The end-user who possesses a set of attributes and generates ABS. These signatures are created according to the access control structure specified by the verifier. Verifiers: In a zero trust network, the verifier is typically a zero trust gateway or policy engine. Based on actual circumstances, the verifier generates the corresponding access structure and verifies the ABS produced by the signer in accordance with this structure. Figure 1 illustrates the system workflow. Figure 1. Open in a new tab System model. Formal definition The scheme consists of four polynomial-time algorithms: :A probabilistic algorithm executed jointly by all AAs on input security parameter to output public parameters and a master public key . :A deterministic algorithm run by a single AA to generate an attribute private key for identity and attribute . :A probabilistic algorithm executed by the signer on message M , user set , and policy to produce an attribute ring signature . :A deterministic algorithm that outputs if is valid and otherwise. Correctness For any honestly generated parameters, keys and signatures, Security model We formalise two standard security properties: unforgeability and anonymity. Existential unforgeability under adaptive chosen-message, identity and attribute attacks (EUF-CMAIA) The EUF-CMAIA game between an adversary and a challenger proceeds as follows: Initialisation. runs , gives to . Queries. adaptively issues: Key queries: ; returns . Signing queries: ; returns a signature . Forgery. outputs such that is valid; has not queried any key for an identity in nor any signing query for . The advantage of is defined as The scheme is EUF-CMAIA secure if for every PPT adversary the advantage is negligible in . Full anonymity Full anonymity requires that neither the signer’s identity nor the subset of attributes used can be linked. The anonymity game is defined between and : Initialisation. Same as above. Queries. may issue key and signing queries adaptively. Challenge. provides a challenge user set , policy , message , and two identities together with the required attributes. flips a bit and returns the signature produced by . Guess. outputs a bit . It wins if . The advantage is The scheme satisfies full anonymity if is negligible for all PPT adversaries. Scheme construction We now present the complete specification of our SM9-based multi-authority anonymous attribute ring signature that supports dynamic attribute composition. All algorithms inherit the pairing groups defined by the SM9 curve. System establishment— All attribute authorities cooperatively execute the following steps: Select the public SM9 parameters as described in Section 2.3. Each authority j chooses an attribute-specific secret for every attribute under its control and publishes the corresponding attribute public key The master secret key is implicitly ; the master public key is Output Attribute private-key generation— Given an identity and an attribute , the responsible authority computes where and is a public identity-encoding string. The user stores the set locally. Attribute ring signature generation— Let denote the user ring and the verifier-specified access policy (attribute conjunction). The signer proceeds as follows: Eligibility check. If the attributes held by do not satisfy , abort. Aggregate attribute public keys. Compute and set . Aggregate private key. Let and compute Commit. Pick random and set Hash chain. Compute Ring loop. For (indices modulo n ) and for (indices modulo k ): i. If set and ; if set and . ii. . iii. . iv. , , . v. If set and exit both loops. Final response. Compute Output. The signature is Signature verification— Upon receiving the verifier proceeds as follows: Pre-compute for . Check formats. Abort if , any or . Re-compute chaining values. Let For and compute Accept if and only if . Correctness Let be an honestly generated and un-tampered signature. Then The correctness follows from the algebraic derivation presented in the original manuscript, which we reproduce verbatim for completeness. Case 1: For or ( and ) Case 2: For and Case 3: For or , the same algebraic chain ensures . Since holds, the verification algorithm always returns . Security analysis We provide formal proofs that the proposed attribute ring signature satisfies existential unforgeability (EUF-CMIAA) and full anonymity under the q-SDH assumption in the random oracle model. All equations and derivations are kept exactly as in the original manuscript, only refined for clarity and English readability. Unforgeability Theorem 1 Under the random oracle model, if the q-Strong Diffie–Hellman (q-SDH) problem is hard, the proposed attribute ring signature achieves existential unforgeability against adaptive chosen-message, identity and attribute attacks (EUF-CMIAA). Proof Assume there exists a probabilistic polynomial-time (PPT) adversary that wins the EUF-CMIAA game with non-negligible advantage . We construct a simulator that, given a q-SDH instance uses to output a valid q-SDH solution . Initialisation. fixes a maximum identity universe , a challenge identity set , a maximum attribute universe , a challenge attribute set . chooses distinct values and sets It then computes All public parameters are thus simulated from the q-SDH instance. Oracle Simulation. maintains two initially empty lists for and . queries. On input : If , picks and records . Otherwise, assigns the smallest unused to , increments l , and records . queries. On input , returns a fresh random value and stores the tuple. Key queries. On : If , aborts. Otherwise, retrieves and computes via polynomial interpolation, which is possible because f ( x ) is known. Signing queries. For queries with and , simulates a signature by choosing random and random and programming the random oracle accordingly. Forgery and Extraction. By the Forking Lemma, can obtain two valid signatures on the same such that and . Solving the resulting linear equation yields which satisfies Hence is a valid q-SDH solution. The success probability is which is non-negligible whenever is non-negligible. Anonymity Theorem 2 If the random values used in are uniformly distributed, the scheme achieves full anonymity: an adversary cannot distinguish the signer’s identity or the subset of attributes actually used beyond the required policy. Proof Let be a signature generated by user holding attributes . We show that can be identically simulated by any other user holding . Observe that where Since r and all intermediate random values are chosen uniformly and independently, the joint distribution of is identical regardless of which is chosen. Consequently, any polynomial-time adversary has negligible advantage in distinguishing the real signer or the exact attributes used. Performance evaluation We provide a comprehensive assessment of both theoretical complexity and empirical performance. All benchmarks are conducted on a Windows 10 workstation equipped with an AMD Ryzen 5 4600H (3.0 GHz, 6 cores, 16 GB RAM). The implementation is written in Python 3.10 on top of the open-source hggm library 43 . Analytical comparison Table 2 summarises the dominant cryptographic operations for each phase, where : scalar multiplication in , : scalar multiplication in , : scalar multiplication in , : bilinear pairing, : exponentiation in , : hash-to-point on the elliptic curve. Table 2. Asymptotic complexity comparison. Scheme KeyGen Sign Verify Chow et al. 40 Peng et al. 41 Xie et al. 42 Our scheme Open in a new tab To evaluate the proposed scheme against the most current standards, we compare our method with Peng et al. 41 , which represents the typical SM9 construction, and Xie et al. 42 , a recently published (2025) state-of-the-art optimization for SM9 ring signatures. As shown in Table 2 , compared with the latest SOTA 42 , our proposed scheme eliminates one fixed-base exponentiation in and reduces scalar multiplications by approximately 30%. Experimental results Setup and methodology We instantiate the proposed scheme, Peng et al. 41 , and Xie et al. 42 in Python using the hggm library 43 . Each measurement is the mean of 50 