A Two-Level Threshold Signature Method and Device for Hierarchical Management
Through the second-level threshold signature method designed by the elliptic curve cryptography system, the security and practicality of signatures in hierarchical management are solved, and safe and efficient signature compliance verification is achieved, which is suitable for cross-platform hierarchical management system.
Patent Information
- Application Number
- CN202310318480.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-28
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2043-03-28
AI Technical Summary
In the existing hierarchical management, threshold signatures have security and practical problems, which are difficult to effectively apply in cross-platform program development.
An elliptic curve cryptographic system is used to design a secondary threshold signature method. The trusted center generates subkeys for branch and department-level signatures through the trusted center, the signature organizer synthesizes and verifys the signature results, and the signature recipient performs final compliance verification to realize the secure signature under hierarchical management.
It improves the security and applicability of signatures, applies to the hierarchical management system, prevents excessive power from being a priority for superiors, and is easy to be industrialized.
Smart Images

Figure CN116318736B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of computer technology and information security, and particularly relates to a two-level threshold signature method and device for hierarchical management. Background Art
[0002] Common public key cryptosystems in modern cryptography mainly include: MH knapsack public key cryptosystem, RSA public key cryptosystem, ElGamal public key cryptosystem, and ECC public key cryptosystem. Under the same security level, the key amount required by elliptic curves is much smaller than that of the public key system for discrete logarithm problems over finite fields, thereby reducing the storage amount and improving the system efficiency. Therefore, the elliptic curve cryptosystem is more superior than other cryptosystems (such as RSA and DSA).
[0003] The public key cryptosystem can conveniently implement digital signatures, and digital signatures include ordinary digital signatures and special digital signatures. Ordinary digital signature algorithms include RSA, ElGamal, Fiat-Shamir, Schnorr, DES / DSA, elliptic curve digital signature algorithm, and finite automaton digital signature algorithm, etc. Special digital signatures include blind signatures, proxy signatures, group signatures, and threshold signatures. Among them, threshold signatures have the advantages of low cost, high security, high credibility, and high scalability. At the same time, companies and enterprises in various fields nowadays adopt a hierarchical management system. Therefore, a signature method suitable for hierarchical management is needed.
[0004] Therefore, designing a new scheme based on the elliptic curve cryptosystem and the threshold signature scheme not only has certain efficiency and high security, but also can promote the scheme to the hierarchical management systems in various fields for cross-platform program development, which has great practical value. Summary of the Invention
[0005] In view of this, the present invention provides a two-level threshold signature method and device for hierarchical management, which can solve the technical problems of security and practicability existing in threshold signatures in hierarchical management.
[0006] To solve the above technical problems, the present invention is implemented as follows.
[0007] A two-level threshold signature method for hierarchical management includes:
[0008] Step S1: Obtain the file M to be signed, and configure the roles participating in the signature. The roles participating in the signature include a trusted center D, a signature organizer C, signers, and signature receivers; the signers include branch-level signers and department-level signers;
[0009] Step S2: The trusted center D selects parameters for the file M to be signed, and generates respective corresponding sub-keys for each branch-level signer and each department-level signer;
[0010] Step S3: Select signers, where the signers include branch-level signers and department-level signers, and the signers are formed by some branch-level signers and some department-level signers; each signer uses their respective corresponding sub-key to sign the file M to be signed;
[0011] Step S4: The signature organizer C receives the signature results of each signer for the file M to be signed, and verifies their compliance; synthesizes the signature results that pass the verification, and uses the private key D of the signature organizer C itself c to sign the synthesized signature result to obtain the final signature result, and publishes the final signature result to the signature receiver;
[0012] Step S5: The signature receiver verifies the signature compliance of the signature organizer C based on the public key E of the signature organizer C c calculates the verification points, compares the verification points with the signature points obtained from the signature organizer C, and verifies the signature compliance of each signer.
[0013] Preferably, in step S1, the roles participating in the signature include the trusted center D, the signature organizer C, the signers, and the signature receiver, where:
[0014] All the department-level signers P i subordinate to the branch-level signer P i,j form the department-level signer group T i , and the correspondence between the branch-level signer P i and the department-level signer P i,j is: there are j department-level signers P i under the i-th branch-level signer P i,j ;
[0015] The trusted center D is used to select parameters for the file to be signed, calculate the private key d of the branch-level signer group P to obtain multiple sub-keys d i , and send each sub-key d i to the corresponding branch-level signer P i respectively; send each sub-key d i calculated based on the sub-key d of the branch-level signer P i to the corresponding department-level signer P i,j respectively; i,j ;
[0016] The signature organizer C receives the signature results of the signature personnel at the branch level and the signature personnel at the department level for the to-be-signed document M, and verifies its correctness; synthesizes the verified signature results, and uses the private key D of the signature organizer C itself c to sign the synthesized signature result to obtain the final signature result, and publishes the final signature result to the signature recipient. The signature organizer C is the only publisher of the group signature message;
[0017] The signer performs a threshold signature operation. The signers are divided into signature personnel at the branch level and signature personnel at the department level. Using the set P = {P1, P2,... P n} to represent the group of signature personnel at the branch level composed of n branch-level signers; using the set T i = {P i,1 , P i,2 ,..., P i,j} to represent the group of signature personnel at the department level composed of j department-level signers under the i-th branch signer, where 1 ≤ i ≤ n.
