Signature Key Generation Method and Related Methods, Computer Device, and Storage Medium

The method of jointly generating and distributing SM2 private keys among multiple parties addresses the challenge of secure key management in cloud and mobile environments, ensuring the keys are never fully exposed.

CN115549926BActive Publication Date: 2025-07-15BEIJING WUZI TIANSHU TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211242805.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-11
Publication Date
2025-07-15
Estimated Expiration
2042-10-11

AI Technical Summary

Technical Problem

In the cloud computing and mobile Internet environment, it is difficult for the existing technology to effectively manage and store SM2 private keys, resulting in limited security and convenience of use.

Method used

The signature key generation method is adopted to generate the signature private key through cooperation between the first communicator and the second communicator, and assisted by the key generation center, each sub-private key D1 and D2 are generated, respectively stored at the communicator. The complete private key is shared by both parties, and the validity of the public key is verified through joint calculation.

Benefits of technology

A solution to securely store and manage SM2 private keys in cloud computing and mobile terminals is realized, ensuring that the private keys are not deduced from any party's data, improving the security and convenience of the private keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115549926B_ABST
    Figure CN115549926B_ABST
Patent Text Reader

Abstract

The present invention provides a method for generating a signature key, and also provides corresponding methods for verifying a signature key, generating a digital signature, verifying a digital signature, a computer device, and a computer-readable storage medium. The method for generating a signature key includes the steps of: A. Setting system parameters; B. A first communication party and a second communication party cooperate to generate a signature private key, obtaining a sub-private key D1 of the first communication party and a sub-private key D2 of the second communication party, and generating a complete public key P A . The method for generating a signature key provided by the present invention uses two communication parties and a key generation center to jointly generate an SM2 private key, and the two communication parties respectively store part of the SM2 private key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and particularly relates to a signature key generation method, a corresponding signature key verification method, a digital signature generation method, a digital signature verification method, a computer device, and a computer-readable storage medium Background Art

[0002] The SM2 cryptographic algorithm is a public key cryptographic algorithm released by the State Cryptography Administration. The traditional certificate-based Public Key Infrastructure (PKI) system is a system that uses digital certificates and associates the public key of the signer, user identity information, and distinguishable identifiers by a trusted third party

[0003] In the prior art, a scheme (i.e., the first technical solution) has been proposed to associate the public key of the signer, identity information, and distinguishable identifiers in a certificate-free system. In this scheme, the SM2 private key is interacted between the key generation center and the user, and is generated according to the private key of the key generation center and the distinguishable identifier of the user. The SM2 private key is generated in the user's cryptographic device or cryptographic module. The SM2 public key is calculated from the declared public key and the public key of the key generation center. In this scheme, the SM2 private key is solely controlled by the user, so it is not convenient to store and use the SM2 private key in environments such as cloud computing and mobile Internet

[0004] In addition, some technical personnel have proposed a signature and decryption method (i.e., the second technical solution) in which two communication parties respectively store part of the SM2 private key and jointly generate the key. In this method, the SM2 private key and public key of the user are jointly calculated by two communication parties, and two communication parties respectively store part of the SM2 private key. However, the key generation method of this method is not adapted to the key generation method in the first technical solution. It cannot solve the problem that the SM2 private key cannot be securely stored and used and managed in environments such as cloud computing and mobile Internet in a certificate-free system Summary of the Invention

[0005] To solve the above technical problems, the present invention proposes a signature key generation method

[0006] The signature key generation method provided by the present invention includes the steps of

[0007] A. Set system parameters

[0008] B. The first communication party and the second communication party cooperate to generate a signature private key, obtain the sub-private key D1 of the first communication party and the sub-private key D2 of the second communication party, and generate a complete public key P A ,

[0009] Wherein

[0010] The first communication party, the second communication party and the key generation center share the elliptic curve parameters E(Fq), G and n of the SM2 algorithm, where E(Fq) is an elliptic curve defined over the finite field Fq, G represents a base point of order n on E, and n is a prime number.

