Method and electronic device for obtaining adapter signature based on bilinear mapping

By adopting a bilinear mapping-based adapter signature scheme in blockchain, the problems of excessive signature length and high computing overhead in the prior art are solved, and more compact and efficient signature processing is achieved.

CN114844643BActive Publication Date: 2025-05-16CHINA NANHU ACAD OF ELECTRONICS & INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210337085.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-01
Publication Date
2025-05-16
Estimated Expiration
2042-04-01

AI Technical Summary

Technical Problem

The existing adapter signature scheme has limitations in terms of signature length and computing overhead, especially the ECDSA and SM2-based schemes are too long and the computing overhead is large, making it difficult to meet the blockchain system's demand for efficient and compact signatures.

Method used

An adapter signature scheme based on bilinear mapping is proposed. The signature scheme is constructed through bilinear mapping, which shortens the signature length and improves the computing efficiency through batch verification.

Benefits of technology

A significant shortening of signature length is achieved, making it half the length of the ECDSA and SM2 scheme based on the length, while improving the computing efficiency of multiple signature processing through batch verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114844643B_ABST
    Figure CN114844643B_ABST
Patent Text Reader

Abstract

The present invention proposes a method and electronic device for obtaining an adapter signature based on a bilinear mapping. The method includes: obtaining a first signature scheme between a signer and a verifier, the first signature scheme being used to realize the generation of a first signature of the signer and the verification of the first signature by the verifier. The first signature scheme is adapted based on the first signature of the signer and the encrypted information of the verifier to obtain an adapted second signature scheme, the second signature scheme being used to realize the information exchange between the signer and the verifier based on the generated second signature, the exchanged information being the first signature of the signer and the encrypted information of the verifier, so that the verifier completes the verification of the first signature and the signer decrypts the encrypted information of the verifier.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the field of data processing and security verification, and in particular relates to a method for obtaining an adapter signature based on a bilinear mapping. Background Art

[0002] Blockchain is a decentralized, tamper-proof, and traceable distributed data storage technology that realizes point-to-point value transfer and solves the problems of trusted ownership and secure sharing of data circulation in the digital world. Its applications have extended to digital finance, the Internet of Things, intelligent manufacturing, supply chain management and other fields, becoming an important infrastructure for building a trust system in the digital world.

[0003] However, the inherent "impossible triangle" of blockchain technology shows that any blockchain can only take into account at most two of the decentralization, scalability and security. Regarding scalability, on-chain expansion and off-chain expansion have become two important development directions. On-chain expansion is to expand the blockchain itself. The main methods include block expansion, segregated witness and sharding technology. Off-chain expansion refers to the technology running on the blockchain system with the goal of improving the scalability of the blockchain, that is, moving some transactions on the blockchain to the off-chain for processing, and only putting the final results on the chain, thereby reducing the processing pressure on the blockchain and improving the overall efficiency of the blockchain. It mainly includes state channels, side chains and off-chain computing.

[0004] Adapter signature is an important technical means to build state channels. It was originally designed to break through the limitations of blockchain systems based on scripting languages, realize invisible scripts (scriptless script) and privacy protection functions, and later evolved into a new type of digital signature cryptographic primitive. The basic idea is to bind the signing process to a secret disclosure process. The user first generates a pre-signature, which implies a statement in a difficult relationship (the statement is a value that can be made public, and it is difficult to calculate the witness from the statement). Only by using the witness in the difficult relationship (it is confidential before it is revealed, and the statement is easy to calculate from the witness) can the pre-signature be converted into a verified legal digital signature; using the pre-signature and the corresponding digital signature, the witness in the difficult relationship can be extracted.

[0005] The signature and secret disclosure binding characteristics of the adapter signature are particularly suitable for application scenarios where blockchain transactions (including signatures) are on-chain (i.e., public) and confirmed (i.e., valid). It can be used to implement various atomic exchanges that do not rely on trusted third parties (i.e., both parties to the exchange either obtain their respective exchange objects or neither obtains anything, also known as fair exchange). It mainly includes using the adapter to construct off-chain state channels of a single blockchain and cross-chain atomic exchanges between two different chains. For example, in 2019, at the Network and Distributed System Security Symposium (NDSS), Malavolta et al. published an article titled "Anonymous multi-hop locks for blockchain scalability and interoperability", which used the adapter signature scheme to implement privacy protection for the state channel network; for another example, in 2020, at the International Conference on Financial Cryptography and Data Security (FC), Deshpande et al. used adapter signatures in their article "Privacy-Preserving Cross-Chain Atomic Swaps" to implement a privacy-preserving cross-chain atomic exchange scheme.

[0006] Take the adapter signature for cross-chain atomic swap as an example: suppose Alice wants to exchange 1 Bitcoin for Bob's 13 Ethereum. Alice first locks 1 Bitcoin in a 2-of-2 Bitcoin address agreed upon with Bob, and stipulates that if the Bitcoin in the address has not been spent after a long period of time, 1 Bitcoin will be returned to Alice's original address. Alice then constructs Bitcoin transaction TX1, outputs 1 Bitcoin from the 2-of-2 address to the Bitcoin address specified by Bob, and the condition for unlocking TX1 is to provide Alice and Bob's signatures on the transaction at the same time. Bob correspondingly locks 13 Ethereum in an account jointly managed by Alice and Bob on Ethereum, and stipulates that if the Ethereum in the account has not been spent after a long period of time, 13 Ethereum will be returned to Bob's original account. Bob then constructs Ethereum transaction TX2 , output 13 ethers in the co-managed account to the Ethereum account specified by Alice. The condition for unlocking TX2 is to provide Alice and Bob's signatures on the transaction at the same time. The remaining task is to make the two transactions TX1 and TX2 effective together or not effective on their respective blockchains (thereby ensuring the atomicity of the exchange). The key to the effectiveness of these two transactions is that in addition to their own signatures, the other party's signature on their respective transactions is also required. Both parties can generate pre-signatures for different transactions according to the adapter signature scheme. These pre-signatures are bound by the same difficult relationship Y=gy based on the discrete logarithm relationship. Once the party who knows the witness y uses y to convert a pre-signature into the full signature it needs, and publishes the transaction (and the corresponding full signature) on the corresponding blockchain, the other party can calculate the witness y through the observed public information, thereby obtaining the full signature it needs, and then publish the corresponding transaction on another blockchain.

