A Multi-Party Collaborative Threshold Signature Method, Device and System Based on ECDSA

By adopting the addition linear secret sharing and Shamir secret sharing methods in ECDSA signatures, each participant generates signature shares without revealing the private key shares, solving the problem of high overhead of the existing multi-party threshold ECDSA signature protocol, and achieving efficient and low-overhead multi-party collaborative signatures.

CN116961917BActive Publication Date: 2025-06-03HUAZHONG UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310704784.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-14
Publication Date
2025-06-03
Estimated Expiration
2043-06-14

AI Technical Summary

Technical Problem

The existing multi-party threshold ECDSA signature protocol has too high calculation overhead, communication overhead and storage overhead, making it difficult to widely apply to actual systems.

Method used

A multi-party collaborative threshold signature method based on ECDSA was designed. Through simple addition linear secret sharing and Shamir secret sharing, each participant generates signature shares without revealing the private key shares, reducing the computational complexity, data interaction topology and data storage.

Benefits of technology

It realizes multi-party collaborative signatures with low computing complexity, simple data interaction topology and less data storage, solves the problem of high overhead in the existing technology and improves the efficiency and applicability of signatures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116961917B_ABST
    Figure CN116961917B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-party collaborative threshold signature method, device and system based on ECDSA, belonging to the technical field of cryptographic signature. A signature scheme is designed based on ECDSA. Each signature participant generates and saves their respective signature shares without disclosing their partial signature keys. Then, the signatures corresponding to all signature participants are calculated. The entire signature scheme has low computational complexity, a simple data interaction topology, and less stored data, thus solving the technical problem that existing multi-party threshold collaborative signature algorithms often have high computational overhead, communication overhead, and storage overhead. In addition, the legitimacy verification of transmitted information is carried out based on the zero-knowledge proof of discrete logarithm and the verifiable secret sharing technology, and the security under the malicious adversary model can be achieved without introducing high-overhead technologies such as range proof or consistency check with high computational overhead and communication overhead.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of cryptographic signature, and more specifically, relates to a multi-party collaborative threshold signature method, device and system based on ECDSA. Background Art

[0002] Digital signature is a security guarantee technology that emerged with the development of information network technology. Its purpose is to achieve the functions of traditional paper signatures or seals through technical means, for identifying the identity of the signer, recognizing the content of an electronic data, and ensuring the integrity, authenticity and non-repudiation of the transmitted electronic file. The Elliptic Curve Digital Signature Algorithm (ECDSA) is a combination of the Elliptic Curves Cryptography (ECC) and the Digital Signature Algorithm (DSA), which has the characteristics of small computational amount, fast processing speed, small storage space occupation, low bandwidth requirement, etc., and is suitable for application scenarios with limited computing power, storage space, bandwidth and power consumption. Therefore, ECDSA is widely used in e-commerce systems and other network fields to provide security services such as identity authentication, data integrity verification, and non-repudiation. With the successful deployment and application of the Bitcoin system, ECDSA has received more extensive attention and has gradually become the default signature mechanism for current mainstream blockchain platforms and projects, such as Ethereum and Hyperledger Fabric.

[0003] The security of a digital signature scheme depends on the security of the signer's private key. To prevent the leakage of the private key and solve the problem of over-concentration of signature power, multi-party collaborative digital signature has currently become one of the most potential cryptographic solutions for the mobile Internet. Whether at the application level such as blockchain or traditional financial institutions, the threshold signature scheme can bring improvements in security and privacy in various scenarios. Existing multi-party threshold ECDSA signatures often need to use cryptographic primitives such as homomorphic encryption, oblivious transfer, and beaver multiplication triples to construct a multi-party computing protocol that converts multiplicative shares into additive shares (MtA) to solve the inverse operation in multi-party ECDSA signatures. However, the application of these cryptographic primitives will cause problems such as too high collaborative signature computational overhead, communication overhead, or storage overhead, making it difficult to be widely applied in practical systems. Therefore, how to reduce the running computational overhead, communication overhead, and storage overhead on the premise of ensuring the security of multi-party threshold collaborative signatures is one of the key technologies that the current multi-party threshold ECDSA signature protocol urgently needs to solve. Summary of the Invention