[0018] Preferably, the step S2 includes:
[0019] Step S21: Obtain the file attributes of the to-be-signed document;
[0020] Step S22: Based on the file attributes, the trusted center D determines the parameters, and the parameters include the finite field F q , F q on the elliptic curve E, the base point G of the elliptic curve E, the one-way hash function h(·), the to-be-signed document M, and the private key d of the group of signers P composed of branch-level signers, where:
[0021] Finite field F q : where q is a large prime number, given by the trusted center D;
[0022] F q on the elliptic curve E: The trusted center D selects two elements a and b in F q to generate the equation of E as y 2 = x 3 + ax + b. There is a unique infinite point on the elliptic curve, denoted as O, and x and y are the abscissa value and the ordinate value respectively;
[0023] The trusted center D selects the base point G of the elliptic curve such that G ∈ E(F q ), G ≠ O, and the order of the base point G is k, where k is a large prime number and satisfies kG = O, and E(F q ) is the elliptic curve E on F q ;
[0024] The file M to be signed, which is notified by the trusted center D to the signature organizer and given by the signature organizer;
[0025] The one-way hash function h(·), using the SM3 algorithm;
[0026] The private key d of the signer group P composed of branch-level signers is generated by a random number generator; the public key Q = dG ≠ O of the signer group P composed of company-level signers;
[0027] Step S23: Calculate the sub-key d based on the private key d of the branch-level signer group P i , and send the sub-key d i to the corresponding branch-level signer P i , and calculate the sub-key d i based on the sub-key d i,j , and send the sub-key d i,j to the corresponding department-level signer P i,j , including:
[0028] The trusted center D divides the private key d of the set P into n equal parts, calculates the sub-key d i , and sends the sub-key d i to the corresponding branch-level signer P i such that any subset composed of branch-level signers with a quantity greater than or equal to t can represent the group composed of all branch-level signers; the distribution process of sending the sub-key d i to the corresponding branch-level signer P i adopts the Shamir secret sharing system:
[0029] The trusted center D divides the private key d of P i into m i equal parts, calculates the sub-key d i based on the sub-key d i , and then distributes each sub-key d i,j to each member P i,j in T i such that, within the same branch, any subset composed of department-level signers with a quantity greater than or equal to s can represent the group composed of all department-level signers under that branch; the distribution process of distributing each sub-key d i,j to each member P i,j in T i adopts the Shamir secret sharing system. i,j
[0030] Preferably, in step S3: select signers, where the signers include branch - level signers and department - level signers, and the signers are formed by some branch - level signers and some department - level signers; each signer uses their respective sub - key to sign the file M to be signed, including:
[0031] Step S31: Select num branch - level signers from all branch - level signers. If num is greater than or equal to t, go to step S32; if num is less than t, determine t - num unselected branch - level signers, and for each of the t - num unselected branch - level signers, select s department - level signers from all their corresponding department signers. Denote the num branch - level signers as P1, P2, …, P u , where 1 < u ≤ num. Then denote the department - level signer replacing the l - th branch signer as P l,1 , P l,2 , …, P l,s , where u < l ≤ t, 1 ≤ s ≤ j, and go to step S32;
[0032] Step S32: For each department - level signer P l,w , where 1 ≤ w ≤ s: each department - level signer P l,w generates a random number k l,w to calculate the intermediate value W l,w = k l,w G and Q l,w = d l,w G, and sends W l,w and Q l,w to the signature organizer C;
[0033] For each branch - level signer P v , where 1 ≤ v ≤ u: each branch - level signer P v generates a random number k v to calculate the intermediate value W v = k v G and Q v = d v G, and sends W v and Q v to the signature organizer C;
[0034] For the signature organizer C: The signature organizer C calculates W l,w received from each department - level signer P l,w , and then combines W l received from each branch - level signer P v to calculate the signature point v Among which W z includes W v and W l Next, the signature organizer C calculates the value r = x (mod q) of the abscissa of the signature point and sends it to each signer;
[0035] Step S33: For each department-level signer P l,w : Each department-level signer P l,w signs the file M to be signed to obtain s l,w and sends it to the signature organizer C, that is
[0036] s l,w = k l,w + d l,w H(r|M)e w (mod q)
[0037] Among which, s l,j is the signature of the file M by the department-level signer P l,j , r is the value of the abscissa of the signature point, and H(r|M) is the hash value after concatenating the file M and the value r of the abscissa of the signature point,
[0038] For each branch-level signer P v : Each branch-level signer P v signs the file M to be signed to obtain s v and sends it to the signature organizer C, that is
[0039] s v = k v + d v H(r|M)b v (mod q)
[0040] Among which, H(r|M) is the hash value after concatenating the file M and the value r of the abscissa of the signature point,
[0041] Preferably, in step S4: The signature organizer C receives the signature results of each signer on the file M to be signed, verifies its compliance; synthesizes the signature results that pass the verification, and uses the private key D c of the signature organizer C itself to sign the synthesized signature result to obtain the final signature result, and publishes the final signature result to the signature receiver, including:
[0042] Step S41: For the signature of each department-level signer P l,w , the signature organizer C compares s l,w G - H(r|M)e w Q l,w with Wl,w Whether they are equal. If they are equal, the signature organizer C determines that the department-level signature person P l,w has a compliant signature and accepts it. If they are not equal, the signature organizer C ends the current signature process and the method ends;
[0043] Step S42: For each department-level signature person P v 's signature, the signature organizer C compares s v G - H(r|M)b v Q v with W v Whether they are equal. If they are equal, the signature organizer C determines that the branch-level signature person P v has a compliant signature and accepts it. If they are not equal, the signature organizer C ends the current signature process and the method ends;
[0044] Step S43: The signature organizer C synthesizes s through l ; The signature organizer C calculates where s z includes s v and s l ; The signature organizer C then signs (s, r) with its own private key D c , and after signing, they are respectively (s′, r′); The signature organizer C outputs (s, r, s′, t′, M) as the final signature of the file M to be signed.
[0045] Preferably, in step S5: The signature receiver verifies the signature compliance of the signature organizer C based on the public key E c of the signature organizer C, then calculates the verification point, and compares the verification point with the signature point obtained from the signature organizer C to verify the signature compliance of each signature person, including:
[0046] Step S51: The signature receiver uses the public key E c of the signature organizer C to determine whether (s′, r′) is a compliant signature of (s, r); If not, it is considered that an abnormality occurs in the current signature process and the subsequent verification is abandoned, and the method ends; If so, go to step S52;
[0047] Step S52: The signature receiver calculates the verification point (x′, y′) = sG - H(r|M)Q;
[0048] Step S53: The signature receiver calculates the value t″ of the abscissa of the verification point, t″ = x′(mod q), and then compares whether r″ and r are equal. If they are equal, it is determined that the signature of the signature person is compliant and accepted, and the method ends; Otherwise, it is rejected and the method ends.