[0007] Due to the unique properties of adapters, they have attracted the attention of blockchain and cryptography researchers. In 2017, Poelstra first proposed the concept of adapter signatures and constructed the first adapter signature scheme based on Schnorr signatures. In 2019, at the Network and Distributed System Security Symposium (NDSS), Malavolta et al. published the paper "Anonymous multi-hoplocks for blockchain scalability and interoperability", which constructed adapter signature schemes based on Schnorr signatures and ECDSA respectively. In 2020, at the European Symposium on Computer Security (ESORICS), Esgin et al. published the paper "Post-quantum adaptor signature and payment channel networks", which constructed a post-quantum secure adapter signature scheme based on lattice cryptography. In 2021, at the International Conference on Financial Cryptography and Data Security, Tairi et al. published the paper "Post-quantum adaptor signature for privacy-preserving off-chain payments", which constructed a post-quantum secure adapter signature scheme based on homology mapping cryptography. In 2021, at the ASIACRYPT conference, Aumayr et al. published a paper titled "Generalized channels from limited blockchain scripts and adaptor signatures", which formally defined the adapter signature as an independent cryptographic primitive and performed a provable security analysis of the adapter signature scheme based on Schnorr signature and ECDSA. In 2021, at the International Conference on Public Key Cryptography (PKC), Erwig et al. published a paper titled "Two-party adapter signatures from identification schemes", which pointed out that digital signature schemes based on identity protocols that meet specific homomorphism can be converted into adapter signature schemes. In 2021, in the domestic journal "Computer Research and Development", Peng et al. published a paper titled "Adapter Signature Scheme Based on SM2 Digital Signature Algorithm", which is based on the national secret algorithm SM2 digital signature algorithm and also designed an adapter signature scheme.

[0008] Adapter signature is a relatively new cryptographic primitive. There are relatively few existing schemes, and there is no adapter signature scheme constructed using bilinear mapping on elliptic curves. Tate pairs or Weil pairs on hyperelliptic curves over finite fields can construct bilinear mappings, and some difficult problems on such hyperelliptic curves are the security basis for constructing public key cryptographic systems using bilinear mappings. Bilinear mapping plays a very important role in public key cryptography. It can be used to construct cryptographic systems that cannot be achieved by other technologies, such as identity-based signatures or encryption; it can also be used to construct cryptographic systems with performance advantages, such as attribute-based encryption, key agreement protocols, and threshold schemes.

[0009] At the same time, the existing adapter signature scheme on the elliptic curve also has certain limitations: although the adapter signature based on the Schnorr signature has incomparable advantages in terms of signature length and signature overhead, it cannot be implemented in the blockchain system at present because the Schnorr signature is still under patent protection. Under the same security strength, the adapter signature based on the ECDSA adapter signature and the adapter signature based on the national secret algorithm SM2 have the same length, which is three times that of the adapter signature based on the Schnorr signature. In terms of computational overhead, the ECDSA adapter signature is significantly higher than the adapter signature based on the Schnorr signature, and the SM2 adapter signature after preprocessing (some operations in the signature process are processed in advance and not counted in the signature overhead) is equivalent to the ECDSA adapter signature.

[0010] Therefore, designing an adapter signature with shorter signature length using bilinear mapping is the main goal of the present invention. Summary of the invention

[0011] In view of the above technical problems, the present invention proposes a solution for obtaining an adapter signature based on a bilinear mapping.

[0012] In the adapter signature, the signer generates a pre-signature for a message. The pre-signature is not a complete signature, but contains a statement in a difficult relationship. Only users who know the witness corresponding to the statement can convert the pre-signature into a digital signature that verifies legality. For the adapter signature, the digital signature must be made public to be effective. The purpose of the public is to allow the signer to obtain the digital signature. At this time, the signer can extract the witness from it and the pre-signature. In this way, the binding of the signing process and the secret disclosure is achieved.

[0013] The ECDSA-based adapter signature is no different in form from the ECDSA signature widely used in mainstream blockchains, but hidden control conditions can be embedded in it to achieve secure interaction between the chain and the off-chain. Therefore, when the adapter signature is used to implement cross-chain atomic swaps, the on-chain data is limited to common digital signatures, which is no different from general conventional blockchain transactions. This makes it impossible for attackers to tell whether the transaction is a cross-chain transaction even if they can monitor the underlying blockchain data, thereby maximizing the privacy of the participants in the cross-chain transaction and minimizing the on-chain overhead.

[0014] However, adapter signature is a relatively new concept, and there are relatively few existing solutions. In particular, there is no adapter signature scheme based on bilinear mapping. Among the few public key schemes currently available, the length of adapter signature based on ECDSA and SM2 is too long, which needs to be further improved for blockchains where block capacity is particularly precious.

