Author Login Chief Editor Login Reviewer Login Editor Login Remote Office

Computer Engineering ›› 2026, Vol. 52 ›› Issue (9): 265-281. doi: 10.19678/j.issn.1000-3428.0260093

• Cyberspace Security • Previous Articles     Next Articles

Post-Quantum Lightweight Certificateless Hybrid Signcryption Scheme for Time-Series Data Sharing

CHENG Guanjie1,*(), SU Taolong2, HUANG Junqin3, KONG Linghe3   

  1. 1. School of Software Technology, Zhejiang University, Ningbo 315000, Zhejiang, China
    2. School of Computer Science and Technology, Zhejiang University, Hangzhou 310000, Zhejiang, China
    3. School of Computer Science, Shanghai Jiao Tong University, Shanghai 200240, China
  • Received:2026-01-19 Revised:2026-03-18 Online:2026-09-15 Published:2026-07-22
  • Contact: CHENG Guanjie

面向时序数据共享的后量子轻量化无证书混合签密方案

程冠杰1,*(), 苏韬龙2, 黄俊钦3, 孔令和3   

  1. 1. 浙江大学软件学院, 浙江 宁波 315000
    2. 浙江大学计算机科学与技术学院, 浙江 杭州 310000
    3. 上海交通大学计算机学院, 上海 200240
  • 通讯作者: 程冠杰
  • 作者简介:

    程冠杰, 男, 研究员、博士, 主研方向为数据安全、多智能体协同

    苏韬龙, 硕士

    黄俊钦, 助理教授、博士

    孔令和, 教授、博士

  • 基金资助:
    国家自然科学基金青年科学基金项目(62502446); 宁波市甬江人才工程(2024A-402-G)

Abstract:

The demand for continuous time-series data sharing in Internet of Things (IoT) scenarios has been increasing. Traditional Certificateless Signcryption (CLSC) schemes based on bilinear pairings or elliptic curves offer limited security under quantum computing threats and incur high computational and communication overheads when repeatedly signcrypting multiple data segments. To address these issues, this paper proposes a post-quantum lightweight certificateless hybrid signcryption scheme tailored for time-series data sharing. First, a bidirectional hash chain-driven symmetric key generation and management mechanism is designed to enable rapid key generation for multiple consecutive data segments while ensuring forward and backward security. Subsequently, a lightweight hybrid signcryption scheme with conditional privacy protection is constructed using a module lattice framework. Combined with an offline/online separation that shifts part of the computation ahead of time, the scheme achieves post-quantum security while significantly reducing the burden on end devices and communication links. The scheme is proven to satisfy IND-CCA confidentiality and EUF-CMA unforgeability in a random oracle model. Prototype implementation and evaluation on resource-constrained terminal devices show that, the proposed scheme achieves significant advantages: on average, the end-side overall latency and transmission volume can be reduced to approximately 40% of those of comparable post-quantum schemes. The advantages of this scheme become even more pronounced in long-duration continuous time-series data scenarios. It effectively balances post-quantum security, lightweight design, and scalability, making it well-suited for time-series data sharing applications in next-generation intelligent IoT.

Key words: Internet of Things (IoT), time-series data sharing, certificateless signcryption, post-quantum cryptography, key generation

摘要:

面向物联网(IoT)场景中海量、连续的时序数据共享需求, 传统基于双线性映射或椭圆曲线的无证书签密(CLSC)方案在量子计算威胁下安全性受限, 且在多段数据的重复签密中引入了较高的计算与通信开销。为此, 提出一种面向时序数据共享的后量子轻量化无证书混合签密方案。首先, 设计双向哈希链驱动的对称密钥生成与管理机制, 实现多段连续数据的密钥快速生成与前向/后向安全; 然后, 在模块格框架下构建条件隐私保护的轻量化混合签密体制, 并结合离线/在线分离将部分计算前移, 在实现后量子安全的同时显著降低端侧与链路负担。在随机预言机模型下证明了该方案满足IND-CCA机密性与EUF-CMA不可伪造性。在资源受限的终端设备上开展原型实现与评测, 对比实验结果显示, 该方案相较代表性对比方案具有显著优势, 端侧整体时延与传输体量平均可降至同类后量子方案的40%左右。在长时段、连续时序数据场景下, 该方案优势将进一步扩大, 其能兼顾后量子安全、轻量化与可扩展性要求, 适用于新一代智能IoT中的时序数据共享应用。

关键词: 物联网, 时序数据共享, 无证书签密, 后量子密码, 密钥生成