Method and apparatus for generating hash values

By using a set of binary linear [n, k] codes and a target Bernoulli distribution in the hash proof system, public and private computational hash values ​​are generated, solving the problem of insufficient security in existing technologies and realizing high-security hash value generation in the post-quantum era.

CN117134888BActive Publication Date: 2025-12-02HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210543169.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-18
Publication Date
2025-12-02
Estimated Expiration
2042-05-18

AI Technical Summary

Technical Problem

Existing hash proof systems based on coding difficulties are not very secure in the post-quantum era and cannot satisfy statistical smoothness, resulting in insufficient security when generating hash values.

Method used

Using a binary linear [n, k] code set and a target Bernoulli distribution, public and private computational hash values ​​are generated through inner product operations. This ensures that the distance between the first instance and the nearest codeword in the [n, k] code set is less than or equal to the second preset parameter w, and when 2d/n is less than or equal to 1/2, the probability that the public and private computational hash values ​​are equal is greater than or equal to the difference between 1 and 1. β is greater than or equal to d log(n/d) and greater than or equal to 4k. The distance between any codeword in the [n, k] code set other than the codeword identical to the second instance in the second language and the codeword in the [n, k] code set lies within the interval [(1-β)*n/2, (1+β)*n/2].

Benefits of technology

This improves the security of hash proof systems, enabling them to achieve statistical smoothness in the post-quantum era, thereby enhancing the security of generated hash values.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117134888B_ABST
    Figure CN117134888B_ABST
Patent Text Reader

Abstract

This application provides a method and apparatus for generating hash values. The technical solution provided in this application generates hash values ​​by constructing a hash proof system that satisfies statistical smoothness based on a coding difficulty problem. Since a hash proof system that satisfies statistical smoothness is more secure than a hash proof system that satisfies computational smoothness, the hash proof system constructed based on a coding difficulty problem in this application is more secure when generating hash values.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a method and apparatus for generating hash values. Background Technology

[0002] A hash proof system (HPS), also known as a smooth projective hash function (SPHF), is a non-interactive proof system that only allows the designated verifier and can be used as a cryptographic tool for constructing many high-level security systems or protocols.

[0003] Typically, the underlying difficult problem used in constructing HPS is discrete logarithms, but discrete logarithm problems are unsafe in the post-quantum era. Therefore, constructing HPS based on post-quantum difficult problems has become a widely concerned research problem.

[0004] Currently, a common approach to constructing HPS based on post-quantum difficult problems is to construct SPHF based on encoded difficult problems, including SPHF based on learning parity with noise (LPN) or SPHF based on rank metric code.

[0005] However, when upper-layer security systems or protocols use the aforementioned SPHF to generate hash values, the security is not high. Summary of the Invention

[0006] This application provides a method and apparatus for generating hash values, which can improve the security of generating hash values.

[0007] In a first aspect, this application provides a method for generating a hash value, applied to a first device, comprising: determining a publicly computed hash value based on a first instance, evidence of the first instance, and a public key of a second device; sending the first instance and the publicly computed hash value; wherein the first instance is equal to the sum of a first target value and first deviation information, the first target value is equal to the product of evidence of the first instance and the generator matrix of a binary linear [n, k] code set, the Hamming weight of the first deviation information is less than or equal to a first threshold, and the first threshold is less than a second threshold; the public key is determined based on a target Bernoulli distribution, the probability value of the target Bernoulli distribution when the experiment is successful is equal to the ratio of a first preset parameter d to n; the values ​​of the first threshold and the second threshold satisfy the following condition: the probability that the publicly computed hash value is equal to the privately computed hash value when the distance between the first instance and the nearest codeword in the [n, k] code set is less than or equal to the second preset parameter w and 2d / n is less than or equal to 1 / 2 is greater than or equal to 1 / 2. The difference, β is greater than or equal to d log(n / d) is greater than or equal to 4k, the distance between any codeword in the [n,k] code set other than the codeword identical to the second instance in the second language and the nearest codeword in the [n,k] code set is within the interval [(1-β)*n / 2, (1+β)*n / 2], β indicates the value of β corresponding to the [n,k] code set being a β-balanced code, the second instance is equal to the sum of the second target value and the second deviation information, the second target value is equal to the product of the evidence of the second instance and the generator matrix of the [n,k] code set, and the Hamming weight of the second deviation information is less than or equal to the second threshold.

[0008] In the hash value generation method provided in this embodiment, when the values ​​of the first threshold and the second threshold satisfy the above conditions, the hash proof system based on the coding difficulty problem constructed based on the [n,k] code set, the second language, and the first instance can be proven to satisfy the smoothness in the statistical sense. Therefore, compared with the existing hash proof system based on the coding difficulty problem that can only satisfy the smoothness in the computational sense, the hash proof system that satisfies the smoothness in the statistical sense is more secure than the hash proof system that satisfies the smoothness in the computational sense. Therefore, the hash proof system constructed based on the [n,k] code set, the second language, and the first instance of this application is also more secure when generating hash values.

[0009] In conjunction with the first aspect, in one possible implementation, the public key is obtained by performing an inner product operation between the generator matrix of the [n, k] code set and the private key of the second device, the private key of the second device being determined based on the target Bernoulli distribution.

[0010] In conjunction with the first aspect, in one possible implementation, the private key of the second device is the information obtained by the second device sampling the target Bernoulli distribution n times.

[0011] In conjunction with the first aspect, in one possible implementation, the publicly computed hash value is obtained by performing an inner product operation on the evidence of the first instance and the public key of the second device, followed by a modulo 2 operation.

[0012] Secondly, this application provides a hash value generation method applied to a second device, comprising: receiving a first instance and a publicly computed hash value corresponding to the first instance sent by a first device; determining a privacy-computed hash value based on the first instance and the private key of the second device, wherein the probability that the privacy-computed hash value and the publicly computed hash value are equal is greater than 1 / 2; wherein the first instance is equal to the sum of a first target value and first deviation information, the first target value is equal to the product of the evidence of the first instance and the generator matrix of the binary linear [n, k] code set, the Hamming weight of the first deviation information is less than or equal to a first threshold, and the first threshold is less than a second threshold; the private key is determined based on a target Bernoulli distribution, the probability value of the target Bernoulli distribution when the experiment is successful is equal to the ratio of a first preset parameter d to n; the values ​​of the first threshold and the second threshold satisfy the following condition: when the distance between the first instance and the nearest codeword in the [n, k] code set is less than or equal to the second preset parameter w and 2d / n is less than or equal to 1 / 2, the probability that the publicly computed hash value and the privacy-computed hash value are equal is greater than or equal to 1 / 2. The difference, β is greater than or equal to d log(n / d) is greater than or equal to 4k, the distance between any codeword in the [n,k] code set other than the codeword identical to the second instance in the second language and the nearest codeword in the [n,k] code set is within the interval [(1-β)*n / 2, (1+β)*n / 2], β indicates the value of β corresponding to the [n,k] code set being a β-balanced code, the second instance is equal to the sum of the second target value and the second deviation information, the second target value is equal to the product of the evidence of the second instance and the generator matrix of the [n,k] code set, and the Hamming weight of the second deviation information is less than or equal to the second threshold.

[0013] In conjunction with the second aspect, in one possible implementation, the private key of the second device is the information obtained by the second device sampling the target Bernoulli distribution n times.

[0014] In conjunction with the second aspect, in one possible implementation, the privacy computation hash value is obtained by performing an inner product operation between the instance to be verified and the private key of the second device, followed by a modulo 2 operation.

