An original image Gaussian sampling method, system, electronic device and storage medium

By constructing a parallel version of the trap gate and using fast sampling technology, the security and efficiency problems of the existing original Gaussian sampling method in the quantum computing environment are solved, and efficient and secure digital signatures are achieved.

CN116232563BActive Publication Date: 2025-06-17GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211658716.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-22
Publication Date
2025-06-17
Estimated Expiration
2042-12-22

AI Technical Summary

Technical Problem

The existing original Gaussian sampling method is difficult to ensure security in a quantum computing environment, and the sampling efficiency is low, making it impossible to take into account high parallelism and low storage space.

Method used

By constructing a parallel version of the trap gate, using fast sampling technology, a fully parallelized original Gaussian sampling method is realized, reducing the time and storage space of trap gate generation and improving the sampling efficiency.

Benefits of technology

Efficient original Gaussian sampling is achieved, reducing the size of Gaussian parameters, improving the security of digital signatures, and improving space and time efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116232563B_ABST
    Figure CN116232563B_ABST
Patent Text Reader

Abstract

The present invention discloses a preimage Gaussian sampling method, which includes the steps of: selecting a Gaussian parameter s, and using a key generation algorithm to generate a signature key sk and a verification key vk; specifically including determining the Gaussian parameter, selecting a polynomial constituting a trapdoor, selecting a tool vector g<supgt;t< / supgt>, constructing a trapdoor matrix R, obtaining a check vector a<supgt;t< / supgt>, and setting the signature key sk = R and the verification key vk = a; using the signature key sk to sign the selected message M; and using the verification key vk to verify the legality of the received signed message. The present invention also discloses a preimage Gaussian sampling system, a computer device, and a storage medium. The present invention requires fewer elements for constructing the trapdoor, and the constructed trapdoor is a parallel version, which can be fully parallelized during the process of disturbing sampling, reducing the ring elements of the disturbed vectors sampled, and improving the efficiency of disturbing sampling.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and particularly relates to a preimage Gaussian sampling method, system, electronic device, and storage medium. Background Art

[0002] Public-key cryptography is an important way to ensure secure information transmission. Traditional public-key cryptography is widely constructed based on the problems of large number factorization and discrete logarithm. In the environment of quantum computers, their security cannot be guaranteed, which makes it an urgent task to study cryptographic algorithms resistant to quantum attacks. As one of the post-quantum algorithm systems resistant to quantum computing, lattice cryptography has a potentially valuable cryptographic structure. The cryptographic scheme based on lattices is concise and efficient, and the security of the scheme is based on the difficult problems on lattices, which enables the worst-case security of the lattice cryptographic scheme to be reduced to the average-case security, a characteristic not possessed by other post-quantum cryptographic systems.

[0003] Due to the good characteristics of lattice cryptography, it has become a research hotspot in recent years. Preimage Gaussian sampling, as one of the core algorithms of lattice cryptography, has extensive applications in cryptographic systems based on lattices. Among them, the hash-and-sign signature based on the preimage sampling algorithm is one of its applications. In 2008, Gentry et al. proposed an algorithm for generating a trapdoor for the Short Integer Solution (SIS) problem and performed preimage Gaussian sampling based on this trapdoor, but the sampling efficiency was relatively low. To improve the efficiency of trapdoor generation and sampling, in 2012, Micciancio and Peikert proposed the G-trapdoor, which divides the preimage Gaussian sampling algorithm into perturbation sampling and G-lattice sampling. Compared with ordinary lattices, preimage Gaussian sampling has higher efficiency on algebraic lattices. In 2014, Ducas et al. first proposed the Ring SIS (RSIS) trapdoor on the NTRU (Number Theory Research Unit) lattice. In 2016, Ducas and Prest made full use of the algebraic structure of the NTRU lattice and improved the efficiency of preimage Gaussian sampling through the Fast Fourier Transform. Recently, Genise and Li introduced two RSIS trapdoors similar to the G-trapdoor on the NTRU lattice. The first trapdoor is a noisy version, but the perturbation sampling can be fully parallelized. However, the modulus q is relatively large and cannot be directly combined with fast sampling techniques, resulting in low signature efficiency. The second trapdoor has a short public key size and can be combined with fast sampling techniques, but it cannot be parallel-accelerated. Summary of the Invention

[0004] The main objective of the present invention is to provide a preimage Gaussian sampling method, system, computer device, and storage medium, which can achieve full parallelization and improve the efficiency of preimage Gaussian sampling by using fast sampling techniques.

