A method and system for generating a digital signature key

By generating verification keys and messages in the signature node and merging them into public keys in the verification nodes, the problem of relying on centralized nodes to generate keys in the prior art is solved, and security and efficiency are improved.

CN116192408BActive Publication Date: 2025-07-18方建
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310260289.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-10
Publication Date
2025-07-18
Estimated Expiration
2043-03-10

AI Technical Summary

Technical Problem

In the prior art, the generation and distribution of digital signature keys depend on centralized third-party nodes, resulting in large communication overhead, time-consuming and cumbersome processes, and it is impossible to avoid relying on centralized nodes to generate keys when multiple nodes sign at the same time.

Method used

All signature nodes generate verification keys and verification messages separately, and send them to the verification node for verification. After verification is passed, merge it into a public key. A bilinear mapped elliptic curve is used to generate verification keys, and a zero-knowledge proof is used to process the signature node update.

Benefits of technology

It effectively avoids dependence on centralized nodes, improves security, simplifies the key generation and update process, and improves the efficiency and security of multi-node signatures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116192408B_ABST
    Figure CN116192408B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for generating a digital signature key. The method includes: first, each signature node generates a verification key and a verification message respectively; then, all the verification keys and verification messages are sent to the verification node; next, the verification node verifies all the received verification messages; finally, when all the received verification messages pass the verification, all the verification keys received by the verification node are merged as the public key, which can effectively avoid the digital signature key depending on a centralized third-party node or a first-party node for generation, and no node can complete the signature alone, effectively improving the security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer technology, and particularly relates to a method and system for generating digital signature keys. Background Art

[0002] With the development of current computer network communication and digital authentication, digital signature is an essential part. A digital signature usually consists of a pair of asymmetric keys (public key and private key). Among them, the public key is used to verify the signature and is made public to all users, while the private key is used to generate the signature and needs to be privately stored at a trusted user or trusted node. The traditional process is that the main user with signature authority generates keys through a key generation device, saves the private key at a local single device or trusted device, makes the public key public to all communication users who communicate with itself. When the main user sends a message to a communication user, the private key is used to sign the message to generate a signature. When the communication user receives the message and the signature, the public key is used to verify the message and the signature.

[0003] With the development of the Internet, in many scenarios, multiple parties need to sign simultaneously. The existing technical solutions generally adopt the BLS threshold signature algorithm to split the private key, and the decomposed results are sent to different communication users for subsequent signature and other operations. However, in the current technical solutions, the generation and distribution of keys in digital signatures usually rely on a trusted third party, such as a digital certification center or a user participating in the signature. Therefore, there will be a situation where a certain third party or user has the complete signature key and can complete the signature independently. If the authority of the original key administrator changes and the key needs to be updated, it also depends on the trusted third party or the first party to regenerate the public key and private key. Not only is the communication overhead large, but all nodes, whether they are signature parties or verification parties, need to update the keys, which is time-consuming and the process is cumbersome.

[0004] Therefore, how to avoid the need for digital signature keys to rely on a centralized third-party node or the first-party node for generation when multiple nodes sign simultaneously is a technical problem to be solved by those skilled in the art. Summary of the Invention

[0005] The purpose of the present invention is to solve the technical problem that in the prior art, when multiple nodes sign simultaneously, digital signature keys need to rely on a centralized third-party node or the first-party node for generation.

[0006] To achieve the above technical purpose, on the one hand, the present invention provides a method for generating digital signature keys, which is applied to multiple signature nodes and verification nodes. The method includes:

[0007] Respectively generate verification keys and verification messages through all signature nodes;

[0008] Send all verification keys and verification messages to the verification nodes;

[0009] Verify all the received verification messages through the verification nodes;

[0010] After all the received verification messages pass the verification by the verification nodes, merge all the verification keys received by the verification nodes and use them as the public key.

[0011] Further, generate verification keys and verification messages through the signature nodes, specifically including:

[0012] Generate signature keys through the signature nodes;

[0013] Generate the verification keys based on the signature keys, and determine the zero-knowledge proof as the verification message through a preset algorithm.