[0015] In conjunction with the second aspect, in one possible implementation, the method further includes: determining the public key of the second device based on the private key of the second device, wherein the public key is obtained by performing an inner product operation between the generator matrix of the [n, k] code set and the private key of the second device.

[0016] In conjunction with the second aspect, in one possible implementation, the method further includes sending the public key of the second device to the first device.

[0017] Thirdly, this application provides a hash proof system, comprising: an instance set module, a first language module, a key projection module, a public computation module, and a privacy computation module; the instance set module contains an instance set, which is a set of binary linear [n, k] codes; the first language module includes a first language, which contains a first instance in the [n, k] code set that satisfies the following conditions: the first instance is equal to the sum of a first target value and a first deviation information, the first target value is equal to the product of the evidence of the first instance and the generator matrix of the [n, k] code set, the Hamming weight of the first deviation information is less than or equal to a first threshold, and the first threshold is less than a second threshold; the second language contains a second instance in the [n, k] code set that satisfies the following conditions: the second instance is equal to the sum of a second target value and a second deviation information, the second target value is equal to the product of the evidence of the second instance and the generator matrix of the [n, k] code set. The product of the matrices, the Hamming weight of the second bias information is less than or equal to the second threshold; the key projection module is used to: determine the private key and public key based on the target Bernoulli distribution, the probability value of the target Bernoulli distribution when the experiment is successful is equal to the ratio of the first preset parameter d to n; the public computation module is used to: for the first instance in the first language, determine the public computation hash value based on the first instance, the evidence of the first instance, and the public key of the second device; the privacy computation module is used to: for any instance in the [n, k] code set, determine the privacy computation hash value based on the private key of the second device and the any instance; the values ​​of the first threshold and the second threshold satisfy the following conditions: the probability that the public computation hash value and the privacy computation hash value are equal when the distance between the first instance and the nearest codeword in the [n, k] code set is less than or equal to the second preset parameter w and 2d / n is less than or equal to 1 / 2 is greater than or equal to 1 and The difference, β is greater than or equal to dlog(n / d) is greater than or equal to 4k, and the distance between any codeword in the [n,k] code set other than the codeword identical to the second instance in the second language and the nearest codeword in the [n,k] code set lies within the interval [(1-β)*n / 2, (1+β)*n / 2], where β indicates the value of β when the [n,k] code set is a β-balanced code.

[0018] In conjunction with the third aspect, in one possible implementation, the private key is sampling information obtained by sampling the target Bernoulli distribution n times.

[0019] In conjunction with the third aspect, in one possible implementation, the public key is obtained by performing an inner product operation between the generator matrix of the [n, k] code set and the private key of the second device.

[0020] In conjunction with the third aspect, in one possible implementation, the publicly computed hash value is obtained by performing an inner product operation on the evidence of the first instance and the public key of the second device, followed by a modulo 2 operation.

[0021] In conjunction with the third aspect, in one possible implementation, the privacy computation hash value is obtained by performing an inner product operation between the instance to be verified and the private key of the second device, followed by a modulo 2 operation.

[0022] Fourthly, this application provides a hash value generation apparatus, including a module for performing the method described in the first aspect or any of the possible implementations thereof.

[0023] Fifthly, this application provides a hash value generation apparatus, including a module for performing the method described in the second aspect or any of the possible implementations thereof.

[0024] Sixthly, this application provides a communication device comprising a hash proof system as described in the third aspect or any one of the above.

[0025] For example, the communication device includes a terminal device.

[0026] In a seventh aspect, this application provides a hash value generation apparatus, comprising: a memory and a processor; the memory being used to store program instructions; the processor being used to invoke the program instructions in the memory to execute the method as described in the first aspect or the second aspect or any possible implementation thereof.

[0027] Eighthly, this application provides a computer-readable medium storing program code for computer execution, the program code including instructions for performing the methods described in the first aspect or the second aspect or any possible implementation thereof.

[0028] Ninthly, this application provides a computer program product including computer program code that, when executed on a computer, causes the computer to implement the method as described in the first aspect or the second aspect or any possible implementation thereof.

[0029] The technical effects of any of the implementation methods in aspects three through nine can be found in the technical effects of any of the possible implementation methods in aspects one or two above, and will not be elaborated upon further. Attached Figure Description

[0030] Figure 1 This is a schematic diagram of the structure of a communication system provided in one embodiment of this application;

[0031] Figure 2 A structural diagram illustrating the construction of different upper-layer protocols based on HPS, provided as an embodiment of this application;

[0032] Figure 3 This is a flowchart illustrating a method for generating hash values ​​according to an embodiment of this application.

[0033] Figure 4 A structural schematic diagram of a hash value generation apparatus provided in one embodiment of this application;

[0034] Figure 5 This is a structural schematic diagram of a terminal device provided in one embodiment of this application;

[0035] Figure 6 This is a structural schematic diagram of a hash value generation apparatus provided in one embodiment of this application. Detailed Implementation

[0036] 1. Quantum Computer

[0037] A quantum computer is a physical device that performs high-speed mathematical and logical operations, stores and processes quantum information, following the laws of quantum mechanics. Simply put, a quantum computer is a machine capable of quantum computing; it's a system that uses the laws of quantum mechanics to perform mathematical and logical operations, process and store information. It uses quantum states as memory units and information storage forms, and quantum communication and quantum computing are based on quantum dynamics evolution for information transmission and processing. The hardware components of a quantum computer are on the order of atoms or molecules. A quantum computer is a physical system capable of storing and processing information represented by qubits (quantum bits).

[0038] Just as traditional computers distinguish between 0 and 1 by switching circuits on and off in integrated circuits, with a silicon chip as their basic unit, quantum computers also have their own basic unit—the qubit. A qubit, also known as a quantum bit, represents 0 or 1 through the quantum mechanical system of two quantum states. Examples include the two orthogonal polarization directions of a photon, the spin direction of an electron in a magnetic field, the two directions of nuclear spin, the two different energy levels of a quantum in an atom, or the spatial mode of any quantum system. The principle of quantum computing is to analyze the evolution of quantum states within a quantum mechanical system.

[0039] Compared to traditional computers, the more information a quantum computer processes, the more advantageous it is for performing calculations, and the more accurate the calculations are.

[0040] 2. Post-quantum cryptography

[0041] Post-quantum cryptography refers to a new generation of cryptographic algorithms that can resist attacks by quantum computers on existing cryptographic algorithms. The term "post-" is used because with the advent of quantum computers, most existing public-key cryptographic algorithms, such as elliptic curve cryptography and the Diffie-Hellman algorithm, can be broken by sufficiently large and stable quantum computers. Cryptographic algorithms that can resist such quantum computer attacks can only be effective in the era of quantum computing or in the era after it, hence the term "post-"quantum cryptography.

[0042] 3. Linear code

[0043] For positive integers n and k, a set C of binary linear codes [n, k] is In the k-dimensional subspace of C, each element (each row vector) is called a codeword. Here, using... Let F2 represent the n-dimensional vector space.

[0044] 4. Generating the matrix

[0045] For positive integers n and k, if the linear code Then matrix It is called the generator matrix of the set C of binary linear [n, k] codes.

[0046] 5. Hamming weight

[0047] The Hamming weight is the number of non-zero symbols in a string of symbols. For example, if a string of symbols is represented as 001110001, then the Hamming weight of that string of symbols is 4.

