A digital signature method and system

By obtaining multiple integer secrets in the digital signature system and distributing sub-copy of the private key, each signature device calculates and sends signature sub-values, and the computing device merges to generate the final signature, solving the problems of multi-device collaborative signature calculation complexity and risk of private key leakage in the prior art, and achieving efficient and reliable digital signatures.

CN115941194BActive Publication Date: 2025-06-27CHINA THREE GORGES CORPORATION
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202211247108.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-12
Publication Date
2025-06-27
Estimated Expiration
2042-10-12

AI Technical Summary

Technical Problem

Existing digital signature algorithms have high computational complexity, low efficiency when collaborative signature of multiple devices, and have a high risk of private key leakage, which affects the reliability of signatures.

Method used

By obtaining multiple integer secrets and calculating each private key sub-copy, it is distributed to each signature device. When digitally signing the target message, each signature device calculates the signature sub-value and sends it to the computing device, which fuses the signature sub-values ​​to generate the final digital signature.

Benefits of technology

It significantly reduces the complexity of the collaborative signature algorithm, improves the computing efficiency, and improves the reliability of signatures by decomposing the sub-parts of the private key to prevent security risks caused by private key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115941194B_ABST
    Figure CN115941194B_ABST
Patent Text Reader

Abstract

The present invention discloses a digital signature method and system, wherein the system includes a computing device and a signature device, and: the computing device obtains a plurality of integer secrets according to the number of signature devices, and respectively calculates a plurality of private key sub-portions by using the user's private key and each integer secret; the computing device distributes the obtained private key sub-portions and each integer secret to each signature device correspondingly; when performing a digital signature on a target message, the computing device sends a signature notification to each signature device based on the target message; when each signature device receives the signature notification, it performs signature calculation by using the private key sub-portion and the integer secret stored by itself to obtain its own signature sub-value; each signature device sends its own calculated signature sub-value to the computing device, and the computing device fuses each received signature sub-value to obtain the digital signature of the target message. The technical solution provided by the present invention realizes a multi-device collaborative signature method with lower complexity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and in particular, to a digital signature method and system. Background Art

[0002] A digital signature algorithm is an algorithm used to verify the identity of an information sender. Currently, the private key of the information sender is mostly stored through a signature device. When a digital signature is required, the private key is directly used to generate a signature value. If the signature device is illegally breached, it is very likely that the private key will be leaked, resulting in a low reliability of the digital signature. If an illegal person uses the private key to forge a digital signature for information transmission, the receiving party will mistake the illegal person for the legitimate sender, which may cause greater losses to both the sender and the receiver.

[0003] In response to the above problems, Patent Documents CN107819585B, CN109962783A, CN110166235A, and CN110213057A all use a variation of the SM9 algorithm for collaborative signature of multiple signature devices. Specifically, an integer secret is assigned to each signature device. Then, when each device signs a message, it cooperates with each other according to the assigned integer secret to calculate and sign the message with the private key of the collaborative user to obtain a total signature value. Even if the integer secrets in some of the signature devices are leaked, the original private key cannot be used to sign the message, thereby improving the reliability of the digital signature.

[0004] However, the algorithms mentioned in the above patent documents require multiple signature devices to calculate pairwise according to a progressive algorithm or an interactive algorithm. The calculation process of the next device requires the calculation result of the previous device. When there are many devices, the calculation process is relatively complex and the calculation efficiency is low. Therefore, it is necessary to simplify the complexity of the algorithm on the basis of collaborative signature. Summary of the Invention

[0005] In view of this, embodiments of the present invention provide a digital signature method and system, thereby realizing a multi-device collaborative signature method with lower complexity.

[0006] According to a first aspect, an embodiment of the present invention provides a digital signature method, which is applied to a computing device. The method includes: obtaining a plurality of integer secrets according to the number of signature devices, and respectively calculating a plurality of private key sub-portions by using the user's private key and each integer secret; corresponding each obtained private key sub-portion with each integer secret and distributing them to each signature device; when digitally signing a target message, sending a signature notification to each signature device based on the target message; receiving signature sub-values sent by each signature device, where the signature sub-value is the result obtained by the signature device through signature calculation by using the saved private key sub-portion and the integer secret; fusing the signature sub-values sent by each signature device to obtain the digital signature of the target message.

