A Method for Generating Two-Party ECDSA Digital Signatures for Active Security

Through the (2,2) threshold signature scheme, the client and the server respectively generate and regularly update some private keys. Paillier encryption and key exchange are used to solve the problem of high risk of private key leakage in the active attack model of the existing two-party ECDSA protocol, achieving efficient and secure signature generation.

CN113132104BActive Publication Date: 2025-07-04INST OF SOFTWARE - CHINESE ACAD OF SCI +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201911392093.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-12-30
Publication Date
2025-07-04
Estimated Expiration
2039-12-30

AI Technical Summary

Technical Problem

The existing two-party ECDSA protocols are difficult to resist the dynamic intrusion of the opponent in the active attack model, resulting in high risk of private key leakage and high interaction complexity and calculation cost.

Method used

Using the (2,2) threshold signature scheme, the client and the server generate part of the private keys respectively, generate the user's public key through key exchange, and use the Paillier public key to encrypt part of the private key, update part of the private key regularly, calculate the evidence value and signature ciphertext through the temporary private key, and the client decrypts and verifies the complete signature, reducing interaction and calculation costs.

Benefits of technology

Enhanced signature security in active attack models, reduce communication and computing costs, ensure that the opponent cannot forge signatures in short cycles, and that the protocol can prove security under the general group model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113132104B_ABST
    Figure CN113132104B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for generating an ECDSA digital signature for active security by two parties. The client and the server respectively generate partial private keys, and generate a user public key through key exchange; the client simultaneously generates Paillier public and private keys, and encrypts its own partial private key with the Paillier public key to generate a ciphertext; the client and the server regularly update their respective partial private keys; the client and the server respectively randomly generate temporary private keys, calculate their respective temporary public keys based on them and send them to the other party; the client and the server respectively calculate evidence values according to their respective temporary private keys; the server calculates the ciphertext of the partial signature according to its own partial private key, temporary private key, as well as the ciphertext and the evidence value; the client decrypts the ciphertext of the partial signature by using the Paillier private key to obtain the partial signature, generates a complete signature according to its own temporary private key and the evidence value, verifies the complete signature, and only outputs the complete signature that passes the verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of cryptography, and discloses a two-party signature protocol based on the ECDSA (Elliptic Curve Digital Signature Algorithm) digital signature algorithm that can resist active attacks, specifically an active-security ECDSA digital signature two-party generation method. Background Art

[0002] Currently, digital signature technologies based on public-key cryptography have been widely applied to applications such as e-commerce and identity authentication, and have become indispensable tools for ensuring information security. The idea of digital signature is that users use private keys for signature to achieve purposes such as identity authentication. The security of private keys is the basis of digital signature algorithms.

[0003] Threshold digital signature is a technology proposed to ensure the security of private keys. Its idea comes from Shamir's secret sharing technology, that is, the private key is split and placed in different physical devices, and multiple devices with a number higher than the threshold value cooperate to complete the digital signature operation. In a (t, n) threshold digital signature scheme, the private key shards are respectively held by n members, and any t members can complete the digital signature through cooperation, while less than t members cannot. Based on the threshold digital signature scheme, it can be ensured that even if an attacker has attacked t - 1 devices, the private key of the signature scheme is still secure.

[0004] ECDSA is a commonly used digital signature standard and is widely applied in places such as the TLS protocol. With the rapid development of cryptographic currencies, threshold ECDSA constructions have also received increasing attention. However, due to the particularity of ECDSA signature construction, it is difficult to design an effective threshold ECDSA protocol. Specifically, there are currently two main methods for constructing a two-party ECDSA protocol. One is to use Paillier homomorphic encryption, and the other is to use oblivious transfer protocols. The first method requires expensive zero-knowledge proofs because there are a large number of large modulus exponentiations in the zero-knowledge proofs related to Paillier; in the second method, each bit of the private key needs to run an oblivious transfer protocol, so the communication complexity is relatively large. In addition, existing two-party ECDSA protocols only consider security against static adversaries, that is, it is assumed that throughout the game, the adversary can only invade one of the parties. However, in the active attack model, the adversary is dynamic. It is assumed that the adversary can only invade one of the parties within a short period, but in the next period, the adversary can invade the other party. If the usage period of the public key is too long for the adversary to invade the devices of both parties, then the adversary can obtain the complete private key. Therefore, existing two-party ECDSA protocols are difficult to resist active attacks. It can be seen that existing two-party ECDSA constructions have the disadvantages of complex interactions, large communication and computational costs, and do not meet the requirements of practical applications. Therefore, an efficient and actively secure two-party ECDSA signature scheme is worth looking forward to. Summary of the Invention

