An ECDSA digital signature generation method and system based on ciphertext private key
Through the ECDSA digital signature method based on ciphertext private key, a homomorphic encryption algorithm is used to jointly calculate signatures between the user terminal and the signature auxiliary device, which solves the problem of signature sharing, realizes the security and effectiveness of signatures, and improves the security of the user terminal.
Patent Information
- Application Number
- CN202211265723.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-17
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-10-17
AI Technical Summary
In the existing ECDSA digital signature scheme based on secret sharing, participants outside the user share the secret share of the signature private key, which violates the requirements of the electronic signature law, and there is a risk of leakage of the signature private key securely stored and used in the user terminal.
The ECDSA digital signature method based on the ciphertext private key is adopted. The signature is synergistically calculated between the user terminal and the signature auxiliary device or system through a homomorphic encryption algorithm to ensure that the signature private key is not shared. The interactive calculation of the random numbers k1 and k2 is used to generate R and Rf, and the signature parameter s is calculated in combination with the homomorphic encryption algorithm to ensure signature security and validity.
Without sharing the signature private key, the security and validity of the signature is realized, the signature private key is prevented from being leaked, the requirements of electronic signature method are met, and the secure storage and use protection of the user terminal is improved.
Smart Images

Figure CN115766019B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of cryptography, and particularly relates to a method and system for generating an ECDSA digital signature based on a ciphertext private key. Background Art
[0002] For user terminal computing environments (such as mobile terminals like personal computers, mobile phones, and tablet computers) that do not have cryptographic hardware to store signature private keys and use signature private keys for cryptographic operations, a digital signature collaborative generation scheme based on secret sharing is often adopted to ensure the security of signature private keys and the generated digital signatures. ECDSA (Elliptic Curve Digital Signature Algorithm) is a digital signature algorithm based on an elliptic curve point group widely adopted internationally at present. A brief description is as follows (for details, refer to "4.1 Elliptic Curve Digital Signature Algorithm" in "Standards for Efficient Cryptography, SEC 1: Elliptic Curve Cryptography", Certicom Research, May 21, 2009 Version 2.0):
[0003] The order of the elliptic curve point group (subgroup) of ECDSA or the order of the base point G is a prime number n, and the signature private key d of the user U is an integer randomly selected within [1, n - 1], and the public key is Q U = d U G; when signing the message M, first calculate the hash value e of the message M using a hash function (in fact, e is an integer converted and derived from the hash value H = H(M) of the message M, but usually simply said that e is the hash value of the message M, and the description in the present invention is also like this); randomly select an integer k within [1, n - 1], calculate R = kG; calculate r = x R mod n, where x R is taken from (x R , y R ) = R (the actual calculation is to first convert x R into an integer according to the specified method, and then take its remainder modulo n, but usually described like this); if r = 0, then re - select k and recalculate R and r until r is not 0; calculate s = k -1 (e + rd U ); if s = 0, then re - select k and recalculate s until s is not 0; then (r, s) is the digital signature for the message M.
[0004] It should be noted that there are various digital signature algorithms based on elliptic curve point groups, which belong to different digital signature algorithms. The ECDSA of the present invention specifically refers to a specific elliptic curve digital signature algorithm widely adopted internationally at present, and its name is ECDSA (the internationally generally accepted name, see the above literature).
[0005] One problem existing in the current digital signature based on secret sharing for ECDSA is that other digital signature collaborative generation participants outside the user share the signature private key of the user, that is, the secret share of the user's signature private key. This is not fully in line with the Electronic Signature Law of the People's Republic of China. The Electronic Signature Law requires that the signature production data when generating an electronic signature be exclusive to and controlled by the signer. For a digital signature, the signature production data is also the signature private key. Therefore, how to securely store and use the user's ECDSA signature private key on the user terminal without sharing the ECDSA signature private key, that is, how to ensure the effectiveness and security of the generated digital signature when other digital signature collaborative generation participants outside the user do not have the secret share of the signature private key, is a technical problem that needs to be solved. Moreover, without adopting the secret sharing of the signature private key, how to ensure the secure storage and use of the signature private key (signature production data) stored on the user terminal is particularly important, because the theft of the signature private key (signature production data) stored on the user terminal will lead to the leakage or theft of the signature private key. Summary of the Invention
[0006] The object of the present invention is to propose corresponding technical solutions to overcome the deficiencies of the prior art in view of the problems existing in the current technical solution of collaborative generation of ECDSA digital signatures based on secret sharing.
[0007] For the object of the present invention, the technical solution proposed by the present invention includes an ECDSA digital signature generation method based on ciphertext private key and a corresponding system.
[0008] In the following description of the technical solution of the present invention, if P and Q are elements (points) in the elliptic curve point group, then P + Q represents the point addition of P and Q, P - Q represents P plus the inverse element of Q, and kP represents the point addition of k elliptic curve points P, that is, P + P +... + P (there are k Ps in total. If k is negative, then kP is the additive inverse of the result of the point addition of |k| elliptic curve points P); c -1 represents the modular multiplicative inverse of the integer c modulo n (that is, cc -1mod n = 1); Unless otherwise specified, the multiplicative inverse in this patent application is the multiplicative inverse modulo n of the order n of the ECDSA elliptic curve point group (i.e., the order n of the base point G); When multiplying multiple integers (including multiplying integer sign parameters, variables, constants with integer sign parameters, variables), the multiplication sign "·" is omitted without ambiguity, e.g., k1·k2 is simplified to k1k2, and 3·c is simplified to 3c; mod n represents the modulo operation, and the operator mod n of the modulo operation has the lowest priority, e.g., a + b mod n is equivalent to (a + b) mod n, a - b mod n is equivalent to (a - b) mod n, and ab mod n is equivalent to (ab) mod n.
[0009] The ECDSA digital signature generation method based on ciphertext private key proposed by the present invention is as follows.
[0010] The user terminal has Q U = d U G, and has a secret S U = E(d U ), where d U is the ECDSA signature private key of the user, G is the base point of the ECDSA elliptic curve point group (subgroup), Q U is the public key corresponding to the ECDSA signature private key d U of the user, and E(·) is the encryption operation using the homomorphic encryption algorithm;
[0011] The user terminal is the user's computing device (such as a personal computer, mobile phone, tablet computer); The homomorphic encryption algorithm is an additive homomorphic encryption algorithm or a fully homomorphic encryption algorithm; The signature assistance device or system has the private key SK1 (the private key of the homomorphic encryption algorithm) for the decryption operation corresponding to the public key used in the encryption operation E(·) of the homomorphic encryption algorithm, or the private key SK1 for the decryption operation corresponding to the public key used in the encryption operation E(·) of the homomorphic encryption algorithm is encrypted into the ciphertext T sk1 using the key of the signature assistance device or system, where the key of the signature assistance device or system used to encrypt SK1 includes a symmetric key or a public key (where the public key includes ordinary public keys, such as the public keys of ordinary public key cryptography algorithms like RSA, SM2, etc., or the group public key of the group-oriented encryption algorithm), and the user terminal stores the ciphertext T sk1 of the private key SK1 for the decryption operation corresponding to the public key used in the encryption operation E(·) sk1 (T
[0012] When the ECDSA signature private key d of the user is required to be used U When performing a digital signature on the message M, the user terminal and the signature assistance device or system generate a digital signature for the message M in the following manner (the ECDSA signature private key d of the user needs to be used U and the entity performing the digital signature on the message M can be an application program or system inside or outside the user terminal that needs to invoke the digital signature function in the user terminal):
[0013] The user terminal calculates the hash value e of the message M using the message M and a hash function, and sends e to the signature assistance device or system. Alternatively, the signature assistance device or system calculates the hash value e of the message M using the message M and a hash function, and sends e to the user terminal;
[0014] The user terminal randomly selects an integer k1 in the interval [1, n - 1], where n is the order of the base point G (i.e., the order of the ECDSA elliptic curve point group (subgroup)), and n is a prime number;
[0015] The signature assistance device or system randomly selects an integer k2 in the interval [1, n - 1];
[0016] The user terminal and the signature assistance device or system complete the following calculations without exposing their respective secrets k1 and k2:
[0017] The user terminal, while ensuring that the signature assistance device or system does not re - select k2, calculates R = k1k2G through interaction with the signature assistance device or system;
[0018] The signature assistance device or system, while ensuring that the user terminal does not re - select k1, calculates R f = k1k2G;
[0019] Or,
[0020] The user terminal, while ensuring that the signature assistance device or system does not re - select k2, calculates R = (k1 + k2)G through interaction with the signature assistance device or system;
[0021] The signature assistance device or system, while ensuring that the user terminal does not re - select k1, calculates R f = (k1 + k2)G;
[0022] If R and / or R f is the zero element (infinity point), then the user terminal, the signature assistance device or system re - select k1 and k2, and recalculate R and R f , until R and Rf Non-zero element;
[0023] The user terminal calculates r = x R mod n, where x R is taken from (x R , y R ) = R;
[0024] The signature assistance device or system calculates r f = x Rf mod n, where x Rf is taken from (x Rf , y Rf ) = R f ;
[0025] The user terminal and the signature assistance device or system check whether r and / or r f is 0 (the integer 0). If so, the user terminal and the signature assistance device or system re-select k1, k2, recalculate R, R f , recalculate r, r f , until both r and r f are not 0;
[0026] The user terminal and the signature assistance device or system respectively check whether there will be a situation where (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0, that is, whether there will be a situation where s = 0, where s is the parameter s in the digital signature (r, s) to be calculated and generated;
[0027] If so, the user terminal and the signature assistance device or system re-select k1, k2, recalculate R, R f , recalculate r, r f , until there will be no situation where (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0, or transfer to error handling;
[0028] If there will be no situation where (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0, then perform subsequent calculation processing;
[0029] The user terminal calculates s1 in one of the following ways:
[0030] Calculation method 1 of s1:
[0031] R, R fThe calculation formula used is R = k1k2G, R f = k1k2G;
[0032] The user terminal randomly selects an integer b within [1, n - 1], and uses b, e, r, S U , k1 to calculate through the homomorphic encryption algorithm:
[0033] s 10 = ((k1) -1 e - b) mod n, s 11 = E(b + (k1) -1 rd U (mod n)),
[0034] Or, s 10 = ((k1) -1 (e - b)) mod n, s 11 = E((k1) -1 (b + rd U )(mod n)),
[0035] Or, s 10 = ((k1) -1 (e - rb)) mod n, s 11 = E((k1) -1 (r(d U + b))(mod n)), where (k1) -1 is the multiplicative inverse of k1 modulo n;
[0036] s 10 、s 11 The numerical pair (s 10 , s 11 ) constitutes s1;
[0037] Calculation method two of s1:
[0038] R, R f The calculation formula used is R = k1k2G, R f = k1k2G;
[0039] The user terminal uses e, r, S U , k1 to calculate through the homomorphic encryption algorithm:
[0040] s1 = E((k1) -1 (e + rd U )(mod n)), where (k1) -1 is the multiplicative inverse of k1 modulo n;
[0041] Calculation method three of s1:
[0042] R, Rf The calculation formula adopted is R = k1k2G, R f = k1k2G;
[0043] The homomorphic encryption algorithm corresponding to E(·) is a fully homomorphic encryption algorithm;
[0044] The signature assistance device or system calculates c2 = E((k2) -1 ), where (k2) -1 is the modular n multiplicative inverse of k2, and sends c2 to the user terminal;
[0045] The user terminal uses e, r, S U , k1, c2 to calculate through the homomorphic encryption algorithm:
[0046] s1 = E((k1k2) -1 (e + rd U )(mod n)), where (k1k2) -1 is the modular n multiplicative inverse of k1k2 (or (k1k2) mod n);
[0047] Calculation method four of s1:
[0048] R, R f The calculation formula adopted is R = (k1 + k2)G, R f = (k1 + k2)G;
[0049] The signature assistance device or system calculates c2 = E(k2), and sends c2 to the user terminal;
[0050] The user terminal randomly selects an integer b within [1, n - 1], and uses b, e, r, S U , k1, c2 to calculate through the homomorphic encryption algorithm:
[0051] s 10 = E(b(k1 + k2)(mod n)), s 11 = E(b(e + rd U )(mod n));
[0052] s 10 、s 11 The numerical pair (s 10 , s 11 ) constitutes s1;
[0053] After calculating s1, the user terminal sends s1 to the signature assistance device or system;
[0054] If the private key SK1 corresponding to the decryption operation of the public key adopted by the encryption operation E(·) of the homomorphic encryption algorithm is encrypted into the ciphertext T by using the key of the signature assistance device or systemsk1 is saved in the user terminal, the user terminal will also T sk1 is sent to the signature auxiliary device or system, and the signature auxiliary device or system decrypts T sk1 Obtain the private key SK1 of the decryption operation corresponding to the public key used in the encryption operation E(·) of the homomorphic encryption algorithm;
[0055] For s1 calculation method 1, the signature auxiliary device or system uses the private key SK1 to decrypt the s in the value pair s1. 11 , get 11 The plaintext s 12 , calculate s = ((k2) -1 (s 10 +s 12 ))mod n;
[0056] For the second calculation method of s1, the signature auxiliary device or system uses the private key SK1 to decrypt s1 and obtain the plaintext s1 12 , calculate s = ((k2) -1 s 12 )mod n;
[0057] For s1 calculation method 3, the signature auxiliary device or system uses the private key SK1 to decrypt s1 and obtain the plaintext s1 12 , calculate s = s 12 mod n;
[0058] For s1 calculation method 4, the signature auxiliary device or system uses the private key SK1 to decrypt the s in the value pair s1. 10 、s 11 , and get s respectively 10 The plaintext s 12 ,s 11 The plaintext s 13 , calculate s = ((s 12 ) -1 s 13 ) mod n, where (s 12 ) -1 For 12 The modulo n multiplicative inverse of ;
[0059] The signature assistance device or system returns s to the user terminal; before returning s to the user terminal, the signature assistance device or system verifies whether s is a signature using e, k1, k2, r f and public key Q U The corresponding private key d U Calculate it according to the ECDSA calculation method. If yes, continue. Otherwise, go to error handling.