[0007] Optionally, the obtaining a plurality of integer secrets according to the number of signature devices includes: randomly selecting m integers in [1, n - 1], where n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm, and m represents the number of signature devices; calculating the remainder of the result of the preset addition and subtraction calculation of the m integers with respect to n, and determining whether the remainder is 0; if the remainder is 0, randomly selecting m integers from [1, n - 1] again until the remainder is not 0.

[0008] Optionally, the respectively calculating a plurality of private key sub-portions by using the user's private key and each integer secret includes: calculating a plurality of independent private key sub-portions according to the formula P Ai = c i * r, where P Ai represents the i-th independent private key sub-portion, c i represents the i-th integer secret, i ∈ [1, m], m represents the number of signature devices, r represents an integer randomly selected in the interval [1, n - 1], and n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm; calculating a shared private key sub-portion according to the formula P B = [c -1 d A , where the fused integer secret c is generated by performing the preset addition and subtraction calculation based on the m integer secrets, and d A represents the user's private key.

[0009] Optionally, the corresponding each obtained private key sub-portion with each integer secret and distributing them to each signature device includes: sending each independent private key sub-portion and the corresponding integer secret to the corresponding signature device according to the serial number; sending the shared private key sub-portion to each signature device.

[0010] Optionally, when digitally signing the target message, sending a signature notification to each signature device based on the target message includes: obtaining the elements of the cyclic group Gt in the SM9 algorithm that are pre - saved, and calculating the hash value of the hash function using the elements of the cyclic group Gt and the target message; sending the hash value as the signature notification to each signature device, so that each signature device calculates a signature sub - value according to the following formula using the hash value, the saved integer secret, the independent private key sub - share, and the shared private key sub - share

[0011] S i =P B *[(P Ai -c i h)mod n]

[0012] In the formula, S i represents the signature sub - value calculated by the i - th signature device, P Ai represents the independent private key sub - share saved by the i - th signature device, c i represents the i - th integer secret saved by the i - th signature device, P B represents the shared private key sub - share, h represents the hash value sent by the computing device, and n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm.

[0013] Optionally, fusing the signature sub - values sent by each signature device to obtain the digital signature of the target message includes: fusing the signature sub - values based on the preset addition and subtraction calculation to obtain a fused signature, and splicing the fused signature with the hash value to obtain the digital signature of the target message.

[0014] According to the second aspect, an embodiment of the present invention further provides a digital signature method applied to a signature device. The method includes: receiving and saving the integer secret and the private key sub - share sent by a computing device, where the integer secret is the integer secret obtained by the computing device according to the number of signature devices, and the private key sub - share is the information calculated by the computing device using the user's private key and the integer secret corresponding to the current signature device; when receiving the signature notification sent by the computing device, performing a signature calculation using the saved private key sub - share and the integer secret to obtain a signature sub - value, where the signature notification is a notification sent by the computing device based on the target message that needs to be digitally signed; sending the signature sub - value to the computing device, so that the computing device fuses the signature sub - values collected from each signature device to obtain the digital signature of the target message.

[0015] Optionally, receiving the integer secret and the private key sub - share sent by the computing device includes: receiving the independent private key sub - share, the shared private key sub - share, and the integer secret sent by the computing device; where the independent private key sub - share is calculated according to the formula P Ai =c i *r, and in the formula, PAi represents the i-th independent private key sub-share, c i represents the i-th integer secret, i ∈ [1, m], where m represents the number of signature devices, r represents an integer randomly selected within the range [1, n - 1], and n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm; the shared private key sub-share is calculated according to the formula P B = [c -1 d A where the fused integer secret c is generated by performing preset addition and subtraction calculations based on m integer secrets, and d A represents the private key of the user.

