Signature generation method, signature verification method, signature processing system, and electronic device

CN117675226BActive Publication Date: 2026-09-25BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202311661889.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-05
Publication Date
2026-09-25
Estimated Expiration
2043-12-05

AI Technical Summary

Technical Problem

[0004]有鉴于此,本申请实施例的目的在于提供一种签名生成方法、签名验签方法、签名处理系统及电子设备,以改善现有技术中存在的数字签名的安全性和有效性较低的问题

Benefits of technology

[0022]第五方面,本申请实施例还提供了一种计算机可读取存储介质,所述可读取存储介质中存储有计算机程序指令,所述计算机程序指令被一处理器读取并运行时,执行上述签名生成方法和签名验签方法中任一实现方式中的步骤。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117675226B_ABST
    Figure CN117675226B_ABST
Patent Text Reader

Abstract

The application provides a signature generation method, a signature verification method, a signature processing system and electronic equipment, and relates to the technical field of cryptography. The signature generation method comprises: determining a first commitment value and a second commitment value according to an identity identifier of a signing party, a message to be signed and random data; wherein the first commitment value comprises a hash commitment value, and the second commitment value comprises a Pedersen commitment value; determining a digital signature of the signing party on the message to be signed according to the first commitment value and the second commitment value; and performing aggregation based on a plurality of digital signatures to obtain an aggregated signature. The signature verification method comprises: receiving a signed message and signature data corresponding to the signed message sent by the signing party; wherein the signature data comprises a digital signature and / or an aggregated signature; the digital signature and the aggregated signature are generated according to the signature generation method; determining the type of the corresponding signature based on the signature data, and verifying the signature.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cryptography technology, and more specifically, to a signature generation method, a signature verification method, a signature processing system, and an electronic device. Background Technology

[0002] A digital signature is a string of numbers that can only be generated by the message signer (which can be the message sender or a specially designated signer) and cannot be forged by others. It can be used for authentication, ensuring the integrity of messages, etc. Since the recipient can prove the source of the message through cryptographic techniques, the signer can also be verified based on the digital signature, thereby preventing repudiation after signing.

[0003] Currently, various general-purpose signature schemes exist, such as those based on public-key cryptography like RSA, as well as signature schemes tailored to specific needs, such as group signatures, ring signatures, blind signatures, multi-signatures, threshold signatures, and non-repudiation signatures. However, due to high computational complexity, the ability of attackers to impersonate signers and forge messages, and the difficulty in effective verification, the security of current signature schemes needs improvement. They cannot guarantee the privacy protection of the signed messages, thus failing to meet user needs. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a signature generation method, a signature verification method, a signature processing system, and an electronic device to improve the problem of low security and effectiveness of digital signatures in the prior art.

[0005] To address the aforementioned problems, in a first aspect, embodiments of this application provide a signature generation method, applied to a signatory, the method comprising: A first commitment value and a second commitment value are determined based on the identity of the signer, the message to be signed, and random data; wherein, the first commitment value includes a hash commitment value, and the second commitment value includes a Pedersen commitment value; The digital signature of the message to be signed by the signer is determined based on the first commitment value and the second commitment value. An aggregated signature is obtained by aggregating multiple digital signatures.

[0006] In the above implementation process, when generating a signature, a cryptographic commitment protocol can be used to determine the corresponding first and second commitment values ​​based on the signer's identity, the message to be signed, and random data. By using a hybrid approach of hash commitment and Pedersen commitment, two commitment values ​​related to the signer's identity and the original message are generated. The signature is then generated based on these two commitment values. Furthermore, when multiple digital signatures are available, they can be aggregated to obtain an aggregated signature. Processing based on hash commitment and Pedersen commitment involves relatively low computational cost, thus ensuring efficiency in signing and verification. Building upon this, the security of the signing process is improved by combining these two commitment schemes with information related to the signer to generate the digital signature. This effectively prevents malicious parties from forging digital signatures, enhancing the validity and security of digital signatures. Furthermore, the aggregation of multiple digital signatures further improves the efficiency of signing and verification, meeting diverse user needs and applicable to various application scenarios.

[0007] Optionally, the random data includes: a blinding factor, a broadcast value corresponding to the blinding factor, and a random number; The step of determining the first commitment value and the second commitment value based on the identity of the signer, the message to be signed, and random data includes: Determine the identity identifier of the signatory; Select the random data; Determine the signature private key and signature public key corresponding to the identity identifier; The first commitment value is calculated based on the identity identifier, the signing public key, the random number, and the message to be signed. The second commitment value is calculated based on the first commitment value and the blind factor.

[0008] In the above implementation process, when calculating the commitment value, the signer can first select the corresponding blinding factor, broadcast value, and random number as random data. Furthermore, it can determine the corresponding signing private key and signing public key based on the public-private key generation method, and then calculate the first commitment value based on the identity identifier, signing public key, random number, and message to be signed. Based on this, it continues to calculate the Pedersen commitment to the first commitment value, i.e., the second commitment value, by combining the blinding factor. This allows for the incorporation of various information related to the signer in the calculation, thereby improving the validity and security of the commitment value.

[0009] Optionally, determining the digital signature of the message to be signed by the signer based on the first commitment value and the second commitment value includes: The first signature value corresponding to the second commitment value is calculated based on the blind factor, the first commitment value, the second commitment value, and the signature private key. Based on the random number, the first commitment value, the second commitment value, and the first signature value, the digital signature of the signer on the message to be signed is determined.

