Signature Quick Generation Method, Apparatus, Electronic Device, and Computer Storage Medium
By using matrix-based operations to generate digital signatures, the method significantly reduces computational requirements, enhancing the applicability of signature generation to devices with limited performance.
Patent Information
- Application Number
- CN202211546358.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-05
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-12-05
AI Technical Summary
Existing signature generation methods such as Guomi SM2 elliptic curve algorithm and ECDSA require a large amount of point multiplication operations, with large calculations, high performance requirements for cryptographic equipment, and low applicability.
By generating random numbers, extracting multiple matrix elements from the pre-generated private key matrix, adding them to obtain the private key and public key, and generating a digital signature in combination with hash values. Finite domain addition operation and elliptic curve point addition operation replace point multiplication operation.
The calculation amount of signature generation is reduced, making it suitable for cipher devices with poor performance, and improving signature performance per unit time.
Smart Images

Figure CN116192396B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of information security technology, and in particular, to a method, apparatus, electronic device, and computer storage medium for quickly generating signatures. Background Art
[0002] With the development of technologies such as cloud platforms, big data, and blockchain, the security of data has become a crucial issue. Therefore, corresponding security technical measures need to be taken for data. As one of the means to ensure network information security, the digital signature mechanism can solve problems such as forgery, repudiation, impersonation, and data tampering, and improve the security of data.
[0003] Currently, cryptographic devices use the national cryptographic SM2 elliptic curve algorithm to generate digital signatures, or ECDSA signatures, etc.
[0004] However, when generating digital signatures using the national cryptographic SM2 elliptic curve algorithm or ECDSA, etc., it is necessary to perform a point multiplication operation on a fixed base point on the elliptic curve, and the amount of calculation is large, and the performance requirements for cryptographic devices are high. Therefore, the applicability of existing signature generation methods is low. By reducing the amount of signature operations, the signature performance per unit time of the same cryptographic device can also be improved. Summary of the Invention
[0005] In view of this, the embodiments of the present application provide a method, apparatus, electronic device, and computer storage medium for quickly generating signatures to at least partially solve the above problems.
[0006] According to a first aspect of the embodiments of the present application, a method for quickly generating signatures is provided. The method includes: generating a first random number; extracting m first matrix elements from a pre-generated private key matrix according to the first random number, where m is a positive integer greater than or equal to 2; extracting m second matrix elements with the same coordinates as the first matrix elements from a pre-generated public key matrix corresponding to the private key matrix; adding the m first matrix elements to obtain a first private key, and adding the m second matrix elements to obtain a first public key; generating a digital signature according to the first private key, the first public key, and a pre-generated hash value.
[0007] In a possible implementation manner, the extracting m first matrix elements from a pre-generated private key matrix according to the first random number includes: determining m bytes from M bytes included in the first random number, where M is a positive integer greater than or equal to m; determining m matrix coordinates according to the content corresponding to the m bytes in the first random number; extracting m first matrix elements corresponding to the matrix coordinates from the private key matrix according to the m matrix coordinates.
[0008] In a possible implementation, extracting m second matrix elements from a pre-generated public key matrix corresponding to the private key matrix includes: extracting m second matrix elements corresponding to the matrix coordinates from the public key matrix according to the m matrix coordinates.
[0009] In a possible implementation, generating a digital signature according to the first private key, the first public key, and a pre-generated hash value includes: obtaining a second private key and a second public key used for the previous generation of the digital signature; adding the first private key to the second private key used for the previous generation of the digital signature to obtain a second private key for the current generation of the digital signature; adding the first public key to the second public key used for the previous generation of the digital signature to obtain a second public key for the current generation of the digital signature; generating the current digital signature according to the second private key for the current generation of the digital signature, the second public key for the current generation of the digital signature, and the hash value.
[0010] In a possible implementation, before generating the current digital signature according to the second private key for the current generation of the digital signature, the second public key for the current generation of the digital signature, and the hash value, it further includes: determining whether the second private key is equal to 0; if the second private key is equal to 0, then generating the first random number to regenerate the second private key.
[0011] In a possible implementation, generating the current digital signature according to the second private key for the current generation of the digital signature, the second public key for the current generation of the digital signature, and the hash value includes: generating a first signature part according to the hash value and / or the second public key for the current generation of the digital signature; generating a second signature part according to the hash value and / or the second private key for the current generation of the digital signature, the signature private key, and the first signature part; combining the first signature part and the second signature part to generate the digital signature.
[0012] In a possible implementation, before combining the first signature part and the second signature part to generate the digital signature, the method further includes: determining whether the first signature part and the second signature part are always equal to 0; if the first signature part and / or the second signature part are always equal to 0, then generating the first random number to regenerate the digital signature.
