A method and system for collaboratively generating RSA digital signatures with hidden private key secrets
By generating and storing confidential parameters in the user terminal and signature assist device or system, hiding the user's RSA signature private key, the problem that private key secrets may be illegally acquired in the prior art is solved, and higher private key security and the validity and security of digital signatures are achieved.
Patent Information
- Application Number
- CN202211427879.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-15
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-11-15
AI Technical Summary
In the existing RSA digital signature collaborative generation technology based on secret sharing, other digital signature collaborative generation participants outside the user may obtain the secret share of the user's signature private key, which increases the risk of the private key being cracked and does not meet the requirements of the "Electronic Signature Law of the People's Republic of China".
A collaborative generation method for RSA digital signatures that hide private key secrets is proposed. By generating and storing confidential parameters in the user terminal and the signature assist device or system, it ensures that the signature assist device or system cannot obtain the secret or its secret share of the user's RSA signature private key.
It effectively prevents the secret of the signed private key from being illegally obtained, improves the security of the private key, ensures the validity and security of the generated digital signature, and complies with the requirements of the "Electronic Signature Law of the People's Republic of China".
Smart Images

Figure CN115733623B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of cryptographic technology, and in particular to a RSA digital signature collaborative generation method and system for hiding a private key secret. Background Art
[0002] For user-side computing environments (such as personal computers, mobile phones, tablets, and other mobile terminals) that do not have cryptographic hardware to store signature private keys and use signature private keys for cryptographic operations, a digital signature collaborative generation scheme based on secret sharing is often used to ensure the security of signature private keys and generated digital signatures, such as the SM2 digital signature collaborative generation scheme for SM2 signature private keys. The RSA algorithm was once a widely used public key cryptographic algorithm, including the RSA digital signature algorithm, but with the country's strengthening of cryptographic management and the low efficiency of RSA algorithm operations, it is gradually withdrawing from the Chinese and international cryptographic application markets, but there are still some applications (legacy applications) that use the RSA algorithm, including the RSA digital signature algorithm. In user-side computing environments that do not have cryptographic hardware to store RSA signature private keys and use RSA signature private keys for cryptographic operations, there are also problems and needs on how to ensure the security of signature private keys and generated digital signatures, and RSA digital signatures based on secret sharing are a possible solution.
[0003] One problem with the current RSA digital signature based on secret sharing is that other digital signature collaborative generation participants (devices, systems) other than the user share the secret of the user's signature private key, that is, the secret share of the user's signature private key. This may not be what the user expects. From the user's perspective, other entities have the secret share of the signature private key, which increases the risk of the signature private key being cracked. Moreover, this is not fully compliant with the "Electronic Signature Law of the People's Republic of China". The "Electronic Signature Law" requires that the signature production data when generating an electronic signature be proprietary and controlled by the signer. Therefore, how to safely store and use the user's RSA signature private key to ensure the validity and security of the generated digital signature when other digital signature collaborative generation participants (devices, systems) other than the user do not have and cannot obtain the signature private key and the secret share of the signature private key is a technical problem that needs to be solved. Summary of the invention
[0004] The purpose of the present invention is to address the problems existing in the current RSA digital signature collaborative generation technical solution based on secret sharing, and to propose an RSA digital signature collaborative generation technical solution in which other digital signature collaborative generation participants other than the user (terminal) do not have and cannot obtain the user's signature private key and the secret share of the signature private key, so as to overcome the shortcomings of the prior art.
[0005] In view of the purpose of the present invention, the technical solution proposed by the present invention includes a RSA digital signature collaborative generation method and a corresponding system that hides the private key secret.
[0006] The RSA digital signature collaborative generation method for hiding the private key secret proposed by the present invention is specifically as follows.
[0007] The user's RSA signature key pair has a public key of (e,n) and a private key of (d,p,q,n) or Where n is the modulus, n = pq, (In a typical implementation, the RSA private key data structure stores e, d, n, p, q or But the RSA private key actually only needs (d,n); d is the secret of the RSA signature private key, but sometimes d is directly called the private key);
[0008] There is a set of confidentiality parameters for the user terminal and the signature auxiliary device or system respectively (that is, there are two sets of confidentiality parameters), and each set of confidentiality parameters includes one or more positive integers called confidentiality parameters; the confidentiality parameters are secret; the confidentiality parameter group for the user terminal is called the user-side confidentiality parameter group, and the confidentiality parameters therein are parameters used by the user terminal, called user-side confidentiality parameters; the confidentiality parameter group for the signature auxiliary device or system is called the server-side confidentiality parameter group (because the signature auxiliary device or system is usually a system component or member or system of the server), and the confidentiality parameters therein are parameters used by the signature auxiliary device or system, called server-side confidentiality parameters; the user-side confidentiality parameters (in the confidentiality parameter group) can only be obtained in plain text by the user terminal, and the server (in the confidentiality parameter group) The confidentiality parameters (in the confidentiality parameter group) can only be obtained by the signature auxiliary device or system in plain text; the confidentiality parameters (in the confidentiality parameter group) of the user end are stored in the user terminal; the confidentiality parameters (in the confidentiality parameter group) of the server end are stored in the signature auxiliary device or system, or stored in the user terminal in the form of ciphertext data that can be decrypted by the signature auxiliary device or system (the signature auxiliary device or system has a decryption key for decrypting the ciphertext of the server confidentiality parameters or can obtain the decryption key for decrypting the ciphertext of the server confidentiality parameters, thereby obtaining the plain text of the server confidentiality parameters); the user terminal is the user's computing device (such as a personal computer, mobile phone, tablet computer); the signature auxiliary device or system is a computing device or system that assists and helps the user terminal to complete the generation and calculation of digital signatures;
[0009] The two sets of confidentiality parameters for the user terminal, signature auxiliary device or system have the following characteristics:
[0010] The modulus of the result v after addition and multiplication is performed (once or more, where multiple times refers to two or more times v) using the confidential parameters in the two sets of confidential parameters and the non-confidential parameters other than the confidential parameters (such as the public key parameter e, etc.) in a predetermined (agreed) manner. The remainder is d, which is the result of the operation. That is, v and d modulus Or, the result v after adding or multiplying (once or multiple times) the confidential parameters in the two sets of parameters and the non-confidential parameters other than the confidential parameters according to the predetermined (agreed) operation method is the modulus of e. Multiplicative inverse, that is
[0011] Cannot be derived from a set of confidential parameters It is impossible to obtain the modulus of d from a set of secret parameters Congruent numbers or get the modulus of e Multiplicative inverse, that is, it is impossible to use the confidential parameters in a set of confidential parameters to obtain v1 through (one or more) addition and multiplication operations, there is or
[0012] The signature auxiliary device or system cannot obtain the secret share of the private key secret d through the confidentiality parameters in the server confidentiality parameter group; the secret share of the private key secret d refers to the secret share of the private key secret d obtained during initialization. Integers d1 and d2 are selected from the or or or Wherein a1, a2, a are (public) non-confidential integer parameters; the inability of the signature auxiliary device or system to obtain the secret share of the private key secret d through the confidentiality parameters in the server confidentiality parameter group means that the signature auxiliary device or system cannot obtain any of the above d1 and d2 directly or by calculation through the confidentiality parameters in the server confidentiality parameter group;
[0013] (d1, d2, are selected at initialization, which means that they are fixed once selected, and are not variable numbers containing random factors obtained by temporary calculation. For a number that is not selected at initialization, is variable each time the signature is calculated, and contains random factors, due to is discarded and is different each time. Even if it is one of the two numbers that satisfy the above relationship, the signature auxiliary device or system cannot obtain useful information for cracking d. Therefore, it does not belong to the secret share of the private secret d mentioned in the present invention; it is allowed for the user terminal to have or be able to obtain the secret share of the private key secret d)
[0014] Set p, q, Discard (i.e., no entity saves p, q, );
[0015] When the user's RSA signature private key needs to be used to digitally sign the message M (for example, when the user uses a program in the user terminal such as an app or WeChat applet, or uses a browser or client program to access the application system and needs to digitally sign the message M, or when the user uses other computing terminals to access the application system and needs to sign, when the user uses a mobile terminal to scan a code for digital signature, or when the user uses the current user terminal or other terminals to access the application system and needs to digitally sign, the application system sends a text message to the user terminal to start the cryptographic program for implementing the digital signature in the user terminal):
[0016] The user terminal or the signature auxiliary device or system calculates the hash value h of the message M (in actual calculation, it is the data of the hash value of the message M after being padded and encoded, usually referred to as the hash value of the message M);
[0017] The user terminal and the signature auxiliary device or system use the confidentiality parameters in their respective confidentiality parameter groups to perform a collaborative calculation of a modulo-n exponentiation operation (modulo-n exponential operation) on h without exposing their respective secrets, and the addition and multiplication operations performed on the exponent part of h in the collaborative calculation of the modulo-n exponentiation operation are calculated using the confidentiality parameters in the two sets of confidentiality parameters through (one or more) addition and multiplication operations to obtain the value modulo d. The addition and multiplication operations performed on the congruence operation result v correspond to each other, that is, if two numbers are added when v is calculated, then when the modulo n power operation of h is performed in conjunction with the addition of two numbers in the exponent part of h, if two numbers are multiplied when v is calculated, then when the modulo n power operation of h is performed in conjunction with the multiplication of two numbers in the exponent part of h, the calculation results in s = (h^v) mod n, where ^ represents the power operation (the number before ^ is the base, and the number after ^ is the exponent, that is, h v mod n), then s is the digital signature for the message M (mod n exponentiation, i.e. k j mod n, where k is an integer base and j is an integer number or exponent of the power operation); the number of the two numbers added or multiplied above is a confidentiality parameter in the confidentiality parameter group, or is a non-confidential parameter, or is a number calculated using the confidentiality parameter in the confidentiality parameter group;
[0018] If the confidentiality parameters in the server confidentiality parameter group are encrypted and stored in the user terminal, then when generating a digital signature, the user terminal submits the ciphertext of the confidentiality parameters in the server confidentiality parameter group to the signature auxiliary device or system, and the signature auxiliary device or system decrypts the plaintext of the confidentiality parameters in its confidentiality parameter group;
[0019] Before assisting or helping to complete the generation of the digital signature, the signature assisting device or system confirms that the user is the owner of the modulus n or the public key (e, n), or the system that relies on calling the signature assisting device or system (such as an application service system) confirms that the user is the owner of the modulus n or the public key (e, n);
[0020] The user terminal implements the above-mentioned digital signature calculation and generation steps through the cryptographic program or cryptographic module or cryptographic component that implements the cryptographic function therein, and implements the RSA digital signature function.