[0011] Furthermore,

[0012] Step B includes the following steps:

[0013] The first communication party sends a private key application request to the second communication party;

[0014] The second communication party generates a random number d in the range [1, n - 1] s , and calculates U s = [d s × G. The second communication party sends U s to the first communication party. In each calculation formula of the signature key generation method, the meaning of the square brackets [] represents the multiple point operation on the elliptic curve;

[0015] The first communication party generates a random number r in the range [1, n - 1] A , and calculates U A = [r A -1 × U s - G;

[0016] The first communication party submits U A and the identifier ID A to the key generation center;

[0017] B5. The key generation center calculates t A and the declared public key W A , and sends t A and the declared public key W A to the first communication party;

[0018] The first communication party calculates t s ≡ (r A × t A ) mod n, and sends t s to the second communication party. The first communication party sets its own sub - private key D1 = r A , where x mod y represents the remainder of x divided by y;

[0019] The second communication party calculates its own sub - private key D2 = (t s + d s ) -1 mod n;

[0020] B8. The first communication party stores the declared public key W A , and selects to generate the complete public key P A according to the declared public key W A , the identification ID Pub , and the system master public key P A .

[0021] Furthermore,

[0022] in the step B5,

[0023] the process of the key generation center calculating t A and the declared public key W A includes the following steps:

[0024] B51. The key generation center calculates H A = H 256 (ENTL A ‖ID A ‖x Pub ‖y Pub ), where ENTL A is the byte length of the identification ID A represented by 2 bytes, || represents the concatenation of the byte strings of the data, x Pub , y Pub are the coordinates of the system master public key P Pub of the key generation center, and H 256 is a hash function with an output of 256 bits;

[0025] B52. The key generation center generates a random number w ∈ [1, n - 1];

[0026] B53. The key generation center calculates the declared public key W A = [w]×G + U A ;

[0027] B54. The key generation center converts the data types of the coordinates x A and y W of the declared public key W W into bit strings, calculates λ = H 256 (x W ‖y W ‖H A ) mod n, and converts the data type of λ into an integer;

[0028] B55. The key generation center calculates t A = (w + λ×ms) mod n.

[0029] Furthermore,

[0030] In the step B8, the following steps are included:

[0031] Calculate λ according to the steps B51 - B54;

[0032] Calculate P A = W A + [λ] × P Pub .

[0033] Furthermore,

[0034] The complete private key of the first communication party is d A = (t A + d S × r A -1 - 1) mod n;

[0035] The complete public key P A = W A + [λ] × P Pub = [t A + d S × r A -1 - 1] × G;

[0036] The sub - private keys D1 and D2 of the first communication party and the second communication party satisfy the relationship:

[0037] D1 × D2 = r A × (t s + d s ) -1 mod n = (1 + d A ) -1 mod n.

[0038] Furthermore,

[0039] The key generation center generates the system master private key ms and the system master public key P Pub ,

[0040] wherein,

[0041] P Pub = [ms] × G.

[0042] The present invention also provides a signature key verification method, including the steps:

[0043] Obtain the sub - private key D1 of the first communication party and the sub - private key D2 of the second communication party by using the above - mentioned signature key generation method,

[0044] The first communication party and the second communication party use their respective sub - private keys D1 and D2 to verify the validity of the declared public key W A , including the following steps:

[0045] The first communication party calculates T1 = [D1 -1 mod n] × G, and sends T1 to the second communication party;

[0046] The second communication party calculates T2 = [D2 -1 mod n] × T1, and sends T2 to the first communication party;

[0047] The first communication party calculates T = T2 - G and compares T and P A , if they are equal, the verification passes; otherwise, the verification fails.

[0048] The present invention also provides a digital signature generation method, including the steps of:

[0049] The first communication party preprocesses the original message m to be signed to obtain 256-bit data e to be signed;

[0050] Using the above signature key generation method to obtain the sub-private key D1 of the first communication party and the sub-private key D2 of the second communication party,

[0051] The first communication party and the second communication party use their respective sub-private keys D1 and D2 to jointly calculate the signature value (r, s) of e according to the following steps:

[0052] DD21. The first communication party generates a random number k1 ∈ [1, n - 1], and calculates Q1 = [k1] × G;

[0053] The first communication party sends e and Q1 to the second communication party;