[0010] In the above implementation process, when generating a digital signature, the first signature value of the second commitment value can be calculated based on the blind factor, the first commitment value, the second commitment value, and the signing private key. Then, the digital signature of the message to be signed by the signer is determined based on the random number, the first commitment value, the second commitment value, and the first signature value. This approach combines commitment values ​​from two different commitment protocols to obtain a digital signature containing various information about the signer, ensuring the non-repudiation of the digital signature, effectively avoiding the adverse situation of signature forgery, and supporting the generation of the signature without disclosing the content of the message to be signed, thus providing effective privacy protection for the original message.

[0011] Optionally, the aggregation of multiple digital signatures to obtain an aggregated signature includes: Broadcast data is determined based on the broadcast values ​​of the multiple signers corresponding to the multiple digital signatures; The aggregate commitment value is calculated based on the first commitment value and the second commitment value of each digital signature; The hash value is determined based on the aggregate commitment value; Based on the blind factor, the hash value, and the signing private key, a second signature value is obtained after each signer signs the hash value, and multiple second signature values ​​are aggregated to obtain a third signature value; The aggregate signature is determined based on the aggregate commitment value, the broadcast data, and the third signature value.

[0012] In the above implementation process, when there are multiple digital signatures corresponding to multiple signers, these multiple digital signatures can be aggregated. During aggregation, to distinguish each digital signature, the broadcast value of the signer corresponding to each digital signature is first obtained to determine the corresponding broadcast data. The first and second commitment values ​​in each digital signature are then combined to calculate the corresponding aggregate commitment value, which in turn determines the hash value corresponding to the aggregate commitment value. Based on the broadcast value, hash value, and signing private key, the second signature value is calculated after each signer signs the hash value. These multiple second signature values ​​are then aggregated to obtain the corresponding third signature value. Thus, based on the broadcast data, aggregate commitment value, and third signature value, the aggregated signature is determined. This allows multiple digital signatures to be aggregated into a single aggregated signature for processing, effectively improving the efficiency of signing and verification.

[0013] Secondly, embodiments of this application also provide a signature verification method, applied to a signature verification party, the method comprising: The system receives a signed message and corresponding signature data from the signer; wherein the signature data includes a digital signature and / or an aggregate signature; the digital signature and the aggregate signature are generated according to any one of the above signature generation methods. The type of the signature is determined based on the signature data, and the signature is verified.

[0014] In the above implementation process, during data transmission, the verifying party can receive the signed message sent by the signing party, along with the corresponding signature data. Due to the diversity of signature data, the signature type can be determined to verify the signature accordingly. Identity verification can be performed based on the received signature to ensure its non-repudiation and effectively prevent the unfavorable situation where a forged signature passes verification.

[0015] Optionally, the type of the signature includes the digital signature; The verification of the signature includes: Verify the range of values ​​for the second commitment value in the digital signature; If the range of the second commitment value is verified, then the range of the first signature value in the digital signature is verified. If the range of the first signature value is verified, then a first verification commitment value is obtained by calculating based on the signed message and the random number in the digital signature; If the first verification commitment value is the same as the first commitment value in the digital signature, then the validity of the first signature value is verified based on the broadcast value corresponding to the blind factor, the first commitment value, the second commitment value, and the signature public key. If the first signature value is verified to be valid, then the digital signature is valid.

[0016] In the above implementation process, when the received signature is a digital signature, during verification, the validity of the range of the second commitment value is first verified. If the verification is successful, the validity of the range of the first signature value is then verified. If this verification is successful, the corresponding first verification commitment value is calculated and compared with the first commitment value to verify the integrity of the signed message and the identity of the signer. After the first commitment value is successfully verified, the validity of the first signature value itself is verified based on various data. If the first signature value is also successfully verified, the digital signature has passed multiple rounds of progressive verification, indicating that the digital signature is a valid and legal signature, i.e., the digital signature has passed verification. This allows for setting up a multi-round progressive verification method, confirming the signer's identity based on the signer's identity identifier, signing public key, random number, and hash commitment scheme. This enables simultaneous signature verification and authentication of the signer, ensuring the non-repudiation of the signing behavior and guaranteeing the validity and accuracy of the verification. Furthermore, during signature verification, the message sender / signer can provide only the hash value of the signed message, thus protecting the privacy of the signed message.

[0017] Optionally, the type of the signature includes the aggregate signature; The verification of the signature includes: Verify the value range of broadcast data in the aggregate signature; If the value range of the broadcast data passes the verification, then the value range of the aggregate commitment value in the aggregate signature is verified. If the range of the aggregate commitment value is verified, then a verification hash value is calculated based on the aggregate commitment value; Verify the validity of the third signature value in the aggregated signature based on the broadcast data and the verification hash value; If the third signature value is verified to be valid, then the aggregate signature is valid.

[0018] In the above implementation process, when the received signature is an aggregate signature, verification only requires one verification of the aggregate signature itself, which is sufficient to verify multiple digital signatures contained within it. First, the validity of the value range of the broadcast data in the aggregate signature is verified. After successful verification, the validity of the value range of the aggregate commitment value is verified. After successful verification, the corresponding verification hash value is calculated. Based on the hash value and the broadcast data, the validity of the third signature value is verified. After the third signature value is also successfully verified, the aggregate signature has passed multiple rounds of progressive verification, indicating that the aggregate signature is a valid and legal signature. That is, the aggregate signature passes verification, and it shows that the digital signature of each signed message is valid and legal. The ability to set up a multi-round progressive verification method ensures the validity and accuracy of the verification. Verifying only the aggregate signature is sufficient to verify the signature of each signed message, effectively improving the efficiency of the verification process. Furthermore, during signature verification, the message sender / signer can provide only the hash value of the signed message, thus protecting the privacy of the signed message.

