Post-Quantum Revocable Linkable Ring Signature Scheme Based on SPHINCS+ for V2G Scenarios
Abstract
1. Introduction
1.1. Related Work
1.2. Contributions
1.3. Structure
2. Preliminaries
2.1. Linkable and Revocable Ring Signature
2.2. WOTS+
2.3. FORS
2.4. SPHINCS+
2.4.1. XMSS
2.4.2. Hypertree
3. SPHINCS+ Linkable and Revocable Ring Signature Scheme
3.1. Description of the Scheme’s Signature Algorithm
3.2. Application of the Scheme in Vehicle-to-Grid (V2G) Networks
4. Security Analysis
4.1. Security Assumptions
4.2. Core Theorem Proofs
to simulate the random oracle of SHA-256 and side-channel characteristics, maintaining a query table , where x includes hash inputs such as cm and , and is a uniform random value , ensuring the same x corresponds to the same and different x correspond to independent random values. For side-channel queries,
generates random power consumption and time data consistent with the statistical characteristics of real signatures (with mean and variance differences ). When generating ,
uses hash values from T for both pseudo-signatures of non-target members and real signatures of the target signer, with pseudo-signatures having an authentication path length of and hash distribution calibrated to and , maintaining complete structural consistency with real signatures. Due to the pseudorandomness of the random oracle and the indistinguishability of side-channel characteristics, the hash distributions and physical attributes of pseudo-signatures and real signatures are polynomially indistinguishable, meaning that for any PPT adversary , there exists a negligible function such that . Let , then , so , indicating that ’s identity tracing attack is ineffective and the scheme satisfies strong anonymity. □
to break the collision resistance of SHA-256 using ’s forgery capability.
selects a target ring member index , sets (where z is an unknown preimage and
aims to find z), replaces the XMSS tree root of with y, generates other public keys normally, and sends them to ; for queries from involving ,
simulates the XMSS root with y without requiring and generates pseudo-signatures through the random oracle to ensure structural consistency, even simulating the tampering behavior of to maintain the validity of query responses. If outputs a forged signature containing , the authentication path of must satisfy XMSS verification logic—hashing layer by layer from to finally reconstruct .
extracts intermediate nodes (where ) from and computes , and if is valid, , at which point , and the real and correspond to different paths but have the same hash value, meaning
finds a collision of SHA-256. By the collision resistance of SHA-256, Pr[Coll(
)] ≤ negl(λ), and since the probability that selects as the forgery target is (where n is the ring size, polynomially bounded), we have Pr[Coll(
)] . Indicating that the forgery attacks by and have negligible advantages and the scheme satisfies unforgeability. □
to break the preimage resistance of SHA-256 using .
first executes the public key generation process of SPHINCS+: It randomly generates PK.seed, iterates through the WOTS+ hash chain (where F is the chain iteration function of SHA-256 and ADRS is the address parameter), generates WOTS+ public key elements, obtains (with ) through XMSS tree hashing, and sends the public key and a randomly constructed ring to . During the attack phase, may launch quantum side-channel attacks to obtain physical characteristic information of on-board terminals, then outputs a forged signature , where contains private key fragments and authentication paths of FORS subtrees, is the WOTS+ signature hash chain, and auth is the XMSS tree authentication path.
extracts the i-th signature node from (where is the message segment value). According to the WOTS+ verification logic, if is valid, (i.e., the i-th element of ) must be obtained by iterating times from , i.e., , meaning finds (the preimage of ), contradicting Assumption 1, so .4.3. Formal Adversary Model
4.4. Risk Analysis
5. Performance Analysis
Performance Evaluation
6. Conclusions and Future Work
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- International Energy Agency (IEA) Global EV Outlook 2025. [EB/OL]. 2025. Available online: https://www.iea.org/reports/global-ev-outlook-2025?language=de (accessed on 30 November 2025).
