Quantum security aggregation signature method and device suitable for embedded system
By generating and verifying signatures based on ring grids, the problem of insecure of the aggregate signature algorithm under quantum computing is solved, and efficient and quantum-safe signature verification is achieved, which is suitable for embedded systems.
Patent Information
- Application Number
- CN202510601795.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-08-05
AI Technical Summary
The existing aggregate signature algorithms are not safe in the quantum computing environment and cannot effectively resist quantum attacks. In addition, the computing resources and storage resources of embedded systems are limited, making it difficult to efficiently conduct signature verification.
The cryptographic system based on ring grid is adopted, and the system parameters are initialized through the trusted key generation center, and the public key and private key are generated for each signature user. The signature user uses the private key and system parameters to sign, aggregate the server and merge the signature, verifying the server uses the system parameters and public key to verify the integrity and correctness of the signature.
It realizes efficient and quantum-security signature verification, reduces the requirements of computing and storage resources, and is suitable for embedded systems with limited computing resources, such as drone clusters, medical wireless sensors, and intelligent connected vehicles.
Smart Images

Figure CN120433946A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of digital signatures, and in particular relates to a quantum-safe aggregate signature method and device suitable for embedded systems. Background Art
[0002] Cryptography is the study of the design and cracking of codes to ensure the confidentiality, integrity, and availability of information. As a core technology for ensuring information security, it continues to evolve in the battle between coders and code breakers. Cryptographic algorithms can be categorized into two types: asymmetric (also known as public-key) and symmetric, depending on the encryption and decryption methods used. In public-key cryptography, a pair of public and private keys exists; the public key is publicly available, while the private key remains secret.
[0003] Digital signature algorithms are designed based on public-key cryptography. As one of the most important applications of cryptography, they are used to verify the authenticity, integrity, and non-repudiation of documents. A mature digital signature algorithm comprises both a signing algorithm and a verification algorithm. The general process is that the signer uses the private key and the message to be signed as input to the signature algorithm. The signature algorithm outputs a signature string (called the signature value), which is sent along with the message to be signed to the verifier. The verifier uses the public key, the message to be signed, and the signature value as input to the verification algorithm. The verification algorithm outputs a bit 0 / 1, indicating whether the verification has passed or failed.
[0004] In the general process of signature, a message should be signed first, and then the message is considered legitimate after it passes the verification algorithm. This also means that the signature algorithm and the verification algorithm appear in pairs in the same system. Second signature required In order to improve the verification efficiency, the aggregate signature is designed. The aggregate signature is a variant of the digital signature. Figure 1 Aggregate signature is different from the above digital signature algorithm which has two stages of signature and verification. Aggregate signature includes three stages of signature, aggregation and verification. It can users On the message Aggregate the signatures to generate a short signature, and merge them through the aggregation algorithm. The signature and public key of each user can be verified through a one-time verification algorithm to complete the legitimacy verification of all signatures. In scenarios with multiple parties involved, signature verification can be completed more efficiently while saving computing and storage resources.
[0005] Aggregate signature algorithms also fall into the broad category of public-key cryptography. The security of public-key cryptography can ultimately be reduced to difficult mathematical problems. This can be intuitively understood as follows: because these mathematical problems are difficult to solve, cryptography designed based on them is difficult to break. Most current public-key algorithms are designed based on difficult mathematical problems such as the discrete logarithm problem and the large number factorization problem. However, these mathematical problems will become easier to solve with the Shor algorithm, which can be run on quantum computers. Consequently, most current public-key algorithms that rely on these problems will become insecure under the computing power of quantum computers. With the continuous development of quantum information technology, current public-key cryptography systems are facing an increasing quantum threat. Therefore, there is an urgent need to design cryptographic algorithms that are resistant to quantum computing. Such cryptographic algorithms are known as post-quantum cryptography.
