Calculation method and device of collaborative digital signature based on variation factor
By introducing change factors into collaborative digital signature calculations and dynamically updating the sub-private keys, the problem that attackers can use the steal sub-private keys to perform multiple digital signature operations, improving the security of digital signatures.
Patent Information
- Application Number
- CN202210839350.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-14
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-07-14
AI Technical Summary
In the prior art, an attacker can steal the client's sub-private key, impersonate the client and cooperate with the server to perform any number of digital signature operations, resulting in the inability to ensure the security of the digital signature operation.
By introducing a change factor in the collaborative digital signature calculation process, dynamically changing the sub-private keys of both parties to the communication, ensuring that each round of digital signature operations uses different sub-private keys, thereby limiting the validity period of the sub-private keys available to the attacker and improving security.
Dynamically updating the sub-private key through the change factor is at least partially overcome the problem that the attacker can use the steal sub-private key to perform any number of digital signature operations, limiting the attacker's attack time window and improving the security of digital signature calculation.
Smart Images

Figure CN115225284B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of cryptography, and more specifically, to a calculation method and device for collaborative digital signature based on a variable factor, an electronic device, and a computer-readable storage medium. Background Art
[0002] With the development of cryptography technology, digital signature technology based on public key cryptography has become an important tool to ensure information security in the fields of e-commerce and identity authentication.
[0003] The private key can be split into multiple sub-private keys and stored in independent devices of multiple parties. In each digital signature operation, multiple parties need to collaborate and multiple sub-private keys need to participate in the calculation. In addition, in the above collaborative digital signature calculation process, each party cannot obtain the information of the sub-private keys of other parties, nor can it obtain the information of the private key as a whole. The most common situation is the digital signature calculation of two parties in collaboration, where the client and the server each master their own sub-private keys and cooperate to complete the digital signature calculation. The digital signature algorithm of the cryptographic industry standard SM2 elliptic curve public key cryptography algorithm also has a two-party collaborative digital signature calculation method.
[0004] However, due to the resource and cost constraints of the client, it is difficult to use dedicated cryptographic hardware devices to protect the sub-private key. Therefore, an attacker can steal the client's sub-private key through software vulnerabilities, network attacks, data duplication, etc. Once the attacker steals the client's sub-private key, he can impersonate the client, perform collaborative computing with the server, and complete the digital signature operation. In addition, the attacker can perform collaborative computing with the server and complete any number of digital signature operations at any time. In the process of realizing the concept of the present disclosure, the inventors found that there are at least the following problems in the related art: an attacker can steal the sub-private key of one of the communicating parties through software vulnerabilities, network attacks, data duplication, etc., and impersonate the party to communicate with the other party and perform any number of digital signature operations, resulting in the inability to ensure the security of the digital signature operation. Summary of the invention
[0005] In view of this, the present disclosure provides a calculation method and device for a collaborative digital signature based on a variation factor, an electronic device, and a computer-readable storage medium.
[0006] According to one aspect of the present disclosure, a calculation method for a collaborative digital signature based on a variation factor is provided, which is applied to a first communication party and includes: in response to the completion of the calculation operation of the original information to be signed, determining an original sub-private key D1' and a first variation factor W1, wherein the original sub-private key D1' is used to calculate the original information to be signed; sending the first variation factor W1 to a second communication party; receiving a second variation factor W2 from the second communication party; using the first variation factor W1 and the second variation factor W2 to process the original sub-private key D1' to obtain a current sub-private key D1; using the current sub-private key D1 to calculate the current information to be signed M to obtain a first signature result S1; sending the first signature result S1 to the second communication party; receiving the second signature result S2 from the second communication party; and using the current sub-private key D1, the first signature result S1 and the second signature result S2 to calculate the current information to be signed M to obtain a signature result S.
[0007] According to an embodiment of the present disclosure, the calculation method of the above digital signature is based on the elliptic curve public key cryptography algorithm.
[0008] The determining of the original sub-private key D1' and the first change factor W1 in response to the completion of the calculation operation of the original information to be signed includes: generating a first random number k1 in response to the completion of the calculation operation of the original information to be signed, wherein the first random number k1 belongs to (1, n-1), and n represents the order of the elliptic curve; and determining the first random number k1 as the first change factor W1;
[0009] The above-mentioned processing of the above-mentioned original sub-private key D1' by using the above-mentioned first change factor W1 and the above-mentioned second change factor W2 to obtain the current sub-private key D1 includes: calculating V1 according to the above-mentioned first change factor W1, the above-mentioned second change factor W2 and the above-mentioned original sub-private key D1', wherein V1=(D1'*W1 -1 *W2)mod n, * represents integer multiplication operation, mod n represents modulo n operation; and V1 is determined as the above-mentioned current sub-private key D1.
[0010] According to an embodiment of the present disclosure, in response to the completion of the calculation operation of the original information to be signed, determining the original sub-private key D1' and the first change factor W1 includes: in response to the completion of the calculation operation of the original information to be signed, generating a first random number k1, wherein the first random number k1 belongs to (1, n-1), and n represents the order of the elliptic curve; and determining the first random number k1 as the first change factor W1;
[0011] The above-mentioned processing of the above-mentioned original child private key D1' by using the above-mentioned first change factor W1 and the above-mentioned second change factor W2 to obtain the current child private key D1 includes: calculating U1 according to the above-mentioned first change factor W1, the above-mentioned second change factor W2 and the above-mentioned original child private key D1', wherein U1=(((D1'+1)*W1*W2 -1 )-1)mod n, * represents integer multiplication operation, mod n represents modulo n operation; and U1 is determined as the above-mentioned current sub-private key D1.
[0012] According to an embodiment of the present disclosure, in response to the completion of the calculation operation of the original information to be signed, determining the original sub-private key D1' and the first change factor W1 includes: in response to the completion of the calculation operation of the original information to be signed, generating a first random number k1, wherein the first random number k1 belongs to (1, n-1), and n represents the order of the elliptic curve; and determining the first random number k1 as the first change factor W1;
[0013] According to an embodiment of the present disclosure, the above-mentioned first change factor W1 and the above-mentioned second change factor W2 are used to process the above-mentioned original sub-private key D1' to obtain the current sub-private key D1, including: calculating J1 according to the above-mentioned first change factor W1, the above-mentioned second change factor W2 and the above-mentioned original sub-private key D1', wherein J1=(D1'+W1-W2)mod, * represents integer multiplication operation, and mod n represents modulo n operation; and determining J1 as the above-mentioned current sub-private key D1.
[0014] According to an embodiment of the present disclosure, the above-mentioned use of the above-mentioned current sub-private key D1 to calculate the current information to be signed M to obtain the first signature result S1 includes: generating a third random number k3, wherein the above-mentioned third random number k3 belongs to (1, n-1), and n represents the order of the elliptic curve; calculating Q1, wherein Q1=[k3]G, G represents the base point of the elliptic curve, and [k3]G represents the k3 times point operation of the base point G of the elliptic curve; and determining Q1 as the above-mentioned first signature result S1;
[0015] According to an embodiment of the present disclosure, the current information to be signed M is calculated using the current sub-private key D1, the first signature result S1 and the second signature result S2 to obtain the signature result S, including: receiving S' and r from the second communication party; calculating s, where s=(D1*(k3+S”)-r)mod n; and when s is not equal to zero and s is not equal to nr, determining (r, s) as the signature result S of the current information to be signed M.
[0016] According to an embodiment of the present disclosure, the above-mentioned use of the above-mentioned current sub-private key D1 to calculate the signature information M to obtain the first signature result S1 includes: generating a third random number k3, wherein the above-mentioned third random number k3 belongs to (1, n-1), and n represents the order of the elliptic curve; calculating Q1, wherein Q1=[k3]G, G represents the base point of the elliptic curve, and [k3]G represents the k3-times point operation of the base point G of the elliptic curve; and determining Q1 as the above-mentioned first signature result S1;
[0017] According to an embodiment of the present disclosure, the current information to be signed M is calculated using the current sub-private key D1, the first signature result S1 and the second signature result S2 to obtain the signature result S, including: receiving S', S" and r from the second communication party; calculating s, where s = (D1*S'+D1*k3*S"-r) mod n, + represents integer addition or elliptic curve point addition, - represents integer subtraction or elliptic curve point subtraction; and when s is not equal to zero and s is not equal to nr, (r, s) is determined as the signature result S of the information to be signed M.
