A Threshold Signature Method Based on SM2
By using different secret value share generation methods to generate user signature private keys in the presence or absence of a trusted center, the problem of low computing efficiency and limited threshold value range of SM2 threshold signature algorithm is solved, and efficient and flexible signature operations and security improvements are achieved.
Patent Information
- Application Number
- CN202111563163.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-20
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-12-20
AI Technical Summary
The existing threshold signature algorithm based on SM2 is inefficient in computing efficiency and limited threshold value range, resulting in greater limitations in the use of the system.
By using different secret value share generation methods to generate user signature private keys in the presence or absence of a trusted center, and signing operations are carried out through any device that is not less than the threshold value, different application systems are supported to improve the robustness and security of the system.
It realizes efficient signature operations, supports flexible threshold setting, expands the scope of algorithm use, and improves the robustness and security of the system.
Smart Images

Figure CN116318636B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of digital signature, and in particular to a threshold signature method based on SM2. Background Art
[0002] With the rapid development of network technology, network security issues have become increasingly important, and information encryption technology is the core technology in network security technology. Digital Signatures is a widely used technology among many information encryption technologies. Digital signature is a method of signing messages stored in electronic form, which can provide the non-forgery, authenticity and integrity of messages, and is widely used in current network communication, finance, commerce and other fields. The security of the private key is the key in the digital signature algorithm. Compared with the RSA public key cryptography algorithm, the SM2 elliptic curve public key cryptography algorithm has the advantages of high security, short key and fast speed, and is widely used in the digital signature algorithm. However, in the ordinary signature algorithm, the private key is only held by one user. If the private key of this user is stolen, the attacker can forge signatures, which poses a high security risk.
[0003] At present, to solve the problem that the private key is completely mastered by a single user with a high security risk, threshold signature is usually adopted. Since the private key is stored by multiple users in threshold signature and the signature algorithm can be completed without all users, on the one hand, threshold signature improves the robustness of the system. Even if a small number of users lose their keys, signature operations can still be performed, and the password system will not lose its functionality. On the other hand, threshold signature improves the security of the system. Even if a malicious adversary steals the keys of some (less than the threshold value) users, it is difficult to break the security of the password system. However, the current threshold signature algorithm based on SM2 uses complex operations such as homomorphism and zero-knowledge proof, with low operation efficiency, or requires the condition of the majority of honest people to be satisfied, and the threshold value t and the total number m of all users need to meet specific conditions, which limits the application scope of the signature algorithm and has great limitations. Summary of the Invention
[0004] In view of the above analysis, an embodiment of the present invention aims to provide a threshold signature method based on SM2 to solve the problems of low operation efficiency of the existing threshold signature algorithm and limited range of the threshold value.
[0005] An embodiment of the present invention provides a threshold signature method based on SM2, including the following steps:
[0006] Key generation process:
[0007] If there is a trusted center in the application system, the trusted center generates a secret value and shares the secret value to m devices to obtain the secret value shares saved by each device; and according to the secret value generated by the trusted center, the user signature public key is obtained;
[0008] If there is no trusted center in the application system, each device is used as the trusted center in turn to generate a secret value and share the secret value to m devices, and the secret value shares saved by each device are obtained; according to the secret value generated by each device, the user signature public key is obtained;
[0009] where m≥2 is the number of devices;
[0010] Signature generation process:
[0011] Reconstruct the respective device private key components according to the secret value shares of any t' devices; where t'≥t; t is the minimum number of devices required to recover the secret value, 2≤t≤m;
[0012] Based on SM2 and according to the user signature public key, the message M to be signed, and the respective device private key components of t' devices, the complete signature of the message M is obtained.
[0013] Furthermore, if there is a trusted center in the application system, the trusted center obtains the secret value shares saved by each device by performing the following steps:
[0014] The trusted center randomly generates a secret value w, where w∈[1,n'-1], and n' satisfies that n' divides (n - 1) and n' does not contain prime factors less than m; n is the order of G, and G is the elliptic curve base point of SM2;
[0015] Construct the polynomial f(x)=a t-1 x t-1 +a t-2 x t-2 +…+a1x + w; where a k is a random number generated by the trusted center, a k ∈[1,n'-1], k = 1,2,…,t - 1;
[0016] Obtain the secret value shares of each device according to the following formula and send them to the corresponding device:
[0017] y i =f(i)mod n′,
[0018] where y i represents the secret value share of device i, 1≤i≤m; mod is the modulo operation.