[0004] In view of the above defects or improvement needs of the prior art, the present invention provides a multi-party collaborative threshold signature method, device and system based on ECDSA, the purpose of which is to design a signature scheme based on ECDSA, in which each participating signing party generates and saves their own signature share without disclosing their own partial signature key, and then calculates the signatures corresponding to all signing parties. The entire signature scheme has low computational complexity, simple data interaction topology, and less stored data, thereby solving the technical problems of existing multi-party threshold collaborative signature algorithms often having high computational overhead, communication overhead and storage overhead.

[0005] To achieve the above object, according to one aspect of the present invention, a multi-party collaborative threshold signature method based on ECDSA is provided, comprising:

[0006] S1: For any participant P i , i∈{1,2,…,N}, N is the number of participants; P i Choose a random number k i Calculate the first intermediate parameter R i =k i G, G is the base point coordinate on the elliptic curve; using k i and the threshold value t of the minimum number of participants to select a random polynomial g i (x), select the random polynomial w using the number of parties T that actually participate in the signature and the threshold value t of the minimum number of parties i (x), and calculate the participant P i and participant P j The corresponding second intermediate parameter g ij and the third intermediate parameter w ij , g ij =g i (x j ), w ij =w i (x j ); x j For the participant P j Labels;

[0007] S2: Participant P i The first intermediate parameter R i , the second intermediate parameter g ij and the third intermediate parameter w ij Sent to participant P j ;

[0008] S3: Participant P j Calculate the fourth intermediate parameter and the fifth intermediate parameter q is the order of the base point G; the sixth intermediate parameter ρ is calculated using the two j= g j · w j mod q; Also calculate the seventh intermediate parameter and then obtain the signature parameter r = r x mod q and the signature parameter e is the encrypted message; Also calculate the eighth intermediate parameter

[0009] S4: Party P j sends ρ j to Party P i ;

[0010] S5: Party P i calculates the ninth intermediate parameter δ i = (h i + r · d i ) · w i mod q and the signature share d i is the private key share of Party P i ;

[0011] S6: All signature participants obtain their respective signature shares s k , k ∈ {1, 2,..., T}, and then obtain the signature When multiple parties establish communication with other communication parties, after receiving the signature data (r, s), the other communication parties use the public keys Q corresponding to all parties to verify the signature data (r, s).

[0012] In one embodiment, when the application scenario is a malicious adversary model, between S2 and S3, it further includes: Party P j verifies the legality of the received R i , g ij , w ij . If R i , g ij , w ij then execute S3.

[0013] In one embodiment,

[0014] The process of verifying R i : Party P j receives (π i , R i ) sent by Party P i , where (π i , R i ) is Party P i invoking the discrete logarithm zero-knowledge proof evidence generation algorithm DLZK.Gen(k i , R i)The generated evidence π i and R i ; Then the participant P j invokes the discrete logarithm zero - knowledge proof verification algorithm DLZK.Ver(π i ) to verify π i and determine the legality of R i ;

[0015] The process of verifying g ij : The participant P j verifies the legality of the received g ij based on the verifiable secret sharing VSS algorithm;

[0016] The process of verifying w ij : The participant P j verifies the legality of the received w ij based on the VSS algorithm.

[0017] In one embodiment, two random polynomials are selected, and where k i is the random number corresponding to the participant P i , b il and c il are the random numbers selected by the participant P i .

[0018] In one embodiment, the determination method of all participants' public keys Q is as follows:

[0019] A1: Any participant P i selects a random number and calculates the public key share Q i = u i G, then selects a random polynomial and calculates the first function value f j based on the x j of other participants P ij , where {a il} 1≤l≤t-1 is the random number selected by P i , and t represents the threshold value corresponding to the polynomial f i (x);

[0020] A2, The participant P i sends its own public key share Q i and the first function value f ij to the participant P j ;

[0021] A3, The participant P j calculates the private key threshold share Calculate the public key Then securely store {Q, d j}, d j for participant P j to calculate its own signature share.