[0018] According to an embodiment of the present disclosure, the above-mentioned use of the above-mentioned current sub-private key D1 to calculate the signature information M to obtain the first signature result S1 includes: generating a third random number k3, wherein the above-mentioned third random number k3 belongs to (1, n-1), and n represents the order of the elliptic curve; calculating Q1, wherein Q1=[k3](G+P), G represents the base point of the elliptic curve, P represents the public key, and [k3](G+P) represents the k3 times point operation of (G+P); and determining Q1 as the above-mentioned first signature result S1;
[0019] The above-mentioned use of the above-mentioned current sub-private key D1, the above-mentioned first signature result S1 and the above-mentioned second signature result S2 to calculate the above-mentioned current information to be signed M to obtain the signature result S includes: receiving S' and r from the above-mentioned second communication party; calculating s, where s=(k3+r*D1+S'-r)mod n, + represents integer addition operation or elliptic curve point addition operation, and - represents integer subtraction operation or elliptic curve point subtraction operation; and when s is not equal to zero and s is not equal to nr, (r, s) is determined as the signature result S of the above-mentioned information to be signed M.
[0020] According to another aspect of the present disclosure, a calculation method for a collaborative digital signature based on a variation factor is provided, which is applied to a second communication party and includes: in response to determining that the calculation operation of the first communication party on the original information to be signed is completed, determining an original sub-private key D2' and a second variation factor W2, wherein the original sub-private key D2' is used to calculate the original information to be signed; sending the second variation factor W2 to the first communication party; receiving the first variation factor W1 from the first communication party; processing the original sub-private key D2' using the first variation factor W1 and the second variation factor W2 to obtain a current sub-private key D2; receiving a first signature result S1 from the first communication party; calculating the current information to be signed M using the first signature result S1 and the current sub-private key D2 to obtain a second signature result S2; and sending the second signature result S2 to the first communication party, so that the first communication party can calculate the current information to be signed M using the second signature result S2 to obtain a signature result S.
[0021] According to another aspect of the present disclosure, a computing device for collaborative digital signature based on a variation factor is provided, which is applied to a first communication party, and includes: a first determining module, which is used to determine an original sub-private key D1' and a first variation factor W1 in response to the completion of the computing operation of the original information to be signed, wherein the original sub-private key D1' is used to calculate the original information to be signed; a first sending module, which is used to send the first variation factor W1 to a second communication party; a first receiving module, which is used to receive a second variation factor W2 from the second communication party; a first processing module, which is used to use the first variation factor W1 and the first variation factor W2 to calculate the original information to be signed; The second change factor W2 is used to process the above-mentioned original sub-private key D1' to obtain the current sub-private key D1; the first signature module is used to use the above-mentioned current sub-private key D1 to calculate the current information to be signed M to obtain the first signature result S1; the second sending module is used to send the above-mentioned first signature result S1 to the above-mentioned second communication party; the second receiving module is used to receive the second signature result S2 from the above-mentioned second communication party; and the calculation module is used to use the above-mentioned current sub-private key D1, the above-mentioned first signature result S1 and the above-mentioned second signature result S2 to calculate the above-mentioned current information to be signed M to obtain the signature result S.
[0022] According to another aspect of the present disclosure, a computing device for collaborative digital signature based on a variation factor is provided, which is applied to a second communication party, and includes: a second determining module, which is used to determine an original sub-private key D2' and a second variation factor W2 in response to determining that the computing operation of the first communication party on the original information to be signed is completed, wherein the original sub-private key D2' is used to calculate the original information to be signed; a third sending module, which is used to send the second variation factor W2 to the first communication party; a third receiving module, which is used to receive the first variation factor W1 from the first communication party; a second processing module, which is used to use the first variation factor W2 to calculate the original information to be signed; a change factor W1 and the above-mentioned second change factor W2, processing the above-mentioned original sub-private key D2' to obtain the current sub-private key D2; a fourth receiving module, used to receive the first signature result S1 from the above-mentioned first communication party; a second signature module, used to use the above-mentioned first signature result S1 and the above-mentioned current sub-private key D2 to calculate the current information to be signed M to obtain the second signature result S2; and a fourth sending module, used to send the above-mentioned second signature result S2 to the above-mentioned first communication party, so that the above-mentioned first communication party can use the above-mentioned second signature result S2 to calculate the current information to be signed M to obtain the signature result S.
[0023] According to the embodiments of the present disclosure, during the digital signature calculation process, when the calculation operation of the original information to be signed in the previous round is completed, the sub-private keys of the communicating parties can be changed by the change factor to obtain the current sub-private key. In the current round of digital signature calculation, the current information to be signed is calculated using the obtained current sub-private key to obtain the signature result. Through the above technical means, the technical problem that the attacker can use the stolen sub-private key to perform any number of digital signature operations in the related art and the security of the private key cannot be guaranteed is at least partially overcome, thereby limiting the attack time window that the attacker can launch, and improving the security of the digital signature calculation. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The above and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:
[0025] Figure 1 A flowchart schematically illustrates a method for calculating a collaborative digital signature based on a variation factor according to an embodiment of the present disclosure;
[0026] Figure 2 A flowchart schematically shows a method for calculating a collaborative digital signature based on a variation factor according to another embodiment of the present disclosure;
[0027] Figure 3 An example schematic diagram schematically illustrates a calculation process of a collaborative digital signature based on a variation factor according to an embodiment of the present disclosure;
[0028] Figure 4 An example schematic diagram schematically illustrates a calculation process of a collaborative digital signature based on a variation factor according to another embodiment of the present disclosure;
[0029] Figure 5 An example schematic diagram schematically illustrates a calculation process of a collaborative digital signature based on a variation factor according to another embodiment of the present disclosure;
[0030] Figure 6 An example schematic diagram schematically illustrates a calculation process of a collaborative digital signature based on a variation factor according to another embodiment of the present disclosure;
[0031] Figure 7 A block diagram schematically shows a computing device for collaborative digital signature based on a variation factor according to an embodiment of the present disclosure;
[0032] Figure 8 A block diagram schematically shows a computing device for collaborative digital signature based on a variation factor according to another embodiment of the present disclosure; and
[0033] Fig. 9 A block diagram of an electronic device suitable for implementing a calculation method of a collaborative digital signature based on a variation factor according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0034] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with specific embodiments and with reference to the accompanying drawings.
[0035] In the technical solution disclosed in the present invention, the acquisition, storage and application of user personal information involved are in compliance with the provisions of relevant laws and regulations, necessary confidentiality measures are taken, and do not violate public order and good morals.
[0036] In the technical solution of the present disclosure, the user's authorization or consent is obtained before obtaining or collecting the user's personal information.
[0037] In order to at least partially solve the technical problems existing in the related art, the present disclosure provides a calculation method and device for collaborative digital signature based on a change factor. The calculation method of the digital signature includes: in response to the completion of the calculation operation of the original information to be signed, determining the original sub-private key D1' and the first change factor W1, wherein the original sub-private key D1' is used to calculate the original information to be signed; sending the first change factor W1 to the second communication party; receiving the second change factor W2 from the second communication party; using the first change factor W1 and the second change factor W2, processing the original sub-private key D1' to obtain the current sub-private key D1; using the current sub-private key D1 to calculate the current information to be signed M to obtain the first signature result S1; sending the first signature result S1 to the second communication party; receiving the second signature result S2 from the second communication party; and using the current sub-private key D1, the first signature result S1 and the second signature result S2 to calculate the current information to be signed M to obtain the signature result S.
[0038] Figure 1 The flowchart of the calculation method of the collaborative digital signature based on the variation factor according to the embodiment of the present disclosure is schematically shown.
[0039] like Figure 1 As shown, the calculation method of the collaborative digital signature based on the variation factor includes operations S110 to S180.
[0040] In operation S110, in response to the completion of the calculation operation of the original information to be signed, the original sub-private key D1' and the first change factor W1 are determined. The original sub-private key D1' is used to calculate the original information to be signed.
[0041] In operation S120, the first variation factor W1 is sent to the second communication party.
[0042] In operation S130, a second variation factor W2 is received from a second communication party.
[0043] In operation S140, the original sub-private key D1' is processed using the first change factor W1 and the second change factor W2 to obtain the current sub-private key D1.
[0044] In operation S150, the current sub-private key D1 is used to calculate the current information to be signed M to obtain a first signature result S1.
[0045] In operation S160, the first signature result S1 is sent to the second communication party.
[0046] In operation S170, a second signature result S2 is received from a second communication party.
[0047] In operation S180, the current information to be signed M is calculated using the current sub-private key D1, the first signature result S1 and the second signature result S2 to obtain a signature result S.
[0048] According to an embodiment of the present disclosure, the first communication party may be a server or a client. The second communication party may be a server or a client. In the case where the first communication party is a server, the second communication party may be a client. In the case where the first communication party is a client, the second communication party may be a server.
[0049] According to an embodiment of the present disclosure, the original information to be signed can be used to represent the information to be signed in the previous round of digital signature calculation. The current information to be signed can be used to represent the information to be signed in the current round of digital signature calculation.