[0015] To this end, the goal of the present invention is to propose for the first time an adapter signature scheme based on bilinear mapping, which has a shorter signature length, which is half the length of the ECDSA adapter signature and the SM2-based adapter signature. In terms of computational overhead, because of the use of bilinear mapping, the computational efficiency of the signature is lower than that of the ECDSA adapter signature and the SM2-based adapter signature. However, this defect can be solved by the technical solution of the present invention for the blockchain system.

[0016] A first aspect of the present invention discloses a method for acquiring an adapter signature based on a bilinear mapping.

[0017] The method comprises:

[0018] Step S1: obtaining a first signature scheme between a signer and a verifier, wherein the first signature scheme is used to realize generation of a first signature of the signer and verification of the first signature by the verifier;

[0019] The first signature scheme includes a key generation step, a first signature generation step and a first signature verification step; wherein:

[0020] In the key generation step, a public key and a private key of the signer are generated, the public key is generated based on the private key, and the verifier can obtain the public key but cannot obtain the private key;

[0021] In the first signature generation step, a first signature of the signer is generated according to the private key and the message to be signed;

[0022] In the first signature verification step, the verifier verifies the legitimacy of the first signature of the signer using the public key and the message to be signed;

[0023] Step S2: Based on the first signature of the signer and the encrypted information of the verifier, the first signature scheme is adapted to obtain an adapted second signature scheme, wherein the second signature scheme is used to implement information exchange between the signer and the verifier based on the generated second signature, wherein the exchanged information is the first signature of the signer and the encrypted information of the verifier, so that the verifier completes the verification of the first signature and the signer decrypts the encrypted information of the verifier;

[0024] The second signature scheme includes a pre-signature generation step, a pre-signature verification step, a second signature adaptation step, and an encrypted information extraction step, the encrypted information includes declaration information and witness information, the declaration information is generated based on the witness information, and the signatory can only obtain the declaration information but not the witness information before adaptation;

[0025] In the pre-signature generation step, a pre-signature of the message to be signed by the signer related to the declaration information is generated according to the private key, the message to be signed and the declaration information;

[0026] In the pre-signature verification step, the verifier verifies the legitimacy of the pre-signature of the signer based on the public key, the message to be signed and the declaration information;

[0027] In the step of adapting the second signature, after completing the legitimacy verification of the pre-signature, the verifier embeds the witness information into the pre-signature to generate the second signature, and simultaneously obtains the first signature from the second signature using the witness information;

[0028] In the encrypted information extraction step, the signer extracts the witness information from the second signature using the declaration information.

[0029] According to the method of the first aspect of the present invention, in step S1, generating the private key and the public key of the signer includes: randomly selecting a finite field Z of an integer modulo q q A non-zero element x in is used as the private key sk, where Calculate h = g x ∈G is used as the public key pk, where g is a generator of the cyclic group G of prime order formed by the points on the elliptic curve, thereby obtaining a public-private key pair (pk, sk) = (h, x).

[0030] According to the method of the first aspect of the present invention, in step S1, generating the first signature of the signer according to the private key and the message to be signed includes: the signer randomly selects Calculate R = g r , s=H(m||R) x , to obtain the first signature δ = (r, s), where m is the message to be signed, H: {0, 1} * →G is a collision-resistant hash function that maps a bit string consisting of 0s and 1s to the cyclic group G.

[0031] According to the method of the first aspect of the present invention, in the step S1, using the public key and the message to be signed to verify the legitimacy of the first signature includes: the verifier uses the public key pk and the message to be signed m to verify the equation e(s, g)=e(H(m||g r ), h) is true, if true, then the legitimacy of the first signature is passed and output 1; otherwise, it fails and outputs 0.

[0032] According to the method of the first aspect of the present invention, in step S2, generating the pre-signature of the message to be signed includes: the signer randomly selects calculate Thus, the pre-signature of the message m to be signed by the signer related to the declaration information Y is obtained.

[0033] According to the method of the first aspect of the present invention, in step S2, the verification party verifies the legitimacy of the pre-signature of the signer, including: the verifier verifies the equation based on the public key pk, the message m to be signed and the declaration information Y Is it true? If so, the legitimacy of the pre-signature is verified and 1 is output; otherwise, it fails and 0 is output.

[0034] According to the method of the first aspect of the present invention, in step S2, embedding the witness information into the pre-signature to generate the second signature includes: make , thereby obtaining the second signature embedded with the witness information

[0035] According to the method of the first aspect of the present invention, in step S2, the signer extracts the witness information from the second signature using the declaration information, including: Verify the equation Y = g y Is it true? If so, output the witness y. Otherwise, the extraction fails and the failure indicator ⊥ is output.

[0036] A second aspect of the present invention discloses a system for acquiring adapter signatures based on bilinear mapping.

[0037] The system comprises:

[0038] A first processing unit is configured to obtain a first signature scheme between a signer and a verifier, wherein the first signature scheme is used to generate a first signature of the signer and verify the first signature by the verifier;

[0039] The first signature scheme includes a key generation step, a first signature generation step and a first signature verification step; wherein:

[0040] In the key generation step, a public key and a private key of the signer are generated, the public key is generated based on the private key, and the verifier can obtain the public key but cannot obtain the private key;

[0041] In the first signature generation step, a first signature of the signer is generated according to the private key and the message to be signed;

[0042] In the first signature verification step, the verifier verifies the legitimacy of the first signature of the signer using the public key and the message to be signed;

[0043] a second processing unit configured to complete adaptation of the first signature scheme based on the first signature of the signer and the encrypted information of the verifier to obtain an adapted second signature scheme, wherein the second signature scheme is used to implement information exchange between the signer and the verifier based on the generated second signature, wherein the exchanged information is the first signature of the signer and the encrypted information of the verifier, so that the verifier completes verification of the first signature and the signer decrypts the encrypted information of the verifier;