[0054] The second communication party generates a random number k2 ∈ [1, n - 1], and calculates Q2 = [k2] × G;

[0055] DD24. The second communication party generates a random number k3 ∈ [1, n - 1], calculates Q3 = [k3] × Q1 + Q2, where + is the point addition operation in the elliptic curve, and records the coordinates of Q3 as (x1, y1);

[0056] The second communication party calculates r = x1 + e mod n, if r is equal to 0, the second communication party returns to the step DD24;

[0057] The second communication party calculates s2 = (D2 × k3) mod n, s3 = (D2 × (r + k2)) mod n, and sends r, s2 and s3 to the first communication party;

[0058] The first communication party calculates s = ((D1 × k1) × s2 + D1 × s3 - r) mod n. If s is equal to 0 or equal to n - r, return to the step DD21;

[0059] The first communication party outputs (r, s) as the complete signature.

[0060] The present invention also provides a digital signature verification method, which uses the above signature key generation method to verify the digital signature of the original signed message mm.

[0061] The present invention also provides a computer device, including a storage, a first processor, and a first computer program stored on the storage and executable on the first processor. When the first computer program is executed by the first processor, one or several of the following methods are implemented:

[0062] The above signature key generation method;

[0063] The above signature key verification method;

[0064] The above digital signature generation method;

[0065] The above digital signature verification method.

[0066] The present invention also provides a computer-readable storage medium for storing a second computer program, which can be executed by at least one second processor, so that the at least one second processor executes one or several of the following methods:

[0067] The above signature key generation method;

[0068] The above signature key verification method;

[0069] The above digital signature generation method;

[0070] The above digital signature verification method.

[0071] The signature key generation method provided by the present invention uses two communication parties and a key generation center to jointly generate an SM2 private key, and the two communication parties respectively store a part of the SM2 private key. During the generation process, the complete signature private key of the user does not appear and cannot be deduced from the data of any party. The first communication party and the second communication party respectively hold a part of the complete signature private key, thus solving the problem of private key management in cloud computing and mobile terminals.

[0072] Other features and advantages of the present invention will be described in the following specification, and part of them will be obvious from the specification or understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the structures pointed out in the specification, claims, and drawings. Brief Description of the Drawings

[0073] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0074] Figure 1 It shows a schematic flowchart of a signature key generation method according to an embodiment of the present invention. Detailed Embodiments

[0075] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0076] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs; the terms used in the description of the present application in this specification are only for the purpose of describing specific embodiments, and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the description and claims of this application and the above drawings are intended to cover non-exclusive inclusion. The terms "first", "second", "third", etc. in the description and claims of this application or the above drawings are used to distinguish different objects, rather than to describe a specific order or primary-secondary relationship. The term "plurality" as used in this application means two or more (including two).

[0077] Referring to the embodiments mentioned herein means that the specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of this application. The phrase appears at various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0078] The following will refer to the drawings to describe in detail the signature key generation method provided by the present invention. Figure 1 It is a schematic flowchart of the signature key generation method of the present invention. Refer to Figure 1 The signature key generation method includes the following steps:

[0079] A. Set system parameters, including the steps of:

[0080] A1. The first communication party, the second communication party, and the key generation center (KGC) share the elliptic curve parameters E(Fq), G, and n of the SM2 algorithm. E(Fq) is an elliptic curve defined over the finite field Fq, G represents the base point of order n on the elliptic curve E(Fq), and n is a prime number. The specific values of each parameter are preset according to the SM2 algorithm;

[0081] A2. The KGC generates the system master private key ms and the system master public key P Pub , where P Pub = [ms] × G. In the present invention, the meaning of the square brackets [] in each calculation formula represents the multiple point operation on the elliptic curve.