[0019] Furthermore, if there is a trusted center in the application system, the user signature public key is obtained by performing the following steps:
[0020] Based on the secret value w generated by the trusted center, the user signature private key d is obtained through the following formula:
[0021] d=(gw mod n) - 1,
[0022] where \(g\in[1, n - 1]\) and the order of \(g\) is \(n'\);
[0023] According to the user's signature private key \(d\), the user's signature public key \(P\) is obtained through the following formula:
[0024] \(P = [d]G\).
[0025] Furthermore, if there is no trusted center in the application system, the trusted center obtains the secret value shares saved by each device by performing the following steps:
[0026] Each device is taken as the trusted center in turn to obtain the secret value share components of each device when the device is the trusted center:
[0027] Take device \(i\) as the trusted center and randomly generate a secret value \(w\) i , where \(w\) i \(\in[1, n' - 1]\), \(n'\) satisfies that \(n'\) divides \((n - 1)\) and \(n'\) does not contain prime factors less than \(m\), \(i = 1, 2, \cdots, m\), \(n\) is the order of \(G\), and \(G\) is the elliptic curve base point of SM2;
[0028] Construct a polynomial \(f\) i (x)=a t-1 x t-1 +a t-2 x t-2 +\cdots+a_1x + w i ; where \(a\) k is a random number generated by the trusted center, \(a\) k \(\in[1, n' - 1]\), \(k = 1, 2, \cdots, t - 1\);
[0029] According to the following formula, obtain the secret value share component \(y\) of device \(j\) when device \(i\) is the trusted center i,j , and send it to device \(j\):
[0030] y i,j =f i (j)\(\bmod n'\);
[0031] where \(\bmod\) is the modulo operation;
[0032] Based on the secret value share components obtained by each device when each device is the trusted center, use the following formula to obtain the secret value share of each device:
[0033]
[0034] where \(y\) i represents the secret value share of device \(i\).
[0035] Further, if there is no trusted center in the application system, the user signature public key is obtained by performing the following steps:
[0036] Based on the secret values generated by each device, the device private key component of each device is obtained according to the following formula:
[0037]
[0038] In the formula, w i represents the secret value generated by device i; d′ i represents the device private key component of device i; g ∈ [1, n - 1], and the order of g is n';
[0039] Based on the device private key components of each device, the user signature public key is obtained in the following manner:
[0040] Device 1 calculates the elliptic curve point P1 according to the formula P1 = [d'1]G and sends P1 to device 2;
[0041] For devices 2 to m - 1, the formula P i = [d' i P i-1 is executed in sequence, i = 2,..., m - 1, and P i is sent to device i + 1 until device m receives P m-1 ;
[0042] Device m executes the formula P = [d' m P m-1 - G, and records P as the user signature public key.
[0043] Further, obtaining the user signature public key further includes: if P = O, it is determined that the generation of the user signature public key fails; otherwise, P is recorded as the user signature public key; where O is the infinite point on the SM2 elliptic curve.
[0044] Further, during the signature generation process, the device private key components of any t' devices are reconstructed according to the following manner based on the secret value shares of the t' devices:
[0045] Any t' devices are re - numbered as l1, l2,..., l t' , where the values of l1, l2,..., l t' are the position numbers among the m devices;
[0046] The reconstructed secret value shares of each of the t' devices are calculated according to the following formula:
[0047]
[0048] where,
[0049]
[0050] In the formula, represents the reconstructed secret value share of device l q1 ; represents the secret value share of device l q1 , where q1 = 1, 2, …, t′;
[0051] Based on the reconstructed secret value share of each device, the device private key component of each device is reconstructed through the following formula:
[0052]
[0053] In the formula, d q1 represents the device private key component of device l q1 ; g ∈ [1, n - 1], and the order of g is n′; n is the order of G, and G is the elliptic curve base point of SM2.
[0054] Furthermore, obtaining the complete signature of message M based on SM2 and according to the user's signature public key, the message M to be signed, and the device private key components of t′ devices includes:
[0055] Based on SM2, and generating a message digest e for the message M to be signed according to the user's signature public key;
[0056] Generating a first - part signature according to the random numbers generated by t′ devices, their respective device private key components, and the message digest e;
[0057] Then generating a second - part signature by using the random numbers generated by t′ devices, their respective device private key components, and the first - part signature to obtain the complete signature of message M.