[0060] The user terminal verifies whether s is the same as the public key using e, k1, k2, r and public key QU The corresponding private key d U It is calculated according to the calculation method of ECDSA digital signature. If the verification passes, (r, s) is the digital signature of message M; otherwise, it transfers to error handling;
[0061] (For calculation methods one, two, and three of s1, s = ((k1k2) -1 (e + rd U )) mod n. For calculation method four of s1, s = ((k1 + k2) -1 (e + rd U )) mod n)
[0062] In the calculation formula of the encryption operation E(·) using the homomorphic encryption algorithm above, a (mod n), where a is an integer, representing the integer congruent to a modulo n (two integers a and b are congruent modulo n, that is, a mod n = b mod n, denoted as a ≡ b (mod n), and the (mod n) operator has the lowest precedence);
[0063] Before the signature assistance device or system assists the user terminal to complete the generation of the digital signature (such as before decrypting s1 or calculating s), it authenticates and confirms that the user of the user terminal, that is, the signer, is the owner of the public key Q U Or the system (such as the application service system) that depends on calling the signature assistance device or system authenticates and confirms that the user of the user terminal, that is, the signer, is the owner of the public key Q U Note that here it is not to authenticate and confirm that the user, that is, the signer, is the owner of the private key d U corresponding to the public key Q U ;
[0064] The user terminal implements the above-mentioned digital signature calculation and generation steps through the password program or password module or password component that implements the password function inside it, and implements the ECDSA digital signature function.
[0065] For the above-mentioned ECDSA digital signature generation method based on the ciphertext private key, the user terminal and the signature assistance device or system, without exposing their secrets k1, k2 and ensuring that the other party does not reselect k1, k2, obtain R = k1k2G, R f = k1k2G through interactive calculation. A method is as follows:
[0066] The user terminal calculates R1 = k1G, calculates the hash value h1 of R1 (using any suitable hash algorithm), and sends h1 to the signature assistance device or system;
[0067] The signature assistance device or system calculates R2 = k2G, calculates the hash value h2 of R2, and sends h2 to the user terminal;
[0068] After the user terminal receives h2 from the signature assistance device or system, it sends R1 to the signature assistance device or system;
[0069] After the signature assistance device or system receives h1 from the user terminal, it sends R2 to the user terminal;
[0070] After the user terminal receives R2, it calculates and checks whether the hash value of the received R2 is h2. If not, it transfers to error handling. If so, it calculates R = k1R2;
[0071] After the signature assistance device or system receives R1, it calculates and checks whether the hash value of the received R1 is h1. If not, it transfers to error handling. If so, it calculates R f = k2R1.
[0072] For the above ECDSA digital signature generation method based on ciphertext private key, without exposing their secrets k1, k2 and ensuring that the other party does not re - select k1, k2, the user terminal and the signature assistance device or system obtain R=(k1 + k2)G, R f =(k1 + k2)G through interactive calculation in the following way:
[0073] The user terminal calculates R1 = k1G, calculates the hash value h1 of R1 (using any suitable hash algorithm), and sends h1 to the signature assistance device or system;
[0074] The signature assistance device or system calculates R2 = k2G, calculates the hash value h2 of R2, and sends h2 to the user terminal;
[0075] After the user terminal receives h2 from the signature assistance device or system, it sends R1 to the signature assistance device or system;
[0076] After the signature assistance device or system receives h1 from the user terminal, it sends R2 to the user terminal;
[0077] After the user terminal receives R2, it calculates and checks whether the hash value of the received R2 is h2. If not, it transfers to error handling. If so, it calculates R = R1 + R2;
[0078] After the signature assistance device or system receives R1, it calculates and checks whether the hash value of the received R1 is h1. If not, it transfers to error handling. If so, it calculates R f = R1 + R2.
[0079] Among the above four methods for calculating s1, namely Method 1, Method 2, and Method 4, the overall computational amount of the user terminal is relatively small (including the calculation of R and s1), while Method 3 has the largest computational amount. Method 1 introduces a randomly selected integer b on the basis of the congruence number, which makes it more difficult to directly crack d from the result of the homomorphic encryption operation. U become more difficult.
[0080] For the above-mentioned ECDSA digital signature generation method based on ciphertext private key, the user terminal and the signature assistance device or system respectively check whether the situation of (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0 will occur (that is, whether the situation of s = 0 will occur, where s is the parameter s in the digital signature (r, s) to be calculated and generated). One method is as follows:
[0081] The user terminal checks whether eG + rQ U is the zero element (the infinite point of the elliptic curve point group). If so, the situation of (e + rd U ) mod n = 0 will occur; otherwise, it will not.
[0082] The signature assistance device or system checks whether eG + r f Q U is the zero element (the infinite point of the elliptic curve point group). If so, the situation of (e + r f d U ) mod n = 0 will occur; otherwise, it will not.
[0083] For the above-mentioned ECDSA digital signature generation method based on ciphertext private key, the signature assistance device or system verifies whether s is calculated according to the calculation method of ECDSA using the private key d f corresponding to e, k1, k2, r U and the public key Q U . The method includes:
[0084] The signature assistance device or system checks and verifies whether (r f , s) is the digital signature of the message M. If so, the verification passes; otherwise, the verification fails.
[0085] Alternatively, the signature assistance device or system checks and verifies whether the value of sR f is the same as eG + r f Q U . If so, the verification passes; otherwise, the verification fails.
[0086] For the above-mentioned ECDSA digital signature generation method based on ciphertext private key, the user terminal verifies whether s is calculated using e, k1, k2, r and the public key Q UThe corresponding private key d U The calculation method calculated according to the ECDSA calculation method includes:
[0087] The user terminal checks whether (r, s) is the digital signature of the message M. If so, the verification passes; otherwise, the verification fails.
[0088] Alternatively, the user terminal checks whether the value of sR is the same as eG + rQ U If they are the same, the verification passes; otherwise, the verification fails.
[0089] For d U The key pair of the homomorphic encryption algorithm for encryption can be pre-existing (i.e., permanent) in the (signature auxiliary device or system), or can be temporarily generated when encrypting d U If the key pair is temporarily generated, the corresponding private key SK1 for decrypting S U is usually encrypted as ciphertext data T sk1 and saved in the user terminal (of course, it can also be encrypted and saved in the user account of the signature auxiliary device or system).
[0090] The encryption algorithm used to encrypt the private key SK1 can be a symmetric key encryption algorithm or a public key encryption algorithm (asymmetric key encryption algorithm); if the encryption algorithm used to encrypt the private key SK1 is a public key encryption algorithm, it can be an ordinary public key encryption algorithm (a non-group-oriented encryption algorithm) or a group-oriented encryption algorithm (abbreviated as group encryption algorithm). The group-oriented encryption algorithm mentioned here refers to a class of public key encryption algorithms: a group has a public key, and each member in the group has a private key (the private keys of different members are usually different), and the data encrypted with the group public key can be decrypted by each group member using their own private key.
[0091] From the perspective of protecting the security of the user's signature private key, the key pair of the homomorphic encryption algorithm generated temporarily is more secure (because the leakage of the private key SK1 for decryption operations may at most lead to the leakage of the ECDSA signature private key of one user). Therefore, the key pair of the homomorphic encryption algorithm generated temporarily should be preferably used. However, using the permanent key pair of the homomorphic encryption algorithm can save the ciphertext data T sk1 .
[0092] For the above-mentioned ECDSA digital signature generation method based on ciphertext private key, a security enhancement scheme for an ECDSA digital signature generation method to prevent S U from being stolen is as follows.
[0093] When a user (using a program in a user terminal or other terminal) needs to use the user's ECDSA signature private key to digitally sign a message M when accessing an application service system, the application service system issues a security token to the user; the security token is an authorization credential for requesting the signature assistance device or system to assist, cooperate in generating, or / and calculating the digital signature (the security token indicates to the digital signature cooperation generation service system that this digital signature cooperation generation request is authorized and guaranteed by the application service system; the security token does not have to contain the user's identity information, but from a security perspective, at least one of the user identity information and public key information is included);
[0094] The application service system (such as through a client program or other means) passes the security token or the information for obtaining the security token to the password program or password module or password component that implements the ECDSA digital signature function in the user terminal; the information for obtaining the security token is the information used to obtain the security token issued by the application service system (at this time, the security token is stored online);
[0095] The user terminal (the password program or password module or password component that implements the ECDSA digital signature function in it) submits the security token or the information for obtaining the security token to the signature assistance device or system;
[0096] If the information for obtaining the security token is submitted to the signature assistance device or system, the signature assistance device or system uses this information for obtaining to obtain the security token issued by the application service system;
[0097] The signature assistance device or system verifies the validity of the security token (such as verifying the validity of the asymmetric key or symmetric key digital signature of the security token, as well as the time validity, where the key digital signature is called HMAC), and then, the user terminal (the password program or password module or password component that implements the ECDSA digital signature function in it) and the signature assistance device or system use the S according to the ECDSA digital signature generation method based on the ciphertext private key described above U To generate a digital signature for the message M.
[0098] The ways for the application service system to pass the security token or the information for obtaining the security token to the password program or password module or password component that implements the ECDSA digital signature function in the user terminal include:
[0099] If the client program used by the user to access the application service system and the password program or password module or password component that implements the ECDSA digital signature function are located in the same user terminal, the application service system passes the security token or the information for obtaining the security token to the password program or password module or password component that implements the ECDSA digital signature function in the user terminal through the client program;
[0100] Alternatively, if the client program used by the user to access the application service system is located on a different user terminal from the cryptographic program or cryptographic module or cryptographic component that implements the ECDSA digital signature function, the application service system displays a barcode (QR code, multi-dimensional code) through the client program used by the user, and then, in the way of the user using the user terminal to scan the code, transfers the security token or the information for obtaining the security token to the cryptographic program or cryptographic module or cryptographic component that implements the ECDSA digital signature function in the user terminal;
[0101] Alternatively, if the user terminal is a mobile communication terminal (such as a mobile phone), the application service system sends a short message through the user's mobile communication terminal, and starts the cryptographic program that implements the ECDSA digital signature function in the user's mobile communication terminal through the information contained in the short message (such as URL Schema), and transfers the security token or the information for obtaining the security token to the cryptographic program that implements the ECDSA digital signature function in the user's mobile communication terminal automatically or by the user inputting the information in the short message through the start information (such as URL Schema).