[0016] Optionally, the calculating the signature sub-value by using the saved private key sub-share and the integer secret includes: the current signature device calculates the signature sub-value according to the following formula

[0017] S i = P B * [(P Ai - c i h) mod n]

[0018] where S i represents the signature sub-value calculated by the i-th signature device, P Ai represents the independent private key sub-share saved by the i-th signature device, c i represents the i-th integer secret saved by the i-th signature device, P B represents the shared private key sub-share, n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm, h represents the hash value sent by the computing device, and the hash value is the result of the hash function calculated by the computing device using the elements of the cyclic group Gt in the pre-saved SM9 algorithm and the target message.

[0019] According to a third aspect, an embodiment of the present invention further provides a digital signature system, including a computing device and a signature device, where: the computing device obtains a plurality of integer secrets according to the number of signature devices, and calculates a plurality of private key sub-shares by using the private key of the user and each integer secret respectively; the computing device distributes the obtained private key sub-shares and each integer secret to each signature device correspondingly; when performing a digital signature on a target message, the computing device sends a signature notice to each signature device based on the target message; when each signature device receives the signature notice, it calculates its own signature sub-value by using the saved private key sub-share and the integer secret; each signature device sends its own calculated signature sub-value to the computing device, and the computing device fuses each received signature sub-value to obtain the digital signature of the target message.

[0020] The technical solution provided by this application has the following advantages:

[0021] The technical solution provided by this application is divided into two stages: an initialization stage and a signature stage. In the initialization stage, multiple integer secrets are obtained according to the number of signature devices, and the private key sub-portions corresponding to each integer secret are calculated. The obtained private key sub-portions and each integer secret are distributed to each signature device correspondingly. In the stage where the computing device performs a digital signature on the target message, the computing device first sends a signature notification to each signature device based on the target message, so that each signature device calculates its own signature sub-value. Then, the computing device collects the signature sub-values calculated by each signature device and fuses the signature sub-values to obtain the digital signature of the target message. The digital signature method provided by the embodiments of the present invention, based on the principle of collaborative signature of multiple signature devices, only requires each signature device to perform one calculation, and the computing device collects the calculation results of each signature device for a secondary fusion calculation, significantly reducing the complexity of the collaborative signature algorithm. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The features and advantages of the present invention will be more clearly understood by referring to the accompanying drawings. The drawings are schematic and should not be construed as limiting the present invention in any way. In the drawings:

[0023] Figure 1 FIG. shows a schematic structural diagram of a digital signature system in an embodiment of the present invention;

[0024] Figure 2 FIG. shows a schematic step diagram of a digital signature method in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0026] Please refer to Figure 1 , in an embodiment, a digital signature system includes a computing device 1 and signature devices 2, and performs a digital signature on a target message in the following manner:

[0027] The computing device 1 obtains multiple integer secrets according to the number of signature devices 2, and calculates multiple private key sub-portions respectively by using the user's private key and each integer secret;

[0028] The computing device 1 distributes the obtained respective private key sub - shares and respective integer secrets to each signature device 2. Specifically, it should be noted that each signature device 2 only stores the private key sub - shares and does not store the user's private key, so that when some of the signature devices 2 are compromised, the security of the digital signature is not affected.

[0029] When performing a digital signature on a target message, the computing device 1 sends a signature notification to each signature device 2 based on the target message;

[0030] When each signature device 2 receives the signature notification, it uses the respective private key sub - share and integer secret stored by itself to perform signature calculation to obtain its respective signature sub - value;

[0031] Each signature device 2 sends the respective signature sub - value calculated by itself to the computing device 1, and the computing device 1 fuses the received signature sub - values to obtain the digital signature of the target message.

[0032] Specifically, in the embodiment of the present invention, the computing device 1 can be an electronic device independent of all signature devices 2 and only used for fusion calculation, or can be one of the electronic devices selected from each signature device 2. The present invention is not limited thereto, as long as the computing device 1 is used to fuse the signature sub - values of each signature device 2. The digital signature method provided by the embodiment of the present invention, based on the principle of collaborative signature of multiple signature devices 2, only requires each signature device 2 to perform one calculation, and the computing device 1 collects the calculation results of each signature device 2 for secondary fusion calculation, significantly reducing the complexity of the collaborative signature algorithm.