[0022] In one embodiment, when the application scenario is a malicious adversary model, between B2 and B3, it further includes: Participant P j verifies the received Q i and f ij for legality. If both Q i and f ij are legal, then execute B3.

[0023] In one embodiment,

[0024] The process of verifying Q i is as follows: Participant P j receives (π i , Q i ) sent by Participant P i , where (π i , Q i ) is the combination of the proof π i and Q i generated by Participant P i invoking the discrete logarithm zero - knowledge proof evidence generation algorithm DLZK.Gen(k i , Q i ); then Participant P j invokes the discrete logarithm zero - knowledge proof verification algorithm DLZK.Ver(π i ) to verify π i to determine the legality of Q i ;

[0025] The process of verifying f ij is as follows: Participant P j verifies the legality of the received f ij based on the VSS algorithm.

[0026] According to another aspect of the present invention, there is provided a multi - party collaborative threshold signature device based on ECDSA, including:

[0027] A first calculation module, for any participant P i , i ∈ {1, 2,..., N}, N is the number of participants; P i selects a random number k i to calculate the first intermediate parameter R i = k i G, G is the base point coordinate on the elliptic curve; using ki and select a random polynomial g i (x) using the threshold value T for signature participation and the maximum allowable colluding party value t - 1, and select a random polynomial w i (x), and calculate the second intermediate parameter g i corresponding to party P j and the third intermediate parameter w ij ; g ij = g ij (x i ), w j = w ij (x i ); x j is the label of party P j ; j ;

[0028] The first sending module is used for party P i to send R i , g ij and w ij to party P j ;

[0029] The second calculation module is used for party P j to calculate the fourth intermediate parameter and the fifth intermediate parameter where q is the order of the base point G; to calculate the sixth intermediate parameter ρ j = g j ·w j mod q;

[0030] The second sending module is used for party P j to broadcast ρ j , and all parties receive ρ j ;

[0031] The share determination module is used for party P i to calculate the seventh intermediate parameter and then obtain the signature parameter r = r x mod q and the signature parameter where e is the encrypted message, and i is the l - th power of the label x i of party P and the ninth intermediate parameter δ i = (h i +r·d i )·w i mod q, where d i is for party Pi Private key share; finally, the signature share is calculated

[0032] Signature module, used for all signature participants to obtain their respective signature shares s according to the methods of S1 - S5 k , k ∈ {1, 2, …, T}, and then the signature is obtained When multiple parties communicate with other communication parties, after receiving the signature data (r, s), the other communication parties use the public keys Q corresponding to all parties to verify the signature.

[0033] According to another aspect of the present invention, a multi - party collaborative threshold signature system based on ECDSA is provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above - mentioned method are implemented.

[0034] According to another aspect of the present invention, a computer - readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above - mentioned method are implemented.

[0035] Generally speaking, compared with the prior art through the above - mentioned technical solutions conceived by the present invention, the following beneficial effects can be achieved:

[0036] (1) The multi - party collaborative threshold signature method designed based on the ECDSA algorithm in the present invention only uses simple additive linear secret sharing and Shamir secret sharing to enable multiple participants to complete signature calculation without revealing their respective private key shares, meeting the requirements of the correctness and efficiency of multi - party collaborative signature. Each signature participant generates and saves their respective signature shares without revealing their partial signature keys, and then calculates the signatures corresponding to all signature participants. The entire signature scheme has low computational complexity, simple data interaction topology, and less stored data, thus solving the technical problem that existing multi - party threshold collaborative signature algorithms often have high computational overhead, communication overhead, and storage overhead.

[0037] (2) The multi - party collaborative threshold signature method designed based on the ECDSA algorithm in this solution verifies the legality of the transmitted information based on discrete logarithm zero - knowledge proof and verifiable secret sharing technology under the malicious adversary model, without introducing high - overhead techniques such as range proof or consistency check with high computational and communication overhead.