- Kennel, F.; Görges, D.; Liu, S. Energy management for smart grids with electric vehicles based on hierarchical MPC. IEEE Trans. Ind. Inform. 2013, 9, 1528–1537. [Google Scholar] [CrossRef] [Scilit]
- Yong, J.Y.; Ramachandaramurthy, V.K.; Tan, K.M.; Mithulananthan, N. A review on the state-of-the-art technologies of electric vehicle, its impacts and prospects. Renew. Sustain. Energy Rev. 2015, 49, 365–385. [Google Scholar] [CrossRef] [Scilit]
- Hassija, V.; Chamola, V.; Garg, S.; Krishna, D.N.G.; Kaddoum, G.; Jayakody, D.N.K. A blockchain-based framework for lightweight data sharing and energy trading in V2G network. IEEE Trans. Veh. Technol. 2020, 69, 5799–5812. [Google Scholar] [CrossRef] [Scilit]
- Liu, Y.; Guo, W.; Fan, C.I.; Chang, L.; Cheng, C. A practical privacy-preserving data aggregation (3PDA) scheme for smart grid. IEEE Trans. Ind. Inform. 2019, 15, 1767–1774. [Google Scholar] [CrossRef] [Scilit]
- Gao, F.; Zhu, L.; Shen, M.; Sharif, K.; Wan, Z.; Ren, K. A blockchain-based privacy-preserving payment mechanism for vehicle-to-grid networks. IEEE Netw. 2018, 32, 184–192. [Google Scholar] [CrossRef] [Scilit]
- Gabay, D.; Akkaya, K.; Cebe, M. Privacy-preserving authentication scheme for connected electric vehicles using blockchain and zero knowledge proofs. IEEE Trans. Veh. Technol. 2020, 69, 5760–5772. [Google Scholar] [CrossRef] [Scilit]
- Wang, L.; Xie, J.; Liu, S. Research progress and prospects of ring signature technology. J. Front. Comput. Sci. Technol. 2023, 17, 985–1001. [Google Scholar] [CrossRef]
- Liu, Y.; He, D.; Bao, Z.; Wang, H.; Khan, M.K.; Choo, K.K.R. An Efficient Multilayered Linkable Ring Signature Scheme With Logarithmic Size for Anonymous Payment in Vehicle-to-Grid Networks. IEEE Trans. Intell. Veh. 2023, 8, 2998–3011. [Google Scholar] [CrossRef] [Scilit]
- Xu, S.; Wang, T.; Sun, A.; Tong, Y.; Ren, Z.; Zhu, R.; Song, H.H. Post-Quantum Anonymous, Traceable and Linkable Authentication Scheme Based on Blockchain for Intelligent Vehicular Transportation Systems. IEEE Trans. Intell. Transp. Syst. 2024, 25, 12108–12119. [Google Scholar] [CrossRef] [Scilit]
- Liu, J.K.; Wei, V.K.; Wong, D.S. Linkable spontaneous anonymous group signature for ad hoc groups. In Proceedings of the Australasian Conference on Information Security and Privacy, Sydney, Australia, 13–15 July 2004; pp. 325–335. [Google Scholar]
- Deutsch, D. Quantum theory, the Church–Turing principle and the universal quantum computer. Proc. R. Soc. Lond. A Math. Phys. Sci. 1985, 400, 97–117. [Google Scholar] [CrossRef] [Scilit]
- Bernstein, D.J.; Hülsing, A.; Kölbl, S.; Niederhagen, R.; Rijneveld, J.; Schwabe, P. The SPHINCS+ signature framework. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, London, UK, 11–15 November 2019; pp. 2129–2146. [Google Scholar]
- Hülsing, A. W-OTS+–shorter signatures for hash-based signature schemes. In Proceedings of the Progress in Cryptology–AFRICACRYPT 2013: 6th International Conference on Cryptology in Africa, Cairo, Egypt, 22–24 June 2013; Springer: Berlin/Heidelberg, Germany, 2013; pp. 173–188. [Google Scholar]
- Yehia, M.; Altawy, R.; Gulliver, T.A. Hash-Based Signatures Revisited: A Dynamic FORS with Adaptive Chosen Message Security. In Cryptology ePrint Archive, Proceedings of the 12th International Conference on Cryptology in Africa, Cairo, Egypt, 20–22 July 2020; [EB/OL]; Springer: Cham, Switzerland, 2020. [Google Scholar]
