A digital signature method, apparatus, terminal device and storage medium

By using ECDSA signature algorithm and deblind calculation in blind signature technology, the problem of low computing efficiency caused by long keys in RSA asymmetric system is solved, and more efficient blind signature operations are achieved.

CN114329632BActive Publication Date: 2025-06-13HANGZHOU QULIAN TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111668886.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-31
Publication Date
2025-06-13
Estimated Expiration
2041-12-31

AI Technical Summary

Technical Problem

The existing blind signature technology based on RSA asymmetric system has low computing efficiency due to the long key.

Method used

By sending request information to the signature end to obtain coordinate parameters, the blinded message is determined based on the message to be signed and the coordinate parameters, and sending it to the signature end for ECDSA signature algorithm calculation, obtain the blinded digital signature, and then perform de-blind calculation to determine the final digital signature.

Benefits of technology

In the case of ensuring security, a shorter key is used to determine the blinded digital signature, which reduces the length of the blinded digital signature, thereby improving the computing efficiency of blind signatures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114329632B_ABST
    Figure CN114329632B_ABST
Patent Text Reader

Abstract

This application is applicable to the field of digital signature technology, and provides a digital signature method, device, terminal device and storage medium. In the embodiments of this application, a request message is sent to a signature end so that the signature end determines coordinate parameters according to the request message; the coordinate parameters and a message to be signed are obtained, and a blinded message is determined according to the message to be signed and the coordinate parameters; the blinded message is sent to the signature end so that the signature end calculates the blinded message according to the ECDSA signature algorithm to determine a blinded digital signature; the blinded digital signature is obtained, and a de-blinding calculation is performed on the blinded digital signature to determine the digital signature corresponding to the message to be signed, thereby improving the operation efficiency of blind signature through the ECDSA signature algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of digital signatures, and particularly relates to a digital signature method, apparatus, terminal device, and storage medium. Background Art

[0002] With the development of society, in related fields that pay attention to privacy protection, such as voting, elections, e-commerce, electronic cash systems, mobile payments, etc., the blind signature technology in digital signature technology has been widely used. Because blind signatures have the ability to make the signer unable to see the specific content of the signed document and the signer cannot trace the whereabouts of the signature when the signature is made public, blind signatures can protect users' privacy better than ordinary digital signatures.

[0003] Existing blind signature technologies based on the RSA asymmetric system need to set relatively long keys to ensure algorithm security, and due to the long keys, the operation efficiency of blind signatures is relatively low. Summary of the Invention

[0004] Embodiments of this application provide a digital signature method, apparatus, terminal device, and storage medium, which can solve the problem of relatively low operation efficiency of blind signatures.

[0005] In a first aspect, embodiments of this application provide a digital signature method, which is applied to a user side and includes:

[0006] Sending a request message to a signature side so that the signature side determines coordinate parameters according to the request message;

[0007] Obtaining the coordinate parameters and the message to be signed, and determining a blinded message according to the message to be signed and the coordinate parameters;

[0008] Sending the blinded message to the signature side so that the signature side calculates the blinded message according to the ECDSA signature algorithm to determine a blinded digital signature;

[0009] Obtaining the blinded digital signature, and performing de-blinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed.

[0010] In one embodiment, the determining a blinded message according to the message to be signed and the coordinate parameters includes:

[0011] Performing blinding calculation on the message to be signed to determine a blinded message to be signed;

[0012] Determining target parameters according to a preset first random number and the coordinate parameters;

[0013] Performing blinding calculation on the target parameters to determine a blinded target parameter;

[0014] Determine the to-be-signed message after the above blinding and the above target parameter after the above blinding as the above blinded message.

[0015] In one embodiment, the above blinding calculation of the to-be-signed message to determine the to-be-signed message after blinding includes:

[0016] Calculate the message digest of the to-be-signed message according to a preset cryptographic hash function;

[0017] Perform a blinding calculation on the above message digest according to the following formula:

[0018] e′ = e · b -1 mod n

[0019] where e′ is the to-be-signed message after the above blinding, e is the above message digest, b is a preset second random number, 1 ≤ b ≤ n - 1, and n is the order of the elliptic curve base point.

[0020] In one embodiment, the above determination of the target parameter according to the preset first random number and the above coordinate parameter includes:

[0021] Determine the above target parameter according to the following formula:

[0022] (x, y) = a -1 ·K

[0023] R = x mod n

[0024] where R is the above target parameter, K is the above coordinate parameter, a is the above first random number, 1 ≤ a ≤ n - 1, and n is the order of the elliptic curve base point.