[0014] Further, all signature nodes and verification nodes include elliptic curves applicable to bilinear mapping.

[0015] Further, the generating of the verification keys based on the signature keys specifically includes:

[0016] Generate a first prime-order group, a second prime-order group, and a third prime-order group through the corresponding elliptic curve in the signature node; after the bilinear mapping relationship satisfies the first prime-order group × the second prime-order group → the third prime-order group, generate the verification keys based on the generator of the second prime-order group and the signature keys;

[0017] Further, specifically generate the verification keys through the following formula:

[0018] vk i =(g2)^(sk i )

[0019] In the formula, vk i is the verification key of the i-th signature node, g2 is the generator, and sk i is the signature key of the i-th signature node.

[0020] Further, the merging of all the verification keys received by the verification nodes and using them as the public key is specifically merged through the following formula:

[0021]

[0022] In the formula, vk is the public key, i is the signature node serial number, j is the signature node serial number less than i, I is the set of all signature node serial numbers, and vk i is the verification key of the i-th signature node.

[0023] Further, the method further includes:

[0024] When the signature node is updated;

[0025] Decompose the signature keys in all the signature nodes before the update into a preset number of private shares respectively, and generate a zero-knowledge proof corresponding to each signature node before the update, where the preset number is specifically the number of signature nodes after the update;

[0026] Send the zero-knowledge proof corresponding to each signature node before the update and all the private shares to each signature node after the update;

[0027] Generate a corresponding new signature key based on the zero-knowledge proof and private shares received by each signature node after the update.

[0028] On the other hand, the present invention also provides a digital signature key generation system, which is applied to multiple signature nodes and verification nodes. The system includes:

[0029] A generation module, which is respectively deployed in all signature nodes and is used to generate a verification key and a verification message in the signature node;

[0030] A sending module, which is respectively deployed in all signature nodes and is used to send the verification key and the verification message in the corresponding signature node to the verification node;

[0031] A verification module, which is deployed in the verification node and is used to verify all the received verification messages;

[0032] A merging module, which is deployed in the verification node and is used to, after all the received verification messages are verified and passed by the verification node, merge all the verification keys received by the verification node as the public key.

[0033] A digital signature key generation method and system provided by the present invention, compared with the prior art, first generate a verification key and a verification message respectively through all signature nodes; then send all the verification keys and verification messages to the verification node; then verify all the received verification messages through the verification node; finally, after all the received verification messages are verified and passed by the verification node, merge all the verification keys received by the verification node as the public key, which can effectively avoid the digital signature key relying on a centralized third-party node or a first-party node to be generated, and no node can complete the signature alone, effectively improving the security. Description of the Drawings

[0034] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments described in this specification. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0035] Figure 1 The following shows a schematic flowchart of the digital signature key generation method provided by the embodiments of this specification;

[0036] Figure 2 The following shows a schematic structural diagram of the digital signature key generation system provided by the embodiments of this specification. Detailed implementation manners

[0037] To enable those of ordinary skill in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this application in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this application.

[0038] As Figure 1 The following shows a schematic flowchart of the digital signature key generation method provided by the embodiments of this specification. Although this specification provides the method operation steps or system structures shown in the following embodiments or accompanying drawings, based on routine or without creative efforts, more or fewer operation steps or module units may be included in the method or system. In the steps or structures where there is no necessary causal relationship logically, the execution order of these steps or the module structure of the system is not limited to the execution order or module structure shown in the embodiments of this specification or the accompanying drawings. When the described method or module structure is applied to an actual system, server, or terminal product, it can be executed sequentially or in parallel according to the method or module structure shown in the embodiments or the accompanying drawings (for example, in an environment of parallel processors or multi-threaded processing, and even including an environment of distributed processing and server clusters).

[0039] The digital signature key generation method provided in the embodiments of this specification can be applied to terminal devices such as clients and servers. As Figure 1 shown, the method specifically includes the following steps:

[0040] Step S101: Generate verification keys and verification messages respectively through all signature nodes.