[0033] Specifically, as Figure 2 shown, in another embodiment, a digital signature method is further provided, where steps S101 to S105 are applied to the computing device, and steps S201 to S203 are applied to the signature device. The specific steps are as follows:

[0034] Step S101: Obtain multiple integer secrets according to the number of signature devices, and calculate multiple private key sub - shares respectively using the user's private key and each integer secret.

[0035] Step S102: Correspondingly distribute the obtained respective private key sub - shares and respective integer secrets to each signature device.

[0036] Step S201: Receive the integer secret and private key sub - share sent by the computing device and save them.

[0037] Step S103: When performing a digital signature on a target message, send a signature notification to each signature device based on the target message.

[0038] Step S202: When receiving the signature notification sent by the computing device, use the saved private key share and the integer secret to perform signature calculation to obtain a signature sub-value.

[0039] Step S203: Send the signature sub-value to the computing device.

[0040] Step S104: Receive the signature sub-values sent by each signature device.

[0041] Step S105: Fuse the signature sub-values sent by each signature device to obtain the digital signature of the target message.

[0042] Specifically, for a detailed explanation of the above method embodiments, reference can be made to the relevant descriptions of the above system embodiments, which will not be elaborated here.

[0043] Specifically, in one embodiment, the above steps S101 to S105 and steps S201 to S203 are implemented based on the SM9 algorithm, thereby further improving the reliability of the digital signature method. Before detailed discussion, for the convenience of further understanding of the embodiments of the present invention, the principle of the SM9 algorithm in the prior art is explained as follows:

[0044] SM9 is an identity-based cryptographic algorithm based on bilinear mapping promulgated by the State Cryptography Administration. Based on the SM9 cryptographic algorithm, identity-based digital signature, key exchange, and data encryption can be realized. When a certain device uses the SM9 private key d of a user A to sign the target message M, the following steps are executed:

[0045] 1. Calculate h = H2(M||w, n), where h is the hash value of the hash function, H2(-) represents the hash function operation, M||w represents the string concatenation of M and w, w is an element in the cyclic group Gt of the SM9 algorithm, w = g^(r), representing the r-th power operation of g, r is an integer randomly selected in the interval [1, n - 1], n is the order of the cyclic groups G1, G2, Gt in the SM9 cryptographic algorithm, g is the calculation result of the bilinear mapping, where g = e(P1, P pub ), P1 is the generator in the cyclic group G1, P pub is the master public key, P pub = [s]P2, s is the master private key or master secret key, and P2 is the generator in the cyclic group G2.

[0046] 2. Determine whether r is equal to h. If r is equal to h, reselect r and execute step 1. If r is not equal to h, execute step 3.

[0047] 3. Calculate S = [r - h]d A , and then splice (h, S) as the digital signature of the target message M.

[0048] An embodiment of the present invention is based on the SM9 algorithm for improvement, realizing the collaborative signature of multiple signature devices and making the complexity of the improved algorithm relatively low.

[0049] The digital signature method provided by the embodiment of the present invention is divided into two stages: initialization and signature. The initialization stage is used to pre-calculate the private key sub-shares required by each signature device, enable each signature device to save the required private key sub-shares, and clear the SM9 private key d A and other intermediate calculation parameters that may cause information leakage, so as to ensure that the information in each signature device does not affect the security of the digital signature even if it is leaked.

[0050] For the initialization stage of the above steps S101 to S102, it specifically includes the following steps:

[0051] Step 1: Obtain multiple integer secrets c1 to c m according to the number m of signature devices, and calculate the independent private key sub-shares P A1 ~P Am corresponding to each integer secret, and also calculate the shared private key sub-share P B .

[0052] Specifically, when the embodiment of the present invention obtains each integer secret, m integers are randomly selected in [1, n - 1], where n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm, and m represents the number of signature devices. Then, perform a preset addition and subtraction calculation on the m integers to obtain a result, and calculate the remainder of the above calculation result and n, and determine whether the remainder is 0; if the remainder is 0, randomly select m integers from [1, n - 1] again until the remainder is not 0. The purpose of doing this is that when calculating the shared private key sub-share P B in the subsequent steps, since this embodiment sets P B =[c -1 d A , where c is the result of the preset addition and subtraction calculation of each integer secret c1 to c m , so c cannot be 0 as a divisor.