[0025] In one embodiment, the above blinding calculation of the target parameter to determine the target parameter after blinding includes:

[0026] Perform a blinding calculation on the above target parameter according to the following formula:

[0027] R′ = R · b -1 mod n

[0028] where R′ is the target parameter after the above blinding, b is a preset second random number, 1 ≤ b ≤ n - 1, and the above n is the order of the elliptic curve base point.

[0029] In one embodiment, the above de-blinding calculation of the blinded digital signature to determine the digital signature corresponding to the to-be-signed message includes:

[0030] Perform a de-blinding calculation on the above blinded digital signature according to the following formula:

[0031] S = S′ · a · b mod n

[0032] Wherein, S is the signature value in the digital signature, and S' is the blinded signature value in the blinded digital signature;

[0033] Determine (R, S) as the above digital signature.

[0034] In a second aspect, an embodiment of the present application provides a digital signature method, which is applied to a signature end and includes:

[0035] Obtain the request information of the user end, generate a third random number according to the above request information, calculate the dot product of the above third random number and the elliptic curve base point, and determine the above dot product as the coordinate parameter;

[0036] Send the above coordinate parameter to the above user end, so that the above user end determines a blinded message according to the above coordinate parameter and a preset message to be signed;

[0037] Obtain the above blinded message, calculate the above blinded message according to the ECDSA signature algorithm, and determine the blinded digital signature;

[0038] Send the above blinded digital signature to the user end, so that the above user end performs a de-blinding calculation on the above blinded digital signature to determine the digital signature corresponding to the above message to be signed.

[0039] In one embodiment, calculating the above blinded message according to the ECDSA signature algorithm to determine the blinded digital signature includes:

[0040] Calculate the above blinded message according to the following formula corresponding to the ECDSA signature algorithm:

[0041] S′ = (R′·d + e′)·k -1 mod n

[0042] Wherein, S′ is the blinded signature value in the above blinded digital signature, R′ is the blinded target parameter in the above blinded message, e′ is the message to be signed after blinding in the above blinded message, d is the private key of the above signature end, k is the above third random number, 1 ≤ k ≤ n - 1, and n is the order of the elliptic curve base point;

[0043] Determine (R′, S′) as the above blinded digital signature.

[0044] In a third aspect, an embodiment of the present application provides a digital signature device, including:

[0045] A request module, configured to send request information to a signature end, so that the above signature end determines a coordinate parameter according to the above request information;

[0046] An acquisition module, configured to acquire the above coordinate parameters and the message to be signed, and determine a blinded message according to the above message to be signed and the above coordinate parameters;

[0047] A calculation module, configured to send the above blinded message to the above signature end, so that the above signature end calculates the above blinded message according to the ECDSA signature algorithm to determine a blinded digital signature;

[0048] A de - blinding calculation module, configured to acquire the above blinded digital signature, perform de - blinding calculation on the above blinded digital signature, and determine the digital signature corresponding to the above message to be signed.

[0049] In a fourth aspect, an embodiment of the present application provides a terminal device, including a memory, a processor, and a computer program stored in the above memory and executable on the above processor. When the above processor executes the above computer program, the steps of any of the above digital signature methods are implemented.

[0050] In a fifth aspect, an embodiment of the present application provides a computer - readable storage medium. The above computer - readable storage medium stores a computer program. When the above computer program is executed by a processor, the steps of any of the above digital signature methods are implemented.

[0051] In a sixth aspect, an embodiment of the present application provides a computer program product. When the computer program product runs on a terminal device, the terminal device is enabled to execute any of the digital signature methods in the above first aspect.

[0052] In the embodiments of the present application, a request message is sent to a signature end, so that the signature end determines coordinate parameters according to the above request message, thereby acquiring the above coordinate parameters and the message to be signed. Then, a blinded message is determined according to the above message to be signed and the above coordinate parameters, and the above blinded message is sent to the above signature end, so that the signature end calculates the above blinded message according to the ECDSA signature algorithm, thereby determining a blinded digital signature with a shorter key while ensuring security. Then, de - blinding calculation is performed on the acquired above blinded digital signature to determine the digital signature corresponding to the above message to be signed. Thus, the length of the key is reduced by the ECDSA signature algorithm, and correspondingly, the length of the blinded digital signature is also reduced, thereby improving the operation efficiency of blind signature. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0054] Figure 1 It is the first process schematic diagram of the digital signature method provided by the embodiment of the present application;

[0055] Figure 2 It is the second process schematic diagram of the digital signature method provided by the embodiment of the present application;

[0056] Figure 3 It is the third process schematic diagram of the digital signature method provided by the embodiment of the present application;

[0057] Figure 4 It is the first structural schematic diagram of the digital signature device provided by the embodiment of the present application;

[0058] Figure 5 It is the second structural schematic diagram of the digital signature device provided by the embodiment of the present application;

[0059] Figure 6 It is the structural schematic diagram of the terminal device provided by the embodiment of the present application. Detailed implementation manners

[0060] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system structures and technologies are presented to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0061] It should be understood that when used in the specification and appended claims of the present application, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0062] As used in the specification and appended claims of the present application, the term "if" can be interpreted as "when" or "once" or "in response to determining" or "in response to detecting" according to the context. Similarly, the phrase "if determined" or "if detecting [the described condition or event]" can be interpreted as meaning "once determined" or "in response to determining" or "once detecting [the described condition or event]" or "in response to detecting [the described condition or event]" according to the context.