[0019] Thirdly, embodiments of this application also provide a signature processing system, which includes a signer and a verifier; The signer is configured to: determine a first commitment value and a second commitment value based on the signer's identity, the message to be signed, and random data; wherein the first commitment value includes a hash commitment value, and the second commitment value includes a Pedersen commitment value; determine the signer's digital signature on the message to be signed based on the first commitment value and the second commitment value; and aggregate multiple digital signatures to obtain an aggregated signature; The signature verifier is configured to: receive a signed message and corresponding signature data sent by the signer; wherein the signature data includes a digital signature and / or an aggregate signature; determine the type of the corresponding signature based on the signature data, and verify the signature.

[0020] In the above implementation process, each user terminal can act as either a signer or a verifier. As a signer, it can generate a digital signature by combining various information related to itself with hash and Pedersen commitments. This computational complexity is relatively low, ensuring efficiency in both signing and verification. Furthermore, the security of the signing process is enhanced by applying these two commitment schemes in combination, effectively preventing malicious parties from forging digital signatures. As a verifier, it can verify the signer's identity based on the received signature data, thus solving the identity authentication problem while verifying the signature and ensuring the non-repudiation of the signing behavior. Moreover, it can aggregate and verify multiple digital signatures, effectively improving the efficiency of both signing and verification.

[0021] Fourthly, embodiments of this application also provide an electronic device, which includes a memory and a processor. The memory stores program instructions, and when the processor reads and runs the program instructions, it executes the steps in any of the above-described implementations of the signature generation method and signature verification method.

[0022] Fifthly, embodiments of this application also provide a computer-readable storage medium storing computer program instructions, which, when read and executed by a processor, perform steps in any of the above-described implementations of the signature generation method and signature verification method.

[0023] In summary, the purpose of this application is to provide a signature generation method, a signature verification method, a signature processing system, and an electronic device that can generate corresponding digital signatures and aggregate signatures by combining various information related to the signer with hash commitments and Pedersen commitments, and simultaneously authenticate the signer's identity during signature verification, thereby effectively improving the validity and security of digital signatures and signature verification, as well as the efficiency of signing and verification. Attached Figure Description

[0024] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 A block diagram illustrating an electronic device provided in an embodiment of this application; Figure 2 A flowchart illustrating a signature generation method provided in an embodiment of this application; Figure 3 A detailed flowchart of step S200 provided for an embodiment of this application; Figure 4 A detailed flowchart of step S300 provided for an embodiment of this application; Figure 5 A detailed flowchart of step S400 provided for an embodiment of this application; Figure 6 A flowchart illustrating a signature verification method provided in an embodiment of this application; Figure 7 A detailed flowchart of the first step S600 provided for an embodiment of this application; Figure 8A detailed flowchart illustrating the second step S600 provided in this application embodiment; Figure 9 This is a schematic diagram of the structure of a signature processing system provided in an embodiment of this application.

[0026] Icons: 100 - Electronic device; 111 - Memory; 112 - Memory controller; 113 - Processor; 114 - Peripheral interface; 115 - Input / output unit; 116 - Display unit; 700 - Signature processing system; 710 - Signer; 720 - Verifier. Detailed Implementation

[0027] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of the embodiments of this application.

[0028] Currently, various general-purpose signature schemes exist, such as those based on public-key cryptography like RSA, as well as signature schemes tailored to specific needs, such as group signatures, ring signatures, blind signatures, multi-signatures, threshold signatures, and non-repudiation signatures. However, current signature verification methods are susceptible to attackers impersonating the signer and forging signatures. Furthermore, verifying the signature cannot verify the signer's identity, leading to computational complexity and verification difficulties during both signing and verification processes. Consequently, the security of current signature schemes needs improvement, and they cannot guarantee the privacy protection of signed messages, thus failing to meet user needs.

[0029] To address the aforementioned issues, this application provides a signature generation method and a signature verification method, applicable to electronic devices such as servers, personal computers (PCs), tablets, smartphones, and personal digital assistants (PDAs) with logical computing capabilities. These methods can generate digital signatures based on hash commitments and Pedersen commitments, and support signature authentication and aggregate signature generation and verification. This approach improves the security of digital signatures while ensuring signing and verification efficiency, making it suitable for various application scenarios.

[0030] It should be noted that the identity of the electronic device corresponding to the user terminal can be determined and changed based on the actual situation. The user terminal can act as the signer or the verifier.

[0031] Optionally, please refer to Figure 1 , Figure 1 This is a block diagram illustrating an electronic device according to an embodiment of this application. The electronic device 100 may include a memory 111, a memory controller 112, a processor 113, a peripheral interface 114, an input / output unit 115, and a display unit 116. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the electronic device 100. For example, the electronic device 100 may also include components that are more... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0032] The aforementioned memory 111, memory controller 112, processor 113, peripheral interface 114, input / output unit 115, and display unit 116 are electrically connected directly or indirectly to each other to achieve data transmission or interaction. For example, these components can be electrically connected to each other through one or more communication buses or signal lines. The aforementioned processor 113 is used to execute executable modules stored in the memory.

[0033] The memory 111 can be, but is not limited to, Random Access Memory (RAM), Read Only Memory (ROM), Programmable Read-Only Memory (PROM), Erasable Programmable Read-Only Memory (EPROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), etc. The memory 111 stores programs. After receiving execution instructions, the processor 113 executes the programs. The methods executed by the electronic device 100 as defined in any embodiment of this application can be applied to the processor 113, or implemented by the processor 113.

[0034] The aforementioned processor 113 may be an integrated circuit chip with signal processing capabilities. The processor 113 may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a digital signal processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor.

[0035] The peripheral interface 114 described above couples various input / output devices to the processor 113 and the memory 111. In some embodiments, the peripheral interface 114, the processor 113, and the memory controller 112 can be implemented on a single chip. In other instances, they can be implemented on separate chips.