[0013] According to a second aspect of the embodiments of the present application, a signature fast generation device is provided. The device includes: a first generation module for generating a first random number; a first extraction module for extracting m first matrix elements from a pre-generated private key matrix according to the first random number, where m is a positive integer greater than or equal to 2; a second extraction module for extracting m second matrix elements with the same coordinates as the first matrix elements from a pre-generated public key matrix corresponding to the private key matrix; a calculation module for adding the m first matrix elements to obtain a first private key and adding the m second matrix elements to obtain a first public key; and a second generation module for generating a digital signature according to the first private key, the first public key, and a pre-generated hash value.
[0014] According to a third aspect of the embodiments of the present application, an electronic device is provided, including: a processor, a memory, a communication interface, and a communication bus. The processor, the memory, and the communication interface complete communication with each other through the communication bus; the memory is used for storing at least one executable instruction, and the executable instruction causes the processor to perform operations corresponding to the method described in the first aspect.
[0015] According to a fourth aspect of the embodiments of the present application, a computer storage medium is provided, on which a computer program is stored. When the program is executed by a processor, it implements the method described in the first aspect.
[0016] According to the signature fast generation method provided by the embodiments of the present application, a first matrix element and a second matrix element are extracted through the generated random number, and the extracted first matrix elements are added to obtain a first private key and the second matrix elements are added to obtain a first public key. Thus, a digital signature is generated according to the first private key, the first public key, and the hash value. By using the first private key generated by the finite field addition operation and the first public key generated by the elliptic curve point addition operation to replace the result of generating a random number k and calculating the point multiplication operation of k and the base point G in the existing signature generation method, the generation process of the digital signature does not require a point multiplication operation, and the operation amounts of a small amount of finite field addition operations and a small amount of elliptic curve point addition operations are much smaller than one point multiplication operation. Therefore, the operation amount of this signature fast generation method is low, only 1 / 10 of the elliptic curve point multiplication operation amount, and the performance requirements for the cryptographic device are low. Therefore, the signature fast generation method is applicable to cryptographic devices with poor performance and has high applicability. It can also improve the signature performance of the same cryptographic device per unit time by reducing the operation amount of the signature. Description of the Drawings
[0017] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments recorded in the embodiments of the present application. For those of ordinary skill in the art, other accompanying drawings can also be obtained based on these drawings.
[0018] Figure 1 is a flowchart of a method for quickly generating a signature provided by an embodiment of the present application;
[0019] Figure 2 is a flowchart of another method for quickly generating a signature provided by an embodiment of the present application;
[0020] Figure 3 is a schematic diagram of a device for quickly generating a signature provided by an embodiment of the present application;
[0021] Figure 4 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0022] To enable those skilled in the art to better understand the technical solutions in the embodiments of the present application, the following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art shall fall within the scope of protection of the embodiments of the present application.
[0023] The terms used in the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The singular forms of "a", "the", and "said" used in the present application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0024] It should be understood that although the terms first, second, third, etc. may be used in the present application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".
[0025] Figure 1The following is a flowchart of a method for quickly generating signatures provided by an embodiment of the present application. As Figure 1 shown, the method includes the following steps 101 to 105:
[0026] Step 101: Generate a first random number.
[0027] Generate a first random number, which can be generated based on the user's ID, or can be a randomly generated array, randomly generated numbers, etc.
[0028] Step 102: Extract m first matrix elements from a pre-generated private key matrix, where m is a positive integer greater than or equal to 2.
[0029] Randomly extract m first matrix elements from the private key matrix. m is a pre-set positive integer greater than or equal to 2. To balance the computational complexity and security requirements, generally, the value range of m is 3 to 5. For example, if m is 5, then 5 first matrix elements are extracted from the private key matrix.
[0030] It should be understood that when the signature device is initialized, a private key matrix is automatically generated. After generating the private key matrix, according to the conversion relationship between the private key matrix and the public key matrix, a public key matrix corresponding to the private key matrix is automatically generated. For example, a 16×16 private key matrix and a corresponding 16×16 public key matrix are generated respectively. The specific generation methods of the private key matrix and the public key matrix are not limited in the present application.
[0031] Step 103: Extract m second matrix elements with the same coordinates as the first matrix elements from a pre-generated public key matrix corresponding to the private key matrix.
[0032] Randomly extract m second matrix elements with the same coordinates as the first matrix elements from the public key matrix according to the first random number.
[0033] Step 104: Add the m first matrix elements to obtain a first private key, and add the m second matrix elements to obtain a first public key.
[0034] Add the extracted m first matrix elements to obtain a first private key sk m , add the extracted m second matrix elements to obtain a first public key PK m , according to the combined public key, the public key corresponding to the first private key sk m is the first public key PK m .