[0021] For the above-mentioned RSA digital signature collaborative generation method for hiding the private key secret, the confidentiality parameters in the server confidentiality parameter group are generated as follows, or have the following characteristics (so that the private key secret d and the secret share of the private key secret d cannot be obtained through the server confidentiality parameter group):
[0022] Each confidentiality parameter in the server confidentiality parameter group is a parameter that is independently valued (at the time of initialization) and its value is independent of the private key secret d and the secret share of the private key secret d (that is, it is not a parameter calculated from other confidentiality parameters selected at the time of initialization, and its value is independent of the private key secret d and the secret share of the private key secret d), or is a parameter composed of multiple confidentiality parameters (selected at the time of initialization) (including the private key secret d, the secret share of d, and a randomly selected integer secret), wherein the multiple confidentiality parameters used to calculate the number include at least one confidentiality parameter that is independently valued and has no relation to the private key secret d and the secret share of the private key secret d; the multiple refers to two or more;
[0023] Furthermore, the result of the addition and multiplication operations using the confidentiality parameters in the server confidentiality parameter group is a confidentiality parameter with a single value and its value is independent of the private key secret d and the secret share of the private key secret d, or is a number calculated from multiple confidentiality parameters (selected during initialization), and the multiple confidentiality parameters used to calculate this number include at least one confidentiality parameter with a single value and its value is independent of the private key secret d and the secret share of the private key secret d;
[0024] The confidentiality parameters that have independent values and are independent of the private key secret d and the secret share of the private key secret d include: The random selection that does not depend on the private key secret d and the secret share of the private key secret d satisfies or Integers b1 and b2.
[0025] For the above-mentioned RSA digital signature collaborative generation method that hides the private key secret, the confidentiality parameters (in the parameter group) stored in the user terminal, whether it is the confidentiality parameters of the user terminal or the signature auxiliary device or system, are securely protected in the user terminal (such as fingerprint protection, PIN code protection, encryption protection, etc.).
[0026] A scheme with variable confidentiality parameters for the above-mentioned RSA digital signature collaborative generation method for hiding the private key secret is as follows:
[0027] The confidentiality parameters in the server confidentiality parameter group are encrypted by a homomorphic encryption algorithm and stored in the user terminal; the confidentiality parameters in the server confidentiality parameter group stored in the user terminal do not have to meet all the aforementioned characteristic requirements for the server confidentiality parameters (that is, only the confidentiality parameters in the server confidentiality parameter group do not have to meet the aforementioned characteristics, but the confidentiality parameters in the user confidentiality parameter group still need to meet the aforementioned characteristics, and the result v after the confidentiality parameters in the user confidentiality parameter group and the confidentiality parameters in the server confidentiality parameter group are added or multiplied still needs to meet the aforementioned characteristics);
[0028] When generating a digital signature for a message M, the user terminal randomly selects one or more (positive) integers as secrets, and uses the selected integers to modify the confidentiality parameters in the two sets of confidentiality parameters, wherein the modification of the confidentiality parameters in the server confidentiality parameter group is performed by homomorphic encryption (algorithm, operation) and homomorphic ciphertext operation; the plurality includes two or more; the modification includes modifying the value of the confidentiality parameter and changing the number of confidentiality parameters in the confidentiality parameter group; the two sets of confidentiality parameters after modification satisfy or have the aforementioned characteristics (note, each confidentiality parameter after modification is still a positive integer, which is a limitation on the modification); the above modification of the confidentiality parameters in the confidentiality parameter group is only valid for the current digital signature generation and calculation, and does not change the original confidentiality parameter group stored in the user terminal (that is, the next digital signature is still faced with the original, unmodified confidentiality parameter group);
[0029] Afterwards, the user terminal submits the modified copy of the server confidentiality parameter group to the signature assistance device or system, and the signature assistance device or system decrypts the confidentiality parameters in the encrypted copy of the confidentiality parameter group to obtain its plain text. Then, the user terminal and the signature assistance device or system use the modified user confidentiality parameter group and the copy of the server confidentiality parameter group to generate a digital signature for the message M according to the RSA digital signature collaborative generation method that hides the private key secret as described above.
[0030] Generally, the above-mentioned modifications will involve modifying the user-side confidentiality parameters and the server-side confidentiality parameter copy. The modification of the server-side confidentiality parameter copy during digital signature means that the signature auxiliary device or system obtains and uses different confidentiality parameters each time it performs digital signature calculation, which makes it more difficult for the signature auxiliary device or system to crack the signature private key or its secret, thereby improving the security of the scheme.
[0031] A scheme for dynamically generating a user-side confidentiality parameter group based on the above-mentioned RSA digital signature collaborative generation method for hiding the private key secret is as follows:
[0032] There is no user-side confidentiality parameter group in advance, and there is only a server-side confidentiality parameter group in advance; the server-side confidentiality parameter group is encrypted by using a homomorphic encryption algorithm and then stored in the user terminal; the server-side confidentiality parameter group stored in the user terminal does not have to meet all the aforementioned characteristic requirements for the server-side confidentiality parameters (the result obtained after the confidentiality parameters in the server-side confidentiality parameter group are added or multiplied still needs to meet the aforementioned characteristics, that is, the confidentiality parameters in the server-side confidentiality parameter group, or one or more addition or multiplication results v thereof still need to have v mod
[0033] When generating a digital signature for a message M, the user terminal randomly selects one or more (positive) integers as user-side confidentiality parameters, creates a temporary user-side confidentiality parameter group, and uses the randomly selected integers, i.e., the confidentiality parameters in the created temporary user-side confidentiality parameter group, to modify the confidentiality parameters (copy) in the server-side confidentiality parameter group copy, wherein the modification of the confidentiality parameters (copy) in the server-side confidentiality parameter group copy is performed through homomorphic encryption (algorithm, operation) and homomorphic ciphertext operation; the plurality includes two or more; the modification includes modifying the value and confidentiality parameters of the confidentiality parameters (copy) in the server-side confidentiality parameter group copy The number of; the temporary user-side confidentiality parameter group created and the modified server-side confidentiality parameter group copy meet or have the aforementioned characteristics (Note: each confidentiality parameter copy after modification is still a positive integer, which is a modification limitation); the generation of the temporary user-side confidentiality parameter group and the modification of the confidentiality parameters (copy) in the server-side confidentiality parameter group copy described above are only valid for the current digital signature generation and calculation, and do not change the original server-side confidentiality parameter group stored in the user terminal (that is, the next digital signature is still faced with the unmodified, original confidentiality parameter group), that is, the modification is for the confidentiality parameters in the server-side confidentiality parameter group copy;
[0034] Afterwards, the user terminal submits the modified copy of the server confidentiality parameter group to the signature assistance device or system, and the signature assistance device or system decrypts the confidentiality parameters (copy) in the encrypted confidentiality parameter group copy to obtain its plain text. Then, the user terminal and the signature assistance device or system use the generated temporary user confidentiality parameter group and the modified copy of the server confidentiality parameter to generate a digital signature for the message M according to the RSA digital signature collaborative generation method that hides the private key secret as described above.
[0035] For the above-mentioned schemes in which the confidentiality parameters are variable and the scheme in which the confidentiality parameter group of the user terminal is dynamically generated, the user terminal randomly selects an integer in the following manner:
[0036] The user terminal randomly selects an integer in [1,w], where w is calculated using n and satisfies integer, and the choice of w does not depend on The value of .
[0037] For the above-mentioned method of randomly selecting an integer by the user terminal, the value of w includes:
[0038] Select an integer m, m ≥ 2, limit p ≥ 2m, q ≥ 2m, and take in Indicates rounding down (usually the value of m does not exceed 10);
[0039] Or, limit p≥3, q≥3, and take Where sqrt(n) is the square root of n.
[0040] If the hash values h and n of the message M are relatively prime, or the probability that the hash values h and n of the message M are not relatively prime is acceptable, then the value of w is allowed to be n, and the modified server confidentiality parameter copy is allowed to be a negative integer;
[0041] If h and n are not coprime and the exponent in the modulo-n exponentiation operation of h is negative, or the exponent in the modulo-n exponentiation operation of h is 0 during the process of generating the digital signature of M, then error handling is entered; the error handling includes: modifying the padding data of h so that h and n are coprime, or reselecting the randomly selected integer when modifying the server-side confidentiality parameter copy, or changing the modification of subtracting a randomly selected integer from the server-side confidentiality parameter copy to adding another randomly selected integer to the server-side confidentiality parameter copy, and then subtracting the same integer from the user-side confidentiality parameter copy, while ensuring that the modification of subtracting the same integer from the user-side confidentiality parameter copy will not result in negative numbers and 0.
[0042] How the signature assistance device or system, or the system that calls the signature assistance device or system, confirms that the user is the owner of the modulus n or the public key (e, n) does not belong to the content of the present invention. In specific implementation, the following methods can be adopted: the signature assistance device or system, or the system that calls the signature assistance device or system (such as an application service system), manages and maintains a user account, and the user account stores the modulus n or the public key (e, n) of the user's RSA key pair, or the user's account is bound to the user's digital certificate, and the user's digital certificate contains the user's public key (e, n).
[0043] Based on the above RSA digital signature collaborative generation method for hiding the private key secret, a security enhancement solution to prevent the confidentiality parameter group stored in the user terminal from being stolen is as follows:
[0044] When a user (using a program in a user terminal or other terminal) accesses an application service system and needs to use the user's RSA signature private key to digitally sign a message M, the application service system issues a security token to the user; the security token is an authorization certificate for requesting a signature auxiliary device or system to assist, collaboratively generate or / and calculate a digital signature (the security token indicates to the digital signature collaborative generation service system, i.e., the signature auxiliary device or system, that this digital signature collaborative generation request is authorized and guaranteed by the application service system; the security token does not have to contain the user's identity information, but from a security perspective, the user's identity information and public key information must contain at least one);
[0045] The application service system (e.g., through a client program or other means) transmits the security token or the acquisition information of the security token to the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function in the user terminal; the acquisition information of the security token is information used to obtain the security token issued by the application service system (the security token is stored online at this time);
[0046] The user terminal (the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function) submits the security token or the acquisition information of the security token to the signature auxiliary device or system;
[0047] If the information submitted to the signature auxiliary device or system is the acquisition information of the security token, the signature auxiliary device or system uses the acquisition information to obtain the security token issued by the application service system;
[0048] The signature auxiliary device or system verifies the validity of the security token (such as verifying the validity of the asymmetric key or symmetric key digital signature of the security token, and the time validity, where the key digital signature is called HMAC). After that, the user terminal (the cryptographic program or cryptographic module or cryptographic component that implements the RSA digital signature function) and the signature auxiliary device or system use the confidentiality parameters in the confidentiality parameter group to generate a digital signature for the message M according to the RSA digital signature collaborative generation method that hides the private key secret as described above.