[0036] The input / output unit 115 described above is used to provide user input data. The input / output unit 115 can be, but is not limited to, a mouse and a keyboard.

[0037] The aforementioned display unit 116 provides an interactive interface (e.g., a user interface) between the electronic device 100 and the user, or displays image data for the user's reference. In this embodiment, the display unit can be a liquid crystal display (LCD) or a touch display. If it is a touch display, it can be a capacitive touchscreen or a resistive touchscreen that supports single-point and multi-point touch operations. Supporting single-point and multi-point touch operations means that the touch display can sense touch operations generated simultaneously from one or more locations on the touch display and pass the sensed touch operations to the processor for calculation and processing. In this embodiment, the display unit 116 can display various information such as generated digital signatures, aggregated signatures, and verification results of digital signatures and aggregated signatures.

[0038] The electronic device in this embodiment can be used to execute the various steps in the signature generation and signature verification methods provided in the embodiments of this application. The implementation process of the signature generation and signature verification methods is described in detail below through several embodiments.

[0039] Please see Figure 2 , Figure 2This is a flowchart illustrating a signature generation method provided in an embodiment of this application. The method may include steps S200-S400.

[0040] Step S200: Determine the first commitment value and the second commitment value based on the signer's identity, the message to be signed, and random data.

[0041] The first commitment value can include a hash commitment value, and the second commitment value can include a Pedersen commitment value. When generating a signature, a cryptographic commitment protocol can be used to determine the corresponding first and second commitment values ​​based on the signer's identity, the message to be signed, and random data. This allows for a mixed use of hash and commitment values ​​to generate two commitment values ​​regarding the signer's identity and the original message. The first commitment value can be denoted as... The second commitment value is recorded as .

[0042] Optionally, a cryptographic commitment is a two-phase interaction protocol involving a promisor and a receiver. It allows the promisor to hide a value / message in a certain way to prevent other parties from obtaining its original value or message, while the promisor can reveal the value or message if necessary to verify the validity of the commitment. A hash commitment allows one party to prove they know a value without revealing the plaintext information, while preventing others from knowing this value, thus ensuring data confidentiality and integrity. A Pedersen commitment is a homomorphic commitment protocol that satisfies computational binding and perfect hiding.

[0043] Step S300: Determine the digital signature of the message to be signed by the signer based on the first commitment value and the second commitment value.

[0044] This can be achieved by signing based on two commitment values, resulting in the digital signature of the message to be signed by the signer. The message to be signed can be denoted as... The corresponding digital signature can then be recorded as .

[0045] Step S400: Aggregate multiple digital signatures to obtain an aggregated signature.

[0046] When multiple digital signatures are present, they can be aggregated to obtain a corresponding aggregated signature. The digital signature can be denoted as... .

[0047] exist Figure 2In the illustrated embodiment, processing can be performed based on hash commitments and Pedersen commitments, which requires less computation and thus ensures the efficiency of signing and verification. On this basis, by combining these two commitment schemes and generating digital signatures with information related to the signer, it is possible to effectively prevent malicious parties from forging digital signatures, thereby improving the validity and security of digital signatures. Furthermore, by aggregating multiple digital signatures to obtain the corresponding digital signature, the processing efficiency of signing and verification is further improved, meeting various user needs and applicable to a variety of different application scenarios.

[0048] Optionally, please refer to Figure 3 , Figure 3 The following is a detailed flowchart of step S200 provided in an embodiment of this application. Step S200 may include steps S210-S250.

[0049] Step S210: Determine the identity of the signatory.

[0050] To distinguish between multiple signatories, information such as an identity ID can be obtained as a unique identifier for each signer, denoted as [identity ID]. .

[0051] Step S220: Select random data.

[0052] Among these, the order can be chosen to be a large prime number. Given a multiplicative cyclic group G, whose two generators are g and h, and an ideal hash function is chosen. Use identity tokens Randomly select the corresponding random data. The random data may include: the blinding factor, the broadcast value corresponding to the blinding factor, and a random number.

[0053] Optionally, the blinding factor is denoted as , The public key corresponding to the blinding factor, i.e., the broadcast value, is denoted as... And select the corresponding random number. , .

[0054] Optionally, each signer may choose a different blinding factor to distinguish between multiple signers.

[0055] Step S230: Determine the signing private key and signing public key corresponding to the identity identifier.

[0056] Specifically, based on the identity identifier, combined with the elliptic curve and the selected base point, the corresponding signing private key and signing public key can be determined, and the signing private key is denoted as... Record the signing public key as .

[0057] Step S240: Calculate the first commitment value based on the identity identifier, signing public key, random number, and message to be signed.

[0058] The first commitment value of the hash commitment can be calculated based on the identity identifier, the signing public key, the random number, and the message to be signed.

[0059] Optionally, the first commitment value can be denoted as , .

[0060] Step S250: Calculate the second commitment value based on the first commitment value and the blind factor.

[0061] Based on this, the Pedersen commitment, which is the first commitment value, is calculated by combining the blind factor and used as the second commitment value.

[0062] Optionally, the second commitment value can be denoted as , .

[0063] It should be noted that if the calculated second commitment value If so, a new random number can be selected as the blind factor, and the second commitment value can be recalculated.

[0064] exist Figure 3 In the illustrated embodiment, the two commitment protocols, hash commitment and Pedersen commitment, can be combined with various information related to the signer to calculate the two commitment values ​​separately, thereby improving the accuracy and effectiveness of the two commitment values ​​and thus improving the effectiveness of the digital signature generated based on the two commitment values.