[0082] B. Generate a signature private key, including the steps of:

[0083] B1. The first communication party sends a private key application request to the second communication party;

[0084] B2. The second communication party generates a random number d between [1, n - 1] s , and calculates U s = [d s × G. The second communication party sends U s to the first communication party;

[0085] B3. The first communication party generates a random number r between [1, n - 1] A , and calculates U A = [r A -1 × U s - G;

[0086] B4. The first communication party submits U A and the identifier ID A to the KGC. Among them, the identifier ID A is consistent with the identifier defined in SM9 and is specified by the upper-layer application system (see 3.1 in Standard GB / T38635.1 - 2020), and is information that can uniquely determine the identity of an entity, and can be the recognizable name, email address, ID number, phone number, etc. of the entity;

[0087] B5. The KGC calculates t A and the declaration public key W A , and sends t A and W A to the first communication party,

[0088] where,

[0089] The KGC calculates t A and declares the public key W A The process includes the following steps:

[0090] B51. The KGC calculates H A =H 256 (ENTL A ‖ID A ‖x Pub ‖y Pub ), where ENTL A is the byte length of the identification ID represented by 2 bytes A of, || represents the merging of the byte strings of the data, x Pub , y Pub are the coordinates of the system master public key P Pub of the KGC;

[0091] B52. The KGC generates a random number w ∈ [1, n - 1];

[0092] B53. The KGC calculates the declared public key W A =[w]×G + U A ;

[0093] B54. The KGC converts the coordinates x A , y W of W W to a bit string according to the methods given in 4.2.6 and 4.2.5 of the standard "GB / T 32918.1 - 2016", calculates λ = H 256 (x W ‖y W ‖H A ) mod n, and converts the data type of λ to an integer according to the methods given in 4.2.4 and 4.2.3 of the standard "GB / T 32918.1 - 2016". Among them, H 256 represents a hash function with an output of 256 bits, and can be a cryptographic algorithm function such as SM3, SHA256, etc. x mod y represents the modulo operation of x with respect to y;

[0094] B55. The KGC calculates t A =(w + λ×ms) mod n;

[0095] B6. The first communication party calculates t s ≡(r A ×t A ) mod n, and sends t s to the second communication party; The first communication party sets its own sub - private key D1 = r A ;

[0096] B7. The second communicating party calculates its own sub-private key D2 = (t s + d s ) -1 mod n;

[0097] B8. The first communicating party saves its own declared public key W A , and can select to generate the complete public key P A according to the declared public key W A , the identifier ID Pub , and the system public key P A as follows:

[0098] B81. Calculate λ according to steps B51 - B54;

[0099] B82. Calculate P A = W A + [λ]×P Pub .

[0100] According to the above calculation process, the complete private key of the first communicating party is d A = (t A + d S × r A -1 - 1) mod n, the complete public key P A = W A + [λ]×P Pub = [t A + d S × r A -1 - 1]×G, and the sub-private keys D1 and D2 of the first communicating party and the second communicating party satisfy the relationship:

[0101] D1×D2 = r A ×(t s + d s ) -1 mod n = (1 + d A ) -1 mod n.

[0102] The present invention also provides a signature key verification method, including the steps:

[0103] C1. The first communicating party and the second communicating party use their respective sub-private keys D1 and D2 to verify the validity of the declared public key W A , and the verification process includes the following steps:

[0104] C11. The first communicating party calculates T1 = [D1 -1 mod n]×G, and sends T1 to the second communicating party;

[0105] C12. The second communication party calculates T2 = [D2 -1 mod n] × T1, and sends T2 to the first communication party;

[0106] C13. The first communication party calculates T = T2 - G and compares T with P A , if they are equal, the verification passes; otherwise, the verification fails.

[0107] The present invention also provides a digital signature generation method, including the steps:

[0108] DD1. The first communication party preprocesses the original message m to be signed to obtain 256-bit data e to be signed. The preprocessing process may follow A1 - A2 in 6.1 of the standard "GB / T 32981.2 - 2016";

[0109] DD2. The first communication party and the second communication party jointly calculate the signature value (r, s) of e using their respective sub-private keys D1 and D2 according to the following steps:

[0110] DD21. The first communication party generates a random number k1 ∈ [1, n - 1], and calculates Q1 = [k1] × G;

[0111] DD22. The first communication party sends e and Q1 to the second communication party;

[0112] DD23. The second communication party generates a random number k2 ∈ [1, n - 1], and calculates Q2 = [k2] × G;

