Lattice-based two-party collaborative signature generation method and system based on Gaussian convolution
Through the Lattice-based two-party collaborative signature method based on Gaussian convolution, the inefficiency problem caused by the restart of the Lattice-based collaborative signature in the multi-party collaboration process is solved, and an efficient and secure signing process is achieved. It is suitable for applications such as distributed key management and blockchain, and has anti-quantum computing capabilities.
Patent Information
- Application Number
- CN202510923732.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2025-09-30
AI Technical Summary
The existing lattice-based collaborative signature scheme is prone to inefficiency due to restarts during the multi-party collaborative signature process, is difficult to apply in practical scenarios, and lacks protection against single point failures.
A lattice-based two-party collaborative signature method based on Gaussian convolution is adopted. System parameters are generated through security parameters. The participating parties generate partial public keys and private keys, and calculate the system public key. The signing process does not require restart. Gaussian convolution technology is used to avoid private key information leakage and improve signature efficiency.
It realizes an efficient and secure signing process in a distributed key management system, prevents single point failure, is suitable for application scenarios such as blockchain and PKI systems, and has anti-quantum computing capabilities.
Smart Images

Figure CN120729533A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and more specifically, to a lattice-based two-party collaborative signature generation method and system based on Gaussian convolution. Background Art
[0002] As a key technology in the public key cryptography system, digital signatures enable recipients to reliably verify the authenticity of the data source, ensure the integrity of the content, and effectively prevent forgery by embedding cryptographic-based verification information in the data. To meet the specific needs of different application scenarios, this technology has spawned a variety of enhanced signature schemes: ring signatures protect identity privacy by allowing signers to sign anonymously within a preset group; blind signatures enable signers to complete signatures without knowing the specific content, making them particularly suitable for scenarios requiring high privacy protection; aggregate signatures optimize the verification process by efficiently merging multiple signatures, significantly improving the processing efficiency of systems such as blockchains; and non-repudiation signatures prevent signers from subsequently denying their rights through an interactive verification mechanism, providing stronger legal binding force for applications such as electronic contracts. These innovative solutions effectively expand the application boundaries of digital signatures while maintaining basic security features.
[0003] Multi-Party Signing (MPS) is a distributed key management mechanism whose core feature is the division of the full signing key into multiple shards, each of which is maintained by two or more independent devices. During the signature generation process, all participating devices must collaborate to complete a valid signature. A single device, holding only a shard of the key, cannot independently generate a valid signature. Through key sharding and distributed computing, this mechanism ensures that even if an attacker fully controls a device, they cannot obtain the complete key or forge a valid signature, significantly improving the security of key storage and signing operations. This design is particularly suitable for high-security applications that require protection against single points of failure.
[0004] Fiat-Shamir Lattice Signatures Based on Convolved Gaussians were proposed by Devevey et al. at the 2023 Asian Cryptography Conference. Compared to previous lattice signatures based on flooding technology and restart (Fiat-Shamir with Abort) technology, its signature size is more compact and the signature efficiency is higher. Current lattice-based collaborative signature schemes are mostly proposed based on restart technology. However, in the multi-party collaborative signature process, the restart of one party often causes the restart of multiple parties, which greatly reduces the signature efficiency and makes it difficult to apply in practical scenarios. No one has yet proposed a restart-free lattice-based collaborative signature. Summary of the Invention
[0005] Based on lattice signature technology based on Gaussian convolution, this paper proposes a new lattice-based two-party collaborative signature generation method and system. Applied to two-party distributed scenarios, this method effectively mitigates the risk of single point failures, and the signing process is restart-free. While ensuring signature accuracy and unforgeability, this solution significantly improves the properties of lattice-based collaborative signatures. Furthermore, the two-party condition can be freely extended to multiple parties, facilitating the practical application of post-quantum collaborative signature technology.