independent executions. Latency measurements Table 3 reports the average running time (ms) for ring sizes .The results substantiate the theoretical efficiency gains derived in the previous section. Table 3. Measured running time (ms). Scheme Phase 4 16 64 256 1024 Peng et al. 41 Sign 109.46 413.08 1680.76 6720.69 27318.90 Xie et al. 42 Sign 46.17 188.98 761.19 3034.18 12391.90 Our Scheme Sign 28.75 122.75 508.64 2037.94 8087.21 Peng et al. 41 Verify 114.07 408.46 1641.07 6519.69 26419.37 Xie et al. 42 Verify 196.82 303.20 874.67 3179.10 12463.80 Our Scheme Verify 160.40 332.13 882.94 3151.35 12264.77 Open in a new tab Signature Generation (Client-Side Efficiency): As illustrated in Fig. 2 , the signature generation time for all three schemes grows linearly with the ring size n . However, the growth rate (slope) of the proposed scheme is significantly lower than that of the baselines. Comparison with Standard Scheme (Peng et al. 41 ): Our scheme achieves a consistent speedup. At , our generation time is 8.08s compared to 27.31s, resulting in a speedup factor of approximately 3.43 x. Comparison with SOTA (Xie et al. 42 ): Even against the most recent optimized scheme published in 2025, our approach maintains a clear advantage. Xie et al. requires 12.39s for , whereas our scheme requires only 8.08s, yielding a speedup of 1.53 x. Underlying Cause of Improvement: This performance gap is directly attributable to the algebraic optimizations detailed in Table 2 . Operations in the multiplicative group are significantly more expensive than those in the additive group . By eliminating one fixed-base exponentiation in and reducing the coefficient of scalar multiplications from 2 n (in Xie et al.) to n (in our scheme), the computational burden increases much more slowly as the ring size expands. This makes the proposed scheme particularly suitable for resource-constrained devices (e.g., mobile phones or IoT sensors) in decentralized identity systems. versus the most recent optimized scheme by Xie et al. 42 when .This confirms that our scheme outperforms both the standard implementation 41 and the latest published optimization 42 . Figure 2. Open in a new tab Relative speed-up of the proposed scheme over Peng et al. 41 and Xie et al. 42 . Verification (Server-Side Efficiency): Regarding verification (Table 3 , bottom rows), our scheme performs comparably to the baselines. For , our verification time (12.26s) is almost identical to Xie et al. (12.46s). This behavior is expected because verification in SM9-based ring signatures is dominated by bilinear pairing operations ( ) and the reconstruction of the pairing product chain, which are structurally similar across all valid constructions. In a Zero-Trust architecture, verification is typically performed by high-performance policy engines or gateways rather than end-users. Therefore, maintaining standard verification costs while significantly reducing client-side signing latency represents an optimal trade-off for real-world deployment. Conclusion of Experiments: The empirical data confirms that while retaining the strong security properties of SM9, the proposed scheme successfully mitigates the “signature bloat” issue common in ring signatures. The scalability trends in Fig. 2 demonstrate that as the network size (ring size) increases, the efficiency advantage of our scheme becomes increasingly pronounced. Discussion The empirical speed-up is attributed to aggressive pre-computation of fixed-base exponentiations in and a reduced scalar multiplication count. Since signers are typically resource-constrained clients whereas verifiers are servers, the improvement in signing latency offers practical value. Future work will explore constant-size signatures independent of ring cardinality. Conclusion In this paper, we designed a multi-authority attribute ring signature scheme with the dynamic attribute composition and dual anonymity, which are very useful to satisfy important authentication needs for the zero trust networks based on DID systems. Under the framework of SM9 and