[0050] According to an embodiment of the present disclosure, the first communication party may generate an original sub-private key D1', in which case the original sub-private key D1' of the first communication party may collaborate with the original sub-private key D2' of the second communication party to generate a public key P. Alternatively, a private key may be randomly generated by a key generator and the public key P may be calculated, in which case the first communication party may receive the original sub-private key D1' from the key generator. The original information to be signed may be calculated using the original sub-private key D1' to obtain an intermediate result.
[0051] According to an embodiment of the present disclosure, after the last round of digital signature calculation is completed, the first communication party may determine the first change factor W1 by generating a random number. Alternatively, the first communication party may determine the first change factor W1 based on the original information to be signed, the first signature result, the second signature result, and all or part of the values in the signature result in the last round of digital signature calculation.
[0052] According to an embodiment of the present disclosure, the first communication party can use the first change factor W1 and the second change factor W2 to change the original sub-private key D1' to obtain the current sub-private key D1. The original sub-private keys D1' and D2' correspond to the same private key as the current sub-private keys D1 and D2.
[0053] According to an embodiment of the present disclosure, the first signature result S1 may be a partial signature result calculated by the first communication party using the current sub-private key D1 for the current information to be signed M. The second signature result S2 may be a partial signature result calculated by the second communication party using the first signature result S1 and the current sub-private key D2 for the current information to be signed M. The signature information S may be a calculation result of a digital signature calculated by the first communication party using the current sub-private key D1, the first signature result S1, and the second signature result S2 for the current information to be signed M.
[0054] According to the embodiments of the present disclosure, during the digital signature calculation process, when the calculation operation of the original information to be signed in the previous round is completed, the sub-private keys of the communicating parties can be changed by the change factor to obtain the current sub-private key. In the current round of digital signature calculation, the current information to be signed is calculated using the obtained current sub-private key to obtain the signature result. Through the above technical means, the technical problem in the related art that an attacker can use the stolen sub-private key to perform any number of digital signature operations and cannot guarantee the security of the private key is at least partially overcome, thereby limiting the attack time window that the attacker can launch, and improving the security of the digital signature calculation.
[0055] Figure 2 The flowchart of a method for calculating a collaborative digital signature based on a variation factor according to another embodiment of the present disclosure is schematically shown.
[0056] like Figure 2 As shown, the calculation method of the collaborative digital signature based on the variation factor includes operations S210 to S270.
[0057] In operation S210, in response to determining that the first communication party has completed the calculation operation on the original information to be signed, the original sub-private key D2' and the second change factor W2 are determined. The original sub-private key D2' is used to calculate the original information to be signed.
[0058] In operation S220, the second variation factor W2 is sent to the first communication party.
[0059] In operation S230, a first variation factor W1 is received from a first communication party.
[0060] In operation S240, the original sub-private key D2' is processed using the first change factor W1 and the second change factor W2 to obtain the current sub-private key D2.
[0061] In operation S250, a first signature result S1 is received from a first communication party.
[0062] In operation S260, the current information to be signed M is calculated using the first signature result S1 and the current sub-private key D2 to obtain a second signature result S2.
[0063] In operation S270, the second signature result S2 is sent to the first communication party, so that the first communication party uses the second signature result S2 to calculate the current information to be signed M to obtain the signature result S.
[0064] According to an embodiment of the present disclosure, the first communication party may be a server or a client. The second communication party may be a server or a client. In the case where the second communication party is a server, the first communication party may be a client. In the case where the second communication party is a client, the first communication party may be a server.
[0065] According to an embodiment of the present disclosure, the original information to be signed can be used to represent the information to be signed in the previous round of digital signature calculation. The current information to be signed can be used to represent the information to be signed in the current round of digital signature calculation.
[0066] According to an embodiment of the present disclosure, the second communication party may generate an original sub-private key D2', in which case the original sub-private key D2' of the second communication party may collaborate with the original sub-private key D1' of the first communication party to generate a public key P. Alternatively, a private key may be randomly generated by a key generator and the public key P may be calculated, in which case the second communication party may receive the original sub-private key D2' from the key generator. The original information to be signed may be calculated using the original sub-private key D2' to obtain an intermediate result.
[0067] According to an embodiment of the present disclosure, after the last round of digital signature calculation is completed, the second communication party may determine the second change factor W2 by generating a random number. Alternatively, the second communication party may determine the second change factor W2 based on the original information to be signed, the first signature result, the second signature result, and all or part of the values in the signature result in the last round of digital signature calculation.
[0068] According to an embodiment of the present disclosure, the second communication party can use the first change factor W1 and the second change factor W2 to change the original sub-private key D2' to obtain the current sub-private key D2. The original sub-private keys D1', D2' and the current sub-private keys D1, D2 correspond to the same private key.
[0069] According to the embodiments of the present disclosure, during the digital signature calculation process, when the calculation operation of the original information to be signed in the previous round is completed, the sub-private keys of the communicating parties can be changed by the change factor to obtain the current sub-private key. In the current round of digital signature calculation, the current information to be signed is calculated using the obtained current sub-private key to obtain the signature result. Through the above technical means, the technical problem that the attacker can use the stolen sub-private key to perform any number of digital signature operations in the related art and the security of the private key cannot be guaranteed is at least partially overcome, thereby limiting the attack time window that the attacker can launch, and improving the security of the digital signature calculation.
[0070] According to an embodiment of the present disclosure, the first communication party and the second communication party can share the elliptic curve parameters E(Fq), G and n of the elliptic curve public key cryptography algorithm (SM2 algorithm), where the elliptic curve E is an elliptic curve defined on a finite field Fq, and G represents the base point of order n on the elliptic curve E. The specific values of each parameter can be pre-set by a person skilled in the art according to the SM2 algorithm based on actual needs. According to an embodiment of the present disclosure, in a calculation method for digital signature based on an elliptic curve public key cryptography algorithm, the private key d is stored in the first communication party and the second communication party in the form of a sub-private key D1 and a sub-private key D2, respectively. The public key P = [d] G, where [d] G represents a d-times point operation of the base point G of the elliptic curve.
[0071] Reference below Figure 3 to Figure 6 , combined with specific embodiments Figure 1 and Figure 2 The method shown is further explained.
[0072] Figure 3 An example schematic diagram of a calculation process of a collaborative digital signature based on a variation factor according to an embodiment of the present disclosure is schematically shown.
[0073] According to an embodiment of the present disclosure, a method for calculating a digital signature based on an elliptic curve public key cryptography algorithm splits a private key into two parts to obtain sub-private keys, which are stored separately on both communicating parties, and both parties collaborate to complete the digital signature operation.
[0074] like Figure 3 As shown, in operation S301, in response to the completion of the calculation operation of the original information to be signed, the first communication party determines the original sub-private key D1' and the first change factor W1.
[0075] In operation S302, the first communication party sends the first variation factor W1 to the second communication party.
[0076] In operation S303, the second communication party determines the original sub-private key D2' and the second change factor W2. The original sub-private key D2' is used to calculate the original information to be signed.
[0077] In operation S304, the second communication party sends the second variation factor W2 to the first communication party.
[0078] In operation S305 , the first communication party receives a second variation factor W2 from the second communication party.
[0079] In operation S306 , the second communication party receives the first variation factor W1 from the first communication party.
[0080] In operation S307, the first communication party processes the original sub-private key D1' using the first change factor W1 and the second change factor W2 to obtain the current sub-private key D1.
[0081] In operation S308, the second communication party processes the original sub-private key D2' using the first change factor W1 and the second change factor W2 to obtain the current sub-private key D2.
[0082] In operation S309, the first communication party uses the current sub-private key D1 to calculate the current information to be signed M to obtain a first signature result S1.
[0083] In operation S310, the first communication party sends the first signature result S1 to the second communication party.
[0084] In operation S311, the second communication party receives the first signature result S1 from the first communication party.
[0085] In operation S312, the second communication party uses the first signature result S1 and the current sub-private key D2 to calculate the current information to be signed M to obtain a second signature result S2.
[0086] In operation S313, the second communication party sends the second signature result S2 to the first communication party.
[0087] In operation S314, the first communication party receives the second signature result S2 from the second communication party.
[0088] In operation S315, the first communication party calculates the current information to be signed M using the current sub-private key D1, the first signature result S1 and the second signature result S2 to obtain the signature result S.
[0089] According to an embodiment of the present disclosure, in each round of digital signature operation, the sub-private keys stored by both the first communication party and the second communication party will change, while the private key of the SM2 algorithm remains unchanged as a whole.
[0090] Figure 4 An example schematic diagram of a calculation process of a collaborative digital signature based on a variation factor according to another embodiment of the present disclosure is schematically shown.
[0091] According to an embodiment of the present disclosure, a method for calculating a digital signature is based on an elliptic curve public key cryptography algorithm.