- Zhang, K.; Cui, H.; Yu, Y. Revisiting the constant-sum Winternitz one-time signature with applications to SPHINCS+ and XMSS. In Proceedings of the Annual International Cryptology Conference, Santa Barbara, CA, USA, 19–24 August 2023; Springer: Berlin/Heidelberg, Germany, 2023; pp. 455–483. [Google Scholar]
- Yang, Z.; Yu, S.; Lou, W.; Liu, C. P2: Privacy-preserving communication and precise reward architecture for V2G networks in smart grid. IEEE Trans. Smart Grid 2011, 2, 697–706. [Google Scholar] [CrossRef] [Scilit]
- Wang, H.; Qin, B.; Wu, Q.; Xu, L.; Domingo-Ferrer, J. TPP: Traceable privacy-preserving communication and precise reward for vehicle-to-grid networks in smart grids. IEEE Trans. Inf. Forensics Secur. 2015, 10, 2340–2351. [Google Scholar] [CrossRef] [Scilit]
- Liu, H.; Ning, H.; Zhang, Y.; Xiong, Q.; Yang, L.T. Role-dependent privacy preservation for secure V2G networks in the smart grid. IEEE Trans. Inf. Forensics Secur. 2014, 9, 208–220. [Google Scholar] [CrossRef] [Scilit]
- Gope, P.; Sikdar, B. An efficient privacy-preserving authentication scheme for energy internet-based vehicle-to-grid communication. IEEE Trans. Smart Grid 2019, 10, 6607–6618. [Google Scholar] [CrossRef] [Scilit]
- Aggarwal, S.; Kumar, N.; Gope, P. An efficient blockchain-based authentication scheme for energy-trading in V2G networks. IEEE Trans. Ind. Inform. 2021, 17, 6971–6980. [Google Scholar] [CrossRef] [Scilit]
- Han, W.; Xiao, Y. Privacy preservation for V2G networks in smart grid: A survey. Comput. Commun. 2016, 91, 17–28. [Google Scholar] [CrossRef] [Scilit]
- Liu, J.K.; Au, M.H.; Susilo, W.; Zhou, J. Enhancing location privacy for electric vehicles (at the right time). In Proceedings of the European Symposium on Research in Computer Security, Pisa, Italy, 10–12 September 2012; pp. 397–414. [Google Scholar]
- Au, M.H.; Liu, J.K.; Fang, J.; Jiang, Z.L.; Susilo, W.; Zhou, J. A new payment system for enhancing location privacy of electric vehicles. IEEE Trans. Veh. Technol. 2014, 63, 3–18. [Google Scholar] [CrossRef] [Scilit]
- Chatterjee, R.; Chung, K.M.; Liang, X.; Malavolta, G. A note on the post-quantum security of (ring) signatures. In Proceedings of the IACR International Conference on Public-Key Cryptography, Virtual, 8–11 March 2022; Springer: Berlin/Heidelberg, Germany, 2022; pp. 407–436. [Google Scholar]
- Xue, Y.; Lu, X.; Au, M.H.; Zhang, C. Efficient linkable ring signatures: New framework and post-quantum instantiations. In Proceedings of the European Symposium on Research in Computer Security, Bydgoszcz, Poland, 16–20 September 2024; Springer: Berlin/Heidelberg, Germany, 2024; pp. 435–456. [Google Scholar]
- Haque, A.; Scafuro, A. Threshold ring signatures: New definitions and post-quantum security. In Proceedings of the Public-Key Cryptography–PKC 2020: 23rd IACR International Conference on Practice and Theory of Public-Key Cryptography, Edinburgh, UK, 4–7 May 2020; Part II 23. Springer: Berlin/Heidelberg, Germany, 2020; pp. 423–452. [Google Scholar]
- Buser, M.; Liu, J.K.; Steinfeld, R.; Sakzad, A. Post-quantum id-based ring signatures from symmetric-key primitives. In Proceedings of the International Conference on Applied Cryptography and Network Security, Rome, Italy, 20–23 June 2022; Springer: Berlin/Heidelberg, Germany, 2022; pp. 892–912. [Google Scholar]