[0053] After that, calculate the independent private key sub-share corresponding to each signature device according to the formula P Ai =c i *r, where P Ai represents the i-th independent private key sub-share, c i represents the i-th integer secret, i ∈ [1, m], m represents the number of signature devices, r represents an integer randomly selected in the interval [1, n - 1], and n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm;

[0054] And calculate the shared private key sub-share according to the formula P B =[c -1 dA Calculate the shared private key sub - portion. In the formula, the fused integer secret c is generated by performing the above - mentioned preset addition and subtraction calculations based on m integer secrets, and d A represents the user's private key.

[0055] Finally, distribute multiple independent private key sub - portions and multiple integer secrets corresponding to the label of each signature device. Send the shared private key sub - portion to each signature device, and fuse the intermediate parameter integer secret c and the user's private key d involved in the initialization process A Destroy.

[0056] Through this step, the user's private key can be decomposed into multiple private key sub - portions. Thus, each signature device can use its own saved independent private key sub - portion, shared private key sub - portion, and integer secret to calculate according to the mathematical principle of the SM9 algorithm without major modifications to the SM9 algorithm, and generate its own signature sub - value. This not only reduces the algorithm complexity but also improves the interpretability of the algorithm. At the same time, even if the information of some signature devices is leaked, criminals cannot complete the digital signature, ensuring the reliability of the digital signature.

[0057] In addition, in the above - mentioned step 1, the element w of the cyclic group Gt in the SM9 algorithm is also pre - calculated. When the calculation device sends a signature notice, there is no need to calculate the element w of the cyclic group Gt again, and the intermediate parameters involved in calculating w are destroyed in advance to further improve the security of the signature method. This step is the same as the method of calculating w in the prior art, and is obtained by calculating w = g^(r), where g = e(P1, P pub ), P1 is the generator in the cyclic group G1, and P pub is the master public key, P pub =[s]P2, s is the master private key or master secret key, P2 is the generator in the cyclic group G2, and r is an integer randomly selected in the interval [1, n - 1]. After calculating the element w of the cyclic group Gt, destroy r, g, the master public key, and the master private key to further ensure that the information about the user's private key is not leaked.

[0058] For the digital signature stage of the above - mentioned steps S103 to S105 and step S202, it specifically includes the following steps:

[0059] Step 2: The calculation device obtains the element w of the cyclic group Gt in the pre - saved SM9 algorithm, and calculates the hash value h of the hash function by using the element w of the cyclic group Gt and the target message M;

[0060] Step 3: The calculation device sends the hash value h as a signature notice to each signature device.

[0061] Specifically, when the computing device obtains the target message M, it is necessary to perform a digital signature on the target message M. The computing device can directly use the element w of the cyclic group Gt pre-computed and saved in step 1 above, and then calculate the hash function value of the target message M and the element w of the cyclic group Gt to obtain the hash value result. The calculation process of this step is the same as the calculation process in the prior art, that is, calculate h = H2(M||w, n), where h is the hash value of the hash function, H2(-) represents the hash function operation, and M||w represents the string concatenation of M and w. Then, the computing device sends the calculated hash value as a signature notice to each signature device respectively, so that each signature device can execute the SM9 algorithm using the received hash value h.

[0062] Step Four: Each signature device calculates the signature sub-value according to the following formula

[0063] S i = P B *[(P Ai - c i h) mod n]

[0064] In the formula, S i represents the signature sub-value calculated by the i-th signature device, P Ai represents the independent private key sub-share saved by the i-th signature device, c i represents the i-th integer secret saved by the i-th signature device, P B represents the shared private key sub-share, n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm, h represents the hash value sent by the computing device, and the hash value is the hash function result calculated by the computing device using the element of the cyclic group Gt in the pre-saved SM9 algorithm and the target message.

[0065] Step Five: The computing device fuses each signature sub-value based on a preset addition and subtraction calculation to obtain a fused signature, and concatenates the fused signature and the hash value into the digital signature of the target message.