[0048] 6. β-balanced code

[0049] A set of binary linear [n, k] codes C is called a β-balanced code if the Hamming weight of each non-zero codeword in C lies in the interval [(1-β)*n / 2, (1+β)*n / 2], where the Hamming weight is the number of 1s in a vector consisting of 0s and 1s.

[0050] 7. Existence of β-balanced codes

[0051] For β greater than or equal to The probability that a set of binary linear [n, k] codes C is a beta-balanced code is 1 or 2. -Ω(k) difference.

[0052] 8. Smoothness of β-balanced codes

[0053] For β greater than or equal to If d log(n / d) is greater than or equal to 4k, then... If the generator matrix of the β-balanced code C is [missing information], then in [missing information] back, Less than or equal to 2 -Ω(d) Where k is k in the binary linear [n, k] code C, and n is n in the binary linear [n, k] code C. Let r be the vector obtained by sampling n times from a Bernoulli distribution with a probability of d / n when the value is equal to 1. The r vector is an n-dimensional column vector. Indicate Gr and The statistical distance between them, where U represents a uniform distribution.

[0054] 9. Language System

[0055] Let X denote a set of instances, and let L be a set of languages ​​defined by a binary relation R. L Let X be a subset of X, and W be a set of evidence. For x ∈ X, W is a subset of X such that for any x ∈ X, W is a subset of X if and only if there exists an evidence w ∈ W such that (x, w) ∈ R. L When x∈L, then (X, L, W, R) L This constitutes a language system. Instances within any L are indistinguishable from instances outside L.

[0056] 10. Hash Proof System

[0057] A hash proof system (HPS), also known as a hash-based proof system, is a non-interactive proof system that allows only designated verifiers. The proof is ultimately provided in the form of a hash value. Currently, HPS is used to construct many different upper-layer protocols, such as leak-resistant public-key cryptography, key exchange protocols and accidental transmission protocols, threshold signature schemes, and password-based authentication key exchange. Using HPS, different upper-layer protocols can be built from the same module, which is more convenient than designing directly from difficult problems.

[0058] HPS is sometimes also called smooth projective hash functions (SPHF). Due to the noisy mathematical problems used for lattice and encoded cryptography, SPHF can only achieve approximate equality. The definition of approximate SPHF is as follows:

[0059] For instance set X, language set L, and language set L', where, An approximate SPHF within a language set L' contains four algorithms: a private key generation algorithm, a projected key generation algorithm, an algorithm for determining the privacy computation hash, and an algorithm for determining the public computation hash. Let's assume the private key generation algorithm is represented by HashKG(L), the projected key (also called the public key) generation algorithm by ProjKG(sk), the algorithm for determining the privacy computation hash by PrivHash(sk, x), and the algorithm for determining the public computation hash by Pubhash(pk, x, w). Then, HashKG(L) is primarily used to generate the private key sk, ProjKG(sk) is primarily used to determine the public key pk based on the private key sk, and PrivHash(sk, x) is primarily used to determine the privacy computation hash H∈{0,1} based on the private key sk and an instance x in X. m Pubhash(pk, x, w) is primarily used to determine the publicly computed hash value PH∈{0,1} based on the public key pk, evidence w, and instance x. m .

[0060] An approximate SPHF needs to satisfy approximate correctness and smoothness.

[0061] The approximate correctness is defined as follows: SPHF is ∈-correct if for x∈L', Pr[dist(Pubhash(pk,x,w),PrivHash(sk,x)≥∈m]=negl(k). Here, Pr represents the probability, and dist(Pubhash(pk,x,w),PrivHash(sk,x)≥∈m represents the Hamming weight of the distance between the public computation hash value determined by Pubhash(pk,x,w) and the private computation hash value determined by PrivHash(sk,x).

[0062] Smoothness is defined as follows: for all x∈X\L, where X\L represents the set of all instances in instance X but not in the language set L, the following two distributions are statistically indistinguishable:

[0063] {(pk,H):sk=HashKG(L),pk=ProjKG(sk),H=PrivHash(sk,x)} and

[0064] {(pk,H):sk=HashKG(L),pk=ProjKG(sk),H=U({0,1} m )}.

[0065] It should be noted that when the hash value of the approximate SPHF output is a single bit, it is called an approximate bit-PHF. An approximate bit-PHF construction needs to satisfy both approximate correctness and universality.

[0066] The approximate correctness is defined as follows: the approximate bit-PHF is ∈-correct if for x∈L', we have:

[0067] Pr[dist(Pubhash(pk,x,w),PrivHash(sk,x)]≥1-∈.

[0068] The generality is defined as follows: for all x∈X\L, X\L represents the set of all instances in instance X but not in the language set L, the following two distributions are statistically indistinguishable:

[0069] |Pr[PrivHash(sk,x)=1|pk=ProjKG(sk)-1 / 2|≤negl(k)

[0070] It should also be noted that, given an approximate bit-PHF, it can be converted to an approximate SPHF using a general conversion method.

[0071] As the scale of the Internet and the number of users increase year by year, various network methods are emerging one after another, constantly changing people's lifestyles. Figure 1 This is a schematic diagram of the structure of a communication system provided in one embodiment of this application. Figure 1 As shown, the communication system includes communication device 101 and communication device 102, and network 103. Communication device 101 and communication device 102 communicate through network 103.

[0072] In this embodiment, communication device 101 or communication device 102 can be a device that provides voice and / or data connectivity to a user, such as a handheld device or vehicle-mounted device with wireless connectivity. Terminal equipment can also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile equipment, user terminal, wireless telecom equipment, user agent, user equipment, or user device. The terminal device can be a station (STA) in a wireless local area network (WLAN), a cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA) device, handheld device with wireless communication capabilities, computing device or other processing device connected to a wireless modem, in-vehicle device, wearable device, and a terminal in a next-generation communication system (e.g., fifth-generation (5G) communication network) or a terminal device in a future evolved public land mobile network (PLMN) network. 5G can also be referred to as new radio (NR). In one possible application scenario of this application, the terminal device can also be a terminal device that frequently operates on the ground, such as an in-vehicle device.

[0073] Understandably, due to the openness and anonymity of network 103, network security issues may arise when communication devices 101 and 102 communicate using network 103, such as the leakage or tampering of communication information between them. Therefore, to ensure the security of transmitted information, communication devices 101 and 102 employ cryptographic protocols to process the information before transmission when communicating using network 103. Examples of such cryptographic protocols include encrypted encryption protocols with chosen ciphertext security, password-based authentication key exchange protocols, stealth transmission protocols, and anti-leakage encryption protocols.

[0074] In response to the potential threat posed by quantum computers, the National Institute of Standards and Technology (NIST) launched a global call for post-quantum cryptography (PQC) encryption and signature schemes in 2017. PQC schemes are cryptographic schemes that can resist both classical and quantum computing attacks. This work is currently in its third round, with surviving schemes primarily based on five types of problems: lattice-based difficulties, coding difficulties, homology difficulties, hash function difficulties, and solving multivariable quadratic equations.

[0075] Encoding-based cryptography is one of the earliest types of post-quantum cryptography researched. The McEliece scheme has remained unbroken for over forty years, offering relatively high security. It can be used to construct various cryptographic primitives such as encryption, signatures, and key exchange, providing diversity and security backups for post-quantum cryptographic algorithms. The third round of NIST post-quantum algorithm standardization includes three encoding-based encryption schemes: "Classic McEliece," "BIKE," and "HQC." Therefore, more encoding-based designs are needed to provide security backups beyond lattice cryptography.

