A Collaborative Signature and Decryption Method for SM2 Cryptographic Algorithm to Protect User Privacy
By defining key pair generation, signature generation and collaborative decryption protocols in the SM2 cryptographic algorithm, the shortcomings of user privacy protection, computing optimization and decryption protocols in the prior art are solved, and efficient and secure user privacy protection and computing performance improvement are achieved.
Patent Information
- Application Number
- CN202111465919.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-03
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2041-12-03
AI Technical Summary
The existing SM2 cryptographic algorithm collaborative signature method has shortcomings in protecting user privacy, optimizing computing processes, and providing decryption protocols, especially in key pair generation, signature generation and collaborative decryption.
A new SM2 cryptographic algorithm collaborative signature and decryption method is proposed, and the key pair generation protocol, signature generation protocol and collaborative decryption protocol are defined. By reducing the number of communications, reducing the number of random numbers and optimizing calculation methods, the performance of the service provider is enhanced and user privacy is effectively protected.
It realizes the protection of user privacy without leaking user public keys, optimizes the signature generation and decryption process, and improves the performance and efficiency of the service provider.
Smart Images

Figure CN114186251B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cryptography, and particularly to a collaborative signature and decryption method of the SM2 cryptographic algorithm applicable to protecting user privacy. Background Art
[0002] Digital signature technologies based on public-key cryptography have been widely applied in applications such as e-commerce, identity authentication, and digital bills. The security of the generation and use of private keys is the basis for ensuring the security of digital signatures. Hardware cryptographic modules (such as USB tokens, etc.) and mobile terminals have become important carriers in personal identity credentials, but there are risks of being stolen and lost. On the other hand, there are more and more attacks on mobile terminals. Many malicious applications can steal private data stored on the terminal by the user and attack the communication between the terminal and the server. Therefore, it is urgent to solve the key storage and computing security on mobile terminals. The collaborative signature technology based on key splitting and collaborative computing can meet the protection requirements of signature private keys while being easy to promote and deploy.
[0003] There are already multiple collaborative signature methods for the SM2 algorithm. The common feature of this type of solution is that two participating parties respectively store part of the private key, and both parties need to jointly complete the signature operation of the message. We will hereinafter refer to the party initiating the collaborative signature as the initiator and the other party as the service party. However, the existing methods generally have one or more of the following problems:
[0004] 1) Key pair generation protocol. The service party can calculate the public key corresponding to the user's complete private key, which is not applicable in scenarios where user privacy needs to be strictly protected.
[0005] 2) Key pair generation protocol. Bind the part of the private key of the initiator and the part of the private key of the service party, and the service party stores this binding relationship, which may cause the leakage of user associated information.
[0006] 3) Signature generation protocol. It requires the service party to calculate the point multiplication operation of the elliptic curve base point G, and the calculation process cannot be optimized.
[0007] 4) Lack of collaborative decryption protocol, and data cannot be decrypted when the user's private key is required to decrypt the data. Summary of the Invention
[0008] In view of this, the present invention discloses a collaborative signature and decryption method of the SM2 cryptographic algorithm for protecting user privacy, defines a key pair generation protocol, a signature generation protocol, and a collaborative decryption protocol. In addition to providing the feature of user privacy protection, it also enhances the performance of the service party by reducing the number of communications, reducing the number of random numbers, and using an optimized calculation method.
[0009] In order to achieve the above object, the technical solution of the present invention is realized as follows:
[0010] 1) Key pair generation protocol: The initiator and the service party respectively generate their own key pairs (d 1 , P 1 ) and (d 2 , P 2 ). The initiator obtains the partial public key P 2 of the service party and generates the public key P A of user A, where the initiator is the terminal where user A is located. The specific steps are as follows:
[0011] Initiator:
[0012] A1: The initiator sends a collaborative key pair generation request to the service party.