[0005] In view of the technical problems existing in the prior art, the purpose of the present invention is to provide a two-party generation mechanism for ECDSA signatures, that is, a (2, 2) threshold signature scheme, which allows users to separately store the private key on the client side and the server side. If the devices of any one of the two parties are attacked, the attacker still cannot forge signatures.

[0006] To achieve the above purpose, the technical solution adopted by the present invention is as follows:

[0007] An actively secure two-party generation method for ECDSA digital signatures, the steps of which include:

[0008] The two communicating parties, the client and the server, each generate and store a partial private key, and generate a user public key through key exchange;

[0009] When the client generates a partial private key, it simultaneously generates Paillier public and private keys, encrypts its own partial private key with the Paillier public key to generate a ciphertext x1, and sends it to the server;

[0010] The client and the server regularly update their respective partial private keys;

[0011] The client and the server each randomly generate a temporary private key, calculate their respective temporary public keys based on it, and send their respective temporary public keys to each other;

[0012] The client and the server respectively calculate a common evidence value according to their respective temporary private keys;

[0013] The server calculates the partially signed ciphertext x3 according to its own partial private key, temporary private key, and the above ciphertext x1 and evidence value, and sends it to the client;

[0014] The client decrypts the partially signed ciphertext x3 using the Paillier private key to obtain the partial signature, generates the complete signature according to its own temporary private key and evidence value, verifies the complete signature, and only outputs the successfully verified complete signature.

[0015] Preferably, the method for generating the user public key through key exchange is as follows:

[0016] The client and the server each select a random number between [1, n - 1], and calculate their respective partial public keys according to the random numbers;

[0017] The client sends its own partial public key, Paillier public key, and ciphertext x1 to the server;

[0018] The server checks the client's partial public key. If the client's partial public key is not the infinite point O on the elliptic curve of the ECDSA algorithm, it calculates the user public key according to its own random number and the client's partial public key;

[0019] The client calculates according to its own random number and the server's partial public key. If the calculation result is equal to the above user public key or not equal to O, then the above user public key is used as the final user public key.

[0020] Preferably, the client and the server multiply their respective temporary private keys by the base point of order n on the elliptic curve of the ECDSA algorithm to obtain their respective temporary public keys.

[0021] Preferably, the client and the server update their respective partial private keys regularly through the method of rerandomization, and the method is as follows:

[0022] The client and the server calculate their respective new partial private keys according to their respective partial private keys and a rerandomization factor;

[0023] The server calculates the ciphertext x′1 according to the rerandomization factor and the ciphertext x1, and takes the ciphertext x′1 as the ciphertext of the client's new partial private key.

[0024] Preferably, the client selects a random number between [1, n-1] as the rerandomization factor and sends it to the server through a secure channel; or both the client and the server derive a shared secret value as the rerandomization factor through key negotiation.

[0025] Preferably, the client and the server calculate a common evidence value through key exchange.

[0026] Preferably, the method for calculating the evidence value is as follows:

[0027] Both the client and the server select a random number between [1, n-1] as the temporary private key and calculate the temporary public key based on it;

[0028] If the client's temporary public key is equal to the infinite point O on the elliptic curve of the ECDSA algorithm, the server terminates the protocol; otherwise, the server calculates the evidence value based on its own temporary private key and the client's temporary public key;

[0029] If the server's temporary public key is equal to O, the client terminates the protocol; otherwise, the client calculates the evidence value based on its own temporary private key and the server's temporary public key.

[0030] Preferably, the method for calculating the ciphertext x3 of the partial signature is as follows:

[0031] The server selects a random number between [0, n 2 -1] and calculates a ciphertext x2 using Paillier's encryption algorithm based on this random number, its own temporary private key, and the hash function;

[0032] The server then calculates the parameter a based on its own temporary private key, the partial private key, and the abscissa of the evidence value;

[0033] The server then obtains the ciphertext x3 of the partial signature based on the parameter a, the ciphertext x1, and the ciphertext x2.