[0102] In the above security enhancement solution for preventing S U Based on the above security enhancement solution for preventing S from being stolen, a security enhancement solution for the ECDSA digital signature generation method based on the ciphertext private key is as follows:
[0103] The homomorphic encryption algorithm corresponding to the homomorphic encryption operation E(·) is a fully homomorphic encryption algorithm;
[0104] When the application service system issues a security token to the user (terminal), it randomly selects an integer k0 within [1, n - 1], calculates R0 = k0G, c0 = E((k0) -1 ) or c0 = E(k0), where (k0) -1 is the modular multiplicative inverse of k0 modulo n, and then transfers R0 together with the security token to the signature assistance device or system through the user terminal. R0 is protected by the security token (for example, the hash value of R0 is part of the security token, or R0 is part of the security token), and transfers c0 or the information for obtaining c0 to the user terminal;
[0105] If the user terminal receives the information for obtaining c0, the user terminal uses this information to obtain c0;
[0106] After verifying the validity of the received security token, the signature assistance device or system determines the validity of R0 through the security token;
[0107] The user terminal or the signature assistance device or system calculates the hash value e of the message M;
[0108] The user terminal randomly selects an integer k1 within the range [1, n - 1], and the signature assistance device or system randomly selects an integer k2 within the range [1, n - 1];
[0109] The user terminal and the signature assistance device or system complete the following calculations without revealing their respective secrets k1 and k2:
[0110] The user terminal, while ensuring that the signature assistance device or system does not re - select k2, calculates R = k1k2R0 through interaction with the signature assistance device or system;
[0111] The signature assistance device or system, while ensuring that the user terminal does not re - select k1, calculates R f = k1k2R0;
[0112] Or,
[0113] The user terminal, while ensuring that the signature assistance device or system does not re - select k2, calculates R = (k1 + k2)R0 through interaction with the signature assistance device or system;
[0114] The signature assistance device or system, while ensuring that the user terminal does not re - select k1, calculates R f = (k1 + k2)R0;
[0115] If R and / or R f is the zero element (infinity point), then the user terminal, the signature assistance device or system re - select k1 and k2, and recalculate R and R f , until R and R f are not the zero element;
[0116] The user terminal calculates r = x R mod n, where x R is taken from (x R , y R ) = R;
[0117] The signature assistance device or system calculates r f = x Rf mod n, where x Rf is taken from (x Rf , y Rf ) = R f ;
[0118] The user terminal and the signature assistance device or system check whether r and / or r f is 0 (the integer 0). If so, the user terminal and the signature assistance device or system re - select k1 and k2, recalculate R and R f , and recalculate r and rf , until both r and r f are not zero;
[0119] The user terminal and the signature assistance device or system respectively check whether (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0 will occur, that is, whether s = 0 will occur, where s is the parameter s in the digital signature (r, s) to be calculated and generated;
[0120] If so, the user terminal and the signature assistance device or system re - select k1, k2, recalculate R, R f , recalculate r, r f , until (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0 does not occur, or transfer to error handling;
[0121] If (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0 does not occur, then perform subsequent calculation processing;
[0122] The user terminal calculates s1 in one of the following ways:
[0123] Calculation method five of s1:
[0124] R, R f The calculation formulas adopted are R = k1k2R0, R f = k1k2R0, c0 = E((k0) -1 );
[0125] The user terminal uses e, r, S U , c0, k1 to calculate through the homomorphic encryption algorithm:
[0126] s1 = E((k0k1) -1 (e + rd U )(mod n)), where (k0k1) -1 is the multiplicative inverse of k0k1 (or (k0k1) mod n) modulo n;
[0127] Calculation method six of s1:
[0128] R, R f The calculation formulas adopted are R = k1k2R0, R f = k1k2R0, c0 = E((k0) -1));
[0129] The signature assistance device or system calculates c2 = E((k2) -1 ), where (k2) -1 is the modular multiplicative inverse of k2 modulo n, and sends c2 to the user terminal;
[0130] The user terminal uses e, r, S U , c0, k1, c2 to calculate through the homomorphic encryption algorithm:
[0131] s1 = E((k0k1k2) -1 (e + rd U )(mod n)), where (k0k1k2) -1 is the modular multiplicative inverse of k0k1k2 (or (k0k1k2) mod n) modulo n;
[0132] Calculation method seven of s1:
[0133] R, R f The calculation formula adopted is R = (k1 + k2)R0, R f = (k1 + k2)R0, c0 = E(k0);
[0134] The signature assistance device or system calculates c2 = E(k2), and sends c2 to the user terminal;
[0135] The user terminal randomly selects an integer b within [1, n - 1], and uses b, e, r, S U , c0, k1, c2 to calculate through the homomorphic encryption algorithm:
[0136] s 10 = E(bk0(k1 + k2)(mod n)), s 11 = E(b(e + rd U )(mod n));
[0137] s 10 , s 11 The numerical pair (s 10 , s 11 ) constitutes s1;
[0138] After calculating s1, the user terminal sends s1 to the signature assistance device or system;
[0139] If the private key SK1 corresponding to the decryption operation of the public key used in the encryption operation E(·) of the homomorphic encryption algorithm is encrypted as the ciphertext T sk1 by the key of the signature assistance device or system, then the user terminal also sends T sk1 to the signature assistance device or system, and the signature assistance device or system decrypts T sk1Obtain the private key SK1 corresponding to the decryption operation of the public key used in the encryption operation E(·) of the homomorphic encryption algorithm;
[0140] For s1 calculation method five, the signature assistance device or system decrypts s1 using the private key SK1 to obtain the plaintext s of s1 12 , calculate s = ((k2) -1 s 12 ) mod n;
[0141] For s1 calculation method six, the signature assistance device or system decrypts s1 using the private key SK1 to obtain the plaintext s of s1 12 , calculate s = s 12 mod n;
[0142] For s1 calculation method seven, the signature assistance device or system decrypts s in the numerical pair s1 10 、s 11 , and respectively obtains the plaintext s of s 10 , the plaintext 1s of s1 12 , calculate s = ((s 13 ) 12 ) -1 s 13 ) mod n, where (s 12 ) -1 is the modular multiplicative inverse of s 12 modulo n;
[0143] The signature assistance device or system returns s to the user terminal; before returning s to the user terminal, the signature assistance device or system verifies whether s is calculated according to the calculation method of ECDSA using e, k0, k1, k2, r f and the private key d corresponding to the public key Q U , if so, continue, if the verification fails, transfer to error handling; U
[0144] The user terminal verifies whether s is calculated according to the calculation method of ECDSA digital signature using e, k0, k1, k2, r and the private key d corresponding to the public key Q U U , if the verification passes, (r, s) is the digital signature of the message M, otherwise, transfer to error handling; -1
[0145] (For s1 calculation methods five and six, s = ((k0k1k2) -1 (e + rd U )) mod n, for s1 calculation method seven, s = (((k1 + k2)k0) -1 (e + rd U )) mod n)
[0146] Before the signature assistance device or system assists the user terminal in generating a digital signature, it authenticates and confirms that the user of the user terminal, i.e., the signer, is the owner of the public key Q U or the system (such as an application service system) that relies on invoking the signature assistance device or system first authenticates and confirms that the user of the user terminal, i.e., the signer, is the owner of the public key Q U (Of course, the security token can include this effect at the same time, but this is not necessary).
[0147] The user terminal and the signature assistance device or system, while ensuring that the other party does not reselect k2 and k1, obtain R = k1k2R0, R f = k1k2R0 or R = (k1 + k2)R0, R f = (k1 + k2)R0 through interactive calculation, in the same way as the user terminal and the signature assistance device or system obtain R = k1k2G, R f = k1k2G or R = (k1 + k2)G, R f = (k1 + k2)G while ensuring that the other party does not reselect k2 and k1, just that R0 replaces G here (R0 is not a secret);
[0148] The signature assistance device or system verifies whether s is calculated using the private key d corresponding to e, k0, k1, k2, r f and the public key Q U according to the calculation method of ECDSA, and the user terminal verifies whether s is calculated using the private key d corresponding to e, k0, k1, k2, r and the public key Q U according to the calculation method of ECDSA digital signature, and can adopt the same verification method as when there is no k0 (because the verification method does not use specific k0, k1, k2). U corresponding to the private key d U
[0149] Based on the security enhancement scheme described above, a scheme to prevent the security token from being stolen is as follows:
[0150] When the application service system issues a security token to the user (terminal), it randomly selects an integer w within [1, n - 1] as a perturbation parameter, encrypts w into ciphertext data that can only be decrypted by the signature assistance device or system (such as encrypting with the public key of the signature assistance device or system, or there is a shared secret between the application service system and the signature assistance device or system from which an encryption key is derived), and then passes the ciphertext data of w together with the security token to the signature assistance device or system through the user terminal. The plaintext or ciphertext data of w is protected by the security of the security token (such as the hash value of w or the ciphertext data of w is part of the security token, or the ciphertext data of w is part of the security token);
[0151] After the signature assistance device or system verifies the validity of the received security token, it decrypts the ciphertext of the perturbation parameter w to obtain the plaintext of w, and at the same time determines the validity of the plaintext or ciphertext of w through the security token;
[0152] After that, the user terminal and the signature assistance device or system generate a digital signature (r, s) for the message M according to the ECDSA digital signature generation method based on the ciphertext private key described above;
[0153] The signature assistance device or system calculates s w =(s + w) mod n or s w =(s - w) mod n, and obtains the perturbed digital signature (r, s w );
[0154] (r, s w ) is submitted or returned to the application service system without passing through the user terminal;
[0155] The application service system calculates s = (s w - w) mod n or s = (w -1 s w ) mod n, where w -1 is the multiplicative inverse of w modulo n, and restores the digital signature (r, s) for the message M.
[0156] The above solution can prevent the security token from being stolen, because only the application service system that signs the security token can obtain the correct digital signature.
[0157] For the ciphertext S U in the above various solutions, it can be encrypted again (double encryption) to become the ciphertext T U (double encryption). If S U is encrypted again to become the ciphertext T U and stored in the user terminal, then when generating a digital signature for the message M, the user terminal decrypts the ciphertext data T U of the re-encrypted S U to obtain S U (note that S U itself is also a ciphertext). The re-encryption of S U here is to solve the storage security of S U and prevent it from being misused after being stolen. U Combining the security token with the method of re-encrypting S
[0158] , there is a further security enhancement solution for the ECDSA digital signature generation method based on the ciphertext private key as follows: U
[0159] S U After being encrypted by (symmetric key or public key), it becomes ciphertext data T U ; The key SK2 (symmetric key or private key) used to decrypt the ciphertext data T U After being encrypted by (using symmetric key or public key), it becomes ciphertext data T sk2 The signature assistance device or system has a key SK3 (symmetric key or private key) for decrypting the ciphertext data T sk2 ; The ciphertext data T U and the ciphertext data T sk2 are stored in the user terminal;
[0160] When the user (uses a program in the user terminal or other terminals) accesses the application service system and needs to use the user's ECDSA signature private key to perform a digital signature on the message M, the application service system issues a security token to the user; The application service system (such as through a client program or other means) transmits the security token or the acquisition information of the security token to the password program or password module or password component in the user terminal that implements the ECDSA digital signature function;
[0161] The user terminal (the password program or password module or password component in it that implements the ECDSA digital signature function) transmits the security token or the acquisition information of the security token and T sk2 to the signature assistance device or system;
[0162] If what is submitted to the signature assistance device or system is the acquisition information of the security token, the signature assistance device or system uses this acquisition information to obtain the security token issued by the application service system;
[0163] After the signature assistance device or system verifies the validity of the security token (such as verifying the validity of the asymmetric key or symmetric key digital signature of the security token, and the time validity, where the symmetric key digital signature is such as HMAC), it uses the key SK3 to decrypt the ciphertext data T sk2 to obtain the key SK2, and returns the key SK2 to the user terminal;
[0164] The user terminal (the password program or password module or password component in it that implements the ECDSA digital signature function) uses the key SK2 to decrypt the ciphertext data T U to obtain S U (S U is the ciphertext of homomorphic encryption), and then the user terminal and the signature assistance device or system generate a digital signature for the message M using S U according to the ECDSA digital signature generation method based on ciphertext private key described above.
