A collaborative signature method, device and equipment applied to a collaborative signature system

By generating and blinding the signature in the collaborative signature system, the service device cannot obtain the signature content of the user device, which solves the problem of reduced information security caused by the service device obtaining the signature information and improves the information security of the user device.

CN118802168BActive Publication Date: 2025-10-21CHINA UNIONPAY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411148804.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-20
Publication Date
2025-10-21
Estimated Expiration
2044-08-20

AI Technical Summary

Technical Problem

During the collaborative signing process, the service device obtains part of the signature information, which reduces the information security of the user device.

Method used

The service device aggregates the first intermediate values ​​of other user devices to generate intermediate parameters and auxiliary parameters. The mth user device generates a first signature based on these parameters and performs blinding processing. The service device generates a second intermediate value based on the blinded first signature. The mth user device then generates the second signature in the collaborative signature based on the second intermediate value of the service device, ensuring that the service device cannot obtain the true signature content of the user device.

Benefits of technology

This improves the information security of user devices and prevents service devices from inferring private information of user devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802168B_ABST
    Figure CN118802168B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a kind of applied to collaborative signature system collaborative signature method, device and equipment, it is related to information security field.The method comprises: determining the first intermediate value of the mth user equipment;And receive the intermediate parameter and auxiliary parameter sent by service equipment;According to intermediate parameter, auxiliary parameter and the first intermediate value of the mth user equipment, generate first signature;Blind processing is carried out to first signature, and the first signature after blinding is obtained;The first signature after blinding is sent to service equipment;Receive the second intermediate value sent by service equipment;And the second intermediate value of service equipment and first signature are handled, and the second signature is obtained;Wherein, first signature and second signature constitute collaborative signature.The method of the present application improves the information security of user equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security, and in particular to a collaborative signature method, apparatus, and device applied to a collaborative signature system. Background Art

[0002] In the financial industry and other industries, when multiple participants such as service devices and multiple user devices share data and conduct joint calculations, each participant is required to collaboratively sign the signature information at the same time to ensure the security of each participant.

[0003] In the prior art, a service device participates in calculating a first signature, and each user device participates in calculating a second signature, thereby obtaining a complete signature to complete the collaborative signature processing process of the information to be signed.

[0004] However, in the above process, if the service device obtains part of the signature information during the collaborative signature process, it can combine the overall collaborative signature process to infer the information of other user devices, thereby reducing the information security of the user device. Summary of the Invention

[0005] The embodiments of the present application provide a collaborative signature method, apparatus, and device applied to a collaborative signature system, to solve the technical problem that the information security of the user device is reduced due to the service device obtaining partial signature information during the collaborative signature process.

[0006] In a first aspect, an embodiment of the present application provides a collaborative signature method applied to a collaborative signature system, wherein the collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the method is applied to the mth user device in the collaborative signature system; the method includes:

[0007] determining a first intermediate value of the m-th user equipment; and receiving intermediate parameters and auxiliary parameters sent by the service device; wherein the intermediate parameters and auxiliary parameters are obtained by processing the first intermediate values ​​of other user equipment; the other user equipment is each other user equipment among the m user equipment except the m-th user equipment; the first intermediate value represents a point on a preset elliptic curve corresponding to the user equipment;

[0008] generating a first signature according to the intermediate parameter, the auxiliary parameter, and the first intermediate value of the m-th user equipment;

[0009] performing blinding processing on the first signature to obtain a blinded first signature;

[0010] Sending the blinded first signature to the service device; wherein the blinded first signature is used to generate a second intermediate value of the service device;

[0011] Receive a second intermediate value sent by the service device; and process the second intermediate value of the service device and the first signature to obtain a second signature; wherein the first signature and the second signature constitute a collaborative signature; the collaborative signature is used for identity authentication processing.

[0012] In one possible implementation, generating a first signature based on the intermediate parameter, the auxiliary parameter, and the first intermediate value of the m-th user device includes: determining signature random information based on a hidden random number, the intermediate parameter, the auxiliary parameter, and the first intermediate value of the m-th user device; obtaining information to be signed and determining summary information corresponding to the information to be signed; and generating the first signature based on the summary information and the signature random information.

[0013] In a possible implementation, the signature random information Q=Q0+Pm+kr·QO′, wherein Q0 is the intermediate parameter; QO′ is the auxiliary parameter; kr is the hidden random number; and Pm is the first intermediate value of the mth user equipment.

[0014] In a possible implementation, blinding the first signature to obtain the blinded first signature includes: blinding the first signature according to a hidden random number to obtain the blinded first signature.

[0015] In a possible implementation, the blinded first signature r′=r·kr -1 ; Wherein, kr is the hidden random number; r is the first signature.

[0016] In one possible implementation, processing the second intermediate value of the service device and the first signature to obtain a second signature includes: processing the second intermediate value of the service device to obtain the second intermediate value of the mth user device; sending the second intermediate value of the mth user device and the first signature to the m-1th user device; wherein the second intermediate value of the mth user device and the first signature are used to generate the second signature.

[0017] In one possible implementation, processing the second intermediate value of the service device to obtain the second intermediate value of the mth user device includes: determining the second intermediate value of the mth user device based on the second intermediate value of the service device, the first signature, the hidden random number, and the private key parameters and secret random number of the mth user device.

[0018] In one possible implementation, determining the first intermediate value of the mth user device includes: determining an initial private key of the mth user device; and determining a key intermediate value of the mth user device based on the initial private key of the mth user device; determining a first secret value of the mth user device based on a public key parameter and the initial private key of the mth user device; sending the public key parameter, the key intermediate value, and the first secret value of the mth user device to the m-1th user device; wherein the public key parameter, the key intermediate value, and the first secret value of the mth user device are used to generate a second secret value of the m-1th user device; receiving the second secret value sent by the m-1th user device; and determining a signature private key of the mth user device based on the private key parameter and the second secret value of the m-1th user device; and determining the first intermediate value of the mth user device based on the signature private key and a secret random number of the mth user device.

[0019] In a second aspect, an embodiment of the present application provides a collaborative signature method applied to a collaborative signature system, wherein the collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the method is applied to the service device in the collaborative signature system; the method includes:

[0020] Receiving a first intermediate value sent by another user device; wherein the other user device is each user device other than the mth user device among the m user devices; the first intermediate value represents a point on a preset elliptic curve corresponding to the user device;

[0021] Performing a summation calculation on the first intermediate values ​​of each of the other user devices to obtain an intermediate parameter; and determining an auxiliary parameter; wherein the auxiliary parameter represents an auxiliary point corresponding to the service device on a preset elliptic curve;

[0022] Sending the intermediate parameters and the auxiliary parameters to the mth user equipment; wherein the intermediate parameters and the auxiliary parameters are used to generate a first signature and a blinded first signature;

[0023] receiving a blinded first signature sent by the mth user equipment; and determining a second intermediate value of the serving device based on the blinded first signature;

[0024] The second intermediate value of the service device is sent to the m-th user device; wherein the second intermediate value of the service device is used to generate a second signature; the first signature and the second signature constitute a collaborative signature; and the collaborative signature is used to perform identity authentication processing.

[0025] In a possible implementation, determining the auxiliary parameters includes: determining a signature public key, a signature private key of the service device, and a signature random number; and determining the auxiliary parameters based on the signature public key, the signature private key of the service device, and the signature random number.