[0058] Furthermore, generating the message digest e for the message M to be signed based on SM2 and according to the user's signature public key, which is represented by the formula:
[0059] e = H 256 (Z U ||M);
[0060] In the formula, H 256 () is a cryptographic hash function with a message digest length of 256 bits, Z U is the hash of the user U's identity identifier, partial elliptic curve parameters, and the user's signature public key; Z U ||M represents the concatenation of the hash Z U and the message M to be signed.
[0061] Further, the m devices share the elliptic curve parameters E(Fp), (p, a, b, G, n, h) of SM2, where the elliptic curve E is an elliptic curve defined over the prime field Fp containing p elements, E(Fp) is the set of all rational points including the infinite point O on the elliptic curve E over Fp, a and b are elements in Fp, G is the base point of order n on the elliptic curve E, and h is the cofactor.
[0062] Compared with the prior art, the present invention can achieve the following beneficial effects:
[0063] A threshold signature method based on SM2 provided by the present invention
[0064] By whether there is a trusted center, different ways of generating secret value shares are adopted, which can support different application systems. The user signature private key is generated by the secret value shares of each device, and the private key information is shared among multiple devices. Any number of devices not less than the threshold value can perform signature operations, improving the robustness and security of the system. And by reconstructing the private key through any t' devices greater than or equal to t, and then obtaining the complete user signature, the calculation is simple, the operation efficiency is high, and the minimum number of devices required to recover the secret value can be set arbitrarily, with a wider range of usage conditions and scopes and less limitations.
[0065] In the present invention, the above technical solutions can also be combined with each other to achieve more preferred combination schemes. Other features and advantages of the present invention will be described in the subsequent description, and some advantages can be made obvious from the description, or understood by implementing the present invention. The objectives and other advantages of the present invention can be realized and obtained from the content specifically pointed out in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] The drawings are only for the purpose of showing specific embodiments and are not considered to be a limitation of the present invention. Throughout the drawings, the same reference numerals represent the same components.
[0067] Figure 1 It is a schematic flowchart of the threshold signature method based on SM2 provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0068] The following will specifically describe the preferred embodiments of the present invention with reference to the drawings, where the drawings form a part of this application and are used together with the embodiments of the present invention to explain the principles of the present invention, and are not used to limit the scope of the present invention.
[0069] Abbreviations and key terms:
[0070] F p : The prime field containing p elements.
[0071] (p, a, b, G, n, h): Curve parameters of the SM2 algorithm, where p is a prime number with a length of 256 bits; a and b are elements in the prime field F p used to define an elliptic curve E over F p ; G is the base point, and in coordinates, G = (x G , y G ); n is the order of G; h is the cofactor.
[0072] E(F p ): The set consisting of all rational points (including the infinite point O) of the elliptic curve E over F p .
[0073] H v (): A cryptographic hash function with a message digest length of v bits, and this hash function uses SM3.
[0074] mod n: Modulo n operation.
[0075] O: A special point on the elliptic curve, called the infinite point or zero point, which is the identity element of the elliptic curve additive group.
[0076] x||y: The concatenation of x and y, where x and y are bit strings or byte strings.
[0077] P A : The signature public key of user A, and in coordinates, P A = (x A , y A ).
[0078] ID A : The identity identifier of user A.
[0079] ENTL A : The length of ID A , and the length of ENTL A is 2 bytes.
[0080] Z A : The hash value regarding the identity identifier of user A, some elliptic curve system parameters, and the signature public key of user A. Specifically, Z = H 256 (ENTL A ||ID A ||a||b||x G ||y G ||x A ||y A ).
[0081] [k]P: The k - fold point of point P on the elliptic curve, that is, k is a positive integer.
[0082] Technical basis of the present invention: Assume that the user identity is U, the user signature public key is P, and the user signature private key is generated from secret value shares, which are respectively stored in m (m≥2) devices, namely Device 1, Device 2, …, Device m.