[0034] Preferably, the method for generating the complete signature is as follows:

[0035] The client decrypts the ciphertext x3 of the partial signature using Paillier's decryption algorithm to generate the plaintext s';

[0036] The client then obtains the plaintext s'' based on its own temporary private key and the plaintext s';

[0037] Take the minimum value of s'' and n - s'' as s, and use σ=(r, s) as the complete signature, where r is the abscissa of the evidence value.

[0038] Preferably, the method for verifying the complete signature is as follows: The client verifies whether the complete signature is a legal signature regarding the message and the user's public key according to the verification algorithm of ECDSA. If it is, the verification passes; otherwise, the protocol is terminated.

[0039] In the method of the present invention, both communication parties store a part of the private key of the ECDSA signature scheme and periodically update their respective parts of the private key, while the public key remains unchanged. Through two rounds of interaction, the two parties jointly sign the message. During the interaction process, neither communication party can obtain any information about the other party's part of the private key. That is to say, as long as the attacker cannot invade both devices within one period, it cannot obtain the complete private key to forge a signature.

[0040] Compared with the prior art, the positive effects of the present invention are as follows:

[0041] 1. Both the key generation stage and the signature stage are two-round protocols, with less interaction and low communication cost;

[0042] 2. Although Paillier homomorphic encryption is used in the protocol, it does not require expensive zero-knowledge proofs and has low computational cost;

[0043] 3. The present invention provides an active update method for part of the private key, so that the old part of the private key of one party cannot be combined with the new part of the private key of the other party to generate a joint signature, thereby enhancing the security of the two-party signature.

[0044] 4. In the general group model, the mechanism provided by the present invention is provably secure in the active attack model. Specifically, if a dynamic adversary can only invade one device between two key updates, it cannot forge the user's digital signature, assuming that the adversary cannot obtain the Paillier decryption private key. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 It is a flowchart of the two-party key generation and update stage.

[0046] Figure 2 It is a flowchart of the two-party signature generation stage. DETAILED DESCRIPTION OF THE INVENTION

[0047] The present invention proposes an active-secure two-party generation method for ECDSA digital signatures, including the following steps:

[0048] 1. The two communication parties are participating party P1 and participating party P2, where P1 is the client and P2 is the server; participating party P1 generates and stores a part of the private key d1, participating party P2 generates and stores a part of the private key d2, and then generates the user's public key Y through a key exchange method; the user's public key Y does not change with the update of the part of the private key.

[0049] 2. While generating the partial private key d1, the participant P1 generates the Paillier public and private keys (ppk, psk), encrypts the partial private key d1 with the public key ppk to generate the ciphertext x1, and sends it to the participant P2;

[0050] 3. The two parties regularly update their partial private keys d1, d2, preferably by re - randomization. The re - randomization factor can be generated by one party and sent to the other party through a secure channel, or can be derived from a two - party key negotiation mechanism;

[0051] 4. The participant P1 randomly generates a temporary private key k1, the participant P2 randomly generates a temporary private key k2, and then calculates a common evidence value R through a key exchange method;

[0052] 5. The participant P2 calculates the ciphertext x3 of the partial signature according to the temporary private key k2, the partial private key d2, the ciphertext x1, and the common evidence value R, and sends x3 to P1;

[0053] 6. The participant P1 first decrypts x3 using the Paillier private key psk to obtain the partial signature s′, and then generates the complete signature and verifies its validity according to the temporary private key k1 and the evidence value R. If the verification is successful, the complete signature is output.

[0054] The protocol of the present invention is run by two participants, participant P1 and participant P2, hereinafter referred to as P1 and P2 for short. In practical applications, the joint generation protocol of the two - party signature is initiated by P1, and the complete signature is also generated and output by P1; the participant P2 calculates the partial signature to assist the participant P1 in generating the complete signature.