[0049] The manner in which the application service system transmits the security token or the acquisition information of the security token to the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function in the user terminal includes:
[0050] If the client program used by the user to access the application service system and the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function are located in the same user terminal, the application service system transmits the security token or the acquisition information of the security token to the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function in the user terminal through the client program;
[0051] Alternatively, if the client program used by the user to access the application service system and the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function are located in different user terminals, the application service system displays a barcode (two-dimensional code, multi-dimensional code) through the client program used by the user, and then transmits the security token or the acquisition information of the security token to the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function in the user terminal by the user scanning the barcode with the user terminal;
[0052] Alternatively, if the user terminal is a mobile communication terminal (such as a mobile phone), the application service system sends a text message through the user's mobile communication terminal, starts the cryptographic program that implements the RSA digital signature function in the user's mobile communication terminal through the information contained in the text message (such as URL Schema), and passes the security token or the acquisition information of the security token to the cryptographic program that implements the RSA digital signature function in the user's mobile communication terminal automatically through the startup information or through the information input by the user in the text message.
[0053] Based on the above-mentioned RSA digital signature collaborative generation method that hides the private key secret, a security enhancement solution to prevent the security token from being stolen is as follows:
[0054] When the application service system issues a security token to a user (terminal), it randomly selects an integer c in [1, n-1] as a perturbation parameter, or randomly selects an integer c that is relatively prime to n in [1, n-1] as a perturbation parameter, and then encrypts c into ciphertext data that can only be decrypted by the signature auxiliary device or system (for example, it is encrypted with the public key of the signature auxiliary device or system, or the application service system and the signature auxiliary device or system share a secret, thereby secretly deriving the encryption key and the decryption key), and then transmits the ciphertext data of c together with the security token to the signature auxiliary device or system through the user terminal, and the plaintext or ciphertext data of c is protected by the security token (for example, the hash value of c or the hash value of the ciphertext data of c is part of the security token, or the ciphertext data of c is part of the security token);
[0055] After verifying the validity of the received security token, the signature auxiliary device or system decrypts the ciphertext of the perturbation parameter c to obtain the plaintext of c, and at the same time determines the validity of the plaintext or ciphertext of c through the security token;
[0056] After completing the generation of the digital signature s for the message M, the signature auxiliary device or system uses c to calculate the disturbed digital signature s c =(s+c)mod n, or, c is an integer randomly selected from [1,n-1] that is relatively prime to n, and c is used to calculate the perturbed digital signature s c =(s*c)mod n, where * is the multiplication operator;
[0057] s c It is not submitted or returned to the application service system through the user terminal;
[0058] The application service system calculates s = (s c -c)mod n or s = (c -1 s c ) mod n, where c -1 is the modulo n multiplicative inverse of c (i.e. (c -1 c) mod n = 1), restore the digital signature s.
[0059] For the above-mentioned RSA digital signature collaborative generation method for hiding the private key secret, the generation and distribution methods of the user's RSA signature key pair and confidentiality parameter group include:
[0060] Method 1:
[0061] The key generation device or system generates an RSA signature key pair, generates a confidentiality parameter group for the user terminal and the signature auxiliary device or system, and then transmits the generated confidentiality parameter group to the user terminal and the signature auxiliary device or system for storage; if the confidentiality parameter group for the signature auxiliary device or system needs to be stored in the user terminal, the key generation device or system encrypts the confidentiality parameters in the confidentiality parameter group for the signature auxiliary device or system and transmits the encrypted confidentiality parameters to the user terminal for storage;
[0062] Method 2:
[0063] The trusted program in the user terminal generates an RSA signature key pair, generates a confidentiality parameter group for the user terminal and the signature auxiliary device or system, and stores the confidentiality parameter group for the user terminal locally in the user terminal; if the confidentiality parameter group for the signature auxiliary device or system needs to be transmitted to the signature auxiliary device or system for storage, the trusted program in the user terminal transmits the confidentiality parameter group for the signature auxiliary device or system to the signature auxiliary device or system for storage; if the confidentiality parameter group for the signature auxiliary device or system is to be stored locally in the user terminal, the trusted program in the user terminal encrypts the confidentiality parameters in the confidentiality parameter group for the signature auxiliary device or system and stores them locally in the user terminal; the trusted program is a program (that has undergone security testing and evaluation) provided by a cryptographic program or cryptographic module developer, or a cryptographic service provider;
[0064] Method 3:
[0065] A trusted program in another terminal (such as a script program in a browser) generates an RSA signature key pair, generates a confidentiality parameter group for the user terminal and the signature auxiliary device or system, and then transmits the confidentiality parameter group for the user terminal to the user terminal for storage by scanning a code or other secure transmission methods (such as file copying, email); if the confidentiality parameter group for the signature auxiliary device or system needs to be transmitted to the signature auxiliary device or system for storage, the trusted program transmits the confidentiality parameter group for the signature auxiliary device or system to the signature auxiliary device or system for storage; if the confidentiality parameter group for the signature auxiliary device or system is to be stored in the user terminal, the trusted program encrypts the confidentiality parameter group for the signature auxiliary device or system, and transmits it to the user terminal for storage by scanning a code or other secure transmission methods (such as file copying, email).
[0066] On the basis of the above RSA digital signature collaborative generation method that hides the private key secret, a corresponding RSA digital signature collaborative generation system that hides the private key secret can be constructed, the system includes a signature auxiliary device or system, a cryptographic program or cryptographic module or cryptographic component in a user terminal; a user terminal confidentiality parameter group for the user's RSA signature private key is stored in the user terminal; the signature auxiliary device or system stores a server confidentiality parameter group for the user's RSA signature private key, or the confidentiality parameters in the server confidentiality parameter group are encrypted and stored in the user terminal; when the user's RSA signature private key needs to be used to digitally sign a message M, the cryptographic program or cryptographic module or cryptographic component in the user terminal, and the signature auxiliary device or system, according to the above RSA digital signature collaborative generation method that hides the private key secret, collaboratively generate a digital signature for the message M, wherein the cryptographic program or cryptographic module or cryptographic component in the user terminal implements the function of the user terminal in the above digital signature generation method. Further, the system may also include a key generation device or system and a trusted program for generating RSA signature key pairs.
[0067] From the above description, it can be seen that based on the solution of the present invention, the secret d of the user's RSA signature private key or the secret share of the secret d is hidden in the confidentiality parameters of the user end and the server end, and the signature auxiliary device or system does not and cannot obtain the secret d of the user's RSA signature private key and the secret share of the secret d from the server end confidentiality parameters, which makes it difficult for the signature auxiliary device or system to crack the user's RSA signature private key (secret share), and for the solution of the present invention with variable confidentiality parameters and the solution of dynamic generation of confidentiality parameters on the user end, the signature auxiliary device or system obtains different confidentiality parameters each time, which further improves the security of the private key and the secret use of the private key; in the present invention, In the scheme, the secret d of the signature private key is completely hidden in the implementation situation of the user terminal, and the digital signature (electronic signature) production data is completely proprietary and controlled by the user, which is in good compliance with the "Electronic Signature Law of the People's Republic of China"; further, the security enhancement scheme of the present invention that prevents the theft of user-side confidential parameters through security tokens provides further security protection for the use of signature production data, and can effectively prevent the theft of signature production data; it should be pointed out that the signature auxiliary device or system in the scheme of the present invention is usually a trusted device or system, and it is not necessary to regard it as an adversary who tries every means to crack the user's signature private key. On the contrary, its role is to protect the security of the user's signature private key. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] Figure 1 It is a basic structure and application diagram of the system of the present invention. DETAILED DESCRIPTION
[0069] The following is a description of the specific implementation of the present invention. The following content is only a description of possible implementations of the present invention and is not intended to limit the scope of protection of the present invention.
[0070] The key to the implementation of the present invention is the implementation method of the confidentiality parameter group of the user terminal and the signature auxiliary device or system, that is, the selection of confidentiality parameters in the confidentiality parameter group that meets the characteristic requirements described above, and how to use the confidentiality parameter group for collaborative calculation of digital signatures.
[0071] The following are some implementation methods of confidentiality parameter group selection and interactive collaborative computing for the basic solution (the method when the confidentiality parameter group parameters do not change and are not dynamically created).
[0072] Basic solution embodiment 1,
[0073] Select during initialization The integer secrets d1 and d2 in the
[0074] The user terminal security parameter group has the security parameters: u1 = d1 or
[0075] The server confidentiality parameter group has confidentiality parameters:
[0076] Then there is And in In the unknown case, the signature auxiliary device or system cannot obtain d2 from t1 (t1 contains two unknown factors);
[0077] When a digital signature is generated for a message M, corresponding to the calculation v=u1+t1, the user terminal and the signature auxiliary device or system use their respective confidentiality parameters to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameters, that is:
[0078] The user terminal calculates s1 = (h^u1) mod n, the signature auxiliary device or system calculates s2 = (h^t1) mod n, and the user terminal or the signature auxiliary device or system calculates:
[0079] s=(s1s2)mod n=(h^(u1+t1))mod n=(h^d)mod n, then s is the digital signature for message M.
[0080] Basic solution embodiment 2,
[0081] Select during initialization Integer and The secrets d1 and d2 are mutually prime, so that
[0082] The user terminal security parameter group has the security parameters: u1 = d1 or
[0083] The server confidentiality parameter group has confidentiality parameters:
[0084] Then there is And in In the unknown case, the signature auxiliary device or system cannot obtain d2 from t1 (t1 contains two unknown factors);
[0085] When a digital signature is generated for a message M, corresponding to the calculation v=u1t1, the user terminal and the signature auxiliary device or system use their respective confidentiality parameters to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameters, that is:
[0086] The user terminal calculates s1=(h^u1)mod n and submits s1 to the signature assistance device or system. The signature assistance device or system calculates s=(s1^t1)mod n=(h^(u1t1))mod n=(h^d)mod n. Alternatively, the signature assistance device or system calculates s2=(h^t1)mod n and submits s2 to the user terminal. The user terminal calculates s=(s2^u1)mod n=(h^(u1t1))mod n=(h^d)mod n, then s is the digital signature for message M.