[0006] Currently, cryptographic algorithms based on computationally difficult lattice problems are being proposed. These lattice-based cryptography algorithms are considered quantum-safe, resistant to attacks from both classical and quantum computers, and fall within the realm of post-quantum cryptography research. Lattice-based cryptography has become a mainstream algorithm in the post-quantum cryptographic algorithm standards being solicited by the National Institute of Standards and Technology (NIST). However, most current aggregate signature algorithms are based on mathematical challenges such as the discrete logarithm problem and the bilinear mapping problem on elliptic curves, and thus face quantum security threats. Therefore, aggregate signature algorithms based on lattice-based problems are needed to be resistant to quantum attacks.
[0007] Ring-LWE (Ring Learning With Errors) is a lattice-based encryption technology that uses the LWE (Learning With Errors) problem on the mathematical structure of rings to construct an encryption scheme. Ring lattice schemes not only have the quantum security of lattice structures, but also have higher computing speeds and more compact ciphertext, which enables this structure to better improve computing efficiency and storage space. Summary of the Invention
[0008] The purpose of the present invention is to provide a quantum-safe aggregate signature method and device suitable for embedded systems, which has the characteristics of high computing efficiency, small storage resource usage, and small total amount of communication information. It can solve the problems of limited computing power of embedded device resources, insufficient storage resources, and insufficient communication bandwidth in various embedded application scenarios.
[0009] In order to solve the above problems, the technical solution of the present invention is: A quantum-safe aggregate signature method for embedded systems, comprising: The trusted key generation center initializes system parameters based on the Ring Grid cryptographic system and generates a pair of keys for each signing user, including a public key and a private key. The public key is published through a public channel, and the private key is sent to the corresponding signing user through a secure channel. The signing user uses the private key and system parameters distributed by the trusted key generation center to sign the message using the signature algorithm, and sends the generated signature, message and their respective public keys to the aggregation server; The aggregation server receives signatures, messages, and public key information of multiple signing users, executes the aggregation algorithm, combines multiple signatures into an aggregate signature, and sends the aggregate signature and related information to the verification server; The verification server receives the aggregate signature and related information sent by the aggregation server, and verifies the aggregate signature using the system parameters provided by the trusted key generation center and the public key of the aggregation server to ensure the integrity and correctness of the signature, thereby verifying the source and authenticity of the message.
[0010] According to an embodiment of the present invention, the trusted key generation center initializes system parameters based on the ring grid cryptographic system, and generates a pair of keys for each signing user, further comprising: Select a large prime number , select for each signing user , and calculate + ,in yes High bit, for The low bit, ;in, For type finite field where , is the highest order polynomial, ; Choose a one-way collision-resistant hash function : , respectively for each signing user to set the low bit As input to this hash function, the output ) ; Select public parameters ; Calculated for each signing user , as the user's public key; Will The private key is sent to each signing user through a secure channel, and the public key is published through a public channel.
[0011] In addition, during the key generation phase, a public key will be generated for the aggregation server according to the above method. , private key .
[0012] According to an embodiment of the present invention, the signing user uses the private key and system parameters distributed by the trusted key generation center to sign the message using the signature algorithm, further comprising: The plaintext of the signing user is defined as m i , and generate a timestamp based on the current time ; User i selects , ,in, yes A subdomain of ;calculate ; User i calculates and ; Check if it exists , , if it does not exist, re-execute the above steps; Will As the user's signature, and the message mi, timestamp Sent to the aggregation server for verification.
[0013] According to one embodiment of the present invention, the aggregation server receives signatures, messages, and public key information of multiple signing users, executes an aggregation algorithm, and merges the multiple signatures into an aggregate signature, further comprising: Set a maximum time interval , and get the timestamp at this time ,like , then continue; otherwise, discard the signature and do not proceed with the subsequent aggregation process; test If not, the signature is considered invalid and will not be verified; if so, the following steps are performed; Will receive As input, step by step calculation Is it consistent with the received The values are the same, if they are different, the signature result will be discarded directly and will not participate in the aggregation. The signature result of . .
[0014] calculate .
[0015] The aggregator generates the signature in the same way as the individual signatures. , get the timestamp at this time , the aggregator performs a similar process to that of a single signature, computing , ; calculate and ; Then calculate , . , and , timestamp The data is sent together to the verification server for aggregate signature verification.