[0041] Specifically, a key generation algorithm, a key decomposition algorithm, and a key merging algorithm are deployed in all signature nodes, and only the key merging algorithm is deployed in the verification nodes. In this application, both the signature and verification methods are standard BLS threshold signature algorithms. The signature nodes can correspond to different software and hardware of different users, or different software and hardware of the same user.

[0042] In the embodiment of this application, the verification key and verification message are generated by the signature node, specifically including:

[0043] Generate a signature key through the signature node;

[0044] Generate the verification key based on the signature key, and determine the zero-knowledge proof as the verification message through a preset algorithm.

[0045] Specifically, all signature nodes and verification nodes in this application include elliptic curves applicable to bilinear mapping. This elliptic curve is used to generate necessary parameters to generate keys or merge keys. The necessary parameters are specifically the first prime-order group, the second prime-order group, and the third prime-order group; after the bilinear mapping relationship satisfies the first prime-order group × the second prime-order group → the third prime-order group, the verification key is generated based on the generator of the second prime-order group and the signature key.

[0046] Among them, the elliptic curve can be the bls12_381 elliptic curve. Through this curve, the first prime-order group G1, the second prime-order group G2, and the third prime-order group G with prime number p are generated T , and the bilinear mapping relationship e satisfies G1 × G2 → G T , where the generator of the second prime-order group G2 is g2. The key generation algorithm runs independently in the signature node i, and a positive integer less than p is randomly selected as the signature key sk i , and the verification key vk of the signature node i i =(g2)^(sk i ), and at the same time, a zero-knowledge proof is determined through a preset algorithm to prove that the above calculation is correct.

[0047] Step S102: Send all the verification keys and verification messages to the verification nodes.

[0048] Specifically, the signature node saves the generated signature key locally and sends the corresponding verification key and verification message to the verification nodes. If there are multiple verification nodes, the verification key and verification message need to be sent to each verification node.

[0049] Step S103: Verify all the received verification messages through the verification nodes.

[0050] Specifically, after receiving all verification keys and verification messages, the verification node will verify the verification messages sent by each signature node in chronological order to determine whether the verification keys are valid. If any of the verification messages fails the verification, it indicates that the key generation has expired or an exception has occurred. The subsequent operations are terminated, and all signature nodes are reset for key generation to regenerate signature keys, verification keys, and verification messages.

[0051] Step S104: After all the received verification messages pass the verification, the verification node merges all the received verification keys as the public key.

[0052] Specifically, after all the verification messages received by the verification node pass the verification, the received verification keys are merged through the following formula:

[0053]

[0054] In the formula, vk is the public key, i is the signature node serial number, j is the signature node serial number less than i, I is the set of all signature node serial numbers, and vk i is the verification key of the i-th signature node.

[0055] In the embodiment of the present application, the method further includes:

[0056] When the signature node is updated;

[0057] The signature keys in all the signature nodes before the update are respectively decomposed into a preset number of privacy shares, and a zero-knowledge proof corresponding to each signature node before the update is generated. The preset number is specifically the number of signature nodes after the update;

[0058] The zero-knowledge proof corresponding to each signature node before the update and all the privacy shares are sent to each signature node after the update;

[0059] Based on the zero-knowledge proof and privacy shares received by each signature node after the update, a corresponding new signature key is generated.

[0060] When an update occurs at the signature node, such as adding or reducing a signature node, the signature keys in all the signature nodes before the update are decomposed through a key sharing algorithm into a preset number of private shares. The preset number is specifically the number of signature nodes after the update. It should be noted that it is not necessary to have all the private shares to construct the complete signature key. Only by specifying a number t of private shares can the complete signature key be generated. After receiving the private shares and zero-knowledge proofs sent by each signature node before the update, the signature nodes after the update first verify the zero-knowledge proofs. After all are correct, any specified number t of private shares sent by the signature nodes before the update received are selected and merged. The merging formula is as follows:

[0061]

[0062] In the formula, sk b is the new signature key of the b-th signature node after the update, sk a,b is the private share 0 sent from the a-th signature node before the update to the b-th signature node after the update. a is the serial number of the signature node before the update, b is the serial number of the signature node after the update, A is the set of serial numbers of the signature nodes before the update, and j ′ is the serial number of the signature node before the update that is not equal to a.