[0038] (3) The multi - party collaborative threshold signature method designed based on the ECDSA algorithm in this solution selects a random polynomial and Combining simple additive linear secret sharing and Shamir secret sharing can achieve multiple parties to complete signature calculation without revealing their respective private key shares, meeting the requirements of the correctness and efficiency of multi-party collaborative signature. Brief Description of the Drawings

[0039] Figure 1 is a flowchart of the private key threshold share and public key generation algorithm under the semi-honest adversary model in an embodiment of the present invention.

[0040] Figure 2 is a flowchart of the signature share generation algorithm under the semi-honest adversary model in an embodiment of the present invention.

[0041] Figure 3 is a flowchart of the private key threshold share and public key generation algorithm under the malicious adversary model in an embodiment of the present invention.

[0042] Figure 4 is a flowchart of the signature share generation algorithm under the malicious adversary model in an embodiment of the present invention. Detailed Embodiments

[0043] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0044] Each party in the present invention is a party participating in key generation. For the N computing devices (such as personal computers and smart mobile devices) participating in signature key generation, their respective public key shares Q i , and the f i required for other parties to generate private key shares s ij are generated, and then each party calculates and saves its own private key share s i . At least T parties are required to generate signatures. In this process, decentralization is achieved, and the leakage of a certain party's key will not affect the security of the signature. Next, P i and P j are used as representatives of the parties for illustration.

[0045] In one embodiment, as Figure 2 shows, a multi-party collaborative threshold signature method based on ECDSA is provided, which is applicable to the semi-honest adversary model. The method includes:

[0046] S1: For any party P i , i ∈ {1, 2,..., N}, where N is the number of parties; Pi Select a random number k i Calculate the first intermediate parameter R i = k i G, where G is the base point coordinate on the elliptic curve; Use k i and the maximum allowed number of colluding parties t - 1 to select a random polynomial g i (x), Use the threshold T for signature participation and the maximum allowed number of colluding parties t - 1 to select a random polynomial w i (x), and calculate the second intermediate parameter g i corresponding to party P j and the third intermediate parameter w ij ; g ij = g ij (x i ), w j = w ij (x i ); x j is the label of party P j ; j

[0047] S2: Party P i Sends the first intermediate parameter R i , the second intermediate parameter g ij and the third intermediate parameter w ij to party P j ;

[0048] S3: Party P j Calculates the fourth intermediate parameter and the fifth intermediate parameter q is the order of the base point G; Calculate the sixth intermediate parameter ρ j = g j · w j mod q;

[0049] S4: Party P j Broadcasts ρ j , and all parties receive ρ j ;

[0050] S5: Party P i Calculates the seventh intermediate parameter and then obtains the signature parameter r = r x mod q and the signature parameter e is the encrypted message, is the l - th power of the label x i of party P i ; Also calculates the eighth intermediate parameter ​and the intermediate parameter δ between nine i =(h i +r·d i )·w i mod q, d i is the private key share of the participating party P i ; finally, the signature share is calculated

[0051] S6: All signature participating parties obtain their respective signature shares s k , k∈{1,2,…,T}, and then obtain the signature When multiple participating parties establish communication with other communication parties, after receiving the signature data (r, s), the other communication parties use the public keys Q corresponding to all participating parties to verify the signature s

[0052] In one embodiment, as Figure 4 shown, when the application scenario is a malicious adversary model, between S2 and S3, it further includes: The participating party P j verifies the legality of the received R i , g ij , w ij . If R i , g ij , w ij then execute S3

[0053] Among them, in the malicious adversary model, for the verification of R i generated by each party, using zero-knowledge proof of discrete logarithm, according to the random number selected by the participating party and the generated R i , generate the zero-knowledge evidence π i , and send it to other participating parties together with R i for verification. If the zero-knowledge evidence and the public key share cannot pass the verification, stop the signature activity

[0054] Among them, in the malicious adversary model, the participating party uses verifiable secret sharing technology to interactively generate g i , w i . During this process, it can be verified whether the shares generated by the polynomials sent by other participating parties are correct. If the verification fails during the process, stop the signature activity

[0055] In one embodiment, two random polynomials are selected and Among them, k i is the random number corresponding to the participating party P i ,, b il and c il are the participating parties P iThe selected random number... The selection of the above two polynomials incorporates random numbers. In the above polynomials, k i is randomly selected to protect the signed message. Combining k i to obtain the final signature forms a discrete logarithm problem, which can avoid message leakage; w i (x) is mainly used in the intermediate process. The selection of random numbers can ensure the randomness of intermediate data and protect the message.