[0063] In addition, in the description of the specification and appended claims of the present application, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0064] Embodiment 1

[0065] Figure 1 The following is a schematic flowchart of a digital signature method in an embodiment of the present application. The execution subject of this method can be a terminal device applied to the user side, such as Figure 1 As shown, the above digital signature method may include the following steps:

[0066] Step S101: Send a request message to the signature end so that the signature end determines coordinate parameters according to the request message.

[0067] In this embodiment, in order to prevent the private key of the signer from being leaked during subsequent interactions, the user side currently needs to obtain the coordinate parameters determined by the signature end according to its request. These coordinate parameters can be temporarily generated according to the request message or updated every preset time.

[0068] Exemplarily, the signature end can randomly generate a random number k from a preset data set according to the request message of the user side. k is equivalent to a private key randomly generated by the signature end. This set can be determined according to the elliptic curve number field corresponding to the ECDSA signature algorithm. For example, if the base point G of the current elliptic curve is of order n and n is a prime number, this set is all integers from 1 to n - 1, that is, 1 ≤ k ≤ n - 1. The signature end then determines the point multiplication of the random number and the base point as the coordinate parameter, that is, k·G = K. The signature end then sends the coordinate parameter K to the signature end and stores the coordinate parameter. It can be understood that since the calculation of the coordinate parameter requires the use of the base point and the base point is located on the elliptic curve, the base point is a set of coordinate values, and correspondingly, the calculated coordinate parameter is also a set of coordinate values. This coordinate parameter is a point in the affine coordinate system.

[0069] It can be understood that since the ECDSA signature algorithm uses the elliptic curve cryptosystem, compared with the RSA algorithm, the length of the key and the length of the corresponding blinded digital signature are both relatively small at the same security level, and correspondingly, the operation efficiency is higher. For example, to ensure a security level of 128 bits, if the RSA algorithm is used, a 3072-bit RSA key is required, while if the ECDSA signature algorithm is used, only a 256-bit key is needed. In addition, since the ECDSA signature algorithm can be widely used in protocols such as tls1.1, 1.2, and 1.3, the ECDSA signature algorithm is more versatile.

[0070] Step S102: Obtain the coordinate parameters and the message to be signed, and determine the blinded message according to the message to be signed and the coordinate parameters.

[0071] In this embodiment, the user side can perform blind calculation on the message to be signed and the coordinate parameters respectively by randomly generating a random number. This random number is equivalent to the private key of the user side, so as to determine the blinded message that prevents the signature end from knowing the message to be signed.

[0072] In one embodiment, as Figure 2 shown, the above step S102 may include:

[0073] Step S201: Perform blinding calculation on the message to be signed to determine the blinded message to be signed.

[0074] In this embodiment, the client blinds the message to be signed, so that the signing end never knows the message to be signed by the user, greatly protecting the user's privacy.

[0075] In one embodiment, the above step S201 may include: calculating the message digest of the message to be signed according to a preset cryptographic hash function. For example, calculating the message digest H(M) of the message to be signed M, and the calculated message digest can also be regarded as a string containing 1s and 0s, so as to convert this string into an integer form for subsequent calculations.

[0076] The client then performs blinding calculation on the message digest according to the following formula:

[0077] e′ = e · b -1 mod n

[0078] where e′ is the blinded message to be signed, e is the message digest, and the message digest can be a processed integer, b is a preset second random number, 1 ≤ b ≤ n - 1, n is the order of the elliptic curve base point, and this random number is randomly generated within the data range.

[0079] Step S202: Determine the target parameter according to the preset first random number and coordinate parameter.

[0080] In one embodiment, step S202 may include: the client determines the target parameter according to the following formula:

[0081] (x, y) = a -1 ·K

[0082] R = x mod n

[0083] where R is the target parameter, K is the coordinate parameter, a is the first random number, 1 ≤ a ≤ n - 1, n is the order of the elliptic curve base point, and this random number is randomly generated within the data range.

[0084] Step S203: Perform blinding calculation on the target parameter to determine the blinded target parameter.