[0016] According to an embodiment of the present invention, the verification server receives the aggregate signature and related information sent by the aggregation server, and verifies the aggregate signature using the system parameters provided by the trusted key generation center and the public key of the aggregation server, further comprising: Get the timestamp at this time ,if , then continue; otherwise, do not proceed with the subsequent aggregation process.
[0017] calculate , then calculate .
[0018] Is it true? If so, all signatures are verified successfully; if not, at least one signature in the aggregation group is illegal.
[0019] According to an embodiment of the present invention, when at least one signature in an aggregation group is illegal, some signatures are verified using a binary search method to improve verification efficiency.
[0020] A quantum-safe aggregate signature device suitable for embedded systems, comprising: The key generation module is used by the trusted key generation center to initialize system parameters based on the ring grid cryptographic system; a pair of keys, including a public key and a private key, is generated for each signing user; the public key is published through a public channel, and the private key is sent to the corresponding signing user through a secure channel; The user signature module is used to sign the private key and system parameters distributed by the user through the trusted key generation center, use the signature algorithm to sign the message, and send the generated signature, message, timestamp and respective public keys to the aggregation server; Aggregate signature module, which is used for the aggregation server to receive signatures, messages, timestamps and public key information of multiple signing users, execute the aggregation algorithm, merge multiple signatures into an aggregate signature, and send the aggregate signature and related information to the verification server; The verification module is used to verify that the server receives the aggregate signature and related information sent by the aggregation server, and uses the system parameters provided by the trusted key generation center and the public key of the aggregation server to verify the aggregate signature to ensure the integrity and correctness of the signature, thereby verifying the source and authenticity of the message.
[0021] An embedded system using a quantum-safe aggregate signature method, comprising: The trusted key generation center is configured with a Ring Grid-based cryptographic system to initialize system parameters. It generates a pair of keys for each signing user, including a public key and a private key. The public key is published through a public channel, and the private key is sent to the corresponding signing user through a secure channel. The signing user is configured with a private key and system parameters distributed by a trusted key generation center, signs the message using a signature algorithm, and sends the generated signature, message, timestamp, and respective public key to the aggregation server; The aggregation server is configured to receive signatures, messages, timestamps, and public key information of multiple signing users, execute an aggregation algorithm, merge the multiple signatures into an aggregate signature, and send the aggregate signature and related information to the verification server; The verification server is configured to receive the aggregate signature and related information sent by the aggregation server, and verify the aggregate signature using the system parameters provided by the trusted key generation center and the public key of the aggregation server to ensure the integrity and correctness of the signature, thereby verifying the source and authenticity of the message.
[0022] Due to the adoption of the above technical solution, the present invention has the following advantages and positive effects compared with the prior art: A quantum-safe aggregate signature method for embedded systems, according to one embodiment of the present invention, initializes system parameters using a ring-based cryptographic system at a trusted key generation center (KGC). A key pair is generated for each signing user. The signing user uses the private key and system parameters distributed by the KGC to sign a message using a signature algorithm, and then sends the generated signature, message, and respective public keys to an aggregation server. The aggregation server receives the signatures, messages, and public key information of multiple signing users, executes an aggregation algorithm, combines the multiple signatures into an aggregate signature, and sends the aggregate signature and related information to a verification server. The verification server verifies the aggregate signature using the system parameters provided by the KGC and the public key of the aggregation server to ensure the integrity and correctness of the signature, thereby verifying the source and authenticity of the message. Compared to methods that verify signatures one by one, this method has the advantages of high computational efficiency, low storage resource usage, small amount of communication information, and quantum security. It is suitable for embedded systems with numerous edge nodes and limited computing resources, such as secure communication in drone swarms, secure communication with medical wireless sensors, intelligent connected vehicles, and even secure satellite communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 Schematic diagram of the aggregation signature; Figure 2 This is a flow chart of a quantum-safe aggregate signature method applicable to embedded systems in one embodiment of the present invention; Figure 3 A diagram showing the relationships between the various roles in a quantum-secure aggregate signature in one embodiment of the present invention. DETAILED DESCRIPTION
[0024] The following is a detailed description of a quantum-safe aggregate signature method and apparatus for embedded systems proposed by the present invention, with reference to the accompanying drawings and specific embodiments. The advantages and features of the present invention will become more apparent from the following description and claims.