[0044] The second signature scheme includes a pre-signature generation step, a pre-signature verification step, a second signature adaptation step, and an encrypted information extraction step, the encrypted information includes declaration information and witness information, the declaration information is generated based on the witness information, and the signatory can only obtain the declaration information but not the witness information before adaptation;

[0045] In the pre-signature generation step, a pre-signature of the message to be signed by the signer related to the declaration information is generated according to the private key, the message to be signed and the declaration information;

[0046] In the pre-signature verification step, the verifier verifies the legitimacy of the pre-signature of the signer based on the public key, the message to be signed and the declaration information;

[0047] In the step of adapting the second signature, after completing the legitimacy verification of the pre-signature, the verifier embeds the witness information into the pre-signature to generate the second signature, and simultaneously obtains the first signature from the second signature using the witness information;

[0048] In the encrypted information extraction step, the signer extracts the witness information from the second signature using the declaration information.

[0049] According to the system of the second aspect of the present invention, the first processing unit is specifically configured to generate the private key and the public key of the signer, including: randomly selecting a finite field Z of an integer modulus q q A non-zero element x in is used as the private key sk, where Calculate h = g x ∈G is used as the public key pk, where g is a generator of the cyclic group G of prime order formed by the points on the elliptic curve, thereby obtaining a public-private key pair (pk, sk) = (h, x).

[0050] According to the system of the second aspect of the present invention, the first processing unit is specifically configured to generate the first signature of the signer according to the private key and the message to be signed, including: the signer randomly selects Calculate R = g r , s=H(m||R) x , to obtain the first signature δ = (r, s), where m is the message to be signed, H: {0, 1} * →G is a collision-resistant hash function that maps a bit string consisting of 0s and 1s to the cyclic group G.

[0051] According to the system of the second aspect of the present invention, the first processing unit is specifically configured to verify the legitimacy of the first signature using the public key and the message to be signed, including: the verifier uses the public key pk and the message to be signed m to verify the equation e(s, g)=e(H(m||g r ), h) is true, if true, then the legitimacy of the first signature is passed and output 1; otherwise, it fails and outputs 0.

[0052] According to the system of the second aspect of the present invention, the second processing unit is specifically configured to generate the pre-signature of the message to be signed, including: the signer randomly selects calculate Thus, the pre-signature of the message m to be signed by the signer related to the declaration information Y is obtained.

[0053] According to the system of the second aspect of the present invention, the second processing unit is specifically configured as: the verifier verifies the legitimacy of the pre-signature of the signer, including: the verifier verifies the equation based on the public key pk, the message m to be signed and the declaration information Y Is it true? If so, the legitimacy of the pre-signature is verified and 1 is output; otherwise, it fails and 0 is output.

[0054] According to the system of the second aspect of the present invention, the second processing unit is specifically configured to embed the witness information into the pre-signature to generate the second signature, including: make Thus, the second signature embedded with the witness information is obtained.

[0055] According to the system of the second aspect of the present invention, the second processing unit is specifically configured as follows: the signatory extracts the witness information from the second signature using the declaration information, including: Verify the equation Y = g y Is it true? If so, output the witness y. Otherwise, the extraction fails and the failure indicator ⊥ is output.

[0056] The third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps in the method for obtaining an adapter signature based on a bilinear mapping described in any one of the first aspects of the present disclosure are implemented.

[0057] The fourth aspect of the present invention discloses a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in any one of the methods for acquiring adapter signatures based on bilinear mapping described in the first aspect of the present disclosure.

[0058] In summary, the technical solution provided by the present invention provides more options for using the adapter signature scheme in the blockchain. Due to the use of bilinear mapping, the length of the adapter signature of the present invention is only half of that based on the ECDSA adapter signature and the adapter signature based on the national secret algorithm SM2. In order to improve the efficiency of the verification algorithm in the present invention, a batch verification method is used to greatly improve the computing efficiency when multiple signatures are used. However, the adapter signature based on the ECDSA adapter signature and the adapter signature based on the national secret algorithm SM2 do not have the characteristics of batch verification. Therefore, when processing multiple signatures, the computing performance of the present invention will further narrow the gap with the adapter signature based on the ECDSA adapter signature and the adapter signature based on the national secret algorithm SM2. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0060] Figure 1 A flowchart of a method for obtaining an adapter signature based on a bilinear map according to an embodiment of the present invention;

[0061] Figure 2 A structural diagram of a system for acquiring an adapter signature based on a bilinear mapping according to an embodiment of the present invention;

[0062] Figure 3 The figure is a structural diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0063] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0064] A first aspect of the present invention discloses a method for acquiring an adapter signature based on a bilinear mapping. Figure 1 FIG. 4 is a flow chart of a method for obtaining an adapter signature based on a bilinear mapping according to an embodiment of the present invention; Figure 1 As shown, the method includes:

[0065] Step S1: obtaining a first signature scheme between a signer and a verifier, wherein the first signature scheme is used to realize generation of a first signature of the signer and verification of the first signature by the verifier;

[0066] The first signature scheme includes a key generation step, a first signature generation step and a first signature verification step; wherein:

[0067] In the key generation step, a public key and a private key of the signer are generated, the public key is generated based on the private key, and the verifier can obtain the public key but cannot obtain the private key;

[0068] In the first signature generation step, a first signature of the signer is generated according to the private key and the message to be signed;