[0087] Basic solution embodiment 3,
[0088] Initialization (random) selection or The inner secret integers b1 and b2 are such that
[0089] The user terminal security parameter group has security parameters: u1 = b1 or
[0090] The server confidentiality parameter group has confidentiality parameters:
[0091] t1=d+b2 or or or
[0092] Then there is And in In the unknown case, the signature auxiliary device or system cannot obtain d from t1 (t1 contains two unknown factors);
[0093] When a digital signature is generated for a message M, corresponding to the calculation v=u1+t1, the user terminal and the signature auxiliary device or system use their respective confidentiality parameters to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameters, that is:
[0094] The user terminal calculates s1 = (h^u1) mod n, the signature auxiliary device or system calculates s2 = (h^t1) mod n, and the user terminal or the signature auxiliary device or system calculates:
[0095] s=(s1s2)mod n=(h^(u1+t1))mod n=(h^d)mod n, then s is the digital signature for message M.
[0096] Basic solution embodiment 4,
[0097] Initialization (random) selection or The inner integer secrets b1 and b2 are such that
[0098] The user terminal parameter group has confidential parameters:
[0099] or or
[0100] The server confidentiality parameter group has confidentiality parameters: Or t1 = b2;
[0101] Then there is And in In the unknown case, the signature auxiliary device or system cannot obtain d from t1 (t1 is independent of the private key secret d and the secret share of d);
[0102] When a digital signature is generated for a message M, corresponding to the calculation v=u1+t1, the user terminal and the signature auxiliary device or system use their respective confidentiality parameters to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameters, that is:
[0103] The user terminal calculates s1 = (h^u1) mod n, the signature auxiliary device or system calculates s2 = (h^t1) mod n, and the user terminal or the signature auxiliary device or system calculates:
[0104] s=(s1s2)mod n=(h^(u1+t1))mod n=(h^d)mod n, then s is the digital signature for message M.
[0105] Basic solution embodiment 5,
[0106] Initialization (random) selection or Internal The integer secrets b1 and b2 are mutually prime, and such that
[0107] The user terminal security parameter group has security parameters: u1 = b1 or
[0108] The server confidentiality parameter group has confidentiality parameters:
[0109] Then there is And in In the unknown case, the signature auxiliary device or system cannot obtain d from t1 (t1 contains three unknown factors);
[0110] When a digital signature is generated for a message M, corresponding to the calculation v=u1t1, the user terminal and the signature auxiliary device or system use their respective confidentiality parameters to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameters, that is:
[0111] The user terminal calculates s1=(h^u1)mod n and submits s1 to the signature assistance device or system. The signature assistance device or system calculates s=(s1^t1)mod n=(h^(u1t1))mod n=(h^d)mod n. Alternatively, the signature assistance device or system calculates s2=(h^t1)mod n and submits s2 to the user terminal. The user terminal calculates s=(s2^u1)mod n=(h^(u1t1))mod n=(h^d)mod n, then s is the digital signature for message M.
[0112] Basic scheme embodiment 6,
[0113] Initialization (random) selection or Internal The integer secrets b1 and b2 are mutually prime, and such that
[0114] The user-side confidentiality parameter group has confidentiality parameters: or
[0115] The server confidentiality parameter group has confidentiality parameters: Or t1 = b2;
[0116] Then there is And in In the unknown case, the signature auxiliary device or system cannot obtain d from t1 (t1 is independent of the private key secret d and the secret share of d);
[0117] When a digital signature is generated for a message M, corresponding to the calculation v=u1t1, the user terminal and the signature auxiliary device or system use their respective confidentiality parameters to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameters, that is:
[0118] The user terminal calculates s1=(h^u1)mod n and submits s1 to the signature assistance device or system. The signature assistance device or system calculates s=(s1^t1)mod n=(h^(u1t1))mod n=(h^d)mod n. Alternatively, the signature assistance device or system calculates s2=(h^t1)mod n and submits s2 to the user terminal. The user terminal calculates s=(s2^u1)mod n=(h^(u1t1))mod n=(h^d)mod n, then s is the digital signature for message M.
[0119] Basic solution embodiment 7,
[0120] Initialization (random) selection or Internal The integer secrets b1 and b2 are mutually prime, and such that
[0121] Initialization (random) selection or Inner integer secrets a1, a2, and such that
[0122] The user terminal security parameter group has security parameters: u1 = b1 or u2=a1or
[0123] The server confidentiality parameter group has confidentiality parameters:
[0124] or or
[0125] Then there is And in In the unknown case, the signature auxiliary device or system cannot obtain d from t1 (t1 contains four unknown factors, including
[0126] When a digital signature is generated for a message M, corresponding to the calculation v=((t1+u2)u1), the user terminal and the signature auxiliary device or system use their respective confidentiality parameters to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponential part of h corresponds to the operation used to calculate v using the confidentiality parameters, that is:
[0127] The signature auxiliary device or system calculates s2 = (h^t1) mod n and submits s2 to the user terminal;
[0128] The user terminal calculates s = (((s2(h^u2))mod n)^u1)mod n = (h^((t1+u2)u1))mod n = (h^d)mod n, then s is the digital signature for message M.
[0129] Basic scheme embodiment 8,
[0130] Initialization (random) selection In or and The integer secrets b1 and b2 are mutually prime, and such that (Random) Selection or Inner integer secrets a1, a2, and such that
[0131] The user-side confidentiality parameter group has confidentiality parameters:
[0132] or
[0133] The server confidentiality parameter group has confidentiality parameters: Or t1 = b2, Or t2 = a2;
[0134] Then there is And in In the unknown case, the signature auxiliary device or system cannot obtain d from t1 and t2 (t1 and t2 are irrelevant to the private key secret d and the secret share of d);
[0135] When a digital signature is generated for a message M, corresponding to the calculation v=((u1+t2)t1), the user terminal and the signature auxiliary device or system use their respective confidentiality parameters to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameters, that is:
[0136] The user terminal calculates s1 = (h^u1) mod n and submits s1 to the signature auxiliary device or system;
[0137] The signature auxiliary device or system calculates s = (((s1(h^t2))mod n)^t1)mod n = (h^((u1+t2)t1))mod n = (h^d)mod n, then s is the digital signature for message M.
[0138] Basic solution embodiment 9,
[0139] Initialization (random) selection or Internal The integer secrets b1 and b2 are mutually prime, and such that (Random) Selection or Inner integer secrets a1, a2, and such that
[0140] The user terminal security parameter group has security parameters: u1 = b1 or u2=a1or
[0141] The server confidentiality parameter group has confidentiality parameters:
[0142] or
[0143] Then there is And in In the unknown case, the signature auxiliary device or system cannot obtain d from t1 (t1 contains four unknown factors, including
[0144] When a digital signature is generated for a message M, corresponding to the calculation v=(t1u1+u2), the user terminal and the signature auxiliary device or system use their respective confidentiality parameters to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameters, that is:
[0145] The signature auxiliary device or system calculates s2 = (h^t1) mod n and submits s2 to the user terminal;
[0146] The user terminal calculates s = (((s2^u1) mod n)(h^u2)) mod n = (h^(t1u1+u2)) mod n = (h^d) mod n, then s is the digital signature for message M.
[0147] Basic scheme embodiment 10,
[0148] Initialization (random) selection or Internal The integer secrets b1 and b2 are mutually prime, and such that (Random) Selection or Inner integer secrets a1, a2, and such that
[0149] The user-side confidentiality parameter group has confidentiality parameters:
[0150] or
[0151] The server confidentiality parameter group has confidentiality parameters:
[0152] Then there is And in In the unknown case, the signature auxiliary device or system cannot obtain d from t1 (there is no relationship between t1 and d);
[0153] When a digital signature is generated for a message M, corresponding to the calculation v=(u1t1+t2), the user terminal and the signature auxiliary device or system use their respective confidentiality parameters to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameters, that is:
[0154] The user terminal calculates s1 = (h^u1) mod n and submits s1 to the signature auxiliary device or system;
[0155] The signature auxiliary device or system calculates s = (((s1^t1)mod n)(h^t2))mod n = (h^(u1t1+t2))modn = (h^d)mod n, then s is the digital signature for message M.
[0156] The above embodiments are only some possible implementation methods for the basic scheme of the present invention and do not represent all of them.
[0157] There are many ways to implement the variable confidentiality parameter solution of the present invention. The following are the applicable implementation principles.
[0158] If there is a confidentiality parameter in the user terminal confidentiality parameter group with In the form of, g is a secret integer (a confidentiality parameter or a number calculated from the confidentiality parameter). When a message M needs to be digitally signed using the user's RSA signature private key, the user terminal randomly selects an integer b in [1,w], where w is an integer calculated using n and satisfies integer, and the choice of w does not depend on , and then modify the copy of u to Then modify the server confidentiality parameter copy. For example, if a server confidentiality parameter is calculated When adding u, b is added to the server confidentiality parameter (copy), then the user terminal and the signature auxiliary device or system use the modified user confidentiality parameter group and the server confidentiality parameter group copy to collaboratively generate a digital signature for the message M according to the method of the present invention. The following is an explanation through several embodiments.
[0159] Confidentiality parameter variable embodiment 1,
[0160] This embodiment is based on the basic solution embodiment 1, and dynamically modifies the confidentiality parameters of the user end and the server end when the message M is digitally signed.
[0161] Initialization (random) selection or The inner integer secrets d1 and d2 are such that
[0162] The user-side confidentiality parameter group has confidentiality parameters:
[0163] The server confidentiality parameter group has confidentiality parameters:
[0164] The server-side confidentiality parameters are stored in the user terminal after addition or full homomorphic encryption;
[0165] When generating a digital signature for a message M, the user terminal randomly selects an integer b in [1,w] and then updates the copy of u1 with u1-b, that is, the copy of u1 is modified to Through homomorphic encryption The copy of Then there is Corresponding to the calculation v=u1+t1, the user terminal and the signature auxiliary device or system each use the modified copy of the confidentiality parameter to perform a collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0166] The user terminal calculates s1=(h^u1)mod n, and the signature auxiliary device or system calculates s2=(h^t1)mod n; the user terminal or the signature auxiliary device or system calculates s=(s1s2)mod n, then s is the digital signature for message M.
[0167] Confidentiality parameter variable embodiment 2,
[0168] This embodiment is based on the basic solution embodiment 3, and dynamically modifies the confidentiality parameters of the user end and the server end when the message M is digitally signed.
[0169] Initialization (random) selection or The inner secret integers b1 and b2 are such that
[0170] The user-side confidentiality parameter group has confidentiality parameters:
[0171] The server confidentiality parameter group has confidentiality parameters:
[0172] t1=d+b2 or or or
[0173] The server-side confidentiality parameters are stored in the user terminal after addition or full homomorphic encryption;
[0174] When generating a digital signature for a message M, the user terminal randomly selects an integer b in [1,w] and then updates the copy of u1 with u1-b, that is, the copy of u1 is modified to Modify the copy of t1 to t1 = d + b2 + b or or or Then there is Corresponding to the calculation v=u1+t1, the user terminal and the signature auxiliary device or system each use the modified copy of the confidentiality parameter to perform a collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0175] The user terminal calculates s1 = (h^u1) mod n, and the signature auxiliary device or system calculates s2 = (h^t1) mod n. The user terminal or the signature auxiliary device or system calculates:
[0176] s=(s1s2)mod n=(h^(u1+t1))mod n=(h^d)mod n, then s is the digital signature for message M.