with combination of the methods from ring signature and attribute-based crypto systems, it lets several authorities distribute attribute keys independently, and granters can sign for the their identity without leaking identity or attribute information to anyone and users can flexibly select the form of their attributes to meet verification rules of the verifiers. We prove that our scheme is EUF-CMIAA and that it provides full anonymity of both signer and attribute with respect to a random oracle model. Empirical performance evaluations validate the computational cost reduction, and reveal a 30 percentage decrease in the number of exponentiations and scalar multiplications during signing operation with respect to the state-of-the-art SM9-based ring signature scheme, which is tailored to the resource-limited clients participating in distributed and DID-based environments. Nevertheless, the current construction inherits linear growth in signature size and verification time relative to the number of ring members and attributes. Future work will focus on designing a constant-size attribute ring signature that maintains security guarantees while eliminating scalability limitations. Incorporating these will make our approach more feasible to employ in the big scale zero-trust system where access control is dynamic, and data is distributed. Author contributions X.Z. determined the research direction and formulated the research plan for the paper. J.C. constructed the proposed model, completed the simulation experiments. J.W. verified the accuracy of the charts and conclusions. W.F. analysed the results. Y.M. drafted the manuscript and proofread the format. All authors discussed the entire research process, verified the conclusions, reviewed the manuscript, and approved its submission. Funding This work was supported by National Natural Science Foundation of China (Grant No. 62276273) Science and Technology Research Project of Jiangxi Provincial Department of Education (Grant No.GJJ2405006). Data availability Data is provided within the manuscript. Declarations Competing interests The authors declare no competing interests. Footnotes Publisher’s note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations. References 1. Sanaei, Z., Abolfazli, S., Gani, A. & Buyya, R. Heterogeneity in mobile cloud computing: Taxonomy and open challenges. IEEE Commun. Surveys Tutor. 16 , 369–392. 10.1109/SURV.2013.050113.00090 (2014). [ Google Scholar ] 2. Azodolmolky, S., Wieder, P. & Yahyapour, R. Cloud computing networking: challenges and opportunities for innovations. IEEE Commun. Mag. 51 , 54–62. 10.1109/MCOM.2013.6553678 (2013). [ Google Scholar ] 3. Lyu, G. Data-driven decision making in patient management: a systematic review. BMC Med. Inform. Decis. Mak. 25 , 239. 10.1186/s12911-025-03072-x (2025). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 4. Chen, B. et al. A security awareness and protection system for 5g smart healthcare based on zero-trust architecture. IEEE Internet Things J. 8 , 10248–10263. 10.1109/JIOT.2020.3041042 (2021). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 5. Spencer, M. & Pizio, D. The de-perimeterisation of information security: The jericho forum, zero trust, and narrativity. Soc. Stud. Sci. 54 , 655–677. 10.1177/03063127231221107 (2024) ( PMID: 38152872 ). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 6. Guo, X. et al. An intelligent zero trust secure framework for software defined networking. PeerJ Comput. Sci. 9 , e1674. 10.7717/peerj-cs.1674 (2023). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 7. Rosenberg, M., White, J., Garman, C. et al. zk-creds: Flexible anonymous credentials from zksnarks and existing identity infrastructure. In Proc. 2023 IEEE Symposium on Security and Privacy (SP) 790–808, 10.1109/SP46215.2023.10179430 (2023). 8. Yan, Z. et al. Blockchain-driven decentralized identity management: An interdisciplinary review and research agenda. Information Management , 104026. 10.1016/j.im.2024.104026 (2024). 