[0026] In one possible implementation, determining the signature public key includes: receiving a public key parameter sent by a first user device, as well as a key intermediate value and a first secret value of the first user device; and determining the signature public key based on an initial private key of the service device and the key intermediate value of the first user device.

[0027] In one possible implementation, the method further includes: determining the first secret value of the service device based on the initial private key of the service device and the first secret value of the first user device; determining the second secret value of the service device based on the public key parameters, and the signature private key and first secret value of the service device; sending the signature public key to each of the user devices; and sending the second secret value of the service device to the first user device; wherein the signature public key and the second secret value of the service device are used to generate the second secret value of the first user device.

[0028] In one possible implementation, the auxiliary parameter Q0′=(Sk0·k0)·(P+G); Sk0 is the signature private key of the service device; k0 is the signature random number of the service device; G is the base point of the preset elliptic curve; P is the point on the preset elliptic curve corresponding to the signature public key.

[0029] In a possible implementation, determining the second intermediate value of the service device based on the blinded first signature includes: determining the second intermediate value of the service device based on the signature private key and signature random number of the service device and the blinded first signature.

[0030] In a third aspect, an embodiment of the present application provides a collaborative signature device applied to a collaborative signature system, wherein the collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the device is applied to the mth user device in the collaborative signature system; the device includes:

[0031] a receiving module, configured to determine a first intermediate value of the m-th user equipment; and receive intermediate parameters and auxiliary parameters sent by the service device; wherein the intermediate parameters and auxiliary parameters are obtained by processing the first intermediate values ​​of other user equipment; the other user equipment is each user equipment other than the m-th user equipment among the m user equipment; and the first intermediate value represents a point on a preset elliptic curve corresponding to the user equipment;

[0032] a generating module, configured to generate a first signature based on the intermediate parameter, the auxiliary parameter, and the first intermediate value of the m-th user equipment;

[0033] a first processing module, configured to perform blinding processing on the first signature to obtain a blinded first signature;

[0034] a sending module, configured to send the blinded first signature to the service device; wherein the blinded first signature is used to generate a second intermediate value of the service device;

[0035] The second processing module is used to receive the second intermediate value sent by the service device; and process the second intermediate value of the service device and the first signature to obtain a second signature; wherein the first signature and the second signature constitute a collaborative signature; the collaborative signature is used for identity authentication processing.

[0036] In a fourth aspect, an embodiment of the present application provides a collaborative signature device applied to a collaborative signature system, wherein the collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the device is applied to the service device in the collaborative signature system; the device includes:

[0037] a receiving module, configured to receive a first intermediate value sent by another user device; wherein the other user device is each user device other than the mth user device among the m user devices; and the first intermediate value represents a point on a preset elliptic curve corresponding to the user device;

[0038] A first determination module is configured to sum and calculate the first intermediate values ​​of each of the other user devices to obtain an intermediate parameter; and determine an auxiliary parameter; wherein the auxiliary parameter represents an auxiliary point corresponding to the service device on a preset elliptic curve;

[0039] a first sending module, configured to send the intermediate parameters and the auxiliary parameters to the mth user equipment; wherein the intermediate parameters and the auxiliary parameters are used to generate a first signature and a blinded first signature;

[0040] a second determining module, configured to receive the blinded first signature sent by the m-th user equipment; and determine a second intermediate value of the serving device based on the blinded first signature;

[0041] The second sending module is used to send the second intermediate value of the service device to the m-th user device; wherein the second intermediate value of the service device is used to generate a second signature; the first signature and the second signature constitute a collaborative signature; the collaborative signature is used to perform identity authentication processing.

[0042] In a fifth aspect, an embodiment of the present application provides a user equipment, including: a memory, a processor;

[0043] The memory stores computer-executable instructions;

[0044] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementations of the first aspect.

[0045] In a sixth aspect, an embodiment of the present application provides a service device, including: a memory, a processor;

[0046] The memory stores computer-executable instructions;

[0047] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above second aspect and / or various possible implementations of the second aspect.

[0048] In the seventh aspect, an embodiment of the present application provides a collaborative signature system, which includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the mth user device in the collaborative signature system is used to implement the first aspect above and / or various possible implementation methods of the first aspect; the service device is used to implement the second aspect above and / or various possible implementation methods of the second aspect.

[0049] In an eighth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, they are used to implement the method of the first aspect or the second aspect above.

[0050] In a ninth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, which implements the method of the first or second aspect above when executed by a processor.

[0051] The collaborative signature method, apparatus, and equipment provided in the embodiments of the present application for a collaborative signature system summarize and process the first intermediate values ​​of each other user device through a service device to generate intermediate parameters and auxiliary parameters. The mth user device generates a first signature in the collaborative signature based on the intermediate parameters and auxiliary parameters, and blinds the first signature. The service device generates a second intermediate value of the service device based on the blinded first signature. The mth user device generates a second signature in the collaborative signature based on the second intermediate value of the service device, and a complete collaborative signature for identity authentication processing can be obtained. Furthermore, the service device cannot obtain the signature content generated by the user device, thereby improving the information security of the user device. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0053] Figure 1 A schematic diagram of an application scenario provided for this application;

[0054] Figure 2 A flowchart of a collaborative signature method applied to a collaborative signature system provided in an embodiment of the present application;

[0055] Figure 3 A flowchart of another collaborative signature method applied to a collaborative signature system provided in an embodiment of the present application;

[0056] Figure 4 A flowchart of another collaborative signature method applied to a collaborative signature system provided in an embodiment of the present application;

[0057] Figure 5 A schematic diagram of the structure of a collaborative signature device applied to a collaborative signature system provided in an embodiment of the present application;

[0058] Figure 6 A schematic diagram of the structure of another collaborative signature device applied to a collaborative signature system provided in an embodiment of the present application;

[0059] Figure 7 A schematic diagram of the structure of a user equipment provided in an embodiment of the present application;

[0060] Figure 8 A schematic diagram of the structure of a service device provided in an embodiment of the present application.

[0061] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0062] Exemplary embodiments are described in detail herein, with examples illustrated in the accompanying drawings. When the following description refers to the drawings, identical numerals in different figures represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatuses and methods consistent with certain aspects of the present application.

[0063] First, let’s explain the terms involved in this application:

[0064] SM2 signature algorithm: A public-key cryptography algorithm based on elliptic curve cryptography (ECC), primarily used for digital signatures, key exchange, and public-key encryption. The SM2 signature algorithm is a key component used to generate and verify digital signatures.

[0065] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, processing, transmission, provision, disclosure and application of relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0066] It should be noted that the collaborative signature method, device and equipment applied to the collaborative signature system of the present application can be used in the field of information security, and can also be used in any field other than information security. The application field of the collaborative signature method, device and equipment applied to the collaborative signature system of the present application is not limited.

[0067] Figure 1 This is a schematic diagram of an application scenario provided by this application. Figure 1 As shown, the specific application scenario of this application includes a service device 101 and multiple user devices 102 in a collaborative signature system. In the financial industry and other industries, when multiple participants such as the service device 101 and multiple user devices 102 perform data sharing and joint computing, each participant needs to perform collaborative signature processing on the signature information at the same time to ensure the security of each participant.

[0068] In one example, the service device 101 participates in calculating the first signature, and each user device 102 participates in calculating the second signature, thereby obtaining a complete signature to complete the collaborative signature processing process of the information to be signed.