[0013] Service party:
[0014] B1: Generate a random number d 2 ∈ [1, n - 1], where n is the order of the elliptic curve base point G;
[0015] B2: Calculate the elliptic curve point P 2 = [d 2 G. The key pair of the service party is (d 2 , P 2 );
[0016] B3: Send P 2 to the initiator.
[0017] Initiator:
[0018] A2: Verify whether P 2 satisfies the elliptic curve equation. If it does not satisfy, the collaborative key pair generation fails; if it satisfies, proceed to A3;
[0019] A3: Generate a random number d 1 ∈ [1, n - 1];
[0020] A4: Calculate the elliptic curve point P 1 = [d 1 G. The key pair of the initiator is (d 1 , P 1 );
[0021] A5: Calculate the elliptic curve point P A = [d 1 P 2 - G, and output the public key of user A as P A .
[0022] 2) Signature generation protocol: The initiator calculates the digest e of the message M to be signed, and generates the elliptic curve point Q 2 according to the public key P 1 of the service party, and sends e and Q1 Send to the service provider; the service provider calculates the partial signature (r, s 2 , e, and Q 1 ) and returns it to the initiator; the initiator then calculates and outputs the final signature (r, s) based on d 2 ), r, and s 1 . The specific steps are as follows: 2 Initiator:
[0023] A1: Calculate the digest e of message M according to the method defined in GM / T 0003.2;
[0024] A2: Generate a random number k
[0025] ∈ [1, n - 1]; 1
[0026] A3: Calculate the elliptic curve point Q 1 = [k 1 P 2 ;
[0027] A4: Send e and Q 1 to the service provider.
[0028] Service provider:
[0029] B1: Verify whether Q 1 satisfies the elliptic curve equation. If not, terminate the collaborative signature process; if so, proceed to B2;
[0030] B2: Generate a random number k 2 ∈ [1, n - 1];
[0031] B3: Calculate the elliptic curve point (x 1 , y 1 ) = [k 2 G + Q 1 , and convert the data type of x 1 to an integer;
[0032] B4: Calculate r = e + x 1 mod n. If r = 0 or r + k 2 = n, then return to B2; otherwise, proceed to B5;
[0033] B5: Calculate s 2 = (d 2 -1 ·(r + k 2 )) mod n;
[0034] B6: Send r and s 2 to the initiator.
[0035] Initiator:
[0036] A5: If k 1 +s 2 =n, then return A2; otherwise, proceed to A6;
[0037] A6: Calculate s = (d 1 -1 ·(k 1 +s 2 ) - r) mod n. If s = 0, then return A2; otherwise, proceed to A7;
[0038] A7: Use the public key P A to verify whether (r, s) is the signature of the message M. If not, the current signature fails; otherwise, output (r, s) as the signature of the message M.
[0039] 3) Cooperative decryption protocol: To decrypt the ciphertext C = C 1 ||C 3 ||C 2 , the initiator generates Q 1 based on C 1 and sends Q 1 to the server; the server generates Q 2 and Q 1 based on d 2 and Q 2 and sends Q 2 to the initiator; finally, the initiator completes the decryption operation based on Q 3 , C 2 and C
[0040] Initiator:
[0041] A1: Extract the bit strings C 1 , C 3 and C 2 from C. Convert the data type of C 1 into a point on the elliptic curve, and verify whether C 1 satisfies the elliptic curve equation and [h]C 1 is not the point at infinity. If not satisfied or [h]C 1 is the point at infinity, then report an error and exit, where h is the cofactor of the order n of the base point G; Extracting the three parts C1C3C2 from the SM2 ciphertext C is a well-known technology. Refer to "GM / T 0003.4 SM2 Elliptic Curve Public Key Cryptography Algorithm - Part 4 Public Key Encryption Algorithm".
[0042] A2: Generate a random number k 1 ∈[1, n - 1], and calculate the elliptic curve point Q 1 =[k 1 C 1 through Q1 , send Q 1 to the service provider.