[0113] DD24. The second communication party generates a random number k3 ∈ [1, n - 1], calculates Q3 = [k3] × Q1 + Q2, where + is the point addition operation in the elliptic curve, and records the coordinates of Q3 as (x1, y1);

[0114] DD25. The second communication party calculates r = x1 + e mod n. If r is equal to 0, the second communication party returns to step DD24;

[0115] DD26. The second communication party calculates s2 = (D2 × k3) mod n, s3 = (D2 × (r + k2)) mod n, and sends r, s2, and s3 to the first communication party;

[0116] DD27. The first communication party calculates s = ((D1 × k1) × s2 + D1 × s3 - r) mod n. If s is equal to 0 or equal to n - r, it returns to step DD21;

[0117] DD28. The first communication party outputs (r, s) as the complete signature.

[0118] The present invention also provides a digital signature verification method. A signature verifier can use the signer identifier ID, the declared public key W, and the system public key P to verify the received original signed message mm and signature values (rr, ss). The steps are as follows: AA and the declared public key W AA and the system public key P Pub for verification, and the steps are as follows:

[0119] E1. Use the calculation in step B8 to recover the complete public key P AA ;

[0120] E2. Use the calculation in step DD1 to calculate the preprocessed value (i.e., the data to be signed) ee of the message mm;

[0121] E3. Complete the verification of the signature values according to steps B5 - B7 in 7.1 of the standard "GB / T32981.2 - 2016".

[0122] The present invention also provides a computer device, including a memory, a first processor, and a first computer program stored on the memory and executable on the first processor. When the first computer program is executed by the first processor, it implements one or several of the above - mentioned signature key generation methods, signature key verification methods, digital signature generation methods, and digital signature verification methods.

[0123] The present invention also provides a computer - readable storage medium for storing a second computer program, which can be executed by at least one second processor, so that at least one second processor executes one or several of the above - mentioned signature key generation methods, signature key verification methods, digital signature generation methods, and digital signature verification methods.

[0124] The signature key generation method provided by the present invention jointly calculates the user's signature key by the first communication party, the second communication party, and the KGC according to the identifier and the KGC system key, and can verify the user's declared public key through the KGC's system public key, ensuring the verifiability of the user identifier, declared public key, and complete public key. During the calculation process, the user's complete signature private key does not appear and cannot be deduced from the data of any party. The first communication party and the second communication party respectively hold a part of the complete signature private key, thus solving the problem of private key management in cloud computing and mobile terminals.

[0125] Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A signature key generation method, characterized in that, Including the steps: A. Set system parameters; B. The first communication party and the second communication party cooperate to generate a signature private key, obtain the sub-private key D1 of the first communication party and the sub-private key D2 of the second communication party, and generate a complete public key P A , Wherein, the first communication party, the second communication party and the key generation center share the elliptic curve parameters E(Fq), G and n of the SM2 algorithm, E(Fq) is an elliptic curve defined over the finite field Fq, G represents a base point of order n on E, and n is a prime number; The step B includes the following steps: The first communication party sends a private key application request to the second communication party; The second communicating party generates a random number d between [1, n - 1] s , and calculates U s = [d s × G. The second communicating party sends U s to the first communicating party. In each calculation formula of the signature key generation method, the meaning of the square brackets [] represents the multiple point operation on the elliptic curve; The first communicating party generates a random number r between [1, n - 1] A , and calculates U A = [r A -1 × U s - G; The first communicating party submits U A and the identification ID A to the key generation center; B5. The key generation center calculates t A and the declared public key W A , and sends t A and the declared public key W A to the first communication party; The first communicating party calculates t s ≡(r A ×t A ) mod n, and sends t s to the second communicating party. The first communicating party sets its own sub-private key D1 = r A , where x mod y represents the remainder operation of x divided by y; The second communicating party calculates its own sub-private key D2 = (t s + d s ) -1 mod n; B8. The first communication party stores the declared public key W A , and selects to generate the complete public key P A according to the declared public key W A , the identification ID Pub , and the system master public key P A , In the step B5, The key generation center calculates t A and the declared public key W A The process includes the following steps: B51. The key generation center calculates H A = H 256 (ENTL A || ID A || x Pub || y Pub ), where ENTL A is the byte length of the identification ID represented by 2 bytes A , || represents the merging of the byte strings of the data, x Pub , y Pub are the coordinates of the system master public key P Pub of the key generation center, and H 256 is a hash function with an output of 256 bits; B52. The key generation center generates a random number w ∈ [1, n - 1]; B53. The key generation center calculates the declared public key W A = [w] × G + U A ; B54. The key generation center converts the coordinates x A and y W of the public key W W into bit strings, calculates λ = H 256 (x W || y W || H A ) mod n, and converts the data type of λ into an integer; B55. The key generation center calculates t A = (w + λ × ms) mod n, where ms is the system master private key.