- Odoom, J.; Huang, X.; Zhou, Z.; Danso, S.; Zheng, J.; Xiang, Y. Linked or unlinked: A systematic review of linkable ring signature schemes. J. Syst. Archit. 2023, 134, 102786. [Google Scholar] [CrossRef] [Scilit]
- Aung, N.; Kechadi, T.; Zhu, T.; Zerdoumi, S.; Guerbouz, T.; Dhelim, S. Blockchain application on the internet of vehicles (iov). In Proceedings of the 2022 IEEE 7th International Conference on Intelligent Transportation Engineering (ICITE), Beijing, China, 11–13 November 2022; pp. 586–591. [Google Scholar]
- Zhang, H.; Liu, J.; Zhao, H.; Wang, P.; Kato, N. Blockchain-based trust management for internet of vehicles. IEEE Trans. Emerg. Top. Comput. 2020, 9, 1397–1409. [Google Scholar] [CrossRef] [Scilit]
- Labrador, M.; Hou, W. Implementing blockchain technology in the internet of vehicle (iov). In Proceedings of the 2019 International Conference on Intelligent Computing and Its Emerging Applications (ICIEA), Tainan, Taiwan, 30 August–1 September 2019; pp. 5–10. [Google Scholar]
- Liu, Y.; Xia, Q.; Li, X.; Gao, J.; Zhang, X. An authentication and signature scheme for uav-assisted vehicular ad hoc network providing anonymity. J. Syst. Archit. 2023, 142, 102935. [Google Scholar] [CrossRef] [Scilit]
- Feng, X.; Wang, X.; Cui, K.; Xie, Q.; Wang, L. A distributed message authentication scheme with reputation mechanism for internet of vehicles. J. Syst. Archit. 2023, 145, 103029. [Google Scholar] [CrossRef] [Scilit]
- Thapliyal, S.; Wazid, M.; Singh, D.P.; Das, A.K.; Islam, S.H. Robust authenticated key agreement protocol for internet of vehicles-envisioned intelligent transportation system. J. Syst. Archit. 2023, 142, 102937. [Google Scholar] [CrossRef] [Scilit]
- Verma, N.; Kumari, S.; Jain, P. Post quantum digital signature change in iot to reduce latency in internet of vehicles (iov) environments. In Proceedings of the 2022 International Conference on IoT and Blockchain Technology (ICBT), Ranchi, India, 6–8 May 2022; pp. 1–6. [Google Scholar]
- Zhang, X.; Cui, Y.; Cao, L. Privacy protection of internet of vehicles based on lattice-based ring signature. Chin. J. Comput. 2019, 42, 980–992. [Google Scholar]
- Castellon, C.; Roy, S.; Kreidl, P.; Dutta, A.; Bólóni, L. Energy efficient merkle trees for blockchains. In Proceedings of the 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Shenyang, China, 20–22 October 2021; pp. 1093–1099. [Google Scholar]
- Derler, D.; Ramacher, S.; Slamanig, D. Post-quantum zero-knowledge proofs for accumulators with applications to ring signatures from symmetric-key primitives. In Proceedings of the Post-Quantum Cryptography: 9th International Conference, PQCrypto 2018, Fort Lauderdale, FL, USA, 9–11 April 2018; Proceedings 9; Springer: Berlin/Heidelberg, Germany, 2018; pp. 419–440. [Google Scholar]
- Zhang, Y.; Tang, Y.; Li, C.; Dong, M.; Ota, K.; Huang, M.; Zhang, H. Privacy-Preserving for Blockchain-Enabled Cold-Chain Logistics System With IoV and Linkable Ring Signature. IEEE Trans. Veh. Technol. 2024, 73, 12585–12596. [Google Scholar] [CrossRef] [Scilit]
- Duan, J.; Zheng, S.; Wang, W.; Wang, L.; Hu, X.; Gu, L. Concise RingCT Protocol Based on Linkable Threshold Ring Signature. IEEE Trans. Dependable Secur. Comput. 2024, 21, 5014–5028. [Google Scholar] [CrossRef] [Scilit]