[0177] For basic scheme embodiment 4, if or Then a completely similar implementation can be performed based on basic scheme embodiment 4.
[0178] Confidentiality parameter variable embodiment 3,
[0179] This embodiment is based on the basic solution embodiment 7, and dynamically modifies the confidentiality parameters of the user end and the server end when the message M is digitally signed.
[0180] Initialization (random) selection or Internal The integer secrets b1 and b2 are mutually prime, and such that (Random) Selection or Inner integer secrets a1, a2, and such that
[0181] The user terminal security parameter group has security parameters: u1 = b1 or
[0182] The server confidentiality parameter group has confidentiality parameters:
[0183] or
[0184] The server-side confidentiality parameters are stored in the user terminal after addition or full homomorphic encryption;
[0185] When generating a digital signature for a message M, the user terminal randomly selects an integer b in [1,w] and then updates the copy of u2 with u2-b, that is, the copy of u2 is modified to Modify the t1 copy to or
[0186] Then there is Corresponding to the calculation v=((t1+u2)u1), the user terminal and the signature auxiliary device or system each use the modified copy of the confidentiality parameter to perform a collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0187] The signature auxiliary device or system calculates s2 = (h^t1) mod n and submits s2 to the user terminal;
[0188] The user terminal calculates s = (((s2(h^u2))mod n)^u1)mod n = (h^((t1+u2)u1))mod n = (h^d)mod n, then s is the digital signature for message M.
[0189] For basic scheme embodiment 8, if A completely similar implementation can be performed based on the basic scheme embodiment 8 (using b selected from [1, w] to calculate u1-b, and using u1-b to update the copy of u1).
[0190] If there is a confidentiality parameter in the server confidentiality parameter group with In the form of, g is a secret integer (a confidentiality parameter or a number calculated from the confidentiality parameter). When a message M needs to be digitally signed using the user's RSA signature private key, the user terminal randomly selects an integer b in [1,w], and then modifies the copy of t into b is used as a newly generated confidentiality parameter in the user terminal confidentiality parameter group, or if a certain user terminal confidentiality parameter is calculated When b is added to t, b is added to the user terminal confidentiality parameter (copy). Then, the user terminal and the signature auxiliary device or system use the modified user terminal confidentiality parameter group and the server confidentiality parameter group copy to collaboratively generate a digital signature for the message M according to the method of the present invention. This is described below through several embodiments.
[0191] Confidentiality parameter variable embodiment 4,
[0192] This embodiment is based on the basic solution embodiment 1, and dynamically modifies the confidentiality parameters of the user end and the server end when the message M is digitally signed.
[0193] Initialization (random) selection or The inner integer secrets d1 and d2 are such that
[0194] The user terminal security parameter group has the security parameters: u1 = d1 or
[0195] The server confidentiality parameter group has confidentiality parameters:
[0196] The server-side confidentiality parameters are stored in the user terminal after addition or full homomorphic encryption;
[0197] When generating a digital signature for a message M, the user terminal randomly selects an integer b in [1, w] and updates the copy of u1 with u1+b, that is, the copy of u1 is modified to u1=d1+b or Through homomorphic encryption The copy is modified to Then there is Corresponding to the calculation v=u1+t1, the user terminal and the signature auxiliary device or system each use the modified copy of the confidentiality parameter to perform a collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0198] The user terminal calculates s1=(h^u1)mod n, and the signature auxiliary device or system calculates s2=(h^t1)mod n; the user terminal or the signature auxiliary device or system calculates s=(s1s2)mod n, then s is the digital signature for message M.
[0199] For basic scheme embodiment 3, if or Then a completely similar implementation can be performed based on the basic scheme embodiment 3 (using b randomly selected from [1, w] to modify and update the copies of u1 and t1).
[0200] Confidentiality parameter variable embodiment 5,
[0201] This embodiment is based on the basic solution embodiment 2, and dynamically modifies the confidentiality parameters of the user end and the server end when the message M is digitally signed.
[0202] Initialization (random) selection or Integer and The secrets d1 and d2 are mutually prime, and such that
[0203] The user terminal security parameter group has the security parameters: u1 = d1 or
[0204] The server confidentiality parameter group has confidentiality parameters:
[0205] The server-side confidentiality parameters are stored in the user terminal after addition or full homomorphic encryption;
[0206] When generating a digital signature for a message M, the user terminal randomly selects an integer b in [1, w], and then uses u2 = b to generate a new user-side confidentiality parameter, and then uses homomorphic encryption to encrypt the message M. The copy of Then there is Corresponding to the calculation v=u1(t1+u2), the user terminal and the signature auxiliary device or system each use the modified copy of the confidentiality parameter to perform a collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0207] The signature auxiliary device or system calculates s2=(h^t1)mod n and submits s2 to the user terminal. The user terminal calculates s1=(h^u2)mod n, s=(((s1s2)mod n)^u1)mod n, then s is the digital signature for message M.
[0208] For basic scheme embodiment 5, if For basic scheme embodiment 6, if Then a completely similar implementation can be performed on the basis of the basic scheme embodiment 5 (using b randomly selected from [1, w] to generate a new user-side parameter u2, and modify and update the copy of t1).
[0209] Confidentiality parameter variable embodiment 6,
[0210] This embodiment is based on the basic solution embodiment 7, and dynamically modifies the confidentiality parameters of the user end and the server end when the message M is digitally signed.
[0211] Initialization (random) selection or Internal The integer secrets b1 and b2 are mutually prime, and such that (Random) Selection or Inner integer secrets a1, a2, and such that
[0212] The user terminal security parameter group has security parameters: u1 = b1 or u2=a1or
[0213] The server confidentiality parameter group has confidentiality parameters:
[0214] The server-side confidentiality parameters are stored in the user terminal after addition or full homomorphic encryption;
[0215] When generating a digital signature for a message M, the user terminal randomly selects an integer b in [1,w] and then uses homomorphic encryption to The copy is modified to:
[0216]
[0217] Update the copy of u2 with u2+b, that is, modify the copy of u2 to u2=a1+b or Then there is Corresponding to the calculation v=((t1+u2)u1), the user terminal and the signature auxiliary device or system each use the modified copy of the confidentiality parameter to perform a collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0218] The signature auxiliary device or system calculates s2 = (h^t1) mod n and submits s2 to the user terminal;
[0219] The user terminal calculates s = (((s2(h^u2))mod n)^u1)mod n = (h^((t1+u2)u1))mod n = (h^d)mod n, then s is the digital signature for message M.
[0220] Confidentiality parameter variable embodiment 7,
[0221] This embodiment is based on the basic solution embodiment 8, and dynamically modifies the confidentiality parameters of the user end and the server end when the message M is digitally signed.
[0222] Initialization (random) selection or Internal The integer secrets b1 and b2 are mutually prime, and such that (Random) Selection or Inner integer secrets a1, a2, and such that
[0223] The user-side confidentiality parameter group has confidentiality parameters:
[0224] or
[0225] The server confidentiality parameter group has confidentiality parameters:
[0226] The server-side confidentiality parameters are stored in the user terminal after addition or full homomorphic encryption;
[0227] When generating a digital signature for a message M, the user terminal randomly selects an integer b in [1,w] and then uses homomorphic encryption to The copy of Update the copy of u1 with u1+b, that is, modify the copy of u1 to or Then there is Corresponding to the calculation v=((u1+t2)t1), the user terminal and the signature auxiliary device or system each use the modified copy of the confidentiality parameter to perform a collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0228] The user terminal calculates s1 = (h^u1) mod n and submits s1 to the signature auxiliary device or system;
[0229] The signature auxiliary device or system calculates s = (((s1(h^t2))mod n)^t1)mod n = (h^((u1+t2)t1))mod n = (h^d)mod n, then s is the digital signature for message M.
[0230] Confidentiality parameter variable embodiment 8,
[0231] This embodiment is based on the basic solution embodiment 9, and dynamically modifies the confidentiality parameters of the user end and the server end when the message M is digitally signed.
[0232] Initialization (random) selection or Internal The integer secrets b1 and b2 are mutually prime, and such that (Random) Selection or Inner integer secrets a1, a2, and such that
[0233] The user terminal security parameter group has security parameters: u1 = b1 or u2=a1or
[0234] The server confidentiality parameter group has confidentiality parameters:
[0235] The server-side confidentiality parameters are stored in the user terminal after addition or full homomorphic encryption;
[0236] When generating a digital signature for a message M, the user terminal randomly selects an integer b in [1,w] and then modifies the copy of t1 to Taking u3=b as the new confidentiality parameter in the copy of the user terminal confidentiality parameter group, we have
[0237] Corresponding to the calculation v=((t1+u3)u1+u2), the user terminal and the signature auxiliary device or system each use the modified copy of the confidentiality parameter to perform a collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0238] The signature auxiliary device or system calculates s2 = (h^t1) mod n and submits s2 to the user terminal;
[0239] The user terminal calculates s1=(s2((h^u3)mod n))mod n, s=(((s1^u1)mod n)(h^u2))mod n, then s is the digital signature for message M.
[0240] The above are just a few examples of implementing variable schemes of confidentiality parameter groups, and do not represent all possible implementation methods.
[0241] There are many implementation methods for implementing the solution of dynamically generating user-side parameters of the present invention. The following is an applicable implementation principle.
[0242] If there is a confidentiality parameter in the server confidentiality parameter group with In the form of , g is a secret integer (a confidentiality parameter or a number calculated from the confidentiality parameter). When a message M needs to be digitally signed using the user's RSA signature private key, the user terminal randomly selects an integer b in [1, w] and then modifies the copy of t into b is used as a confidentiality parameter in the newly generated user-side confidentiality parameter group, and then the user terminal and the signature auxiliary device or system use the newly generated user-side confidentiality parameter group and the modified copy of the server-side confidentiality parameter group to collaboratively generate a digital signature for the message M according to the method of the present invention. This is described below through several embodiments.
[0243] User terminal confidentiality parameter dynamic generation embodiment 1,
[0244] The server has a confidentiality parameter group and confidentiality parameters in advance. t1 is saved in the user terminal after addition or full homomorphic encryption.