[0165] How does the signature assistance device or system, or the system (such as the application service system) that calls the signature assistance device or system, confirm that the user is the public key QU The owner of which does not belong to the content of the present invention. The possible ways in specific implementation include: a signature assistance device or system, or a system that invokes a signature assistance device or system, manages and maintains a user account, and a public key Q of the user is stored in the user account. U ; or the user's account is bound to the user's digital certificate, and the user's public key Q is in the user digital certificate. U .
[0166] For the above-mentioned ECDSA digital signature generation method based on ciphertext private key, the generation and distribution methods of the user's ECDSA signature key pair include:
[0167] Method 1:
[0168] Generate the ECDSA signature key pair Q U , d U by a trusted program in the user terminal, encrypt the signature private key d U to obtain the ciphertext S U , discard d U , and then securely store S U (and Q U ); the trusted program is a program provided by a cryptographic program or cryptographic module developer, or a cryptographic service provider (after security testing and evaluation);
[0169] Method 2:
[0170] Generate the ECDSA signature key pair Q U , d U by a trusted program in another terminal (such as a script program in a browser), encrypt the signature private key d U to obtain the ciphertext S U , discard d U , and then transmit S U (and Q U ) to the user terminal for saving by scanning a barcode (such as a QR code or multi-dimensional code); the other terminal refers to a computing device other than the user terminal for storing and using S U ;
[0171] Method 3:
[0172] Generate the ECDSA signature key pair Q U , d U by a key generation device or system, encrypt the signature private key d U to obtain the ciphertext S U , discard d U , and then transmit S U (and Q U ) to the user terminal for saving in a secure manner;
[0173] Method 4:
[0174] The key generation device or system randomly selects an integer d1 within [1, n - 1], encrypts d1 using the homomorphic encryption algorithm to obtain S U1 = E(d1), calculates Q U1 = d1G, and sends S U1 , Q U1 to the user terminal;
[0175] The user terminal randomly selects an integer d2 within [1, n - 1], and uses the homomorphic encryption algorithm and S U1 to calculate S U = E(d1d2), calculates Q U = d2Q U1 ;
[0176] Without exposing d1d2, the user terminal verifies that d1d2 is congruent modulo n to an ECDSA signature private key d U within [1, n - 1], i.e., d1d2 = d U (mod n), and there is Q U = d U G, i.e., verifies that d U = (d1d2) mod n and Q U = d U G;
[0177] Method 5:
[0178] The key generation device or system randomly selects an integer d1 within [1, n - 1], encrypts d1 using the homomorphic encryption algorithm to obtain S U1 = E(d1), calculates Q U1 = d1G, and sends S U1 , Q U1 to the user terminal;
[0179] The user terminal randomly selects an integer d2 within [1, n - 1], and calculates Q U = d2G + Q U1 ; Checks whether Q U is the zero element (the infinite point of the elliptic curve point group). If so, the key generation device or system randomly selects an integer d1 within [1, n - 1] again, recalculates S U1 , Q U1 , and the user terminal randomly selects an integer d2 within [1, n - 1] again, calculates Q U = d2G + Q U1 , Q U until it is a non - zero element;
[0180] The user terminal uses a homomorphic encryption algorithm and S U1 to calculate S U = E(d1 + d2);
[0181] Without exposing d1 + d2, the user terminal verifies that d1 + d2 is congruent modulo n to an ECDSA signature private key d within [1, n - 1], that is, d1 + d2 = d U (mod n), and there is Q U = d U G, that is, it is verified that d U = (d1 + d2) mod n and Q U = d U G; U G;
[0182] For the above-mentioned ECDSA signature private key generation and distribution methods, if the public key of the homomorphic encryption algorithm used to encrypt d U or d1d2 or d1 + d2 is temporarily generated, then the device, system or program that generates d U or d1 uses a symmetric key or a public key to encrypt the private key SK1 of the homomorphic encryption algorithm corresponding to the decryption operation, and obtains the ciphertext T of SK1 sk1 , where encrypting SK1 with a public key is applicable to all five ECDSA signature key pair generation and distribution methods, and encrypting SK1 with a symmetric key is only applicable to ECDSA signature key pair generation and distribution methods three, four, and five.
[0183] Usually, the program, device or system that generates the ECDSA signature private key will use the generated signature private key to sign information such as a Certificate Signing Request (CSR) that proves the user's possession of the corresponding public key, and establish an initial connection between the user and the public key.
[0184] Based on the above ECDSA digital signature generation method based on ciphertext private key, a corresponding ECDSA digital signature generation system based on ciphertext private key can be constructed. The system includes a signature assistance device or system, a password program or password module or password component in the user terminal; the user terminal stores the ciphertext S of the user's ECDSA signature private key d U of U; When it is necessary to use the user's ECDSA signature private key to perform a digital signature on message M, the password program or password module or password component in the user terminal, as well as the signature assistance device or system, cooperate to generate a digital signature for message M according to the aforementioned ECDSA digital signature generation method based on the ciphertext private key, where the password program or password module or password component in the user terminal implements the operations and processes executed by the user terminal in the aforementioned ECDSA digital signature generation method based on the ciphertext private key. Further, the system may also include a key generation device or system and a trusted program for generating the ECDSA signature key pair.
[0185] As can be seen from the above description, based on the solution of the present invention, the user's signature private key d for generating the ECDSA digital signature U is encrypted and stored and used by the user entirely in the form of ciphertext S U and no other entity has a secret share of the signature private key d U That is, the user's digital signature (electronic signature) production data d U belongs exclusively to the user. When generating a digital signature, the signature production data d U is completely controlled by the user (terminal). At the same time, the present invention also has various solutions to further ensure the secure use and storage of the ciphertext private key. Therefore, the storage and use of the signature production data of the present invention better comply with the Electronic Signature Law of the People's Republic of China, and its storage and use are strictly protected by security, and the generated digital signature is secure. BRIEF DESCRIPTION OF THE DRAWINGS
[0186] Figure 1 is a schematic diagram of the basic structure and application of the system of the present invention.
[0187] Figure 2 is a schematic diagram of the central deployment scenario of the signature assistance device or system of the present invention.
[0188] Figure 3 is a schematic diagram of the distributed deployment scenario of the signature assistance device or system of the present invention.
[0189] Figure 4 is a schematic diagram of the independent deployment scenario of the signature assistance device or system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0190] The following describes the specific embodiments of the present invention. The following content is only an illustration of the possible embodiments of the present invention and does not limit the protection scope of the present invention.
[0191] The implementation of the present invention uses homomorphic encryption algorithms, which can be additive homomorphic encryption algorithms (such as the Paillier algorithm) and fully homomorphic encryption algorithms (such as BGV, BFV, CKKS), and can be exact homomorphic encryption algorithms (such as Paillier, BGV, BFV) or approximate homomorphic encryption algorithms (such as CKKS). For the approximate homomorphic encryption algorithm, after decrypting to obtain the data, its absolute value is rounded to the nearest integer, and the sign bit remains unchanged.
[0192] In the following description, represents the multiplication of two ciphertext numbers of homomorphic encryption, and the result corresponds to the ciphertext number of the product of the multiplication of two corresponding plaintext numbers; represents the addition of two ciphertext numbers of homomorphic encryption, and the result corresponds to the ciphertext number of the sum of the addition of two corresponding plaintext numbers; ⊙ represents the multiplication of a plaintext number and a ciphertext number in homomorphic encryption, and the result corresponds to the ciphertext number of the product of the multiplication of two corresponding plaintext numbers.
[0193] In the homomorphic encryption operation of the present invention, E(a (mod n)) often appears, where a is an integer, and a (mod n) represents a number congruent to a modulo n. In the present invention, the number congruent to a modulo n is used instead of directly using a. This is to avoid the secret being cracked by directly decomposing a when a is the operation result of two or more secret numbers (confidential numbers) (such as a product). For example, a = pq. Since the number of digits of p and q is relatively small (relatively speaking, not very large numbers), it is relatively easy to decompose p and q from a, which will lead to the cracking of p and q. However, if a number congruent to a modulo n is used, this will increase the difficulty of directly cracking p and q or make it computationally impossible.
[0194] A specific scheme for implementing E(a (mod n)) is as follows (certainly not all possibilities):
[0195] The calculation of E(a (mod n)) is changed to the calculation of where z is a randomly selected integer (not limited to an integer selected within [1, n - 1]) during the calculation process (such as in the signature device), or an integer calculated from a randomly selected integer (z can be positive, negative, or zero). The selection principle of z is: to make the plaintext number to be encrypted, that is, a + zn, not exceed the representation range of the encrypted integer of the homomorphic encryption algorithm E(·), or the probability of exceeding the representation range of the encrypted integer of the homomorphic encryption algorithm E(·) is extremely small (the exceeding probability is within the specified range) (the encrypted operation E(·) of the homomorphic encryption algorithm represents positive, negative, and zero with complementary numbers. If the modulus of the encrypted integer of E(·) is m, then m is divided into two parts, where the lower half part represents positive integers and zero, and the upper half part represents negative integers, similar to the complement code in binary numbers).
[0196] When generating a digital signature for message M, there are seven ways to calculate s1 in the present invention. The first four of them are basic calculation methods, and the last three are enhanced calculation methods for s1 when an application service system participates in digital signature generation. How these calculation methods are specifically implemented is related to whether the homomorphic encryption algorithm adopted by E(·) is an additive homomorphic encryption algorithm or a fully homomorphic encryption algorithm. The following gives an explanation of how the four s1 calculation methods are specifically implemented.
[0197] For the first s1 calculation method, the user terminal can use b, e, r, S U , k1, and calculate s through homomorphic encryption in the following way 11 = E(b + (k1) -1 rd U (mod n)), or s 11 = E((k1) -1 (b + rd U )(mod n)), or, s 11 = E((k1) -1 (r(d U + b))(mod n)):
[0198] Calculate s 01 = ((k1) -1 r) mod n, s 02 = ((k1) -1 b) mod n,;
[0199] For the first s 11 formula, calculate
[0200] For the second s 11 formula, calculate
[0201] For the third s 11 formula, calculate
[0202] s 10 directly calculate; s 10 、s 11 The numerical pair (s 10 , s 11 ) constitutes s1.