[0066] Specifically, when each signature device receives the hash value sent by the computing device, if the step of taking the remainder is not considered, it is necessary to calculate P B *(P Ai - c i h) = P B * c i *(r - h) = [c -1 d A * c i *(r - h). If this result is used as the signature sub-value S iSent to the computing device, which fuses each signature sub-value according to a preset addition and subtraction calculation. Taking addition as an example (any combination operation method that conforms to addition and subtraction calculations can be used, only for example here, not limited to this), if the fused signature S = S1 + S2 + … + S i +…+S m , where m is the number of signature devices, then S = [c -1 d A *c1*(r - h) + [c -1 d A *c2*(r - h) + … + [c -1 d A *c m *(r - h) = [c -1 d A *c*(r - h) = d A *(r - h). Referring to the description of the SM9 algorithm in the above steps S101 - S105, it is not difficult to find that the scheme of calculating signature sub-values using the private key sub-shares disassembled in this embodiment and then fusing the signature sub-values completely conforms to the mathematical principle of the SM9 algorithm. In the embodiment of the present invention, considering that n is the order of the cyclic groups G1, G2, and Gt, the maximum number in the SM9 algorithm cannot exceed n. Therefore, the remainder operation (P Ai -c i h) mod n is used to ensure the rationality of the improved SM9 collaborative signature algorithm. Based on this principle, when calculating the fused signature S in this embodiment, the remainder processing is also performed on the preset addition and subtraction calculations of S1 - S m . The computing device finally concatenates the calculated fused signature S and the hash value h to obtain the digital signature of the target message M.

[0067] Through the above steps, the embodiment of the present invention proposes a collaborative signature algorithm based on the SM9 algorithm. Combining the calculation principle of the SM9 algorithm, the user's private key d A is disassembled into multiple private key sub-shares and distributed to each signature device. Each signature device uses the private key sub-share to sign to obtain a signature sub-value. The computing device fuses the signature sub-values collected from each signature device to obtain the digital signature of the target message M. On the one hand, the reliability and security of the digital signature are improved. On the other hand, compared with the existing patent documents, the essential principle of the SM9 algorithm is not changed, and the basic principle of the SM9 algorithm is continued. On the premise of maintaining the basic calculation principle of the SM9 algorithm, a signature scheme is realized in which each signature device calculates the signature sub-value and the computing device fuses each signature sub-value at one time. Thus, compared with the collaborative signature method provided by the existing patent documents, the algorithm complexity is significantly reduced when using more signature devices, and the signature efficiency is improved.

[0068] Specifically, in an embodiment of an actual application scenario, based on the above steps, a digital signature method provided by an embodiment of the present invention is applied as follows:

[0069] Initialization phase:

[0070] 1. The computing device obtains m integer secrets c1 to c m , where m is the number of signature devices, and checks whether (the preset addition and subtraction cloud operation of c1 to c m ) mod n is 0. If it is 0, reselect c1 to c m . If it is not 0, proceed to the next step.

[0071] 2. The computing device calculates an independent private key sub-share P Ai = c i * r for each integer secret, where r and c i are randomly selected integers in the range [1, n - 1], and i ∈ [1, m].

[0072] 3. The computing device calculates a shared private key sub-share P B = [c -1 d A , where d A is the SM9 private key of the user, c is the secret integer that none of the m devices have saved, and c is the result of the preset addition and subtraction combined operation of c1 to c m .

[0073] 4. The computing device calculates the element w = g^(r) in the cyclic group Gt, and converts the data type of w into a bit string (since the SM9 algorithm is a large number operation, to avoid exceeding the representation range of the computer, w is converted into a bit string for large number operations). Among them, the bilinear mapping calculates g = e(P1, P pub ), P1 is the generator in G1, and P pub is the public key (i.e., P pub = [s]P2, s is the master private key or master secret key, and P2 is the generator in G2).

[0074] 5. The computing device destroys c, d A , r, sends the independent private key sub-share P Ai to the corresponding signature device respectively, sends each integer secret c i to the corresponding signature device respectively, sends the shared private key sub-share P B to each signature device, and the computing device saves the element w in the cyclic group Gt.