[0069] In the first signature verification step, the verifier verifies the legitimacy of the first signature of the signer using the public key and the message to be signed;

[0070] Step S2: Based on the first signature of the signer and the encrypted information of the verifier, the first signature scheme is adapted to obtain an adapted second signature scheme, wherein the second signature scheme is used to implement information exchange between the signer and the verifier based on the generated second signature, wherein the exchanged information is the first signature of the signer and the encrypted information of the verifier, so that the verifier completes the verification of the first signature and the signer decrypts the encrypted information of the verifier;

[0071] The second signature scheme includes a pre-signature generation step, a pre-signature verification step, a second signature adaptation step, and an encrypted information extraction step, the encrypted information includes declaration information and witness information, the declaration information is generated based on the witness information, and the signatory can only obtain the declaration information but not the witness information before adaptation;

[0072] In the pre-signature generation step, a pre-signature of the message to be signed by the signer related to the declaration information is generated according to the private key, the message to be signed and the declaration information;

[0073] In the pre-signature verification step, the verifier verifies the legitimacy of the pre-signature of the signer based on the public key, the message to be signed and the declaration information;

[0074] In the step of adapting the second signature, after completing the legitimacy verification of the pre-signature, the verifier embeds the witness information into the pre-signature to generate the second signature, and simultaneously obtains the first signature from the second signature using the witness information;

[0075] In the encrypted information extraction step, the signer extracts the witness information from the second signature using the declaration information.

[0076] The method of the first aspect of the present invention constructs a probabilistic digital signature scheme (first signature scheme) using bilinear mapping, and then uses the scheme to construct a corresponding adapter signature scheme (second signature scheme). Before introducing the constructed signature scheme, two concepts used in the scheme are first introduced, namely, bilinear mapping and difficulty relation.

[0077] Bilinear Maps: G and G T It is a cyclic group of points on the elliptic curve with an order of a large prime number q, called the mapping e: G×G→G T is a bilinear map if e has the following properties:

[0078] Bilinear: For P, Q∈G, and a finite field Z of integers modulo q q For any two elements a and b in a , Q b ) = e(P,Q) ab .

[0079] Non-degeneracy: If g is a generator of the group G, then e(g, g) is non-degenerate, that is,

[0080] Computability: For any P, Q∈G, e(P, Q) can be efficiently computed.

[0081] Difficult relations: Let R be a binary relation, L R is the language to describe this relationship, denoted by here Indicates that (Y, y) satisfies the binary relationship An instance of , call Y a statement and y a witness. If R satisfies the following properties, then R is called a difficult relation:

[0082] (1) There exists a probabilistic polynomial-time algorithm that takes a security parameter as input and outputs

[0083] (2) There exists a deterministic polynomial time algorithm that can determine whether (Y, y) satisfies the difficult relation, namely Is it true?

[0084] (3) Against any polynomial-time adversary and Calculate y so that The probability of is negligible.

[0085] In step S1, a first signature scheme between a signer and a verifier is obtained, where the first signature scheme is used to realize generation of a first signature of the signer and verification of the first signature by the verifier.

[0086] The first signature scheme includes a key generation step, a first signature generation step and a first signature verification step; wherein:

[0087] In the key generation step, a public key and a private key of the signer are generated, the public key is generated based on the private key, and the verifier can obtain the public key but cannot obtain the private key;

[0088] In the first signature generation step, a first signature of the signer is generated according to the private key and the message to be signed;

[0089] In the first signature verification step, the verifier verifies the legitimacy of the first signature of the signer using the public key and the message to be signed.

[0090] Specifically, based on the bilinear map e defined above: G×G→G T , and a collision-resistant hash function that maps a bit string consisting of 0s and 1s to the group G, namely H: {0, 1} * →G, the first signature scheme SIG = (KeyGen, Sign, Vrfy), which includes the key generation algorithm KeyGen (key generation step), the signature algorithm Sign (first signature generation step) and the signature verification algorithm Vrfy (first signature verification step). The three sub-algorithms (modules) are as follows:

[0091] In some embodiments, in step S1, generating the private key and the public key of the signer includes: randomly selecting a finite field Z of an integer modulo q q A non-zero element x in is used as the private key sk, where Calculate h = g x ∈G is used as the public key pk, where g is a generator of the cyclic group G of prime order formed by the points on the elliptic curve, thereby obtaining a public-private key pair (pk, sk) = (h, x).

[0092] Specifically, KeyGen(1 n ): Key generation algorithm, the input is security parameter n, and the output is a public key pair (pk, sk) = (h, x). The specific process is: randomly select a finite field Z of integer modulus q q A non-zero element x in Calculate h = g x ∈ G. The signer's public-private key pair is (pk, sk) = (h, x), the public key pk is made public, and the private key sk is kept secret.

[0093] In some embodiments, in step S1, generating the first signature of the signer according to the private key and the message to be signed includes: the signer randomly selects Calculate R = g r , s=H(m||R) x , to obtain the first signature δ = (r, s), where m is the message to be signed, H: {0, 1} * →G is a collision-resistant hash function that maps a bit string consisting of 0s and 1s to the cyclic group G.

[0094] Specifically, Sign(sk, m): signature algorithm, the input is the signer's private key sk and the message m to be signed, and the output is the signature δ = (r, s) of the message m. The specific process is: the signer randomly selects Calculate R = g r , s=H(m||R) x , and obtain the signature δ=(r, s) of message m.

[0095] In some embodiments, in step S1, using the public key and the message to be signed to verify the legitimacy of the first signature includes: the verifier uses the public key pk and the message to be signed m to verify the equation e(s, g)=e(H(m||g r ), h) is true, if true, then the legitimacy of the first signature is passed and output 1; otherwise, it fails and outputs 0.