[0085] In one embodiment, step S203 may include: the client performs blinding calculation on the target parameter according to the following formula:

[0086] R′ = R · b -1mod n

[0087] Wherein, R' is the blinded target parameter, b is a preset second random number, 1 ≤ b ≤ n - 1, and the above n is the order of the elliptic curve base point. This random number is randomly generated within the data range.

[0088] Step S204: Determine the blinded message by using the blinded message to be signed and the blinded target parameter.

[0089] In this embodiment, the blinded message includes the blinded message e' to be signed and the blinded target parameter R'.

[0090] Step S103: Send the blinded message to the signature end so that the signature end calculates the blinded message according to the ECDSA signature algorithm to determine the blinded digital signature.

[0091] In this embodiment, the user end sends the blinded message to the signature end, which can prompt the signature end to calculate the blinded message according to the ECDSA signature algorithm under the ANSI X9.62 standard specification to determine the blinded digital signature. For example, the signature value S' in the blinded digital signature can be calculated based on the blinded message e' to be signed and the blinded target parameter R'. In addition, the blinded digital signature also includes the signature value R'.

[0092] Step S104: Obtain the blinded digital signature and perform a de - blinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed.

[0093] In this embodiment, the user end performs a de - blinding calculation on the blinded digital signature sent by the signature end according to the random number used to generate the blinded message before. The obtained digital signature is the digital signature of the message to be signed by the signature end.

[0094] In one embodiment, step S104 may include: The user end performs a de - blinding calculation on the blinded digital signature according to the following formula:

[0095] S = S'·a·b mod n

[0096] Wherein, S is the signature value in the digital signature, and S' is the blinded signature value in the blinded digital signature.

[0097] After obtaining the signature value in the digital signature, the user end determines (R, S) as the digital signature, which is the ECDSA signature signed by the signer based on the message to be signed.

[0098] In this embodiment, since the value of the target parameter R has been determined when the user end calculates the blinded message, there is no need to perform a de - blinding calculation on the signature value R' in the blinded digital signature.

[0099] In the embodiment of the present application, a request message is sent to the signature end, so that the signature end determines coordinate parameters according to the request message, thereby obtaining the coordinate parameters and the message to be signed. Then, a blinded message is determined according to the message to be signed and the coordinate parameters, and the blinded message is sent to the signature end, so that the signature end calculates the blinded message according to the ECDSA signature algorithm, thereby determining a blinded digital signature with a shorter key while ensuring security. Then, a deblinding calculation is performed on the obtained blinded digital signature to determine the digital signature corresponding to the message to be signed, thereby reducing the length of the key through the ECDSA signature algorithm, correspondingly reducing the length of the blinded digital signature, and further improving the operation efficiency of the blind signature.

[0100] Embodiment 2

[0101] Figure 3 The following is a schematic flowchart of a digital signature method in the embodiment of the present application. The execution subject of this method can be a terminal device applied to the signature end, such as Figure 3 As shown, the above digital signature method may include the following steps:

[0102] Step S301: Obtain the request message of the user end, generate a third random number according to the request message, calculate the dot product of the third random number and the elliptic curve base point, and determine the dot product as the coordinate parameter.

[0103] Step S302: Send the coordinate parameter to the user end, so that the user end determines a blinded message according to the coordinate parameter and the preset message to be signed.

[0104] Step S303: Obtain the blinded message, calculate the blinded message according to the ECDSA signature algorithm, and determine the blinded digital signature.

[0105] In one embodiment, step S303 may include: The signature end calculates the blinded message according to the formula corresponding to the following ECDSA signature algorithm:

[0106] S′ = (R′·d + e′)·k -1 mod n

[0107] Where S′ is the blinded signature value in the blinded digital signature, R′ is the blinded target parameter in the blinded message, e′ is the blinded message to be signed in the blinded message, d is the private key of the signature end, obtained from the certificate of the signature end, k is the third random number, 1 ≤ k ≤ n - 1, and n is the order of the elliptic curve base point G.

[0108] After obtaining the blinded signature value in the blinded digital signature, the user end determines (R′, S′) as the blinded digital signature.

[0109] Step S304: Send the blinded digital signature to the client so that the client can perform de - blinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed.

[0110] In the embodiment of the present application, the request information of the client is obtained, a third random number is generated according to the above - mentioned request information, the dot - product of the third random number and the elliptic - curve base point is calculated, and the dot - product is determined as the coordinate parameter. The coordinate parameter is sent to the client so that the client can determine the blinded message according to the coordinate parameter and the preset message to be signed, obtain the blinded message, calculate the blinded message according to the ECDSA signature algorithm to determine the blinded digital signature. Thus, a shorter key is used to determine the blinded digital signature while ensuring security. Then, the blinded digital signature is sent to the client so that the client can perform de - blinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed. Therefore, the length of the key is reduced by the ECDSA signature algorithm, and correspondingly, the length of the blinded digital signature is also reduced, thereby improving the operation efficiency of the blind signature.