[0069] In another example, a multi-party collaborative signature scheme based on SM2 includes a key generation link and a signature link; wherein, in the key generation link, the service device 101 and each user device 102 generate their own signature private keys, and the service device 101 and each user device 102 collaboratively calculate the signature public key; in the signature link, the service device 101 and each user device 102 generate their own signature random numbers, combine their own signature private keys, and calculate the corresponding signature intermediate results (elliptic curve midpoints) through continuous transfer or simultaneous transfer. The service device 101 summarizes the signature intermediate results of each user device 102, and directly calculates the first part of the signature, and finally passes it to the mth user device 102. From the mth user device 102 to the second user device 102, each combines the signature private key and random number to generate a signature intermediate value. The first user device 102 calculates the final signature value to obtain a complete signature.

[0070] However, in the above method, after the collaborative signature is made public, the service device can associate the first signature with the collaborative signature process, thereby obtaining the exact time when each user device executes the signature, resulting in the leakage of the privacy information of each user device, thereby reducing the information security of the user device.

[0071] To address the above technical issues, this application proposes the following technical concept: Based on the mth user device, the service device processes the first intermediate values ​​of each other user device to obtain intermediate parameters and auxiliary parameters to generate the first signature in the collaborative signature. This first signature is then blinded. The service device generates the second intermediate value of the service device based on the blinded first signature. The mth user device then generates the second signature in the collaborative signature based on the second intermediate value of the service device, thereby obtaining a complete collaborative signature. This solves the problem in the prior art that the service device can obtain the exact time when each user device executed the signature based on the first signature, which may lead to the leakage of privacy information of each user device.

[0072] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0073] Figure 2 A flowchart of a collaborative signature method applied to a collaborative signature system provided in an embodiment of the present application is shown as follows: Figure 2 As shown, the collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the method is applied to the mth user device in the collaborative signature system; the method includes:

[0074] 201. Determine a first intermediate value of the mth user device; and receive intermediate parameters and auxiliary parameters sent by a service device; wherein the intermediate parameters and auxiliary parameters are obtained by processing the first intermediate values ​​of other user devices; the other user devices are each other user device among the m user devices except the mth user device; the first intermediate value represents a point on a preset elliptic curve corresponding to the user device.

[0075] For example, the execution entity of this embodiment may be the mth user device in the collaborative signature system. Based on the mth user device and each other user device among the m user devices, a first intermediate value is generated for each user device using its own private key and a signature secret random number based on an elliptic curve cryptographic algorithm to represent the point corresponding to the user device on the preset elliptic curve. Then, based on each other user device other than the mth user device, i.e., other user devices, the generated first intermediate value is sent to the service device. The service device processes the received first intermediate values ​​of each other user device to generate intermediate parameters and auxiliary parameters, and sends the obtained intermediate parameters and auxiliary parameters to the mth user device.

[0076] 202. Receive intermediate parameters and auxiliary parameters sent by the service device; and generate a first signature according to the intermediate parameters, the auxiliary parameters, and a first intermediate value of the mth user equipment.

[0077] Exemplarily, the mth user device receives the intermediate parameters and auxiliary parameters sent by the service device, and based on the preset signature algorithm, calculates and processes the intermediate parameters, auxiliary parameters and the first intermediate value of the mth user device obtained to generate the first part of the collaborative signature, i.e., the first signature.

[0078] 203. Perform blinding processing on the first signature to obtain a blinded first signature.

[0079] Exemplarily, the mth user equipment performs blinding processing on the obtained first signature based on a preset hiding algorithm to obtain the blinded first signature, so as to hide and protect the first signature.

[0080] 204. Send the blinded first signature to the service device; wherein the blinded first signature is used to generate a second intermediate value of the service device.

[0081] Exemplarily, the mth user device sends the obtained blinded first signature to the service device. The service device processes the received blinded first signature to generate a second intermediate value of the service device, and sends the second intermediate value of the service device to the mth user device.

[0082] 205. Receive a second intermediate value sent by the service device; and process the second intermediate value and the first signature of the service device to obtain a second signature; wherein the first signature and the second signature constitute a collaborative signature; and the collaborative signature is used for identity authentication processing.

[0083] Exemplarily, the mth user device receives the second intermediate value of the service device sent by the service device, and processes the second intermediate value of the service device and the generated first signature based on a preset signature algorithm to generate the second part of the collaborative signature, i.e., the second signature. Then, a complete collaborative signature is formed based on the first signature and the second signature for identity authentication processing, such as applying the signature verification process of the SM2 algorithm to verify the collaborative signature.

[0084] In this embodiment, a collaborative signature method applied to a collaborative signature system is provided, in which a service device aggregates and processes the first intermediate values ​​of each other user device to generate intermediate parameters and auxiliary parameters. The mth user device generates a first signature in the collaborative signature based on the intermediate parameters and auxiliary parameters, and blinds the first signature. The service device generates a second intermediate value of the service device based on the blinded first signature. The mth user device generates a second signature in the collaborative signature based on the second intermediate value of the service device, and a complete collaborative signature for identity authentication processing is obtained. Furthermore, the service device cannot obtain the signature generated by the user device, and cannot infer the privacy information of the user device, thereby improving the information security of the user device.

[0085] Figure 3 A flowchart of another collaborative signature method applied to a collaborative signature system provided in an embodiment of the present application is shown as follows: Figure 3 As shown, the collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the method includes:

[0086] 301. The mth user equipment determines a first intermediate value of the mth user equipment.

[0087] For example, this step can refer to step 201 and will not be described in detail here.

[0088] In one example, step 301 includes:

[0089] Step 1: Determine the initial private key of the mth user device; and determine the key intermediate value of the mth user device based on the initial private key of the mth user device.

[0090] Step 2: Determine the first secret value of the mth user device based on the public key parameters and the initial private key of the mth user device.

[0091] Step 3: Send the public key parameters, the key intermediate value and the first secret value of the mth user device to the m-1th user device; wherein the public key parameters, the key intermediate value and the first secret value of the mth user device are used to generate the second secret value of the m-1th user device.

[0092] Step 4: Receive the second secret value sent by the m-1th user device; and determine the signature private key of the mth user device based on the private key parameter and the second secret value of the m-1th user device.

[0093] Step 5: Determine the first intermediate value of the mth user device based on the signature private key and the secret random number of the mth user device.

[0094] Specifically, based on the mth user device, a secret initial private key Sm is generated, and a pair of public and private key pairs of the additive homomorphic cryptographic algorithm are generated, including public key parameters pk and private key parameters sk, according to the preset elliptic curve encryption algorithm Pkm=[Sm -1 ]G, calculates and processes the initial private key Sm of the m-th user device to obtain the key intermediate value Pkm of the m-th user device, wherein the elliptic curve base point is G. Based on the m-th user device, the initial private key Sm of the m-th user device is encrypted according to the public key parameter pk by applying the additive homomorphic cryptographic algorithm, such as the calculation formula Em=Encpk(Sm), and the first secret value Em of the m-th user device can be obtained. Finally, the m-th user device sends the obtained public key parameter pk, the key intermediate value Pkm and the first secret value Em of the m-th user device to the m-1-th user device, so that the m-1-th user device processes the received public key parameter pk, the key intermediate value Pkm and the first secret value Em of the m-1-th user device to generate the second secret value E of the m-1-th user device. m-1 ', and the obtained second secret value E of the m-1th user equipment m-1 'Sent to the mth user device. Based on the mth user device, the second secret value E of the m-1th user device is received m-1 ', and according to the generated private key parameter sk, by the formula Skm=Dec sk (E m-1 '), the second secret value E for the m-1th user equipment m-1 Perform decryption to obtain the signature private key Skm of the mth user device. The mth user device generates a secret random number km and combines it with the signature private key Skm of the mth user device and the public key parameter Pk to perform a point multiplication on the elliptic curve. The calculated point on the elliptic curve is the first intermediate value Pm of the mth user device = [Skm km](P+G), where P is the point on the elliptic curve corresponding to the public key parameter Pk. The base point of the elliptic curve is G.