[0245] When the user's RSA signature private key is needed to digitally sign the message M, the user terminal randomly selects an integer b in [1, w], w is the same as before, and modifies the copy of t1 to With b as the confidentiality parameter u1=b in the newly generated temporary user-side parameter group, the modified server-side confidentiality parameter copy and the generated temporary user-side confidentiality parameter are Corresponding to the calculation v=(u1+t1), the user terminal and the signature auxiliary device or system each use the newly generated temporary confidentiality parameter and the modified confidentiality parameter copy to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponential part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0246] The user terminal calculates s1=(h^u1)mod n; the signature auxiliary device or system calculates s2=(h^t1)mod n; the user terminal or the signature auxiliary device or system calculates s=(s1s2)mod n, then s is the digital signature for message M.
[0247] User terminal security parameter dynamic generation embodiment 2,
[0248] The server has a confidentiality parameter group in advance, with confidentiality parameter t1 = (b1d) mod n or t1 and t2 are stored in the user terminal after addition or full homomorphic encryption, where b1 and b2 are or An integer selected (randomly) from within that satisfies the relation (b1b2) mod = 1;
[0249] When the user's RSA signature private key is needed to digitally sign the message M, the user terminal randomly selects an integer a in [1, w], where w is the same as before; the copy of t2 is modified to Taking u1=a as the confidentiality parameter in the newly generated temporary user-side parameter group, the modified server-side confidentiality parameter copy and the generated temporary user-side confidentiality parameter are: Corresponding to the calculation v=t1(u1+t2), the user terminal and the signature auxiliary device or system each use the newly generated temporary confidentiality parameter and the modified confidentiality parameter copy to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0250] User terminal calculations 11 =(h^u1)mod n; the signature auxiliary device or system calculates s 12 =(h^t2)mod n; the user terminal or the signature auxiliary device or system calculates s1=(s 11 s 12 )mod n; the signature auxiliary device or system calculates s=(s1^t1)mod n, then s is the digital signature for the message M.
[0251] User terminal security parameter dynamic generation embodiment 3,
[0252] The server has a confidentiality parameter group and confidentiality parameters in advance. t2=b2 or t1 and t2 are stored in the user terminal after addition or full homomorphic encryption, where b1 and b2 are or An integer randomly selected from the inner part that satisfies the relationship (b1b2) mod = 1;
[0253] When the user's RSA signature private key is needed to digitally sign the message M, the user terminal randomly selects an integer a in [1, w], where w is the same as before; the copy of t1 is modified to Taking u1=a as the confidentiality parameter in the newly generated temporary user-side parameter group, the modified server-side confidentiality parameter copy and the generated temporary user-side confidentiality parameter are: Corresponding to the calculation v=(u1+t1)t2, the user terminal and the signature auxiliary device or system each use the newly generated temporary confidentiality parameter and the modified confidentiality parameter copy to perform collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0254] User terminal calculations 11 =(h^u1)mod n; the signature auxiliary device or system calculates s 12 =(h^t1)mod n; the user terminal or the signature auxiliary device or system calculates s1=(s 11 s12 )mod n; the signature auxiliary device or system calculates s=(s1^t2)mod n, then s is the digital signature for the message M.
[0255] Example 4 of Dynamic Generation of User-side Confidentiality Parameters
[0256] The server has a confidentiality parameter group and confidentiality parameters in advance. t1 and t2 are stored in the user terminal after addition or full homomorphic encryption, where b1 and b2 are or An integer randomly selected from the inner part that satisfies the relationship (b1b2) mod = 1;
[0257] When the user's RSA signature private key needs to be used to digitally sign the message M, the user terminal randomly selects two integers a1 and a2 in [1, w], where w is the same as before; the copies of t1 and t2 are modified to With u1=a1 and u2=a2 as the confidentiality parameters in the newly generated temporary user-side parameter group, the modified server-side confidentiality parameter copy and the generated temporary user-side confidentiality parameters are: When a digital signature is generated for a message M, corresponding to the calculation v=(u1+t1)(u2+t2), the user terminal and the signature auxiliary device or system each use the newly generated temporary confidentiality parameter and the modified confidentiality parameter to perform a collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponential part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0258] User terminal calculations 11 =(h^u1)mod n; the signature auxiliary device or system calculates s 12 =(h^t1)mod n; the user terminal or the signature auxiliary device or system calculates s1=(s 11 s 12 )mod n;
[0259] User terminal calculations 21 =(s1^u2)mod n; the signature auxiliary device or system calculates s 22 =(s1^t2)mod n;
[0260] The user terminal or the signature auxiliary device or system calculates s = (s 21 s 22 )mod n, then s is the digital signature for message M.
[0261] The above are just a few examples of the implementation of the dynamic generation scheme of the user terminal confidentiality parameter group, and do not represent all possible implementation methods.
[0262] The above-mentioned variable confidentiality parameter scheme and user-side confidentiality parameter dynamic generation scheme can be implemented on the premise that the confidentiality parameter minus an integer is The integers are in the form of , and the integers to be subtracted are selected from [1,w], where And the value of w does not depend on The value of is to ensure that the modified confidentiality parameter is a positive integer, so that the exponent will not be negative or 0 when performing a modulo-n exponentiation operation on h. However, if the hash value h of the message M is relatively prime to n, or the probability that the hash value h of the message M is not relatively prime to n is acceptable, then the value of w is allowed to be n, and the modified server confidentiality parameter copy is allowed to be a negative integer; and if h and n are not relatively prime and the exponent is negative in the modulo-n exponentiation operation on h, or the exponent is 0 in the modulo-n exponentiation operation on h during the process of generating the digital signature of M, then error processing is entered; the error processing includes: modifying the padding data of h so that h and n are relatively prime, or reselecting the integer randomly selected when modifying the server confidentiality parameter copy, or changing the modification of subtracting a randomly selected integer from the server confidentiality parameter copy to adding another randomly selected integer to the server confidentiality parameter copy, and then subtracting the same integer from the user confidentiality parameter copy, while ensuring that the modification of subtracting the same integer from the user confidentiality parameter copy will not result in negative numbers or 0. This can be illustrated by the following example in which the confidentiality parameter is variable.
[0263] Confidentiality parameter variable embodiment 9,
[0264] Initialization (random) selection or The inner integer secrets b1 and b2 are such that
[0265] The user terminal parameter group has confidentiality parameters: u1 = d + b1 or
[0266] The server confidentiality parameter group has confidentiality parameters: t1 = b2;
[0267] The server-side confidentiality parameters are stored in the user terminal after addition or full homomorphic encryption;
[0268] When generating a digital signature for a message M, the user terminal randomly selects an integer b in [1,n] and then updates the copy of u1 with u1+b, that is, the copy of u1 is modified to u1=d+b1+b or By using homomorphic encryption, the copy of the server-side confidentiality parameter t1=b2 is modified to t1=b2-b, then Corresponding to the calculation v=u1+t1, the user terminal and the signature auxiliary device or system each use the modified copy of the confidentiality parameter to perform a collaborative calculation of the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter, that is:
[0269] The user terminal calculates s1=(h^u1) mod n, and the signature auxiliary device or system calculates s2=(h^t1) mod n; the user terminal or the signature auxiliary device or system calculates s=(s1s2) mod n, then s is the digital signature for the message M;
[0270] In the above collaborative calculation process, if h and n are not coprime and t1 is negative, or t1 is 0, then error handling is performed, for example, the filling method of h is modified to make h and n coprime, or b is reselected and the copy of t1 is modified to make t1 positive, or an integer b is randomly selected in [1,u1-1] and then the copy of u1 is updated with u1-b, that is, the copy of u1 is modified to u1=d+b1-b or By using homomorphic encryption, the copy of the server-side confidential parameter t1=b2 is modified to t1=b2+b, then Then, corresponding to the calculation v=u1+t1, the user terminal and the signature auxiliary device or system each use a modified copy of the confidentiality parameter to collaboratively calculate the modulo-n exponentiation operation on the hash value h of the message M without exposing their respective secrets, and in the collaborative calculation process of the modulo-n exponentiation operation, the operation performed on the exponent part of h corresponds to the operation used to calculate v using the confidentiality parameter.
[0271] The implementation of the security enhancement scheme of the present invention requires the use of a homomorphic encryption algorithm, which can be an additive homomorphic encryption algorithm (such as the Paillier algorithm) and a fully homomorphic encryption algorithm (such as BGV, BFV, CKKS), an exact homomorphic encryption algorithm (such as Paillier, BGV, BFV) or an approximate homomorphic encryption algorithm (such as CKKS). For the approximate homomorphic encryption algorithm, after decrypting the data, its absolute value is rounded to the nearest integer, and the sign bit remains unchanged.
[0272] If the key generation device or system is used to generate an RSA signature key pair and generate a user-side confidentiality parameter group and a server-side confidentiality parameter group, the key generation device or system can be specifically implemented as plug-and-play cryptographic hardware (such as a cryptographic card, USBKey) or a device or system that combines hardware and software (such as a cryptographic machine, cryptographic server).
[0273] If a trusted program in a user terminal is used to generate an RSA signature key pair, generate a user-side confidentiality parameter group and a server-side confidentiality parameter group, and encrypt the server-side confidentiality parameters, the corresponding program can be provided by the cryptographic program or cryptographic module developer or cryptographic service provider, and ensure that it is executed in a secure user terminal environment, such as ensuring that there is no Trojan horse in the user terminal, or executing in a trusted execution environment (TEE); then the user-side confidentiality parameters are saved in the user terminal, and the server-side confidentiality parameters are transmitted to a signature auxiliary device or system for storage, or the server-side confidentiality parameters are encrypted and saved in the user terminal.
[0274] If the RSA signature key pair is generated by a program in another terminal, a user-side confidentiality parameter group and a server-side confidentiality parameter group are generated, and the server-side confidentiality parameters are encrypted (if the server-side confidentiality parameters are encrypted and stored in the user terminal), the corresponding program can be provided by the cryptographic program or cryptographic module developer or cryptographic service provider to generate the RSA signature key pair, and the confidentiality parameters and other parameters (such as the modulus n) are transmitted to the user terminal, signature auxiliary device or system for storage by scanning a barcode (such as a QR code, a multi-dimensional code) or other secure transmission methods (such as file copying, email). Alternatively, the user can use a browser in another terminal to visit a special trusted website, and the script program returned by the trusted website generates the RSA signature key pair in the browser, and then the confidentiality parameters and other parameters (such as the modulus n) are transmitted to the user terminal, signature auxiliary device or system for storage by scanning a barcode (such as a QR code, a multi-dimensional code) or other secure transmission methods (such as file copying, email).