[0065] Optionally, please refer to Figure 4 , Figure 4 This is a detailed flowchart of step S300 provided in an embodiment of the present application. Step S300 may include steps S310-S320.

[0066] Step S310: Calculate the first signature value corresponding to the second commitment value based on the blind factor, the first commitment value, the second commitment value, and the signature private key.

[0067] When generating a digital signature, the first signature value for the second commitment value can be calculated based on the blind factor, the first commitment value, the second commitment value, and the signing private key.

[0068] Optionally, the first signature value can be denoted as , If the calculated first signature value Then, a new random number can be selected as the blind factor, and the first signature value can be recalculated.

[0069] Step S320: Based on the random number, the first commitment value, the second commitment value, and the first signature value, determine the digital signature of the message to be signed by the signer.

[0070] The digital signature of the message to be signed by the signer can be determined based on a random number, a first commitment value, a second commitment value, and a first signature value.

[0071] Optionally, digital signature .

[0072] It should be noted that, in practical applications, since cryptographic commitment schemes such as Pedersen commitments are already used in blockchains, the signature generation method provided in this application can be used in blockchains. When generating a digital signature, an elliptic curve-based Pedersen commitment scheme can be used. In addition to the base point G of the elliptic curve used by the blockchain, another point H on the elliptic curve is selected, and an ideal hash function is chosen. ,in It is a large prime number. Information such as DID is used as the user's identifier. The process of a user generating a digital signature is as follows: User Randomly select blinding factor , Then the public key corresponding to the blinding factor, i.e., the broadcast value. And select the corresponding random number. , ;user Select random number As a private key for signing The corresponding signature public key is ;use This refers to user-generated transaction data, i.e., messages to be signed. First, the first commitment value is calculated. (Transaction data in a blockchain generally does not need to be kept confidential; therefore, as an optional implementation, the transaction data itself can be used directly in the calculation instead of its hash value.) The symbol "||" represents concatenation, and then further calculations are performed. The Pedersen commitment, as the second commitment value ; Calculate the value of the second commitment First signature value , The final blockchain users Transaction data The digital signature is: .

[0073] exist Figure 4In the illustrated embodiment, the commitment values ​​of two different commitment protocols can be combined for processing to obtain a digital signature containing multiple information about the signer, ensuring the non-repudiation of the digital signature, effectively avoiding the adverse situation of signature forgery, and supporting the generation of the signature without disclosing the content of the message to be signed, thus providing effective privacy protection for the original message.

[0074] Optionally, please refer to Figure 5 , Figure 5 The following is a detailed flowchart of step S400 provided in an embodiment of this application. Step S400 may include steps S410-S450.

[0075] Step S410: Determine broadcast data based on the broadcast values ​​of the multiple signers corresponding to the multiple digital signatures.

[0076] In cases where there are multiple digital signatures corresponding to multiple signers, these digital signatures can be aggregated. During aggregation, the broadcast value of the signer corresponding to each digital signature can be obtained first to determine the corresponding broadcast data.

[0077] It should be noted that if there are n signatures that need to be aggregated, each user can use the signature verification method provided in this application to verify the validity of the value range of each digital signature after receiving the digital signatures sent by other users. After the verification is successful, the aggregation process is performed based on the multiple digital signatures.

[0078] Alternatively, broadcast data can be denoted as , .

[0079] Step S420: Calculate the aggregate commitment value based on the first and second commitment values ​​of each digital signature.

[0080] Step S430: Determine the hash value based on the aggregate commitment value.

[0081] Specifically, the corresponding aggregate commitment value can be calculated by combining the first and second commitment values ​​in each digital signature, thereby determining the hash value corresponding to the aggregate commitment value.

[0082] Optionally, to generate an aggregated signature, the commitment values ​​in each user's digital signature need to be aggregated, and the resulting aggregated commitment value can be denoted as... , The corresponding hash value can be denoted as , .

[0083] Step S440: Calculate the second signature value after each signer signs the hash value based on the blind factor, hash value and signing private key, and aggregate multiple second signature values ​​to obtain the third signature value.

[0084] Specifically, the second signature value can be calculated based on the blind factor, hash value, and signing private key, after each signer signs the hash value, and multiple second signature values ​​can be aggregated to obtain the corresponding third signature value.

[0085] Optionally, each signer can separately process the hash value. The second signature value obtained is recorded as follows: , Multiple second signature values ​​can be assigned by a designated signer or the last signer to do so. The aggregation yields a third signature value, which can be denoted as... , .

[0086] Step S450: Determine the aggregate signature based on the aggregate commitment value, broadcast data, and third signature value.

[0087] Specifically, the aggregated signature can be determined based on broadcast data, the aggregated commitment value, and the third signature value, after aggregating multiple digital signatures. Optionally, the final aggregated signature... .

[0088] It's important to note that in blockchain applications, sometimes it's necessary to package all transaction signatures in a block into a single signature to simultaneously verify the correctness of all transaction signatures. For example, scenarios like "using rollups to batch-package non-standard blockchain transactions (such as transactions from certain sidechains) and publish them to the underlying blockchain's blocks" can be used. In such cases, the signatures of the batch-packaged transactions can be aggregated. To achieve this, a node can be designed to verify and batch-package non-standard blockchain transactions. This node is also responsible for generating the aggregated signatures for these non-standard blockchain transactions. When generating the aggregated signature, the identity of the node generating the aggregated signature can be denoted as... It can extract digital signatures from non-standard blockchain transaction data that needs to be packaged. Assuming there are n such transaction data, the specific process of aggregate signature is as follows: The aggregate signature generation node calculates the aggregate commitment value. And further calculation Aggregate signature generation node pairs Perform a signature to obtain a third signature value. ; final aggregate signature Among them, the broadcast value of the aggregate signature generation node. = .