[0025] Based on the problem of error-prone learning on a ring lattice, this embodiment designs a quantum-secure aggregate signature method suitable for embedded systems. This method has the characteristics of high computational efficiency, small storage resource usage, and small total amount of communication information. It can solve various embedded application scenarios. Problems such as limited computing power of embedded device resources, insufficient storage resources, and insufficient communication bandwidth can achieve efficient signature and verification.
[0026] Please see Figure 2 The quantum-safe aggregate signature method for embedded systems includes the following steps: The trusted key generation center is configured with a Ring Grid-based cryptographic system to initialize system parameters. It generates a pair of keys for each signing user, including a public key and a private key. The public key is published through a public channel, and the private key is sent to the corresponding signing user through a secure channel. The signing user is configured with a private key and system parameters distributed by a trusted key generation center, signs the message using a signature algorithm, and sends the generated signature, message, timestamp, and respective public key to the aggregation server; The aggregation server is configured to receive signatures, messages, timestamps, and public key information of multiple signing users, execute an aggregation algorithm, merge the multiple signatures into an aggregate signature, and send the aggregate signature and related information to the verification server; The verification server is configured to receive the aggregate signature and related information sent by the aggregation server, and verify the aggregate signature using the system parameters provided by the trusted key generation center and the public key of the aggregation server to ensure the integrity and correctness of the signature, thereby verifying the source and authenticity of the message.
[0027] Specifically, in the trusted key generation center's ring-based cryptographic system, the system parameter initialization step primarily involves initializing all parameters used in the system, particularly key generation. Only after completing this phase can the system operate normally. This primarily involves the following steps: (1) The trusted key generation center first selects a large prime number ; (2) The trusted key generation center selects , and calculate )+ ), (3) Select a one-way collision-resistant hash function : , respectively input the low bit generated in step (2) for each user Output ) ; (4) The trusted key distribution center selects public parameters ; (5) The trusted key distribution center calculates the , as the user's public key; (6) The private key is sent to every Internet user through a secure channel, and the public key can be published through an open channel.
[0028] (7) In addition, during the key generation phase, a public key will be generated for the aggregation server according to the above method. , private key .
[0029] In step (1), the large prime number Taking 16760833, it effectively resists future decomposition attacks without affecting computing power.
[0030] In step (2), is a cyclotomic polynomial ring finite field where , is the highest order polynomial, . It is taken from A sample of are the polynomial coefficients, They are and High bit, They are and The low bit of As a hash function : When the input is , the output result is ), and The combination serves as the user's private key.
[0031] The user executes the signature algorithm, which includes the following steps: (1) Users generate plaintext based on their own circumstances , and generate a timestamp based on the current time ; (2) User i selects , ,in, yes A subdomain of ;calculate ; (3) User i calculates and ; Check if it exists , , if it does not exist, re-execute the above steps; (4) User i calculates and ; User check if it exists , , if it is not true, then start again from step (1); (5) As the user's signature result , and messages , timestamp Sent to the aggregation server for verification.
[0032] In step (3), yes A subdomain of Select samples as well as .
[0033] In step (4), H2: → is a collision-resistant hash function, is a set of polynomials with a specific sparsity, in which the degree of the polynomial is , contains at most 32 non-zero coefficients, and the non-zero coefficients can only take the value +1 or -1. It will The result obtained as the input of H2 is used to bind these parameters and prevent attackers from tampering with them. yes A subdomain of , where each polynomial coefficient is in ]between.