2. The signature key generation method according to claim 1, wherein In the step B8, it includes the following steps: Calculate λ according to the steps B51 and B54; Calculate P A = W A + [λ] × P Pub .

3. The signature key generation method according to claim 2, wherein The complete private key of the first communicating party is d A =(t A +d S ×r A -1 -1) mod n; The complete public key P A = W A + [λ] × P Pub = [t A + d S × r A -1 -1] × G; The sub-private keys D1 and D2 of the first communication party and the second communication party satisfy the relationship: D1 × D2 = r A × (t s + d s ) -1 mod n = (1 + d A ) -1 mod n。 4. The signature key generation method according to any one of claims 2 - 3, wherein The key generation center generates the system master private key ms and the system master public key P Pub , Wherein, P Pub = [ms] × G.

5. Signature key verification method, characterized in that Including the steps: Obtain the sub-private key D1 of the first communication party and the sub-private key D2 of the second communication party by using the signature key generation method according to any one of claims 1 - 4, The first communication party and the second communication party use their respective sub-private keys D1 and D2 to verify the validity of the declared public key W A including the following steps: The first communicating party calculates T1 = [D1 -1 mod n] × G and sends T1 to the second communicating party; The second communicating party calculates T2 = [D2 -1 mod n] × T1, and sends T2 to the first communicating party; The first communication party calculates T = T2 - G and compares T with P A , if they are equal, the verification passes; otherwise, the verification fails.

6. A method for generating a digital signature, characterized in that, Including the steps: DD1. The first communication party preprocesses the original message m to be signed to obtain a 256-bit data e to be signed; Obtain the sub-private key D1 of the first communication party and the sub-private key D2 of the second communication party by using the signature key generation method according to any one of claims 1 - 4, The first communication party and the second communication party use their respective sub-private keys D1 and D2 to jointly calculate the signature value (r, s) of e according to the following steps: DD21. The first communication party generates a random number k1 ∈ [1, n - 1] and calculates Q1 = [k1] × G; The first communication party sends e and Q1 to the second communication party; The second communication party generates a random number k2 ∈ [1, n - 1] and calculates Q2 = [k2] × G; DD24. The second communication party generates a random number k3 ∈ [1, n - 1], calculates Q3 = [k3] × Q1 + Q2, where + is the point addition operation in the elliptic curve, and denote the coordinates of Q3 as (x1, y1); The second communication party calculates r = x1 + e mod n, if r is equal to 0, then the second communication party returns to the step DD24; The second communication party calculates s2 = (D2 × k3) mod n, s3 = (D2 × (r + k2)) mod n, and sends r, s2 and s3 to the first communication party; The first communication party calculates s = ((D1 × k1) × s2 + D1 × s3 - r) mod n, if s is equal to 0 or equal to n - r, then returns to the step DD21; The first communication party outputs (r, s) as the complete signature.

7. A computer device, characterized in that, Including a memory, a first processor, and a first computer program stored on the memory and executable on the first processor. When the first computer program is executed by the first processor, it implements one or several of the following methods: The signature key generation method according to any one of claims 1 - 4; The signature key verification method according to claim 5; The digital signature generation method according to claim 6.

8. A computer-readable storage medium, characterized in that, For storing a second computer program, the second computer program being executable by at least one second processor to cause the at least one second processor to perform one or more of the following methods: The signature key generation method according to any one of claims 1-4; The signature key verification method according to claim 5; The digital signature generation method according to claim 6.

Citation Information

Patent Citations

  • Signature method, system and device and readable storage medium

    CN112653554A