[0083] A specific embodiment of the present invention discloses a threshold signature method based on SM2, as Figure 1 shown, including the following steps:
[0084] Key generation process:
[0085] If there is a trusted center in the application system, the trusted center generates a secret value and shares the secret value to m devices to obtain the secret value shares saved in each device; and based on the secret value generated by the trusted center, the user signature public key is obtained;
[0086] If there is no trusted center in the application system, each device is sequentially used as the trusted center to generate a secret value and share the secret value to m devices to obtain the secret value shares saved in each device; based on the secret value generated by each device, the user signature public key is obtained;
[0087] where m≥2 is the number of devices;
[0088] Signature generation process:
[0089] Based on the secret value shares of any t' devices, the respective device private key components are reconstructed; where t'≥t; t is the minimum number of devices required to recover the secret value, 2≤t≤m;
[0090] Based on SM2, and according to the user signature public key, the message M to be signed, and the respective device private key components of t' devices, the complete signature of the message M is obtained.
[0091] Compared with the prior art, the threshold signature method based on SM2 provided in this embodiment can support different application systems by adopting different secret value share generation methods according to the existence of a trusted center. The user signature private key is generated through the secret value shares of each device, and the private key information is shared among multiple devices. Any number of devices not less than the threshold value can perform signature operations, improving the robustness and security of the system. And by reconstructing the private key through any t' devices greater than or equal to t, and then obtaining the complete user signature, the calculation is simple, the operation efficiency is high, and the minimum number of devices required to recover the secret value can be set arbitrarily, with a wider range of use conditions and scopes and less limitations.
[0092] It should be noted that when using the threshold signature method in an application system, it can be determined whether there is a trusted center in the application system according to the own information of the application system, and different methods are selected to generate secret value shares according to the existence of a trusted center, specifically as follows:
[0093] Case 1: If there is a trusted center in the application system, the trusted center generates a secret value and shares the secret value with m devices to obtain the secret value shares saved by each device; and obtains the user signature public key according to the secret value generated by the trusted center.
[0094] During implementation, if there is a trusted center in the application system, the trusted center obtains the secret value shares saved by each device by performing the following steps:
[0095] The trusted center randomly generates a secret value w, where w ∈ [1, n' - 1], n' satisfies that n' divides (n - 1) and n' does not contain prime factors less than m, n is the order of G, and G is the elliptic curve base point of SM2;
[0096] Construct the polynomial f(x) = a t-1 x t-1 + a t-2 x t-2 + … + a1x + w; where a k is a random number generated by the trusted center, a k ∈ [1, n' - 1], k = 1, 2, …, t - 1; t is the minimum number of devices required to recover the secret value, 2 ≤ t ≤ m;
[0097] Obtain the secret value share of each device according to the following formula and send it to the corresponding device:
[0098] y i = f(i) mod n′,
[0099] In the formula, y i represents the secret value share of device i, 1 ≤ i ≤ m; mod is the modulo operation.
[0100] During implementation, if there is a trusted center in the application system, the user signature public key is obtained by performing the following steps:
[0101] Based on the secret value w generated by the trusted center, obtain the user signature private key d through the following formula:
[0102] d = (g w mod n)-1,
[0103] In the formula, g ∈ [1, n - 1], and the order of g is n';
[0104] According to the user signature private key d, obtain the user signature public key P through the following formula:
[0105] P = [d]G.
[0106] Case 2: If there is no trusted center in the application system, then each device is used as the trusted center in turn to generate a secret value and share the secret value to m devices, and the secret value shares saved by each device are obtained; according to the secret value generated by each device, the user signature public key is obtained.
[0107] During implementation, if there is no trusted center in the application system, the trusted center obtains the secret value shares saved by each device by executing the following steps:
[0108] Each device is used as the trusted center in turn, and the secret value share component of each device when each device is the trusted center is obtained:
[0109] Take device i as the trusted center and randomly generate a secret value w i , where w i ∈[1, n'-1], n' satisfies that n' divides (n - 1) and n' does not contain prime factors less than m, i = 1, 2,..., m, n is the order of G, and G is the elliptic curve base point of SM2;
[0110] Construct a polynomial f i (x) = a t-1 x t-1 + a t-2 x t-2 + … + a1x + w i ; where a k is a random number generated by the trusted center, a k ∈[1, n'-1], k = 1, 2,..., t - 1;
[0111] According to the following formula, obtain the secret value share component y i,j of device j when device i is the trusted center, and send it to device j:
[0112] y i,j = f i (j) mod n′;
[0113] In the formula, mod is the modulo operation;
[0114] Based on the secret value share components obtained by each device when each device is the trusted center, use the following formula to obtain the secret value share of each device:
[0115]
[0116] In the formula, y i represents the secret value share of device i.