[0092] According to an embodiment of the present disclosure, operation S110 may include the following operations.
[0093] In response to the completion of the calculation operation of the original information to be signed, a first random number k1 is generated. The first random number k1 belongs to (1, n-1), where n represents the order of the elliptic curve. The first random number k1 is determined as a first variation factor W1.
[0094] According to an embodiment of the present disclosure, operation S210 may include the following operations.
[0095] In response to determining that the first communication party has completed the calculation operation on the original information to be signed, a second random number k2 is generated. The second random number k2 belongs to (1, n-1), where n represents the order of the elliptic curve. The second random number k2 is determined as a second variation factor W2.
[0096] According to an embodiment of the present disclosure, in this case, the private key d, the original sub-private key D1' of the first communication party, and the original sub-private key D2' of the second communication party satisfy (d+1) -1 =(D1'*D2')mod n.
[0097] According to an embodiment of the present disclosure, operation S140 may include the following operations.
[0098] According to the first change factor W1, the second change factor W2 and the original child private key D1', V1 is calculated, V1 = (D1' * W1 -1 *W2)mod n, * represents integer multiplication operation, mod n represents modulo n operation. V1 is determined as the current child private key D1.
[0099] According to an embodiment of the present disclosure, operation S240 may include the following operations.
[0100] According to the first change factor W1, the second change factor W2 and the original child private key D2', V2 is calculated, V2 = (D2'*W1*W2 -1 )mod n, * represents integer multiplication, W2 -1 mod n represents the inverse of W2 mod n. V2 is determined as the current child private key D2.
[0101] According to an embodiment of the present disclosure, the first communication party may generate an original sub-private key D1′. The original sub-private key D1′ of the first communication party may be used to generate a public key P in collaboration with the original sub-private key D2′ of the second communication party.
[0102] For example, the first communication party can generate a random number between (1, n-1) and use the generated random number as the original sub-private key D1'. The first communication party can calculate the inverse element T1=D1' of D1' modulo n -1 mod n, that is, D1'*T1=1 modn. The first communication party can calculate P1=[T1]G and send P1 to the second communication party.
[0103] According to an embodiment of the present disclosure, the second communication party may generate an original child private key D2', and the original child private key D2' of the second communication party may be used to generate a public key P in collaboration with the original child private key D1' of the first communication party.
[0104] For example, the second communication party can generate a random number between (1, n-1) and use the generated random number as the original sub-private key D2'. The second communication party can calculate the inverse element T2 = D2' of D2' modulo n -1 mod n, that is, D2'*T2=1 modn. The second communication party can receive P1 from the first communication party and calculate P=[T2]P1-G, and use the calculation result P as the public key, that is, P=[T2*T1-1]G. When calculating -G, the equivalent +[n-1]G calculation can be used.
[0105] According to an embodiment of the present disclosure, a private key may be randomly generated by a key generator and a public key P may be calculated, and the first communication party may receive an original sub-private key D1' from the key generator.
[0106] For example, the key generator may generate a random number between (1, n-1), use the generated random number as the private key d, calculate P=[d]G, and use the calculation result P as the public key. The key generator may generate a random number between (1, n-1) as the original child private key D1'. The key generator may send D1' to the first communication party. The key generator may receive the original child private key D1' from the first communication party and calculate D2'=((d+1) -1 *D1' -1 ) mod n, and use the calculated result D2' as the original child private key D2'.
[0107] According to an embodiment of the present disclosure, operation S150 may include the following operations.
[0108] Generate a third random number k3. The third random number k3 belongs to (1, n-1), where n represents the order of the elliptic curve. Calculate Q1, where Q1=[k3]G, where G represents the base point of the elliptic curve, and [k3]G represents the k3-times point operation of the base point G of the elliptic curve. Determine Q1 as the first signature result S1.
[0109] According to an embodiment of the present disclosure, operation S180 may include the following operations.
[0110] Receive S' and r from the second communication party. Calculate s, s = (D1*(k3+S') - r) mod n. When s is not equal to zero and s is not equal to nr, determine (r, s) as the signature result S of the current information M to be signed.
[0111] According to an embodiment of the present disclosure, operation S260 may include the following operations.
[0112] Concatenate Z and M to obtain M', M'=Z||M, Z represents the hash value of the identity identifiers of the first and second communication parties based on the elliptic curve public key cryptography algorithm standard, and || represents the concatenation of bit strings or byte strings. Calculate e, T2 and Q2, e=Hash(M'), T2=D2 -1 mod n, Q2 = [T2] Q1, Hash() represents the hash function, D2 -1 mod n represents the inverse element of D2 mod n, and [T2]Q1 represents the T2 times point operation of Q1. Generate a fifth random number k5. The fifth random number k5 belongs to (1, n-1), and n represents the order of the elliptic curve. Calculate (x, y) and r, (x, y) = [k5]G + Q2, r = (e + x) mod n, (x, y) represents the coordinates of the point of the elliptic curve, G represents the base point of the elliptic curve, [k5]G represents the k5 times point operation of the base point G of the elliptic curve, and + represents integer addition or elliptic curve point addition. When r is not equal to zero, calculate S', S' = (D2*(r+k5)) modn, and mod n represents the modulo n operation. Determine S' as the second signature result S2.
[0113] like Figure 4 As shown, in operation S401, in response to the completion of the calculation operation of the original information to be signed, the first communication party can calculate V1=(D1'*W1 -1 *W2)mod n, and determine the calculation result V1 as the current child private key D1.
[0114] In operation S402, in response to determining that the first communication party has completed the calculation operation on the original information to be signed, the second communication party may calculate V2=(D2'*W1*W2 -1 ) mod n, and determine the calculation result V2 as the current child private key D2.
[0115] In operation S403, the first communication party may generate a third random number k3 belonging to (1, n-1), and calculate Q1, Q1=[k3]G, and determine Q1 as the first signature result S1.
[0116] In operation S404, the first communication party may send S1 to the second communication party.
[0117] In operation S405 , the second communication party may receive S1 from the first communication party.
[0118] In operation S406, the second communication party may concatenate Z and M to obtain M' and calculate e=Hash(M').
[0119] In operation S407, the second communication party may calculate T2=D2 -1 mod n, Q2=[T2]Q1.
[0120] In operation S408, the second communicating party may generate a fifth random number k5 belonging to (1, n-1), and calculate (x, y)=[k5]G+Q2, r=(e+x)mod n.
[0121] In operation S409, when r is not equal to zero, the second communication party may calculate S'=(D2*(r+k5))modn, and determine S' as the second signature result S2.
[0122] In operation S410, the second communication party may send r and a second signature result S2 including S' to the first communication party.
[0123] In operation S411, the first communication party may receive S' and r from the second communication party.
[0124] In operation S412, the first communication party may calculate s=(D1*(k3+S')-r) mod n.
[0125] In operation S413, when s is not equal to zero and s is not equal to nr, the first communication party may determine (r, s) as the signature result S of the information M to be signed.
[0126] According to the embodiment of the present disclosure, the above process is equivalent to using k3*D2 -1 +k5 replaces the random number k in the calculation method of the digital signature of the SM2 elliptic curve public key cryptography algorithm. The private key of the elliptic curve public key cryptography algorithm can be kept unchanged as a whole, that is, the changed current sub-private keys D1 and D2 still satisfy (d+1) -1 =(D1*D2)mod n.
[0127] According to an embodiment of the present disclosure, the first communication party and the second communication party can calculate W1 in the calculation of the next round of digital signature according to the entire value or partial value of Q1. For example, W1 can be set to the x coordinate of Q1, the y coordinate of Q1, or Hash(Q1) mod n, etc.
[0128] According to an embodiment of the present disclosure, the first communication party and the second communication party can respectively calculate W1 and W2 according to the full value or partial value of r and S'. For example, W1 and W2 can be set to (r+S') mod n, (r+S') mod n, or Hash(r) mod n, etc.
[0129] Figure 5 An example schematic diagram of a calculation process of a collaborative digital signature based on a variation factor according to another embodiment of the present disclosure is schematically shown.
[0130] According to an embodiment of the present disclosure, a method for calculating a digital signature is based on an elliptic curve public key cryptography algorithm.
[0131] According to an embodiment of the present disclosure, operation S110 may include the following operations.
[0132] In response to the completion of the calculation operation of the original information to be signed, a first random number k1 is generated. The first random number k1 belongs to (1, n-1), where n represents the order of the elliptic curve. The first random number k1 is determined as a first variation factor W1.
[0133] According to an embodiment of the present disclosure, operation S210 may include the following operations.
[0134] In response to determining that the first communication party has completed the calculation operation on the original information to be signed, a second random number k2 is generated. The second random number k2 belongs to (1, n-1), where n represents the order of the elliptic curve. The second random number k2 is determined as a second variation factor W2.