[0035] It should be noted that since the matrix elements in the private key matrix and the public key matrix are different, adding the m first matrix elements extracted from the private key matrix is an addition operation in a finite field, and adding the m second matrix elements extracted from the public key matrix is a point addition operation on an elliptic curve.
[0036] Step 105: Generate a digital signature based on the first private key, the first public key, and a pre-generated hash value.
[0037] Based on the first private key sk m and the first public key PK m generate a digital signature together with the pre-generated hash value.
[0038] In an embodiment of the present application, the first matrix element and the second matrix element are extracted through the generated random number, and the added first matrix elements are added to obtain the first private key, and the added second matrix elements are added to obtain the first public key. Therefore, a digital signature is generated based on the first private key, the first public key, and the hash value. By replacing the generation of the random number k and the result of the dot product operation of k and the base point G in the existing signature generation method with the first private key generated by the finite field addition operation and the first public key generated by the elliptic curve point addition operation, the dot product operation is not required in the process of generating the digital signature. Moreover, the operation amounts of a small number of finite field addition operations and a small number of elliptic curve point addition operations are much smaller than one dot product operation. Therefore, the operation amount of this signature fast generation method is relatively low, only a small number of point addition operations need to be calculated, and the performance requirements for the cryptographic device are relatively low. Therefore, the signature fast generation method is applicable to cryptographic devices with poor performance and has high applicability. It can also improve the signature performance of the same cryptographic device per unit time by reducing the operation amount of the signature.
[0039] In a possible implementation manner, when extracting m first matrix elements from a pre-generated private key matrix according to a first random number, m bytes can be determined from M bytes included in the first random number, where M is a positive integer greater than or equal to m. Then, according to the content corresponding to the m bytes in the first random number, m matrix coordinates are determined, and then m first matrix elements corresponding to the matrix coordinates are extracted from the private key matrix according to the m matrix coordinates.
[0040] Randomly determine m bytes from all bytes included in the first random number. For example, it can be the first m bytes of the first random number, the last m bytes of the first random number, m bytes in a random position and in a random order, and so on. Determine m matrix coordinates according to the determined m bytes, and extract the m first matrix elements corresponding to the coordinates from the private key matrix according to the m matrix coordinates.
[0041] It should be noted that the positions of the elements in the private key matrix and the public key matrix can all be represented by bytes. Therefore, the matrix coordinates can be determined through the bytes, and thus the matrix elements located at the current position can be extracted according to the positions corresponding to the matrix coordinates in the matrix.
[0042] In the embodiment of the present application, according to the multiple bytes included in the first random number, m first matrix elements are randomly selected, realizing the random selection function and ensuring the randomness of the first private key, so that the generated digital signature can be random. To ensure the security of fast signature generation, the first private key sk m should cover the entire range of [1, n - 1].
[0043] In a possible implementation manner, m second matrix elements with the same coordinates as the first matrix elements are extracted from the pre-generated public key matrix corresponding to the private key matrix. m second matrix elements corresponding to the matrix coordinates can be extracted from the public key matrix according to the m matrix coordinates.
[0044] The extraction rule of the second matrix elements is similar to that of the first matrix elements, which will not be elaborated here.
[0045] The first private key sk generated according to the combined public key and the m first matrix elements m The corresponding public key is the first public key PK generated by combining m second matrix elements with the same coordinates as the first matrix elements m .
[0046] In a possible implementation manner, when generating the hash information, the preprocessing information can be generated according to the relevant parameters of the elliptic curve and the identity identifier of the signer, and the hash value is generated according to the preprocessing information.
[0047] Initialize the relevant parameters of the elliptic curve. Through the formula Z A =H 256 (ENTL A ||ID A ||a||b||x G ||y G ||x A ||y A ) to calculate the preprocessing information, where Z A is used to represent the preprocessing information, H 256 () is used to represent the hash function, ID A is used to represent the identity identifier of the signer, ENTL A is two bytes converted from the bit length of ID A , a and b are used to represent two elements in the prime field Fp and satisfy y 2 =x 3 +ax + b, (x G , y G ) is used to represent the coordinates of the base point G on the elliptic curve, n is the order of the base point G, (x A , y A ) is used to represent the signature public key held by the signer, and the corresponding signature private key is d A, that is, (x A , y A ) = d A *G.
[0048] After calculating the preprocessing information Z A , according to the preprocessing information Z A , the hash value is calculated through the following formula e = H v (Z A ||M), where H v () is used to represent the hash function, M is used to represent the encoding of the information to be transmitted, and e is used to represent the hash value. Thus, the generation of the hash value can be realized.