[0095] Further, when the m-1th user equipment receives the public key parameter pk and the key intermediate value Pkm and the first secret value Em of the m-th user equipment, when i=m-1, it can be obtained by Pki=[Si -1 ]Pk i+1 Calculate the intermediate key value Pkm of the m-th user device and the initial private key Si generated by the m-1-th user device to obtain the intermediate key value Pk of the m-1-th user device m-1 and through Ei=E i+1 Si, calculate the first secret value Em of the mth user equipment and the initial private key Si of the m-1th user equipment to obtain the first secret value E of the m-1th user equipment m-1 , and the obtained public key parameter pk, the first secret value E of the m-1th user equipment m-1 and the intermediate key value Pk m-1 , sent to the m-2th user device by continuous forwarding or simultaneous delivery, and so on, so that the first user device can send the public key parameter pk, the first secret value E1 of the first user device and the key intermediate value Pk1 to the service device. Based on a preset algorithm, the service device processes the first secret value E1 and the key intermediate value Pk1 of the first user device to obtain the second secret value E0' of the service device, and sends the second secret value E0' to the first user device. For each user device Ai from the first user device to the m-1th user device, i = 1, ..., m-1, it can randomly generate its own signature private key Ski, and based on its own signature private key Ski, based on the formula Ei' = E0'·Encpk(Ski), the received signature public key Pk and the second secret value E0' of the service device, as well as the signature private key Ski randomly generated by the i-th user device, to obtain the second secret value Ei' of the i-th user device, and send it to the i+1th user device Ai+1, so that the m-1th user device can obtain the second secret value Ei' of the m-1th user device. m-1 At this point, each user device Ai has generated its own signature private key Ski. This ensures that no signing party can obtain the complete signature private key during the key generation phase, and that the signature private key cannot be reverse-calculated from the intermediate results and the final signature during the signing process, thus ensuring the security of the signature.

[0096] 302. The service device receives a first intermediate value sent by another user device, wherein the other user device is each user device other than the mth user device among the m user devices; the first intermediate value represents a point corresponding to the user device on a preset elliptic curve.

[0097] Exemplarily, each user device except the m-th user device in the collaborative signature system will generate its own first intermediate value through a preset elliptic curve encryption algorithm to represent the point corresponding to each user device on the preset elliptic curve, such as through the first intermediate value Pi = [Ski·ki](P+G) of the i-th user device, where i is an integer greater than or equal to 1 and less than m, P is the point on the elliptic curve corresponding to the public key parameter Pk, and the base point of the elliptic curve is G; and send its own first intermediate value to the service device, and based on the receiving end of the service device, receive the first intermediate value sent by each user device except the m-th user device.

[0098] 303. The service device performs summation calculation on the first intermediate values ​​of each other user device to obtain an intermediate parameter, and determines an auxiliary parameter. The auxiliary parameter represents an auxiliary point corresponding to the service device on the preset elliptic curve.

[0099] Exemplarily, the service device calculates the sum of the first intermediate values ​​received from each other user device based on a summation algorithm to obtain a corresponding intermediate parameter. For example, each other user device Ai sends Pi (i=1, ...m-1) as the first intermediate value to service device A0, and service device A0 calculates Q0=P1+...+Pm-1 to obtain the intermediate parameter Q0. The service device generates auxiliary parameters based on an elliptic curve cryptography algorithm to represent the auxiliary point corresponding to the service device on a preset elliptic curve.

[0100] 304. The service device sends the intermediate parameters and the auxiliary parameters to the mth user equipment; wherein the intermediate parameters and the auxiliary parameters are used to generate the first signature and the blinded first signature.

[0101] Exemplarily, the service device sends the obtained intermediate parameters and auxiliary parameters to the mth user equipment, so that the mth user equipment processes the received intermediate parameters and auxiliary parameters to generate the first signature and the blinded first signature.

[0102] 305. The m-th user device receives intermediate parameters and auxiliary parameters sent by the service device; wherein the intermediate parameters and auxiliary parameters are obtained by processing first intermediate values ​​of other user devices; the other user devices are each other user device among the m user devices except the m-th user device; and the first intermediate value represents the point on the preset elliptic curve corresponding to the user device.

[0103] For example, this step can refer to step 201 and will not be described in detail here.

[0104] 306. The mth user equipment generates a first signature according to the intermediate parameter, the auxiliary parameter, and the first intermediate value of the mth user equipment.

[0105] For example, this step may refer to step 202 and will not be described in detail here.

[0106] 307. The mth user equipment performs blinding processing on the first signature to obtain a blinded first signature.

[0107] For example, this step may refer to step 203 and will not be described in detail here.

[0108] 308. The mth user equipment sends the blinded first signature to the serving device; wherein the blinded first signature is used to generate a second intermediate value of the serving device.

[0109] For example, this step can refer to step 204 and will not be described in detail here.

[0110] 309. The service device receives the blinded first signature sent by the mth user equipment; and determines a second intermediate value of the service device according to the blinded first signature.

[0111] Exemplarily, the service device receives the blinded first signature sent by the mth user equipment, and calculates and processes the blinded first signature based on a preset algorithm to obtain a second intermediate value of the service device.

[0112] In one example, step 309 includes determining a second intermediate value of the service device according to the signature private key and the signature random number of the service device and the blinded first signature.

[0113] Exemplarily, the service device can calculate and process the blinded first signature based on a preset algorithm using the signature private key and signature random number of the service device generated by itself to obtain the second intermediate value of the service device. For example, the second intermediate value s0 of the service device can be calculated based on the formula s0=Sk0(r'+k0)mod n, where mod represents a modulus operation, Sk0 is the signature private key of the service device, k0 is the signature random number of the service device, n is the order of the preset elliptic curve, and r' is the blinded first signature.

[0114] 310. The service device sends the second intermediate value of the service device to the mth user device; wherein the second intermediate value of the service device is used to generate a second signature; the first signature and the second signature constitute a collaborative signature; and the collaborative signature is used to perform identity authentication processing.

[0115] Exemplarily, the service device sends the obtained second intermediate value s0 of the service device to the mth user device, so that the mth user device processes the second intermediate value of the service device to generate a second signature.

[0116] 311. The mth user device receives the second intermediate value sent by the service device; and processes the second intermediate value and the first signature of the service device to obtain a second signature; wherein the first signature and the second signature constitute a collaborative signature; the collaborative signature is used for identity authentication processing.

[0117] For example, this step can refer to step 205 and will not be described in detail here.

[0118] In this embodiment, based on the above embodiment, the service device uses the first intermediate values ​​of other user devices to perform summation calculation to obtain intermediate parameters and auxiliary parameters, and the mth user device uses the intermediate parameters and auxiliary parameters to perform signature blinding processing, and the blinded first signature is sent to the service device. As a result, the service device cannot obtain the real signature content, and cannot infer the privacy information of each user device, thereby ensuring the information security of the user device.