[0043] Service provider:
[0044] B1: Verify whether Q 1 satisfies the elliptic curve equation and [h]Q 1 is not the point at infinity. If it does not satisfy or [h]Q 1 is the point at infinity, then end the collaborative decryption process;
[0045] B2: Calculate the elliptic curve point Q 2 = [d 2 Q 1 ;
[0046] B3: Send Q 2 to the initiator.
[0047] Initiator:
[0048] A3: Verify whether Q 2 satisfies the elliptic curve equation. If it does not satisfy, then report an error and exit;
[0049] A4: Calculate the elliptic curve point (x 2 , y 2 ) = [d 1 ·k -1 Q 2 - C 1 ; Convert the data types of x 2 , y 2 into bit strings;
[0050] A5: Calculate t = KDF(x 2 ||y 2 , klen), where klen is the bit length of C 2 in the ciphertext; If t is a bit string of all 0s, then report an error and exit.
[0051] A6: Calculate M' = C 2 ⊕t;
[0052] A7: Calculate u = Hash(x 2 ||M'||y 2 ). If u ≠ C 3 , then report an error and exit;
[0053] A8: Output the plaintext M'.
[0054] It can be seen that in the solution of the present invention, the service party does not know the user's public key and does not need to associate with the initiator's private key, thus effectively protecting the user's privacy. At the same time, the data sent during the protocol execution does not contain sensitive content, and there is no need to protect the confidentiality of the communication data; in the signature generation protocol, only one communication process is required to complete the signature. The service party only needs to generate a random number, and for the time-consuming elliptic curve point multiplication operation, the service party only needs to calculate the point multiplication of the base point G and the random number, and can also perform pre-computation before the initiator's request. Therefore, the service party disclosed in the present invention has higher performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] Figure 1 It is a flowchart of an embodiment of the SM2 cryptographic algorithm collaborative signature method for protecting user privacy in the present invention.
[0056] Figure 2 It is a schematic diagram of the process of the key pair generation protocol of the present invention.
[0057] Figure 3 It is a schematic diagram of the process of the signature generation protocol of the present invention.
[0058] Figure 4 It is a schematic diagram of the process of the signature generation protocol that requires the service party to verify or confirm the message content in the present invention.
[0059] Figure 5 It is a schematic diagram of the process of the collaborative decryption protocol of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0060] In order to make the technical solution of the present invention clearer and more understandable, the following examples are given with reference to the accompanying drawings to further elaborate on the solution of the present invention.
[0061] The present invention uses the following terms and definitions:
[0062] 1) Collaborative digital signature: The process of calculating the digital signature of a certain input message by two participating parties through protocol interaction and using the user's partial private keys they each hold.
[0063] 2) Partial private key: The secret data items specifically used by the initiator and the service party respectively during the collaborative digital signature process.
[0064] 3) User public key: The public key corresponding to the user's private key, which in this document is the public key corresponding to the user's private key jointly composed of the partial private keys respectively held by the two participating parties.
[0065] 4) Key pair collaborative generation: The process of generating the partial private keys each held by two participating parties through protocol interaction and outputting the user public key.
[0066] 5) Initiator: The participant that sends the first-round information during the operation of the protocol, which is generally the terminal used by the user in this document.
[0067] 6) Server: The participant that assists the initiator in generating key pairs or signatures during the operation of the protocol, which is generally the server or auxiliary device in this document.
[0068] The present invention uses the following symbols:
[0069] d 1 The partial private key of the initiator.
[0070] d 2 The partial private key of the server.
[0071] d -1 The inverse of d modulo n.
[0072] E(F q ) F q The set consisting of all rational points (including the point at infinity) on the elliptic curve E over F.
[0073] F q The finite field containing q elements.
[0074] e The output value of the cryptographic hash algorithm applied to the message M.
[0075] G A base point of the elliptic curve, whose order is a prime number.
[0076] H v () The cryptographic hash algorithm with a message digest length of v bits.