[0049] It should be understood that H 256 () and H v () are used to represent the hash function, and this hash function is generally the national secret SM3 hash algorithm. Through this algorithm, the hash value can be generated.
[0050] In the embodiment of the present application, the preprocessing information is generated through the relevant parameters of the elliptic curve and the identity identifier of the signer. Thus, the hash value can be generated according to the preprocessing information, completing the preprocessing process in the fast signature generation process and ensuring the normal progress of the fast signature generation process.
[0051] Figure 2 is the flowchart of another fast signature generation method provided by the embodiment of the present application. As Figure 2 shown, this method includes the following steps 201 to step 208:
[0052] Step 201, generate a first random number.
[0053] Step 202, extract m first matrix elements from the pre-generated private key matrix according to the first random number, where m is a positive integer greater than or equal to 2.
[0054] Step 203, extract m second matrix elements with the same coordinates as the first matrix elements from the pre-generated public key matrix corresponding to the private key matrix.
[0055] Step 204, add the m first matrix elements to obtain the first private key, and add the m second matrix elements to obtain the first public key.
[0056] The first private key is equivalent to the combination of m first matrix elements, and the first public key is equivalent to the combination of m second matrix operations.
[0057] It should be noted that the above steps 201 to step 204 are similar to steps 101 to step 104 in other embodiments of the present application, and will not be elaborated here. For the specific implementation method, please refer to steps 101 to step 104 in other embodiments of the present application.
[0058] Step 205: Obtain the second private key and the second public key used for the previous generation of the digital signature.
[0059] Obtain the second private key and the second public key used when generating the digital signature last time.
[0060] It should be understood that depending on the signer or the data, the digital signature device will generate digital signatures multiple times. For example: For two data of signer A, the digital signature method will be run twice to generate two digital signatures, and then signer B generates one digital signature, for a total of 3 times of generating digital signatures. Therefore, when the digital signature device performs the second digital signature, it obtains the second private key and the second public key used in the first digital signature. When performing the third signature, it obtains the second private key and the second public key used in the second signature, and so on.
[0061] Step 206: Add the first private key to the second private key used for the previous generation of the digital signature to obtain the second private key used for the current generation of the digital signature.
[0062] Add the first private key generated this time to the second private key used in the previous generation of the digital signature to obtain the second private key used when generating the digital signature this time, that is, sk i = sk i-1 + sk m sk i is used to represent the second private key used when generating the digital signature this time, sk i-1 is used to represent the second private key used in the previous generation of the digital signature, sk m is used to represent the first private key. Therefore, the second private key for the i-th signature is equivalent to the combination of i * m first matrix elements.
[0063] Step 207: Add the first public key to the second public key used for the previous generation of the digital signature to obtain the second public key used for the current generation of the digital signature.
[0064] Add the first public key generated this time to the second public key used in the previous generation of the digital signature to obtain the second public key used when generating the digital signature this time, that is, PK i = PK i-1 + PK m PK i is used to represent the second public key used when generating the digital signature this time, PK i-1 is used to represent the second public key used in the previous generation of the digital signature, PK m is used to represent the first public key. Therefore, the second public key for the i-th signature is equivalent to the combination of i * m second matrix elements.
[0065] It should be understood that since the private key matrix and the public key matrix are usually not too large, generally being 16×16 matrices with only 256 elements, or j×j matrices with only j 2 elements, randomly selecting 3 to 5 elements and adding them up cannot cover the entire range of the finite field [1, n - 1] for the first private key. Therefore, continuously accumulating during the generation process of the private key and the public key can make the combination of the private key and the public key have infinitely many possibilities. The second private key can cover the entire range of [1, n - 1], satisfying the range [1, n - 1] for generating the random number k in the original signature step, and the second public key is the public key corresponding to the second private key. So, it can replace the generation of the random number k and the result of calculating the point multiplication of k and the base point G in the original signature step. Also, the first / second private keys and the first / second public keys are all intermediate values of the signature operation and are not made public, nor are the first matrix and the second matrix made public. Therefore, it can avoid the linear collusion attack on the combined public key.
[0066] Step 208: Generate the digital signature for the current time according to the second private key used for generating the digital signature for the current time, the second public key used for generating the digital signature for the current time, and the hash value.
[0067] According to the second private key sk i used for generating the digital signature for the current time, the second public key PK i used for generating the digital signature for the current time, and the hash value, generate the digital signature for the current time.