[0135] According to an embodiment of the present disclosure, in this case, the private key d, the original sub-private key D1' of the first communication party, and the original sub-private key D2' of the second communication party satisfy (d+1) -1 =(D1'+1)*(D2'+1)mod n.
[0136] According to an embodiment of the present disclosure, operation S140 may include the following operations.
[0137] Calculate U1 based on the first change factor W1, the second change factor W2 and the original child private key D1'. U1 = (((D1'+1)*W1*W2 -1 )-1)mod n, * represents integer multiplication operation, mod n represents modulo n operation. U1 is determined as the current sub-private key D1.
[0138] According to an embodiment of the present disclosure, operation S240 may include the following operations.
[0139] According to the first change factor W1, the second change factor W2 and the original child private key D2', calculate U2, U2 = (((D2'+1)*W1 -1 *W2)-1)mod n, * represents integer multiplication, W2 -1 mod n represents the inverse of W2 mod n. U2 is determined as the current child private key D2.
[0140] According to an embodiment of the present disclosure, operation S150 may include the following operations.
[0141] Generate a third random number k3. The third random number k3 belongs to (1, n-1), where n represents the order of the elliptic curve. Calculate Q1, where Q1=[k3]G, where G represents the base point of the elliptic curve, and [k3]G represents the k3-times point operation of the base point G of the elliptic curve. Determine Q1 as the first signature result S1.
[0142] According to an embodiment of the present disclosure, operation S180 may include the following operations.
[0143] Receive S', S" and r from the second communication party. Calculate s, s = ((D1+1)*S'+(D1+1)*k3*S"-r)modn, + represents integer addition or elliptic curve point addition, - represents integer subtraction or elliptic curve point subtraction. When s is not equal to zero and s is not equal to nr, (r, s) is determined as the signature result S of the information to be signed M.
[0144] According to an embodiment of the present disclosure, operation S260 may include the following operations.
[0145] Concatenate Z and M to obtain M', M'=Z||M, Z represents the hash value of the identity identifiers of the first communication party and the second communication party based on the elliptic curve public key cryptography algorithm standard, and || represents the concatenation of bit strings or byte strings. Calculate e, e=Hash(M'), Hash() represents the hash function. Generate a fourth random number k4. The fourth random number k4 belongs to (1, n-1), and n represents the order of the elliptic curve. Calculate Q2, Q2=[k4]Q1, Q1 represents the first signature result S1, and [k4]Q1 represents the k4 times point operation of Q1. Generate a fifth random number k5. The fifth random number k5 belongs to (1, n-1), and n represents the order of the elliptic curve. Calculate (x, y) and r, (x, y) = [k5] G + Q2, r = (e + x) mod n, (x, y) represents the coordinates of the point of the elliptic curve, G represents the base point of the elliptic curve, [k5] G represents the k5 times point operation of the base point G of the elliptic curve, + represents integer addition operation or elliptic curve point addition operation. When r is not equal to zero, calculate S' and S", S' = ((D2 + 1) * (r + k5)) mod n, S" = ((D2 + 1) * k4) mod n, modn represents modulo n operation. Determine S' and S" as the second signature result S2.
[0146] like Figure 5 As shown, in operation S501, in response to the completion of the calculation operation of the original information to be signed, the first communication party can calculate U1=(((D1'+1)*W1*W2 -1 )-1)mod n, and determine the calculation result U1 as the current sub-private key D1.
[0147] In operation S502, in response to determining that the first communication party has completed the calculation operation on the original information to be signed, the second communication party may calculate U2=(((D2'+1)*W1 -1 *W2)-1)mod n, and determine the calculation result U2 as the current sub-private key D2.
[0148] In operation S503, the first communication party may generate a third random number k3 belonging to (1, n-1), and calculate Q1, Q1=[k3]G, and determine Q1 as the first signature result S1.
[0149] In operation S504, the first communication party may send Q1 to the second communication party.
[0150] In operation S505 , the second communication party may receive Q1 from the first communication party.
[0151] In operation S506, the second communication party may concatenate Z and M to obtain M' and calculate e=Hash(M').
[0152] In operation S507, the second communicating party may generate a fourth random number k4 belonging to (1, n-1), and calculate Q2=[k4]Q1.
[0153] In operation S508, the second communicating party may generate a fifth random number k5 belonging to (1, n-1), and calculate (x, y)=[k5]G+Q2, r=(e+x)mod n.
[0154] In operation S509, when r is not equal to zero, the second communication party may calculate S'=((D2+1)*(r+k5)) mod n, S"=((D2+1)*k4) mod n, and determine S' and S" as the second signature result S2.
[0155] In operation S510, the second communication party may send r and a second signature result S2 including S' and S" to the first communication party.
[0156] In operation S511, the first communication party may receive S', S", and r from the second communication party.
[0157] In operation S512, the first communication party may calculate s=((D1+1)*S'+(D1+1)*k3*S″-r) mod n.
[0158] In operation S513, when s is not equal to zero and s is not equal to nr, the first communication party may determine (r, s) as the signature result S of the information M to be signed.
[0159] According to the embodiment of the present disclosure, the above process is equivalent to using k3*k4+k5 to replace the random number k in the calculation method of the digital signature of the SM2 elliptic curve public key cryptography algorithm. The private key of the elliptic curve public key cryptography algorithm can be kept unchanged as a whole, that is, the changed current sub-private keys D1 and D2 still satisfy (d+1) -1 =(D1+1)*(D2+1)mod n.
[0160] According to an embodiment of the present disclosure, the first communication party and the second communication party can calculate W1 in the calculation of the next round of digital signature according to the entire value or partial value of Q1. For example, W1 can be set to the x coordinate of Q1, the y coordinate of Q1, or Hash(Q1) mod n, etc.
[0161] According to an embodiment of the present disclosure, the first communication party and the second communication party can respectively calculate W1 and W2 based on the full value or partial value of r, S' and S". For example, W1 and W2 can be set to (r+S'+S") mod n, (r+S') mod n, or Hash(r) mod n, etc.
[0162] Figure 6 An example schematic diagram of a calculation process of a collaborative digital signature based on a variation factor according to another embodiment of the present disclosure is schematically shown.
[0163] According to an embodiment of the present disclosure, a method for calculating a digital signature is based on an elliptic curve public key cryptography algorithm.
[0164] According to an embodiment of the present disclosure, operation S110 may include the following operations.
[0165] In response to the completion of the calculation operation of the original information to be signed, a first random number k1 is generated. The first random number k1 belongs to (1, n-1), where n represents the order of the elliptic curve. The first random number k1 is determined as a first variation factor W1.
[0166] According to an embodiment of the present disclosure, operation S210 may include the following operations.
[0167] In response to determining that the first communication party has completed the calculation operation on the original information to be signed, a second random number k2 is generated. The second random number k2 belongs to (1, n-1), where n represents the order of the elliptic curve. The second random number k2 is determined as a second variation factor W2.
[0168] According to an embodiment of the present disclosure, in this case, the private key d, the original sub-private key D1' of the first communication party, and the original sub-private key D2' of the second communication party satisfy (d+1) -1 =(D1'+D2')mod n.
[0169] According to an embodiment of the present disclosure, operation S140 may include the following operations.
[0170] According to the first change factor W1, the second change factor W2 and the original child private key D1', J1 is calculated, J1 = (D1' + W1-W2) mod n, * represents integer multiplication operation, mod n represents modulo n operation. V1 is determined as the current child private key D1. According to an embodiment of the present disclosure, operation S240 may include the following operations.
[0171] According to the first change factor W1, the second change factor W2 and the original child private key D2', J2 is calculated. J2 = (D2'-W1+W2) mod n, * represents integer multiplication operation, mod n represents modulo n operation. U2 is determined as the current child private key D2.
[0172] According to an embodiment of the present disclosure, operation S150 may include the following operations.
[0173] Generate a third random number k3. The third random number k3 belongs to (1, n-1), where n represents the order of the elliptic curve. Calculate Q1, where Q1=[k3](G+P), where G represents the base point of the elliptic curve, and [k3](G+P) represents the k3-times point operation of (G+P). Determine Q1 as the first signature result S1.
[0174] According to an embodiment of the present disclosure, operation S180 may include the following operations.
[0175] Receive S' and r from the second communication party. Calculate s, s = (k3 + r * D1 + S' - r) mod n, + represents integer addition or elliptic curve point addition, - represents integer subtraction or elliptic curve point subtraction. When s is not equal to zero and s is not equal to nr, (r, s) is determined as the signature result S of the information to be signed M.
[0176] According to an embodiment of the present disclosure, operation S260 may include the following operations.