[0275] On the basis of the RSA digital signature collaborative generation method for hiding the private key secret of the present invention, a corresponding RSA digital signature collaborative generation system for hiding the private key secret can be implemented, the system includes a signature auxiliary device or system, a cryptographic program or a cryptographic module or a cryptographic component in a user terminal; a user terminal confidentiality parameter group for the user's RSA signature private key is stored in the user terminal; the signature auxiliary device or system stores a server confidentiality parameter group for the user's RSA signature private key, or the confidentiality parameters in the server confidentiality parameter group are encrypted and stored in the user terminal; when the user's RSA signature private key needs to be used to digitally sign a message M, the cryptographic program or cryptographic module or cryptographic component in the user terminal, and the signature auxiliary device or system, collaboratively generate a digital signature for the message M according to the above-mentioned RSA digital signature collaborative generation method for hiding the private key secret, wherein the cryptographic program or cryptographic module or cryptographic component in the user terminal implements the function of the user terminal in the above-mentioned digital signature generation method. The basic structure of the system implemented by the present invention is as follows: Figure 1 Furthermore, the system may also include a key generation device or system and a trusted program for generating an RSA signature key pair.
[0276] In the implementation of the present invention, the signature assistance device or system can be a software device or system, or a device or system that combines software and hardware. The software device can be an independently running program or cryptographic module, and the device that combines software and hardware can be plug-and-play cryptographic hardware such as a cryptographic card, USB Key, or a cryptographic machine / cryptographic server.
[0277] In the implementation of the present invention, the user terminal is a variety of computing devices used by the user, such as computers, mobile phones, tablet computers, etc. The user terminal implements the digital signature generation function in the user terminal of the present invention by running a cryptographic program, a cryptographic module or a cryptographic component therein. The program that implements cryptographic functions such as digital signatures in the user terminal can be an independently running cryptographic program, such as a program formed by an app or a WeChat applet, or a cryptographic module or cryptographic component that implements cryptographic functions such as digital signatures, such as a cryptographic API, SDK, WeChat applet plug-in, browser control, etc. If the program that implements cryptographic functions such as digital signatures is an independently running cryptographic program, then when the program in the user terminal passes data to the cryptographic program, the data can be transferred by utilizing the mechanism for transferring data between the user terminal and the computing device provided by the program development; if the program that implements cryptographic functions such as digital signatures is a cryptographic module or cryptographic component, then the program that calls the cryptographic module or cryptographic component directly transfers data to the called cryptographic module or cryptographic component; if the user terminal is a mobile communication terminal (such as a mobile phone), the application service system can send a text message through the user's mobile communication terminal, and start the cryptographic program that implements the RSA digital signature function in the user's mobile communication terminal through the information contained in the text message, such as the URL Schema, and transfer the security token or the acquisition information of the security token to the cryptographic program that implements the RSA digital signature function in the user's mobile communication terminal automatically through a URL link or through the information entered by the user in the text message.
[0278] Other specific technical implementations not described are well known and self-evident to technicians in the relevant fields.
Claims
1. A collaborative RSA digital signature generation method that hides the secret of the private key. In the user's RSA signature key pair, the public key is (e,n) and the private key is (d,p,q,n) or Where n is the modulus, n = pq, Its characteristics are: There is a group of confidentiality parameters for the user terminal and the signature auxiliary device or system respectively, and each group of confidentiality parameters includes one or more positive integers called confidentiality parameters; the confidentiality parameters are secret; the confidentiality parameter group for the user terminal is called the user-side confidentiality parameter group, and the confidentiality parameters therein are parameters used by the user terminal, and are called user-side confidentiality parameters; the confidentiality parameter group for the signature auxiliary device or system is called the server-side confidentiality parameter group, and the confidentiality parameters therein are parameters used by the signature auxiliary device or system, and are called server-side confidentiality parameters; the user-side confidentiality parameters can only be obtained in plain text by the user terminal, and the server-side confidentiality parameters can only be obtained in plain text by the signature auxiliary device or system; The user-side confidentiality parameters are stored in the user terminal; The server-side confidentiality parameters are stored in the signature auxiliary device or system, or stored in the user terminal in the form of ciphertext data that can be decrypted by the signature auxiliary device or system; the user terminal is the user's computing device; the signature auxiliary device or system is a computing device or system that assists and helps the user terminal to complete the generation and calculation of the digital signature; The two sets of confidentiality parameters for the user terminal, signature auxiliary device or system have the following characteristics: The modulus of the result v after adding and multiplying the confidential parameters in the two sets of confidential parameters and the non-confidential parameters other than the confidential parameters in a predetermined operation method is The remainder is d, which is the result of the operation. That is, v and d modulus Or, the result v after adding and multiplying the confidential parameters in the two sets of parameters and the non-confidential parameters other than the confidential parameters in a predetermined operation method is the modulus of e. Multiplicative inverse, that is Cannot be derived from a set of confidential parameters It is impossible to obtain the modulus of d from a set of secret parameters Congruent numbers or get the modulus of e Multiplicative inverse, that is, it is impossible to use the confidential parameters in a set of confidential parameters to obtain v1 through addition and multiplication operations, there is or The signature auxiliary device or system cannot obtain the secret share of the private key secret d through the confidentiality parameters in the server confidentiality parameter group; the secret share of the private key secret d refers to the secret share of the private key secret d obtained during initialization. Integers d1 and d2 are selected from the or or or Wherein a1, a2, a are non-confidential integer parameters; the signature auxiliary device or system cannot obtain the secret share of the private key secret d through the confidentiality parameters in the server confidentiality parameter group means that the signature auxiliary device or system cannot obtain any of the above d1 and d2 directly or by calculation through the confidentiality parameters in the server confidentiality parameter group; Set p, q, throw away; When you need to use the user's RSA signature private key to digitally sign message M: The user terminal or the signature auxiliary device or system calculates the hash value h of the message M; The user terminal and the signature auxiliary device or system use the confidentiality parameters in their respective confidentiality parameter groups to perform collaborative calculation of the modulo n exponentiation operation on h without exposing their respective secrets, and the addition and multiplication operations performed on the exponent part of h in the collaborative calculation of the modulo n exponentiation operation are calculated by using the confidentiality parameters in the two sets of confidentiality parameters through addition and multiplication operations to obtain the value modulo d. The addition and multiplication operations performed on the congruence operation result v correspond to each other, that is, if two numbers are added when v is calculated, then when the modulo n exponentiation operation of h is performed in a coordinated calculation, the exponent part of h also has the same two numbers added; if two numbers are multiplied when v is calculated, then when the modulo n exponentiation operation of h is performed in a coordinated calculation, the exponent part of h also has the same two numbers multiplied, so as to calculate s=(h^v)mod n, where ^ represents the exponentiation operation, and s is the digital signature for the message M; the number of the two numbers added or multiplied above is the confidentiality parameter in the confidentiality parameter group, or is a non-confidential parameter, or is a number calculated using the confidentiality parameter in the confidentiality parameter group; If the confidentiality parameters in the server confidentiality parameter group are encrypted and stored in the user terminal, then when generating a digital signature, the user terminal submits the ciphertext of the confidentiality parameters in the server confidentiality parameter group to the signature auxiliary device or system, and the signature auxiliary device or system decrypts the plaintext of the confidentiality parameters in its confidentiality parameter group; Before assisting or helping to complete the generation of the digital signature, the signature assisting device or system confirms that the user is the owner of the modulus n or the public key (e, n), or the system that relies on calling the signature assisting device or system confirms that the user is the owner of the modulus n or the public key (e, n); The user terminal implements the above-mentioned digital signature calculation and generation steps through the cryptographic program or cryptographic module or cryptographic component that implements the cryptographic function therein, and implements the RSA digital signature function.
2. The RSA digital signature collaborative generation method for hiding the private key secret according to claim 1 is characterized by: The confidentiality parameters in the server confidentiality parameter group are generated as follows, or have the following characteristics: Each confidentiality parameter in the server confidentiality parameter group is a parameter with a single value and its value is independent of the private key secret d and the secret share of the private key secret d, or is a number calculated from multiple confidentiality parameters, and the multiple confidentiality parameters used to calculate this number include at least one confidentiality parameter with a single value and its value is independent of the private key secret d and the secret share of the private key secret d; the multiple refers to two or more; Furthermore, the result of the addition and multiplication operations using the confidentiality parameters in the server confidentiality parameter group is a confidentiality parameter with a single value and its value is independent of the private key secret d and the secret share of the private key secret d, or is a number calculated from multiple confidentiality parameters, and the multiple confidentiality parameters used to calculate this number include at least one confidentiality parameter with a single value and its value is independent of the private key secret d and the secret share of the private key secret d; The confidentiality parameters that have independent values and are independent of the private key secret d and the secret share of the private key secret d include: The random selection that does not depend on the private key secret d and the secret share of the private key secret d satisfies or Integers b1 and b2.
3. The RSA digital signature collaborative generation method for hiding the private key secret according to claim 2 is characterized in that: A scheme with variable confidentiality parameters for the RSA digital signature collaborative generation method for hiding the private key secret is as follows: The confidentiality parameters in the server confidentiality parameter group are encrypted using a homomorphic encryption algorithm and then stored in the user terminal; the confidentiality parameters in the server confidentiality parameter group stored in the user terminal do not have to meet all the aforementioned characteristic requirements for the server confidentiality parameters; When generating a digital signature for a message M, the user terminal randomly selects one or more integers as secrets, and uses the selected integers to modify the confidentiality parameters in the two sets of confidentiality parameters, wherein the modification of the confidentiality parameters in the server confidentiality parameter group is performed by homomorphic encryption and homomorphic ciphertext operation; the plurality includes two or more; the modification includes modifying the value of the confidentiality parameter and changing the number of confidentiality parameters in the confidentiality parameter group; the two sets of confidentiality parameters after modification satisfy or have the aforementioned characteristics; the above modification of the confidentiality parameters in the confidentiality parameter group is only effective for the current digital signature generation and calculation, and does not change the original confidentiality parameter group stored in the user terminal, that is, the modification is for a copy of the user confidentiality parameter group and the server confidentiality parameter group; Afterwards, the user terminal submits the modified copy of the server confidentiality parameter group to the signature assistance device or system, and the signature assistance device or system decrypts the confidentiality parameters in the encrypted copy of the confidentiality parameter group to obtain its plain text. Then, the user terminal and the signature assistance device or system use the modified user confidentiality parameter group and the copy of the server confidentiality parameter group to generate a digital signature for the message M according to the RSA digital signature collaborative generation method that hides the private key secret as described above.