[0111] It should be understood that the magnitudes of the sequence numbers of the above - mentioned steps in the embodiments do not mean the sequence of execution. The execution sequence of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0112] Embodiment Three

[0113] Corresponding to the digital - signature method described in Embodiment One above, Figure 4 The following is a schematic structural diagram of a digital - signature device in an embodiment of the present application. As Figure 4 shown, the above - mentioned digital - signature device may include:

[0114] A request module 401, configured to send request information to the signature end so that the signature end determines the coordinate parameter according to the request information.

[0115] An acquisition module 402, configured to acquire the coordinate parameter and the message to be signed, and determine the blinded message according to the message to be signed and the coordinate parameter.

[0116] A calculation module 403, configured to send the blinded message to the signature end so that the signature end calculates the blinded message according to the ECDSA signature algorithm to determine the blinded digital signature.

[0117] A de - blinding calculation module 404, configured to acquire the blinded digital signature, perform de - blinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed.

[0118] In one embodiment, the above - mentioned acquisition module 402 may include:

[0119] The first blinding calculation sub-module is used to perform blinding calculation on the message to be signed and determine the blinded message to be signed.

[0120] The parameter determination sub-module is used to determine the target parameter according to the preset first random number and coordinate parameter.

[0121] The second blinding calculation sub-module is used to perform blinding calculation on the target parameter and determine the blinded target parameter.

[0122] The message determination sub-module is used to determine the blinded message by using the blinded message to be signed and the blinded target parameter.

[0123] In one embodiment, the above first blinding calculation sub-module may include:

[0124] The digest calculation unit is used to calculate the message digest of the message to be signed according to the preset cryptographic hash function.

[0125] The first formula calculation unit is used to perform blinding calculation on the message digest according to the following formula:

[0126] e′ = e · b -1 mod n

[0127] where e′ is the blinded message to be signed, e is the message digest, b is the preset second random number, 1 ≤ b ≤ n - 1, and n is the order of the elliptic curve base point G.

[0128] In one embodiment, the above parameter determination sub-module may include:

[0129] The second formula calculation unit is used to determine the target parameter according to the following formula:

[0130] (x, y) = a -1 ·K

[0131] R = x mod n

[0132] where R is the target parameter, K is the coordinate parameter, a is the first random number, 1 ≤ a ≤ n - 1, and n is the order of the elliptic curve base point G.

[0133] In one embodiment, the above second blinding calculation sub-module may include:

[0134] The third formula calculation unit is used to perform blinding calculation on the target parameter according to the following formula:

[0135] R′ = R · b -1 mod n

[0136] where R′ is the blinded target parameter, b is the preset second random number, 1 ≤ b ≤ n - 1, and the above n is the order of the elliptic curve base point G.

[0137] In one embodiment, the above-mentioned deblinding calculation module 404 may include:

[0138] A formula calculation sub-module, configured to perform deblinding calculation on the blinded digital signature according to the following formula:

[0139] S = S'·a·b mod n

[0140] Where S is the signature value in the digital signature, and S' is the blinded signature value in the blinded digital signature.

[0141] A signature determination sub-module, configured to determine (R, S) as the digital signature.

[0142] In the embodiment of the present application, a request message is sent to the signature end, so that the signature end determines coordinate parameters according to the request message, thereby obtaining the coordinate parameters and the message to be signed. Then, according to the message to be signed and the coordinate parameters, a blinded message is determined, and the blinded message is sent to the signature end, so that the signature end calculates the blinded message according to the ECDSA signature algorithm, thereby determining the blinded digital signature with a shorter key while ensuring security. Then, deblinding calculation is performed on the obtained blinded digital signature to determine the digital signature corresponding to the message to be signed, thereby reducing the length of the key through the ECDSA signature algorithm, correspondingly reducing the length of the blinded digital signature, and further improving the operation efficiency of the blind signature.

[0143] Embodiment 4

[0144] Corresponding to the digital signature method described in Embodiment 2 above, Figure 5 The following shows a schematic structural diagram of a digital signature device in the embodiment of the present application. As Figure 5 shown, the above-mentioned digital signature device may include:

[0145] A parameter calculation module 501, configured to obtain the request message of the user end, generate a third random number according to the request message, calculate the dot product of the third random number and the elliptic curve base point, and determine the dot product as the coordinate parameter.

[0146] A parameter sending module 502, configured to send the coordinate parameter to the user end, so that the user end determines a blinded message according to the coordinate parameter and a preset message to be signed.

