Method and system for verifiable oblivious transmission of messages based on national secret algorithm
By introducing a message validation mechanism based on the Guomi algorithm in the inadvertent transmission protocol, the verification points on the elliptic curve ensure the effectiveness of message delivery, the problem of message non-verification in the existing technology is solved, and the computing efficiency and reliability are improved.
Patent Information
- Application Number
- CN202411746988.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-02
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-02
AI Technical Summary
The existing inadvertent transmission protocol cannot verify the validity of the sender's message, and there is a risk of an attacker or malicious sender forgery or tampering with the message, causing the receiver to receive the wrong message and cause the calculation error.
The inadvertent transmission method that can be verified by message based on the national secret algorithm is adopted. By generating and verifying verification points on the elliptic curve, the validity verification during the message delivery process is ensured, and a random key is generated for message encryption and decryption.
It realizes validation of messages during inadvertent transmission, avoids invalid calculations, improves computing efficiency and reliability, and ensures that the receiver only receives the correct messages.
Smart Images

Figure CN119232378B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a method and system for verifiable oblivious transmission of messages based on a national secret algorithm. Background Art
[0002] The Oblivious Transfer (OT) protocol is an important basic tool for secure multi-party computing. Any secure multi-party computing protocol can be constructed based on the Oblivious Transfer protocol to achieve privacy-protected message transmission between the sender and the receiver. The sender uses the receiver's public key and other information to encrypt or hide the multiple messages it wants to send, so that only the receiver can receive the message corresponding to the index it secretly promised in advance. The Oblivious Transfer protocol ensures that the sender does not know which message the receiver has received, the receiver does not know messages other than the received message, and any third party does not know the messages transmitted during the communication process. These methods help solve the problem of insufficient privacy in multi-party joint data analysis solutions and can protect the privacy of all parties.
[0003] The existing oblivious transfer protocol can only ensure the confidentiality and correctness of the sender's message transmission, but cannot verify the validity of the sender's message. If an attacker or malicious sender forges or tampers with the message transmitted by the protocol to cause the receiver to receive an incorrect message and cause errors in subsequent calculations, it will increase the cost of computational analysis and produce unreliable results. Therefore, an oblivious transfer method is urgently needed to solve the problem of message unverifiability in such scenarios. Summary of the invention
[0004] Based on this, it is necessary to provide a verifiable oblivious transmission method and system for messages based on a national encryption algorithm that can verify the validity of the messages in order to address the above technical issues.
[0005] In the first aspect, a method for verifiable oblivious transmission of messages based on a national encryption algorithm is provided in this embodiment, including:
[0006] generating a first key pair and a first identity identifier based on the negotiated parameters;
[0007] Based on the elliptic curve in the negotiation parameter, generate a first random point; and transmit the first random point to a receiving party;
[0008] Obtaining a second random point and a third random point transmitted by the receiving party;
[0009] Generate a first verification point and a second verification point using a key agreement algorithm based on the first random point, the second random point, the third random point, the negotiation parameter, the first key pair, and the first identity identifier;
[0010] The validity of the first verification point and the second verification point is verified by using the infinity point of the elliptic curve; and a first random key and a second random key are generated based on the first verification point and the second verification point that have passed the validity verification.
[0011] In some embodiments, generating the first verification point and the second verification point by using a key agreement algorithm based on the first random point, the second random point, the third random point, the negotiation parameter, the first key pair, and the first identity identifier includes:
[0012] Generate a first temporary random point and a second temporary random point based on the second random point, the third random point and a random function;
[0013] The first random point and the first temporary random point and the second temporary random point that are verified to satisfy the elliptic curve are calculated by using a key agreement algorithm to generate a first verification point and a second verification point.
[0014] In some embodiments, the step of calculating the first random point and verifying the first temporary random point and the second temporary random point satisfying the elliptic curve by using a key agreement algorithm to generate a first verification point and a second verification point includes:
[0015] Parsing the first random point, the first temporary random point and the second temporary random point to obtain coordinate data;
[0016] Extracting the horizontal coordinate in the coordinate data, and converting the horizontal coordinate into an integer;
[0017] The first verification point and the second verification point are calculated based on the converted horizontal coordinate, the first identity identifier, the first temporary random point, the second temporary random point and the first key pair.