[0005] To achieve the above object, the technical solution adopted by the present invention is as follows:

[0006] In a first aspect, the present invention discloses a preimage Gaussian sampling method, including the steps of:

[0007] Step 1: Select Gaussian parameter s, and use a key generation algorithm to generate a signature key sk and a verification key vk; specifically including the steps of:

[0008] Step 1.1: Let the Gaussian parameter of the signature where α represents a quality parameter, σ represents the Gaussian parameter of the trapdoor, and n is a power of 2;

[0009] Step 1.2: Select polynomials f, g1, g2,..., g k-1 ∈R, where represents a ring, b is a small integer, q represents the modulus, and these polynomials are invertible on R q R q is the coefficient of the polynomial on the ring R modulo q, and each polynomial follows a discrete Gaussian distribution with parameter σ;;

[0010] Step 1.2: Select the tool vector Construct the trapdoor matrix R = diag(f, g1, g2,..., g k-1 )∈R k×k , Let the check vector where m = k;

[0011] Step 1.3: Select the tool vector Construct the trapdoor matrix R = diag(f, g1, g2,..., g k-1 )∈R k×k , Let the check vector where m = k;

[0012] Step 1.4: Let the signature key sk = R and the verification key vk = a;

[0013] Step 2: Sign the selected message M using the signature key sk;

[0014] Step 3: Verify the legality of the received signed message using the verification key vk.

[0015] Preferably, in step 2: Sign the selected message M using the signature key sk, including the steps of:

[0016] Step 2.1: From the signature message space {0,1} *Select the message M to be signed, and calculate μ = h(M, r), where h(·): {0, 1} * →R q is a collision-resistant hash function, and r is a random bit string;

[0017] Step 2.2: Sample the perturbation vector where

[0018] Step 2.3: Calculate the target v = (μ - a t ·p)·f -1 mod q, and sample on the coset of the g-lattice according to the discrete Gaussian distribution to obtain the target vector z.

[0019] Step 2.4: Let x = p + Rz = (x0, x1, …, x k-1 );

[0020] Step 2.5: Discard the first component x0 of x, and output x' = (x1, …, x k-1 ) as the signature of the message M.

[0021] Preferably, in Step 2.2: Sampling the perturbation vector where Specifically includes the steps:[[]]

[0022] Step 2.2.1: Using as the Gaussian parameter and 0 as the center point, sample on the ring R to obtain q0; for i = 1, …, k - 1, using as the Gaussian parameter and 0 as the center point, sample on the ring R to obtain q i ;

[0023] Step 2.2.2: Let p = (q0, q1, …, q k-1 ) ∈ R k .

[0024] Preferably, in Step 3: Use the verification key vk to verify the legality of the received signed message, including the steps:

[0025] Step 3.1: Calculate x0 = h(M, r) - a t ·x mod q, where the signature x' = (x1, …, x k-1 );

[0026] Step 3.2: If ||(x0, x1, …, x k-1 )|| 2 ≤ s2 If ·m·n holds, the verification passes; otherwise, the verification fails.

[0027] In a second aspect, the present invention discloses a preimage Gaussian sampling system, including:

[0028] A generation module, which is used to select Gaussian parameter s and generate a signature key sk and a verification key vk by using a key generation algorithm;

[0029] A signature module, which is used to sign the selected message M by using the signature key sk;

[0030] A verification module, which is used to verify the legitimacy of the received signed message by using the verification key vk.