[0147] A message acquisition module 503, configured to acquire the blinded message, calculate the blinded message according to the ECDSA signature algorithm, and determine the blinded digital signature.

[0148] The signature determination module 504 is configured to send the blinded digital signature to the client, so that the client performs de - blinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed.

[0149] In one embodiment, the above - mentioned message acquisition module 503 may include:

[0150] A message calculation sub - module, configured to calculate the blinded message according to the formula corresponding to the following ECDSA signature algorithm:

[0151] S′=(R′·d + e′)·k -1 mod n

[0152] where S′ is the blinded signature value in the blinded digital signature, R′ is the blinded target parameter in the blinded message, e′ is the message to be signed after blinding in the blinded message, d is the private key of the signing end, k is the third random number, 1≤k≤n - 1, and n is the order of the elliptic curve base point G.

[0153] A blinded signature determination sub - sub - module, configured to determine (R′, S′) as the blinded digital signature.

[0154] In the embodiment of the present application, the request information of the client is obtained, a third random number is generated according to the above - mentioned request information, the point multiplication of the third random number and the elliptic curve base point is calculated, and the point multiplication is determined as the coordinate parameter. The coordinate parameter is sent to the above - mentioned client, so that the client determines the blinded message according to the coordinate parameter and the preset message to be signed, obtains the blinded message, calculates the blinded message according to the ECDSA signature algorithm, determines the blinded digital signature, so as to determine the blinded digital signature with a shorter key while ensuring security, and then sends the blinded digital signature to the client, so that the client performs de - blinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed, thereby reducing the length of the key through the ECDSA signature algorithm, correspondingly reducing the length of the blinded digital signature, and further improving the operation efficiency of the blind signature.

[0155] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the above - described devices and modules can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again.

[0156] Embodiment Five

[0157] Figure 6 It is a schematic structural diagram of the terminal device provided by the embodiment of the present application. For the sake of convenience of description, only the parts related to the embodiment of the present application are shown.

[0158] As Figure 6As shown, the terminal device 6 of this embodiment includes: at least one processor 600 ( Figure 6 only one is shown in the figure), a memory 601 connected to the above-mentioned processor 600, and a computer program 602 stored in the above-mentioned memory 601 and operable on the above-mentioned at least one processor 600, such as a digital signature program. When the above-mentioned processor 600 executes the above-mentioned computer program 602, it implements the steps in the above-mentioned various digital signature method embodiments, such as Figure 1 the steps S101 to S104 shown in the figure, or Figure 3 the steps S301 to S304 shown in the figure. Alternatively, when the above-mentioned processor 600 executes the above-mentioned computer program 602, it implements the functions of each module in the above-mentioned various device embodiments, such as Figure 4 the functions of the modules 401 to 404 shown in the figure, or Figure 5 the functions of the modules 501 to 504 shown in the figure.

[0159] Exemplarily, the above-mentioned computer program 602 can be divided into one or more modules. The above-mentioned one or more modules are stored in the above-mentioned memory 601 and executed by the above-mentioned processor 600 to complete this application. The above-mentioned one or more modules can be a series of computer program instruction segments capable of completing specific functions, and these instruction segments are used to describe the execution process of the above-mentioned computer program 602 in the above-mentioned terminal device 6. For example, the above-mentioned computer program 602 can be divided into a request module 401, an acquisition module 402, a calculation module 403, and a deblinding calculation module 404, or can be divided into a parameter calculation module 501, a parameter sending module 502, a message acquisition module 503, and a signature determination module 504. The specific functions of each module are as follows:

[0160] The request module 401 is used to send a request message to the signature end so that the signature end determines coordinate parameters according to the request message;

[0161] The acquisition module 402 is used to acquire coordinate parameters and the message to be signed, and determine a blinded message according to the message to be signed and the coordinate parameters;

[0162] The calculation module 403 is used to send the blinded message to the signature end so that the signature end calculates the blinded message according to the ECDSA signature algorithm and determines the blinded digital signature;

[0163] The deblinding calculation module 404 is used to acquire the blinded digital signature, perform deblinding calculation on the blinded digital signature, and determine the digital signature corresponding to the message to be signed.

[0164] The coordinate parameter calculation module 501 is used to acquire the request message of the user end, generate a third random number according to the request message, calculate the dot product of the third random number and the base point of the elliptic curve, and determine the dot product as the coordinate parameter;

[0165] A coordinate parameter sending module 502, configured to send coordinate parameters to a client, so that the client determines a blinded message according to the coordinate parameters and a preset message to be signed;

[0166] A message obtaining module 503, configured to obtain the blinded message, calculate the blinded message according to the ECDSA signature algorithm, and determine a blinded digital signature;

[0167] A signature determining module 504, configured to send the blinded digital signature to the client, so that the client performs a deblinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed.