[0077] KDF() The key derivation function.
[0078] h The cofactor, h = #E(F q ) / n, where n is the order of the base point G.
[0079] M The message to be signed or encrypted.
[0080] mod n Modulo n operation.
[0081] n The order of the base point G.
[0082] P 1 The partial public key of the initiator.
[0083] P 2 The partial public key of the server.
[0084] P A The public key of user A.
[0085] x||y The concatenation of x and y, where x and y can be bit strings or byte strings.
[0086] Z A The hash value of the identifier of user A, some elliptic curve system parameters, and the public key of user A.
[0087] [k]P The k - multiple point of point P on the elliptic curve, where k is a positive integer.
[0088] (r, s) The signature of the message.
[0089] [x, y] The set of integers greater than or equal to x and less than or equal to y.
[0090] #E(F q ) E(F q ) The number of points on it, called the order of the elliptic curve E(F q ).
[0091] Figure 1 This is the flowchart of the collaborative signature method of the SM2 cryptographic algorithm for protecting user privacy in the present invention. As Figure 1 shown, it includes the following steps 11 - 13.
[0092] Step 11: The initiator and the service provider respectively generate their own key pairs (d 1 , P 1 ) and (d 2 , P 2 ). The initiator obtains the partial public key P 2 of the service provider and generates the public key P A of user A.
[0093] Step 12: The initiator calculates the digest e of the message M to be signed, and generates the elliptic curve point Q 2 according to the partial public key P 1 of the service provider, and sends e and Q 1 to the service provider; the service provider calculates the partial signature (r, s 2 , e and Q 1 ) and returns it to the initiator; the initiator then calculates and outputs the final signature (r, s) according to d 2 ) 1 , r, s 2 .
[0094] Step 13: In order to decrypt the ciphertext C = C 1 ||C 3 ||C 2 , the initiator generates Q 1 according to C 1 and sends Q 1 to the service provider; the service provider according to d2 and Q 1 Generate Q 2 and send Q 2 to the initiator; finally, the initiator decrypts according to Q 2 , C 3 and C 2 to complete the decryption operation.
[0095] Figure 2 This is a schematic diagram of the process of the key pair generation protocol of the present invention. As Figure 2 shown, it includes the initiator steps A1 to A5 and the service provider steps B1 to B3.
[0096] Initiator:
[0097] A1: The initiator sends a collaborative key pair generation request to the service provider.
[0098] Service provider:
[0099] B1: Generate a random number d 2 ∈ [1, n - 1];
[0100] B2: Calculate the elliptic curve point P 2 = [d 2 G, and the key pair of the service provider is (d 2 , P 2 );
[0101] B3: Send P 2 to the initiator.
[0102] Initiator:
[0103] A2: Verify whether P 2 satisfies the elliptic curve equation. If not, the collaborative key pair generation fails;
[0104] A3: Generate a random number d 1 ∈ [1, n - 1];
[0105] A4: Calculate the elliptic curve point P 1 = [d 1 G, and the key pair of the initiator is (d 1 , P 1 );
[0106] A5: Calculate the elliptic curve point P A = [d 1 P 2 - G, and the public key of user A is P A .