[0096] Specifically, Vrfy(pk, m, δ): verification algorithm, input message m, signature δ = (r, s) and signature public key pk, if the signature verification is legal, it outputs 1, otherwise it outputs 0. The specific process is: after the signature verifier receives the message m and its corresponding signature δ = (r, s), it verifies the equation e(s, g) = e(H(m||g r ), h) is true, if true, the signature verification is legal and outputs 1; otherwise, outputs 0.

[0097] In step S2, the first signature scheme is adapted based on the first signature of the signer and the encrypted information of the verifier to obtain an adapted second signature scheme, wherein the second signature scheme is used to implement information exchange between the signer and the verifier based on the generated second signature, wherein the exchanged information is the first signature of the signer and the encrypted information of the verifier, so that the verifier completes the verification of the first signature and the signer decrypts the encrypted information of the verifier;

[0098] The second signature scheme includes a pre-signature generation step, a pre-signature verification step, a second signature adaptation step, and an encrypted information extraction step, the encrypted information includes declaration information and witness information, the declaration information is generated based on the witness information, and the signatory can only obtain the declaration information but not the witness information before adaptation;

[0099] In the pre-signature generation step, a pre-signature of the message to be signed by the signer related to the declaration information is generated according to the private key, the message to be signed and the declaration information;

[0100] In the pre-signature verification step, the verifier verifies the legitimacy of the pre-signature of the signer based on the public key, the message to be signed and the declaration information;

[0101] In the step of adapting the second signature, after completing the legitimacy verification of the pre-signature, the verifier embeds the witness information into the pre-signature to generate the second signature, and simultaneously obtains the first signature from the second signature using the witness information;

[0102] In the encrypted information extraction step, the signer extracts the witness information from the second signature using the declaration information.

[0103] Based on the first signature scheme SIG=(KeyGen, Sign, Vrfy) above, and an instance of the difficult relation Π on the group G above (Y, y), that is, Y=g y , proposed an adapter signature scheme based on bilinear mapping (Second signature scheme), which includes the pre-signature algorithm pSign (pre-signature generation step), the pre-signature verification algorithm pVrfy (pre-signature verification step), the adaptation algorithm Adapt (adaptation second signature step) and the extraction algorithm Ext (encrypted information extraction step). The four sub-algorithms (modules) are as follows:

[0104] In some embodiments, in step S2, generating the pre-signature of the message to be signed includes: the signer randomly selects calculate Thus, the pre-signature of the message m to be signed by the signer related to the declaration information Y is obtained.

[0105] Specifically, pSign(sk, m, Y): a pre-signature algorithm, the input is the signer's private key sk, the message m and the statement Y in the difficult relation, and the output is the corresponding pre-signature The specific process is as follows: The signer randomly selects calculate So the pre-signature of message m associated with statement Y is

[0106] In some embodiments, in step S2, the verifier verifies the legitimacy of the pre-signature of the signer, including: the verifier verifies the equation based on the public key pk, the message m to be signed and the declaration information Y Is it true? If so, the legitimacy of the pre-signature is verified and 1 is output; otherwise, it fails and 0 is output.

[0107] Specifically, Pre-signature verification algorithm, input signature public key pk, message m, statement Y and pre-signature If the pre-signature verification is legal, it outputs 1, otherwise it outputs 0. The specific process is as follows: The pre-signature verifier receives the pre-signature of message m Afterwards, check the equation Is it true? If so, the pre-signature verification is legal and outputs 1, otherwise it outputs 0.

[0108] In some embodiments, in step S2, embedding the witness information into the pre-signature to generate the second signature includes: make Thus, the second signature embedded with the witness information is obtained:

[0109]

[0110] Specifically, Adapt algorithm, input pre-signature and witness y, output the signature of message m δ = (r, s). The specific process is as follows: the signature verifier with witness y uses this algorithm to convert the pre-signed Transformed into the second signature of message m (in which the witness information is embedded). The specific calculation process is: make So we get the signature of message m:

[0111]

[0112] In some embodiments, in step S2, the signatory extracts the witness information from the second signature using the declaration information, including: Verify the equation Y = g y Is it true? If so, output the witness y. Otherwise, the extraction fails and the failure indicator ⊥ is output.

[0113] Specifically, Witness extraction algorithm, input pre-signature Sign δ = (r, s) and declare Y, and output witness y. The specific process is as follows: The signer calculates Verify the equation Y = g y Is it true? If it is true, output the witness y. Otherwise, the extraction fails and output the failure indicator ⊥.

[0114] From the above signing process, we can see that the adapter signature has the following characteristics:

[0115] (1) Adapter signature is to bind the signing process with the disclosure of a secret. It first embeds the statement Y in the difficult relation into the pre-signature, and then uses the witness y in the difficult relation (which is confidential before being revealed to the signer) to transform the pre-signature into a complete signature.

[0116] (2) Signed by the adapter The final complete signature is consistent with the signature obtained by the previous digital signature SIG. Therefore, other users, except for the signing participants, cannot distinguish whether a signature is obtained by the adapter or the digital signature calculated by the adapter, which further enhances the privacy of the blockchain.