[0177] Concatenate Z and M to obtain M', M'=Z||M, Z represents the hash value of the identity identifiers of the first communication party and the second communication party based on the elliptic curve public key cryptography algorithm standard, and || represents the concatenation of bit strings or byte strings. Calculate e and Q2, e=Hash(M"), Hash() represents the hash function. Generate a fifth random number k5, the fifth random number k5 belongs to (1, n-1), n represents the order of the elliptic curve, calculate Q2, Q2=[k5](G+P). Calculate (x, y) and r, (x, y)=S1+Q2, r=(e+x)modn, (x, y) represents the coordinates of the point of the elliptic curve, G represents the base point of the elliptic curve, [k5]G represents the k5 times point operation of the base point G of the elliptic curve, and + represents integer addition operation or elliptic curve point addition operation. When r is not equal to zero, calculate S', S'=(k5+r*D2")mod n, mod n represents the modulus n operation. S' is determined as the second signature result S2.
[0178] like Figure 6 As shown, in operation S601, in response to the completion of the calculation operation of the original information to be signed, the first communication party can calculate J1=(D1'+W1-W2)mod n, and determine the calculation result J1 as the current sub-private key D1.
[0179] In operation S602, in response to determining that the first communication party completes the calculation operation on the original information to be signed, the second communication party may calculate J2=(D2'-W1+W2) mod n, and determine the calculation result J2 as the current sub-private key D2.
[0180] In operation S603, the first communication party may generate a third random number k3 belonging to (1, n-1), and calculate Q1, where Q1=[k3](G+P), and determine Q1 as the first signature result S1.
[0181] In operation S604, the first communication party may send S1 to the second communication party.
[0182] In operation S605 , the second communication party may receive S1 from the first communication party.
[0183] In operation S606, the second communication party may concatenate Z and M to obtain M' and calculate e=Hash(M').
[0184] In operation S607, the second communication party may generate a fifth random number k5 belonging to (1, n-1) and calculate Q2. The second communication party may calculate Q2=[k5](G+P).
[0185] In operation S608, the second communication party may calculate (x, y)=S1+Q2, r=(e+x) mod n.
[0186] In operation S609, when r is not equal to zero, the second communication party may calculate S'=(k5+r*D2) mod n, and determine S' as the second signature result S2.
[0187] In operation S610, the second communication party may send r and a second signature result S2 including S' to the first communication party.
[0188] In operation S611, the first communication party may receive S' and r from the second communication party.
[0189] In operation S612, the first communication party may calculate s=(k3+r*D1+S'-r)mod n.
[0190] In operation S613, when s is not equal to zero and s is not equal to nr, the first communication party may determine (r, s) as the signature result S of the information M to be signed.
[0191] According to the embodiment of the present disclosure, the above process is equivalent to using (d+1)(k3*k5) to replace the random number k in the calculation method of the digital signature of the SM2 elliptic curve public key cryptography algorithm. The private key of the elliptic curve public key cryptography algorithm can be kept unchanged as a whole, that is, the changed current sub-private keys D1 and D2 still satisfy (d+1) 11 =(D1+D2)mod n.
[0192] According to an embodiment of the present disclosure, the first communication party and the second communication party can calculate W1 in the calculation of the next round of digital signature according to the entire value or partial value of Q1. For example, W1 can be set to the x coordinate of Q1, the y coordinate of Q1, or Hash(Q1) mod n, etc.
[0193] According to an embodiment of the present disclosure, the first communication party and the second communication party can respectively calculate W1 and W2 according to the full value or partial value of r and S'. For example, W1 and W2 can be set to (r+S') mod n, (r+S') mod n, or Hash(r) mod n, etc.
[0194] Figure 7 A block diagram of a computing device for collaborative digital signature based on a variation factor according to an embodiment of the present disclosure is schematically shown.
[0195] like Figure 7 As shown, the computing device 700 for collaborative digital signature based on a variation factor includes a first determination module 710, a first sending module 720, a first receiving module 730, a first processing module 740, a first signature module 750, a second sending module 760, a second receiving module 770 and a computing module 780.
[0196] The first determination module 710 is used to determine the original sub-private key D1' and the first change factor W1 in response to the completion of the calculation operation of the original information to be signed. The original sub-private key D1' is used to calculate the original information to be signed.
[0197] The first sending module 720 is configured to send the first change factor W1 to the second communication party.
[0198] The first receiving module 730 is configured to receive a second variation factor W2 from a second communication party.
[0199] The first processing module 740 is configured to process the original sub-private key D1 ′ using the first change factor W1 and the second change factor W2 to obtain the current sub-private key D1 .
[0200] The first signature module 750 is used to use the current sub-private key D1 to calculate the current information to be signed M to obtain a first signature result S1.
[0201] The second sending module 760 is used to send the first signature result S1 to the second communication party.
[0202] The second receiving module 770 is used to receive a second signature result S2 from a second communication party.
[0203] The calculation module 780 is used to calculate the current information to be signed M using the current sub-private key D1, the first signature result S1 and the second signature result S2 to obtain the signature result S.
[0204] According to an embodiment of the present disclosure, the calculation method of the digital signature is based on an elliptic curve public key cryptography algorithm.
[0205] According to an embodiment of the present disclosure, the first determining module 710 may include a first generating unit and a first determining unit.
[0206] The first generating unit is used to generate a first random number k1 in response to the completion of the calculation operation of the original information to be signed, wherein the first random number k1 belongs to (1, n-1), and n represents the order of the elliptic curve.
[0207] The first determining unit is configured to determine the first random number k1 as the first variation factor W1.
[0208] According to an embodiment of the present disclosure, the first processing module 740 may include a first calculating unit and a second determining unit.
[0209] A first calculation unit is configured to calculate V1 according to the first change factor W1, the second change factor W2 and the original sub-private key D1', wherein V1=(D1'*W1 -1*W2)mod n, * represents integer multiplication operation, and mod n represents modulo n operation.
[0210] The second determining unit is used to determine V1 as the current sub-private key D1.
[0211] According to an embodiment of the present disclosure, the first determining module 710 may include a second generating unit and a third determining unit.
[0212] The second generating unit is used to generate a first random number k1 in response to the completion of the calculation operation of the original information to be signed, wherein the first random number k1 belongs to (1, n-1), and n represents the order of the elliptic curve.
[0213] The third determining unit is configured to determine the first random number k1 as the first variation factor W1.
[0214] According to an embodiment of the present disclosure, the first processing module 740 may include a second calculating unit and a fourth determining unit.
[0215] A second calculation unit is used to calculate U1 according to the first change factor W1, the second change factor W2 and the original sub-private key D1', wherein U1=(((D1'+1)*W1*W2 -1 )-1)mod n, * represents integer multiplication, mod n represents modulo n operation; and
[0216] The fourth determining unit is configured to determine U1 as the current sub-private key D1.
[0217] According to an embodiment of the present disclosure, the first determining module 710 may include a third generating unit and a fifth determining unit.
[0218] The third generating unit is used to generate a first random number k1 in response to the completion of the calculation operation of the original information to be signed, wherein the first random number k1 belongs to (1, n-1), and n represents the order of the elliptic curve.
[0219] A fifth determining unit is configured to determine the first random number k1 as the first variation factor W1.
[0220] According to an embodiment of the present disclosure, the first processing module 740 may include a third calculating unit and a sixth determining unit.
[0221] The third calculation unit is used to calculate J1 according to the first change factor W1, the second change factor W2 and the original sub-private key D1', where J1=(D1'+W1-W2)mod, * represents integer multiplication operation, and mod n represents modulo n operation.
[0222] The sixth determining unit is configured to determine J1 as the current sub-private key D1.
[0223] According to an embodiment of the present disclosure, the first signature module 750 may include a fourth generating unit, a fourth calculating unit, and a seventh determining unit.
[0224] The fourth generating unit is used to generate a third random number k3, wherein the third random number k3 belongs to (1, n-1), and n represents the order of the elliptic curve.
[0225] The fourth calculation unit is used to calculate Q1, wherein Q1=[k3]G, G represents the base point of the elliptic curve, and [k3]G represents a k3-times point operation of the base point G of the elliptic curve.
[0226] A seventh determining unit is configured to determine Q1 as the first signature result S1.
[0227] According to an embodiment of the present disclosure, the calculation module 780 may include a first receiving unit, a fifth calculating unit, and an eighth determining unit.
[0228] The first receiving unit is configured to receive S' and r from the second communication party.
[0229] The fifth calculation unit is used to calculate s, where s=(D1*(k3+S')-r)mod n.
[0230] The eighth determining unit is used to determine (r, s) as the signature result S of the current information M to be signed when s is not equal to zero and s is not equal to nr.