[0107] Through the process shown in the above steps, the partial private keys d 1 and d 2 of the initiator and the service provider can be generated respectively., and synthesize the user's public key P A . The user's actual private key is d A =(d 1 d 2 -1) mod n. Neither the initiator nor the service provider can independently calculate the user's private key
[0108] It should be noted that the above step representation is only for illustrative purposes and does not limit the execution order of each step. In actual applications, the execution order of each step can be set according to actual needs, as long as the desired result can be obtained eventually. The same applies to each subsequent schematic diagram and will not be elaborated further
[0109] Figure 3 This is a schematic diagram of the process of the signature generation protocol of the present invention. As Figure 3 shown, it includes initiator steps A1 to A7 and service provider steps B1 to B6
[0110] Initiator:
[0111] A1: Calculate the message digest e = H v (Z A ||M), convert the data type of e to an integer according to the method defined in Section 4.2 of Part 1 of GM / T 0003.1-2012, where Z A needs to be calculated according to the method defined in Section 5.5 of Part 2 of GM / T 0003.2-2012
[0112] A2: Generate a random number k 1 ∈[1, n - 1]
[0113] A3: Calculate the elliptic curve point Q 1 =[k 1 P 2 ;
[0114] A4: Send e, Q 1 to the service provider
[0115] Service provider:
[0116] B1: Verify whether Q 1 satisfies the elliptic curve equation. If not, terminate the collaborative signature process
[0117] B2: Generate a random number k 2 ∈[1, n - 1]
[0118] B3: Calculate the elliptic curve point (x 1 , y 1 ) = [k 2 G + Q 1, convert the x data type to an integer according to the method defined in Section 4.2 of Part 1 of GM / T 0003.1-2012; 1 Data type conversion to integer;
[0119] B4: Calculate r = (e + x 1 ) mod n. If r = 0 or r + k 2 = n, then return to B2;
[0120] B5: Calculate s 2 = (d 2 -1 ·(r + k 2 )) mod n;
[0121] B6: Send r, s 2 to the initiator.
[0122] Initiator:
[0123] A5: If k 1 + s 2 = n, then return to A2;
[0124] A6: Calculate s = (d 1 -1 ·(k 1 + s 2 ) - r) mod n. If s = 0, then return to A2;
[0125] A7: Use the public key P A to verify whether (r, s) is the signature of the message M. If not, the current signature fails; otherwise, output (r, s) as the signature of the message M.
[0126] Figure 4 This is the process schematic diagram of the signature generation protocol for the service party to verify or confirm the message content in the present invention. As Figure 4 shown, it includes the initiator steps A1 - A6 and the service party steps B1 - B8.
[0127] Initiator:
[0128] A1: Generate a random number k 1 ∈ [1, n - 1];
[0129] A2: Calculate the elliptic curve point Q 1 = [k 1 P 2 ;
[0130] A3: Send M, Z A , Q 1 to the service party, where Z AIt needs to be calculated according to the method defined in Section 5.5, Part 2 of GM / T 0003.2—2012.
[0131] Service provider:
[0132] B1: Verify Q 1 to see if it satisfies the elliptic curve equation. If not, terminate the collaborative signature process;
[0133] B2: Check and confirm the content of message M. If the message content is incorrect, terminate the collaborative signature process;
[0134] B3: Calculate the message digest e = H v (Z A ||M), and convert the data type of e to an integer according to the method defined in Section 4.2, Part 1 of GM / T 0003.1-2012;
[0135] B4: Generate a random number k 2 ∈[1, n - 1];
[0136] B5: Calculate the elliptic curve point (x 1 , y 1 ) = [k 2 G + Q 1 , and convert the data type of x 1 to an integer according to the method defined in Section 4.2, Part 1 of GM / T 0003.1-2012;
[0137] B6: Calculate r = (e + x 1 ) mod n. If r = 0 or r + k 2 = n, then return to B4;
[0138] B7: Calculate s 2 = (d 2 -1 ·(r + k 2 )) mod n;
[0139] B8: Send r, s 2 to the initiator.
[0140] Initiator:
[0141] A4: If k 1 + s 2 = n, then return to A1;
[0142] A5: Calculate s = (d 1 -1 ·(k 1 + s 2 ) - r) mod n. If s = 0, then return to A1;
[0143] A6: Use public key P A Verify whether (r, s) is the signature of message M. If not, the signature fails; otherwise, output (r, s) as the signature of message M.
[0144] Figure 5 This is a schematic diagram of the collaborative decryption protocol of the present invention. As Figure 5 shown, it includes initiator steps A1 to A8 and server steps B1 to B3.