[0031] In a third aspect, the present invention discloses a computer device, which includes a memory, a processor, and a computer program stored on the memory and executable on the processor. Wherein, when the processor executes the program, the steps of the method described above are implemented.

[0032] In a fourth aspect, the present invention discloses a computer-readable storage medium, on which a computer program is stored, and the program is executed by a processor to implement the method described above.

[0033] Compared with the prior art, the preimage Gaussian sampling method, system, electronic device, and storage medium of the present invention have at least the following beneficial effects:

[0034] (1) The present invention requires fewer elements to construct a trapdoor, reduces the time for trapdoor generation, and reduces the storage space of the trapdoor.

[0035] (2) The trapdoor constructed by the present invention is a parallel version, which can be fully parallelized during the scrambling sampling process, and reduces the ring elements of the sampled scrambling vectors, improving the efficiency of the scrambling sampling.

[0036] (3) By reducing the Gaussian parameter, the present invention reduces the size of the signature and improves the security of the digital signature. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 is a schematic flow chart of the preimage Gaussian sampling method of the present invention;

[0038] Figure 2 is a schematic structural diagram of the preimage Gaussian sampling system of the present invention;

[0039] Figure 3 is a circuit module connection diagram of the computer device of the present invention.

[0040] In the figure: 101, generation module; 102, signature module; 103, verification module;

[0041] 300, Bus; 301, Receiver; 302, Processor; 303, Transmitter; 304, Memory; 306, Bus Interface. Detailed Implementation Manner

[0042] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0043] Embodiment 1

[0044] This embodiment combines Figure 1 the flowchart to illustrate the usage mode of the original-phase Gaussian sampling method in practical applications. In this demonstration scenario, the signer S signs the message M, and after the verifier V receives the signature, it verifies its legality. The specific process is as follows:

[0045] Step 1: The signer S selects the Gaussian parameter s for signing, and uses the key generation algorithm to generate the signature key sk and the verification key vk; specifically, it includes the following steps:

[0046] Step 1.1: Let the Gaussian parameter for signing where α represents a quality parameter, σ represents the Gaussian parameter of the trapdoor, and n is a power of 2;

[0047] Step 1.2: Select the polynomials f, g1, g2,..., g k-1 ∈R, where represents a ring, b is a small integer, q represents the modulus, these polynomials are invertible on R q , R q is the coefficient of the polynomial on the ring R modulo q, and each polynomial follows a discrete Gaussian distribution with parameter σ; the specific steps of selecting the polynomials f and g1, g2,..., g k-1 are the same. Taking the selection of the polynomial f as an example, it is described as follows:

[0048] Step 1.2.1: For i = 1,..., K, select the random vectors f1,..., f from the discrete Gaussian distribution with parameter K , where represents an integer;

[0049] Step 1.2.2: For i = 1,..., K, j = 1,..., K and i ≠ j, calculate f = f i+f j If the largest singular value s1(f) of f ≤ s, end the process and return this f; if no f is returned, repeat steps 1.2.1 and 1.2.2 until an f is returned.

[0050] Step 1.3: Select the tool vector Construct the trapdoor matrix R = diag(f, g1, g2,..., g k-1 ) ∈ R k×k , and let the check vector where m = k;

[0051] Step 1.4: Let the signature key sk = R and the verification key vk = a.

[0052] Step 2: The signer S signs the selected message M using the signature key sk; specifically, it includes the following steps:

[0053] Step 2.1: Select the message M to be signed from the signature message space {0, 1} * , calculate μ = h(M, r), where h(·): {0, 1} * → R q is a collision-resistant hash function and r is a random bit string;

[0054] Step 2.2: Sample the perturbation vector where The specific steps of step 2.2 are as follows:

[0055] Step 2.2.1: Using as the Gaussian parameter and 0 as the center point, sample on the ring R to obtain q0; for i = 1,..., k - 1, using as the Gaussian parameter and 0 as the center point, sample on the ring R to obtain q i ;

[0056] Step 2.2.2: Let p = (q0, q1,..., q k-1 ) ∈ R k .