[0056] In one embodiment, as Figure 1 shown, in the semi - honest adversary model, during the collaborative signature initialization phase:

[0057] 1. Party P i selects a random number and calculates the public key share Q i = u i G. Then, it selects a random polynomial and then calculates the first function value f ij based on the label of other party P j , where {a il} 1≤l≤t-1 is the random number selected by P i , and t represents the threshold value corresponding to the polynomial f i (x).

[0058] 2. Party P i sends the public key share Q i and the first function value f ij to party P j .

[0059] 3. Party P j calculates the private key threshold share calculates the public key Then it securely stores {Q, d j}}.

[0060] Specifically, party P i selects its own random number u i calculates its own public key share, selects a random polynomial calculates f ij , and transmits Q i , f ij to party P j . Similarly, party P j transmits the calculated Q j , f ji to party P i . Party P i all need to calculate the public key and respectively calculate their own private key threshold shares Then store {Q, d i}, the participant P j Similarly.

[0061] In one embodiment, as Figure 3 shown, in the malicious adversary model, the collaborative signature initialization phase:

[0062] 1. The participant P i Selects a random number Calculates the public key share Q i = u i G, and then selects a random polynomial After that, calculates the first function value f j according to the labels of other participants P ij , where {a il} 1≤l≤t-1 is the random number selected by P i , and t represents the threshold value corresponding to the polynomial f i (x).

[0063] 2.1. The participant P i Sends Q i to the participant P j ;

[0064] 2.2. The participant P i Sends the first function value f ij to the participant P j ;

[0065] 3. The participant P j Verifies the legality of Q i and f ij . If it is legal, then execute the next step;

[0066] 4. The participant P j Calculates the private key threshold share Calculates the public key Then securely stores {Q, d j}.

[0067] In one embodiment, the participant P i Invokes the discrete logarithm zero-knowledge proof evidence generation algorithm DLZK.Gen(k i , Q i ) to generate the evidence π i . Fuses the part related to Q i in it to get (π i , Q i ) and sends it to the participant P j . P j Invokes the discrete logarithm zero-knowledge proof verification algorithm DLZK.Ver(π i)Verify π i to determine the i legitimacy of Q.

[0068] Among them, under the malicious adversary model, for the verification of the public key share, the zero-knowledge proof of discrete logarithm is used. According to the random number selected by the participating party P i and the generated public key share Q i , generate the zero-knowledge proof π i , and send it to other participating parties together with its own public key share Q i for verification. If the zero-knowledge proof and the public key share cannot pass the verification, the signature activity is stopped.

[0069] In one embodiment, under the malicious adversary model, the participating party P j uses the verifiable secret sharing technology to interactively generate the private key threshold share. During this process, it can verify whether the data generated by the polynomials sent by other parties is correct. If the verification fails during the process, the signature activity is stopped.

[0070] According to another aspect of the present invention, a multi-party collaborative threshold signature device based on ECDSA is provided, including:

[0071] The first calculation module is used for any participating party P i , i ∈ {1, 2,..., N}, N is the number of participating parties; P i selects a random number k i to calculate the first intermediate parameter R i = k i G, G is the base point coordinate on the elliptic curve; uses k i and the maximum number of colluding participating parties value t - 1 to select a random polynomial g i (x), uses the threshold value T for signature and the maximum number of colluding participating parties value t - 1 to select a random polynomial w i (x), and calculates the second intermediate parameter g i corresponding to the participating party P j and the third intermediate parameter w ij , g ij = g ij = g i (x j ), w ij = w i (x j ); x j is the label of the participating party P j ;

[0072] The first sending module is used for the participating party P i to send R i , g ij and wij Sent to Participant P j ;

[0073] The second calculation module, for Participant P j Calculate the fourth intermediate parameter And the fifth intermediate parameter q is the order of the base point G; to calculate the sixth intermediate parameter ρ j = g j ·w j mod q;