[0049] A device for two - level threshold signature for hierarchical management provided by the present invention, the device includes:
[0050] A configuration module: configured to obtain a file M to be signed, configure the roles participating in the signature, and the roles participating in the signature include a trusted center D, a signature organizer C, signers, and signature receivers; the signers include branch - level signers and department - level signers;
[0051] A key generation module: configured to have the trusted center D select parameters for the file M to be signed and generate respective corresponding sub - keys for each branch - level signer and each department - level signer;
[0052] A signature module: configured to select signature personnel, the signature personnel including branch - level signature personnel and department - level signature personnel, and the signature personnel are formed by some branch - level signers and some department - level signers; each signature personnel uses their respective corresponding sub - keys to sign the file M to be signed;
[0053] A release module: configured to have the signature organizer C receive the signature results of each signature personnel for the file M to be signed, verify its compliance; synthesize the verified signature results, and use the private key D of the signature organizer C c to sign the synthesized signature result to obtain a final signature result, and release the final signature result to the signature receiver;
[0054] A verification module: configured to have the signature receiver verify the signature compliance of the signature organizer C based on the public key E of the signature organizer C c to verify the signature compliance of the signature organizer C, then calculate verification points, compare the verification points with the signature points obtained from the signature organizer C, and verify the signature compliance of each signature personnel.
[0055] Beneficial effects:
[0056] The present invention proposes a method and device for two - level threshold signature for hierarchical management, realizing the operations of threshold signature of files and judgment of the compliance of the signature in a hierarchical management system.
[0057] It has the following technical effects:
[0058] (1) Obtain the signature of the file and conduct compliance verification, which is applicable to the hierarchical management system;
[0059] (2) Adopt a two - time signature method during signature, improving security;
[0060] (3) To a certain extent, prevent the problem of excessive power of superiors in the hierarchical management system and the problem that superiors are unable to participate in the signature due to reasons;
[0061] (4) The method of the present invention innovates the signature method of threshold signature, improves security, and is easy to be realized and applied industrially. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] Figure 1 It is a schematic flowchart of the method for two-level threshold signature for hierarchical management provided by the present invention;
[0063] Figure 2 It is a schematic structural diagram of the hierarchical management system provided by the present invention;
[0064] Figure 3 It is a schematic structural diagram of the system for testing two-level threshold signature for hierarchical management provided by the present invention;
[0065] Figure 4(A) is a schematic diagram of the login interface effect provided by the present invention;
[0066] Figure 4(B) is a schematic diagram of the trusted center interface effect provided by the present invention;
[0067] Figure 4(C) is a schematic diagram of the trusted center parameter selection effect provided by the present invention;
[0068] Figure 4(D) is for the private key generation and sub-keys, b i , e j distribution effect diagram;
[0069] Figure 4(E) is for the sub-keys of the branch company and b i parameter effect diagram;
[0070] Figure 4(F) is for the sub-keys of the subordinate department of Branch Company 3 and e j parameter effect diagram;
[0071] Figure 4(G) is a schematic diagram of the signature organizer inputting the signature file provided by the present invention;
[0072] Figure 4(H) is a schematic diagram of a certain branch company signer selecting "agree to sign" provided by the present invention;
[0073] Figure 4(I) is a schematic diagram of a certain department signer selecting "agree to sign" provided by the present invention;
[0074] Figure 4(J) is a schematic diagram of the signature organizer randomly selecting signers provided by the present invention;
[0075] Figure 4(K) is a schematic diagram of a certain branch company signer being selected as a participant in this signature provided by the present invention;
[0076] Figure 4(L) is a schematic diagram of a certain department signer being selected as a participant in this signature provided by the present invention;
[0077] Figure 4(M) is a schematic diagram of the parameter generation and sending effect of a branch signer participating in this signature provided by the present invention;
[0078] Figure 4(N) is a schematic diagram of the parameter generation and sending effect of a department signer participating in this signature provided by the present invention;
[0079] Figure 4(O) is a schematic diagram of the parameter generation and sending effect of a signature organizer provided by the present invention;
[0080] Figure 4(P) is a schematic diagram of the signature calculation effect of a branch signer participating in this signature provided by the present invention;
[0081] Figure 4(Q) is a schematic diagram of the signature calculation effect of a department signer participating in this signature provided by the present invention;
[0082] Figure 4(R) is a schematic diagram of the signature calculation and sending effect of a signature organizer provided by the present invention;
[0083] Figure 4(S) is a schematic diagram of the first-step verification effect of a signature receiver provided by the present invention;
[0084] Figure 4(T) is a schematic diagram of the second-step verification effect of a signature receiver provided by the present invention;
[0085] Figure 5 It is a schematic structural diagram of a device for two-level threshold signature for hierarchical management provided by the present invention. Specific Embodiments
[0086] The present invention will be described in detail below with reference to the accompanying drawings and embodiments.
[0087] As Figures 1 - 3 shown, the present invention proposes a method for two-level threshold signature for hierarchical management, and the method includes:
[0088] Step S1: Obtain the file M to be signed, configure the roles participating in the signature, and the roles participating in the signature include a trusted center D, a signature organizer C, signers, and signature receivers; the signers include branch-level signers and department-level signers;
[0089] Step S2: The trusted center D selects parameters for the file M to be signed and generates respective corresponding sub-keys for each branch-level signer and each department-level signer;
[0090] Step S3: Select signers, and the signers include branch-level signers and department-level signers, and the signers are formed by some branch-level signers and some department-level signers; each signer signs the file M to be signed with their respective corresponding sub-keys;
[0091] Step S4: The signature organizer C receives the signature results of each signatory for the file M to be signed, verifies their compliance; synthesizes the verified signature results, and uses the private key D of the signature organizer C itself c to sign the synthesized signature result to obtain the final signature result, and publishes the final signature result to the signature receiver;
[0092] Step S5: The signature receiver verifies the signature compliance of the signature organizer C based on the public key E of the signature organizer C c and then calculates the verification points, compares the verification points with the signature points obtained from the signature organizer C, and verifies the signature compliance of each signatory.