[0057] Specifically, in step 2.2.1, the process of sampling y ∈ R with as the Gaussian parameter and as the center point is as follows:

[0058] 1) Let F(X) = s 2 -f 2 = f0 + f1·X +... + f n-1 ·X n-1 , C(X) = c0 + c1·X +... + c n-1 ·Xn-1 .

[0059] 2) Let \(F_0(X\) 2 ) = \(f_0 + f_2\cdot X\) 2 +…+\(f\) n-2 \(\cdot X\) n-2 , where \(f_0,f_2,\ldots,f\) n-2 represent the coefficients of the even terms in \(F(X)\); let \(C_0(X\) 2 ) = \(c_0 + c_2\cdot X\) 2 +…+\(c\) n-2 \(\cdot X\) n-2 , where \(c_0,c_2,\ldots,c\) n-2 represent the coefficients of the even terms in \(C(X)\).

[0060] 3) Let \(F_1(X\) 2 ) = \(f_1 + f_3\cdot X\) 2 +…+\(f\) n-1 \(\cdot X\) n-2 , where \(f_1,f_3,\ldots,f\) n-1 represent the coefficients of the odd terms in \(F(X)\), i.e., \(F(X)=F_0(X\) 2 ) + X\cdot F_1(X\) 2 ). Let \(C_1(X\) 2 ) = \(c_1 + c_3\cdot X\) 2 +…+\(c\) n-1 \(\cdot X\) n-2 , where \(c_1,c_3,\ldots,c\) n-1 represent the coefficients of the odd terms in \(C(X)\), i.e., \(C(X)=C_0(X\) 2 ) + X\cdot C_1(X\) 2 ).

[0061] 4) Using as the Gaussian parameter and \(C_1\) as the center point, sample on the ring \(R\) to obtain \(y_1\).

[0062] 5) Using as the Gaussian parameter and as the center point, sample on \(R\) to obtain \(y_0\);

[0063] Since the tasks in steps 4) and 5) and the original task are all to sample on the ring \(R\) to obtain \(y_1\) and \(y_0\), and the execution processes of the two steps are the same, but their scales have become half of the original task. By continuously subdividing like this until a sampling structure with a dimension of 1 is obtained, the execution processes of steps 4) and 5) can repeatedly call the above steps 1) to 5) until sampling with a dimension of 1 is achieved.

[0064] 6) Return \(y = y_0(X\) 2 ) + X\cdot y_1(X\) 2 ) \(\in R\).

[0065] Step 2.3: Calculate the target \(v = (\mu - a t \cdot p)\cdot f -1 \bmod q\), and sample on the coset of the \(g -\)lattice according to the discrete Gaussian distribution to obtain the target vector \(z\).

[0066] Step 2.4: Let \(x = p+Rz=(x_0,x_1,\ldots,x k-1 )\);

[0067] Step 2.5: Discard the first component \(x_0\) in \(x\), and output \(x'=(x_1,\ldots,x k-1 )\) as the signature of the message \(M\).

[0068] Step 3: The verifier \(V\) uses the verification key \(vk\) to verify the legality of the received signed message; the steps include:

[0069] Step 3.1: Calculate \(x_0 = h(M,r)-a t \cdot x\bmod q\), where the signature \(x'=(x_1,\ldots,x k-1 )\);

[0070] Step 3.2: If \(\|(x_0,x_1,\ldots,x k-1 )\|\) 2 \leq s 2 \cdot m\cdot n\) holds, the verification passes, otherwise the verification fails.