[0006] To achieve the above objectives, the present invention provides a first aspect of a lattice-based two-party collaborative signature generation method based on Gaussian convolution, comprising: Based on the security parameters, output system parameters; The collaborative signature participant generates a partial public key and its own private key based on the system parameters, obtains the other party's partial public key from the other party, and calculates the system public key based on the partial public key generated by itself and the partial public key obtained from the other party; The parties involved in the collaborative signature perform collaborative signing based on system parameters, the message to be signed, and the private key to obtain the final signature; The verifier verifies the final signature based on the system parameters, the message to be verified, the final signature, and the system public key.
[0007] In one embodiment, outputting system parameters based on security parameters includes: Choosing a hash function ,in, is a polynomial ring, Represent the dimensions of matrix and vector respectively, is the modulus; Given an upper bound parameter ,distributed ; Output system parameters .
[0008] In one embodiment, a collaborative signing party generates a partial public key and its own private key based on system parameters, obtains a partial public key from another party, and calculates a public key based on the partial public key generated by itself and the partial public key obtained from the other party, including: The parties involved in the collaborative signature extract a second random matrix and a second vector; Calculating a second hash value based on the extracted random matrix and vector, sending the second random matrix, the second vector, and the second hash value to another participant, and obtaining the first hash value, the first random matrix, and the first vector from the other participant; Check whether the hash value obtained from the other party is correct. If correct, calculate the intermediate matrix and intermediate vector; When the preset conditions are met, the combined vector is obtained according to the extracted random vector combination and used as one's own private key; Extracting a matrix having a specific form as a partial public key, calculating a third hash value, sending the third hash value, the partial public key, and the intermediate vector to another participant, and simultaneously obtaining a fourth hash value, the partial public key, and the intermediate vector from the other participant; Check whether the hash value obtained from the other party is correct. If correct, calculate the system public key based on the partial public key generated by itself and the partial public key obtained from the other party.
[0009] In one embodiment, when a preset condition is met, a combined vector is obtained based on the extracted random vector combination as one's own private key, including: Extract random vector combinations ,in, is a centered binomial distribution, 、 are two vectors; Calculating vectors ,in, is the middle vector, is the intermediate matrix, is a vector; Running the bit decomposition algorithm yields , is the bit decomposition algorithm, is the bit decomposition parameter, is the result of decomposition, where is the low bit obtained after decomposition, is the high bit obtained after decomposition; Combine to get the combined vector , as the private key.
[0010] In one embodiment, the collaborative signing parties perform collaborative signing based on system parameters, the message to be signed, and the private key to obtain a final signature, including: After extracting the vector based on the system parameters and the private key, the second commitment is calculated and the first commitment is obtained from the other party; Calculate its own second signature based on the system parameters, the message to be signed, and the private key, and obtain the first signature from the other party; The second part of the signature is calculated by itself and the first part of the signature is obtained from the other party.
[0011] In one embodiment, after extracting the vector based on the system parameters and the private key, calculating the second commitment and obtaining the first commitment from the other party include: Extract vector , calculate the second commitment vector ,in, is the private key of the second party, is a matrix; Calculate the commitment key , is a hash function, Messages waiting to be signed; Calculate the second commitment and send it to the first party , Commit is the random number generated during the commitment calculation (which will be used as part of the second signature). From the first party Get the first commitment , , The first commitment vector computed for the first party, A random number (which will be used as part of the first signature).
[0012] In one embodiment, the verifier verifies the final signature based on the system parameters, the message to be verified, the final signature, and the system public key, including: judge Is it true? If it is true, continue; otherwise, return 0 to exit. For the final signature part, The signature can be bounded by the norm; Compute the commitment key for the verification process , and hash value , For the final promise, ; Calculate the median value , For partial signature, , 、 Sign the first and second parts respectively. is a predefined vector; judge Is it true? If it is true, output 1, otherwise return 0. Open the algorithm for commitment, Indicates a portion of the final signature.
[0013] Based on the same inventive concept, the second aspect of the present invention provides a lattice-based two-party collaborative signature generation system based on Gaussian convolution, comprising: System initialization module, used to output system parameters based on security parameters; A key generation module is used for a collaborative signing participant to generate a partial public key and its own private key based on system parameters, obtain a partial public key from another participant, and calculate a system public key based on the partial public key generated by itself and the partial public key obtained from the other participant; The collaborative signature module is used by the collaborative signing parties to perform collaborative signing based on system parameters, the message to be signed, and the private key to obtain the final signature; The verification module is used by the verifier to verify the final signature based on the system parameters, the message to be verified, the final signature and the system public key.