[0034] The aggregation server executes the signature aggregation algorithm, which includes the following steps: (1) Set a maximum time interval , and get the timestamp at this time ,if , then proceed; otherwise the signature will not be passed; (2) Inspection If not, the signature is considered invalid and will not be verified; if so, the following steps are performed; (3) The received As input, step by step calculation Is it consistent with the received The values are the same, if they are different, the signature result will be discarded directly and will not participate in the aggregation. The signature result of . .
[0035] (4) Calculation .
[0036] The aggregator generates the signature in the same way as the individual signatures. , get the timestamp at this time The aggregator performs a similar process to a single signature, calculating , ; calculate and ; Then calculate , . ,Aggregate signature results , and timestamp The data is sent together to the verification server for aggregate signature verification.
[0037] The authentication server executes the authentication algorithm, which includes the following steps: The verifier is required to be trusted and obtain the timestamp at this time ,if , then continue; otherwise, do not proceed with the subsequent aggregation process.
[0038] calculate , then calculate ,in is the public key of the aggregation server.
[0039] Is it true? If so, all signatures are verified successfully; if not, at least one signature in the aggregation group is illegal.
[0040] If they are the same, all signatures are verified. If they are not the same, at least one signature in the aggregation group is illegal. In this case, there is no need to discard all signatures. A binary search method can be designed to verify some signatures to improve system efficiency.
[0041] For the test formula: , the following correctness verification can be performed: According to the relationship between the above parameters, the following calculation results can be obtained: For this formula, we can continue to simplify it to For example, there are: because ,therefore .
[0042] Therefore, when each signature in the aggregate signature is legal, there exists , the correctness of the aggregate signature is demonstrated. If the result of the aggregate signature fails to be verified, it means that there is at least one signature error in the aggregated signature group, that is, any error in the signature in the aggregation group will lead to an error in the result verification.
[0043] This embodiment designs an aggregate signature based on a ring lattice, which has the characteristics of quantum security and lightweight, a simple calculation process, a fast running speed, and a higher verification efficiency than the verification of traditional non-aggregate digital signatures. At the same time, this solution has low requirements for storage and calculation. In terms of calculation, the aggregate signature also disperses the computing pressure at different time nodes. Each signature received only needs to be aggregated and processed, and then unified verification is performed, which reduces the computing pressure. After each aggregate signature frame is received in the data storage, no additional storage space is required to store all the received signatures, and the memory space can be effectively reused. Finally, the design based on the ring lattice improves the computing efficiency of the solution and makes the ciphertext more compact, so that the solution can meet the needs of various embedded system scenarios, run smoothly on various embedded devices, and have quantum security.
[0044] Based on the same concept, this embodiment also provides a quantum-safe aggregate signature device suitable for embedded systems, including: The key generation module is used by the trusted key generation center to initialize system parameters based on the ring grid cryptographic system; a pair of keys, including a public key and a private key, is generated for each signing user; the public key is published through a public channel, and the private key is sent to the corresponding signing user through a secure channel; The user signature module is used to sign the private key and system parameters distributed by the user through the trusted key generation center, use the signature algorithm to sign the message, and send the generated signature, message, timestamp and respective public keys to the aggregation server; Aggregate signature module, which is used for the aggregation server to receive signatures, messages, timestamps and public key information of multiple signing users, execute the aggregation algorithm, merge multiple signatures into an aggregate signature, and send the aggregate signature and related information to the verification server; The verification module is used to verify that the server receives the aggregate signature and related information sent by the aggregation server, and uses the system parameters provided by the trusted key generation center and the public key of the aggregation server to verify the aggregate signature to ensure the integrity and correctness of the signature, thereby verifying the source and authenticity of the message.
[0045] This device is used to implement the above-mentioned quantum-secure aggregate signature method, and its implementation method is similar and will not be repeated here.