[0076] In 2002, Cramer and Shoup proposed the concept of HPS. HPS is a non-interactive proof system that allows only designated verifiers, with proofs ultimately provided as hash values. Currently, HPS can be used to construct leak-resistant public-key cryptography, key exchange protocols and unintentional transmission protocols, threshold signature schemes, and password-based authentication key exchange. Using HPS, different upper-layer protocols can be built from the same module, which is more convenient than designing directly from difficult problems. In other words, the underlying layer of cryptographic protocols (upper-layer protocols) used between communication devices can be constructed using HPS.

[0077] For example, Figure 2 This application provides a structural diagram illustrating the different upper-layer protocols built upon HPS. For example... Figure 2As shown, HPS is first constructed based on post-quantum difficulties, and then different upper-layer protocols are built using HPS, such as... Figure 2 The protocols used include password-based key exchange protocols, leak-proof encryption protocols, and accidental transmission protocols.

[0078] like Figure 2 As shown, constructing HPS requires a foundational hard problem. Early construction of HPS used discrete logarithms as the foundational hard problem, but discrete logarithm problems are unsafe in the post-quantum era. Therefore, constructing HPS based on post-quantum hard problems has become a widely studied research topic.

[0079] Currently, a common approach to constructing HPS based on post-quantum difficult problems is to construct SPHF based on encoded difficult problems, including SPHF based on learning parity with noise (LPN) or SPHF based on rank metric code.

[0080] However, when upper-layer security systems or protocols use the aforementioned SPHF to generate hash values, the security is not high.

[0081] Analysis revealed that the low security of upper-layer security systems or protocols using the aforementioned SPHF to generate hash values ​​stems from the following reasons: Typically, the constructed SPHF needs to satisfy approximate correctness and smoothness. Smoothness includes both computational smoothness and statistical smoothness, with statistically smooth SPHF generally offering higher security than computationally smooth SPHF. However, existing SPHF construction methods based on coding difficulties cannot prove statistical smoothness. Therefore, SPHF constructed based on coding difficulties is inherently insecure, leading to low security when upper-layer security systems or protocols use SPHF constructed based on existing coding difficulties to generate hash values.

[0082] Therefore, embodiments of this application provide an SPHF constructed based on a coding difficulty problem that can satisfy statistical smoothness, thereby improving the security when generating hash values.

[0083] The following description, in conjunction with the accompanying drawings, illustrates the hash proof system that satisfies statistical smoothness according to embodiments of this application, and the method for generating public and private computational hash values ​​using the hash proof system constructed in this application.

[0084] First, the hash proof system that satisfies statistical smoothness constructed in this application is explained. It should be noted that the hash proof system that satisfies statistical smoothness constructed in this application is also called the target hash proof system.

[0085] It should be understood that when constructing a hash proof system, a target language system (also referred to as the target language definition in this embodiment) must first be defined. In this embodiment, the target language definition includes:

[0086] 1) Define an instance set X

[0087] In this embodiment, the instance set X is a set of binary linear [n, k] codes C, and the generator matrix corresponding to C is G.

[0088] In this embodiment, each codeword in the [n, k] code set C can be considered as an instance of X, and each instance is an n-dimensional vector in an n-dimensional space, denoted as: G is a matrix with k rows and n columns, denoted as

[0089] 2) Define the first language set L1 and the second language set L2, also known as the first language L1 and the second language L2.

[0090] In this embodiment, the instance in L1 is referred to as the first instance, and the instance in L2 is referred to as the second instance.

[0091] Specifically, L1 contains a first instance in the set of [n, k] codes that satisfies the following conditions: the first instance is equal to the sum of the first target value and the first deviation information; the first target value is equal to the product of the evidence of the first instance and the generator matrix of the set of binary linear [n, k] codes; the Hamming weight of the first deviation information is less than or equal to the first threshold, and the first threshold is less than the second threshold.

[0092] Specifically, L2 contains a second instance in the set of [n, k] codes that satisfies the following conditions: the second instance is equal to the sum of the second target value and the second deviation information; the second target value is equal to the product of the evidence of the second instance and the generator matrix of the set of [n, k] codes; and the Hamming weight of the second deviation information is less than or equal to the second threshold.

[0093] In this case, regardless of whether it is the first instance or the second instance, if we denote the instance as v, the evidence of the instance as u, the first deviation information as e1, the first threshold as o(B), the second threshold as B, and the second deviation information as e2, then:

[0094] For instances in the first language L1, the following condition must be satisfied: there exist u and e1 such that v equals the sum of uG and e1 and the Hamming weight of e1 is less than or equal to o(B), denoted as:

[0095]

[0096] For instances in the second language L2, the following conditions must be met: there exist u and e2 such that the second instance v is equal to the sum of uG and e2, and the Hamming weight of e2 is less than or equal to B, denoted as:

[0097]

[0098] Where dist(v, C) represents the distance between instance v and the nearest codeword in C, and o(B) is less than or equal to B.

[0099] In this embodiment, the target hash proof system based on the above target language definition can execute the following algorithms: a) generating a private key, b) generating a public key, c) calculating a public computation hash value for the first instance in the first language L1, and d) calculating a privacy computation hash value (also known as a private computation hash value) for any instance in the instance set X.

[0100] One possible implementation for generating the private key is to sample the target Bernoulli distribution n times to generate the private key sk information, denoted as sampling. Output the private key sk information. Among them, Let sk = s, which represents n samplings of a target Bernoulli distribution with a probability of d / n when the value is 1.

[0101] One possible implementation for generating the public key is as follows: The key is obtained by performing an inner product operation based on the generation matrix G and the sk information, denoted as:

[0102] One possible implementation for calculating the public computed hash value for the first instance in the first language L1 is as follows: the public computed hash value is obtained by performing an inner product operation on the evidence u of the first instance and the public key pk of the second device, followed by a modulo 2 operation, denoted as: PubHash(pk,v,u)=<u,pk>=<u,Gs>mod / 2.

[0103] In this context, for any instance in the instance set X, the privacy computation hash value is calculated. One possible implementation is as follows: the privacy computation hash value is obtained by performing an inner product operation between the instance v to be verified and the private key s of the second device, followed by a modulo 2 operation, denoted as: PrivHash(sk,v)=<v,s>mod2.

[0104] In this embodiment, the values ​​of B and o(B) satisfy the following conditions: the probability that the public computation hash value and the private computation hash value are equal when the distance between the first instance and the nearest codeword in the [n, k] code set is less than or equal to the second preset parameter w and 2d / n is less than or equal to 1 / 2 is greater than or equal to 1. The difference, β is greater than or equal to d log(n / d) is greater than or equal to 4k, and the distance between any codeword in the [n,k] code set other than the codeword identical to the second instance in the second language and the nearest codeword in the [n,k] code set lies within the interval [(1-β)*n / 2, (1+β)*n / 2], where β indicates the value of β when the [n,k] code set is a β-balanced code.

[0105] In this embodiment, since β is greater than or equal to Since d log(n / d) is greater than or equal to 4k, and the distance between any instance in the instance set X (excluding instances in L2) and the nearest codeword in C lies within the interval [(1-β)*n / 2, (1+β)*n / 2], the target hash proof system constructed based on the coding difficulty problem in this embodiment can satisfy the requirement of generality. The proof process is as follows:

[0106] Since the probability that the set C of binary linear [n, k] codes is a β-balanced code is 1 or 2... -Ω(k) The difference is such that if dist(v, C) is contained in [(1-β)*n / 2, (1+β)*n / 2], then (G||v) is still a binary linear code of a β-balanced code, where (G||v) represents adding the vector v after the last row of the generator matrix G. Then, based on the smoothness of the binary linear code of a β-balanced code, we have... Where, ≈ s This indicates that the statistics are close, that is:

[0107] |Pr[PrivHash(sk,v)=1|pk=ProjKG(sk)]-1 / 2|≤negl(k)

[0108] Therefore, the target hash proof system of this application, based on the above target language definition, satisfies smoothness in a statistical sense.