[0117] A second aspect of the present invention discloses a system for acquiring adapter signatures based on bilinear mapping. Figure 2 is a structural diagram of a system for acquiring adapter signatures based on bilinear mapping according to an embodiment of the present invention; Figure 2 As shown, the system 200 includes:

[0118] The first processing unit 201 is configured to obtain a first signature scheme between a signer and a verifier, where the first signature scheme is used to generate a first signature of the signer and verify the first signature by the verifier;

[0119] The first signature scheme includes a key generation step, a first signature generation step and a first signature verification step; wherein:

[0120] In the key generation step, a public key and a private key of the signer are generated, the public key is generated based on the private key, and the verifier can obtain the public key but cannot obtain the private key;

[0121] In the first signature generation step, a first signature of the signer is generated according to the private key and the message to be signed;

[0122] In the first signature verification step, the verifier verifies the legitimacy of the first signature of the signer using the public key and the message to be signed;

[0123] The second processing unit 202 is configured to complete adaptation of the first signature scheme based on the first signature of the signer and the encrypted information of the verifier to obtain an adapted second signature scheme, wherein the second signature scheme is used to implement information exchange between the signer and the verifier based on the generated second signature, wherein the exchanged information is the first signature of the signer and the encrypted information of the verifier, so that the verifier completes verification of the first signature and the signer decrypts the encrypted information of the verifier;

[0124] The second signature scheme includes a pre-signature generation step, a pre-signature verification step, a second signature adaptation step, and an encrypted information extraction step, the encrypted information includes declaration information and witness information, the declaration information is generated based on the witness information, and the signatory can only obtain the declaration information but not the witness information before adaptation;

[0125] In the pre-signature generation step, a pre-signature of the message to be signed by the signer related to the declaration information is generated according to the private key, the message to be signed and the declaration information;

[0126] In the pre-signature verification step, the verifier verifies the legitimacy of the pre-signature of the signer based on the public key, the message to be signed and the declaration information;

[0127] In the step of adapting the second signature, after completing the legitimacy verification of the pre-signature, the verifier embeds the witness information into the pre-signature to generate the second signature, and simultaneously obtains the first signature from the second signature using the witness information;

[0128] In the encrypted information extraction step, the signer extracts the witness information from the second signature using the declaration information.

[0129] According to the system of the second aspect of the present invention, the first processing unit 201 is specifically configured to generate the private key and the public key of the signer, including: randomly selecting a finite field Z of an integer modulus q q A non-zero element x in is used as the private key sk, where Calculate h = g x ∈G is used as the public key pk, where g is a generator of the cyclic group G of prime order formed by the points on the elliptic curve, thereby obtaining a public-private key pair (pk, sk) = (h, x).

[0130] According to the system of the second aspect of the present invention, the first processing unit 201 is specifically configured to generate the first signature of the signer according to the private key and the message to be signed, including: the signer randomly selects Calculate R = g r , s=H(m||R) x , to obtain the first signature δ = (r, s), where m is the message to be signed, H: {0, 1} * →G is a collision-resistant hash function that maps a bit string consisting of 0s and 1s to the cyclic group G.

[0131] According to the system of the second aspect of the present invention, the first processing unit 201 is specifically configured to verify the legitimacy of the first signature using the public key and the message to be signed, including: the verifier uses the public key pk and the message to be signed m to verify the equation e(s, g)=e(H(m||g r ), h) is true, if true, then the legitimacy of the first signature is passed and output 1; otherwise, it fails and outputs 0.

[0132] According to the system of the second aspect of the present invention, the second processing unit 202 is specifically configured to generate the pre-signature of the message to be signed, including: the signing party randomly selects calculate Thus, the pre-signature of the message m to be signed by the signer related to the declaration information Y is obtained.

[0133] According to the system of the second aspect of the present invention, the second processing unit 202 is specifically configured as: the verifier verifies the legitimacy of the pre-signature of the signer, including: the verifier verifies the equation based on the public key pk, the message m to be signed and the declaration information Y Is it true? If so, the legitimacy of the pre-signature is verified and 1 is output; otherwise, it fails and 0 is output.

[0134] According to the system of the second aspect of the present invention, the second processing unit 202 is specifically configured to embed the witness information into the pre-signature to generate the second signature, including: make Thus, the second signature embedded with the witness information is obtained.

[0135] According to the system of the second aspect of the present invention, the second processing unit 202 is specifically configured to: the signer extracts the witness information from the second signature using the declaration information, including: Verify the equation Y = g y Is it true? If so, output the witness y. Otherwise, the extraction fails and the failure indicator ⊥ is output.

[0136] The third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps in the method for obtaining an adapter signature based on a bilinear mapping described in any one of the first aspects of the present disclosure are implemented.

[0137] The third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps in the method for evaluating the quality of on-board slice images based on edge structure similarity described in any one of the first aspects of the present disclosure are implemented.

[0138] Figure 3 is a structural diagram of an electronic device according to an embodiment of the present invention, such as Figure 3 As shown, the electronic device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the electronic device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, near field communication (NFC) or other technologies. The display screen of the electronic device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the electronic device can be a touch layer covered on the display screen, or a button, a trackball or a touch pad set on the housing of the electronic device, or an external keyboard, touch pad or mouse, etc.

[0139] Those skilled in the art will understand that Figure 3 The structure shown in the figure is only a structural diagram of the part related to the technical solution of the present disclosure, and does not constitute a limitation on the electronic device to which the technical solution of the present application is applied. The specific electronic device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0140] The fourth aspect of the present invention discloses a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in any one of the methods for acquiring adapter signatures based on bilinear mapping described in the first aspect of the present disclosure.