[0018] In some of the embodiments, it also includes:
[0019] Based on the first random key and the second random key, the first message and the second message are encrypted; and the encrypted first message and the second message are transmitted to the receiving party.
[0020] In the second aspect, in this embodiment, a method for verifiable oblivious transmission of messages based on a national encryption algorithm is provided, including:
[0021] generating a second key pair and a second identity identifier based on the negotiated parameters;
[0022] Based on the elliptic curve in the negotiation parameters, generate a second random point and a third random point; and transmit the second random point and the third random point to the sender;
[0023] Obtaining a first random point transmitted by the sender;
[0024] Generate a third verification point using a key agreement algorithm based on the first random point, the negotiation parameter, the second key pair, and the second identity identifier;
[0025] The validity of the third verification point is verified by using the infinity point of the elliptic curve; and a third random key is generated based on the third verification point that passes the validity verification.
[0026] In some embodiments, generating a third verification point using a key negotiation algorithm based on the first random point, the negotiation parameter, the second key pair, and the second identity identifier includes:
[0027] Parse the first random point that satisfies the elliptic curve to obtain coordinate data;
[0028] Extracting the horizontal coordinate in the coordinate data, and converting the horizontal coordinate into an integer;
[0029] The third verification point is calculated based on the converted horizontal coordinate, the second identity identifier, the first random point and the second key pair.
[0030] In some of the embodiments, it also includes:
[0031] Obtaining a first message and a second message transmitted by the sender;
[0032] Based on the third random key, the first message or the second message is correspondingly selected for decryption to obtain the first message or the second message.
[0033] In a third aspect, in this embodiment, a message verifiable oblivious transmission system based on a national secret algorithm is provided, including:
[0034] A first negotiation module, configured to generate a first key pair and a first identity identifier based on a negotiation parameter;
[0035] A first verification module is configured to generate a first random point based on the elliptic curve in the negotiation parameters; and transmit the first random point to a receiver; obtain a second random point and a third random point transmitted by the receiver; generate a first verification point and a second verification point using a key negotiation algorithm based on the first random point, the second random point, the third random point, the negotiation parameters, the first key pair, and the first identity identifier; and verify the validity of the first verification point and the second verification point using an infinity point of the elliptic curve;
[0036] The first generating module is used to generate a first random key and a second random key based on a first verification point and a second verification point that pass the validity verification.
[0037] In a fourth aspect, in this embodiment, a message verifiable oblivious transmission system based on a national encryption algorithm is provided, including:
[0038] A second negotiation module, configured to generate a second key pair and a second identity identifier based on the negotiation parameters;
[0039] A second verification module is configured to generate a second random point and a third random point based on the elliptic curve in the negotiation parameters; and transmit the second random point and the third random point to the sender; obtain the first random point transmitted by the sender; generate a third verification point using a key negotiation algorithm based on the first random point, the negotiation parameters, the second key pair and the second identity identifier; and verify the validity of the third verification point using the infinity point of the elliptic curve;
[0040] The second generating module is used to generate a third random key based on a third verification point that passes the validity verification.
[0041] In a fifth aspect, a computer device is provided in this embodiment, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the computer program, the method for verifiable oblivious transmission of messages based on the national encryption algorithm as described in the first or second aspect above is implemented.
[0042] In a sixth aspect, in this embodiment, a storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the method for verifiable oblivious transmission of messages based on a national encryption algorithm as described in the first or second aspect above is implemented.
[0043] Compared with the related art, the message verifiable oblivious transmission method and system based on the national secret algorithm provided in this embodiment generates a first key pair and a first identity identifier based on the negotiation parameters; generates a first random point based on the elliptic curve in the negotiation parameters; and transmits the first random point to the receiver; obtains the second random point and the third random point transmitted by the receiver; generates a first verification point and a second verification point using the key negotiation algorithm based on the first random point, the second random point, the third random point, the negotiation parameters, the first key pair and the first identity identifier; verifies the validity of the first verification point and the second verification point using the infinity point of the elliptic curve; and generates a first random key and a second random key based on the first verification point and the second verification point that pass the validity verification. Through this embodiment, the message validity verification can be performed using the infinity point of the elliptic curve in the key negotiation algorithm, and the message verifiability is realized in the oblivious transmission method, thereby avoiding invalid calculations and improving calculation efficiency and reliability.