[0074] The second sending module, for Participant P j Broadcast ρ j All participants receive ρ j ;;

[0075] The share determination module, for Participant P i Calculate the seventh intermediate parameter Furthermore, obtain the signature parameter r = r x mod q and the signature parameter e is the encrypted message, For Participant P i The label x i To the l-th power; also calculate the eighth intermediate parameter And the ninth intermediate parameter δ i =(h i + r·d i )·w i mod q, d i For Participant P i The private key share; finally calculate the signature share

[0076] The signature module, for all signature participants to obtain their respective signature shares s according to the method of S1 - S5 k , k ∈ {1, 2,..., T}, and then obtain the signature When multiple participants communicate with other communication parties, after receiving the signature data (r, s), the other communication parties use the public keys Q corresponding to all participants to verify the signature.

[0077] According to another aspect of the present invention, there is provided a multi-party collaborative threshold signature system based on ECDSA, including a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps of the above method are implemented.

[0078] Among them, the ECDSA collaborative signature generation system constructed based on the present invention includes N devices participating in key generation, and T of them participate in generating the signature of the message and verifying the signature. By adding discrete logarithm zero-knowledge proof and verifiable secret sharing technology, the security under the malicious adversary model is ensured.

[0079] According to another aspect of the present invention, there is provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0080] It is easy for those skilled in the art to understand that the above are only the preferred embodiments of the present invention, and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A multi-party collaborative threshold signature method based on ECDSA, characterized in that, it includes: S1: For any participant P i , i∈{1,2,…,N}, N is the number of participants; P i Choose a random number k i Calculate the first intermediate parameter R i =k i G, G is the base point coordinate on the elliptic curve; using k i and the maximum number of collusion participants allowed is t-1, and a random polynomial g is selected i (x) Select a random polynomial w using the threshold value T of participating signatures and the maximum number of collusion participants allowed, t-1. i (x), and calculate the participant P i and participant P j The corresponding second intermediate parameter g ij and the third intermediate parameter w ij , g ij =g i (x j ), w ij =w i (x j ); x j For the participant P j Labels; S2: Party P i Send R i , g ij and w ij to Party P j ; S3: Party P j Calculate the fourth intermediate parameter and the fifth intermediate parameter q is the order of the base point G; to calculate the sixth intermediate parameter ρ j = g j · w j mod q; S4: Participant P j broadcasts ρ j and all participants receive ρ j ; S5: Party P i Calculate the seventh intermediate parameter and then obtain the signature parameter r = r x mod q and the signature parameter where e is the encrypted message, for Party P i is the tag x i to the l-th power; also calculate the eighth intermediate parameter where l ∈ {1,…,T} and the ninth intermediate parameter δ i =(h i + r·d i )·w i mod q, where d i is the private key share of Party P i Finally, calculate the signature share S6: All signature participants obtain their respective signature shares s according to the methods of S1 - S5 k , k ∈ {1, 2, …, T}, and then obtain the signature When multiple participants communicate with other communication parties, after receiving the signature data (r, s), the other communication parties verify the signature using the public keys Q corresponding to all participants 2. The multi-party collaborative threshold signature method based on ECDSA according to claim 1, characterized in that, When the application scenario is a malicious adversary model, between S2 and S3, it also includes: Party P j Verify the received R i , g ij , w ij for legality. If the legality verification of R i , g ij , w ij passes, then execute S3.

3. The multi-party collaborative threshold signature method based on ECDSA according to claim 2, characterized in that, Verification of R i Process: Party P j receives (π i , R i ) sent by Party P i , where (π i , R i ) is the combination of the proof π i generated by Party P i calling the discrete logarithm zero - knowledge proof evidence generation algorithm DLZK.Gen(k i , R i ) and R i ; then Party P j calls the discrete logarithm zero - knowledge proof verification algorithm DLZK.Ver(π i ) to verify π i and determine the legitimacy of R i . Process of verifying g ij by Party P j Verify the legality of the received g based on the verifiable secret sharing (VSS) algorithm ij ; Process of verifying w ij : Party P j verifies the legality of the received w based on the VSS algorithm ij .