[0014] Based on the same inventive concept, the third aspect of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the Gaussian convolution-based two-party collaborative signature generation method described in the first aspect.
[0015] Based on the same inventive concept, the fourth aspect of the present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the program, the Gaussian convolution-based two-party collaborative signature generation method based on lattice basis described in the first aspect is implemented.
[0016] Compared with the prior art, the advantages and beneficial technical effects of the present invention are as follows: The present invention provides a lattice-based two-party collaborative signature generation method based on Gaussian convolution, comprising: outputting system parameters based on security parameters; the collaborative signature participants generate partial public keys and their own private keys according to the system parameters, obtain the other party's partial public key from the other party, and calculate the system public key based on the partial public key generated by themselves and the partial public key obtained from the other party; the collaborative signature participants perform collaborative signing based on the system parameters, the message to be signed and the private key to obtain a final signature; the verifier verifies the final signature based on the system parameters, the message to be verified, the final signature and the system public key. The present invention utilizes Gaussian convolution technology to avoid restarting, effectively prevents the leakage of private key information, and improves the efficiency of collaborative signature. In general, the present invention has the advantages of high security, complete functions, high computational efficiency, etc., has a great driving effect on the application of anti-quantum cryptographic algorithms, and is suitable for various application scenarios such as blockchain and PKI systems under the background of distributed key management. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 4 is an overall flow chart of a method for generating a collaborative signature based on a lattice two-party signature using Gaussian convolution in an embodiment of the present invention; Figure 2 This is a flowchart of key generation in an embodiment of the present invention; Figure 3 A flowchart of collaborative signature and verification generation in an embodiment of the present invention; Figure 4 This is a structural diagram of a lattice-based two-party collaborative signature generation system based on Gaussian convolution in an embodiment of the present invention. DETAILED DESCRIPTION
[0019] This invention discloses a lattice-based two-party collaborative signature method and system based on Gaussian convolution. This method utilizes Gaussian convolution technology to avoid restarts, effectively preventing the leakage of private key information and improving collaborative signature efficiency. This method offers advantages such as high security, comprehensive functionality, and high computational efficiency. It significantly promotes the application of quantum-resistant cryptographic algorithms and is suitable for a variety of applications, including blockchain and PKI systems, within the context of distributed key management.
[0020] Example 1 This embodiment provides a lattice-based two-party collaborative signature generation method based on Gaussian convolution. Figure 1 ,include: S1: Output system parameters based on security parameters; S2: The collaborative signature participant generates a partial public key and its own private key based on the system parameters, obtains the other party's partial public key from the other party, and calculates the system public key based on the partial public key generated by itself and the partial public key obtained from the other party; S3: The collaborative signing parties perform collaborative signing based on the system parameters, the message to be signed, and the private key to obtain the final signature; S4: The verifier verifies the final signature based on the system parameters, the message to be verified, the final signature, and the system public key.
[0021] First, the characters involved in the present invention are explained and illustrated: : Polynomial ring .
[0022] : Security parameters.
[0023] : Dimension of matrix and vector.
[0024] : represents a vector.
[0025] : represents a matrix.
[0026] : Central binomial distribution.
[0027] : Modulo operation.
[0028] :one dimensional square matrix, The elements are polynomials .
[0029] :matrix The maximum singular value of .
[0030] The upper limit of the conditions for rejecting samples during key generation.
[0031] : The signature can be upper bounded by the norm.
[0032] : and connection.
[0033] : Hash function.
[0034] : Commitment value.
[0035] : Commitment algorithm.
[0036] : Commit to opening the algorithm.
[0037] : Bit decomposition algorithm.
[0038] : Collaborative signature participants.
[0039] : .
[0040] : covariance matrix.
[0041] : The message value to be signed.
[0042] : Commitment key.
[0043] : is a predefined vector, .