[0093] In step S1, the roles participating in the signature include the trusted center D, the signature organizer C, the signatories, and the signature receiver, where:
[0094] The branch-level signatory P i and all subordinate department-level signatories P i,j constitute the department-level signatory group T i , and the branch-level signatory P i and the department-level signatory P i,j have the following corresponding relationship: The i-th branch-level signatory P i has j department-level signatories P i,j .
[0095] The trusted center D is used to select parameters for the file to be signed, calculate the private key d of the branch-level signatory group P to obtain multiple sub-keys d i , and send each sub-key d i to the corresponding branch-level signatory P i respectively; send each sub-key d i calculated based on the sub-key d i of the branch-level signatory P i,j to the corresponding department-level signatory P i,j respectively.
[0096] The signature organizer C receives the signature results of each branch-level signatory and each department-level signatory for the file M to be signed, verifies their correctness; synthesizes the verified signature results, and uses the private key D of the signature organizer C itself c to sign the synthesized signature result to obtain the final signature result, and publishes the final signature result to the signature receiver. The signature organizer C is the only publisher of the group signature message.
[0097] The signer performs a threshold signature operation. The signers are divided into branch-level signers and department-level signers. Let the set \(P = \{P_1, P_2, \ldots, P n \}\) represent the group of branch-level signers composed of \(n\) branch-level signers; let the set \(T i = \{P i,1 , P i,2 , \ldots, P i,j \}\) represent the group of department-level signers composed of \(j\) department-level signers under the \(i\)-th branch signer, where \(1\leq i\leq n\).
[0098] Step S2 includes: The trusted center D selects parameters for the file M to be signed, calculates the sub-key \(d i \) based on the private key \(d\) of the branch-level signer group \(P\), sends the sub-key \(d i \) to the corresponding branch-level signer \(P i \), calculates the sub-key \(d i \) based on the sub-key \(d i,j \), and sends the sub-key \(d i,j \) to the corresponding department-level signer \(P i,j .
[0099] Furthermore, step S2 includes:
[0100] Step S21: Obtain the file attributes of the file to be signed;
[0101] Step S22: Based on the file attributes, the trusted center D determines the parameters, which include the finite field \(F q \), the elliptic curve \(E\) over \(F q \), the base point \(G\) of the elliptic curve \(E\), the one-way hash function \(h(\cdot)\), the file M to be signed, and the private key \(d\) of the signer group \(P\) composed of branch-level signers, where:
[0102] Finite field \(F q : where \(q\) is a large prime number, given by the trusted center D;
[0103] Elliptic curve \(E\) over \(F q : The trusted center D selects two elements \(a\) and \(b\) in \(F q \) to generate the equation of \(E\) as \(y 2 = x 3 + ax + b\). There is a unique infinite point on the elliptic curve, denoted as \(O\), and \(x\) and \(y\) are the values of the abscissa and ordinate respectively;
[0104] The trusted center D selects the base point \(G\in E(F q )\), \(G\neq O\), and the order of the base point \(G\) is \(k\), where \(k\) is a large prime number and satisfies \(kG = O\), \(E(F q) is F q the upper elliptic curve E;
[0105] The file M to be signed, which is notified by the trusted center D to the signature organizer and given by the signature organizer;
[0106] The one-way hash function h(·), using the SM3 algorithm;
[0107] The private key d of the signer group P composed of the branch-level signers is generated by a random number generator; the public key Q = dG ≠ O of the signer group P composed of the company-level signers;
[0108] Step S23: Calculate the sub-key d based on the private key d of the branch-level signer group P i , and send the sub-key d i to the corresponding branch-level signer P i , calculate the sub-key d based on the sub-key d i , and send the sub-key d i,j to the corresponding department-level signer P i,j including: i,j , including:
[0109] The trusted center D divides the private key d of the set P into n equal parts, calculates the sub-key d i , and sends the sub-key d i to the corresponding branch-level signer P i , so that any subset composed of branch-level signers with a number greater than or equal to t can represent the group composed of all branch-level signers; that is, any subset composed of less than t branch-level signers cannot represent the group composed of all branch-level signers for signature. Send the sub-key d i to the corresponding branch-level signer P i The distribution process of is carried out by using the Shamir secret sharing system:
[0110] The trusted center D randomly selects a polynomial g(x) of degree t - 1 on F q , g(x) = c0 + c1x + c2x 2 +…+ c t-1 x t-1 (mod q), where g(0) = c0 = d, c1, c2, …, c t-1 are random numbers; then the trusted center D calculates d i = g(i)(mod q), 1 ≤ i ≤ n, and sends d i to the branch-level signer P through a secret channel i , d i is the branch-level signer Pi The held sub - key (or called secret share), P i The public key Q of i Is Q i = d i G
[0111] The trusted center D divides the private key d of P i Into m i Equal parts, calculates the sub - key d based on the sub - key d i , and then distributes each sub - key d i To each member P i,j In T i,j So that, under the same branch, a subset composed of department - level signers with a number greater than or equal to s can represent the group composed of all department - level signers under this branch; that is to say, under the same branch, a subset composed of any department - level signers with a number less than t cannot represent the group composed of all department - level signers to sign. Distribute each sub - key d i To each member P i,j In T i,j The distribution process to each member P i Adopts the Shamir secret sharing system: i,j The trusted center D randomly selects n polynomials f
[0112] Of degree s - 1 on F q (x), f i (x)=a i +a i,0 x + a i,1 2x i, +…+a 2 x i,s-1 (mod q), i = 1,2,…n, where f s-1 (0)=a i = d i,0 , a i , a i,1 ,…, a i,2 ,…, a i,s-1 Are random numbers; then the trusted center D calculates d i,j = f i (j)(mod q), 1≤i≤n, 1≤j≤m i , and sends d i,j To the j - th department - level signer under the i - th branch through a secret channel. d i,j Is the sub - key (or called secret share) held by the member P i,j , and the public key Q of P i,j Is Q i,j = d i,j G i,j G
[0113] In this embodiment, any t signers can reconstruct the polynomial through the Lagrange interpolation polynomial. Without loss of generality, let the t members be P1, P2, …, P t :
[0114]
[0115] Therefore, the secret key d can be recovered by d = g(0), that is
[0116] where
[0117] When t - 1 signers want to recover the secret key d, they can obtain t - 1 linear equations with t unknowns, so d cannot be recovered.