[0075] When it is necessary to sign the message M, enter the component signature phase:

[0076] 1. The computing device calculates the hash value h = H2(M||w, n), where H2 is the hash function specified in SM9, M||w represents the concatenation of the strings of M and w, and n is the order of G1, G2, and Gt.

[0077] 2. The computing device sends h to each signature device.

[0078] 3. Each signature device calculates the signature sub-value using h. The i-th signature device calculates the i-th signature sub-value S i The steps are as follows:

[0079] Calculate T Ai =(P Ai -c i h) mod n; and calculate S i =T Ai* P B

[0080] 4. The computing device collects the S calculated by each signature device i , and calculates the combined signature S, where

[0081] S=(the result of the preset addition and subtraction combination operation of S1 to S m ) mod n

[0082] 5. The computing device concatenates the hash value h and the combined signature S to obtain the digital signature of the message M.

[0083] Through the above steps, the technical solution provided by this application is divided into two stages: the initialization stage and the signature stage. In the initialization stage, the computing device obtains multiple integer secrets according to the number of signature devices, calculates the private key sub-portions corresponding to each integer secret, and distributes the obtained private key sub-portions and each integer secret to each signature device correspondingly. In the stage where the computing device performs digital signature on the target message, the computing device first sends a signature notice to each signature device based on the target message, so that each signature device calculates its own signature sub-value. Then, the computing device collects the signature sub-values calculated by each signature device and fuses the signature sub-values to obtain the digital signature of the target message. The digital signature method provided by the embodiments of the present invention, based on the principle of collaborative signature of multiple signature devices, only requires each signature device to perform one calculation, and the computing device collects the calculation results of each signature device for secondary fusion calculation, significantly reducing the complexity of the collaborative signature algorithm.

[0084] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations fall within the scope defined by the appended claims.

Claims

1. A digital signature method, characterized in that, Applied to a computing device, the method includes: Randomly select m integers in [1, n-1], where n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm, and m represents the number of signature devices; calculate the remainder of the result of the preset addition and subtraction calculation of the m integers divided by n, and determine whether the remainder is 0; if the remainder is 0, randomly select m integers from [1, n-1] again until the remainder is not 0, to obtain m integer secrets; According to the formula P Ai = c i * r, multiple independent private key sub - shares are calculated, where P Ai represents the i - th independent private key sub - share, c i represents the i - th integer secret, i ∈ [1, m], m represents the number of signature devices, r represents an integer randomly selected in the interval [1, n - 1], and n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm; Calculate the shared private key sub - portion according to the formula P B =[c -1 d A where the fused integer secret c is generated by performing preset addition and subtraction calculations based on m integer secrets, and d A represents the user's private key; Send each independent private key sub-share and the corresponding integer secret to the corresponding signature device according to the serial number, and send the shared private key sub-share to each signature device; Obtain the elements of the cyclic group Gt in the SM9 algorithm saved in advance, and calculate the hash value of the hash function by using the elements of the cyclic group Gt and the target message; Send the hash value as a signature notification to each signature device, so that each signature device calculates the signature sub-value according to the following formula by using the hash value, the saved integer secret, the independent private key sub-share, and the shared private key sub-share: S i = P B * [(P Ai - c i h) mod n] Wherein, S i represents the signature sub-value calculated by the i-th signature device, P Ai represents the independent private key sub-share saved by the i-th signature device, c i represents the i-th integer secret saved by the i-th signature device, P B represents the shared private key sub-share, h represents the hash value sent by the computing device, and n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm; Receive the signature sub-values sent by each signature device; Fuse the signature sub-values of each signature device to obtain the digital signature of the target message.

2. The method according to claim 1, wherein The fusing the signature sub-values sent by each signature device to obtain the digital signature of the target message includes: Fuse the signature sub-values of each signature device based on the preset addition and subtraction calculation to obtain a fused signature, and splice the fused signature and the hash value into the digital signature of the target message.