[0145] Initiator:
[0146] A1: Extract bit strings C 1 , C 3 and C 2 from C, and convert the data type of C 1 into a point on the elliptic curve according to the method defined in Section 3.2 of Part 1 of GM / T 0003.1 - 2012. Verify whether C 1 satisfies the elliptic curve equation and [h]C 1 is not the infinite point. If not satisfied or [h]C 1 is the infinite point, report an error and exit, where h is the cofactor of the order n of the base point G;
[0147] A2: Generate a random number k 1 ∈ [1, n - 1], and calculate the elliptic curve point Q 1 through Q 1 C 1 . Send Q 1 = C 1 to the server. 1
[0148] Server:
[0149] B1: Verify whether Q 1 satisfies the elliptic curve equation and [h]Q 1 is not the infinite point. If not satisfied or [h]Q 1 is the infinite point, end the collaborative decryption process;
[0150] B2: Calculate the elliptic curve point Q 2 = [d 2 Q 1 ;
[0151] B3: Send Q 2 to the initiator.
[0152] Initiator:
[0153] A3: Verify whether Q 2 satisfies the elliptic curve equation. If not satisfied, report an error and exit;
[0154] A4: Calculate the elliptic curve point (x 2 , y 2 ) = [d 1 ·k -1 Q 2 -C 1 ; Convert the data types of x 2 , y 2 into bit strings according to the method defined in Section 3.2, Part 1 of GM / T 0003.1 - 2012;
[0155] A5: Calculate t = KDF(x 2 ||y 2 , klen), if t is a bit string of all 0s, then report an error and exit, where klen is the bit length of C 2 in the ciphertext;
[0156] A6: Calculate M' = C 2 ⊕t;
[0157] A7: Calculate u = Hash(x 2 ||M'||y 2 ), if u ≠ C 3 , then report an error and exit;
[0158] A8: Output the plaintext M'.
[0159] In summary, the above is only the preferred embodiment of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A collaborative signature method for SM2 cryptographic algorithm to protect user privacy, the steps of which include: 1) The initiator and the service provider respectively generate their own key pairs (d 1 , P 1 ) and (d 2 , P 2 ). The initiator obtains the partial public key P 2 of the service provider and generates the public key P 2 of user A based on P A ; where the initiator is the terminal where user A is located; 2) The initiator calculates the digest e of the message M to be signed and generates an elliptic curve point Q based on the partial public key P 2 ; Then it sends e and Q 1 to the service provider; 1 3) The service provider calculates a partial signature (r, s 2 ), e, and Q 1 and returns them to the initiator; 2 ) 4) The initiator calculates and outputs the final signature (r, s) based on the partial private key d of the initiator 1 , r, s 2 of the initiator 2. According to the method described in claim 1, characterized in that, Method for generating key pairs (d 1 , P 1 ) and (d 2 , P 2 ) is as follows: The initiator sends a collaborative key pair generation request to the service provider; After the service party receives the collaborative key pair generation request, it generates a random number d 2 ∈ [1, n - 1], where n is the order of the elliptic curve base point G; Calculate the elliptic curve point P 2 = [d 2 G, to obtain the service party's key pair (d 2 , P 2 ) and send P 2 to the initiator; The initiator verifies P 2 to check if it satisfies the elliptic curve equation. If it does, a random number d 1 ∈[1, n - 1] is generated; then the elliptic curve point P 1 = [d 1 G is calculated, and the initiator's key pair is obtained as (d 1 , P 1 ).
3. According to the method described in claim 2, characterized in that, The initiator generates a random number k 1 ∈ [1, n - 1], and calculates the elliptic curve point Q 1 through Q 1 =[k 2 P 1 .