4. The multi-party collaborative threshold signature method based on ECDSA according to claim 1, characterized in that, Select two random polynomials and where k i is the random number corresponding to the participant P i , b il and c il are the random numbers selected by the participant P i .

5. The multi-party collaborative threshold signature method based on ECDSA according to claim 1, characterized in that, the determination method of the public keys Q of all participating parties is as follows: A1: Any participant P i Select a random number Calculate the public key share Q i = u i G, and then select a random polynomial According to other participants P j 's x j Calculate the first function value f ij , where {a il} 1≤l≤t-1 is the random number selected by P i , and t represents the threshold value corresponding to the polynomial f i (x); A2, Participant P i sends its public key share Q i and the first function value f ij to Participant P j ; A3. Party P j Calculate the private key threshold share Calculate the public key Then securely store {Q, d j}, d j For Party P j Calculate its own signature share.

6. The multi-party collaborative threshold signature method based on ECDSA according to claim 5, characterized in that, When the application scenario is a malicious adversary model, between S2 and S3, it also includes: Party P j Verify the received Q i and f ij for legality. If both Q i and f ij are legal, then execute S3.

7. The multi-party collaborative threshold signature method based on ECDSA according to claim 6, characterized in that, Verify Q i The process is as follows: Party P j receives (π i , Q i ) sent by Party P i , where (π i , Q i ) is the combination of the proof π i generated by Party P i calling the discrete logarithm zero - knowledge proof evidence generation algorithm DLZK.Gen(k i , Q i ) and Q i ; then Party P j calls the discrete logarithm zero - knowledge proof verification algorithm DLZK.Ver(π i ) to verify π i to determine the legality of Q i . Verify f ij The process is as follows: Party P j verifies the legality of the received f ij based on the VSS algorithm.

8. A multi-party collaborative threshold signature device based on ECDSA, characterized in that, it includes: The first calculation module is used for any participant P i , i∈{1,2,…,N}, N is the number of participants; P i Choose a random number k i Calculate the first intermediate parameter R i =k i G, G is the base point coordinate on the elliptic curve; using k i and the maximum number of collusion participants allowed is t-1, and a random polynomial g is selected i (x) Select a random polynomial w using the threshold value T of participating signatures and the maximum number of collusion participants allowed, t-1. i (x), and calculate the participant P i and participant P j The corresponding second intermediate parameter g ij and the third intermediate parameter w ij , g ij =g i (x j ), w ij =w i (x j ); x j For the participant P j Labels; The first sending module is used for participant P i to send R i , g ij and w ij to participant P j ; The second computing module, for Party P j Calculate the fourth intermediate parameter and the fifth intermediate parameter q is the order of the base point G; to calculate the sixth intermediate parameter ρ j = g j ·w j mod q; The second sending module is used for participant P j to broadcast ρ j so that all participants receive ρ j ; The share determination module is used for participant P i Calculate the seventh intermediate parameter Furthermore, obtain the signature parameter r = r x mod q and the signature parameter e is the encrypted message, for participant P i the label x i to the l-th power; also calculate the eighth intermediate parameter l ∈ {1, …, T} and the ninth intermediate parameter δ i =(h i + r · d i )· w i mod q, d i is the private key share of participant P i Finally, calculate the signature share Signature module, for all signature participants to obtain their respective signature shares s according to the methods of S1 - S5 k , k ∈ {1, 2, …, T}, and then obtain the signature When multiple participants communicate with other communication parties, after receiving the signature data (r, s), the other communication parties use the public keys Q corresponding to all participants to verify the signature.

9. A multi-party collaborative threshold signature system based on ECDSA, including a memory and a processor, and the memory stores a computer program, characterized in that, when the processor executes the computer program, the steps of the method described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, on which a computer program is stored, characterized in that, when the computer program is executed by a processor, the steps of the method described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • ECDSA digital signature method based on two-party collaboration

    CN109639439A

  • Digital signature multi-party generation method and system with participants not needing to be online at same time

    CN113704831A