[0168] The above terminal device 6 may include, but is not limited to, a processor 600 and a memory 601. Those skilled in the art can understand that Figure 6 merely an example of the terminal device 6, which does not constitute a limitation on the terminal device 6, and may include more or fewer components than shown in the figure, or combine some components, or different components. For example, it may also include input / output devices, network access devices, buses, etc.

[0169] The so-called processor 600 may be a central processing unit (CPU), and the processor 600 may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0170] In some embodiments, the aforementioned memory 601 may be an internal storage unit of the aforementioned terminal device 6, such as the hard disk or memory of the terminal device 6. In other embodiments, the aforementioned memory 601 may also be an external storage device of the aforementioned terminal device 6, such as a plug-in hard disk equipped on the aforementioned terminal device 6, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. Further, the aforementioned memory 601 may also include both the internal storage unit of the aforementioned terminal device 6 and the external storage device. The aforementioned memory 601 is used to store an operating system, application programs, a Boot Loader, data, and other programs, such as the program code of the aforementioned computer program, etc. The aforementioned memory 601 may also be used to temporarily store data that has been output or will be output.

[0171] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the above-mentioned device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiments can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of the functional units and modules are only for the convenience of mutual distinction and do not limit the protection scope of this application. The specific working processes of the units and modules in the above-mentioned system can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here. In the above-mentioned embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0172] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0173] In the embodiments provided in the present application, it should be understood that the disclosed device / terminal device and method can be implemented in other ways. For example, the device / terminal device embodiments described above are merely illustrative. For example, the above-mentioned division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in electrical, mechanical or other forms.

[0174] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0175] If the above-mentioned integrated unit is implemented in the form of a software function unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned method embodiments of the present application, a computer program can be used to instruct the relevant hardware to complete. The above-mentioned computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned method embodiments can be implemented. Among them, the above-mentioned computer program includes computer program code, and the above-mentioned computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The above-mentioned computer-readable medium can at least include: any entity or device that can carry the computer program code to the photographing device / terminal device, recording medium, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunication signal.

[0176] The foregoing embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A digital signature method, characterized in that, applied to the client side, including: sending a request message to the signature side so that the signature side determines coordinate parameters according to the request message; wherein, the signature side randomly generates a random number from a preset data set according to the request message of the client side, the random number is a private key randomly generated by the signature side, and the data set is determined according to the elliptic curve number field corresponding to the ECDSA signature algorithm; when the base point of the current elliptic curve is of order n and n is a prime number, the data set is all integers from 1 to n - 1; the signature side determines the point multiplication of the random number and the base point as the coordinate parameters; the signature side sends the coordinate parameters to the signature side and stores the coordinate parameters, the base point is located on the elliptic curve, and the base point is a set of coordinate values; obtaining the coordinate parameters and the message to be signed, and determining a blinded message according to the message to be signed and the coordinate parameters; sending the blinded message to the signature side so that the signature side calculates the blinded message according to the ECDSA signature algorithm to determine the blinded digital signature; obtaining the blinded digital signature and performing de - blinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed; The determining the blinded message according to the message to be signed and the coordinate parameters includes: performing blinding calculation on the message to be signed to determine the blinded message to be signed, including: calculating the message digest of the message to be signed according to a preset cryptographic hash function; performing blinding calculation according to a preset second random number and the message digest; determining a target parameter according to a preset first random number and the coordinate parameters; performing blinding calculation on the target parameter to determine the blinded target parameter; determining the blinded message by using the blinded message to be signed and the blinded target parameter.

2. The digital signature method according to claim 1, characterized in that, performing blinding calculation on the message digest according to the following formula: e’ = e · b -1 mod n wherein, e’ is the blinded message to be signed, e is the message digest, b is a preset second random number, 1 ≤ b ≤ n - 1, and n is the order of the elliptic curve base point.

3. The digital signature method according to claim 1, characterized in that, The determining the target parameter according to the preset first random number and the coordinate parameters includes: determining the target parameter according to the following formula: (x, y) = a -1 ·K R = x mod n wherein, R is the target parameter, K is the coordinate parameter, a is the first random number, 1 ≤ a ≤ n - 1, and n is the order of the elliptic curve base point.

4. The digital signature method according to claim 3, characterized in that, The performing blinding calculation on the target parameter to determine the blinded target parameter includes: performing blinding calculation on the target parameter according to the following formula: R’ = R·b -1 mod n wherein, R’ is the blinded target parameter, b is a preset second random number, 1 ≤ b ≤ n - 1, and the above n is the order of the elliptic curve base point.