[0119] Figure 4 A flowchart of another collaborative signature method applied to a collaborative signature system provided in an embodiment of the present application is shown as follows: Figure 4 As shown, the collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the method includes:

[0120] 401. The mth user equipment determines a first intermediate value of the mth user equipment.

[0121] For example, the content of this step can be referred to step 201 and will not be repeated here.

[0122] 402. The service device receives a first intermediate value sent by another user device, wherein the other user device is each user device other than the mth user device among the m user devices; the first intermediate value represents a point on a preset elliptic curve corresponding to the user device.

[0123] For example, the content of this step can be found in step 302 and will not be repeated here.

[0124] 403. The service device determines the signature public key, the signature private key of the service device, and the signature random number.

[0125] Exemplarily, the service device generates a signature public key through a preset encryption algorithm, and generates a signature private key and a signature random number of the service device.

[0126] In one example, step 403 includes:

[0127] The first step is to receive a public key parameter sent by a first user device, as well as a key intermediate value and a first secret value of the first user device.

[0128] The second step is to determine the signature public key based on the initial private key of the service device and the key intermediate value of the first user device.

[0129] In one example, step 403 further includes:

[0130] The third step is to determine the first secret value of the service device according to the initial private key of the service device and the first secret value of the first user device.

[0131] The fourth step is to determine the second secret value of the service device according to the public key parameter, the signature private key of the service device and the first secret value.

[0132] The fifth step is to send the signature public key to each user device; and send the second secret value of the service device to the first user device; wherein the signature public key and the second secret value of the service device are used to generate the second secret value of the first user device.

[0133] Specifically, a secret initial private key Si is generated for the service device and each user device, and based on the first user device, the public key parameters are first obtained, and the initial private key S1 generated by itself is processed according to its own preset encryption algorithm. For example, based on the aforementioned process of calculating the second secret value of the m-1th user device, when i=1, it can be obtained by Pk1=[S1 -1 ]Pk2, calculate the key intermediate value Pk2 of the second user device and the initial private key S1 generated by the first user device itself to obtain the key intermediate value Pk1 of the first user device, and calculate the first secret value E2 of the second user device and the initial private key S1 of the first user device through E1=E2S1 to obtain the first secret value E1 of the first user device; and send the public key parameter pk, the first secret value E1 of the first user device and the key intermediate value Pk1 to the service device. Based on the service device, after receiving the public key parameter pk, the key intermediate value Pk1 of the first user device and the first secret value E1, the initial private key S0 of the service device and the key intermediate value Pk1 of the first user device are calculated, such as calculating Pk=[S0 -1 ]Pk1-G, G is the base point on the preset elliptic curve, and the signature public key Pk can be generated. At the same time, the service device is based on the preset formula E0=E1 S0, the service device's initial private key S0 and the first secret value E1 of the first user device are calculated to obtain the service device's first secret value E0. The service device then randomly generates its own signature private key Sk0 and, based on the formula E0'=E0·Encpk(Sk0), encrypts the public key parameter pk, the service device's signature private key Sk0, and the first secret value E0 to obtain the service device's second secret value E0'. The service device sends the generated signature public key Pk to each user device and sends the service device's second secret value E0' to the first user device, so that the first user device obtains the first user device's second secret value E1'. For example, based on the aforementioned calculation of the second secret value of the m-1th user device, the received signature public key Pk, the service device's second secret value E0', and the first user device's randomly generated signature private key Sk1 are processed based on the formula E1'=E0'·Encpk(Sk1) to obtain the first user device's second secret value E1'.

[0134] 404. The service device determines the auxiliary parameters according to the signature public key, the signature private key of the service device, and the signature random number.

[0135] In an example, the auxiliary parameter Q0′=(Sk0·k0)·(P+G); Sk0 is the signature private key of the service device; k0 is the signature random number of the service device; G is the base point of the preset elliptic curve; P is the point on the preset elliptic curve corresponding to the signature public key.

[0136] Exemplarily, the service device calculates and processes the generated signature public key, the service device's signature private key, and the signature random number based on the elliptic curve cryptography algorithm to obtain the auxiliary parameters. The signature public key can be calculated using the elliptic curve cryptography algorithm to obtain the point on the preset elliptic curve corresponding to the signature public key. The auxiliary parameter Q0′ is calculated using the formula Q0′=(Sk0·k0)·(P+G) based on the point P on the preset elliptic curve corresponding to the signature public key, the service device's signature private key Sk0 and the signature random number k0, and the base point G of the preset elliptic curve.

[0137] 405. The service device sends the intermediate parameters and the auxiliary parameters to the mth user equipment; wherein the intermediate parameters and the auxiliary parameters are used to generate the first signature and the blinded first signature.

[0138] For example, this step may refer to step 304 and will not be described in detail here.

[0139] 406. The mth user device receives intermediate parameters and auxiliary parameters sent by the service device; wherein the intermediate parameters and auxiliary parameters are obtained by processing first intermediate values ​​of other user devices; the other user devices are each other user device among the m user devices except the mth user device; and the first intermediate value represents the point on the preset elliptic curve corresponding to the user device.

[0140] For example, this step can refer to step 201 and will not be described in detail here.

[0141] 407. The mth user equipment generates a first signature according to the intermediate parameter, the auxiliary parameter, and the first intermediate value of the mth user equipment.

[0142] For example, this step may refer to step 202 and will not be described in detail here.

[0143] In one example, step 407 includes:

[0144] Step 1: Determine signature random information based on the hidden random number, the intermediate parameter, the auxiliary parameter, and the first intermediate value of the mth user equipment.

[0145] Step 2: Obtain the information to be signed and determine the summary information corresponding to the information to be signed.

[0146] Step 3: Generate the first signature based on the summary information and the signature random information.

[0147] In one example, the signature random information Q=Q0+Pm+kr·QO′; wherein Q0 is an intermediate parameter; QO′ is an auxiliary parameter; kr is a hidden random number; and Pm is a first intermediate value of the mth user equipment.

[0148] Exemplarily, the mth user device generates a hidden random number kr and, in combination with the intermediate parameter Q0, the auxiliary parameter QO′, and the first intermediate value Pm of the mth user device, calculates and processes the signature random information to represent the signature random point corresponding to the mth user device on the preset elliptic curve. The signature random information Q can be calculated using the formula Q = Q0 + Pm + kr·QO′. Then, when the obtained signature random information Q is not zero, let Q = (x, y). The digest information of the message to be signed is calculated according to the requirements of the SM2 signature algorithm, such as by calculating e = Hash(Z||M) to obtain the digest information e, where the message to be signed is M and Z is additional, usually fixed-length data. The digest information and the signature random information are calculated and processed according to the SM2 signature algorithm, such as r = (x + e) ​​mod n, to obtain the first signature r, where mod is a modular operation and n is the order of the preset elliptic curve.

[0149] 408. The mth user equipment performs blinding processing on the first signature according to the hidden random number to obtain a blinded first signature.

[0150] In one example, the first blinded signature r′=r·kr -1 ; Where kr is the hidden random number; r is the first signature.

[0151] For example, the mth user equipment generates a hidden random number kr based on a preset hidden protection algorithm, such as r′=r·kr -1 , the hidden random number kr and the first signature r are calculated and processed to obtain the blinded first signature r′.