4. The RSA digital signature collaborative generation method for hiding the private key secret according to claim 2 is characterized in that: exist A scheme for dynamically generating a user-side confidentiality parameter group based on the RSA digital signature collaborative generation method that hides the private key secret is as follows: There is no user-side confidentiality parameter group in advance, and only a server-side confidentiality parameter group is in advance; the server-side confidentiality parameter group is encrypted using a homomorphic encryption algorithm and then stored in the user terminal; the server-side confidentiality parameter group stored in the user terminal does not have to meet all the aforementioned characteristic requirements for the server-side confidentiality parameters; When generating a digital signature for a message M, the user terminal randomly selects one or more integers as user-side confidentiality parameters, creates a temporary user-side confidentiality parameter group, and uses the randomly selected integers, i.e., the confidentiality parameters in the created temporary user-side confidentiality parameter group, to modify the confidentiality parameters in the server-side confidentiality parameter group copy, wherein the modification of the confidentiality parameters in the server-side confidentiality parameter group copy is performed by homomorphic encryption and homomorphic ciphertext operation; the multiple includes two or more; the modification includes modifying the value of the confidentiality parameter and the number of confidentiality parameters in the server-side confidentiality parameter group copy; the created temporary user-side confidentiality parameter group and the modified server-side confidentiality parameter group copy satisfy or have the aforementioned characteristics; the generation of the temporary user-side confidentiality parameter group and the modification of the confidentiality parameters in the server-side confidentiality parameter group copy as described above are only valid for the current digital signature generation and calculation, and do not change the original server-side confidentiality parameter group stored in the user terminal; Afterwards, the user terminal submits the modified copy of the server confidentiality parameter group to the signature assistance device or system, and the signature assistance device or system decrypts the confidentiality parameters in the encrypted copy of the confidentiality parameter group to obtain its plain text. Then, the user terminal and the signature assistance device or system use the generated temporary user confidentiality parameter group and the modified copy of the server confidentiality parameter to generate a digital signature for the message M according to the RSA digital signature collaborative generation method that hides the private key secret as described above.
5. The RSA digital signature collaborative generation method for hiding the private key secret according to claim 3 or 4 is characterized in that: The user terminal randomly selects an integer as follows: The user terminal randomly selects an integer in [1,w], where w is calculated using n and satisfies integer, and the choice of w does not depend on The value of .
6. The RSA digital signature collaborative generation method for hiding the private key secret according to claim 5 is characterized in that: For the above-mentioned method of randomly selecting an integer by the user terminal, the value of w includes: Select an integer m, m ≥ 2, limit p ≥ 2m, q ≥ 2m, and take in Indicates rounding down; Or, limit p≥3, q≥3, and take Where sqrt(n) is the square root of n.
7. The RSA digital signature collaborative generation method for hiding the private key secret according to claim 5 is characterized by: If the hash values h and n of the message M are relatively prime, or the probability that the hash values h and n of the message M are not relatively prime is acceptable, then the value of w is allowed to be n, and the modified server confidentiality parameter copy is allowed to be a negative integer; If h and n are not coprime in the process of generating the digital signature of M and the exponent of h is negative during the modulo-n exponentiation operation, or the exponent of h is 0 during the modulo-n exponentiation operation, then the process goes to error handling; The error handling includes: modifying the padding data of h so that h and n are relatively prime, or reselecting the randomly selected integer when modifying the server-side confidentiality parameter copy, or changing the modification of subtracting a randomly selected integer from the server-side confidentiality parameter copy to adding another randomly selected integer to the server-side confidentiality parameter copy, and then subtracting the same integer from the user-side confidentiality parameter copy, while ensuring that the modification of subtracting the same integer from the user-side confidentiality parameter copy will not result in negative numbers and 0.
8. The collaborative generation method of RSA digital signature with hidden private key secret according to any one of claims 1 to 4, characterized in that: exist The basis of the RSA digital signature collaborative generation method that hides the private key secret, a security enhancement solution to prevent the confidentiality parameter group stored in the user terminal from being stolen is as follows: When a user accesses the application service system and needs to use the user's RSA signature private key to digitally sign a message M, the application service system issues a security token to the user; the security token is an authorization certificate for requesting a signature auxiliary device or system to assist, collaboratively generate or / and calculate a digital signature; The application service system transmits the security token or the acquisition information of the security token to the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function in the user terminal; the acquisition information of the security token is information used to obtain the security token issued by the application service system; The user terminal submits the security token or the acquisition information of the security token to the signature auxiliary device or system; If the information submitted to the signature auxiliary device or system is the acquisition information of the security token, the signature auxiliary device or system uses the acquisition information to obtain the security token issued by the application service system; The signature auxiliary device or system verifies the validity of the security token, after which the user terminal and the signature auxiliary device or system use the confidentiality parameters in the confidentiality parameter group to generate a digital signature for the message M according to the RSA digital signature collaborative generation method that hides the private key secret as described above.
9. The RSA digital signature collaborative generation method for hiding the private key secret according to claim 8 is characterized by: The manner in which the application service system transmits the security token or the acquisition information of the security token to the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function in the user terminal includes: If the client program used by the user to access the application service system and the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function are located in the same user terminal, the application service system transmits the security token or the acquisition information of the security token to the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function in the user terminal through the client program; Alternatively, if the client program used by the user to access the application service system and the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function are located in different user terminals, the application service system displays the barcode through the client program used by the user, and then transmits the security token or the acquisition information of the security token to the cryptographic program or cryptographic module or cryptographic component implementing the RSA digital signature function in the user terminal by the user scanning the barcode with the user terminal; Alternatively, if the user terminal is a mobile communication terminal, the application service system sends a text message through the user's mobile communication terminal, starts the cryptographic program that implements the RSA digital signature function in the user's mobile communication terminal through the information contained in the text message, and passes the security token or the acquisition information of the security token to the cryptographic program that implements the RSA digital signature function in the user's mobile communication terminal automatically through the startup information or through the user inputting information in the text message.
10. The RSA digital signature collaborative generation method for hiding the private key secret according to claim 8 is characterized by: exist Based on the security enhancement scheme of the RSA digital signature collaborative generation method for hiding the private key secret to prevent the confidentiality parameter group stored in the user terminal from being stolen, a security enhancement scheme to prevent the security token from being stolen is as follows: When the application service system issues a security token to a user, it randomly selects an integer c in [1, n-1] as a perturbation parameter, or randomly selects an integer c that is relatively prime to n in [1, n-1] as a perturbation parameter, and then encrypts c into ciphertext data that can only be decrypted by the signature auxiliary device or system, and then transmits the ciphertext data of c together with the security token to the signature auxiliary device or system through the user terminal, and the plaintext or ciphertext data of c is protected by the security token; After verifying the validity of the received security token, the signature auxiliary device or system decrypts the ciphertext of the perturbation parameter c to obtain the plaintext of c, and at the same time determines the validity of the plaintext or ciphertext of c through the security token; After completing the generation of the digital signature s for the message M, the signature auxiliary device or system uses c to calculate the disturbed digital signature s c =(s+c)mod n, or, c is an integer randomly selected from [1,n-1] that is relatively prime to n, and c is used to calculate the perturbed digital signature s c =(s*c)mod n, where * is the multiplication operator; s c It is not submitted or returned to the application service system through the user terminal; The application service system calculates s = (s c -c)mod n or s = (c -1 s c ) mod n, where c -1 The modulo n multiplicative inverse of c restores the digital signature s.
11. The RSA digital signature collaborative generation method for hiding the private key secret according to any one of claims 1 to 4, characterized in that: The generation and distribution methods of the user's RSA signature key pair and confidentiality parameter group include: Method 1: The key generation device or system generates an RSA signature key pair, generates a confidentiality parameter group for the user terminal and the signature auxiliary device or system, and then transmits the generated confidentiality parameter group to the user terminal and the signature auxiliary device or system for storage; if the confidentiality parameter group for the signature auxiliary device or system needs to be stored in the user terminal, the key generation device or system encrypts the confidentiality parameters in the confidentiality parameter group for the signature auxiliary device or system and transmits the encrypted confidentiality parameters to the user terminal for storage; Method 2: The trusted program in the user terminal generates an RSA signature key pair, generates a confidentiality parameter group for the user terminal and the signature auxiliary device or system, and stores the confidentiality parameter group for the user terminal locally in the user terminal; if the confidentiality parameter group for the signature auxiliary device or system needs to be transmitted to the signature auxiliary device or system for storage, the trusted program in the user terminal transmits the confidentiality parameter group for the signature auxiliary device or system to the signature auxiliary device or system for storage; if the confidentiality parameter group for the signature auxiliary device or system is to be stored locally in the user terminal, the trusted program in the user terminal encrypts the confidentiality parameters in the confidentiality parameter group for the signature auxiliary device or system and stores them locally in the user terminal; the trusted program is a program provided by a cryptographic program or cryptographic module developer, or a cryptographic service provider; Method 3: A trusted program in another terminal generates an RSA signature key pair, generates a confidentiality parameter group for the user terminal and the signature auxiliary device or system, and then transmits the confidentiality parameter group for the user terminal to the user terminal for storage by scanning a code or other secure transmission methods; if it is necessary to transmit the confidentiality parameter group for the signature auxiliary device or system to the signature auxiliary device or system for storage, the trusted program transmits the confidentiality parameter group for the signature auxiliary device or system to the signature auxiliary device or system for storage; if the confidentiality parameter group for the signature auxiliary device or system is to be stored in the user terminal, the trusted program encrypts the confidentiality parameter group for the signature auxiliary device or system and transmits it to the user terminal for storage by scanning a code or other secure transmission methods.
12. A system for collaboratively generating RSA digital signatures with hidden private key secrets based on the method for collaboratively generating RSA digital signatures with hidden private key secrets as claimed in any one of claims 1 to 4, characterized in that: The system includes a signature auxiliary device or system, a cryptographic program or a cryptographic module or a cryptographic component in a user terminal; a user terminal stores a user-side confidentiality parameter group for a user's RSA signature private key; a signature auxiliary device or system stores a server-side confidentiality parameter group for a user's RSA signature private key, or the confidentiality parameters in the server-side confidentiality parameter group are encrypted and stored in the user terminal; when it is necessary to use the user's RSA signature private key to digitally sign a message M, the cryptographic program or the cryptographic module or the cryptographic component in the user terminal, and the signature auxiliary device or system, according to the above-mentioned RSA digital signature collaborative generation method that hides the private key secret, collaboratively generate a digital signature for the message M, wherein the cryptographic program or the cryptographic module or the cryptographic component in the user terminal implements the function of the user terminal in the above-mentioned digital signature generation method.
Citation Information
Patent Citations
Digital signature generation method and system based on encrypted private key secrets
CN107483205A
Collaborative generation method and system of digital signatures based on homomorphic encryption
CN107872322A