[0046] The above-mentioned quantum-secure aggregate signature method is applicable to various embedded systems with numerous edge nodes and limited computing resources, such as secure communication in drone clusters, secure communication in medical wireless sensors, intelligent connected vehicles, and even secure satellite communication. Based on this, this embodiment also provides an embedded system using the quantum-secure aggregate signature method, including: The trusted key generation center is configured with a Ring Grid-based cryptographic system to initialize system parameters. It generates a pair of keys for each signing user, including a public key and a private key. The public key is published through a public channel, and the private key is sent to the corresponding signing user through a secure channel. The signing user is configured with a private key and system parameters distributed by a trusted key generation center, signs the message using a signature algorithm, and sends the generated signature, message, timestamp, and respective public key to the aggregation server; The aggregation server is configured to receive signatures, messages, timestamps, and public key information of multiple signing users, execute an aggregation algorithm, merge the multiple signatures into an aggregate signature, and send the aggregate signature and related information to the verification server; The verification server is configured to receive the aggregate signature and related information sent by the aggregation server, and verify the aggregate signature using the system parameters provided by the trusted key generation center and the public key of the aggregation server to ensure the integrity and correctness of the signature, thereby verifying the source and authenticity of the message.
[0047] Please see Figure 3 During the system initialization phase, the trusted key generation center generates the main system parameters, and then the users in the system sign the messages. The signature algorithm of this embodiment can run quickly on various embedded devices. Figure 3 The user in the scheme can be a user node in a sensor, mobile phone, or user PC. After signing, the signature result is sent to an aggregation server for signature aggregation, and finally to a verification server for signature verification. Taking a medical sensor network as an example, the user node represents different medical sensor data. After the data is signed by the signature algorithm, the data and its signature result are sent together to the aggregation server, which can be a laptop, a remote server, or other device. After the data is aggregated, it is sent to the verification server, which can also be a laptop, a remote server, or other device. In theory, the functions of aggregator and verifier can be performed by the same device or by different devices. However, both the aggregator and the verifier must be trustworthy. In the medical sensor network scenario, these devices should be owned by the hospital to ensure data security during management. In addition to medical sensor networks, this solution can be used in most multi-node-to-one-node networks. This solution can play an important role in intelligent connected vehicle cellular networks, drone networks, satellite networks, and industrial IoT sensor networks.
[0048] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings, but the present invention is not limited to the above embodiments. Even if various changes are made to the present invention, if these changes fall within the scope of the claims of the present invention and their equivalents, they still fall within the scope of protection of the present invention.
Claims
1. A quantum-safe aggregate signature method for embedded systems, characterized in that: include: The trusted key generation center initializes system parameters based on the ring grid cryptographic system; Generate a pair of keys for each signing user, including a public key and a private key. The public key is published through a public channel, and the private key is sent to the corresponding signing user through a secure channel. The signing user uses the private key and system parameters distributed by the trusted key generation center to sign the message using the signature algorithm, and sends the generated signature, message and their respective public keys to the aggregation server; The aggregation server receives signatures, messages, and public key information of multiple signing users, executes the aggregation algorithm, combines multiple signatures into an aggregate signature, and sends the aggregate signature and related information to the verification server; The verification server receives the aggregate signature and related information sent by the aggregation server, and verifies the aggregate signature using the system parameters provided by the trusted key generation center and the public key of the aggregation server to ensure the integrity and correctness of the signature, thereby verifying the source and authenticity of the message.
2. The quantum-safe aggregate signature method for embedded systems according to claim 1, wherein: The trusted key generation center initializes system parameters based on the Ring Grid cryptographic system and generates a pair of keys for each signing user, further including: Select a large prime number , select for each signing user , and calculate + ,in yes High bit, for The low bit, ;in, is a cyclotomic polynomial ring finite field, , is the highest order polynomial, ; It is taken from A sample of are the polynomial coefficients, They are and High bit, They are and The low bit of As a hash function : When the input is , the output result is ), and Combined together as the user's private key; Choose a one-way collision-resistant hash function : , respectively for each signing user to set the low bit As input to this hash function, the output ) ; Select public parameters ; Calculated for each signing user , as the user's public key; Will The private key is sent to each signing user through a secure channel, and the public key is published through a public channel; During the key generation phase, a public key is generated for the aggregation server according to the above method. , private key .