[0044] Specifically, S1 is system initialization, which inputs security parameters and outputs system parameters as the basis for subsequent steps. S2 is key generation, where the collaborative signing parties (P1 and P2) generate keys based on the system parameters. S3 is when the collaborative signing parties perform their collaborative signing, and S4 is when the verifier verifies the final signature.
[0045] Among them, S1 can be achieved in the following ways: Choosing a hash function ,in, is a polynomial ring, Represent the dimensions of matrix and vector respectively, is the modulus; Given an upper bound parameter ,distributed ; Output system parameters .
[0046] S2 can be implemented in the following ways: The parties involved in the collaborative signature extract a second random matrix and a second vector; Calculating a second hash value based on the extracted random matrix and vector, sending the second random matrix, the second vector, and the second hash value to another participant, and obtaining the first hash value, the first random matrix, and the first vector from the other participant; Check whether the hash value obtained from the other party is correct. If correct, calculate the intermediate matrix and intermediate vector; When the preset conditions are met, the combined vector is obtained according to the extracted random vector combination and used as one's own private key; Extracting a matrix having a specific form as a partial public key, calculating a third hash value, sending the third hash value, the partial public key, and the intermediate vector to another participant, and simultaneously obtaining a fourth hash value, the partial public key, and the intermediate vector from the other participant; Check whether the hash value obtained from the other party is correct. If correct, calculate the system public key based on the partial public key generated by itself and the partial public key obtained from the other party.
[0047] See Figure 2 , which is a flowchart of key generation in an embodiment of the present invention. In the specific implementation process, the second party As an example, the specific implementation process of key generation is explained. Enter the system parameters , The execution steps are as follows: a) Extract random matrices and vectors , ; b) Calculate the hash value ; c) Send to ; d) From Obtained ; e) Inspection Is it true? If so, continue; otherwise, return 0 and exit. f) Calculate intermediate matrices and vectors ; g) Combine the extracted random vectors to obtain a combined vector as your own private key; h) Extract matrices with a specific form , calculate the hash value ; i) will Send to ; j) From Get the hash value, partial public key and intermediate vector ; k) Inspection Is it true? If so, calculate the public key ,reserve ; Otherwise, it returns 0. Here, The private key is .
[0048] Specifically, when the preset conditions are met, a combination vector is obtained based on the extracted random vector combination as its own private key, including: Extract random vector combinations ,in, is a centered binomial distribution, 、 are two vectors; Calculating vectors ,in, is the middle vector, is the intermediate matrix, is a vector; Running the bit decomposition algorithm yields , is the bit decomposition algorithm, is the bit decomposition parameter, is the result of decomposition, where is the low bit obtained after decomposition, is the high bit obtained after decomposition; Combine to get the combined vector , as the private key.
[0049] The preset conditions are: satisfying the matrix maximum singular value judgment condition .
[0050] S3 can be implemented in the following ways: After extracting the vector based on the system parameters and the private key, the second commitment is calculated and the first commitment is obtained from the other party; Calculate its own second signature based on the system parameters, the message to be signed, and the private key, and obtain the first signature from the other party; The second part of the signature is calculated by itself and the first part of the signature is obtained from the other party.
[0051] In the specific implementation process, the second party Take this as an example to illustrate the specific implementation process of collaborative signature: Enter system parameters , Message to be signed , private key , The execution steps are as follows: a) Extract vector , calculate the second commitment vector ; b) Calculate the second commitment key ; c) Calculate the second commitment and send it to , To calculate the random number generated in the commitment process; d) From Get the first commitment ; e) Calculate the hash value ; f) Extract elements ; g) Calculate vector ; h) Sign the second part Send to ,from Get the first signature ; i) Output the final signature .
[0052] See Figure 3 , which is a flowchart of collaborative signature and verification generation in an embodiment of the present invention. S4 can be implemented in the following ways: judge Is it true? If it is true, continue; otherwise, return 0 to exit. For the final signature part, The signature can be bounded by the norm; Compute the commitment key for the verification process , and hash value , For the final promise, ; Calculate the median value , For partial signature, , 、 Sign the first and second parts respectively. is a predefined vector; judge Is it true? If it is true, output 1, otherwise return 0. Open the algorithm for commitment, Indicates a portion of the final signature.
