Bilinear-Pairing-Free Universal Designated Verifier Signatures for Private Access in Zero Trust Network

Xun Wang, Chao Lin, Wei Wu, Xu Yang, Yudi Zhang · IEEE Internet of Things Journal · 2025

Zero Trust networks provide an innovative cybersecurity architecture that effectively incorporates “never trust, always verify" principles to address traditional network security threats. Universal Designated Verifier Signature (UDVS) can protect the clients’ privacy in Zero Trust networks, preventing malicious gateways from leaking clients access information to third parties. However, existing UDVS schemes suffer from computational overhead due to their reliance on bilinear pairing operations. This paper primarily focuses on the general transformation method from Identity-Based Key Encapsulation Mechanism (ID-KEM) to UDVS proposed by Steinfeld et al. We first propose ID-KEM based on the SM2 algorithm and prove that it satisfies the EK and Separable properties required by the transformation. Then, we obtain the first UDVS scheme without bilinear pairing through transformation. In terms of performance analysis, the computational overhead of our scheme is 144.36 milliseconds, which is at least 74.39% lower than the previous UDVS schemes. The communication cost is 96 bytes, which is at least 88.89% lower than other schemes, including the first UDVSP scheme without bilinear pairing. To show the utility of our UDVS scheme, we finally apply it into a Zero Trust-based Software Defined Perimeter (SDP) environment, which reaps privacy-preserving authentication for single packet authorization.

Read the paper · More papers on PaperTik