- Zhan, Q.; Luo, M.; Qiu, M. An Efficient Multimode Certificateless Ring Signcryption Scheme in VANETs. IEEE Internet Things J. 2024, 11, 33508–33524. [Google Scholar] [CrossRef] [Scilit]
- Chen, X.; Xu, S.; Gao, S.; Guo, Y.; Yiu, S.M.; Xiao, B. FS-LLRS: Lattice-Based Linkable Ring Signature With Forward Security for Cloud-Assisted Electronic Medical Records. IEEE Trans. Inf. Forensics Secur. 2024, 19, 8875–8891. [Google Scholar] [CrossRef] [Scilit]
- Gao, W.; Jin, S.; Wang, B.; Fu, T.; Ren, S.; Dong, X.; Qin, B. Logarithmic Certificate-Less Linkable Ring Signature Over Lattices and Application in Electronic Voting Systems. Comput. Stand. Interfaces 2026, 96, 104081. [Google Scholar] [CrossRef] [Scilit]
- Wu, T.; Wang, W.; Zhang, C.; Zhang, W.; Zhu, L.; Gai, K.; Wang, H. Blockchain-Based Anonymous Data Sharing With Accountability for Internet of Things. IEEE Internet Things J. 2023, 10, 5461–5475. [Google Scholar] [CrossRef] [Scilit]
- Liang, W.; You, L.; Hu, G. LRS_PKI: A Novel Blockchain-Based PKI Framework Using Linkable Ring Signatures. Comput. Netw. 2023, 237, 110043. [Google Scholar] [CrossRef] [Scilit]
- Wang, G.; Liu, Q.; Yu, Z.; Zhang, H.; Dong, A. BCE-PPDS: Blockchain-Based Cloud–Edge Collaborative Privacy-Preserving Data Sharing Scheme for IoT. Future Gener. Comput. Syst. 2026, 174, 107922. [Google Scholar] [CrossRef] [Scilit]
- Yadav, V.K. Anonymous and Linkable Ring Signcryption Scheme for Location-Based Services in VANETs. Veh. Commun. 2024, 45, 100717. [Google Scholar] [CrossRef] [Scilit]
- Hu, M.; Liu, Z.; Ren, X.; Zhou, Y. Linkable Ring Signature Scheme with Stronger Security Guarantees. Inf. Sci. 2024, 680, 121164. [Google Scholar] [CrossRef] [Scilit]
- Lin, K.; Sun, Q.; Wang, K.; Wang, J.; Ding, M.; Dong, Z.; Niu, Z. HRPACS: A Non-End-to-End Anonymous Communication System Based on Hybrid Routing Policies. IEEE Trans. Netw. 2025, 34, 1112–1127. [Google Scholar] [CrossRef] [Scilit]
- Xie, J.; Zhou, J.; Cao, Z.; Dong, X.; Choo, K.K.R. Linkable, k-Times Traceable, and Revocable Ring Signature for Fine-Grained Accountability in Blockchain Transactions. IEEE Internet Things J. 2025, 12, 4349–4361. [Google Scholar] [CrossRef] [Scilit]
- Chen, Y.; He, D.; Bao, Z.; Luo, M.; Choo, K.K.R. A Post-Quantum Privacy-Preserving Payment Protocol in Vehicle to Grid Networks. IEEE Trans. Intell. Veh. 2025, 10, 2349–2361. [Google Scholar] [CrossRef] [Scilit]

















| Symbol | Description |
|---|---|
| Security Parameter | |
| L | Ring Size (number of members in the ring) |
| Public–Private Key Pair | |
| Unique Revocation Identifier (bound to user for revocation operations) | |
| System Public Parameters (including RID generation rules) | |
| A ring consisting of | |
| M | Message Hash Digest |
| Message Space (the set of all valid messages corresponding to security parameter ) | |
| Linkable and Revocable Ring Signature | |
| I | Linking Tag (for identifying signatures from the same signer) |
| Valid/Invalid | Signature Verification Result |
| Linked/Unlinked | Link Detection Result |
| Revoked/Not Revoked | Revocation Operation Result |
| Scheme Type | Scheme Name |
|---|---|
| OTS | Lamport–Diffie, WOTS, WOTS+ |
| FTS | HORS, HORST-T, PORS, FORS |
| MTS | XMSS, SPHINCS, SPHINCS+ |
| Parameter | Description |
|---|---|
| Security parameter | |
| Winternitz parameter | |
| Number of message segments | |