[0071] Currently, existing similar signature methods cannot balance high parallelism and low storage space. The preimage Gaussian sampling algorithm proposed by the present invention can improve both space efficiency and time efficiency for the following reasons:

[0072] (1) As can be seen from Step 1.1 in Embodiment 1, the size of the Gaussian parameter \(s\) in the present invention is determined by the maximum singular value of the matrix corresponding to ring elements such as \(f,g_1,\ldots,g k-1 etc., which is significantly smaller than the Gaussian parameters in other existing similar methods, so the security can be improved;

[0073] (2) A smaller Gaussian parameter corresponds to a smaller modulus \(q\), and the number of ring elements in the public key, private key, and signature is all determined by certain, so when \(b\) is determined, reducing the size of \(q\) can directly reduce the storage space and can also reduce the computational scale;

[0074] (3) As can be seen from Step 2.2 in Embodiment 1, the \(k\) times of scrambling vector samplings \(q_0,\ldots,q k-1 are completely independent of each other, so they can be fully executed in parallel to improve the running efficiency.

[0075] Example 2

[0076] See Figure 2 , corresponding to Example 1, this example correspondingly discloses a preimage Gaussian sampling system, which includes:

[0077] A generation module 101, which is used to select Gaussian parameter s and generate a signature key sk and a verification key vk by using a key generation algorithm; specifically, the generation module 101 is used to execute the following steps:

[0078] Step 1.1: Let the Gaussian parameter of the signature where α represents a quality parameter, σ represents the Gaussian parameter of the trapdoor, and n is a power of 2;

[0079] Step 1.2: Select polynomials f, g1, g2,..., g k-1 ∈R, where represents a ring, b is a small integer, q represents the modulus, these polynomials are invertible over R q , R q is the coefficient of the polynomial over ring R modulo q, and each polynomial follows a discrete Gaussian distribution with parameter σ;

[0080] Step 1.3: Select the tool vector Construct the trapdoor matrix R = diag(f, g1, g2,..., g k-1 ) ∈ R k×k , and let the check vector where m = k;

[0081] Step 1.4: Let the signature key sk = R and the verification key vk = a.

[0082] A signature module 102, which is used to sign the selected message M by using the signature key sk;

[0083] A verification module 103, which is used to verify the legality of the received signed message by using the verification key vk.

[0084] The preimage Gaussian sampling system of this example is used to execute and implement the preimage Gaussian sampling method of Example 1, so this example will not elaborate on it.

[0085] Example 3

[0086] See Figure 3 , this example discloses a computer device, which includes a memory 304, a processor 302, and a computer program stored on the memory and executable on the processor. Among them, when the processor 302 executes the program, it implements the steps of the method described in Example 1.

[0087] Further, in Figure 3 this embodiment, it further includes a bus architecture (represented by bus 300). The bus 300 may include any number of interconnected buses and bridges. The bus 300 links together various circuits including one or more processors represented by processor 302 and a memory represented by memory 304. The bus 300 may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, etc., which are well known in the art. Therefore, further description thereof will not be provided herein. The bus interface 306 provides an interface between the bus 300 and the receiver 301 and the transmitter 303. The receiver 301 and the transmitter 303 may be the same element, i.e., a transceiver, which provides a unit for communicating with various other devices on the transmission medium. The processor 302 is responsible for managing the bus 300 and general processing, while the memory 304 may be used to store data used by the processor 302 when performing operations.

[0088] Embodiment 4

[0089] This embodiment provides a computer-readable storage medium, on which a computer program is stored. The program is executed by a processor to implement the method as described in Embodiment 1.

[0090] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0091] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be realized by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, so that the instructions executed by the processors of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0092] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to work in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the functions specified in one or more of the procedures Figure 1 and / or blocks Figure 1 specified in one or more of the procedures and / or blocks.

[0093] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, such that a series of operational steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one or more of the procedures Figure 1 and / or blocks Figure 1 specified in one or more of the procedures and / or blocks.

[0094] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn of the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.