[0152] 409. The mth user equipment sends the blinded first signature to the serving device; wherein the blinded first signature is used to generate a second intermediate value of the serving device.

[0153] For example, this step can refer to step 204 and will not be described in detail here.

[0154] 410. The service device receives the blinded first signature sent by the mth user equipment.

[0155] For example, this step may refer to step 309 and will not be described in detail here.

[0156] 411. The service device determines a second intermediate value of the service device according to the signature private key and the signature random number of the service device and the blinded first signature.

[0157] Exemplarily, the service device can calculate and process the blinded first signature based on a preset algorithm using the signature private key and signature random number of the service device generated by itself to obtain the second intermediate value of the service device. For example, the second intermediate value s0 of the service device can be calculated based on the formula s0=Sk0(r'+k0)mod n, where mod represents a modulus operation, Sk0 is the signature private key of the service device, k0 is the signature random number of the service device, n is the order of the preset elliptic curve, and r' is the blinded first signature.

[0158] 412. The service device sends the second intermediate value of the service device to the mth user device; wherein the second intermediate value of the service device is used to generate a second signature; the first signature and the second signature constitute a collaborative signature; and the collaborative signature is used to perform identity authentication processing.

[0159] For example, this step may refer to step 310 and will not be described in detail here.

[0160] 413. The mth user equipment receives the second intermediate value sent by the serving device.

[0161] For example, this step can refer to step 205 and will not be described in detail here.

[0162] 414. The mth user equipment processes the second intermediate value of the serving device to obtain the second intermediate value of the mth user equipment.

[0163] Exemplarily, the mth user device calculates and processes the second intermediate value of the service device and the private key parameters and secret random number of the mth user device according to a preset signature algorithm such as the SM2 algorithm to obtain the second intermediate value of the mth user device.

[0164] In one example, step 414 includes determining the second intermediate value of the mth user device based on the second intermediate value of the service device, the first signature, the hidden random number, and the private key parameters and the secret random number of the mth user device.

[0165] Specifically, the mth user device first determines the private key parameter Skm and secret random number km of its own mth user device, and randomly generates a hidden random number kr. Based on the formula sm=(Skm(r+km)+kr·s0)mod n, the private key parameter Skm of the mth user device, the secret random number km, the hidden random number kr, the first signature r, and the second intermediate value s0 of the service device are calculated to obtain the second intermediate value sm of the mth user device, where n is the order of the preset elliptic curve and mod represents a modular operation.

[0166] 415. The mth user equipment sends the second intermediate value and the first signature of the mth user equipment to the (m-1)th user equipment; wherein the second intermediate value and the first signature of the mth user equipment are used to generate a second signature.

[0167] Exemplarily, the mth user device sends the obtained second intermediate value sm and first signature r of the mth user device to the m-1th user device, so that the m-1th user device processes the second intermediate value and first signature of the mth user device to generate a second signature.

[0168] Further, after the m-1th user equipment receives the second intermediate value sm and the first signature r of the m-th user equipment, it transmits the second intermediate value sm and the first signature r to each user equipment Ai (i=m-1, ..., 2) from the m-1th user equipment to the second user equipment through continuous forwarding or simultaneous transmission. i+1 Get the first signature r and the second intermediate value s i+1 , and combined with the signature private key Ski of the user device Ai and the random number ki, calculate the second intermediate value si of the user device Ai = (Ski(r+ki)+s i+1 ) mod n, and send the second intermediate value si and the first signature r together to Ai-1 , and so on, the first user device can receive the second intermediate value s2 and the first signature r of the second user device; based on the first user device, combined with its own signature private key Sk1 and random number k1, according to the formula s1 = (Sk1(r+k1)+s2-r) mod n, the second intermediate value s1 of the first user device is calculated. If s1≠0, s1 is the second part of the collaborative signature, that is, the second signature s, and the signature (r, s) is the collaborative signature jointly generated by all participants. Then, the SM2 algorithm's signature verification process is directly applied to verify the obtained collaborative signature to complete the identity authentication process. Then, by each user-side participant calculating their own signature intermediate value in turn, and finally completing the overall collaborative signature, it can be met that during the signing process, the signature private key cannot be reversely calculated from the intermediate result and the final generated signature, ensuring the security of the signature and further improving information security.

[0169] It is worth adding that when m=1, that is, the collaborative signature system includes a service device and a user device, the service device first generates its own random number k0∈[1,n-1], combines its own signature private key Sk0, and directly calculates the auxiliary point Q0' through the formula Q0'=[Sk0k0](P+G), where the elliptic curve base point is G and the point corresponding to the signature public key on the preset elliptic curve is P, and the calculation result Q0' is sent to the user device. After receiving the calculation result Q0', the user device directly calculates its own first intermediate value Pm and generates a hidden random number kr. Then, combined with the calculation result Q0', the signature random point Q is calculated using the formula Q = Pm + krQ0'. The user device then calculates the digest of the message to be signed according to the SM2 signature algorithm and further calculates the first signature part r. The user device then uses the hidden random number kr to hide and protect r and sends the blinded signature r' to the service device, allowing the service device to calculate its own second intermediate value s0 and send it to the user device. After receiving s0, the user device directly calculates the second signature part s using its own signature private key Skm and the random number km using the formula s = (Skm(r+km)+krs0-r) mod n. When s ≠ 0, the collaborative signature (r, s) is obtained. Here, n is the order of the elliptic curve and mod is the modulo operation. Furthermore, in this application scenario of a service device and a user device, it can also be satisfied that the signature private key cannot be reversely calculated from the intermediate results and the final generated signature during the signing process, thereby ensuring the security of the signature.

[0170] In this embodiment, based on the above embodiment, the service device obtains the blinded first signature and calculates its second intermediate value, and then each user device calculates its own second intermediate value in turn until the first user device finally generates a second signature to obtain an overall collaborative signature; thereby, it can ensure that the final result of the signature algorithm will not be leaked to the server during the collaborative signing process. After the signature result is made public, the server cannot associate the signature result with the signing behavior, thereby protecting the security of the signing process and preventing the leakage of the precise time of signature calculation and the privacy information of users participating in the collaborative signing.

[0171] Figure 5 A schematic diagram of the structure of a collaborative signature device applied to a collaborative signature system provided in an embodiment of the present application is shown as follows: Figure 5 As shown, the collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the device is applied to the mth user device in the collaborative signature system; the device includes:

[0172] Receiving module 501 is configured to determine a first intermediate value of the mth user equipment; and receive intermediate parameters and auxiliary parameters sent by a serving device; wherein the intermediate parameters and auxiliary parameters are obtained by processing the first intermediate values ​​of other user equipment; the other user equipment is each user equipment other than the mth user equipment among the m user equipment; and the first intermediate value represents a point on a preset elliptic curve corresponding to the user equipment;

[0173] A generating module 502, configured to generate a first signature based on the intermediate parameter, the auxiliary parameter, and the first intermediate value of the m-th user equipment;

[0174] A first processing module 503 is configured to perform blinding processing on the first signature to obtain a blinded first signature;

[0175] A sending module 504 is configured to send the blinded first signature to the service device; wherein the blinded first signature is used to generate a second intermediate value of the service device;

[0176] The second processing module 505 is used to receive the second intermediate value sent by the service device; and process the second intermediate value and the first signature of the service device to obtain a second signature; wherein the first signature and the second signature constitute a collaborative signature; the collaborative signature is used for identity authentication processing.