[0203] For the second s1 calculation method, the user terminal can use e, r, S U , k1, and calculate s1 = E((k1) -1 (e + rd U )(mod n)) through homomorphic encryption:
[0204] s 10 = ((k1) -1 e) mod n, s 11 = ((k1) -1 r) mod n,
[0205] Alternatively, if E(·) is the encryption operation of a fully homomorphic encryption algorithm, then:
[0206] s 10 = ((k1) -1 e) mod n, s 11 = ((k1) -1 r) mod n,
[0207] For the third calculation method of s1, the homomorphic encryption algorithm corresponding to E(·) is a fully homomorphic encryption algorithm, and the user terminal can use e, r, S U , k1, c2, where c2 = E((k2) -1 ), and calculate s1 = E((k1k2) -1 (e + rd U )(mod n)) through homomorphic encryption as follows:
[0208] s 10 = ((k1) -1 e) mod n, s 11 = ((k1) -1 r) mod n,
[0209] Or,
[0210] s 10 = ((k1) -1 e) mod n, s 11 = ((k1) -1 r) mod n,
[0211] For the fourth calculation method of s1, the user terminal can use b, e, r, S U , k1, c2, where c2 = E(k2), and calculate s 10 = E(b(k1 + k2)(mod n)), s 11 = E(b(e + rd U )(mod n)) as follows:
[0212] s 01 = (bk1) mod n, s 02 = (be) mod n, s 03=(br) mod n;
[0213]
[0214] Alternatively, the homomorphic encryption algorithm corresponding to E(·) is a fully homomorphic encryption algorithm.
[0215]
[0216] s 10 and s 11 The numerical pair (s 10 , s 11 ) constitutes s1.
[0217] For the fifth calculation method of s1, the encryption algorithm corresponding to E(·) is a fully homomorphic encryption algorithm. The user terminal can use e, r, S U , c0, k1, where c0 = E((k0) -1 ), and calculate s1 = E((k0k1) -1 (e + rd U )(mod n)) through homomorphic encryption as follows:
[0218] s 10 = ((k1) -1 e) mod n, s 11 = ((k1) -1 r) mod n.
[0219] Or,
[0220] Or,
[0221] For the sixth calculation method of s1, the encryption algorithm corresponding to E(·) is a fully homomorphic encryption algorithm. The user terminal can use e, r, S U , c0, k1, c2, where c0 = E((k0) -1 ), c2 = E((k2) -1 ), and calculate s1 = E((k0k1k2) -1 (e + rd U )(mod n)) through homomorphic encryption as follows:
[0222] s 10 = ((k1) -1 e) mod n, s 11 = ((k1) -1 r) mod n.
[0223]
[0224] Alternatively,
[0225] For the seventh calculation method of s1, the user terminal can utilize b, e, r, S U , c0, k1, c2, where c0 = E(k0) and c2 = E(k2), and calculate s in the following manner through homomorphic encryption 10 = E(bk0(k1 + k2)(mod n)), s 11 = E(b(e + rd U )(mod n)):
[0226] s 01 = (bk1) mod n, s 02 = (be) mod n, s 03 = (br) mod n;
[0227]
[0228] Or, the homomorphic encryption algorithm corresponding to E(·) is a fully homomorphic encryption algorithm,
[0229]
[0230] s 10 、s 11 The numerical pair (s 10 , s 11 ) constitutes s1.
[0231] In the specific implementation of the present invention, the method for encrypting d U and decrypting the ciphertext S U is related to the deployment method of the signature assistance device or system, and is related to the generation and distribution method of the user's ECDSA signature key pair.
[0232] The signature assistance device or system may include the following deployment methods:
[0233] (1) Centralized deployment, which is centrally deployed by a professional cryptographic service institution, such as being centrally deployed in the form of cloud services, and provides digital signature services for different customers, users, and applications;
[0234] (2) Distributed deployment, which is distributedly deployed by a professional cryptographic service institution, and provides digital signature services for customers, users, and applications in different places and regions;
[0235] (3) Independent deployment, where each enterprise, institution, or application system deploys its own signature assistance device or system, and provides digital signature services for its own customers, users, and applications.
[0236] Regardless of the deployment method adopted by the signature assistance device or system, the above-mentioned five methods for generating and distributing ECDSA signature key pairs can be implemented. Of course, other methods for generating and distributing ECDSA signature key pairs can also be implemented, and the present invention places no restrictions on this, as long as the relevant security requirements are met.
[0237] In a specific implementation, if a key generation device or system is used to generate or participate in generating the user's ECDSA signature private key d U (or ECDSA signature key pair), the key generation device or system is usually implemented as a server-side device or system, but a user-side device such as a USB Key can also be used. The server-side key generation device or system can be specifically implemented as a plug-and-play cryptographic hardware (such as a cryptographic card) or a software and hardware combination device or system (such as a cryptographic machine, a cryptographic server).
[0238] If, in a specific implementation, the server-side key generation device or system generates and distributes (including separately generating and jointly generating) the ECDSA signature key pair, the key generation device or system can also adopt a central deployment, distributed deployment, or independent deployment method. Among them, independent deployment is mainly used for providing dedicated key services for institutions and enterprises. At this time, the users of the ECDSA signature key pair are usually only the customers and users of the institutions and enterprises themselves.
[0239] If, in a specific implementation, the trusted program in the user terminal generates the ECDSA signature key pair, the corresponding program can be provided by the developer of the cryptographic program or module, or the cryptographic service provider, and it is ensured that the program is executed in a secure user terminal environment, such as ensuring that there is no Trojan in the user terminal, or executing in a trusted execution environment (TEE).
[0240] If, in a specific implementation, the program in another terminal generates the ECDSA signature key pair, the corresponding program can be provided by the developer of the cryptographic program or module, or the cryptographic service provider, for generating the ECDSA signature key pair, and the ciphertext S U of the signature private key d U and other parameters and data (such as the public key Q U ) are transmitted to the user terminal. Or, the user can use the browser in another terminal to access a dedicated trusted website, and the script program returned by the trusted website generates the ECDSA signature key pair in the browser, and then the ciphertext S U of the signature private key d U and other parameters and data are transmitted to the user terminal.
[0241] The following describes the implementation modes related to the encryption of d and the decryption of the ciphertext S in combination with the implementation modes of the signature assistance device or system and the generation and distribution of the ECDSA signature key pair. U Encryption and for the ciphertext S U Related implementation modes of decryption.
[0242] Regardless of the deployment mode and implementation mode adopted by the signature assistance device or system, and regardless of the implementation mode and deployment mode adopted for the generation and distribution of the ECDSA signature key pair, for the U Encryption and for the ciphertext S U Key pair of the homomorphic encryption algorithm for decryption can either be pre-existing in the signature assistance device or system or be U Temporarily generated during encryption (by the key pair generation program or device or system).
[0243] If the key pair of the homomorphic encryption algorithm for U Encryption and for S U Decryption is pre-existing in the signature assistance device or system, then the following are some possible implementation scenarios:
[0244] For U Encryption and for S U The key pair of the homomorphic encryption algorithm for decryption is pre-existing in the signature assistance device or system, and the signature assistance device or system adopts a central deployment implementation mode. Then, for U Encryption is usually performed using the public key in a public key pair of a homomorphic encryption algorithm of the signature assistance device or system (the public key pair means that multiple signature assistance devices or systems share one key pair). The private key SK1 of the homomorphic encryption algorithm for decrypting the U Ciphertext S U Is the private key in this public key pair of the homomorphic encryption algorithm. At this time, the generation and distribution of the ECDSA signature key pair can adopt any implementation mode and deployment mode;
[0245] For U Encryption and for S U The key pair of the homomorphic encryption algorithm for decryption is pre-existing in the signature assistance device or system, and the signature assistance device or system adopts a distributed deployment implementation mode. Then, the public key in a public key pair of a homomorphic encryption algorithm of the signature assistance device or system can be used to perform U Encryption on d (that is, multiple signature assistance devices or systems in distributed deployment share one key pair). The private key SK1 of the homomorphic encryption algorithm for decrypting the U Ciphertext S U Is the private key in this public key pair of the homomorphic encryption algorithm. At this time, the generation and distribution of the ECDSA signature key pair can adopt any implementation mode and deployment mode;
[0246] ForU Encryption and for S U The key pair of the homomorphic encryption algorithm for decryption is pre-existing in the signature assistance device or system, and if the signature assistance device or system adopts an independently deployed implementation method, then usually the public key in a key pair of a homomorphic encryption algorithm of the independently deployed signature assistance device or system is used to encrypt d U Encrypt to obtain S U , at this time, the generation and distribution of the ECDSA signature key pair can adopt any implementation method and deployment method. However, the program and system used to generate and distribute the ECDSA signature key pair need to be configured with or customized to use the public key of the corresponding homomorphic encryption algorithm for the independently deployed signature assistance device or system.
[0247] For d U Encryption and for S U If the key pair of the homomorphic encryption algorithm for decryption is pre-existing in the signature assistance device or system, the following is a special explanation for the following implementation situations:
[0248] The signature assistance device or system is independently deployed in different institutions and enterprises, and they belong to different institutions and enterprises. However, the user's ECDSA signature private key (and the corresponding digital certificate) may need to be used in the application systems of different institutions and enterprises. For example, the ECDSA signature private key corresponds to a digital certificate trusted by each institution and enterprise, and the certificate and private key are used in the application systems of different institutions. That is, the signature assistance devices or systems independently deployed by different institutions and enterprises may all need to decrypt s1 and T generated by the user terminal of the same user during the generation of digital signatures. sk1 , in this regard, the following method is a method that can be adopted (but not the only possible method):
[0249] The user's S U Is only bound to the signature assistance device or system of one institution or enterprise. When the user needs to use S U To generate a digital signature, no matter which institution or enterprise's system the user (terminal) is interacting with, the user terminal only interacts with the bound signature assistance device or system to generate a digital signature.
[0250] If for d U Encryption and for S U The key pair of the homomorphic encryption algorithm for decryption is generated temporarily, then the following are some possible implementation situations:
[0251] For d U Encryption and for S UThe key pair of the decrypted homomorphic encryption algorithm is generated temporarily, and the public key encryption algorithm is used to encrypt the private key SK1. If the signature assistance device or system adopts a centralized deployment implementation method, usually the public key in a public key pair of the signature assistance device or system is used to encrypt SK1 (the public key pair means that multiple signature assistance devices or systems share a key pair). At this time, the generation and distribution of the ECDSA signature key pair can adopt any implementation method and deployment method;
[0252] For d U Encryption and for S U The key pair of the decrypted homomorphic encryption algorithm is generated temporarily, and the public key encryption algorithm is used to encrypt the private key SK1. If the signature assistance device or system adopts a distributed deployment implementation method, the public key in a public key pair of the signature assistance device or system can be used to encrypt SK1 (that is, multiple distributed signature assistance devices or systems share a key pair), or a group public key can be used to encrypt SK1 using a group-oriented encryption algorithm (that is, multiple distributed signature assistance devices or systems belong to a group, and group members can have their own private keys). At this time, the generation and distribution of the ECDSA signature key pair can adopt any implementation method and deployment method.
[0253] For d U Encryption and for S U The key pair of the decrypted homomorphic encryption algorithm is generated temporarily, and the public key encryption algorithm is used to encrypt the private key SK1. If the signature assistance device or system adopts an independent deployment implementation method, usually the public key in a key pair of the independently deployed signature assistance device or system is used to encrypt SK1. At this time, the generation and distribution of the ECDSA signature key pair can adopt any implementation method and deployment method. However, the program and system used to generate and distribute the ECDSA signature key pair need to be configured with or customized to use the corresponding public key for the independently deployed signature assistance device or system;
[0254] For d U Encryption and for S U The key pair of the decrypted homomorphic encryption algorithm is generated temporarily, and the symmetric key encryption algorithm is used to encrypt the private key SK1. At this time, the generation and distribution of the ECDSA signature key pair need to adopt the implementation method of being generated and distributed by the key generation device or system of the server (including the implementation methods of being generated and distributed separately or collaboratively), and the key generation device or system needs to share the symmetric key with the corresponding signature assistance device or system that needs to decrypt T sk1 of the signature assistance device or system.