[0231] According to an embodiment of the present disclosure, the first signature module 750 may include a fifth generating unit, a sixth calculating unit, and a ninth determining unit.
[0232] The fifth generating unit is used to generate a third random number k3, wherein the third random number k3 belongs to (1, n-1), and n represents the order of the elliptic curve.
[0233] The sixth calculation unit is used to calculate Q1, wherein Q1=[k3]G, G represents the base point of the elliptic curve, and [k3]G represents a k3-times point operation of the base point G of the elliptic curve.
[0234] A ninth determining unit is configured to determine Q1 as the first signature result S1.
[0235] According to an embodiment of the present disclosure, the calculation module 780 may include a second receiving unit, a seventh calculation unit, and a tenth determination unit.
[0236] The second receiving unit is used to receive S', S", and r from the second communication party.
[0237] The seventh calculation unit is used to calculate s, where s=((D1+1)*S'+(D1+1)*k3*S"-r)mod n, + represents integer addition operation or elliptic curve point addition operation, and - represents integer subtraction operation or elliptic curve point subtraction operation.
[0238] The tenth determining unit is used to determine (r, s) as the signature result S of the information to be signed M when s is not equal to zero and s is not equal to nr.
[0239] According to an embodiment of the present disclosure, the first signature module 750 may include a sixth generation unit, an eighth calculation unit, and an eleventh determination unit.
[0240] The sixth generating unit is used to generate a third random number k3, wherein the third random number k3 belongs to (1, n-1), and n represents the order of the elliptic curve.
[0241] The eighth calculation unit is used to calculate Q1, wherein Q1=[k3](G+P), G represents the base point of the elliptic curve, and [k3](G+P) represents a k3-times point operation of (G+P).
[0242] An eleventh determining unit is configured to determine Q1 as the first signature result S1.
[0243] According to an embodiment of the present disclosure, the calculation module 780 may include a third receiving unit, a ninth calculation unit, and a twelfth determination unit.
[0244] The third receiving unit is configured to receive S' and r from the second communication party.
[0245] The ninth calculation unit is used to calculate s, where s=(k3+r*D1+S'-r)mod n, + represents integer addition operation or elliptic curve point addition operation, and - represents integer subtraction operation or elliptic curve point subtraction operation.
[0246] The twelfth determining unit is used to determine (r, s) as the signature result S of the information to be signed M when s is not equal to zero and s is not equal to nr.
[0247] Figure 8 A block diagram of a computing device for collaborative digital signature based on a variation factor according to another embodiment of the present disclosure is schematically shown.
[0248] like Figure 8 As shown, the computing device 800 for collaborative digital signature based on a variation factor includes a second determination module 810, a third sending module 820, a third receiving module 830, a second processing module 840, a fourth receiving module 850, a second signature module 860 and a fourth sending module 870.
[0249] The second determination module 810 is configured to determine the original sub-private key D2' and the second change factor W2 in response to determining that the first communication party has completed the calculation operation on the original information to be signed. The original sub-private key D2' is used to calculate the original information to be signed.
[0250] The third sending module 820 is configured to send the second change factor W2 to the first communication party.
[0251] The third receiving module 830 is configured to receive a first variation factor W1 from a first communication party.
[0252] The second processing module 840 is used to process the original sub-private key D2' by using the first change factor W1 and the second change factor W2 to obtain the current sub-private key D2.
[0253] The fourth receiving module 850 is configured to receive a first signature result S1 from a first communication party.
[0254] The second signature module 860 is used to calculate the current information to be signed M using the first signature result S1 and the current sub-private key D2 to obtain a second signature result S2.
[0255] The fourth sending module 870 is used to send the second signature result S2 to the first communication party, so that the first communication party can use the second signature result S2 to calculate the current information to be signed M to obtain the signature result S.
[0256] It should be noted that the computing device part of the collaborative digital signature based on a variable factor in the embodiment of the present disclosure corresponds to the computing method part of the collaborative digital signature based on a variable factor in the embodiment of the present disclosure. The description of the computing device part of the collaborative digital signature based on a variable factor specifically refers to the computing method part of the collaborative digital signature based on a variable factor, which will not be repeated here.
[0257] Fig. 9 A block diagram of an electronic device suitable for implementing a calculation method of a collaborative digital signature based on a variation factor according to an embodiment of the present disclosure is schematically shown. Fig. 9 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0258] like Fig. 9As shown, the computer electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage part 909 into a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include an onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0259] In RAM 903, various programs and data required for the operation of electronic device 900 are stored. Processor 901, ROM 902 and RAM 903 are connected to each other via bus 904. Processor 901 performs various operations of the method flow according to the embodiment of the present disclosure by executing the program in ROM 902 and / or RAM 903. It should be noted that the program can also be stored in one or more memories other than ROM 902 and RAM 903. Processor 901 can also perform various operations of the method flow according to the embodiment of the present disclosure by executing the program stored in the one or more memories.
[0260] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the I / O interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card, a modem, etc. The communication portion 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed, so that a computer program read therefrom is installed into the storage portion 908 as needed.
[0261] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist independently without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiment of the present disclosure is implemented.
[0262] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium. For example, it may include, but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, an apparatus, or a device.
[0263] For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the ROM 902 and / or the RAM 903 described above and / or one or more memories other than the ROM 902 and the RAM 903 .
[0264] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram may represent a module, a program segment, or a part of a code, and the above-mentioned module, program segment, or a part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box may also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions. It can be understood by those skilled in the art that the features recorded in the various embodiments and / or claims of the present disclosure can be combined and / or combined in a variety of ways, even if such a combination or combination is not explicitly recorded in the present disclosure. In particular, without departing from the spirit and teaching of the present disclosure, the features described in the various embodiments and / or claims of the present disclosure may be combined and / or combined in a variety of ways. All of these combinations and / or combinations fall within the scope of the present disclosure.
[0265] The embodiments of the present disclosure are described above. However, these embodiments are only for illustrative purposes and are not intended to limit the scope of the present disclosure. Although the embodiments are described above separately, this does not mean that the measures in the various embodiments cannot be used in combination to advantage. The scope of the present disclosure is defined by the attached claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art may make a variety of substitutions and modifications, which should all fall within the scope of the present disclosure.
Claims
1. A method for calculating a collaborative digital signature based on a variable factor, applied to a first communication party, include: In response to the completion of the calculation operation of the original information to be signed, determining an original sub-private key D1' and a first change factor W1, wherein the original sub-private key D1' is used to calculate the original information to be signed, and the first change factor W1 is determined by the first communication party according to the original information to be signed, the first signature result, the second signature result, and all or part of the values in the signature result in the previous round of digital signature calculation; Sending the first change factor W1 to the second communication party; Receiving a second change factor W2 from the second communication party, where the second change factor W2 is determined by the second communication party according to the original information to be signed, the first signature result, the second signature result, and all or part of the values in the signature result in the previous round of digital signature calculation; Using the first change factor W1 and the second change factor W2, the original sub-private key D1' is processed to obtain a current sub-private key D1; The current sub-private key D1 is used to calculate the current information to be signed M to obtain a first signature result S1; Sending the first signature result S1 to the second communication party; receiving a second signature result S2 from the second communication party, where the second signature result S2 is obtained by the second communication party calculating the current information M to be signed by using the first signature result S1 and the current sub-private key D2, where the current sub-private key D2 is obtained by the second communication party processing the original sub-private key D2' by using the first change factor W1 and the second change factor W2, where the original sub-private key D2' is determined by the second communication party and is used to calculate the original information to be signed; The current information to be signed M is calculated using the current sub-private key D1, the first signature result S1 and the second signature result S2 to obtain a signature result S.
2. The method according to claim 1, in, The calculation method of the digital signature is based on the elliptic curve public key cryptography algorithm; In response to the calculation operation of the original information to be signed being completed, determining the original sub-private key D1' and the first change factor W1 comprises: In response to the completion of the calculation operation of the original information to be signed, a first random number k1 is generated, wherein the first random number k1 belongs to (1, n-1), and n represents the order of the elliptic curve; and Determine the first random number k1 as the first variation factor W1; The using the first change factor W1 and the second change factor W2 to process the original sub-private key D1' to obtain the current sub-private key D1 includes: According to the first change factor W1, the second change factor W2 and the original sub-private key D1', V1 is calculated, where V1=(D1'*W1 -1 *W2) mod n, * represents integer multiplication, W1 -1 represents the inverse element of W1 modulo n; and V1 is determined as the current child private key D1.