[0177] In one possible implementation, the generation module 502 is specifically used to: determine the signature random information based on the hidden random number, the intermediate parameter, the auxiliary parameter, and the first intermediate value of the mth user device; obtain the information to be signed and determine the summary information corresponding to the information to be signed; and generate a first signature based on the summary information and the signature random information.

[0178] In a possible implementation, the signature random information Q=Q0+Pm+kr·QO′, wherein Q0 is an intermediate parameter; QO′ is an auxiliary parameter; kr is a hidden random number; and Pm is a first intermediate value of the mth user equipment.

[0179] In a possible implementation, the first processing module 503 is specifically configured to: perform blinding processing on the first signature according to the hidden random number to obtain a blinded first signature.

[0180] In one possible implementation, the blinded first signature r′=r·kr -1 ; Where kr is the hidden random number; r is the first signature.

[0181] In one possible implementation, the second processing module 505 is specifically used to: process the second intermediate value of the service device to obtain the second intermediate value of the mth user device; send the second intermediate value and the first signature of the mth user device to the m-1th user device; wherein the second intermediate value and the first signature of the mth user device are used to generate the second signature.

[0182] In a possible implementation, the second processing module 505 is specifically configured to determine the second intermediate value of the mth user device based on the second intermediate value of the service device, the first signature, the hidden random number, and the private key parameter and secret random number of the mth user device.

[0183] In one possible implementation, the receiving module 501 is specifically used to: determine the initial private key of the mth user device; and determine the key intermediate value of the mth user device based on the initial private key of the mth user device; determine the first secret value of the mth user device based on the public key parameters and the initial private key of the mth user device; send the public key parameters, the key intermediate value and the first secret value of the mth user device to the m-1th user device; wherein the public key parameters, the key intermediate value and the first secret value of the mth user device are used to generate the second secret value of the m-1th user device; receive the second secret value sent by the m-1th user device; and determine the signature private key of the mth user device based on the private key parameters and the second secret value of the m-1th user device; determine the first intermediate value of the mth user device based on the signature private key and the secret random number of the mth user device.

[0184] The device of this embodiment can execute the technical solution in the above method. Its specific implementation process and technical principles are the same and will not be repeated here.

[0185] Figure 6 A schematic diagram of the structure of another collaborative signature device applied to a collaborative signature system provided in an embodiment of the present application is shown as follows: Figure 6As shown, the collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the device is applied to the service device in the collaborative signature system; the device includes:

[0186] A receiving module 601 is configured to receive a first intermediate value sent by another user device; wherein the other user device is each user device other than the mth user device among the m user devices; and the first intermediate value represents a point on a preset elliptic curve corresponding to the user device;

[0187] A first determination module 602 is configured to sum and calculate the first intermediate values ​​of each of the other user devices to obtain an intermediate parameter and determine an auxiliary parameter, wherein the auxiliary parameter represents an auxiliary point corresponding to the serving device on a preset elliptic curve;

[0188] A first sending module 603 is configured to send the intermediate parameters and auxiliary parameters to the mth user equipment; wherein the intermediate parameters and auxiliary parameters are used to generate the first signature and the blinded first signature;

[0189] A second determining module 604 is configured to receive the blinded first signature sent by the m-th user equipment, and determine a second intermediate value of the serving device based on the blinded first signature;

[0190] The second sending module 605 is used to send the second intermediate value of the service device to the mth user device; wherein the second intermediate value of the service device is used to generate a second signature; the first signature and the second signature constitute a collaborative signature; the collaborative signature is used to perform identity authentication processing.

[0191] In a possible implementation, the first determination module 602 is specifically configured to: determine a signature public key, a signature private key of the service device, and a signature random number; and determine auxiliary parameters based on the signature public key, the signature private key of the service device, and the signature random number.

[0192] In one possible implementation, the first determination module 602 is specifically used to: receive the public key parameters sent by the first user device, as well as the key intermediate value and the first secret value of the first user device; and determine the signature public key based on the initial private key of the service device and the key intermediate value of the first user device.

[0193] In a possible implementation, the first determination module 602 is further specifically used to: determine the first secret value of the service device based on the initial private key of the service device and the first secret value of the first user device; determine the second secret value of the service device based on the public key parameters, and the signature private key and the first secret value of the service device; send the signature public key to each user device; and send the second secret value of the service device to the first user device; wherein the signature public key and the second secret value of the service device are used to generate the second secret value of the first user device.

[0194] In one possible implementation, the auxiliary parameter Q0′=(Sk0·k0)·(P+G); Sk0 is the signature private key of the service device; k0 is the signature random number of the service device; G is the base point of the preset elliptic curve; P is the point on the preset elliptic curve corresponding to the signature public key.

[0195] In a possible implementation, the second determination module 604 is specifically configured to determine the second intermediate value of the service device according to the signature private key and the signature random number of the service device and the blinded first signature.

[0196] The device of this embodiment can execute the technical solution in the above method. Its specific implementation process and technical principles are the same and will not be repeated here.

[0197] It should be noted that it should be understood that the division of the various modules of the above device is only a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. And these modules can all be implemented in the form of software called by processing elements; they can also all be implemented in the form of hardware; some modules can also be implemented in the form of software called by processing elements, and some modules can be implemented in the form of hardware. Each module can be a separately established processing element, or it can be integrated into a chip of the above device. In addition, it can also be stored in the memory of the above device in the form of program code, and called by a processing element of the above device to execute the functions of the above modules. In addition, these modules can be fully or partially integrated together, or they can be implemented independently. The processing element here can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each module above can be completed by the hardware integrated logic circuit in the processor element or software instructions.

[0198] Figure 7 A schematic diagram of the structure of a user equipment provided in an embodiment of the present application is shown in FIG. Figure 7 As shown, the user equipment includes: a memory 701 and a processor 702; the memory 701 is used to store instructions executable by the processor 702.

[0199] The processor 702 is configured to execute the method provided in the above embodiment.

[0200] The user equipment further includes a receiver 703 and a transmitter 704. The receiver 703 is used to receive instructions and data sent by other devices, and the transmitter 704 is used to send instructions and data to external devices.

[0201] Figure 8 A schematic diagram of the structure of a service device provided in an embodiment of the present application is shown in FIG. Figure 8 As shown, the service device includes: a memory 801, a processor 802; the memory 801; and a memory for storing instructions executable by the processor 802.

[0202] The processor 802 is configured to execute the method provided in the above embodiment.

[0203] The service device further includes a receiver 803 and a transmitter 804. The receiver 803 is used to receive instructions and data sent by other devices, and the transmitter 804 is used to send instructions and data to external devices.

[0204] An embodiment of the present application also provides a collaborative signature system, which includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the mth user device and the service device in the collaborative signature system are used to execute the technical solution of the collaborative signature method in the above embodiment.

[0205] An embodiment of the present application also provides a chip for executing instructions, which is used to execute the technical solution of the processing method in the above embodiment.

[0206] An embodiment of the present application further provides a computer-readable storage medium, in which computer instructions are stored. When the computer instructions are executed on a computer, the computer executes the technical solution of the processing method of the above embodiment.

[0207] An embodiment of the present application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when at least one processor executes the computer program, it can implement the technical solution of the processing method in the above embodiment.

[0208] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods, such as multiple modules can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or module, which can be electrical, mechanical or other forms.