[0255] If for d U Encryption and for S UThe key pair of the decrypted homomorphic encryption algorithm is generated temporarily. Therefore, the following implementation scenarios are specifically described:
[0256] The signature assistance devices or systems are independently deployed in different institutions and enterprises. They belong to different institutions and enterprises. However, the ECDSA signature private key (and the corresponding digital certificate) of the user may need to be used in the application systems of different institutions and enterprises. For example, the ECDSA signature private key corresponds to a digital certificate trusted by each institution and enterprise. The certificate and the private key are used in the application systems of different institutions, that is, the signature assistance devices or systems independently deployed by different institutions and enterprises may all face decrypting s1 and T generated by the user terminal of the same user during the generation of digital signatures. sk1 In this regard, the following two methods can be adopted (but not all possible methods):
[0257] (1) The S U and T sk1 of the user are only bound to the signature assistance device or system of one institution or enterprise. When the user needs to use S U and T sk1 to generate a digital signature, no matter which institution or enterprise's system the user (terminal) interacts with, the user terminal only interacts with the bound signature assistance device or system to generate a digital signature.
[0258] (2) The public key of the homomorphic encryption algorithm for encrypting d U is generated temporarily. The encryption of the temporarily generated private key SK1 of the homomorphic encryption algorithm adopts a group-oriented encryption method. The signature assistance devices or systems independently deployed by different institutions and enterprises are all members of the group and each has a group member private key.
[0259] If the group-oriented encryption method is adopted in the implementation, the life cycle management (generation, update, revocation) of the group key (public key, private key) is provided by the key service system of a dedicated cryptographic service institution.
[0260] In the specific implementation of the present invention, although S U is stored in the user terminal in ciphertext form, in order to prevent it from being stolen, further security protection measures can still be taken for S U stored in the user terminal, such as fingerprint protection, PIN code protection, or even re-encryption, etc.
[0261] In the implementation of the present invention, in order to prevent S UBefore the signature auxiliary device or system assists in completing the digital signature generation for the user terminal, it must pass strict and secure identity authentication, such as through SMS, identity authentication based on biometrics, or by calling the signature auxiliary device or system system such as the application service system to complete the user's identity authentication to ensure that the user is the public key Q U The owner of.
[0262] Generation and distribution methods of ECDSA signature key pairs in four and five: the user terminal verifies d1d2, d1+d2 and an ECDSA signature private key d in [1,n-1] without revealing d1d2, d1+d2 U Modulo n congruence means d1d2=d U (mod n), d1+d2=d U (mod n) and Q U =d U G, that is, verify that there is d U =(d1d2)mod n, d U =(d1+d2)mod n and Q U =d U G, there are many ways, here are some of the ways you can use.
[0263] The user terminal randomly selects an integer b in [1,n-1] and uses S U And homomorphic encryption operation to get S b =E((bd1d2)(mod n)),S b =E((b(d1+d2))(mod n)), S b Sent to the key generation device or system; the key generation device or system calculates Q b =(D(S b )mod n)G, where D(·) is the decryption operation of the private key using the homomorphic encryption algorithm (assuming that the key generation device or system is capable of completing this operation, for example, sharing a cryptographic device with the signature auxiliary device or system, or with the help of the signature auxiliary device or system); the key generation device or system converts Q b Send to user terminal; user terminal checks bQ U With Q b Are they the same? If they are the same, the verification passes; otherwise, the verification fails.
[0264] Alternatively, the user terminal randomly selects an integer b in [1, n-1] and uses S U And homomorphic encryption operation to get S b =E((d1d2+b)(mod n)),S b =E((d1+d2+b)(mod n)), Sb Send to the key generation device or system; the key generation device or system calculates Q b =(D(S b ) mod n)G, where D(·) is the decryption operation of the private key using the homomorphic encryption algorithm; the key generation device or system sends Q b to the user terminal; the user terminal checks Q U +bG and Q b whether they are the same. If they are the same, the verification passes; otherwise, the verification fails.
[0265] The security token issued by the application service system is a temporary authorization credential, which can either adopt standard security tokens (such as WS-Security security tokens, SAML assertions, security tickets, Json Web Tokens i.e. JWT, etc.), or security tokens in a custom format; the security token is signed with an asymmetric key (such as SM2, SM9, RSA, ECDSA), or a symmetric key signature (such as HMAC).
[0266] In the implementation of the present invention, if S U is encrypted again into the ciphertext T U and then T U is saved in the user terminal, this encryption (usually) is not performed in the signature assistance device or system, but (usually) is performed in the user terminal. Otherwise, the signature assistance device or system can decrypt S U to obtain d U , which obviously does not meet the security requirements and security objectives of the solution. Now the question is who generates the decryption key SK2 for T U and who completes the encryption of SK2? Notice such a simple fact that SK2 is not a secret between the user terminal and the signature assistance device or system. Therefore, SK2 and its corresponding encryption key for encrypting S U (if SK2 is a private key, the corresponding encryption key is the corresponding public key; if SK2 is a symmetric key, the corresponding encryption key is also a symmetric key) can either be generated by the user terminal (when initializing the user signature key), or (when initializing the user signature key) be generated by the signature assistance device or system and then passed to the user terminal; if the key SK3 for decrypting T sk2 is a private key, then use the corresponding public key to encrypt SK2, which can be completed either in the user terminal or in the signature assistance device or system; if the key SK3 for decrypting T sk2 is a symmetric key, then using SK3 to encrypt SK2 can be completed by the signature assistance device or system, and then the encrypted result T sk2Returned to the user terminal because SK2 is not a secret for the signature assistance device or system. The remaining question is which encryption key corresponding to SK3 of the signature assistance device or system should be used to encrypt SK2 for different deployment methods of the signature assistance device or system? A simple principle is: when performing a digital signature, use the encryption key corresponding to SK3 of the signature assistance device or system with which the user terminal interacts to encrypt SK2, where the encryption key corresponding to SK3 includes a symmetric key or a public key. If the public key includes a common public key and a group public key, then it is similar to encrypting the private key SK1 of the homomorphic encryption algorithm that is temporarily generated when the key pair of the homomorphic encryption algorithm for encrypting d U When the key pair of the homomorphic encryption algorithm for encrypting is temporarily generated, it is similar to encrypting the privately generated private key SK1 of the homomorphic encryption algorithm.
[0267] There are many keys involved in the present invention, which are confused in specific implementation: SK1 is the private key for decrypting d U The ciphertext S after homomorphic encryption U The private key, SK2 is the key for decrypting S U The ciphertext T after being encrypted again U The key, not the key T for decrypting SK1 sk1 The key for decrypting T sk1 The key (not specifically named) belongs to the signature assistance device or system, and SK2 does not belong to the key of the signature assistance device or system; SK3 is the key for decrypting the ciphertext T of SK2 sk2 The key, SK3 is the key belonging to the signature assistance device or system; there is no direct or indirect association between SK1 and SK2, SK3.
[0268] Based on the ECDSA digital signature generation method based on ciphertext private key of the present invention, a corresponding ECDSA digital signature generation system based on signature private key can be implemented. The system includes a signature assistance device or system, a password program or password module or password component in the user terminal; the user terminal stores the ciphertext S of the user's ECDSA signature private key d U The ciphertext S U ; When it is necessary to use the user's ECDSA signature private key to perform a digital signature on the message M, the password program or password module or password component in the user terminal, and the signature assistance device or system, cooperate to generate a digital signature for the message M according to the aforementioned ECDSA digital signature generation method based on ciphertext private key, where the password program or password module or password component in the user terminal implements the operation processing performed by the user terminal in the above digital signature generation method. Further, the implemented system may further include a key generation device or system for generating an ECDSA signature key pair, a trusted program.
[0269] In the implementation of the present invention, the signature assistance device or system can be a software device or system, or a device or system combining software and hardware. The software device can be an independently running program or a cryptographic module, and the device combining software and hardware can be a plug-and-play cryptographic hardware such as a cryptographic card, or a cryptographic machine / cryptographic server.
[0270] In the implementation of the present invention, the user terminal is various computing devices used by the user, such as a computer, a mobile phone, a tablet computer, etc. The user terminal implements the digital signature generation function in the user terminal of the present invention through the cryptographic program, cryptographic module or cryptographic component running therein. That is, the program implementing cryptographic functions such as digital signature in the user terminal can be an independently running cryptographic program, such as a program formed by an app or a WeChat mini-program, or a cryptographic module or cryptographic component implementing cryptographic functions such as digital signature, such as a cryptographic API, SDK, WeChat mini-program plug-in, browser plug-in or control, etc. If the program implementing cryptographic functions such as digital signature is an independently running cryptographic program, the program in the same user terminal can transfer data to the cryptographic program by using the mechanism for transferring data between programs within the computing device provided by the user terminal and program development technology; if the program implementing cryptographic functions such as digital signature is a cryptographic module or cryptographic component, the program calling the cryptographic module or cryptographic component directly transfers data to the called cryptographic module or cryptographic component; if another terminal outside the user terminal implementing the digital signature function needs to use the digital signature function in the user terminal, the program in the other terminal, such as the client program of the application service system, can transfer the call information and data to the cryptographic program, cryptographic module or cryptographic component implementing the digital signature function in the user terminal by displaying a barcode and the user scanning the code; if the user terminal is a mobile communication terminal (such as a mobile phone), the application service system can send a short message through the user's mobile communication terminal, and start the cryptographic program implementing the ECDSA digital signature function in the user's mobile communication terminal through the information contained in the short message, such as URL Schema, and transfer the security token or the information for obtaining the security token to the cryptographic program implementing the ECDSA digital signature function in the user's mobile communication terminal automatically through the URL link or by the user inputting the information in the short message.
[0271] Figure 1 It is a schematic diagram of the basic structure and application of the system of the present invention. Figure 2 It is a schematic diagram of the central deployment scenario of the signature assistance device or system of the present invention. Figure 3 It is a schematic diagram of the distributed deployment scenario of the signature assistance device or system of the present invention. Figure 4 It is a schematic diagram of the independent deployment scenario of the signature assistance device or system of the present invention.
[0272] Other specific technical implementations not described are well-known and self-evident to those skilled in the relevant art.