[0053] Compared with the prior art, the present invention has the following advantages and beneficial effects: 1. A lattice-based two-party collaborative signature without restart has not yet been proposed. This paper designs a new lattice-based two-party collaborative signature based on Gaussian convolution. The signing process does not have restart, is suitable for distributed key management systems, and has good application prospects.
[0054] 2. The present invention uses the lattice difficulty problem assumption as a security guarantee and has the ability to resist quantum computer attacks.
[0055] Example 2 Based on the same inventive concept, this embodiment discloses a lattice-based two-party collaborative signature generation system based on Gaussian convolution, see Figure 4 ,include: The system initialization module 101 is used to output system parameters based on security parameters; Key generation module 102, for a collaborative signing participant to generate a partial public key and its own private key based on system parameters, obtain a partial public key from another participant, and calculate a system public key based on the partial public key generated by itself and the partial public key obtained from the other participant; Collaborative signature module 103, used for collaborative signing by the parties based on system parameters, the message to be signed and the private key to obtain the final signature; The verification module 104 is used for the verifier to verify the final signature based on the system parameters, the message to be verified, the final signature and the system public key.
[0056] Since the system of the second embodiment of the present invention is the system used in the method of the first embodiment, those skilled in the art will be able to understand the specific structure and variations of the system based on the method described in the first embodiment of the present invention, and therefore will not be described in detail here. All systems used in the method of the first embodiment of the present invention fall within the scope of protection of the present invention.
[0057] Example 3 Based on the same inventive concept, the present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the Gaussian convolution-based lattice two-party collaborative signature generation method of embodiment one.
[0058] Since the computer-readable storage medium described in Example 3 of the present invention is used to implement the Gaussian convolution-based lattice-based two-party collaborative signature generation method described in Example 1 of the present invention, the specific structure and variations of the computer-readable storage medium are readily understood by those skilled in the art based on the method described in Example 1 of the present invention, and thus will not be further described here. All computer-readable storage media used in the method of Example 1 of the present invention fall within the scope of protection of the present invention.
[0059] Example 4 Based on the same inventive concept, the present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in Embodiment 1 when executing the program.
[0060] Since the computer device described in Example 4 of the present invention is the computer device used to implement the Gaussian convolution-based lattice-based two-party collaborative signature generation method described in Example 1 of the present invention, the specific structure and variations of the computer device are readily understood by those skilled in the art based on the method described in Example 1 of the present invention, and thus will not be further described here. All computer devices used in the method of Example 1 of the present invention fall within the scope of protection of the present invention.
[0061] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0062] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0063] Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they are aware of the basic inventive concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention. Obviously, those skilled in the art may make various changes and modifications to the embodiments of the present invention without departing from the spirit and scope of the embodiments of the present invention. Thus, the present invention is intended to include such changes and modifications to the embodiments of the present invention if they fall within the scope of the claims and their equivalents.
Claims
1. A lattice-based two-party collaborative signature generation method based on Gaussian convolution, characterized in that: include: Based on the security parameters, output system parameters; The collaborative signature participant generates a partial public key and its own private key based on the system parameters, obtains the other party's partial public key from the other party, and calculates the system public key based on the partial public key generated by itself and the partial public key obtained from the other party; The parties involved in the collaborative signature perform collaborative signing based on system parameters, the message to be signed, and the private key to obtain the final signature; The verifier verifies the final signature based on the system parameters, the message to be verified, the final signature, and the system public key.
2. The method for generating a two-party collaborative signature based on a lattice based on Gaussian convolution according to claim 1, wherein: Based on the security parameters, output system parameters, including: Choosing a hash function ,in, is a polynomial ring, Represent the dimensions of matrix and vector respectively, is the modulus; Given an upper bound parameter ,distributed ; Output system parameters .