[0118] In this embodiment, any s signers can reconstruct the polynomial through the Lagrange interpolation polynomial. Without loss of generality, let the s members be P i,1 , P i,2 , …, P i,s :
[0119] Among them, all the branch - level signer groups d i,j (mod q)
[0120] Therefore, the secret key d i,j can be recovered by d i = f i (0), that is
[0121] where
[0122] When s - 1 signers want to recover the secret key d i they can obtain s - 1 linear equations with s unknowns, so d cannot be recovered i .
[0123] Meanwhile, the trusted center sends the values of b i and e j to the corresponding signers through the secret channel.
[0124] Step S3: Select signers. The signers include branch - level signers and department - level signers. The signers are formed by some branch - level signers and some department - level signers; each signer uses their respective sub - secret key to sign the file M to be signed, including:
[0125] Step S31: Select num branch-level signers from all branch-level signers. If num is greater than or equal to t, go to Step S32; if num is less than t, determine t - num unselected branch-level signers, and for each of the t - num unselected branch-level signers, select s department-level signers from all their corresponding department-level signers. Denote the num branch-level signers as P1, P2, …, P u , where 1 < u ≤ num. Then denote the department-level signer who replaces the l-th branch signature as P l,1 , P l,2 , …, P l,s , where u < l ≤ t and 1 ≤ s ≤ j, and go to Step S32.
[0126] In this embodiment, for example, the signature organizer C randomly selects t branch-level signers from the set P and requests them to sign the file M to be signed. For branch-level signers who refuse to sign or agree but cannot sign normally due to reasons, the signature organizer C randomly selects s department-level signers from the group of department-level signers corresponding to this branch to sign the file M to replace the signature of this branch until t branches (including the replaced branches) participate. Without loss of generality, let the branch-level signers who agree and can sign normally be P1, P2, …, P u , where 1 < u < t. Then let the department-level signers who replace the branch signature be P l,1 , P l,2 , …, P l,s , where u < l ≤ t and 1 ≤ s ≤ j.
[0127] Step S32: For each department-level signer P l,w , where 1 ≤ w ≤ s: Each department-level signer P l,w generates a random number k l,w for calculating the intermediate value W l,w = k l,w G and Q l,w = d l,w G, and sends W l,w and Q l,w to the signature organizer C.
[0128] For each branch-level signer P v , where 1 ≤ v ≤ u: Each branch-level signer P v generates a random number k v for calculating the intermediate value W v = k v G and Q v = d v G, and sends W v and Qv Sent to signature organizer C.
[0129] For signature organizer C: Signature organizer C calculates W by receiving W sent by each department-level signatory P l,w sent l,w and obtains W l , and then combines with W sent by each branch-level signatory P v sent v to calculate the signature point where W z includes W v and W l . Then signature organizer C calculates the value r = x (mod q) of the abscissa of the signature point and sends it to each signatory.
[0130] Step S33: For each department-level signatory P l,w : Each department-level signatory P l,w signs the file M to be signed to obtain s l,w and sends it to signature organizer C, that is
[0131] s l,w = k l,w + d l,w H(r|M)e w (mod q)
[0132] where s l,j is the signature of file M by department-level signatory P l,j , r is the value of the abscissa of the signature point, and H(r|M) is the hash value after concatenating file M and the value r of the abscissa of the signature point.
[0133] For each branch-level signatory P v : Each branch-level signatory P v signs the file M to be signed to obtain s v and sends it to signature organizer C, that is
[0134] s v = k v + d v H(r|M)b v (mod q)
[0135] where H(r|M) is the hash value after concatenating file M and the value r of the abscissa of the signature point.
[0136] In this embodiment, e w and b v correspond to e j and b in the recovery key.i , which is used to represent the calculation formula.
[0137] Step S4: The signature organizer C receives the signature results of each signatory on the file M to be signed, and verifies its compliance; synthesizes the signature results that pass the verification, and uses the private key D of the signature organizer C itself c to sign the synthesized signature result to obtain the final signature result, and publishes the final signature result to the signature recipient, including:
[0138] Step S41: For the signatures of each department-level signatory P l,w , the signature organizer C compares s l,w G-H(r|M)e w Q l,w with W l,w to see if the two are equal. If the two are equal, that is
[0139] s l,w G-H(r|M)e w Q l,w = s l,w G-d l,w H(r|M)e w G
[0140] =(s l,w -d l,w H(r|M)e w )G
[0141] = k l,w G
[0142] = W l,w
[0143] then the signature organizer C determines that the signature of this department-level signatory P l,w is compliant and accepts it. If the two are not equal, the signature organizer C ends this signature process and the method ends;
[0144] Step S42: For the signatures of each department-level signatory P v , the signature organizer C compares s v G-H(r|M)b v Q v with W v to see if the two are equal. If the two are equal, that is
[0145] s v G-H(R|M)b v Q v = s v G-d v H(r|M)b v G
[0146] =(s v -d v H(r|M)b v )G
[0147] =k v G
[0148] =W v
[0149] Then the signature organizer C determines that the signature of the branch-level signature personnel P v is compliant and accepted. If the two are not equal, the signature organizer C ends the current signature process and the method ends;
[0150] Step S43: The signature organizer C synthesizes s through ; The signature organizer C calculates l ; where s includes s z and s v and s l ; The signature organizer C then signs (s, r) with its own private key D c , and after signing, they are respectively (s′, r′); The signature organizer C outputs (s, r, s′, t′, M) as the final signature of the file M to be signed.