9. Ahmadi, S. Distributed identity for zero trust and segmented access control: A novel approach to securing network infrastructure. arXiv preprint arXiv:2501.09032 , 10.48550/arXiv.2501.09032 (2025). 10. Nie, S. et al. Zero-trust access control mechanism based on blockchain and inner-product encryption in the internet of things in a 6g environment. Sensors 25 , 550. 10.3390/s25020550 (2025). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 11. Reed, D., Sporny, M., Longley, D. et al. Decentralized identifiers (dids) v1.0. W3C Draft Community Group Report (2020). Accessed: 2025–05-11. 12. Maji, H. K., Prabhakaran, M. & Rosulek, M. Attribute-based signatures. In Topics in Cryptology – CT-RSA 2011 , vol. 6558 of Lecture Notes in Computer Science , 376–392, 10.1007/978-3-642-19074-2_24 (Springer, Berlin, Heidelberg, 2011). 13. Ling, S., Nguyen, K., Phan, D. H. et al. Fully dynamic attribute-based signatures for circuits from codes. Proc. International Conference on Public-Key Cryptography (PKC) 37–73, 2024, 10.1007/978-3-031-57718-5_2. 14. Li, J. & Kim, K. Attribute-based ring signatures. IACR Cryptol. ePrint Arch. (2008). Report 2008/394. 15. Guo, Z., Li, M. & Fan, X. Attribute-based ring signcryption scheme. Secur. Commun. Netw. 6 , 790–796. 10.1002/sec.614 (2013). [ Google Scholar ] 16. Toluee, R., Asaar, M. R. & Salmasizadeh, M. Attribute-based ring signatures: Security analysis and a new construction. In Proc. 10th International ISC Conference on Information Security and Cryptology (ISCISC) , 1–6, 10.1109/ISCISC.2013.6767342 (IEEE, Piscataway, NJ, USA, 2013). 17. Li, J., Au, M. H., Susilo, W. et al. Attribute-based signature and its applications. Proc. 5th ACM Symposium on Information, Computer and Communications Security (ASIACCS) 60–69, 2010, 10.1145/1755688.1755697. 18. Herranz, J., Laguillaumie, F., Libert, B. & Ràfols, C. Short attribute-based signatures for threshold predicates. In Topics in Cryptology – CT-RSA 2012 , vol. 7178 of Lecture Notes in Computer Science , 51–67, 10.1007/978-3-642-27954-6_4 (Springer, Berlin, Heidelberg, 2012). 19. Okamoto, T. & Takashima, K. Decentralized attribute-based signatures. Proc. International Workshop on Public Key Cryptography (PKC) 125–142, 2013, 10.1007/978-3-642-36362-7_9. 20. Okamoto, T. & Takashima, K. Efficient attribute-based signatures for non-monotone predicates in the standard model. IEEE Trans. Cloud Comput. 2 , 409–421. 10.1109/TCC.2014.2346754 (2014). [ Google Scholar ] 21. Guo, R. et al. Secure attribute-based signature scheme with multiple authorities for blockchain in electronic health records systems. IEEE Access 6 , 11676–11686. 10.1109/ACCESS.2018.2801266 (2018). [ Google Scholar ] 22. Hou, S., Yang, S. & Lin, C. Attribute-based designated combiner transitive signature scheme. Mathematics 12 , 3070. 10.3390/math12193070 (2024). [ Google Scholar ] 23. Ma, R. & Du, L. Attribute-based blind signature scheme based on elliptic curve cryptography. IEEE Access 10 , 34221–34227. 10.1109/ACCESS.2022.3162231 (2022). [ Google Scholar ] 24. Ma, R. & Du, L. Efficient attribute-based strong designated verifier signature scheme based on elliptic curve cryptography. PLoS ONE 19 , e0300153. 10.1371/journal.pone.0300153 (2024). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 25. Zhang, Z. et al. An efficient reusable attribute-based signature scheme for mobile services with multi-access policies in fog computing. Comput. Commun. 196 , 9–22. 10.1016/j.comcom.2022.09.017 (2022). [ Google Scholar ] 26. Zhang, Y., Zhao, J., Zhu, Z. et al. Registered attribute-based signature. In Public-Key Cryptography – PKC 2024 , vol. 14601 of Lecture Notes in Computer Science , 133–162, 10.1007/978-3-031-57718-5_5 (Springer, Cham, 2024). 27. Wu, Y. T. et al. Efficient and provably secured puncturable attribute-based signature for web 3.0. Futur. Gener. Comput. Syst. 164 , 107568. 10.1016/j.future.2024.107568 (2025). [ Google Scholar ] 28. Guo, C., Lu, Y., Xia, N. et al. User-friendly and expressive forward-secure attribute-based signature with server-aided signature and outsourced verification. IEEE Trans. Knowl. Data Eng. . 