[0063] It should be noted that generating the signature key through the above formula is actually a private share for generating the private key in the BLS threshold signature algorithm. The private key in this application can be obtained by merging a specified number of signature keys. If the number is less than the specified number, no information about the private key can be obtained. In the definition of cryptography, the signature key that satisfies these conditions is a private share of the private key.

[0064] Based on the above digital signature key generation method, one or more embodiments of this specification also provide a platform and a terminal for generating a digital signature key. The platform or terminal may include devices, software, modules, plugins, servers, clients, etc. that use the method described in the embodiments of this specification and are combined with the necessary implementation hardware. Based on the same innovative concept, the systems in one or more embodiments provided by the embodiments of this specification are as described in the following embodiments. Since the implementation schemes for the systems to solve problems are similar to the methods, the implementation of the specific systems in the embodiments of this specification can refer to the implementation of the foregoing methods, and the repeated parts will not be elaborated. The term "unit" or "module" used below can be a combination of software and / or hardware that can achieve a predetermined function. Although the systems described in the following embodiments are preferably implemented in software, implementation in hardware or a combination of software and hardware is also possible and contemplated.

[0065] Specifically, Figure 2It is a schematic diagram of the module structure of an embodiment of the digital signature key generation system provided in this specification. As Figure 2 shown, the digital signature key generation system provided in this specification includes:

[0066] A generation module 201, which is respectively deployed in all signature nodes and is used to generate a verification key and a verification message in the signature nodes;

[0067] A sending module 202, which is respectively deployed in all signature nodes and is used to send the verification key and the verification message in the corresponding signature nodes to the verification nodes;

[0068] A verification module 203, which is deployed in the verification nodes and is used to verify all the received verification messages;

[0069] A merging module 204, which is deployed in the verification nodes and is used to, after all the received verification messages pass the verification, merge all the verification keys received by the verification nodes and use them as the public key.

[0070] It should be noted that the above system may also include other implementation manners according to the description of the corresponding method embodiment. The specific implementation manner may refer to the description of the corresponding method embodiment above and will not be elaborated here one by one.

[0071] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0072] The method or device described in the above embodiments provided in this specification can implement the business logic through a computer program and record it on a storage medium. The storage medium can be read and executed by a computer to achieve the effects of the solutions described in the embodiments of this specification, such as:

[0073] Generating a verification key and a verification message respectively through all signature nodes;

[0074] Sending all the verification keys and verification messages to the verification nodes;

[0075] Verifying all the received verification messages through the verification nodes;

[0076] After all the received verification messages pass the verification, merging all the verification keys received by the verification nodes and using them as the public key.

[0077] The storage medium may include a physical device for storing information, usually by digitizing the information and then storing it in a medium using electrical, magnetic, or optical means. The storage medium may include: devices that store information using electrical energy, such as various memories, such as RAM, ROM, etc.; devices that store information using magnetic energy, such as hard disks, floppy disks, magnetic tapes, magnetic core memories, magnetic bubble memories, USB flash drives; devices that store information using optical means, such as CDs or DVDs. Of course, there are also other types of readable storage media, such as quantum memories, graphene memories, and so on.

[0078] The embodiments of this specification are not limited to those that must conform to industry communication standards, standard computer resource data update and data storage rules, or the situations described in one or more embodiments of this specification. Certain industry standards or implementation bases described using custom methods or embodiments, with slightly modified implementation schemes, can also achieve the same, equivalent, or similar, or predictable implementation effects after transformation as the above embodiments. The embodiments obtained by applying these modified or transformed data acquisition, storage, judgment, processing methods, etc. still fall within the scope of the optional implementation schemes of the embodiments of this specification.

[0079] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor, and a computer-readable medium that stores computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, application specific integrated circuit (ASIC), programmable logic controller, and embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, the method steps can be logically programmed to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, and embedded microcontrollers to achieve the same function. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or the structures within the hardware component.

[0080] The system embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or plugins can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed among each other can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.