[0095] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. An original image Gaussian sampling method, characterized in that, Including steps: Step 1: Select the Gaussian parameter s, and use the key generation algorithm to generate the signature key sk and the verification key vk; specifically including the steps: Step 1.1: Let the signed Gaussian parameter where α represents a mass parameter, σ represents the Gaussian parameter of the trapdoor, and n is a power of 2; Step 1.2: Select polynomials f, g1, g2, …, g that form a trapdoor, where k-1 ∈R, where represents a ring,[[]] b is a small integer, q represents the modulus, and these polynomials are invertible over R q and R q is the coefficient of the polynomial over the ring R modulo q, and each polynomial follows a discrete Gaussian distribution with parameter σ; The specific steps for selecting the polynomial f include: Step 1.2.1: For i = 1, …, K, select random vectors f1, …, f from a discrete Gaussian distribution with parameter K , where represents an integer; Step 1.2.2: For \(i = 1,\ldots,K\), \(j = 1,\ldots,K\) and \(i\neq j\), calculate \(f=f\) i +f j; If the largest singular value \(s_1(f)\) of \(f\) is \(\leq s\), then end the process and return this \(f\); if no \(f\) is returned, then repeat Step 1.2.1 and Step 1.2.2 until an \(f\) is returned; Step 1.3: Select the tool vector Construct the trapdoor matrix \(R = diag(f, g_1, g_2, \ldots, g\) k-1 )\in\mathbb{R} k×k , and let the check vector where \(m = k\); Step 1.4: Let the signature key sk = R, and the verification key vk = a; Step 2: Sign the selected message M using the signature key sk; Step 3: Verify the legitimacy of the received signed message using the verification key vk.

2. The original image Gaussian sampling method according to claim 1, characterized in that, The said Step 2: Sign the selected message M using the signature key sk, including the steps: Step 2.1: Select a message M to be signed from the signature message space {0, 1} * and calculate μ = h(M, r), where h(·): {0, 1} * → R q is a collision-resistant hash function and r is a random bit string; Step 2.2: Sampling the perturbation vector wherein Step 2.3: Calculate the target \(v = (\mu - a t \cdot p)\cdot f -1 \bmod q\), and sample on the coset of the \(g\)-lattice according to the discrete Gaussian distribution to obtain the target vector \(z\); Step 2.4: Let \(x = p+Rz=(x_0,x_1,\ldots,x k-1 )\); Step 2.5: Discard the first component x0 in x, and output x' = (x1, …, x k-1 ) as the signature of message M.

3. The original image Gaussian sampling method according to claim 2, characterized in that, Step 2.2: Sampling the perturbation vector wherein Specifically, it includes the steps of: Step 2.2.1: Using as the Gaussian parameter, with 0 as the center point, sample on the ring R to obtain q0; for i = 1, …, k - 1, using as the Gaussian parameter, with 0 as the center point, sample on the ring R to obtain q i ; Step 2.2.2: Let p = (q0, q1, …, q k-1 ) ∈ R k .

4. The original image Gaussian sampling method according to claim 3, characterized in that, The said Step 3: Verify the legitimacy of the received signed message using the verification key vk, including the steps: Step 3.1: Calculate x0 = h(M, r) - a t ·x mod q, where the signature x' = (x1, …, x k-1 ). Step 3.2: If ||(x0, x1, …, x k-1 )|| 2 ≤ s 2 ·m·n holds, the verification passes; otherwise, the verification fails.

5. An original image Gaussian sampling system, characterized in that, For implementing the preimage Gaussian sampling method according to any one of claims 1-4, including: A generation module, which is used to select the Gaussian parameter s and generate the signature key sk and the verification key vk by using the key generation algorithm; A signature module, which is used to sign the selected message M using the signature key sk; A verification module, which is used to verify the legitimacy of the received signed message using the verification key vk.

6. A computer device, characterized in that, Including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the steps of the method according to any one of claims 1-4 are implemented.

7. A computer-readable storage medium, characterized in that, Stored thereon is a computer program, which is executed by the processor for implementing the method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Signature verification method based on Gaussian sampling

    CN104038347A

  • Identity-based blind signature method on lower lattice of standard model

    CN106533699A