[0068] In the embodiments of the present application, multiple first matrix elements and second matrix elements are randomly selected, and the second private key and the second public key are continuously generated by accumulation respectively. Thus, the digital signature is generated according to the second private key and the second public key, realizing the generation of the digital signature. When generating the second private key and the second public key, the second private key and the second public key used in the previous digital signature are accumulated, making the range of the generated second private key and second public key larger, satisfying the range for generating the random number k in the original signature generation. Also, as intermediate values of the signature, the relevant matrices and results are not made public, avoiding the situation where the digital signature is cracked due to a collusion attack and improving the security of the signature generation method.
[0069] In a possible implementation manner, before generating the digital signature for the current time according to the second private key used for generating the digital signature for the current time, the second public key used for generating the digital signature for the current time, and the hash value, it is also possible to determine whether the second private key is equal to 0. If the second private key is equal to 0, then generate a first random number to regenerate the second private key.
[0070] Since the value range of the random number k in the original signature generation method is [1, n - 1], while the range of the second private key finite field is [0, n - 1], if the value of the second private key is 0, the process of generating a random number is re-executed. Thus, a new first private key can be generated based on the generated new random number, and accordingly, a new second private key can be generated.
[0071] In the embodiment of the present application, it is determined whether the second private key is equal to 0. If the second private key is equal to 0, a random number is regenerated, and further, a second private key can be regenerated, so that the second private key generated according to this method meets the value range of the random number in the original signature process. Therefore, the process of generating a random number in the original signature method can be replaced.
[0072] In a possible implementation manner, when generating the digital signature for the current time based on the second private key, the second public key, and the hash value used for generating the digital signature for the current time, the first signature part can be generated according to the hash value and / or the second public key used for generating the digital signature for the current time; the second signature part is generated according to the hash value and / or the second private key used for generating the digital signature for the current time, the signature private key, and the first signature part, and then the first signature part and the second signature part are combined to generate the digital signature.
[0073] According to the second public key and the hash value used for generating the digital signature for the current time, the first signature part r is calculated through the following formula r = (e + x1) mod n, where e is the hash value of the signature message, x1 is used to represent the x-axis coordinate of the second public key PK i and n is used to represent the order of the base point G.
[0074] Alternatively, the first signature part r in the ECDSA signature process can be calculated through the following formula r = x1 mod n according to the second public key used for generating the digital signature for the current time.
[0075] It should be understood that since the generation process of the public key is the point addition operation of the elliptic curve, the final value of the second public key is the point (x1, y1) on the elliptic curve.
[0076] According to the second private key and the first signature part used for generating the digital signature for the current time, the second signature part s is generated through the following formula s = ((1 + d A )) -1 *(sk i - r * d A )) mod n, where d A is used to represent the signature private key held by the signature user, and sk i is used to represent the second private key. The above is the signature process for replacing the national cryptographic standard SM2.
[0077] Similarly, the signature process of ECDSA can also be replaced, that is, through the second public key PKi For the x-axis coordinate x1, calculate r = x1 mod n, and calculate s = (sk i -1 *(e + r * d A )) mod n, where sk i is used to represent the second private key, e is the hash value of the signature message, and d A is used to represent the signature private key held by the signature user, and n is used to represent the order of the base point G.
[0078] Similarly, it is also possible to replace the dot multiplication operation of generating a random number k and calculating k * G in the Schnorr signature process and other signature processes. The replacement principle is the same as the above, and will not be elaborated here. Therefore, this signature fast generation method has a certain universality. For any signature process with the dot multiplication operation of generating a random number k and calculating k * G, this method can be used to replace it with the second private key sk i and the corresponding second public key PK i . The generated second private key sk i can satisfy that the value range of k covers [1, n - 1] and has randomness, which can meet its security. The generated second public key PK i is the public key corresponding to sk i . Therefore, the signature no longer requires dot multiplication operations, only a small number of finite field addition operations and a small number of elliptic curve point addition operations. Therefore, the amount of operations required in the signature process can be reduced.
[0079] It should also be understood that according to the ECC composite characteristic, the second public key is equal to the second private key multiplied by the base point G, that is, PK = [sk] * G, which satisfies the relationship of (x1, y1) = [k] * G in the prior art. And since the second private key is a random value and the second public key is a point on the elliptic curve, the second private key can replace the random number k in the prior art, and the second public key can replace the elliptic curve point (x1, y1) in the prior art. Therefore, dot multiplication operations are not required, and only elliptic curve point addition operations and finite field addition operations are needed to meet the elements required in the signature fast generation process. The specific derivation results of the ECC composite characteristic will not be elaborated here.
[0080] Combine the first signature part r and the second signature part s, and output the signature (r, s).