10.1109/TKDE.2025.3554973 (2025). In press. 29. He, L., Gan, Y. & Yin, Y. Efficient threshold attribute-based signature scheme for unmanned aerial vehicle networks. Electronics 14 , 339. 10.3390/electronics14020339 (2025). [ Google Scholar ] 30. Tao, Q., Cui, X. & Iftekhar, A. A novel lightweight decentralized attribute-based signature scheme for social co-governance. Inf. Sci. 654 , 119839. 10.1016/j.ins.2023.119839 (2024). [ Google Scholar ] 31. Kang, Z., Li, J., Zuo, Y. et al. OABS: Efficient outsourced attribute-based signature scheme with constant-size. IEEE Internet Things J. 10.1109/JIOT.2024.3444827 (2024). In press. 32. Gardham, D. & Manulis, M. Revocable hierarchical attribute-based signatures from lattices. In Applied Cryptography and Network Security – ACNS 2022 , vol. 13269 of Lecture Notes in Computer Science , 459–479, 10.1007/978-3-031-09234-3_23 (Springer, Cham, 2022). 33. Luo, F. & Al-Kuwari, S. Attribute-based signatures from lattices: Unbounded attributes and semi-adaptive security. Des. Codes Crypt. 90 , 1157–1177. 10.1007/s10623-022-01027-1 (2022). [ Google Scholar ] 34. Liu, L. et al. A revocable and comparable attribute-based signature scheme from lattices for IoMT. J. Syst. Architect. 154 , 103222. 10.1016/j.sysarc.2024.103222 (2024). [ Google Scholar ] 35. State Cryptography Administration. Identity-based cryptographic algorithms SM9. GM/T 0003–2016 (2016). Beijing, China. 36. Lai, J. C. et al. Security analysis of SM9 digital signature and key encapsulation. Sci. Sin. Inf. 51 , 1900–1913. 10.1360/SSI-2021-0049 (2021). [ Google Scholar ] 37. Tang, F., Ling, G. & Shan, J. Traceable attribute signature scheme based on domestic cryptographic SM9 algorithm. J. Electron. Inf. Technol. 44 , 3610–3617. 10.11999/JEIT210747 (2022). [ Google Scholar ] 38. Zhu, L. et al. Attribute-based online/offline signature scheme based on SM9. J. Comput. Res. Dev. 60 , 362–370. 10.7544/issn1000-1239.202220530 (2023). [ Google Scholar ] 39. Zhou, Q., Chen, M., Wei, K. & Zheng, Y. Traceable attribute-based signature for SM9-based support policy hidden. J. Comput. Res. Dev. 62 , 1065–1074. 10.7544/issn1000-1239.202330744 (2025). [ Google Scholar ] 40. Chow, S. S. M., Yiu, S. M. & Hui, L. C. K. Efficient identity based ring signature. Proc. Applied Cryptography and Network Security (ACNS) 499–512, 2005, 10.1007/11496137_34. 41. Peng, C., He, D., Luo, M., Huang, X. & Li, D. An identity-based ring signature scheme for SM9 algorithm. J. Cryptol. Res. 8 , 724–734. 10.13868/j.cnki.jcr.000473 (2021). [ Google Scholar ] 42. Xie, Z., Zhang, Y., Yang, Q. & Song, E. Ring signature scheme based on domestic cryptographic algorithm sm9, 10.11896/jsjkx.241000072 (2025). 43. Basddsa. hggm — domestic cryptographic algorithm SM2/SM3/SM4/SM9/ZUC — complete source code for Python implementation. https://gitee.com/basddsa/hggm . Accessed: 2025–05-11. Associated Data This section collects any data citations, data availability statements, or supplementary materials included in this article. Data Availability Statement Data is provided within the manuscript. Articles from Scientific Reports are provided here courtesy of Nature Publishing Group ACTIONS View on publisher site PDF (2.9 MB) Cite Collections Permalink PERMALINK Copy RESOURCES Similar articles Cited by other articles Links to NCBI Databases Cite Copy Download .nbib .nbib Format: AMA APA MLA NLM Add to Collections Create a new collection Add to an existing collection Name your collection * Choose a collection Unable to load your collection due to an error Please try again Add Cancel Follow NCBI NCBI on X (formerly known as Twitter) NCBI on Facebook NCBI on LinkedIn NCBI on GitHub NCBI RSS feed Connect with NLM NLM on X (formerly known as Twitter) NLM on Facebook NLM on YouTube National Library of Medicine 8600 Rockville Pike Bethesda, MD 20894 Web Policies FOIA HHS Vulnerability Disclosure Help Accessibility Careers NLM NIH HHS USA.gov Back to Top

Record · ID 1192 · SHA-256 2845bb741416d20a
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.