[0151] In step S5: The signature receiver verifies the signature compliance of the signature organizer C based on the public key E c of the signature organizer C, then calculates the verification point, compares the verification point with the signature point obtained from the signature organizer C, and verifies the signature compliance of each signature personnel, including:
[0152] Step S51: The signature receiver uses the public key E c of the signature organizer C to determine whether (s′, r′) is a compliant signature of (s, t); If not, it is considered that an abnormality occurs in the current signature process and the subsequent verification is abandoned, and the method ends; If so, go to step S52;
[0153] Step S52: The signature receiver calculates the verification point (x′, y′)=sG - H(r|M)Q;
[0154] Step S53: The signature receiver calculates the value t″ of the abscissa of the verification point t″ = x′(mod q), then compares whether r″ and r are equal. If they are equal, it is determined that the signature of the signature personnel is compliant and accepted, and the method ends; Otherwise, it is rejected and the method ends.
[0155] In the present invention, by using the design of the solution of the present invention, it is realized that through the Shamir secret sharing system, according to the input of different threshold values, sub-key distribution is realized, and the sub-keys are saved to the local document.
[0156] In the present invention, by using the design of the solution of the present invention, the signature organizer, the branch signer, and the department signer can generate parameters, calculate and verify intermediate values, and perform two-level threshold signature on the file.
[0157] In the present invention, by using the design of the solution of the present invention, the signature verifier can determine the compliance of the signature, so as to accept or reject the signature.
[0158] As Figures 4(A) - 4(T) shown, a system for testing two-level threshold signature for hierarchical management based on elliptic curves is provided, which has the following functions.
[0159] Role login function
[0160] First, input the username and password assigned by the system.
[0161] Then, select the user identity that matches the username, click "Login", and enter the corresponding user interface.
[0162] Example: Input the username admin001 and the corresponding password, select the "Trusted Center" identity, click Login, and enter the Trusted Center interface, as Figures 4(A) - 4(B) shown.
[0163] Parameter selection and sub-key distribution function
[0164] First, the Trusted Center D inputs a large prime number q, two elements a and b in F q the abscissa and ordinate of the elliptic curve base point, the order n of the elliptic curve base point, the number of branches, the branch threshold value t, the number of departments in the branch, and the department threshold value s, all of which are input in hexadecimal here.
[0165] Then, click "Generate private key and perform key distribution". The system determines whether the parameters are compliant. If they are compliant, it determines the branch and department threshold values, obtains the private key, and completes the distribution of the sub-key and b i and e j , otherwise, re-input is required. Among them, the sub-key and b i and e j can be viewed through the local document.
[0166] Example: Input the parameters, click "Generate private key and perform key distribution", obtain the private key, and complete the distribution of the sub-key and b i and e j , as Figures 4(C) - 4(F) shown.
[0167] Signature function
[0168] First, the signature organizer C inputs the content of the file to be signed, clicks "Submit", and distributes the signature task.
[0169] Then, the department signers and branch signers select "Agree to Sign" or "Refuse to Sign" and click "Submit".
[0170] Then, the signature organizer clicks "Randomly Select Signers" to start the current signature process; at the same time, the department signers and branch signers who agree to sign can click "Query" to check whether they are selected as participants in the current signature.
[0171] Then, the signers participating in the current signature click "Parameter Generation" to generate the parameters required for signing and send them to the signature organizer.
[0172] Then, the signature organizer clicks "Parameter Generation" to generate parameters and send them to each signer participating in the current signature.
[0173] Next, the signers participating in the current signature click "Sign" to perform the signature operation and finally send the signature result to the signature organizer.
[0174] Finally, the signature organizer clicks "Verify and Sign" to verify the signature result sent by the signer, and uses its own private key to sign, and sends the final result to the recipient.
[0175] Example: Input the file content "The Little Prince is a novella by French aristocrat, writer.", click "Submit"; a branch signer selects "Agree to Sign", and a department signer selects "Refuse to Sign"; the signature organizer clicks "Randomly Select Signers" to start the signature process, and the branch signer and department signer who select "Agree to Sign" click "Query" to check whether they are selected as participants in the current signature; a participant in the current signature clicks "Parameter Generation" to generate parameters and send them to the signature organizer; the signature organizer clicks "Parameter Generation" to generate parameters and send them to each signer participating in the current signature; a participant in the current signature clicks "Sign" to perform the operation on the parameters and send them to the signature organizer; the signature organizer clicks "Verify and Sign" to verify the signature sent by the signer, and uses its own private key to sign, and sends the final result to the recipient; as Figures 4(G) - 4(R) shown.
[0176] Signature Verification Function
[0177] First, the signature recipient clicks "Verify Whether it is a Compliance Signature of the Signature Organizer" to perform the first step of verification on the received signature. If it is compliant, it prompts to continue with the subsequent verification; otherwise, it rejects the signature.
[0178] Then, the signature recipient clicks "Verify whether it is a compliant signature of the signer", performs a second verification on the received signature, and accepts the signature if it is compliant, otherwise rejects it.
[0179] Example: The signature recipient clicks "Verify whether it is a compliant signature of the signature organizer" and gets a "compliant" result; then, the signature recipient clicks "Verify whether it is a compliant signature of the signer" and gets a "compliant" result, and accepts the signature; as Figures 4(S) - 4(T) shown.
[0180] As Figure 5 shown, a device for two - level threshold signature based on elliptic curve for hierarchical management provided by the present invention, the device includes:
[0181] Configuration module: Configured to obtain the file M to be signed, configure the roles participating in the signature. The roles participating in the signature include the trusted center D, the signature organizer C, the signer, and the signature recipient; the signer includes branch - level signers and department - level signers;
[0182] Key generation module: Configured such that the trusted center D selects parameters for the file M to be signed and generates respective corresponding sub - keys for each branch - level signer and each department - level signer;
[0183] Signature module: Configured to select signature personnel, the signature personnel include branch - level signature personnel and department - level signature personnel, and the signature personnel are formed by some branch - level signers and some department - level signers; each signature personnel uses their respective corresponding sub - keys to sign the file M to be signed;
[0184] Publication module: Configured such that the signature organizer C receives the signature results of each signature personnel for the file M to be signed, verifies their compliance; synthesizes the verified signature results, and signs the synthesized signature result with the private key D of the signature organizer C c to obtain the final signature result, and publishes the final signature result to the signature recipient;
[0185] Verification module: Configured such that the signature recipient verifies the signature compliance of the signature organizer C based on the public key E of the signature organizer C c calculates the verification points, compares the verification points with the signature points obtained from the signature organizer C, and verifies the signature compliance of each signature personnel.