3. The quantum-safe aggregate signature method for embedded systems according to claim 1, wherein: The signing user uses the private key and system parameters distributed by the trusted key generation center to sign the message using the signature algorithm, which further includes: The plaintext of the signing user is defined as m i , and generate a timestamp based on the current time ; User i selects , ,in, yes A subdomain of ;calculate ; User i calculates and ; Check if it exists , If it does not exist, then re-execute the above steps; yes subdomains of; Will As the user's signature, and with the message mi, timestamp Sent to the aggregation server for verification.
4. The quantum-safe aggregate signature method for embedded systems according to claim 1, wherein: The aggregation server receives signatures, messages, and public key information of multiple signing users, executes an aggregation algorithm, and combines multiple signatures into an aggregate signature, further including: Set a maximum time interval , and get the timestamp at this time ,like , then continue; otherwise, discard the signature and do not proceed with the subsequent aggregation process; test If not, the signature is considered invalid and will not be verified; if so, the following steps are performed; Will receive As input, step by step calculation Is it consistent with the received The values are the same, if they are different, the signature result will be discarded directly and will not participate in the aggregation; The signature result of ; calculate ; The aggregator generates the signature in the same way as the individual signatures. , get the timestamp at this time ; Aggregators perform calculations , ; calculate and ; Then calculate , ; , and , timestamp The data is sent together to the verification server for aggregate signature verification.
5. The quantum-safe aggregate signature method for embedded systems according to claim 1, wherein: The verification server receives the aggregate signature and related information sent by the aggregation server, and verifies the aggregate signature using the system parameters provided by the trusted key generation center and the public key of the aggregation server, further comprising: Get the timestamp at this time ,like , then continue; otherwise, do not proceed with the subsequent aggregation process; calculate , then calculate ; Is it true? If so, all signatures are verified successfully; if not, at least one signature in the aggregation group is illegal.
6. The quantum-safe aggregate signature method for embedded systems according to claim 5, wherein: When at least one signature in the aggregation group is illegal, some signatures are verified using the binary search method to improve verification efficiency.
7. A quantum-safe aggregate signature device suitable for embedded systems, characterized in that: include: The key generation module is used for the trusted key generation center based on the ring grid cryptographic system to initialize system parameters; Generate a pair of keys for each signing user, including a public key and a private key. The public key is published through a public channel, and the private key is sent to the corresponding signing user through a secure channel. The user signature module is used to sign the private key and system parameters distributed by the user through the trusted key generation center, use the signature algorithm to sign the message, and send the generated signature, message, timestamp and respective public keys to the aggregation server; Aggregate signature module, which is used for the aggregation server to receive signatures, messages, timestamps and public key information of multiple signing users, execute the aggregation algorithm, merge multiple signatures into an aggregate signature, and send the aggregate signature and related information to the verification server; The verification module is used to verify that the server receives the aggregate signature and related information sent by the aggregation server, and uses the system parameters provided by the trusted key generation center and the public key of the aggregation server to verify the aggregate signature to ensure the integrity and correctness of the signature, thereby verifying the source and authenticity of the message.
8. An embedded system using a quantum-safe aggregate signature method, characterized in that: include: The trusted key generation center is configured as a ring-based cryptographic system to initialize system parameters; Generate a pair of keys for each signing user, including a public key and a private key. The public key is published through a public channel, and the private key is sent to the corresponding signing user through a secure channel. The signing user is configured with a private key and system parameters distributed by a trusted key generation center, signs the message using a signature algorithm, and sends the generated signature, message, timestamp, and respective public key to the aggregation server; The aggregation server is configured to receive signatures, messages, timestamps, and public key information of multiple signing users, execute an aggregation algorithm, merge the multiple signatures into an aggregate signature, and send the aggregate signature and related information to the verification server; The verification server is configured to receive the aggregate signature and related information sent by the aggregation server, and verify the aggregate signature using the system parameters provided by the trusted key generation center and the public key of the aggregation server to ensure the integrity and correctness of the signature, thereby verifying the source and authenticity of the message.
Citation Information
Cited By
General aggregation signature method and system based on partial aggregation
CN121664429A