5. The digital signature method according to claim 4, characterized in that, Performing de - blinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed, includes: Performing de - blinding calculation on the blinded digital signature according to the following formula: S = S’·a·b mod n Wherein, S is the signature value in the digital signature, and S’ is the blinded signature value in the blinded digital signature; Determining (R, S) as the digital signature.

6. A digital signature method, Characterized in that, Applied to the signature side, includes: Obtaining the request information of the user side, generating a third random number according to the request information, calculating the point multiplication of the third random number and the elliptic curve base point, and determining the point multiplication as the coordinate parameter; wherein, the signature side randomly generates a random number from a preset data set according to the request information of the user side, the random number is a private key randomly generated by the signature side, and the data set is determined according to the elliptic curve number field corresponding to the ECDSA signature algorithm; when the base point of the current elliptic curve is of order n and n is a prime number, the data set is all integers from 1 to n - 1; the signature side determines the point multiplication of the random number and the base point as the coordinate parameter; the signature side sends the coordinate parameter to the signature side and stores the coordinate parameter, the base point is located on the elliptic curve and the base point is a set of coordinate values; Sending the coordinate parameter to the user side so that the user side determines the blinded message according to the coordinate parameter and the preset message to be signed; Obtaining the blinded message, calculating according to the ECDSA signature algorithm for the blinded message to determine the blinded digital signature; Sending the blinded digital signature to the user side so that the user side performs de - blinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed; The user side determines the blinded message according to the coordinate parameter and the preset message to be signed, includes: Performing blinding calculation on the message to be signed to determine the blinded message to be signed, includes: calculating the message digest of the message to be signed according to a preset cryptographic hash function; performing blinding calculation according to a preset second random number and the message digest; Determining the target parameter according to a preset first random number and the coordinate parameter; Performing blinding calculation on the target parameter to determine the blinded target parameter; Determining the blinded message to be signed and the blinded target parameter as the blinded message.

7. The digital signature method according to claim 6, Characterized in that, The calculating according to the ECDSA signature algorithm for the blinded message to determine the blinded digital signature, includes: Calculating the blinded message according to the formula corresponding to the ECDSA signature algorithm as follows: S’ = (R’·d + e’)·k -1 mod n Wherein, S’ is the blinded signature value in the blinded digital signature, R’ is the blinded target parameter in the blinded message, e’ is the blinded message to be signed in the blinded message, d is the private key of the signature side, k is the third random number, 1 ≤ k ≤ n - 1, and n is the order of the elliptic curve base point; Determining (R’, S’) as the blinded digital signature.

8. A digital signature device, It is characterized in that it includes: A request module, configured to send request information to a signature end, so that the signature end determines coordinate parameters according to the request information; wherein, the signature end randomly generates a random number from a preset data set according to the request information of the user end, and the random number is a private key randomly generated by the signature end, and the data set is determined according to the elliptic curve number field corresponding to the ECDSA signature algorithm; when the base point of the current elliptic curve is of order n and n is a prime number, the data set is all integers from 1 to n-1; the signature end determines the point multiplication of the random number and the base point as the coordinate parameters; the signature end sends the coordinate parameters to the signature end and stores the coordinate parameters, the base point is located on the elliptic curve, and the base point is a set of coordinate values; An acquisition module, configured to acquire the coordinate parameters and the message to be signed, and determine a blinded message according to the message to be signed and the coordinate parameters; A calculation module, configured to send the blinded message to the signature end, so that the signature end calculates the blinded message according to the ECDSA signature algorithm to determine a blinded digital signature; A de-blinding calculation module, configured to acquire the blinded digital signature and perform de-blinding calculation on the blinded digital signature to determine the digital signature corresponding to the message to be signed; The acquisition module includes: A first blinding calculation sub-module, configured to perform blinding calculation on the message to be signed to determine the blinded message to be signed; A parameter determination sub-module, configured to determine a target parameter according to a preset first random number and the coordinate parameters; A second blinding calculation sub-module, configured to perform blinding calculation on the target parameter to determine the blinded target parameter; A message determination sub-module, configured to determine the blinded message to be signed and the blinded target parameter as the blinded message; The first blinding calculation sub-module includes: A digest calculation unit, configured to calculate the message digest of the message to be signed according to a preset cryptographic hash function; A first formula calculation unit, configured to perform blinding calculation according to a preset second random number and the message digest.

9. A terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, it is characterized in that when the processor executes the computer program, the steps of a digital signature method according to any one of claims 1 to 5 or any one of claims 6 to 7 are implemented.

Citation Information

Patent Citations

  • Construction method for one-time anonymous signcryption of public key

    CN103297241A

  • Blind signature method based on elliptic curve and device thereof

    CN103780385A