[0117] During implementation, if there is no trusted center in the application system, the user signature public key is obtained by executing the following steps:
[0118] Based on the secret value generated by each device, the device private key component of each device is obtained according to the following formula:
[0119]
[0120] In the formula, w i represents the secret value generated by device i; d′ i represents the device private key component of device i; g∈[1,n-1], and the order of g is n';
[0121] Based on the device private key component of each device, the user signature public key is obtained in the following way:
[0122] Device 1 calculates the elliptic curve point P1 according to the formula P1=[d'1]G, and sends P1 to device 2;
[0123] For device 2 to device m-1, execute formula P in sequence i =[d' i ]P i-1 , i=2,…,m-1, and P i Send to device i+1 until device m receives P m-1 ;
[0124] Device m executes the formula P = [d' m ]P m-1 -G, record P as the user's signature public key.
[0125] It can be understood that according to the minimum number of devices t required to restore the secret value, that is, the threshold value, a polynomial is constructed to generate the secret value share stored by each device. In the signature calculation process, the signature operation can be performed by any device not less than t, while the signature operation cannot be performed by less than t devices, and the combination of less than t devices will not leak any information. It is more flexible and does not require all users to participate. Only some devices are needed to sign, which ensures the robustness of the system. In addition, in the user signature private key and user signature public key, the process is simple and the operation efficiency is high.
[0126] It should be noted that in actual applications, the user signature public key obtained by device m can be sent to other devices (device 1 to device m-1) as needed; it can also be calculated starting from device m' until device m'-1 obtains the user signature public key; wherein, 2≤m'≤m; illustratively, m'=3, i.e., calculation starts from device 3 until device 2 obtains the user signature public key.
[0127] In specific implementation, obtaining the user signature public key in both Case 1 and Case 2 further includes: if P = O, it is determined that the generation of the user signature public key fails; otherwise, P is recorded as the user signature public key, where O is the infinite point on the SM2 elliptic curve.
[0128] It should be noted that according to the above, the secret value shares saved by each device and the user signature public key are obtained. The secret can be restored only when any t or more devices participate together. According to the secret value shares of the participating devices, the device private key components of each device are obtained, and then the signature is generated. Specifically, as follows:
[0129] The device private key components of each device are reconstructed according to the secret value shares of any t' devices, where t' ≥ t; t is the minimum number of devices required to restore the secret value, and 2 ≤ t ≤ m.
[0130] Based on SM2, and according to the user signature public key, the message M to be signed, and the device private key components of each of the t' devices, the complete signature of the message M is obtained.
[0131] During implementation, in the signature generation process, the device private key components of each of the t' devices are reconstructed according to the following method based on the secret value shares of any t' devices:
[0132] Any t' devices are re-numbered as l1, l1, …, l t' , where the values of l1, l2, …, l t' are the position numbers among the m devices. Exemplarily, when m = 5 and t' = 3, which are Device 1, Device 3, and Device 5 respectively, after re-numbering, l1 = 1, l2 = 3, and l3 = 5.
[0133] The reconstructed secret value share of each device among the t' devices is calculated according to the following formula:
[0134]
[0135] where
[0136]
[0137] In the formula, represents the reconstructed secret value share of device l q1 , represents the secret value share of device l q1 , and q1 = 1, 2, …, t′.
[0138] Based on the reconstructed secret value share of each device, the device private key component of each device is reconstructed through the following formula:
[0139]
[0140] In the formula, dq1 Denote the device private key component of device \(l\); \(g\in[1,n - 1]\) and the order of \(g\) is \(n'\); \(n\) is the order of \(G\), and \(G\) is the elliptic curve base point of SM2. q1 It can be understood that in the signature algorithm of this embodiment, the secret value shares are saved by different devices, and the device private key components in the signature algorithm are reconstructed from the secret value shares, without directly storing the device private key components, which has higher security.