[0055] The present invention needs to use Paillier encryption, which is an encryption scheme that satisfies the additive homomorphic property. It consists of three algorithms:

[0056] Key generation algorithm KGen, which generates the public and private keys (ppk, psk);

[0057] Encryption algorithm Enc ppk (·), which encrypts the plaintext pt using the public key ppk to generate the ciphertext ct;

[0058] Decryption algorithm Dec psk (·), which decrypts the ciphertext ct using the private key psk to generate the plaintext pt.

[0059] The additive homomorphic property can ensure where the ciphertext operation ⊙ corresponds to the scalar multiplication of the plaintext, and the ciphertext operation corresponds to the addition of the plaintext.

[0060] The common input of the two parties is the system parameters of the ECDSA digital signature algorithm, including the security parameter λ, the elliptic curve parameters G and n, where E is an elliptic curve defined over a finite field and G represents the base point of order n on the elliptic curve E, and the infinite point on the elliptic curve is O. The specific selection of the system parameters should comply with the ECDSA digital signature algorithm standard specification.

[0061] A specific embodiment of the present invention is as follows:

[0062] 1. The parties P1 and P2 jointly generate the key of the ECDSA digital signature algorithm in the following manner

[0063] Step 1: P1 selects a random number d1 between [1, n - 1] and calculates Y1 = d1·G.

[0064] Step 2: P2 selects a random number d2 between [1, n - 1] and calculates Y2 = d2·G.

[0065] Step 3: P1 calls the key generation algorithm of the Paillier encryption scheme to generate the public and private keys (ppk, psk) ← KGen(1 λ ), and encrypts d1 to generate the ciphertext x1, x1 = Enc ppk (d1).

[0066] Step 4: P1 sends Y1, ppk, and x1 to P2.

[0067] Step 5: P2 checks if Y1 = O, and if so, terminates the protocol.

[0068] Step 6: P2 calculates Y = d2·Y1, stores the ciphertext x1 and the Paillier public key ppk, and outputs Y as the user public key.

[0069] Step 7: P2 sends Y2 to P1.

[0070] Step 8: P1 calculates Y' = d1·Y2. If Y' ≠ Y or Y' = O, then P1 terminates the protocol; otherwise, P1 stores Y as the public key of the ECDSA signature algorithm.

[0071] 2. The parties P1 and P2 actively update part of the private key of the ECDSA digital signature algorithm in the following manner.

[0072] Step 9: P1 selects a random number δ between [1, n - 1] and sends it to P2 through a secure channel. The two parties can also derive a shared secret value δ through key negotiation.

[0073] Step 10: P1 calculates d′1 = d1·δ mod n and stores d′1 as the new partial private key.

[0074] Step 11: P2 calculates d′2 = d2·δ -1 mod n and stores d′2 as the new partial private key.

[0075] Step 12: P2 calculates the ciphertext x′1 = δ⊙x1 and stores x′1 as the ciphertext of the new partial private key d′1 of P1.

[0076] 3. For a given message m, the parties P1 and P2 jointly generate an ECDSA digital signature in the following manner

[0077] Step 13: P1 selects a random number k1 between [1, n - 1] and calculates R1 = k1·G.

[0078] Step 14: P2 selects a random number k2 between [1, n - 1], calculates R2 = k2·G.

[0079] Step 15: P1 sends R1 to P2.

[0080] Step 16: If R1 = O, then P2 terminates the protocol; otherwise, P2 calculates (r x , r y ) = R = k2·R1.

[0081] Step 17: P2 selects a random number ρ between [0, n 2 - 1], calculates the ciphertext where h(·) is a hash function, and calculates and the ciphertext

[0082] Step 18: P2 sends R2, x3 to the party P1.

[0083] Step 19: If R2 = O, then P1 terminates the protocol; otherwise, P1 calculates (r x , r y ) = R = k2·R1, records r = r x .

[0084] Step 20: P1 decrypts x3 to generate the plaintext s′ = Dec psk (x3), calculates Finally, let s = min{s″, n - s″}, and take σ = (r, s) as the complete signature.

[0085] Step 21: According to the verification algorithm of the ECDSA digital signature scheme, P1 verifies whether σ is a legal signature for the message m and the public key Y. If the verification passes, σ is output; if the verification fails, the protocol is terminated.

[0086] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Those of ordinary skill in the art can modify the technical solutions of the present invention or make equivalent replacements. The protection scope of the present invention shall be subject to the claims.