[0089] exist Figure 5 In the illustrated embodiment, multiple digital signatures can be aggregated into a single aggregate signature, thereby effectively improving the efficiency of signing and verifying signatures.

[0090] Please see Figure 6 , Figure 6 This is a flowchart illustrating a signature verification method provided in an embodiment of this application. The method may include steps S500-S600.

[0091] Step S500: Receive the signed message and the signature data corresponding to the signed message sent by the signer.

[0092] During data transmission, the verifier can receive the signed message sent by the signer, as well as the signature data corresponding to the signed message.

[0093] It should be noted that signature data may include digital signatures and / or aggregate signatures.

[0094] Step S600: Determine the type of the corresponding signature based on the signature data, and verify the signature.

[0095] In particular, due to the diversity of signature data, the signature type of the signature data can be determined so that the signature can be verified accordingly.

[0096] For example, when the received signature data is a digital signature, the verifier can verify the legality (i.e., the validity of the value range) of multiple digital signatures in order to perform signature aggregation processing after verification; when the received signature data is an aggregated signature, the verifier only needs to verify the aggregated signature to complete the verification of all digital signatures.

[0097] exist Figure 6 In the illustrated embodiment, verification can be performed based on the received signature to ensure the non-repudiation of the signature and effectively avoid the adverse situation where a forged signature passes verification.

[0098] Optionally, please refer to Figure 7 , Figure 7 The following is a detailed flowchart of the first step S600 provided in the embodiments of this application. Step S600 may include steps S611-S615.

[0099] Step S611: Verify the range of values ​​for the second commitment value in the digital signature.

[0100] When the received signature includes a digital signature, during verification, the validity of the range of values ​​for the second commitment value in the digital signature is first verified to confirm whether the range of values ​​for the second commitment value is valid.

[0101] Optionally, after the verifier receives the signed message from the signer... and digital signatures At that time, you can first... Whether it holds true will be verified to validate the second commitment value. Is the range of values ​​valid? Second commitment value. If the value range is invalid, the signature verification will fail.

[0102] Step S612: If the range of the second commitment value is verified, then the range of the first signature value in the digital signature is verified.

[0103] After the range of the second commitment value is verified, the validity of the range of the first signature value is then verified to confirm whether the range of the first signature value is valid.

[0104] Optionally, one can continue to [do something]. Verification is performed to determine whether the first signature value is valid. The validity of the range of values ​​is verified. First signature value. If the value range is invalid, the signature verification will fail.

[0105] Step S613: If the range of the first signature value is verified, the first verification commitment value is obtained by calculating based on the random number in the signed message and the digital signature.

[0106] After the first signature value passes the verification within its range, the corresponding first verification commitment value is calculated and compared with the first commitment value to verify the integrity of the signed message and the identity of the signer.

[0107] Alternatively, random numbers can be used. and signed messages Calculate the first verification commitment value , and to The system verifies whether the signature is valid. If it is invalid, the verification fails. If it is valid, it indicates that the digital signature was indeed created by the user. This is generated, thereby enabling authentication of the signer.

[0108] Step S614: If the first verification commitment value is the same as the first commitment value in the digital signature, then verify the validity of the first signature value based on the broadcast value corresponding to the blind factor, the first commitment value, the second commitment value, and the signature public key.

[0109] After the first commitment value is successfully verified, the validity of the first signature value itself is further verified based on various data.

[0110] Optionally, it can be As the private key, calculate its corresponding public key according to the public key generation rules. In order to The verification process checks whether the signature is valid; if it is invalid, the signature verification fails.

[0111] Step S615: If the first signature value is verified to be valid, then the digital signature is valid.

[0112] Once the first signature value is also successfully verified, the digital signature has passed multiple rounds of progressive verification, indicating that the digital signature is a legitimate and valid signature, that is, the digital signature has passed verification.

[0113] It should be noted that in real-world use cases, other blockchain users, i.e., the signature verifiers... ( ) Received from user Broadcast transaction data And extract the digital signature. Then, the hash value of the transaction is calculated. This is to verify the legality and validity of digital signatures. Verification may include: using... and calculate , and verify Whether it is true or not; as an optional implementation method, it can also be verified. Whether it is true; final verification Is it valid? If all the above verifications pass, then the digital signature is a legitimate and valid signature.

[0114] exist Figure 7 In the illustrated embodiment, a multi-round progressive signature verification method can be set up to confirm the signer's identity based on the signer's identity identifier, signing public key, random number, and hash commitment scheme. This allows for simultaneous signature verification and signature authentication, ensuring the non-repudiation of the signing behavior and guaranteeing the validity and accuracy of the verification. Furthermore, during signature verification, the signer can provide only the hash value of the signed message, thus protecting the privacy of the signed message.

[0115] Optionally, please refer to Figure 8 , Figure 8 The following is a detailed flowchart of the second step S600 provided in the embodiments of this application. Step S600 may include steps S621-S625.

[0116] Step S621: Verify the value range of the broadcast data in the aggregate signature.

[0117] When the received signature includes an aggregate signature, verification only needs to be performed on the aggregate signature once, which is sufficient to verify multiple digital signatures. First, the validity of the value range of the broadcast data in the aggregate signature is verified.

[0118] Optionally, after the verifier receives the aggregated signature from the signer... At that time, you can first... The validity of the data needs to be verified to confirm the broadcast data. The validity of the range of values ​​is checked. If the range is invalid, the validation fails.

[0119] Step S622: If the value range verification of the broadcast data passes, then the value range of the aggregate commitment value in the aggregate signature is verified.