[0186] The present invention provides an implementation of a two - level threshold signature scheme based on elliptic curve. The implementation is based on the design described above, and the implementation includes:
[0187] Implement the parameter selection function of the design; that is, the trusted center completes the parameter selection;
[0188] Implement the sub - key distribution function of the said design; that is, the trusted center implements sub - key distribution;
[0189] Implement the signature function of the said design; that is, the signature organizer and the signer complete the signature of the file;
[0190] Implement the signature verification function of the said design; that is, the signature verifier completes the verification of the signature compliance.
[0191] The above - mentioned specific embodiments only describe the design principle of the present invention. The shapes and names of the components in this description can be different and are not restricted. Therefore, those skilled in the art of the present invention can modify or equivalently replace the technical solutions recorded in the foregoing embodiments; and these modifications and replacements that do not depart from the purpose and technical solutions of the present invention shall fall within the protection scope of the present invention.
Claims
1. A two - level threshold signature method for hierarchical management, characterized in that, The method includes the following steps: Step S1: Obtain the file M to be signed, and configure the roles participating in the signature. The roles participating in the signature include the trusted center D, the signature organizer C, the signers, and the signature receiver; the signers include branch-level signers and department-level signers; Step S2: The trusted center D selects parameters for the file M to be signed, and generates respective corresponding sub-keys for each branch-level signer and each department-level signer; Step S3: Select signature personnel, where the signature personnel include branch-level signature personnel and department-level signature personnel, and the signature personnel are formed by some branch-level signers and some department-level signers; each signature personnel signs the file M to be signed using their respective corresponding sub-keys; Step S4: The signature organizer C receives the signature results of each signatory for the file M to be signed, verifies its compliance; synthesizes the signature results that pass the verification, and uses the private key D of the signature organizer C itself c to sign the synthesized signature result to obtain the final signature result, and publishes the final signature result to the signature recipient; Step S5: The signature receiver verifies the signature compliance of the signature organizer C based on the public key E of the signature organizer C c 2. The method according to claim 1, wherein In step S1, the roles participating in the signature include the trusted center D, the signature organizer C, the signers, and the signature receiver, where: Branch-level Signer P i All subordinate department-level Signers P i,j form the department-level Signer group T i , the branch-level Signer P i and the department-level Signer P i,j have the following corresponding relationship: the i-th branch-level Signer P i has j department-level Signers P i,j ; The trusted center D is used to select parameters for the file to be signed, calculate the private key d of the branch-level signer group P, and obtain multiple sub-keys d i , and send each sub-key d i to the corresponding branch-level signer P i respectively; and send each sub-key d i obtained by calculating based on the sub-key d i of the branch-level signer P i,j to the corresponding department-level signer P i,j respectively; The signature organizer C receives the signature results of the signature personnel at the branch level and the signature personnel at the department level for the file M to be signed, and verifies their correctness; synthesizes the verified signature results, and uses the private key D of the signature organizer C itself c to sign the synthesized signature result to obtain the final signature result, and publishes the final signature result to the signature receiver. The signature organizer C is the only publisher of the group signature message; The signer performs a threshold signature operation. The signer is divided into branch-level signers and department-level signers. Let the set \(P = \{P_1, P_2, \ldots, P\) n \} represent the group of branch-level signers composed of \(n\) branch-level signers; Let the set \(T\) i = \{P i,1 , P i,2 , \ldots, P i,j \} represent the group of department-level signers composed of \(j\) department-level signers under the \(i\)-th branch signer, where \(1\leq i\leq n\); The step S5 includes: the signature receiver verifies the signature compliance of the signature organizer C based on the public key E of the signature organizer C c then calculates the verification points, compares the verification points with the signature points obtained from the signature organizer C, and verifies the signature compliance of each signatory.
3. The method according to claim 2, wherein Step S2 includes: Step S21: Obtain the file attributes of the file to be signed; Step S22: Based on the file attributes, the trusted center D determines the parameters, where the parameters include a finite field F q , F q elliptic curve E over, the base point G of the elliptic curve E, one-way hash function h(·), the file M to be signed, and the private key d of the signer group P composed of branch-level signers, where: Finite field F q : where q is a large prime number given by the trusted center D; F q On the upper elliptic curve E: The trusted center D selects two elements a and b in F q to generate the equation of E, y 2 = x 3 + ax + b. There is a unique point at infinity on the elliptic curve, denoted as O. Let x and y be the values of the abscissa and ordinate respectively; The trusted center D selects the base point G of the elliptic curve, where G ∈ E(F q ), G ≠ O, the order of the base point G is k, where k is a large prime number and satisfies kG = O, and E(F q ) is the elliptic curve E over F q ; For the file M to be signed, the trusted center D notifies the signature organizer, and the signature organizer provides it; One-way hash function h(·), using the SM3 algorithm; The private key d of the signer group P composed of branch-level signers is generated by a random number generator; the public key Q = dG ≠ O of the signer group P composed of company-level signers; Step S23: Calculate the sub - key d based on the private key d of the branch - level signer group P i , and send the sub - key d i to the corresponding branch - level signer P i . Calculate the sub - key d i based on the sub - key d i,j , and send the sub - key d i,j to the corresponding department - level signer P i,j , including: The trusted center D divides the private key d of the set P into n equal parts, calculates the sub-private key d i , and sends the sub-private key d i to the corresponding branch-level signer P i , so that any subset composed of branch-level signers with a quantity greater than or equal to t can represent the group composed of all branch-level signers; the distribution process of sending the sub-private key d i to the corresponding branch-level signer P i adopts the Shamir secret sharing system: The trusted center D will P i The private key d i Divided into m i Equal parts, based on subkey d i Calculate the subkey d i,j , and then each subkey d i,j Distribute to T i Each member P in i,j , so that the subsets of department-level signers with a number greater than or equal to s under the same branch can represent the group of all department-level signers under the branch; i,j Distribute to T i Each member P in i,j The distribution process adopts the Shamir secret sharing system.