3. A digital signature method, characterized in that, Applied to a signature device, the method includes: Receive the independent private key sub-share, the shared private key sub-share, and the integer secret sent by the computing device; Among them, the independent private key sub - portion is calculated according to the formula P Ai = c i * r, where P Ai represents the i - th independent private key sub - portion, c i represents the i - th integer secret, i ∈ [1, m], m represents the number of signature devices, r represents an integer randomly selected in the interval [1, n - 1], and n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm; The shared private key sub - portion is calculated according to the formula P B =[c -1 d A where the fused integer secret c is generated by performing preset addition and subtraction calculations based on m integer secrets, and d A represents the user's private key; The integer secret is: randomly select m integers in [1, n-1], where n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm, and m represents the number of signature devices; calculate the remainder of the result of the preset addition and subtraction calculation of the m integers divided by n, and determine whether the remainder is 0; if the remainder is 0, randomly select m integers from [1, n-1] again until the remainder is not 0, to obtain m integer secrets; When receiving the signature notification sent by the computing device, the current signature device calculates the signature sub-value according to the following formula: S i = P B * [(P Ai - c i h) mod n] Wherein, S i represents the signature sub-value calculated by the i-th signature device, P Ai represents the independent private key sub-share saved by the i-th signature device, c i represents the i-th integer secret saved by the i-th signature device, P B represents the shared private key sub-share, n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm, h represents the hash value sent by the computing device, and the hash value is the result of the hash function calculated by the computing device using the elements of the cyclic group Gt pre-saved in the SM9 algorithm and the target message; Send the signature sub-value to the computing device, so that the computing device fuses the signature sub-values of each signature device collected to obtain the digital signature of the target message.

4. A digital signature system, characterized in that, Including a computing device and a signature device, where: The computing device randomly selects m integers in [1, n-1], where n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm, and m represents the number of signature devices; calculate the remainder of the result of the preset addition and subtraction calculation of the m integers divided by n, and determine whether the remainder is 0; if the remainder is 0, randomly select m integers from [1, n-1] again until the remainder is not 0, to obtain m integer secrets; The computing device calculates multiple independent private key sub - portions according to the formula P Ai = c i * r, where P Ai represents the i - th independent private key sub - portion, c i represents the i - th integer secret, i ∈ [1, m], m represents the number of signature devices, r represents an integer randomly selected within the interval [1, n - 1], and n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm; The computing device calculates according to the formula P B = [c -1 d A to calculate the shared private key sub - portion, where the fused integer secret c is generated by performing preset addition and subtraction calculations based on m integer secrets, and d A represents the user's private key; The computing device sends each independent private key sub-share and the corresponding integer secret to the corresponding signature device according to the serial number, and sends the shared private key sub-share to each signature device; When performing a digital signature on the target message, the computing device obtains the elements of the cyclic group Gt in the SM9 algorithm saved in advance, and calculates the hash value of the hash function by using the elements of the cyclic group Gt and the target message; sends the hash value as a signature notification to each signature device; When each signature device receives the signature notification, the signature device calculates a signature sub-value according to the following formula: S i = P B * [(P Ai - c i h) mod n] Wherein, S i represents the signature sub-value calculated by the i-th signature device, P Ai represents the independent private key sub-share saved by the i-th signature device, c i represents the i-th integer secret saved by the i-th signature device, P B represents the shared private key sub-share, n represents the order of the cyclic groups G1, G2, and Gt in the SM9 algorithm, h represents the hash value sent by the computing device, and the hash value is the result of the hash function calculated by the computing device using the elements of the cyclic group Gt pre-saved in the SM9 algorithm and the target message; Each signature device sends the calculated signature sub-value to the calculation device, and the calculation device fuses the received signature sub-values to obtain the digital signature of the target message.

Citation Information

Patent Citations

  • SM9 Digital Signature Collaborative Generation Method and System

    CN107819585B

  • SM9 digital signature collaborative generation method and system based on progressive calculation

    CN109962783A

  • SM9 digital signature collaborative generation method and system for enhancing security

    CN110166235A

  • SM9 digital signature collaborative generation method and system with product r parameter

    CN110213057A

  • Digital signature method and device and storage medium

    CN110048839A