4. According to the method described in claim 3, characterized in that, The method for obtaining the partial signature (r, s 2 ) is as follows: 31) The service provider verifies Q 1 to check if it satisfies the elliptic curve equation. If it does, a random number k 2 ∈[1, n - 1] is generated; 32) Calculate the elliptic curve point (x 1 , y 1 ) = [k 2 G + Q 1 , and convert the data type of x 1 to an integer; 33) Calculate r = e + x 1 mod n, if r = 0 or r + k 2 = n, then regenerate the random number k 2 Return to step 32); otherwise calculate s 2 = (d 2 -1 ·(r + k 2 )) mod n; obtain the partial signature (r, s 2 ).
5. According to the method described in claim 4, characterized in that, The method for obtaining the signature (r, s) is: 41) The initiator calculates according to k 1 , s 2 . If k 1 +s 2 =n, then return to step 2) to regenerate the elliptic curve point Q 1 , and send e and Q 1 to the service party; 42) Calculate s = (d 1 -1 ·(k 1 + s 2 ) - r) mod n. If s = 0, return to step 2) to regenerate the elliptic curve point Q 1 , and send e and Q 1 to the service provider; otherwise, use the public key P A to verify whether (r, s) is the signature of the message M. If not, the signature fails this time; otherwise, output the signature (r, s).
6. A collaborative decryption method for SM2 cryptographic algorithm to protect user privacy, the steps of which include: 1) The initiator and the service provider respectively generate their own key pairs (d 1 , P 1 ) and (d 2 , P 2 ). The initiator obtains the partial public key P 2 of the service provider; 2) For the ciphertext C to be decrypted; where the ciphertext C is the ciphertext encrypted by the SM2 cryptographic algorithm, consisting of C 1 , C 3 and C 2 ; The initiator extracts the bit strings C 1 , C 3 and C 2 from the ciphertext C; Generates the elliptic curve point Q 1 according to C 1 and sends Q 1 to the service provider; 3) The service provider generates an elliptic curve point Q based on d 2 and Q 1 and sends Q 2 to the initiator; 2 4) The initiator decrypts the ciphertext C based on Q 2 , C 3 and C 2 to complete the decryption of the ciphertext C.
7. According to the method described in claim 6, characterized in that, In step 2), the method for generating the elliptic curve point Q 1 is as follows: convert the data type of C 1 into a point on the elliptic curve, verify whether C 1 satisfies the elliptic curve equation and [h]C 1 is not the infinite point. If it does not satisfy or [h]C 1 is the infinite point, then terminate the collaborative decryption process. Otherwise, generate a random number k 1 ∈[1, n - 1], and calculate the elliptic curve point Q 1 through Q 1 =[k 1 C 1 ; where h is the cofactor of the order n of the base point G.
8. According to the method described in claim 7, characterized in that, Method for generating elliptic curve point Q 2 is as follows: Verify whether Q 1 satisfies the elliptic curve equation and [h]Q 1 is not the infinite point. If it does not satisfy or [h]Q 1 is the infinite point, then end the collaborative decryption process; otherwise, calculate the elliptic curve point Q 2 = [d 2 Q 1 .
9. According to the method described in claim 8, characterized in that, In step 4), the decryption method for the ciphertext C is as follows: Verify Q 2 whether it satisfies the elliptic curve equation. If it does not satisfy, end the collaborative decryption process. If it satisfies, calculate the elliptic curve point (x 2 , y 2 ) = [d 1 ·k -1 Q 2 - C 1 . Convert the data types of x 2 and y 2 into bit strings. Then calculate t = KDF(x 2 || y 2 , klen). If t is an all-zero bit string, end the collaborative decryption process. Otherwise, calculate M ′ = C 2 ⊕ t. Then calculate u = Hash(x 2 || M ′ || y 2 ). If u ≠ C 3 , end the collaborative decryption process. Otherwise, output the plaintext M ′ ; where klen is the bit length of C 2 in the ciphertext.
Citation Information
Patent Citations
Two-party collaborative signature method based on SM2 algorithm for resisting energy analysis attack
CN112422288A
Authentication based on a recoverd public key
EP3607483A2