3. The method for generating a two-party collaborative signature based on a lattice based on Gaussian convolution according to claim 2, wherein: Each party in the collaborative signature generates a partial public key and its own private key based on system parameters, obtains a partial public key from the other party, and calculates a public key based on the partial public key it generates and the partial public key obtained from the other party, including: The parties involved in the collaborative signature extract a second random matrix and a second vector; Calculating a second hash value based on the extracted random matrix and vector, sending the second random matrix, the second vector, and the second hash value to another participant, and obtaining the first hash value, the first random matrix, and the first vector from the other participant; Check whether the hash value obtained from the other party is correct. If correct, calculate the intermediate matrix and intermediate vector; When the preset conditions are met, the combined vector is obtained according to the extracted random vector combination and used as one's own private key; Extracting a matrix having a specific form as a partial public key, calculating a third hash value, sending the third hash value, the partial public key, and the intermediate vector to another participant, and simultaneously obtaining a fourth hash value, the partial public key, and the intermediate vector from the other participant; Check whether the hash value obtained from the other party is correct. If correct, calculate the system public key based on the partial public key generated by itself and the partial public key obtained from the other party.
4. The method for generating a two-party collaborative signature based on a lattice based on Gaussian convolution according to claim 3, wherein: When the preset conditions are met, the combined vector is obtained according to the extracted random vector combination as its own private key, including: Extract random vector combinations ,in, is a centered binomial distribution, 、 are two vectors; Calculating vectors ,in, is the middle vector, is the intermediate matrix, is a vector; Running the bit decomposition algorithm yields , is the bit decomposition algorithm, is the bit decomposition parameter, is the result of decomposition, where is the low bit obtained after decomposition, is the high bit obtained after decomposition; Combine to get the combined vector , as the private key.
5. The method for generating a two-party collaborative signature based on a lattice based on Gaussian convolution as claimed in claim 2, wherein: The parties involved in the collaborative signature perform collaborative signing based on system parameters, the message to be signed, and the private key to obtain the final signature, including: After extracting the vector based on the system parameters and the private key, the second commitment is calculated and the first commitment is obtained from the other party; Calculate its own second signature based on the system parameters, the message to be signed, and the private key, and obtain the first signature from the other party; The second part of the signature is calculated by itself and the first part of the signature is obtained from the other party.
6. The method for generating a two-party collaborative signature based on a lattice based on Gaussian convolution according to claim 5, wherein: After extracting the vector based on the system parameters and the private key, the second commitment is calculated and the first commitment is obtained from the other party, including: Extract vector , calculate the second commitment vector ,in, is the private key of the second party, is a matrix; Calculate the commitment key , is a hash function, Messages waiting to be signed; Calculate the second commitment and send it to the first party , To calculate the random number generated during the commitment process, Commit is the commitment algorithm; From the first party Get the first commitment , , The first commitment vector computed for the first party, is a random number.
7. The method for generating a two-party collaborative signature based on a lattice based on Gaussian convolution according to claim 6, wherein: The verifier verifies the final signature based on the system parameters, the message to be verified, the final signature, and the system public key, including: judge Is it true? If it is true, continue; otherwise, return 0 to exit. For the final signature part, The signature can be bounded by the norm; Compute the commitment key for the verification process , and hash value , For the final promise, ; Calculate the median value , For partial signature, , 、 Sign the first and second parts respectively. is a predefined vector; judge Is it true? If it is true, output 1, otherwise return 0. Open the algorithm for commitment, Indicates a portion of the final signature.
8. A lattice-based two-party collaborative signature generation system based on Gaussian convolution, characterized in that: include: System initialization module, used to output system parameters based on security parameters; A key generation module is used for a collaborative signing participant to generate a partial public key and its own private key based on system parameters, obtain a partial public key from another participant, and calculate a system public key based on the partial public key generated by itself and the partial public key obtained from the other participant; The collaborative signature module is used by the collaborative signing parties to perform collaborative signing based on system parameters, the message to be signed, and the private key to obtain the final signature; The verification module is used by the verifier to verify the final signature based on the system parameters, the message to be verified, the final signature and the system public key.
9. A computer-readable storage medium, characterized in that A computer program is stored thereon, which, when executed by a processor, implements the Gaussian convolution-based two-party collaborative signature generation method according to any one of claims 1 to 7.
10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the Gaussian convolution-based two-party collaborative signature generation method according to any one of claims 1 to 7 is implemented.