[0109] In this embodiment, when the distance between the first instance and the nearest codeword in C is less than or equal to the second preset parameter w and 2d / n is less than or equal to 1 / 2, the probability that the privacy-computing hash value and the public-computing hash value are equal is greater than or equal to 1. The difference, where β indicates the value of β corresponding to C being a β-balanced code, and the ratio of d / n is equal to the probability value of the target Bernoulli distribution when it is 1. Let it be: if dist(v, C) ≤ w, and 2d / n ≤ 1 / 2, then for v ∈ L1, we have:

[0110] The proof process is as follows:

[0111] PrivHash(sk,v)=<v,s>=<uG,s>+<e,s>=<u,G s>+<e,s>=<u,pk>+<e,sk>,

[0112]

[0113] (The inequality is derived from the "pilling-up" lemma), therefore:

[0114]

[0115] That is, in this embodiment, the constructed target hash system satisfies approximate correctness. The relevant "pilling-up" lemma can be found in descriptions in related technologies, and will not be repeated here.

[0116] Based on the above proof, if the definition Generality applies only to:

[0117] If dist(v, C) ∈ [(1-β)*n / 2, (1+β)*n / 2] holds true, then v ∈ L1 can be obtained by bit flipping the elements in v.

[0118] As an optional embodiment, to satisfy the conditions of approximate correctness and generality, this application provides a set of bit-PHF constructs with appropriate language and parameters. Specifically, the construct includes:

[0119] First, select appropriate parameters and definition language: For example Let there be a set C of binary linear [n, k] codes, and the generator matrix of the set C is: k and n are a set of parameters that satisfy the given security of the encoding scheme.

[0120] Define language

[0121] Define language Setting parameters d = k / log(k), w = n log 2 (k) / k. That is, in this embodiment, B equals (1-β)*n / 2-1, and o(B) equals n log (k) / k. 2 (k) / k, β equals d equals k / log(k).

[0122] After defining the language and setting the parameters, the specific steps for the bit-PHF scheme are as follows:

[0123] Private key generation: sampling Output private key

[0124] Generate public key: Calculate and output the projection key based on the private key sk.

[0125] Generate privacy-preserving computation hash: For instance v∈X, compute and output the privacy-preserving computation hash based on <v,s>.

[0126] Generate public computed hash values: For instance v∈L1, compute and output public computed hash values ​​according to <u,pk>=<u,Gs>.

[0127] The above, through formulaic proof, presents the hash proof system that satisfies the smoothness in a statistical sense constructed in the embodiments of this application, namely the target hash proof system.

[0128] It should be noted that the specific deployment of the constructed target hash proof system is not limited in the embodiments of this application. For example, when a proof device only needs to prove to other devices that an instance is an instance with evidence, the proof device may deploy a module for determining the public hash value, but not a module for determining the privacy hash value. Similarly, when a verification device only needs to verify whether the instance to be verified sent by other devices is an instance with evidence, the verification device may deploy a module for determining the privacy hash value, but not a module for determining the public hash value.

[0129] Below, based on the target hash system described in the above embodiments of this application, we will explain the method by which the proof device generates a publicly computed hash value when it needs to prove to other devices that an instance is an instance with evidence, and the method by which the designated verifier device generates a privacy-computed hash value when it receives an instance to be verified sent by the proof device.

[0130] like Figure 3 As shown, the method in this embodiment includes: S301, S302, S303, S304, S305 and S306.

[0131] S301, the first device determines a first instance, the first instance being equal to the sum of a first target value and first deviation information, the first target value being equal to the product of the evidence of the first instance and the generator matrix of the binary linear [n, k] code set, the Hamming weight of the first deviation information being less than or equal to a first threshold, and the first threshold being less than a second threshold.

[0132] In this embodiment, the first device can be considered as a communication device that needs to prove itself to other devices (the second device) based on a hash proof system.

[0133] In this embodiment, when the first device needs to prove something to the second device, the first instance obtained by the first device is an instance equal to the sum of the first target value and the first deviation information.

[0134] Specifically, in this embodiment, any instance is represented by v, the evidence of the first instance is represented by u, the generator matrix of the binary linear [n, k] code set is represented by G, the first threshold is represented by o(B), and the second threshold is represented by B. Then, the first instance v in this embodiment satisfies the following condition: there exist u, e 1 Let v be equal to the sum of uG and e1, and the Hamming weight of e1 be less than or equal to o(B), denoted as: Where o(B) is less than B.

[0135] More specifically, in this embodiment, the values ​​of o(B) and B satisfy the following conditions: the probability that the public computation hash value and the private computation hash value are equal when the distance between the first instance and the nearest codeword in the [n, k] code set is less than or equal to the second preset parameter w and 2d / n is less than or equal to 1 / 2 is greater than or equal to 1. The difference, β is greater than or equal to dlog(n / d) is greater than or equal to 4k, and the distance between any codeword in the [n,k] code set other than the codeword identical to the second instance in the second language and the nearest codeword in the [n,k] code set lies within the interval [(1-β)*n / 2, (1+β)*n / 2], where β indicates the value of β when the [n,k] code set is a β-balanced code.

[0136] Wherein, the second instance equals the sum of the second target value and the second bias information; the second target value equals the product of the evidence of the second instance and the generator matrix of the [n, k] code set; and the Hamming weight of the second bias information is less than or equal to the second threshold. That is, for an instance in L2 second language, the following condition must be satisfied: there exists u, e2 The second instance v is equal to the sum of uG and e2, and the Hamming weight of e2 is less than or equal to B, denoted as:

[0137] In other words, in this embodiment, the [n, k] code set forms the instance set X. All instances in X that are equal to the sum of the second target value and the second deviation information form the second language (denoted as L2), while all instances in L2 that are also equal to the sum of the first target value and the first deviation information form the first language (denoted as L1). In this embodiment, the first instance refers to the instance from L1.

[0138] It should be noted that the concept of evidence for instances can be found in the detailed conceptual introduction of hash proof systems in related technologies, and will not be repeated here.

[0139] S302, the first device obtains the public key of the second device, the public key being determined based on a target Bernoulli distribution, the probability value of the target Bernoulli distribution when the experiment is successful being equal to the ratio of the first preset parameter d to n.

[0140] It should be understood that for a communication device that needs to prove itself to a second device, it is necessary to obtain the public key of the second device, and then calculate a hash value based on the public key of the second device, the instance to be verified, and the evidence of the instance to be verified. This is also known as publicly computed hash value.

[0141] Therefore, in this embodiment, when the first device needs to prove something to the second device, the first device needs to obtain the public key of the second device, rather than the public key of a communication device other than the second device.

[0142] It should be noted that the embodiments of this application do not limit the implementation method of obtaining the public key of the second device. For example, in one possible implementation, the first device can send a request for a public key to the second device, and then the second device, after receiving the request for a public key, sends its own public key to the first device; or, after generating its own public key, the second device can continuously broadcast its public key so that any device that needs to use the second device's public key can directly obtain it.

[0143] In this embodiment, the public key of the second device can be denoted as pk.

[0144] In this embodiment, the public key of the second device is obtained based on the target Bernoulli distribution, wherein the probability value of the target Bernoulli distribution when the experiment is successful is equal to the ratio of the first preset parameter d to n.