[0120] After the validity of the range of values ​​for broadcast data is verified, the validity of the range of values ​​for aggregate commitment values ​​can be verified.

[0121] Optionally, one can continue to [do something]. Whether it holds true is verified to validate the aggregate commitment value. The validity of the range of values ​​is checked. If the range is invalid, the validation fails.

[0122] Step S623: If the range of values ​​of the aggregate commitment value is verified, then the verification hash value is calculated based on the aggregate commitment value.

[0123] Step S624: Verify the validity of the third signature value in the aggregate signature based on the broadcast data and the verification hash value.

[0124] After the validity of the range of values ​​of the aggregate commitment value is verified, the corresponding verification hash value can be calculated to verify the validity of the third signature value based on the hash value and the broadcast data.

[0125] Optionally, the signatory can calculate the hash value. , The third signature value can be... As the private key, calculate the corresponding public key. Then verify The verification process checks whether the signature is valid; if it is invalid, the signature verification fails.

[0126] Step S625: If the third signature value is verified to be valid, then the aggregate signature is valid.

[0127] Once the third signature value is also verified, the aggregate signature has passed multiple rounds of progressive verification, indicating that the aggregate signature is a legitimate and valid signature. In other words, the aggregate signature has passed verification, and it shows that the signature of each signed message is legitimate and valid.

[0128] It should be noted that in practical use cases, after a blockchain node receives the aggregated signature, the verification methods can include: calculation... ;verify The system checks whether the aggregate signature is valid. If it is valid, it proves that the aggregate signature is a legitimate and valid signature. If the aggregate signature is legitimate and valid, it means that the signature information of each transaction data in the batch-packaged non-standard blockchain transactions is legitimate and valid. Therefore, blockchain network nodes only need to verify the aggregate signature to verify the signature of each transaction data in the batch-packaged non-standard blockchain transactions.

[0129] exist Figure 8 In the illustrated embodiment, a multi-round progressive signature verification method can be set up to verify the validity of the aggregate signature based on the signer's broadcast data, aggregate commitment value, etc., ensuring the validity and accuracy of the signature verification. Only the aggregate signature needs to be verified to achieve signature verification for each signed message, effectively improving the efficiency of signature verification. Furthermore, during signature verification, the signer can provide only the hash value of the signed message, thereby protecting the privacy of the signed message.

[0130] Among the various signature verification methods mentioned above, when verifying a signature, the signer can provide only the hash value of the original message, thus protecting the privacy of the original message. When necessary, such as when the original message does not need to be kept confidential, the signer can also provide the original message for signature verification.

[0131] Please see Figure 9 , Figure 9 This is a schematic diagram of the structure of a signature processing system provided in an embodiment of this application. The signature processing system 700 may include a signer 710 and a verifier 720; multiple signers 710 may be connected to multiple verifiers 720 through networks or other means.

[0132] The signer 710 is used to: determine a first commitment value and a second commitment value based on the signer 710's identity, the message to be signed, and random data; wherein the first commitment value includes a hash commitment value and the second commitment value includes a Pedersen commitment value; determine the digital signature of the message to be signed by the signer 710 based on the first commitment value and the second commitment value; and aggregate multiple digital signatures to obtain an aggregated signature; The signer 720 is used to: receive a signed message and corresponding signature data sent by the signer 710; wherein the signature data includes a digital signature and / or an aggregate signature; determine the type of the corresponding signature based on the signature data, and verify the signature.

[0133] In an optional implementation, the random data includes: a blind factor, a broadcast value corresponding to the blind factor, and a random number; the signer 710 is specifically used to: determine the identity identifier of the signer 710; select random data; determine the signing private key and signing public key corresponding to the identity identifier; calculate a first commitment value based on the identity identifier, the signing public key, the random number, and the message to be signed; and calculate a second commitment value based on the first commitment value and the blind factor.

[0134] In an optional implementation, the signer 710 is specifically configured to: calculate a first signature value corresponding to the second commitment value based on the blind factor, the first commitment value, the second commitment value, and the signing private key; and determine the digital signature of the message to be signed by the signer 710 based on the random number, the first commitment value, the second commitment value, and the first signature value.

[0135] In an optional implementation, the signer 710 is specifically configured to: determine broadcast data based on the broadcast values ​​of the multiple signers 710 corresponding to the multiple digital signatures; calculate an aggregated commitment value based on the first commitment value and the second commitment value of each digital signature; determine a hash value based on the aggregated commitment value; calculate a second signature value after each signer 710 signs the hash value based on the blind factor, the hash value, and the signing private key, and aggregate multiple second signature values ​​to obtain a third signature value; and determine an aggregated signature based on the aggregated commitment value, the broadcast data, and the third signature value.

[0136] In an optional implementation, the signature type includes a digital signature; the verifier 720 is specifically configured to: verify the range of values ​​for the second commitment value in the digital signature; if the range of values ​​for the second commitment value is verified, then verify the range of values ​​for the first signature value in the digital signature; if the range of values ​​for the first signature value is verified, then calculate a first verification commitment value based on the signed message and the random number in the digital signature; if the first verification commitment value is the same as the first commitment value in the digital signature, then verify the validity of the first signature value based on the broadcast value corresponding to the blind factor, the first commitment value, the second commitment value, and the signature public key; if the first signature value is verified to be valid, then the digital signature is valid.

[0137] In an optional implementation, the signature type includes an aggregate signature; the signature verifier 720 is specifically configured to: verify the value range of the broadcast data in the aggregate signature; if the value range of the broadcast data is verified, then verify the value range of the aggregate commitment value in the aggregate signature; if the value range of the aggregate commitment value is verified, then calculate a verification hash value based on the aggregate commitment value; verify the validity of the third signature value in the aggregate signature according to the broadcast data and the verification hash value; if the third signature value is verified to be valid, then the aggregate signature is valid.