| Number of checksum segments | |
| len | Total segments |
| PK.seed | Public seed for WOTS+ instance |
| Secret preimages | |
| F | Hash function chain iteration: |
| Address encoding chain index i and node index j | |
| PRF |
| Parameter | Description |
|---|---|
| Security parameter | |
| Number of independent FORS subtrees | |
| Exponent defining the height of each subtree | |
| Number of leaf nodes in each FORS subtree | |
| Public seed for FORS instance | |
| Secret preimage | |
| Array of secret preimages | |
| F | Hash function, |
| H | Hash function, |
| Hash function, | |
| ADRS | Address encoding structure for chain/index identification |
| Parameter | Description |
|---|---|
| Security parameter | |
| Overall depth of the SPHINCS+ hyperstructure | |
| Count of tiers within the hyperstructure | |
| Height of a single XMSS subtree | |
| Height of a FORS subtree | |
| Number of independent FORS subtrees | |
| Window size for WOTS+ | |
| Secret seed of the private key | |
| PRF seed of the private key | |
| H | |
| n | Number of ring members in the signature ring |
| Randomizer for hash commitment | |
| Linking tag | |
| Hash commitment value | |
| Merkle root of the ring | |
| Authentication path from the signer’s public key hash to | |
| Time window identifier (mapped from transaction timestamp) | |
| Linkage private key of user in time window t | |
| Random factor for forward-secure link tag | |
| Forward-secure linking tag (user , time window t) | |
| Address encoding of FORS tree for non-signer i | |
| System random seed for pseudo-signature | |
| Start timestamp of time window t | |
| User registration timestamp |
| Scheme | Sign | Verify | Keygen | Communication Overhead |
|---|---|---|---|---|
| AZALEA [52] | ||||
| Emularis [9] | ||||
| LK-TRS [51] | (take bit) | |||
| PQ-ATL [10] | (unit: bit) | |||
| CL-LRS [44] | (take , ) | |||
| BCE-PPDS [47] | (take ms) | (take ms) | (take ms) | |
| Ours |
| Scheme | Post-Quantum Security | Anony Mity | Linka Bility | Unforgea Bility | Non- Frameability | Stateless Ness | Revoca Bility |
|---|---|---|---|---|---|---|---|
| AZALEA [52] | Yes | Yes | Yes | Yes | Yes | No | No |
| Emularis [9] | No | Yes | Yes | Yes | Yes | No | No |
| BCE-PPDS [47] | No | Yes | Yes | Yes | Yes | No | No |
| CL-LRS [44] | Yes | Yes | Yes | Yes | Yes | No | No |
| LK-TRS [51] | No | Yes | Yes | Yes | Yes | No | Yes |
| PQ-ATL [10] | Yes | Yes | Yes | Yes | Yes | No | No |
| Ours | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Liu, S.; Du, Y.N.; Wang, X.A.; Hu, X.; Su, H.E. Post-Quantum Revocable Linkable Ring Signature Scheme Based on SPHINCS+ for V2G Scenarios. Sensors 2026, 26, 754. https://doi.org/10.3390/s26030754
Liu S, Du YN, Wang XA, Hu X, Su HE. Post-Quantum Revocable Linkable Ring Signature Scheme Based on SPHINCS+ for V2G Scenarios. Sensors. 2026; 26(3):754. https://doi.org/10.3390/s26030754
Chicago/Turabian StyleLiu, Shuanggen, Ya Nan Du, Xu An Wang, Xinyue Hu, and Hui En Su. 2026. "Post-Quantum Revocable Linkable Ring Signature Scheme Based on SPHINCS+ for V2G Scenarios" Sensors 26, no. 3: 754. https://doi.org/10.3390/s26030754
APA StyleLiu, S., Du, Y. N., Wang, X. A., Hu, X., & Su, H. E. (2026). Post-Quantum Revocable Linkable Ring Signature Scheme Based on SPHINCS+ for V2G Scenarios. Sensors, 26(3), 754. https://doi.org/10.3390/s26030754