[0145] Specifically, in one possible implementation, the public key of the second device in this embodiment is the result of taking the inner product of the generation matrix G and the private key of the second device.

[0146] If the private key of the second device is denoted as sk, then in one implementation, sk is the information generated by the second device through n samplings of the target Bernoulli distribution.

[0147] The concept of the generator matrix G can be found in the description of the generator matrix section in the target hash proof system constructed in this application, and will not be repeated here.

[0148] S303, the first device determines the publicly computed hash value based on the first instance, the evidence of the first instance, and the public key of the second device.

[0149] It should be understood that once the first device obtains the first instance, the evidence of the first instance, and the public key of the second device, it can determine the publicly computed hash value based on the first instance, the evidence of the first instance, and the public key of the second device.

[0150] In one possible implementation, after the first device obtains the public key pk information of the second device, it uses the pk information and the evidence u of the first instance v to perform an inner product operation, and then performs a modulo 2 operation on the result to obtain the public computed hash value corresponding to the first instance.

[0151] That is, the public computed hash value PubHash(pk,v,u) of the first instance v can be obtained by the following formula: PubHash(pk,v,u)=<u,pk>=<u,Gs>mod / 2.

[0152] S304, the first device sends a publicly computed hash value and a first instance to the second device, and the second device receives the first instance and the publicly computed hash value accordingly.

[0153] In this embodiment, after the first device determines the public hash value of the first instance based on the public keys of the first instance and the second device, it sends the determined first public hash value and the first instance to the second device so that the second device can determine the private hash value of the first instance.

[0154] S305, the second device obtains the private key of the second device, the private key being determined based on the target Bernoulli distribution.

[0155] It should be understood that when the second device receives the first instance sent by the first device, the second device needs to determine the privacy computing hash value of the first instance based on its own private key.

[0156] In this embodiment, assuming the private key of the second device is denoted as sk, then in this embodiment, sk is determined based on the target Bernoulli distribution, and the probability value of the target Bernoulli distribution when the experiment is successful is equal to the ratio of the first preset parameter d to n.

[0157] Specifically, in one possible implementation, sk is the sampling information obtained by the second device sampling the target Bernoulli distribution n times.

[0158] S306, the second device determines a privacy-computing hash value based on the private keys of the first instance and the second device, wherein the probability that the privacy-computing hash value is equal to the public hash value is greater than 1 / 2.

[0159] In this embodiment, when the second device receives the first instance v, it can calculate the privacy computing hash value of the first instance v based on the private key sk information.

[0160] Specifically, in one possible implementation, the privacy-computing hash value is obtained by performing an inner product operation between the first instance v and the private key of the second device, followed by a modulo-2 operation. That is, the target hash system described above in this application is executed as follows:

[0161] PrivHash(sk,v)=<v,s>mod2

[0162] It is understandable that, since the values ​​of the first threshold and the second threshold satisfy the conditions described above, in this embodiment, since the first instance is an instance in L1, the probability that the first hash value and the second hash value are equal is greater than 1 / 2.

[0163] In the hash value generation method provided in this embodiment, when the values ​​of the first threshold and the second threshold satisfy the above conditions, the hash proof system constructed based on the [n, k] code set, the second language, and the first instance can be proven to satisfy the smoothness in the statistical sense. Since the hash proof system that satisfies the smoothness in the statistical sense is more secure than the hash proof system that satisfies the smoothness in the computational sense, the hash proof system constructed based on the [n, k] code set, the second language, and the first instance of this application is also more secure when generating hash values.

[0164] It should be understood that the above describes the construction method for a target hash system to output a privacy-computing hash value and a public hash value with a single bit, i.e., the construction method of a bit-PHF. It is understood that, given a bit-PHF, it can be converted into SPHF using some general conversion methods. For example, for the construction method of the bit-PHF in this scheme, it can be achieved by: 1) repeating the bit-PHF process by sampling different private keys s using polynomials, or 2) repeating the bit-PHF process by selecting different instances v using polynomials for a fixed private key and projection key, or by combining 1 and 2 using polynomials. All of these methods can yield an SPHF that satisfies both approximate correctness and statistical smoothness.

[0165] Specifically, in this embodiment, after the target prover obtains the public key pk information, the above process can be repeated, and then based on the hash value obtained from multiple repetitions, it can be determined whether the first instance v is an instance in the second language L2 of the target hash proof system.

[0166] The foregoing mainly describes the methods provided in the embodiments of this application. It is understood that each device, in order to achieve the above functions, includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, based on the algorithm steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0167] This application embodiment can divide each device into functional modules according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.

[0168] When dividing each function into modules according to its corresponding function. Figure 4 This is a schematic diagram of a hash value generation apparatus provided in one embodiment of this application. Figure 4 As shown, the device 400 includes: a processing module 401 and / or a transceiver module 402.

[0169] In the first embodiment, the processing module 401 is configured to: determine a publicly computed hash value based on the first instance, the evidence of the first instance, and the public key of the second device; the transceiver module 402 is configured to: send the first instance and the publicly computed hash value;

[0170] Wherein, the first instance is equal to the sum of the first target value and the first deviation information, the first target value is equal to the product of the evidence of the first instance and the generator matrix of the binary linear [n, k] code set, the Hamming weight of the first deviation information is less than or equal to the first threshold, and the first threshold is less than the second threshold;

[0171] The public key is determined based on a target Bernoulli distribution, and the probability value of the target Bernoulli distribution when the experiment is successful is equal to the ratio of the first preset parameter d to n;

[0172] The values ​​of the first and second thresholds satisfy the following conditions: the probability that the public computed hash value and the private computed hash value are equal when the distance between the first instance and the nearest codeword in the [n, k] code set is less than or equal to the second preset parameter w and 2d / n is less than or equal to 1 / 2 is greater than or equal to 1. The difference, β is greater than or equal to d log(n / d) is greater than or equal to 4k, the distance between any codeword in the [n,k] code set other than the codeword identical to the second instance in the second language and the nearest codeword in the [n,k] code set is within the interval [(1-β)*n / 2, (1+β)*n / 2], β indicates the value of β corresponding to the [n,k] code set being a β-balanced code, the second instance is equal to the sum of the second target value and the second deviation information, the second target value is equal to the product of the evidence of the second instance and the generator matrix of the [n,k] code set, and the Hamming weight of the second deviation information is less than or equal to the second threshold.

[0173] In one possible implementation, the public key is obtained by performing an inner product operation between the generator matrix of the [n, k] code set and the private key of the second device, the private key of the second device being determined based on the target Bernoulli distribution.

[0174] In one possible implementation, the private key of the second device is information obtained by the second device sampling the target Bernoulli distribution n times.

[0175] In one possible implementation, the publicly computed hash value is obtained by performing an inner product operation on the evidence of the first instance and the public key of the second device, followed by a modulo 2 operation.