[0141] Optionally, when there is no trusted center, when obtaining the user signature public key, it can also be generated by any \(t'\) devices among the \(m\) devices, where \(t'\geq t\); specifically:
[0142] Reconstruct the device private key components of the \(t'\) devices respectively according to the secret value shares of any \(t'\) devices in the above manner;
[0143] According to the device private key component of each device among the \(t'\) devices, obtain the user signature public key in the following manner:
[0144] Device \(l_1\) calculates the elliptic curve point \(P_1\) according to the formula \(P_1=[d_1]G\) and sends \(P_1\) to the device;
[0145] For devices \(l_2\) to device \(l\)
[0146] t'-1 q1 , successively execute the formula \(P\) q1 =[d q1 P q1-1 , \(q_1 = 2,\cdots,t'-1\) and send \(P\) q1 to device \(q_1 + 1\) until device \(l\) t' receives \(P\) t'-1 ;
[0147] Device \(l\) t' executes the formula \(P=[d' t' P t'-1 -G\), and records \(P\) as the user signature public key.
[0148] In implementation, based on SM2, and obtaining the complete signature of message \(M\) according to the user signature public key, the message \(M\) to be signed, and the device private key components of the \(t'\) devices respectively, includes:
[0149] Based on SM2, generate the message digest \(e\) of the message \(M\) to be signed according to the user signature public key;
[0150] Generate the first part of the signature according to the random numbers generated by the \(t'\) devices, their respective device private key components, and the message digest \(e\);
[0151] Use the random numbers generated by t' devices, their respective device private key components, and the first part of the signature to generate the second part of the signature, obtaining the complete signature of message M.
[0152] In specific implementation, based on SM2, generate a message digest e for the message M to be signed according to the user's signature public key. The formula is expressed as:
[0153] e = H 256 (Z U ||M);
[0154] In the formula, H 256 () is a cryptographic hash function with a message digest length of 256 bits. Z U is the hash of the user U's identity identifier, part of the elliptic curve parameters, and the user's signature public key. Z U ||M represents the concatenation of the hash Z U and the message M to be signed.
[0155] It should be noted that the calculation of the message digest e can be performed on any one of the m devices. If it is not calculated by device m, only e needs to be transmitted to device m.
[0156] In specific implementation, generating the first part of the signature according to the random numbers generated by t' devices, their respective device private key components, and the message digest e is specifically as follows:
[0157] Device l1 generates a random number k1, k1 ∈ [1, n - 1], calculates the elliptic curve point R1 that satisfies the elliptic curve equation according to the formula R1 = [k1]G, and sends R1 to device l2;
[0158] For devices l2 to device l t'-1 , successively execute the formula R q1 = [d q1 R q1-1 + [k q1 G, and send the elliptic curve point R q1 that satisfies the elliptic curve equation to device l q1+1 , until the elliptic curve point R t'-1 that satisfies the elliptic curve equation is calculated and sent to device l t' ; where d q1 is the device private key component of device l q1 , k q1 is the random number generated by device l q1 , k q1 ∈ [1, n - 1], q1 = 2, 3,..., t' - 1, G is the elliptic curve base point of SM2, n is the order of G, and mod is the modulo operation.
[0159] Device l t'Generate a random number k t' , k t' ∈[1, n - 1], and according to the formula (x1, y1) = [d t' R t'-1 +[k t' G, calculate the elliptic curve point (x1, y1). If (x1, y1) ≠ O, then calculate r according to the formula r = (e + x1) mod n; if r is not equal to 0, then use it as the first part of the signature r.
[0160] Specifically, when implementing, use the random numbers generated by t' devices, their respective device private key components, and the first part of the signature to generate the second part of the signature, obtaining the complete signature of message M. Specifically:
[0161] For devices from lt' to l2, successively execute the formula t q1-1 = d q1 -1 (k q1 + t q1 ) mod n, and send r and t q1-1 to device l q1-1 , until t1 is sent to device l1; where, if t q1 = 0 or k q1 + t q1 = n, then judge that an error occurs and stop executing;
[0162] Among them, t q1-1 is the parameter calculated by device l q1 and transmitted to device l q1-1 , q1 = m, m - 1,..., 2, t m = r;
[0163] Device l1 calculates the second part of the signature s according to the formula s = (d1 -1 (k1 + t1) - r) mod n.
[0164] When implementing, m devices share the elliptic curve parameters E(Fp), (p, a, b, G, n, h) of SM2. Among them, the elliptic curve E is an elliptic curve defined on the prime field Fp containing p elements, E(Fp) is the set of all rational points including the infinite point O on the elliptic curve E over Fp, a and b are elements in Fp, G is the base point of order n on the elliptic curve E, and h is the cofactor.