[0209] Modules described as separate components may or may not be physically separate, and components shown as modules may or may not be physical units, that is, they may be located in one place or distributed across multiple network elements. Some or all of these modules may be selected to implement the solution of this embodiment based on actual needs.

[0210] It should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), or application-specific integrated circuits (ASICs). A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly implemented by a hardware processor or implemented by a combination of hardware and software modules in the processor.

[0211] The storage medium may be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium may be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0212] An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the storage medium can also exist as discrete components in an electronic control unit or a main control device.

[0213] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all optional embodiments, and the actions and modules involved are not necessarily required by this application.

[0214] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0215] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. A collaborative signature method applied to a collaborative signature system, characterized in that: The collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the method is applied to the mth user device in the collaborative signature system; the method includes: determining a first intermediate value of the m-th user equipment; and receiving intermediate parameters and auxiliary parameters sent by the service device; wherein the intermediate parameters and auxiliary parameters are obtained by processing the first intermediate values ​​of other user equipment; the other user equipment is each other user equipment among the m user equipment except the m-th user equipment; the first intermediate value represents a point on a preset elliptic curve corresponding to the user equipment; generating a first signature according to the intermediate parameter, the auxiliary parameter, and the first intermediate value of the m-th user equipment; performing blinding processing on the first signature to obtain a blinded first signature; Sending the blinded first signature to the service device; wherein the blinded first signature is used to generate a second intermediate value of the service device; receiving a second intermediate value sent by the service device; and processing the second intermediate value of the service device and the first signature to obtain a second signature; wherein the first signature and the second signature constitute a collaborative signature; and the collaborative signature is used for identity authentication processing; The processing of the second intermediate value of the service device and the first signature to obtain a second signature includes: Determine a second intermediate value of the mth user equipment according to the second intermediate value of the service device, the first signature, the hidden random number, and the private key parameter and the secret random number of the mth user equipment; The second intermediate value of the mth user equipment and the first signature are sent to the (m-1)th user equipment; wherein the second intermediate value of the mth user equipment and the first signature are used to generate the second signature.

2. The method according to claim 1, characterized in that Generating a first signature according to the intermediate parameter, the auxiliary parameter, and the first intermediate value of the m-th user equipment includes: Determine signature random information according to the hidden random number, the intermediate parameter, the auxiliary parameter, and the first intermediate value of the m-th user equipment; Obtaining information to be signed and determining summary information corresponding to the information to be signed; Generate the first signature according to the summary information and the signature random information.

3. The method according to claim 2, characterized in that The signature random information Q=Q0+Pm+kr·QO ′ ; Wherein, Q0 is the intermediate parameter; QO ′ is the auxiliary parameter; kr is the hidden random number; Pm is the first intermediate value of the mth user equipment.

4. The method according to claim 1, wherein Blinding the first signature to obtain a blinded first signature includes: The first signature is blinded according to the hidden random number to obtain a blinded first signature.

5. The method according to claim 4, characterized in that The first blinded signature r ′ =r·kr -1 ; Wherein, kr is the hidden random number; r is the first signature.

6. The method according to any one of claims 1 to 5, characterized in that Determining a first intermediate value of the m-th user equipment includes: Determining an initial private key of an m-th user device; and determining a key intermediate value of the m-th user device based on the initial private key of the m-th user device; Determining a first secret value of the mth user equipment according to a public key parameter and an initial private key of the mth user equipment; Sending the public key parameter, the key intermediate value, and the first secret value of the m-th user equipment to the m-1-th user equipment; wherein the public key parameter, the key intermediate value, and the first secret value of the m-th user equipment are used to generate a second secret value of the m-1-th user equipment; receiving a second secret value sent by the m-1th user equipment; and determining a signature private key of the m-1th user equipment based on a private key parameter and the second secret value of the m-1th user equipment; Determine a first intermediate value of the mth user equipment according to the signature private key and the secret random number of the mth user equipment.

7. A collaborative signature method applied to a collaborative signature system, characterized in that: The collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the method is applied to the service device in the collaborative signature system; the method includes: Receiving a first intermediate value sent by another user device; wherein the other user device is each user device other than the mth user device among the m user devices; the first intermediate value represents a point on a preset elliptic curve corresponding to the user device; Performing a summation calculation on the first intermediate values ​​of each of the other user devices to obtain an intermediate parameter; and determining an auxiliary parameter; wherein the auxiliary parameter represents an auxiliary point corresponding to the service device on a preset elliptic curve; Sending the intermediate parameters and the auxiliary parameters to the mth user equipment; wherein the intermediate parameters and the auxiliary parameters are used to generate a first signature and a blinded first signature; receiving a blinded first signature sent by the mth user equipment; and determining a second intermediate value of the serving device based on the blinded first signature; Sending the second intermediate value of the service device to the mth user device; wherein the second intermediate value of the service device is used to generate a second signature; the first signature and the second signature constitute a collaborative signature; the collaborative signature is used to perform identity authentication processing; The second intermediate value of the service device is used to obtain the second intermediate value of the m-th user device; the second intermediate value of the m-th user device and the first signature are forwarded to the m-1-th user device to generate the second signature.

8. The method according to claim 7, characterized in that Determine auxiliary parameters, including: Determine a signature public key, a signature private key of the service device, and a signature random number; The auxiliary parameter is determined according to the signature public key, the signature private key of the service device, and the signature random number.

9. The method according to claim 8, characterized in that Determine the signature public key, including: Receiving a public key parameter sent by a first user equipment, as well as a key intermediate value and a first secret value of the first user equipment; The signature public key is determined according to the initial private key of the service device and the key intermediate value of the first user device.

10. The method according to claim 9, characterized in that The method further comprises: Determining a first secret value of the service device according to an initial private key of the service device and a first secret value of the first user device; Determining a second secret value of the service device according to the public key parameter, the signature private key of the service device, and the first secret value; The signature public key is sent to each of the user devices; and the second secret value of the service device is sent to the first user device; wherein the signature public key and the second secret value of the service device are used to generate the second secret value of the first user device.

11. The method according to claim 8, characterized in that The auxiliary parameter Q0 ′ =(Sk0·k0)·(P+G); Sk0 is the signature private key of the service device; k0 is the signature random number of the service device; G is the base point of the preset elliptic curve; P is the point on the preset elliptic curve corresponding to the signature public key.

12. The method according to any one of claims 7 to 11, characterized in that Determining a second intermediate value of the serving device according to the blinded first signature includes: A second intermediate value of the service device is determined according to the signature private key and the signature random number of the service device and the blinded first signature.

13. A collaborative signature device applied to a collaborative signature system, characterized in that: The collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the device is applied to the mth user device in the collaborative signature system; the device is used to execute the method as described in any one of claims 1-6.

14. A collaborative signature device applied to a collaborative signature system, characterized in that: The collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the device is applied to the service device in the collaborative signature system; the device is used to execute the method according to any one of claims 7 to 12.

15. A user equipment, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 6.

16. A service device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 7 to 12.

17. A collaborative signature system, characterized in that: The collaborative signature system includes a service device and m user devices, where m is a positive integer greater than or equal to 2; the mth user device in the collaborative signature system is used to implement the method as described in any one of claims 1 to 6; and the service device is used to implement the method as described in any one of claims 7 to 12.

18. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 6 or the method according to any one of claims 7 to 12 when executed by a processor.

19. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the method according to any one of claims 1 to 6 or the method according to any one of claims 7 to 12.