Claims
1. An ECDSA digital signature generation method based on ciphertext private key, characterized in that: The user terminal has Q U = d U G, has a secret S U = E(d U ), where d U is the user's ECDSA signature private key, G is the base point of the ECDSA elliptic curve point group, Q U is the public key corresponding to the user's ECDSA signature private key d U and E(·) is an encryption operation using a homomorphic encryption algorithm; The user terminal is the user's computing device; the homomorphic encryption algorithm is an additive homomorphic encryption algorithm or a fully homomorphic encryption algorithm; the signature assistance device or system has the private key SK1 for the decryption operation corresponding to the public key used in the encryption operation E(·) of the homomorphic encryption algorithm, or the private key SK1 for the decryption operation corresponding to the public key used in the encryption operation E(·) of the homomorphic encryption algorithm is encrypted into the ciphertext T by using the key of the signature assistance device or system. sk1 , where the key of the signature assistance device or system used for encrypting SK1 includes a symmetric key or a public key, and the user terminal stores the ciphertext T of the private key SK1 for the decryption operation corresponding to the public key used in the encryption operation E(·). sk1 ; the signature assistance device or system is a computing device or system that assists the user terminal in completing the generation and calculation of digital signatures. When the ECDSA signature private key d of the user needs to be used U to perform a digital signature on the message M, the user terminal and the signature assistance device or system generate a digital signature for the message M in the following manner: The user terminal calculates the hash value e of the message M using the message M and a hash function, and sends e to the signature assistance device or system. Alternatively, the signature assistance device or system calculates the hash value e of the message M using the message M and a hash function, and sends e to the user terminal; The user terminal randomly selects an integer k1 within the interval [1, n - 1], where n is the order of the base point G and n is a prime number; The signature assistance device or system randomly selects an integer k2 within the interval [1, n - 1]; The user terminal and the signature assistance device or system complete the following calculations without exposing their respective secrets k1 and k2: The user terminal, while ensuring that the signature assistance device or system does not reselect k2, calculates R = k1k2G through interaction with the signature assistance device or system; The signature assistance device or system calculates R through interaction with the user terminal while ensuring that the user terminal does not reselect k1 f = k1k2G; Or, The user terminal, while ensuring that the signature assistance device or system does not reselect k2, calculates R = (k1 + k2)G through interaction with the signature assistance device or system; The signature assistance device or system calculates R through interaction with the user terminal on the premise of ensuring that the user terminal does not reselect k1 f =(k1 + k2)G; If R and / or R f is the zero element, the user terminal, the signature assistance device or the system re-selects k1 and k2, and recalculates R and R f , until R and R f are not the zero element; The user terminal calculates r = x R mod n, where x R is taken from (x R , y R ) = R; The signature assistance device or system calculates r f = x Rf mod n, where x Rf is taken from (x Rf , y Rf ) = R f ; The user terminal and the signature assistance device or system check r and / or r f to see if they are 0. If so, the user terminal and the signature assistance device or system re-select k1 and k2, recalculate R and R f , and recalculate r and r f , until both r and r f are not 0; The user terminal and the signature assistance device or system respectively check whether (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0, that is, whether s = 0 will occur, where s is the parameter s in the digital signature (r, s) to be calculated and generated; If so, the user terminal and the signature assistance device or system reselect k1 and k2, recalculate R and R f , recalculate r and r f , until the situation where (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0 does not occur, or transfer to error handling; If (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0 does not occur, then subsequent calculation processing is performed; The user terminal calculates s1 in one of the following ways: Calculation method 1 of s1: R, R f The calculation formula adopted is R = k1k2G, R f = k1k2G; The user terminal randomly selects an integer b within [1, n - 1], and uses b, e, r, S U , and k1 to calculate through the homomorphic encryption algorithm: s 10 = ((k1) -1 e - b) mod n, s 11 = E(b + (k1) -1 rd U (mod n)), Alternatively, s 10 = ((k1) -1 (e - b)) mod n, s 11 = E((k1) -1 (b + rd U )(mod n)), Or, s 10 = ((k1) -1 (e - rb)) mod n, s 11 = E((k1) -1 (r(d U + b))(mod n)), where (k1) -1 is the multiplicative inverse of k1 modulo n; s 10 、s 11 The numerical pair (s 10 , s 11 ) constitutes s1; Calculation method 2 of s1: R, R f The calculation formula adopted is R = k1k2G, R f = k1k2G; The user terminal uses e, r, S U , and k1 is calculated through a homomorphic encryption algorithm as follows: s1 = E((k1) -1 (e + rd U )(mod n)), where (k1) -1 is the multiplicative inverse of k1 modulo n; Calculation method 3 of s1: R, R f The calculation formula adopted is R = k1k2G, R f = k1k2G; The homomorphic encryption algorithm corresponding to E(·) is a fully homomorphic encryption algorithm; The signature assistance device or system calculates c2 = E((k2) -1 ), where (k2) -1 is the modular multiplicative inverse of k2 modulo n, and sends c2 to the user terminal; The user terminal calculates using e, r, S U , k1, and c2 through a homomorphic encryption algorithm as follows: s1 = E((k1k2) -1 (e + rd U )(mod n)), where (k1k2) -1 is the multiplicative inverse of k1k2 modulo n; Calculation method 4 of s1: R, R f The calculation formula used is R = (k1 + k2)G, R f = (k1 + k2)G; The signature assistance device or system calculates c2 = E(k2) and sends c2 to the user terminal; The user terminal randomly selects an integer b within [1, n - 1], and uses b, e, r, S U , k1, and c2 to calculate through the homomorphic encryption algorithm: s 10 = E(b(k1 + k2)(mod n)), s 11 = E(b(e + rd U )(mod n)); s 10 , s 11 The numerical pair (s 10 , s 11 ) constitutes s1; After calculating s1, the user terminal sends s1 to the signature assistance device or system; If the private key SK1 of the decryption operation corresponding to the public key used in the encryption operation E(·) of the homomorphic encryption algorithm is encrypted into the ciphertext T by using the key of the signature assistance device or system sk1 and saved in the user terminal, the user terminal will also send T sk1 to the signature assistance device or system, and the signature assistance device or system decrypts T sk1 to obtain the private key SK1 of the decryption operation corresponding to the public key used in the encryption operation E(·) of the homomorphic encryption algorithm; For the first calculation method of s1, the signature assistance device or system decrypts s in the numerical pair s1 using the private key SK1 11 , to obtain the plaintext s 11 of s 12 , and calculates s = ((k2) -1 (s 10 + s 12 )) mod n; For the second calculation method of s1, the signature assistance device or system decrypts s1 using the private key SK1 to obtain the plaintext s of s1 12 , calculate s = ((k2) -1 s 12 ) mod n; For the third calculation method of s1, the signature assistance device or system decrypts s1 using the private key SK1 to obtain the plaintext s of s1 12 , calculate s = s 12 mod n; For the fourth calculation method of s1, the signature assistance device or system uses the private key SK1 to decrypt s in the numerical pair s1 10 , s 11 , respectively obtaining the plaintext s 10 of s 12 , s 11 of the plaintext s 13 , calculating s = ((s 12 ) -1 s 13 ) mod n, where (s 12 ) -1 is the modular multiplicative inverse of s 12 ; The signature assistance device or system returns s to the user terminal; before returning s to the user terminal, the signature assistance device or system verifies whether s is calculated using e, k1, k2, r f and the public key Q U and the corresponding private key d U calculated according to the calculation method of ECDSA. If so, continue; otherwise, transfer to error handling; The user terminal verifies whether s is calculated using e, k1, k2, r, and the public key Q U corresponding private key d U calculated according to the ECDSA digital signature calculation method. If the verification passes, then (r, s) is the digital signature of the message M; otherwise, transfer to error handling In the calculation formula of the encryption operation E(·) using the homomorphic encryption algorithm above, a (mod n), where a is an integer, represents the integer congruent to a modulo n; Before the signature assistance device or system assists the user terminal in completing the generation of a digital signature, it authenticates and confirms that the user of the user terminal, i.e., the signer, is the owner of the public key Q U ; or the system that relies on invoking the signature assistance device or system authenticates and confirms that the user of the user terminal, i.e., the signer, is the owner of the public key Q U ; The user terminal implements the above digital signature calculation and generation steps, and implements the ECDSA digital signature function through a password program or password module or password component that implements password functions within it.
2. The ECDSA digital signature generation method based on ciphertext private key according to claim 1, characterized in that: The user terminal and the signature assistance device or system respectively check whether the situation of (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0 will occur. A method is as follows: The user terminal checks eG+rQ U whether it is zero. If so, then (e+rd U ) mod n = 0 will occur; otherwise, it will not. The signature assistance device or system checks eG+r f Q U whether it is the zero element. If so, the situation of (e+r f d U ) mod n = 0 will occur; otherwise, it will not.
3. The ECDSA digital signature generation method based on ciphertext private key according to claim 1, characterized in that: The signature assistance device or system verifies whether s is calculated using e, k1, k2, r f and the public key Q U and the corresponding private key d U The method calculated according to the ECDSA calculation method includes: The signature assistance device or system checks and verifies whether (r f , s) is the digital signature of message M. If so, the verification passes; otherwise, the verification fails. Alternatively, the signature assistance device or system checks and verifies whether the value of sR f is the same as eG + r f Q U If so, the verification passes; otherwise, the verification fails. The user terminal verifies whether s is calculated using e, k1, k2, r, and the public key Q U the corresponding private key d U The method calculated according to the ECDSA calculation method includes: The user terminal checks and verifies whether (r, s) is the digital signature of the message M. If so, the verification passes; otherwise, the verification fails; Alternatively, the user terminal checks whether the value of sR is the same as eG + rQ U If so, the verification passes; otherwise, the verification fails.
4. The ECDSA digital signature generation method based on ciphertext private key according to claim 1, characterized in that: A method for generating an ECDSA digital signature based on a ciphertext private key to prevent S from being misappropriated, based on the method for generating an ECDSA digital signature based on a ciphertext private key described above U The method for generating an ECDSA digital signature based on a ciphertext private key When the user accesses the application service system and needs to use the user's ECDSA signature private key to perform a digital signature for the message M, the application service system issues a security token to the user; The security token is an authorization credential for requesting the signature assistance device or system to assist in, cooperate in generating, or / and calculating the digital signature; The application service system transmits the security token or the information for obtaining the security token to the password program or password module or password component that implements the ECDSA digital signature function in the user terminal; the information for obtaining the security token is the information for obtaining the security token issued by the application service system; The user terminal submits the security token or the information for obtaining the security token to the signature assistance device or system; If the information for obtaining a security token is submitted to a signature assistance device or system, the signature assistance device or system uses this information for obtaining to obtain a security token issued by an application service system; The signature assistance device or system verifies the validity of the security token. After that, the user terminal and the signature assistance device or system generate a digital signature for the message M by using the ECDSA digital signature generation method based on the ciphertext private key as described above, and utilize S U to generate a digital signature for the message M.
5. The method for generating an ECDSA digital signature based on a ciphertext private key according to claim 4, characterized in that: The ways for an application service system to transfer a security token or the information for obtaining a security token to a password program or password module or password component that implements the ECDSA digital signature function in a user terminal include: If the client program used by a user to access the application service system and the password program or password module or password component that implements the ECDSA digital signature function are located in the same user terminal, the application service system transfers the security token or the information for obtaining a security token to the password program or password module or password component that implements the ECDSA digital signature function in the user terminal through the client program; Or, if the client program used by a user to access the application service system and the password program or password module or password component that implements the ECDSA digital signature function are located in different user terminals, the application service system displays a bar code through the client program used by the user, and then transfers the security token or the information for obtaining a security token to the password program or password module or password component that implements the ECDSA digital signature function in the user terminal by means of the user scanning the code using the user terminal; Or, if the user terminal is a mobile communication terminal, the application service system sends a short message through the user's mobile communication terminal, starts the password program that implements the ECDSA digital signature function in the user's mobile communication terminal through the information contained in the short message, and transfers the security token or the information for obtaining a security token to the password program that implements the ECDSA digital signature function in the user's mobile communication terminal automatically or by means of the user inputting the information in the short message.