[0165] It should be noted that in the threshold signature algorithm in this implementation, the value space of the private key of the SM2 algorithm is mapped from to an additive group Z n-1However, since n - 1 is not a prime number and contains small prime factors, threshold secret sharing still cannot be directly used. Thus, the value space of the private key of the SM2 algorithm is reduced to a cyclic subgroup G of order n' n' on, and map G n' to Z n' Here, it is required that n' divides (n - 1) and n' does not contain prime factors less than m. Although the value space of the private key of the SM2 algorithm is reduced to G n' at this time, since n' and n - 1 only differ by a small constant, the security is not affected.
[0166] Exemplarily, in this embodiment, according to the cryptographic industry standard "GM / T 0003-2012 SM2 Elliptic Curve Public Key Cryptography Algorithm Part 5 Parameter Definition", the values of parameters n and n - 1 are n = 0xFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFF7203DF6B21C6052B53BBF40939D54123, n - 1 = 2×3×0x1E4F×0x36E9×0x543D32E5×0x13F1F3759051C182B92C3AD803BF3CB6B53F7B1C01A44AC369. And in this embodiment, the values of parameters n' and g selected in the threshold signature algorithm are n' = (n - 1) / 6 = 0x2AAAAAAA7FFFFFFFFFFFFFFFFFFFFFFFE855FA91DAF65631E349FE0189A38ADB, g = 4. At this time, the number of devices m is less than 7759 (i.e., 0x1E4F). It can be understood that in practical applications, the value of m is generally much smaller than this number. Therefore, the values of n' and g selected in this embodiment will neither affect the security nor the actual application.
[0167] Those skilled in the art can understand that all or part of the processes of implementing the above embodiment methods can be completed by instructing relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. Among them, the computer-readable storage medium is a disk, an optical disc, a read-only memory, or a random access memory, etc.
[0168] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention.
Claims
1. A threshold signature method based on SM2, characterized in that Including the following steps: Key generation process: If there is a trusted center in the application system, the trusted center generates a secret value and shares the secret value to m devices, obtaining the secret value shares saved by each device; And based on the secret value generated by the trusted center, obtain the user signature private key, and then obtain the user signature public key; If there is no trusted center in the application system, each device is successively used as the trusted center to generate a secret value and share the secret value to m devices, obtaining the secret value shares saved by each device; Based on the secret value generated by each device, obtain the device private key component of each device, and then obtain the user signature public key; Wherein, m≥2, which is the number of devices; Signature generation process: Reconstruct the device private key components of each of any t' devices according to the secret value shares of the t' devices; wherein, t'≥t; t is the minimum number of devices required to recover the secret value, 2≤t≤m; Based on SM2 and according to the user signature public key, the message M to be signed, and the device private key components of the t' devices respectively, obtain the complete signature of the message M.
2. The threshold signature method based on SM2 according to claim 1, wherein If there is a trusted center in the application system, the trusted center obtains the secret value shares saved by each device by performing the following steps: The trusted center randomly generates a secret value w, wherein, w∈[1,n'-1], n' satisfies that n' divides (n - 1) and n' does not contain prime factors less than m; n is the order of G, and G is the elliptic curve base point of SM2; Construct the polynomial \(f(x)=a\) t-1 x t-1 +a t-2 x t-2 +…+a1x + w; where, a k is a random number generated by the trusted center, a k ∈[1, n'-1], k = 1, 2, …, t - 1; Obtain the secret value shares of each device according to the following formula and send them to the corresponding devices: y i = f(i) mod n′, where y i represents the share of the secret value of device i, 1 ≤ i ≤ m; mod is the modulo operation.
3. The threshold signature method based on SM2 according to claim 2, wherein If there is a trusted center in the application system, the user signature public key is obtained by performing the following steps: Based on the secret value w generated by the trusted center, obtain the user signature private key d through the following formula: d = (g w mod n) - 1, In the formula, g∈[1,n - 1], and the order of g is n'; According to the user signature private key d, obtain the user signature public key P through the following formula: P = [d]G.