3. The method according to claim 1, in, The calculation method of the digital signature is based on the elliptic curve public key cryptography algorithm; In response to the calculation operation of the original information to be signed being completed, determining the original sub-private key D1' and the first change factor W1 comprises: In response to the completion of the calculation operation of the original information to be signed, a first random number k1 is generated, wherein the first random number k1 belongs to (1, n-1), and n represents the order of the elliptic curve; and Determine the first random number k1 as the first variation factor W1; The using the first change factor W1 and the second change factor W2 to process the original sub-private key D1' to obtain the current sub-private key D1 includes: According to the first change factor W1, the second change factor W2 and the original sub-private key D1', U1 is calculated, where U1=(((D1'+1)*W1*W2 -1 )-1) mod n, * represents integer multiplication, W2 -1 represents the inverse element of W2 modulo n; and Determine U1 as the current child private key D1.
4. The method according to claim 1, in, The calculation method of the digital signature is based on the elliptic curve public key cryptography algorithm; In response to the calculation operation of the original information to be signed being completed, determining the original sub-private key D1' and the first change factor W1 comprises: In response to the completion of the calculation operation of the original information to be signed, a first random number k1 is generated, wherein the first random number k1 belongs to (1, n-1), and n represents the order of the elliptic curve; and Determine the first random number k1 as the first variation factor W1; The using the first change factor W1 and the second change factor W2 to process the original sub-private key D1' to obtain the current sub-private key D1 includes: Calculate J1 according to the first change factor W1, the second change factor W2 and the original sub-private key D1', where J1=(D1'+W1-W2) mod n, mod n represents modulo n operation, + represents integer addition operation or elliptic curve point addition operation, and - represents integer subtraction operation or elliptic curve point subtraction operation; and J1 is determined as the current child private key D1.
5. The method according to claim 2, in, The calculation of the current information to be signed M using the current sub-private key D1 to obtain the first signature result S1 includes: Generate a third random number k3, wherein the third random number k3 belongs to (1, n-1), and n represents the order of the elliptic curve; Calculate Q1, where Q1=[k3]G, G represents the base point of the elliptic curve, and [k3]G represents a k3-times point operation of the base point G of the elliptic curve; and Determine Q1 as the first signature result S1; The calculation of the current information to be signed M by using the current sub-private key D1, the first signature result S1 and the second signature result S2 to obtain the signature result S includes: receiving S' and r from the second communication party; Calculate s, where s=(D1*(k3+S')-r) mod n; and When s is not equal to zero and s is not equal to nr, (r, s) is determined as the signature result S of the current information M to be signed.
6. The method according to claim 3, in, The calculation of the signature information M using the current sub-private key D1 to obtain the first signature result S1 includes: Generate a third random number k3, wherein the third random number k3 belongs to (1, n-1), and n represents the order of the elliptic curve; Calculate Q1, where Q1=[k3]G, G represents the base point of the elliptic curve, and [k3]G represents a k3-times point operation of the base point G of the elliptic curve; and Determine Q1 as the first signature result S1; The calculation of the current information to be signed M by using the current sub-private key D1, the first signature result S1 and the second signature result S2 to obtain the signature result S includes: receiving S', S'' and r from the second communication party; Calculate s, where s=((D1+1)*S'+(D1+1)*k3*S''-r) mod n, + represents integer addition or elliptic curve point addition, and - represents integer subtraction or elliptic curve point subtraction; and When s is not equal to zero and s is not equal to nr, (r, s) is determined as the signature result S of the information to be signed M.
7. The method according to claim 4, in, The calculation of the signature information M using the current sub-private key D1 to obtain the first signature result S1 includes: Generate a third random number k3, wherein the third random number k3 belongs to (1, n-1), and n represents the order of the elliptic curve; Calculate Q1, where Q1=[k3](G+P), G represents the base point of the elliptic curve, P represents the public key, and [k3](G+P) represents a k3-times point operation of (G+P); and Determine Q1 as the first signature result S1; The calculation of the current information to be signed M by using the current sub-private key D1, the first signature result S1 and the second signature result S2 to obtain the signature result S includes: receiving S' and r from the second communication party; Calculate s, where s=(k3+r*D1+S'-r) mod n, + represents integer addition or elliptic curve point addition, and - represents integer subtraction or elliptic curve point subtraction; and When s is not equal to zero and s is not equal to nr, (r, s) is determined as the signature result S of the information M to be signed.
8. A method for calculating a collaborative digital signature based on a variation factor, applied to a second communication party, include: In response to determining that the first communication party has completed the calculation operation on the original information to be signed, determining an original sub-private key D2' and a second change factor W2, wherein the original sub-private key D2' is used to calculate the original information to be signed, and the second change factor W2 is determined by the second communication party according to the original information to be signed, the first signature result, the second signature result, and all or part of the values in the signature result in the previous round of digital signature calculation; Sending the second variation factor W2 to the first communication party; receiving a first change factor W1 from the first communication party, where the first change factor W1 is determined by the first communication party according to the original information to be signed, the first signature result, the second signature result, and all or part of the values in the signature result in the previous round of digital signature calculation; Using the first change factor W1 and the second change factor W2, the original sub-private key D2' is processed to obtain a current sub-private key D2; Receive a first signature result S1 from the first communication party, where the first signature result S1 is obtained by the first communication party using the current sub-private key D1 to calculate the current information M to be signed, where the current sub-private key D1 is obtained by the first communication party using the first change factor W1 and the second change factor W2 to process the original sub-private key D1', where the original sub-private key D1' is determined by the first communication party and is used to calculate the original information to be signed; Calculate the current information to be signed M using the first signature result S1 and the current sub-private key D2 to obtain a second signature result S2; The second signature result S2 is sent to the first communication party, so that the first communication party uses the second signature result S2 to calculate the current information to be signed M to obtain a signature result S.
9. A computing device for collaborative digital signature based on a variable factor, applied to a first communication party, include: A first determination module is configured to determine, in response to the completion of the calculation operation of the original information to be signed, an original sub-private key D1' and a first change factor W1, wherein the original sub-private key D1' is used to calculate the original information to be signed, and the first change factor W1 is determined by the first communication party according to the original information to be signed, the first signature result, the second signature result, and all or part of the values in the signature result in the previous round of digital signature calculation; A first sending module, configured to send the first change factor W1 to a second communication party; A first receiving module is used to receive a second change factor W2 from a second communication party, where the second change factor W2 is determined by the second communication party according to the original information to be signed, the first signature result, the second signature result, and all or part of the values in the signature result in the previous round of digital signature calculation; A first processing module, configured to process the original sub-private key D1' by using the first change factor W1 and the second change factor W2 to obtain a current sub-private key D1; A first signature module, configured to use the current sub-private key D1 to calculate the current information to be signed M to obtain a first signature result S1; A second sending module, used to send the first signature result S1 to the second communication party; a second receiving module, configured to receive a second signature result S2 from the second communication party, wherein the second signature result S2 is obtained by the second communication party calculating the current information M to be signed by using the first signature result S1 and the current sub-private key D2, wherein the current sub-private key D2 is obtained by the second communication party processing the original sub-private key D2' by using the first change factor W1 and the second change factor W2, and the original sub-private key D2' is determined by the second communication party and is used to calculate the original information to be signed; The calculation module is used to calculate the current information to be signed M by using the current sub-private key D1, the first signature result S1 and the second signature result S2 to obtain a signature result S.
10. A computing device for collaborative digital signature based on a variable factor, applied to a second communication party, include: A second determination module is configured to determine, in response to determining that the first communication party has completed the calculation operation on the original information to be signed, an original sub-private key D2' and a second change factor W2, wherein the original sub-private key D2' is used to calculate the original information to be signed, and the second change factor W2 is determined by the second communication party according to the original information to be signed, the first signature result, the second signature result, and all or part of the values in the signature result in the previous round of digital signature calculation; A third sending module, configured to send the second change factor W2 to the first communication party; A third receiving module is used to receive a first change factor W1 from the first communication party, where the first change factor W1 is determined by the first communication party according to the original information to be signed, the first signature result, the second signature result, and all or part of the values in the signature result in the previous round of digital signature calculation; A second processing module, configured to process the original sub-private key D2' by using the first change factor W1 and the second change factor W2 to obtain a current sub-private key D2; a fourth receiving module, configured to receive a first signature result S1 from the first communication party, wherein the first signature result S1 is obtained by the first communication party using the current sub-private key D1 to calculate the current information to be signed M, wherein the current sub-private key D1 is obtained by the first communication party using the first change factor W1 and the second change factor W2 to process the original sub-private key D1', wherein the original sub-private key D1' is determined by the first communication party and is used to calculate the original information to be signed; A second signature module, configured to calculate the current information to be signed M using the first signature result S1 and the current sub-private key D2 to obtain a second signature result S2; The fourth sending module is used to send the second signature result S2 to the first communication party, so that the first communication party uses the second signature result S2 to calculate the current information to be signed M to obtain the signature result S.
Citation Information
Patent Citations
Private key protection method, system and device based on key updating
CN107302438A