Claims

1. A method for generating a two-party ECDSA digital signature for active security, characterized in that, The steps include: The two participating parties in the communication, the client and the server, each generate a partial private key and store it, and generate a user public key through key exchange. The method of generating a user public key through key exchange is as follows: The client and the server each select a random number between [1, n - 1], and calculate their respective partial public keys according to the random numbers. The client sends its partial public key, Paillier public key, and ciphertext x1 to the server. The server checks the client's partial public key. If the client's partial public key is not the infinite point O on the elliptic curve of the ECDSA algorithm, it calculates the user public key according to its own random number and the client's partial public key. The client calculates according to its own random number and the server's partial public key. If the calculation result is equal to the above user public key or not equal to O, then the above user public key is used as the final user public key. When generating the partial private key, the client simultaneously generates Paillier public and private keys, encrypts its partial private key with the Paillier public key to generate ciphertext x1, and sends it to the server. Both the client and the server regularly update their respective partial private keys by means of re-randomization. The method is as follows: The client and the server calculate their respective new partial private keys based on their respective partial private keys and a re-randomization factor; The server calculates the ciphertext x ′ 1 based on the re-randomization factor and the ciphertext x1, and takes the ciphertext x ′ 1 as the ciphertext of the client's new partial private key. Among them, the client selects a random number between [1, n - 1] as the re-randomization factor and sends it to the server through a secure channel; or both the client and the server derive a shared secret value as the re-randomization factor through key negotiation; The client and the server each randomly generate a temporary private key, calculate their respective temporary public keys according to it, and send their respective temporary public keys to each other. The client and the server respectively calculate a common evidence value according to their respective temporary private keys. The server calculates the ciphertext x3 of the partial signature according to its own partial private key, temporary private key, and the above ciphertext x1 and evidence value, and sends it to the client. The client decrypts the ciphertext x3 of the partial signature with the Paillier private key to obtain the partial signature, generates a complete signature according to its own temporary private key and evidence value, and verifies the complete signature, and only outputs the complete signature that passes the verification.

2. The method according to claim 1, characterized in that, The client and the server multiply their respective temporary private keys by the base point of order n on the elliptic curve of the ECDSA algorithm to obtain their respective temporary public keys.

3. The method according to claim 1, characterized in that, The client and the server calculate a common evidence value through key exchange.

4. The method according to claim 1, characterized in that, The method of calculating the evidence value is: The client and the server both select a random number between [1, n - 1] as the temporary private key, and calculate the temporary public key according to it. If the client's temporary public key is equal to the infinite point O on the elliptic curve of the ECDSA algorithm, the server terminates the protocol. Otherwise, the server calculates the evidence value according to its own temporary private key and the client's temporary public key. If the server's temporary public key is equal to O, the client terminates the protocol. Otherwise, the client calculates the evidence value according to its own temporary private key and the server's temporary public key.

5. The method according to claim 1, wherein The method of calculating the ciphertext x3 of the partial signature is: The server selects a random number between [0, n 2 - 1], and calculates a ciphertext x2 using Paillier's encryption algorithm based on this random number, its own temporary private key, and a hash function; The server further calculates the parameter a according to its own temporary private key, partial private key, and the abscissa of the evidence value. The server further obtains the ciphertext x3 of the partial signature according to the parameter a, ciphertext x1, and ciphertext x2.

6. The method according to claim 1, wherein The method of generating a complete signature is: The client decrypts the partially signed ciphertext x3 using Paillier's decryption algorithm to generate the plaintext s ′ ; The client then uses its own ephemeral private key and the plaintext s ′ , to obtain the plaintext s ″ ; Take the minimum of s ″ and n - s″ as s, and take σ = (r, s) as the complete signature, where r is the abscissa of the evidence value.

7. The method according to claim 1, wherein The method of verifying the complete signature is: The client verifies whether the complete signature is a legal signature regarding the message and the user public key according to the ECDSA verification algorithm. If it is, the verification passes; otherwise, the protocol is terminated.

Citation Information

Patent Citations

  • Anonymous entity identification method based on password

    CN106341232A

  • Both-sides cooperation signature method based on SM9 signature algorithm

    CN108173639A