4. The threshold signature method based on SM2 according to claim 1, wherein If there is no trusted center in the application system, the trusted center obtains the secret value shares saved by each device by performing the following steps: Successively use each device as the trusted center to obtain the secret value share components of each device when each device is the trusted center: Randomly generate a secret value \(w\) with device \(i\) as the trusted center i , where \(w\) i \(\in [1, n' - 1]\), \(n'\) satisfies that \(n'\) divides \((n - 1)\) and \(n'\) does not contain prime factors less than \(m\), \(i = 1, 2, \ldots, m\), \(n\) is the order of \(G\), and \(G\) is the elliptic curve base point of SM2; Construct polynomial f i (x) = a t-1 x t-1 + a t-2 x t-2 + … + a1x + w i ; where a k is a random number generated by the trusted center, a k ∈ [1, n' - 1], k = 1, 2, …, t - 1; Obtain the secret value share component y of device j when device i is the trusted center according to the following formula i,j , and send it to device j: y i,j = f i (j) mod n′; In the formula, mod is the modulo operation; Based on the secret value share components of each device when each device is the trusted center, use the following formula to obtain the secret value share of each device: where y i represents the share of the secret value of device i.
5. The threshold signature method based on SM2 according to claim 4, wherein If there is no trusted center in the application system, the user signature public key is obtained by performing the following steps: Based on the secret value generated by each device, obtain the device private key component of each device according to the following formula: where, w i represents the secret value generated by device i; d i ' represents the device private key component of device i; g ∈ [1, n - 1], and the order of g is n'; According to the device private key components of each device, obtain the user signature public key in the following manner: Device 1 calculates the elliptic curve point P1 according to the formula P1 = [d'1]G and sends P1 to device 2; For devices 2 to m - 1, successively execute the formula P i = [d' i P i-1 , i = 2, …, m - 1, and send P i to device i + 1 until device m receives P m-1 ; Device m executes the formula P = [d' m P m-1 -G, and records P as the user's signature public key.
6. The threshold signature method based on SM2 according to claim 3 or 5, characterized in that, Obtaining the user signature public key further includes: if P = O, then determine that the generation of the user signature public key fails, otherwise record P as the user signature public key; wherein, O is the infinite point on the SM2 elliptic curve.
7. The threshold signature method based on SM2 according to claim 2 or 4, characterized in that, In the signature generation process, the device private key components of the t' devices are reconstructed according to the secret value shares of any t' devices by performing the following manner: Renumber any t' devices as l1, l2, …, l t' , where the values of l1, l2, …, l t' are the position numbers among the m devices; Calculate the reconstructed secret value share of each of the t' devices according to the following formula: Wherein, In the formula, represents the reconstructed secret value share of device l q1 , represents the secret value share of device l q1 , where q1 = 1, 2, …, t′; Based on the reconstructed secret value shares of each device, the device private key components of each device are reconstructed through the following formula: where d q1 represents the device private key component of device l q1 ; g ∈ [1, n - 1], and the order of g is n'; n is the order of G, and G is the elliptic curve base point of SM2.
8. The threshold signature method based on SM2 according to claim 1, characterized in that, The complete signature of message M based on SM2 and according to the user's signature public key, the message M to be signed, and the device private key components of t' devices respectively includes: Based on SM2, generate a message digest e for the message M to be signed according to the user's signature public key; Generate the first part of the signature according to the random numbers generated by t' devices, their respective device private key components, and the message digest e; Then generate the second part of the signature using the random numbers generated by t' devices, their respective device private key components, and the first part of the signature to obtain the complete signature of message M.
9. The threshold signature method based on SM2 according to claim 8, wherein Based on SM2, generate a message digest e for the message M to be signed according to the user's signature public key, and the formula is expressed as: e = H 256 (Z U ||M); Where H 256 () is a cryptographic hash function with a message digest length of 256 bits, and Z U is the hash of the identity of user U, partial elliptic curve parameters, and the user's signature public key; Z U ||M represents the concatenation of the hash Z U and the message M to be signed.
10. The threshold signature method based on SM2 according to claim 1, wherein m devices share the elliptic curve parameters E(Fp), (p, a, b, G, n, h) of SM2, where the elliptic curve E is an elliptic curve defined on the prime field Fp containing p elements, E(Fp) is the set of all rational points including the infinite point O on the elliptic curve E over Fp, a and b are elements in Fp, G is the base point of order n on the elliptic curve E, and h is the cofactor.
Citation Information
Patent Citations
Multi-party collaborative signature method and system based on SM2
CN111147246A
SM2 digital signature method suitable for threshold calculation
CN112118111A