[0081] It should be noted that, according to the operation amounts in the national cryptography SM2 document for evaluation, the addition and subtraction operation amount of the finite field < the square operation (S) amount of the finite field < the multiplication operation (M) amount of the finite field < the inversion operation (I) amount of the finite field. The point addition in the Jacobian projective coordinate system of SM2 over the Fp field requires (12M + 4S) computational amount, and doubling a point requires (4M + 6S) computational amount. The method of pre-computing the k-fold point of the fixed point G approximately requires 32 doubling operations and 64 point addition operations. The method provided in this application optimizes the calculation process to calculate m point addition operations, and the operation amounts of the remaining steps can be converted into 1M, that is, let t = (1 + d A ) -1 mod n, then s = (t * (sk i + r) - r) mod n. Therefore, the ratio of the actual signature operation amounts when m takes values from 3 to 5 is approximately (37 - 61M + 12 - 20S) / (897M + 448S). So the total operation amount required for signing is less than 1 / 10 of the previous one, thereby improving the signature performance of the cryptographic device.
[0082] In the embodiments of this application, a digital signature is generated through a second private key, a second public key, and a hash value. The random number k and the dot product result of k and the base point G in the national cryptography SM2 signature or ECDSA signature steps can be replaced by the second private key and the second public key. The operation of the second private key only requires m addition operations in the finite field, and the operation of the second public key only requires m point addition operations in the finite field (because adding m elements requires m - 1 addition operations, and then one more addition operation is performed with the result of the second private key or the second public key of the previous signature), which greatly reduces the operation amount during the rapid generation of the signature and is applicable to signature generation devices with poor performance. Therefore, the rapid signature generation method has high applicability. It can also improve the signature performance per unit time of the same cryptographic device by reducing the operation amount of the signature.
[0083] In a possible implementation, before combining the first signature part and the second signature part to generate a digital signature, it is determined whether the first signature part and the second signature part are identically equal to 0. If the first signature part and / or the second signature part is identically equal to 0, then a first random number is generated to regenerate the digital signature.
[0084] When the first signature part and / or the second signature part is identically equal to 0, the step of generating the first random number is re-executed, that is, step 101 and step 201 in other embodiments of this application. After the first random number is regenerated, due to the change of the first random number, the first private key and the first public key change, resulting in changes in the results of subsequent steps, so that the first signature part and the second signature part can be regenerated until the requirements are met.
[0085] In the embodiment of the present application, when the first signature part and / or the second signature part do not meet the requirements, a first random number is regenerated, which ensures the validity of the digital signature, avoids the generation of invalid digital signatures, and improves the security of the signature quick generation method.
[0086] Figure 3 It is a schematic diagram of a signature quick generation device provided by an embodiment of the present application. As Figure 3 shown, the device 300 includes:
[0087] A first generation module 301, configured to generate a first random number.
[0088] A first extraction module 302, configured to extract m first matrix elements from a pre-generated private key matrix according to the first random number, where m is a positive integer greater than or equal to 2.
[0089] A second extraction module 303, configured to extract m second matrix elements with the same coordinates as the first matrix elements from a pre-generated public key matrix corresponding to the private key matrix.
[0090] A calculation module 304, configured to add the m first matrix elements to obtain a first private key, and add the m second matrix elements to obtain a first public key.
[0091] A second generation module 305, configured to generate a digital signature according to the first private key, the first public key, and a pre-generated hash value.
[0092] In the embodiment of the present application, the first generation module 301 can be used to execute step 101 in the above method embodiment, the first extraction module 302 can be used to execute step 102 in the above method embodiment, the second extraction module 303 can be used to execute step 103 in the above method embodiment, the calculation module 304 can be used to execute step 104 in the above method embodiment, and the second generation module 305 can be used to execute step 105 in the above method embodiment.
[0093] In a possible implementation manner, the first extraction module 302 can be used to determine m bytes from M bytes included in the first random number, where M is a positive integer greater than or equal to m; determine m matrix coordinates according to the content corresponding to the m bytes in the first random number; and extract m first matrix elements corresponding to the matrix coordinates from the private key matrix according to the m matrix coordinates.
[0094] In a possible implementation manner, the second extraction module 303 can be used to extract m second matrix elements corresponding to the matrix coordinates from the public key matrix according to the m matrix coordinates.
[0095] In a possible implementation, the signature fast generation device 300 may further generate preprocessing information according to the relevant parameters of the elliptic curve and the identity identifier of the signer; generate a hash value according to the preprocessing information.
[0096] In a possible implementation, the second generation module 305 may be used to obtain the second private key and the second public key used for the previous generation of the digital signature; add the first private key to the second private key used for the previous generation of the digital signature to obtain the second private key used for the current generation of the digital signature; add the first public key to the second public key used for the previous generation of the digital signature to obtain the second public key used for the current generation of the digital signature; generate the current digital signature according to the second private key used for the current generation of the digital signature, the second public key used for the current generation of the digital signature, and the hash value.