6. The method for generating an ECDSA digital signature based on a ciphertext private key according to claim 4, characterized in that: A security enhancement solution for the method of generating ECDSA digital signatures based on ciphertext private keys to prevent the theft described above is as follows: U A security enhancement solution for the method of generating ECDSA digital signatures based on ciphertext private keys to prevent the theft described above is as follows: The homomorphic encryption algorithm corresponding to the homomorphic encryption operation E(·) is a fully homomorphic encryption algorithm; When the application service system issues a security token to a user, it randomly selects an integer k0 within [1, n - 1], calculates R0 = k0G, c0 = E((k0) -1 ) or c0 = E(k0), where (k0) -1 is the modular multiplicative inverse of k0 modulo n, and then passes R0 together with the security token to the signature assistance device or system through the user terminal. R0 is protected by the security token, and passes c0 or the acquisition information of c0 to the user terminal; If the information for obtaining c0 is received by the user terminal, the user terminal uses this information for obtaining to obtain c0; After verifying the validity of the received security token, the signature assistance device or system determines the validity of R0 through the security token; The user terminal or the signature assistance device or system calculates the hash value e of the message M; The user terminal randomly selects an integer k1 within the interval [1, n - 1], and the signature assistance device or system randomly selects an integer k2 within the interval [1, n - 1]; The user terminal and the signature assistance device or system complete the following calculations without exposing their respective secrets k1 and k2: The user terminal, while ensuring that the signature assistance device or system does not reselect k2, calculates R = k1k2R0 through interaction with the signature assistance device or system; The signature assistance device or system calculates R through interaction with the user terminal on the condition that the user terminal does not reselect k1 f = k1k2R0; Or, The user terminal, while ensuring that the signature assistance device or system does not reselect k2, calculates R = (k1 + k2)R0 through interaction with the signature assistance device or system; The signature assistance device or system calculates R through interaction with the user terminal while ensuring that the user terminal does not reselect k1 f =(k1 + k2)R0; If R and / or R f is the zero element, the user terminal, the signature assistance device or the system reselects k1 and k2, and recalculates R and R f , until R and R f are not the zero element; The user terminal calculates r = x R mod n, where x R is taken from (x R , y R ) = R; The signature assistance device or system calculates r f = x Rf mod n, where x Rf is taken from (x Rf , y Rf ) = R f ; The user terminal and the signature assistance device or system check whether r and / or r f is 0. If so, the user terminal and the signature assistance device or system reselect k1 and k2, recalculate R and R f , and recalculate r and r f , until both r and r f are not 0; The user terminal and the signature assistance device or system respectively check whether (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0, that is, whether s = 0 will occur, where s is the parameter s in the digital signature (r, s) to be calculated and generated; If so, the user terminal and the signature assistance device or system re-select k1 and k2, recalculate R and R f , recalculate r and r f , until the situation where (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0 does not occur, or transfer to error handling; If (e + rd U ) mod n = 0 and / or (e + r f d U ) mod n = 0 does not occur, then subsequent calculation processing is performed; The user terminal calculates s1 in one of the following ways: Calculation method five for s1: R, R f The calculation formula adopted is R = k1k2R0, R f = k1k2R0, c0 = E((k0) -1 ); The user terminal uses e, r, S U , c0, and k1 to be calculated through the homomorphic encryption algorithm s1 = E((k0k1) -1 (e + rd U )(mod n)), where (k0k1) -1 is the multiplicative inverse of k0k1 modulo n; s1 Calculation Method Six: R, R f The calculation formula adopted is R = k1k2R0, R f = k1k2R0, c0 = E((k0) -1 ); The signature assistance device or system calculates c2 = E((k2) -1 ), where (k2) -1 is the modular multiplicative inverse of k2 modulo n, and sends c2 to the user terminal; The user terminal uses e, r, S U , c0, k1, c2 are calculated through the homomorphic encryption algorithm as follows: s1 = E((k0k1k2) -1 (e + rd U )(mod n)), where (k0k1k2) -1 is the multiplicative inverse of k0k1k2 modulo n; s1 Calculation Method Seven: R, R f The calculation formula used is R = (k1 + k2)R0, R f = (k1 + k2)R0, c0 = E(k0); The signature assistance device or system calculates c2 = E(k2) and sends c2 to the user terminal; The user terminal randomly selects an integer b within [1, n - 1], and calculates, through a homomorphic encryption algorithm, using b, e, r, S U , c0, k1, c2 to obtain: s 10 = E(bk0(k1 + k2)(mod n)), s 11 = E(b(e + rd U )(mod n)); s 10 、s 11 The numerical pair (s 10 , s 11 ) constitutes s1; After calculating s1, the user terminal sends s1 to the signature assistance device or system; If the private key SK1 of the decryption operation corresponding to the public key used in the encryption operation E(·) of the homomorphic encryption algorithm is encrypted into the ciphertext T by using the key of the signature assistance device or system sk1 , then the user terminal will also send T sk1 to the signature assistance device or system, and the signature assistance device or system decrypts T sk1 to obtain the private key SK1 of the decryption operation corresponding to the public key used in the encryption operation E(·) of the homomorphic encryption algorithm; For signature calculation method five of s1, the signature assistance device or system decrypts s1 using the private key SK1 to obtain the plaintext s of s1 12 , calculate s = ((k2) -1 s 12 ) mod n; For signature calculation method six of s1, the signature assistance device or system decrypts s1 using the private key SK1 to obtain the plaintext s of s1 12 , calculate s = s 12 mod n; For the seventh calculation method of s1, the signature assistance device or system uses the private key SK1 to decrypt s in the numerical pair s1 10 and s 11 , respectively obtaining the plaintext s 10 of s 12 , the plaintext s 11 of s 13 . Calculate s = ((s 12 ) -1 s 13 ) mod n, where (s 12 ) -1 is the multiplicative inverse of s 12 modulo n; The signature assistance device or system returns s to the user terminal; before returning s to the user terminal, the signature assistance device or system verifies whether s is calculated using e, k0, k1, k2, r f and the public key Q U and the corresponding private key d U calculated according to the calculation method of ECDSA. If so, continue; if the verification fails, transfer to error handling; The user terminal verifies whether s is calculated using e, k0, k1, k2, r, and the public key Q U and the corresponding private key d U calculated according to the ECDSA digital signature calculation method. If the verification passes, then (r, s) is the digital signature of the message M; otherwise, transfer to error handling Before the signature assistance device or system assists the user terminal in completing the generation of a digital signature, it authenticates and confirms that the user of the user terminal, i.e., the signer, is the owner of the public key Q U or relies on the system that calls the signature assistance device or system to first authenticate and confirm that the user of the user terminal, i.e., the signer, is the owner of the public key Q U of the owner.
7. The method for generating an ECDSA digital signature based on a ciphertext private key according to any one of claims 4-6, characterized in that: Based on the method for generating an ECDSA digital signature using a ciphertext private key for preventing S U A method for generating an ECDSA digital signature using a ciphertext private key for preventing a security token from being stolen is as follows, based on the method for generating an ECDSA digital signature using a ciphertext private key for preventing theft When the application service system issues a security token to the user, a random integer w within [1, n-1] is selected as a perturbation parameter, and w is encrypted into ciphertext data that can only be decrypted by the signature assistance device or system. Then, the ciphertext data of w and the security token are transmitted to the signature assistance device or system through the user terminal together, and the plaintext or ciphertext data of w is protected by the security token; After verifying the validity of the received security token, the signature assistance device or system decrypts the ciphertext of the perturbation parameter w to obtain the plaintext of w, and at the same time determines the validity of the plaintext or ciphertext of w through the security token; After that, the user terminal and the signature assistance device or system generate a digital signature (r, s) for the message M according to the ECDSA digital signature generation method based on the ciphertext private key described above; The signature assistance device or system calculates s w =(s + w) mod n or s w =(s - w) mod n, obtaining the perturbed digital signature (r, s w ); (r,s w ) is submitted or returned to the application service system without passing through the user terminal; The application service system calculates s = (s w - w) mod n or s = (w -1 s w ) mod n, where w -1 is the multiplicative inverse of w modulo n, and restores the digital signature (r, s) for the message M.
8. The method for generating an ECDSA digital signature based on a ciphertext private key according to any one of claims 4-6, characterized in that: Combine the security token with S U Combined with the method of re-encryption, there is the following method for security enhancement: S U After encryption, it becomes ciphertext data T U ; The key SK2 for decrypting the ciphertext data T U After encryption, it becomes ciphertext data T sk2 , and the signature assistance device or system has the key SK3 for decrypting the ciphertext data T sk2 ; The ciphertext data T U and the ciphertext data T sk2 are stored in the user terminal; When the user accesses the application service system and needs to use the user's ECDSA signature private key to generate a digital signature for the message M, the application service system issues a security token to the user; The application service system transmits the security token or the acquisition information of the security token to the password program or password module or password component that implements the ECDSA digital signature function in the user terminal; The user terminal submits the security token or the information for obtaining the security token, and T sk2 to the signature assistance device or system; If the acquisition information of the security token is submitted to the signature assistance device or system, the signature assistance device or system uses this acquisition information to obtain the security token issued by the application service system; After the signature assistance device or system verifies the validity of the security token, it decrypts the ciphertext data T using the key SK3 sk2 , obtains the key SK2, and returns the key SK2 to the user terminal; The user terminal decrypts the ciphertext data T using the secret key SK2 U to obtain S U , and then the user terminal and the signature assistance device or system use S according to the ECDSA digital signature generation method based on the ciphertext private key described above U to generate a digital signature for the message M 9. The method for generating an ECDSA digital signature based on a ciphertext private key according to any one of claims 1-6, characterized in that: For the method for generating an ECDSA digital signature based on a ciphertext private key described above, the generation and distribution methods of the user's ECDSA signature key pair include: Method One: Generate an ECDSA signature key pair Q by a trusted program in the user terminal U , d U , encrypt the signature private key d U to obtain the ciphertext S U , discard d U , and then securely store S U ; The trusted program is a program provided by a cryptographic program or cryptographic module developer, or a cryptographic service provider; Method Two: Generate the ECDSA signature key pair Q by a trusted program in another terminal U , d U , encrypt the signature private key d U to obtain the ciphertext S U , discard d U , and then transmit S U to the user terminal for storage by barcode scanning; the other terminal refers to a computing device other than the user terminal for storing and using S U Method Three: Generate an ECDSA signature key pair Q by a key generation device or system U , d U , encrypt the signature private key d U to obtain the ciphertext S U , discard d U , and then transmit S U to the user terminal for storage in a secure manner; Method Four: The key generation device or system randomly selects an integer d1 within [1, n - 1], encrypts d1 using a homomorphic encryption algorithm to obtain S U1 = E(d1), calculates Q U1 = d1G, and sends S U1 , Q U1 to the user terminal; The user terminal randomly selects an integer d2 within [1, n - 1], and uses the homomorphic encryption algorithm and S U1 to calculate and obtain S U = E(d1d2), and calculates Q U = d2Q U1 ; The user terminal verifies that d1d2 is congruent to an ECDSA signature private key d within [1, n - 1] without exposing d1d2 U Congruent modulo n means d1d2 = d U (mod n), and there is Q U = d U G, that is, verify that there is d U = (d1d2) mod n and Q U = d U G; Method Five: A key generation device or system randomly selects an integer d1 within [1, n - 1], and encrypts d1 using a homomorphic encryption algorithm to obtain S U1 = E(d1), and calculates Q U1 = d1G, and sends S U1 , Q U1 to the user terminal; The user terminal randomly selects an integer d2 within [1, n - 1] and calculates Q U = d2G + Q U1 ; Check whether Q U is the zero element. If so, the key generation device or system randomly selects an integer d1 within [1, n - 1] again and recalculates S U1 , Q U1 . The user terminal randomly selects an integer d2 within [1, n - 1] again and calculates Q U = d2G + Q U1 , Q U until it is a non-zero element; The user terminal uses the homomorphic encryption algorithm and S U1 to calculate and obtain S U = E(d1 + d2); The user terminal verifies that d1 + d2 is congruent modulo n to an ECDSA signature private key d within [1, n - 1] without exposing d1 + d2 U That is, d1 + d2 = d U (mod n), and there is Q U = d U G, that is, verify that there is d U = (d1 + d2) mod n and Q U = d U G; For the above-mentioned ECDSA signature private key generation and distribution methods, if the public key of the homomorphic encryption algorithm used for encrypting d U or d1d2 or d1 + d2 is temporarily generated, then the device, system or program that generates d U or d1 uses a symmetric key or a public key to encrypt the private key SK1 of the homomorphic encryption algorithm corresponding to the decryption operation, and obtains the ciphertext T of SK1 sk1 , where encrypting SK1 with a public key is applicable to the generation and distribution methods of all five ECDSA signature key pairs, and encrypting SK1 with a symmetric key is only applicable to the generation and distribution methods three, four, and five of the ECDSA signature key pairs.
10. A system for generating an ECDSA digital signature based on a ciphertext private key constructed on the basis of the method for generating an ECDSA digital signature based on a ciphertext private key according to any one of claims 1-6, characterized in that: The system includes a signature assistance device or system, and a password program or password module or password component in the user terminal; the user terminal stores the user's ECDSA signature private key d U ciphertext S U ; when it is necessary to use the user's ECDSA signature private key to perform a digital signature on the message M, the password program or password module or password component in the user terminal, and the signature assistance device or system, cooperate to generate a digital signature for the message M according to the foregoing method for generating an ECDSA digital signature based on a ciphertext private key, wherein the password program or password module or password component in the user terminal implements the operation processing performed by the user terminal in the foregoing method for generating an ECDSA digital signature based on a ciphertext private key.
Citation Information
Patent Citations
Digital signature multi-party generation method and system with participants not needing to be online at same time
CN113704831A
Privacy-enhanced ECDSA collaborative signature method and device
CN114117548A