[0138] Since the principle of the signature processing system 700 in this embodiment is similar to that of the aforementioned signature generation method and signature verification method, the implementation of the signature processing system 700 in this embodiment can refer to the description in the above-mentioned signature generation method and signature verification method embodiments, and the repeated parts will not be described again.

[0139] This application also provides a computer-readable storage medium storing computer program instructions. When the computer program instructions are read and executed by a processor, they perform the steps of any one of the signature generation method and signature verification method provided in this embodiment.

[0140] In the several embodiments provided in this application, it should be understood that the disclosed device can also be implemented in other ways. The device embodiments described above are merely illustrative; for example, the block diagrams in the accompanying drawings illustrate the possible architecture, functions, and operations of the device according to various embodiments of this application. In this regard, each block in the block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagram, and combinations of block diagrams, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0141] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0142] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0143] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0144] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.

[0145] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A signature generation method, characterized in that, Applied to the signing party, the method includes: A first commitment value and a second commitment value are determined based on the identity of the signer, the message to be signed, and random data; wherein, the first commitment value includes a hash commitment value, and the second commitment value includes a Pedersen commitment value; The digital signature of the message to be signed by the signer is determined based on the first commitment value and the second commitment value. An aggregated signature is obtained by aggregating multiple digital signatures. The random data includes: a blind factor, a broadcast value corresponding to the blind factor, and a random number; determining the first commitment value and the second commitment value based on the signer's identity, the message to be signed, and the random data includes: determining the signer's identity; selecting the random data; determining the signing private key and signing public key corresponding to the identity; calculating the first commitment value based on the identity, the signing public key, the random number, and the message to be signed; and calculating the second commitment value based on the first commitment value and the blind factor.

2. The method according to claim 1, characterized in that, Determining the digital signature of the message to be signed by the signer based on the first commitment value and the second commitment value includes: The first signature value corresponding to the second commitment value is calculated based on the blind factor, the first commitment value, the second commitment value, and the signature private key. Based on the random number, the first commitment value, the second commitment value, and the first signature value, the digital signature of the signer on the message to be signed is determined.

3. The method according to claim 1, characterized in that, The aggregation of multiple digital signatures to obtain an aggregated signature includes: Broadcast data is determined based on the broadcast values ​​of the multiple signers corresponding to the multiple digital signatures; The aggregate commitment value is calculated based on the first commitment value and the second commitment value of each digital signature; The hash value is determined based on the aggregate commitment value; Based on the blind factor, the hash value, and the signing private key, a second signature value is obtained after each signer signs the hash value, and multiple second signature values ​​are aggregated to obtain a third signature value; The aggregate signature is determined based on the aggregate commitment value, the broadcast data, and the third signature value.

4. A signature verification method, characterized in that, Applied to the verification party, the method includes: The system receives a signed message and corresponding signature data from a signer; wherein the signature data includes a digital signature and / or an aggregate signature; the digital signature and the aggregate signature are generated according to any one of claims 1-3. The type of the signature is determined based on the signature data, and the signature is verified.

5. The method according to claim 4, characterized in that, in, The type of signature includes the digital signature; The verification of the signature includes: Verify the range of values ​​for the second commitment value in the digital signature; If the range of the second commitment value is verified, then the range of the first signature value in the digital signature is verified. If the range of the first signature value is verified, then a first verification commitment value is obtained by calculating based on the signed message and the random number in the digital signature; If the first verification commitment value is the same as the first commitment value in the digital signature, then the validity of the first signature value is verified based on the broadcast value corresponding to the blind factor, the first commitment value, the second commitment value, and the signature public key. If the first signature value is verified to be valid, then the digital signature is valid.

6. The method according to claim 4, characterized in that, in, The type of signature includes the aggregated signature; The verification of the signature includes: Verify the value range of broadcast data in the aggregate signature; If the value range of the broadcast data passes the verification, then the value range of the aggregate commitment value in the aggregate signature is verified. If the range of the aggregate commitment value is verified, then a verification hash value is calculated based on the aggregate commitment value; Verify the validity of the third signature value in the aggregated signature based on the broadcast data and the verification hash value; If the third signature value is verified to be valid, then the aggregate signature is valid.

7. A signature processing system, characterized in that, The signature processing system includes a signer and a verifier; The signer is configured to: determine a first commitment value and a second commitment value based on the signer's identity, the message to be signed, and random data; wherein the first commitment value includes a hash commitment value, and the second commitment value includes a Pedersen commitment value; determine the signer's digital signature on the message to be signed based on the first commitment value and the second commitment value; and aggregate multiple digital signatures to obtain an aggregated signature; The random data includes: a blind factor, a broadcast value corresponding to the blind factor, and a random number; the signer is specifically used to: determine the signer's identity identifier; select the random data; determine the signing private key and signing public key corresponding to the identity identifier; calculate the first commitment value based on the identity identifier, the signing public key, the random number, and the message to be signed; and calculate the second commitment value based on the first commitment value and the blind factor. The signature verifier is configured to: receive a signed message and corresponding signature data sent by the signer; wherein the signature data includes a digital signature and / or an aggregate signature; determine the type of the corresponding signature based on the signature data, and verify the signature.

8. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores program instructions, and when the processor executes the program instructions, it performs the steps of the method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The readable storage medium stores computer program instructions, which, when executed by a processor, perform the steps of the method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Signature method, signature system and related equipment in blockchain system

    CN110719172A

  • Data integrity rapid test method based on block chain

    CN111597590A

  • Block chain-based digital twin construction method and device, storage medium and electronic equipment

    CN115766082A