[0176] In the second embodiment, the transceiver module 402 is configured to: receive a first instance and a publicly computed hash value corresponding to the first instance sent by the first device; the processing module 401 is configured to: determine a privacy-computed hash value based on the first instance and the private key of the second device, wherein the probability that the privacy-computed hash value and the publicly computed hash value are equal is greater than 1 / 2; wherein the first instance is equal to the sum of a first target value and a first deviation information, the first target value is equal to the product of the evidence of the first instance and the generator matrix of the binary linear [n, k] code set, the Hamming weight of the first deviation information is less than or equal to a first threshold, and the first threshold is less than a second threshold; the private key is determined based on a target Bernoulli distribution, the probability value of the target Bernoulli distribution when the experiment is successful is equal to the ratio of a first preset parameter d to n; the values ​​of the first threshold and the second threshold satisfy the following condition: when the distance between the first instance and the nearest codeword in the [n, k] code set is less than or equal to the second preset parameter w and 2d / n is less than or equal to 1 / 2, the probability that the publicly computed hash value and the privacy-computed hash value are equal is greater than or equal to 1 / 2. The difference, β is greater than or equal to dlog(n / d) is greater than or equal to 4k, the distance between any codeword in the [n,k] code set other than the codeword identical to the second instance in the second language and the nearest codeword in the [n,k] code set is within the interval [(1-β)*n / 2, (1+β)*n / 2], β indicates the value of β corresponding to the [n,k] code set being a β-balanced code, the second instance is equal to the sum of the second target value and the second deviation information, the second target value is equal to the product of the evidence of the second instance and the generator matrix of the [n,k] code set, and the Hamming weight of the second deviation information is less than or equal to the second threshold.

[0177] In one possible implementation, the private key of the second device is information obtained by the second device sampling the target Bernoulli distribution n times.

[0178] In one possible implementation, the privacy computation hash value is obtained by performing an inner product operation between the instance to be verified and the private key of the second device, followed by a modulo-2 operation.

[0179] In one possible implementation, the processing module 401 is further configured to: determine the public key of the second device based on the private key of the second device, wherein the public key is obtained by performing an inner product operation between the generator matrix of the [n, k] code set and the private key of the second device.

[0180] In one possible implementation, the transceiver module 402 is used to: send the public key of the second device to the first device.

[0181] Figure 5 This is a structural schematic diagram of a terminal device 500 provided in this application. For ease of explanation, Figure 5 Only the main components of the terminal device are shown. For example... Figure 5 As shown, the terminal device 500 includes a processor, a memory, a control circuit, an antenna, and input / output devices. The terminal device 500 can perform the methods described above.

[0182] The processor is primarily used to process communication protocols and data, control the entire terminal device, execute software programs, and process the data within those programs, such as controlling the terminal device to perform the actions described in the above method embodiments. The memory is primarily used to store software programs and data. The control circuit is primarily used for converting baseband signals to radio frequency (RF) signals and processing RF signals. The control circuit and antenna together can also be called a transceiver, primarily used for transmitting and receiving RF signals in the form of electromagnetic waves. Input / output devices, such as touchscreens, displays, and keyboards, are primarily used to receive user input data and output data to the user.

[0183] When the terminal device is powered on, the processor can read the software program from the storage unit, interpret and execute the software program's instructions, and process the software program's data. When data needs to be transmitted wirelessly, the processor performs baseband processing on the data to be transmitted and outputs the baseband signal to the radio frequency (RF) circuit. The RF circuit then processes the baseband signal and transmits the RF signal outward as electromagnetic waves through the antenna. When data is sent to the terminal device, the RF circuit receives the RF signal through the antenna, converts the RF signal into a baseband signal, and outputs the baseband signal to the processor. The processor converts the baseband signal back into data and processes the data.

[0184] Those skilled in the art will understand that, for ease of explanation, Figure 5 Only one memory and processor are shown. In actual terminal devices, multiple processors and memories may exist. Memory can also be called storage medium or storage device, etc., and this application embodiment does not limit this.

[0185] As an optional implementation, the processor may include a baseband processor and a central processing unit (CPU). The baseband processor is mainly used to process communication protocols and communication data, while the CPU is mainly used to control the entire terminal device, execute software programs, and process the data of the software programs. Figure 5The processor integrates the functions of a baseband processor and a central processing unit (CPU). Those skilled in the art will understand that the baseband processor and CPU can also be independent processors interconnected via technologies such as buses. It will also be understood that a terminal device can include multiple baseband processors to adapt to different network standards, and multiple CPUs to enhance its processing capabilities. The various components of the terminal device can be connected via various buses. The baseband processor can also be described as a baseband processing circuit or a baseband processing chip. Similarly, the CPU can be described as a central processing circuit or a central processing chip. The function of processing communication protocols and communication data can be built into the processor or stored as software programs in a storage unit, with the processor executing the software programs to implement the baseband processing function.

[0186] For example, in Figure 5 In this embodiment, the antenna and control circuit with transceiver functions can be regarded as the transceiver unit 501 of the terminal device 500, and the processor with processing functions can be regarded as the processing unit 502 of the terminal device 500. For example... Figure 5 As shown, the terminal device 500 includes a transceiver unit 501 and a processing unit 502. The transceiver unit can also be referred to as a transceiver, transceiver device, or transceiver apparatus. Optionally, the device in the transceiver unit 501 used to implement the receiving function can be considered as a receiving unit, and the device in the transceiver unit 501 used to implement the transmitting function can be considered as a transmitting unit; that is, the transceiver unit 501 includes a receiving unit and a transmitting unit. For example, the receiving unit can also be referred to as a receiver, receiver circuit, or receiving device, and the transmitting unit can be referred to as a transmitter, transmitter, or transmitting circuit.

[0187] Figure 5 The terminal device 500 shown can achieve Figure 3 The methods illustrated are described in detail below. The operations and / or functions of each module in the terminal device 500 are respectively for implementing the corresponding processes in the above method embodiments. For details, please refer to the descriptions in the above method embodiments; to avoid repetition, detailed descriptions are appropriately omitted here.

[0188] Figure 6 This is a structural schematic diagram of a hash value generation apparatus provided in another embodiment of this application. Figure 6 The apparatus shown can be used to perform the method described in any of the foregoing embodiments.

[0189] like Figure 6 As shown, the device 600 in this embodiment includes a memory 601, a processor 602, a communication interface 603, and a bus 604. The memory 601, processor 602, and communication interface 603 are interconnected via the bus 604.

[0190] The memory 601 can be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 601 can store programs, and when the program stored in the memory 601 is executed by the processor 602, the processor 602 uses it to execute... Figure 3 The steps of the method shown.

[0191] The processor 602 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, used to execute relevant programs to implement this application. Figure 3 The method shown.

[0192] The processor 602 can also be an integrated circuit chip with signal processing capabilities. In its implementation, the embodiments of this application... Figure 3 Each step of the method can be accomplished through integrated logic circuits in the hardware of the processor 602 or through instructions in software form.

[0193] The processor 602 described above can also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0194] The steps of the method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory 601. The processor 602 reads the information in memory 601 and, in conjunction with its hardware, completes the functions required by the units included in the device of this application. For example, it can execute... Figure 3 The various steps / functions of the illustrated embodiment.

[0195] The communication interface 603 can use, but is not limited to, transceivers to enable communication between the device 600 and other devices or communication networks.

[0196] Bus 604 may include a pathway for transmitting information between various components of device 600 (e.g., memory 601, processor 602, communication interface 603).

[0197] It should be understood that the device 600 shown in the embodiments of this application may be an electronic device, or it may be a chip configured in an electronic device.

[0198] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.

[0199] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.

[0200] In this application, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.

[0201] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0202] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0203] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0204] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0205] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0206] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0207] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory, random access memory, magnetic disks, or optical disks.