[0081] These computer program instructions can also be loaded onto a computer or other programmable resource data update device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the steps for the functions specified in Figure 1 one process or multiple processes and / or Figure 1 the steps for the functions specified in one block or multiple blocks.

[0082] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple. The relevant parts can refer to the description of the method embodiments. In the description of this specification, the description referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0083] Those of ordinary skill in the art will realize that the embodiments described here are for helping readers understand the principles of the present invention. It should be understood that the protection scope of the present invention is not limited to such specific statements and embodiments. Those of ordinary skill in the art can make various other specific deformations and combinations that do not depart from the essence of the present invention based on these technical revelations disclosed in the present invention, and these deformations and combinations are still within the protection scope of the present invention.

Claims

1. A method for generating a digital signature key, characterized in that, Applied to multiple signature nodes and verification nodes, the method includes: Generating verification keys and verification messages respectively by all signature nodes; Sending all the verification keys and verification messages to the verification nodes; Verifying all the received verification messages by the verification nodes; When all the received verification messages are successfully verified by the verification nodes, merging all the verification keys received by the verification nodes as the public key; The merging of all the verification keys received by the verification nodes as the public key is specifically carried out through the following formula: Wherein, vk is the public key, i is the serial number of the signature node, j is the serial number of the signature node less than i, I is the set of all serial numbers of the signature nodes, and vk i is the verification key of the i-th signature node; Generating verification keys and verification messages by the signature nodes specifically includes: Generating signature keys by the signature nodes; Generating the verification keys based on the signature keys and determining zero-knowledge proofs through a preset algorithm as the verification messages.

2. The digital signature key generation method according to claim 1, wherein All signature nodes and verification nodes include elliptic curves applicable to bilinear mapping.

3. The digital signature key generation method according to claim 2, wherein The generating of the verification keys based on the signature keys specifically includes: Generating a first prime-order group, a second prime-order group, and a third prime-order group through the corresponding elliptic curve in the signature node; after the bilinear mapping relationship satisfies the first prime-order group × the second prime-order group → the third prime-order group, generating the verification keys based on the generator of the second prime-order group and the signature keys.

4. The digital signature key generation method according to claim 3, characterized in that, Specifically generating the verification keys through the following formula: vk i =(g2)∧(sk i ) where, vk i is the verification key of the i-th signature node, g2 is the generator, sk i is the signature key of the i-th signature node.

5. The digital signature key generation method according to claim 1, wherein, The method further includes: When the signature node is updated; Decomposing the signature keys in all pre-update signature nodes into a preset number of privacy shares respectively, and generating zero-knowledge proofs corresponding to each pre-update signature node, the preset number is specifically the number of post-update signature nodes; Sending the zero-knowledge proofs corresponding to each pre-update signature node and all privacy shares to each post-update signature node; Generating corresponding new signature keys based on the zero-knowledge proofs and privacy shares received by each post-update signature node.

6. A digital signature key generation system, characterized in that, Applied to multiple signature nodes and verification nodes, the system includes: A generating module, respectively deployed in all signature nodes, for generating verification keys and verification messages in the signature nodes; Generating verification keys and verification messages by the signature nodes specifically includes: Generating signature keys by the signature nodes; Generating the verification keys based on the signature keys and determining zero-knowledge proofs through a preset algorithm as the verification messages; A sending module, respectively deployed in all signature nodes, for sending the verification keys and verification messages in the corresponding signature nodes to the verification nodes; A verification module, deployed in the verification nodes, for verifying all the received verification messages; A merging module, deployed in the verification nodes, for when all the received verification messages are successfully verified by the verification nodes, merging all the verification keys received by the verification nodes as the public key; The merging of all the verification keys received by the verification nodes as the public key is specifically carried out through the following formula: Wherein, vk is the public key, i is the serial number of the signature node, j is the serial number of the signature node less than i, I is the set of serial numbers of all signature nodes, and vk i is the verification key of the i-th signature node.

Citation Information

Patent Citations

  • Threshold signature-based alliance chain cross-chain transaction method and device

    CN113902439A