[0097] In a possible implementation, the second generation module 305 may be used to generate a first signature part according to the hash value and / or the second public key used for the current generation of the digital signature; generate a second signature part according to the hash value and / or the second private key used for the current generation of the digital signature, the signature private key, and the first signature part; combine the first signature part and the second signature part to generate a digital signature.
[0098] In a possible implementation, the second generation module 305 may be used to determine whether the first signature part and the second signature part are identically equal to 0; if the first signature part and / or the second signature part is identically equal to 0, then generate a first random number to regenerate the digital signature.
[0099] It should be noted that the information interaction, execution process, etc. between the modules in the above signature fast generation device, due to being based on the same concept as the foregoing signature fast generation method embodiment, the specific content can be referred to the description in the foregoing signature fast generation method embodiment, and will not be elaborated here.
[0100] Refer to Figure 4 , which shows a schematic structural diagram of an electronic device according to an embodiment of the present application. The specific implementation of the electronic device in the specific embodiment of the present application is not limited.
[0101] As Figure 4 shown, the electronic device may include: a processor 402, a communication interface 404, a memory 406, and a communication bus 408.
[0102] Wherein:
[0103] The processor 402, the communication interface 404, and the memory 406 communicate with each other through the communication bus 408.
[0104] A communication interface 404 for communicating with other electronic devices or servers.
[0105] A processor 402 for executing a program 410, which can specifically execute the relevant steps in the above-mentioned embodiments of the signature quick generation method.
[0106] Specifically, the program 410 may include program code, which includes computer operation instructions.
[0107] The processor 402 may be a central processing unit (CPU), or a graphics processing unit (GPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application. One or more processors included in the smart device may be of the same type of processor, such as one or more CPUs; one or more GPUs; or may be of different types of processors, such as one or more CPUs, one or more GPUs, and one or more ASICs.
[0108] A memory 406 for storing the program 410. The memory 406 may include high-speed RAM memory and may also include non-volatile memory, such as at least one disk memory.
[0109] The program 410 can specifically be used to cause the processor 402 to execute the signature quick generation method in any of the foregoing embodiments.
[0110] For the specific implementation of each step in the program 410, reference may be made to the corresponding steps and descriptions in the corresponding units in any of the foregoing embodiments of the signature quick generation method, which will not be elaborated here. Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described devices and modules can refer to the corresponding process descriptions in the foregoing method embodiments, which will not be elaborated here.
[0111] In the embodiment of the present application, the first matrix element and the second matrix element are extracted through the generated random number, and the first private key is obtained by adding the extracted first matrix elements, and the first public key is obtained by adding the second matrix elements. Then, a digital signature is generated according to the first private key, the first public key, and the hash value. By using the first private key generated by the finite field addition operation and the first public key generated by the elliptic curve point addition operation to replace the result of generating the random number k and calculating the dot product operation of k and the base point G in the existing signature generation method, the dot product operation is not required in the digital signature generation process. Moreover, the operation amounts of a small number of finite field addition operations and a small number of elliptic curve point addition operations are much smaller than one dot product operation. Therefore, the operation amount of this signature fast generation method is relatively low, only a small number of point addition operations need to be calculated, and the performance requirements for the cryptographic device are relatively low. Thus, the signature fast generation method is applicable to cryptographic devices with poor performance and has high applicability. It can also improve the signature performance per unit time of the same cryptographic device by reducing the operation amount of the signature.
[0112] The embodiment of the present application also provides a computer program product, including computer instructions, and the computer instructions direct a computing device to perform the operations corresponding to any one of the above-mentioned multiple method embodiments.
[0113] It should be noted that, according to the needs of implementation, each component / step described in the embodiment of the present application can be split into more components / steps, or two or more components / steps or partial operations of components / steps can be combined into new components / steps to achieve the purpose of the embodiment of the present application.
[0114] The method according to the embodiment of the present application can be implemented in hardware, firmware, or be implemented as software or computer code that can be stored in a recording medium (such as a CD ROM, RAM, floppy disk, hard disk, or magneto-optical disk), or be implemented as computer code that is originally stored in a remote recording medium or a non-transitory machine-readable medium and downloaded through a network and will be stored in a local recording medium. Thus, the method described herein can be processed by such software stored on a recording medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware (such as an ASIC or FPGA). It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component (such as RAM, ROM, flash memory, etc.) that can store or receive software or computer code. When the software or computer code is accessed and executed by the computer, the processor, or the hardware, the signature fast generation method described herein is implemented. In addition, when a general-purpose computer accesses the code for implementing the signature fast generation method shown herein, the execution of the code converts the general-purpose computer into a dedicated computer for executing the signature fast generation method shown herein.