[0141] In summary, the technical solution provided by the present invention provides more options for using the adapter signature scheme in the blockchain. Due to the use of bilinear mapping, the length of the adapter signature of the present invention is only half of that based on the ECDSA adapter signature and the adapter signature based on the national secret algorithm SM2. In order to improve the efficiency of the verification algorithm in the present invention, a batch verification method is used to greatly improve the computing efficiency when multiple signatures are used. However, the adapter signature based on the ECDSA adapter signature and the adapter signature based on the national secret algorithm SM2 do not have the characteristics of batch verification. Therefore, when processing multiple signatures, the computing performance of the present invention will further narrow the gap with the adapter signature based on the ECDSA adapter signature and the adapter signature based on the national secret algorithm SM2.

[0142] Please note that the technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, all possible combinations of the technical features in the above embodiments are not described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification. The above-mentioned embodiments only express several implementation methods of the present application, and their descriptions are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that for ordinary technicians in this field, without departing from the concept of the present application, several variations and improvements can be made, which all belong to the scope of protection of the present application. Therefore, the scope of protection of the patent in this application shall be based on the attached claims.

Claims

1. A method for obtaining an adapter signature based on a bilinear map, characterized in that: The method comprises: Step S1: obtaining a first signature scheme between a signer and a verifier, wherein the first signature scheme is used to realize generation of a first signature of the signer and verification of the first signature by the verifier; The first signature scheme includes a key generation step, a first signature generation step and a first signature verification step; wherein: In the key generation step, a public key and a private key of the signer are generated, the public key is generated based on the private key, and the verifier can obtain the public key but cannot obtain the private key; In the first signature generation step, a first signature of the signer is generated according to the private key and the message to be signed; In the first signature verification step, the verifier verifies the legitimacy of the first signature of the signer using the public key and the message to be signed; Step S2: Based on the first signature of the signer and the encrypted information of the verifier, the first signature scheme is adapted to obtain an adapted second signature scheme, wherein the second signature scheme is used to implement information exchange between the signer and the verifier based on the generated second signature, wherein the exchanged information is the first signature of the signer and the encrypted information of the verifier, so that the verifier completes the verification of the first signature and the signer decrypts the encrypted information of the verifier; The second signature scheme includes a pre-signature generation step, a pre-signature verification step, a second signature adaptation step, and an encrypted information extraction step, the encrypted information includes declaration information and witness information, the declaration information is generated based on the witness information, and the signatory can only obtain the declaration information but not the witness information before adaptation; In the pre-signature generation step, a pre-signature of the message to be signed by the signer related to the declaration information is generated according to the private key, the message to be signed and the declaration information; In the pre-signature verification step, the verifier verifies the legitimacy of the pre-signature of the signer based on the public key, the message to be signed and the declaration information; In the step of adapting the second signature, after completing the legitimacy verification of the pre-signature, the verifier embeds the witness information into the pre-signature to generate the second signature, and simultaneously obtains the first signature from the second signature using the witness information; In the encrypted information extraction step, the signer extracts the witness information from the second signature using the declaration information.

2. According to claim 1, a method for obtaining an adapter signature based on a bilinear mapping is characterized in that: In step S1, generating the private key and the public key of the signer includes: randomly selecting a finite field Z of an integer modulo q q A non-zero element x in is used as the private key sk, where Calculate h = g x ∈G is used as the public key pk, where g is a generator of the cyclic group G of prime order formed by the points on the elliptic curve, thereby obtaining a public-private key pair (pk, sk) = (h, x).

3. The method for obtaining an adapter signature based on a bilinear mapping according to claim 2, characterized in that: In step S1, generating the first signature of the signer according to the private key and the message to be signed includes: the signer randomly selects Calculate R = g r , s=H(m||R) x , to obtain the first signature δ = (r, s), where m is the message to be signed, H: {0, 1} * →G is a collision-resistant hash function that maps a bit string consisting of 0s and 1s to the cyclic group G.

4. The method for obtaining an adapter signature based on a bilinear mapping according to claim 3, characterized in that: In the step S1, using the public key and the message to be signed to verify the legitimacy of the first signature includes: the verifier uses the public key pk and the message to be signed m to verify the equation e(s, g)=e(H(m||g r ), h) is true, if true, the legitimacy of the first signature is verified and output 1; otherwise, it fails and outputs 0.

5. The method for obtaining an adapter signature based on a bilinear mapping according to claim 4, characterized in that: In step S2, generating the pre-signature of the message to be signed includes: the signatory randomly selects calculate Thus, the pre-signature of the message m to be signed by the signer related to the declaration information Y is obtained.

6. The method for obtaining an adapter signature based on a bilinear mapping according to claim 5, characterized in that: In step S2, the verification of the legitimacy of the pre-signature of the signer by the verification party includes: the verification party verifies the equation based on the public key pk, the message m to be signed and the declaration information Y Is it true? If so, the legitimacy of the pre-signature is verified and 1 is output; otherwise, it fails and 0 is output.

7. The method for obtaining an adapter signature based on a bilinear mapping according to claim 6, characterized in that: In step S2, embedding the witness information into the pre-signature to generate the second signature includes: make Thus, the second signature embedded with the witness information is obtained. y is the witness information.

8. The method for obtaining an adapter signature based on a bilinear mapping according to claim 7, characterized in that: In step S2, the signatory extracts the witness information from the second signature using the declaration information, including: Verify the equation Y = g y Is it true? If so, output the witness information y. Otherwise, the extraction fails and the failure indicator ⊥ is output.

9. An electronic device, characterized in that: The electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps in the method for obtaining an adapter signature based on a bilinear mapping according to any one of claims 1 to 8 are implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the method for obtaining an adapter signature based on a bilinear mapping according to any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • A cryptosystem and digital signature method

    CN108989054A

  • Alliance chain encryption method based on bilinear mapping technology

    CN111030821A