4. The method according to claim 3, characterized in that, Step S3: Select signature personnel, where the signature personnel include branch-level signature personnel and department-level signature personnel, and the signature personnel are formed by some branch-level signers and some department-level signers; Each signature personnel signs the file M to be signed using their respective corresponding sub-keys, including: Step S31: Select num branch-level signers from all branch-level signers. If num is greater than or equal to t, go to Step S32; if num is less than t, determine t - num unselected branch-level signers, and for each of the t - num unselected branch-level signers, select s department-level signers from all its corresponding department-level signers. Denote the num branch-level signers as P1, P2, …, P u , where 1 < u ≤ num, and then denote the department-level signer replacing the l-th branch signature as P l,1 , P l,2 , …, P l,s , where u < l ≤ t, 1 ≤ s ≤ j, and go to Step S32; Step S32: For each department-level signatory P l,w , where 1 ≤ w ≤ s: Each department-level signatory P l,w generates a random number k l,w for calculating the intermediate value W l,w = k l,w G and Q l,w = d l,w G, and sends W l,w and Q l,w to the signature organizer C; For each signature personnel P at the branch level v , where 1 ≤ v ≤ u: Each signature personnel P at the branch level v generates a random number k v for calculating the intermediate value W v = k v G and Q v = d v G, and sends W v and Q v to the signature organizer C; For signature organizer C: Signature organizer C calculates W l,w received from each department-level signature personnel P l,w and then combines it with W l received from each branch-level signature personnel P v to calculate the signature point v where W includes W z and W v and W l Then, signature organizer C calculates the value r = x (mod q) of the abscissa of the signature point and sends it to each signature personnel; Step S33: For each department-level signatory P l,w : Each department-level signatory P l,w signs the file M to be signed to obtain s l,w and sends it to the signature organizer C, that is s l,w = k l,w + d l,w H(r|M)e w (mod q) where s l,w is the signature of the department-level signatory P l,w for the document M, r is the value of the abscissa of the signature point, and H(r|M) is the hash value after concatenating the document M and the value r of the abscissa of the signature point For each signature personnel P at the branch level v : Each signature personnel P at the branch level v Signs the file M to be signed to obtain s v And sends it to the signature organizer C, that is s v = k v + d v H(r|M)b v (mod q) Among them, H(r|M) is the hash value after concatenating the file M and the abscissa value r of the signature point.
5. The method according to claim 4, characterized in that, Step S4: The signature organizer C receives the signature results of each signatory for the file M to be signed, and verifies its compliance; synthesizes the signature results that pass the verification, and uses the private key D of the signature organizer C itself c signs the synthesized signature result to obtain the final signature result, and publishes the final signature result to the signature recipient, including: Step S41: For the signatures of each department-level signatory P l,w the signature organizer C compares s l,w G-H(r|M)e w Q l,w with W l,w to check if they are equal. If they are equal, the signature organizer C determines that the signature of the department-level signatory P l,w is compliant and accepts it. If they are not equal, the signature organizer C ends the current signature process and the method ends; Step S42: For the signatures of each department-level signatory P v the signature organizer C compares s v G-H(r|M)b v Q v with W v to see if they are equal. If they are equal, the signature organizer C determines that the signature of the branch-level signatory P v is compliant and accepts it. If they are not equal, the signature organizer C ends the current signature process and the method ends; Step S43: The signature organizer C passes through synthesize s l ; The signature organizer C calculates where s z includes s v and s l ; The signature organizer C then signs (s, r) with its own private key D c to obtain (s′, r′) after signing; The signature organizer C outputs (s, r, s′, r′, M) as the final signature for the file M to be signed.
6. The method according to claim 5, wherein Step S5: The signature receiver verifies the signature compliance of the signature organizer C based on the public key E of the signature organizer C c verifies the signature compliance of the signature organizer C, then calculates the verification points, compares the verification points with the signature points obtained from the signature organizer C, and verifies the signature compliance of each signatory, including: Step S51: The signature recipient uses the public key E of the signature organizer C c to determine whether (s′, r′) is a compliant signature of (s, r); if not, it is considered that an exception has occurred in the current signature process, and subsequent verification is abandoned, and the method ends; if so, go to step S52; Step S52: The signature receiver calculates the verification point (x′, y′) = sG - H(r|M)Q; Step S53: The signature receiver calculates the value r″ of the abscissa of the verification point, and then compares whether r″ and r are equal. If they are equal, it is determined that the signature of the signature personnel is compliant and accepted, and the method ends; otherwise, it is rejected and the method ends.
7. A two - level threshold signature device for hierarchical management, characterized in that, The device includes: Configuration module: Configured to obtain the file M to be signed, and configure the roles participating in the signature. The roles participating in the signature include the trusted center D, the signature organizer C, the signers, and the signature receiver; the signers include branch-level signers and department-level signers; Key generation module: Configured to have the trusted center D select parameters for the file M to be signed, and generate respective corresponding sub-keys for each branch-level signer and each department-level signer; Signature module: Configured to select signature personnel, where the signature personnel include branch-level signature personnel and department-level signature personnel, and the signature personnel are formed by some branch-level signers and some department-level signers; each signature personnel signs the file M to be signed using their respective corresponding sub-keys; Publication module: Configured to receive the signature results of each signatory on the file M to be signed by the signature organizer C, and verify its compliance; synthesize the verified signature results, and use the private key D of the signature organizer C itself c Sign the synthesized signature result to obtain the final signature result, and publish the final signature result to the signature recipient; Verification module: configured to verify the signature compliance of the signature organizer C by the signature recipient based on the public key E of the signature organizer C c and verify the signature compliance of the signature organizer C.
Citation Information
Patent Citations
Paper peer review method based on blockchain technology
CN113032827A
Threshold digital signature method and system
US20200213113A1