[0115] Those of ordinary skill in the art can realize that the units and method steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the embodiments of this application.
[0116] The above embodiments are only used to illustrate the embodiments of this application, rather than to limit the embodiments of this application. Those of ordinary skill in the relevant technical field can also make various changes and modifications without departing from the spirit and scope of the embodiments of this application. Therefore, all equivalent technical solutions also belong to the scope of the embodiments of this application. The patent protection scope of the embodiments of this application should be defined by the claims.
Claims
1. A method for quickly generating a signature, comprising: Generating a first random number; Extracting m first matrix elements from a pre-generated private key matrix according to the first random number, where m is a positive integer greater than or equal to 2; Extracting m second matrix elements with the same coordinates as the first matrix elements from a pre-generated public key matrix corresponding to the private key matrix; Adding the m first matrix elements to obtain a first private key, and adding the m second matrix elements to obtain a first public key; Generating a digital signature according to the first private key, the first public key, and a pre-generated hash value; The generating a digital signature according to the first private key, the first public key, and a pre-generated hash value includes obtaining a second private key and a second public key used for the previous generation of the digital signature; adding the first private key to the second private key used for the previous generation of the digital signature to obtain a second private key for the current generation of the digital signature; adding the first public key to the second public key used for the previous generation of the digital signature to obtain a second public key for the current generation of the digital signature; generating the digital signature for the current time according to the second private key for the current generation of the digital signature, the second public key for the current generation of the digital signature, and the hash value.
2. The method according to claim 1, wherein The extracting m first matrix elements from a pre-generated private key matrix according to the first random number includes: Determining m bytes from M bytes included in the first random number, where M is a positive integer greater than or equal to m; Determining m matrix coordinates according to the content corresponding to the m bytes in the first random number; Extracting m first matrix elements corresponding to the matrix coordinates from the private key matrix according to the m matrix coordinates.
3. The method according to claim 2, wherein The extracting m second matrix elements with the same coordinates as the first matrix elements from a pre-generated public key matrix corresponding to the private key matrix includes: Extracting m second matrix elements corresponding to the matrix coordinates from the public key matrix according to the m matrix coordinates.
4. The method according to claim 1, wherein, Before generating the digital signature for the current time according to the second private key for the current generation of the digital signature, the second public key for the current generation of the digital signature, and the hash value, the method further includes: Judging whether the second private key is equal to 0; If the second private key is equal to 0, then execute the generating of the first random number to regenerate the second private key.
5. The method according to claim 1, wherein, The generating the digital signature for the current time according to the second private key for the current generation of the digital signature, the second public key for the current generation of the digital signature, and the hash value includes: Generating a first signature part according to the hash value and / or the second public key for the current generation of the digital signature; Generating a second signature part according to the hash value and / or the second private key for the current generation of the digital signature, a signature private key, and the first signature part; Combining the first signature part and the second signature part to generate the digital signature.
6. The method according to claim 5, wherein, Before combining the first signature part and the second signature part to generate the digital signature, the method further includes: Judging whether the first signature part and the second signature part are always equal to 0; If the first signature part and / or the second signature part is constantly equal to 0, then execute the generation of the first random number to regenerate the digital signature.
7. A signature fast generation device, comprising: A first generation module, configured to generate a first random number; A first extraction module, configured to extract m first matrix elements from a pre-generated private key matrix according to the first random number, where m is a positive integer greater than or equal to 2; A second extraction module, configured to extract m second matrix elements with the same coordinates as the first matrix elements from a pre-generated public key matrix corresponding to the private key matrix; A calculation module, configured to add the m first matrix elements to obtain a first private key, and add the m second matrix elements to obtain a first public key; A second generation module, configured to generate a digital signature according to the first private key, the first public key, and a pre-generated hash value; The second generation module is further configured to: obtain a second private key and a second public key used for the previous generation of the digital signature; add the first private key to the second private key used for the previous generation of the digital signature to obtain a second private key for the current generation of the digital signature; add the first public key to the second public key used for the previous generation of the digital signature to obtain a second public key for the current generation of the digital signature; generate the digital signature for the current time according to the second private key for the current generation of the digital signature, the second public key for the current generation of the digital signature, and the hash value.
8. An electronic device, comprising: A processor, a memory, a communication interface, and a communication bus, where the processor, the memory, and the communication interface complete mutual communication through the communication bus; The memory is used to store at least one executable instruction, and the executable instruction causes the processor to execute the signature fast generation method according to any one of claims 1-6.
9. A computer storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the signature fast generation method according to any one of claims 1-6.
Citation Information
Patent Citations
Digital signature generation method and device, computer equipment and storage medium
CN111628868A