[0208] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for generating hash values, characterized in that, Applied to the first device, including: Based on the first instance, the evidence from the first instance, and the public key of the second device, determine the publicly computed hash value; Send the first instance and the publicly computed hash value; Wherein, the first instance is equal to the sum of the first target value and the first deviation information, the first target value is equal to the product of the evidence of the first instance and the generator matrix of the binary linear [n, k] code set, the Hamming weight of the first deviation information is less than or equal to the first threshold, and the first threshold is less than the second threshold; The public key is determined based on a target Bernoulli distribution, and the probability value of the target Bernoulli distribution when the experiment is successful is equal to the ratio of the first preset parameter d to n; The values ​​of the first and second thresholds satisfy the following conditions: the probability that the public computed hash value and the private computed hash value are equal when the distance between the first instance and the nearest codeword in the [n, k] code set is less than or equal to the second preset parameter w and 2d / n is less than or equal to 1 / 2 is greater than or equal to 1. The difference, β is greater than or equal to dlog(n / d) is greater than or equal to 4k, the distance between any codeword in the [n,k] code set other than the codeword identical to the second instance in the second language and the nearest codeword in the [n,k] code set is within the interval [(1-β)*n / 2, (1+β)*n / 2], β indicates the value of β corresponding to the [n,k] code set being a β-balanced code, the second instance is equal to the sum of the second target value and the second deviation information, the second target value is equal to the product of the evidence of the second instance and the generator matrix of the [n,k] code set, and the Hamming weight of the second deviation information is less than or equal to the second threshold.

2. The method according to claim 1, characterized in that, The public key is obtained by performing an inner product operation between the generator matrix of the [n, k] code set and the private key of the second device, and the private key of the second device is determined based on the target Bernoulli distribution.

3. The method according to claim 2, characterized in that, The private key of the second device is the information obtained by the second device sampling the target Bernoulli distribution n times.

4. The method according to claim 3, characterized in that, The publicly computed hash value is obtained by performing an inner product operation on the evidence of the first instance and the public key of the second device, followed by a modulo 2 operation.

5. A method for generating hash values, characterized in that, Applied to a second device, including: Receive the first instance and the publicly computed hash value corresponding to the first instance sent by the first device; Based on the private keys of the first instance and the second device, a privacy computation hash value is determined, wherein the probability that the privacy computation hash value is equal to the public computation hash value is greater than 1 / 2; Wherein, the first instance is equal to the sum of the first target value and the first deviation information, the first target value is equal to the product of the evidence of the first instance and the generator matrix of the binary linear [n, k] code set, the Hamming weight of the first deviation information is less than or equal to the first threshold, and the first threshold is less than the second threshold; The private key is determined based on a target Bernoulli distribution, and the probability value of the target Bernoulli distribution when the experiment is successful is equal to the ratio of the first preset parameter d to n. The values ​​of the first and second thresholds satisfy the following conditions: the probability that the public computed hash value and the private computed hash value are equal when the distance between the first instance and the nearest codeword in the [n, k] code set is less than or equal to the second preset parameter w and 2d / n is less than or equal to 1 / 2 is greater than or equal to 1. The difference, β is greater than or equal to dlog(n / d) is greater than or equal to 4k, the distance between any codeword in the [n,k] code set other than the codeword identical to the second instance in the second language and the nearest codeword in the [n,k] code set is within the interval [(1-β)*n / 2, (1+β)*n / 2], β indicates the value of β corresponding to the [n,k] code set being a β-balanced code, the second instance is equal to the sum of the second target value and the second deviation information, the second target value is equal to the product of the evidence of the second instance and the generator matrix of the [n,k] code set, and the Hamming weight of the second deviation information is less than or equal to the second threshold.

6. The method according to claim 5, characterized in that, The private key of the second device is the information obtained by the second device sampling the target Bernoulli distribution n times.

7. The method according to claim 6, characterized in that, The privacy computation hash value is obtained by performing an inner product operation between the instance to be verified and the private key of the second device, followed by a modulo 2 operation.

8. The method according to claim 6 or 7, characterized in that, The method further includes: Based on the private key of the second device, the public key of the second device is determined. The public key is obtained by performing an inner product operation between the generator matrix of the [n, k] code set and the private key of the second device.

9. The method according to claim 8, characterized in that, The method further includes: Send the public key of the second device to the first device.

10. A hash proof system, characterized in that, include: The module includes an instance collection module, a first language module, a key projection module, a public computation module, and a private computation module. The instance set module contains an instance set, which is a set of binary linear [n, k] codes. The first language module includes a first language, which contains a first instance in the [n, k] code set that satisfies the following conditions: the first instance is equal to the sum of the first target value and the first deviation information, the first target value is equal to the product of the evidence of the first instance and the generator matrix of the [n, k] code set, the Hamming weight of the first deviation information is less than or equal to a first threshold, and the first threshold is less than a second threshold; The second language contains a second instance in the [n, k] code set that satisfies the following conditions: the second instance is equal to the sum of the second target value and the second deviation information, the second target value is equal to the product of the evidence of the second instance and the generator matrix of the [n, k] code set, and the Hamming weight of the second deviation information is less than or equal to the second threshold. The key projection module is used to: determine the private key and public key based on the target Bernoulli distribution, wherein the probability value of the target Bernoulli distribution when the experiment is successful is equal to the ratio of the first preset parameter d to n; The public computation module is used to: for a first instance in the first language, determine a public computation hash value based on the first instance, the evidence of the first instance, and the public key of the second device; The privacy computation module is used to: for any instance in the [n, k] code set, determine a privacy computation hash value based on the private key of the second device and the arbitrary instance; The values ​​of the first and second thresholds satisfy the following conditions: the probability that the public computed hash value and the private computed hash value are equal when the distance between the first instance and the nearest codeword in the [n, k] code set is less than or equal to the second preset parameter w and 2d / n is less than or equal to 1 / 2 is greater than or equal to 1. The difference, β is greater than or equal to dlog(n / d) is greater than or equal to 4k, and the distance between any codeword in the [n,k] code set other than the codeword identical to the second instance in the second language and the nearest codeword in the [n,k] code set lies within the interval [(1-β)*n / 2, (1+β)*n / 2], where β indicates the value of β when the [n,k] code set is a β-balanced code.

11. The system according to claim 10, characterized in that, The private key is the sampling information obtained by sampling the target Bernoulli distribution n times.

12. The system according to claim 11, characterized in that, The public key is obtained by performing an inner product operation between the generator matrix of the [n, k] code set and the private key of the second device.

13. The system according to claim 12, characterized in that, The publicly computed hash value is obtained by performing an inner product operation on the evidence of the first instance and the public key of the second device, followed by a modulo 2 operation.

14. The system according to claim 13, characterized in that, The privacy computation hash value is obtained by performing an inner product operation between the instance to be verified and the private key of the second device, followed by a modulo 2 operation.

15. A hash value generation apparatus, characterized in that, Includes a module for performing the method according to any one of claims 1 to 4.

16. A hash value generation apparatus, characterized in that, Includes a module for performing the method according to any one of claims 5 to 9.

17. A hash value generation apparatus, characterized in that, The device includes at least one processor and a memory coupled together, the processor and the memory storing program instructions that, when executed by the processor, cause the device to perform the method as claimed in any one of claims 1 to 4, or to perform the method as claimed in any one of claims 5 to 9.

18. A computer-readable storage medium, characterized in that, The computer-readable medium stores instructions for computer execution, which, when executed, cause the method as described in any one of claims 1 to 9.

19. A computer program product, the computer program product comprising computer program instructions, characterized in that, When the computer program instructions are executed on a computer, the computer causes the computer to perform the method as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Anti-quantum key negotiation method based on coding

    CN110011790A

  • Hash code generation method and device, computer equipment and storage medium

    CN113821527A