[0044] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0046] Figure 1 is a hardware structure block diagram of a terminal of a message verifiable oblivious transmission method based on a national encryption algorithm in an embodiment;
[0047] Figure 2 is a flow chart of a method for verifiable oblivious transmission of messages based on a national encryption algorithm in one embodiment;
[0048] Figure 3 is a flow chart of a method for verifiable oblivious transmission of messages based on a national encryption algorithm in another embodiment;
[0049] Figure 4 is a schematic diagram of two rounds of message transmission between a sender and a receiver in one embodiment;
[0050] Figure 5 is a structural block diagram of a message verifiable oblivious transmission system based on a national secret algorithm in an embodiment;
[0051] Figure 6 It is a structural block diagram of a message verifiable oblivious transmission system based on a national encryption algorithm in another embodiment.
[0052] In the figure: 102, processor; 104, memory; 106, transmission device; 108, input and output device; 10, first negotiation module; 20, first verification module; 30, first generation module; 40, second negotiation module; 50, second verification module; 60, second generation module. DETAILED DESCRIPTION
[0053] In order to more clearly understand the purpose, technical solutions and advantages of the present application, the present application is described and illustrated below in conjunction with the accompanying drawings and embodiments.
[0054] Unless otherwise defined, the technical terms or scientific terms involved in this application shall have the general meaning understood by people with general skills in the technical field to which this application belongs. The words "one", "a", "the", "these" and the like in this application do not indicate a quantitative limitation, and they may be singular or plural. The terms "include", "comprise", "have" and any variants thereof involved in this application are intended to cover non-exclusive inclusions; for example, a process, method and system, product or device comprising a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent to these processes, methods, products or devices. The words "connect", "connected", "coupled" and the like involved in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The "multiple" involved in this application refers to two or more. "And / or" describes the association relationship of associated objects, indicating that there may be three relationships, for example, "A and / or B" may mean: A exists alone, A and B exist at the same time, and B exists alone. Generally, the character " / " indicates that the objects associated with each other are in an "or" relationship. The terms "first", "second", "third", etc. in this application are only used to distinguish similar objects and do not represent a specific ordering of the objects.
[0055] The method embodiment provided in this embodiment can be executed in a terminal, a computer or a similar computing device. For example, running on a terminal, Figure 1 1 is a hardware structure block diagram of a terminal of the method for oblivious transmission of messages with verifiable information based on the national encryption algorithm of this embodiment. Figure 1 As shown, the terminal may include one or more ( Figure 1 Only one is shown in the figure) a processor 102 and a memory 104 for storing data, wherein the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA. The above terminal may also include a transmission device 106 and an input and output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above terminal. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations shown.
[0056] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the message verifiable oblivious transmission method based on the national secret algorithm in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, to implement the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0057] The transmission device 106 is used to receive or send data via a network. The above network includes a wireless network provided by the communication provider of the terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (Radio Frequency, referred to as RF) module, which is used to communicate with the Internet wirelessly.
[0058] The Oblivious Transfer (OT) protocol is an important basic tool for secure multi-party computing. Any secure multi-party computing protocol can be constructed based on the Oblivious Transfer protocol to achieve privacy-protected message transmission between the sender and the receiver. The sender uses the receiver's public key and other information to encrypt or hide the multiple messages it wants to send, so that only the receiver can receive the message corresponding to the index it secretly promised in advance. The Oblivious Transfer protocol ensures that the sender does not know which message the receiver has received, the receiver does not know messages other than the received message, and any third party does not know the messages transmitted during the communication process. These methods help solve the problem of insufficient privacy in multi-party joint data analysis solutions and can protect the privacy of all parties.
[0059] The existing oblivious transfer protocol can only ensure the confidentiality and correctness of the sender's message transmission, but cannot verify the validity of the sender's message. If an attacker or malicious sender forges or tampers with the message transmitted by the protocol to cause the receiver to receive an incorrect message and cause errors in subsequent calculations, it will increase the cost of computational analysis and produce unreliable results. Therefore, an oblivious transfer method is urgently needed to solve the problem of message unverifiability in such scenarios.
[0060] In this embodiment, a method for verifiable oblivious transmission of messages based on a national encryption algorithm is provided. The method is applied to the sender. Figure 2 is a flow chart of the method for verifiable oblivious transmission of messages based on the national encryption algorithm in this embodiment, such as Figure 2 As shown, the method comprises the following steps:
[0061] Step S210: Generate a first key pair and a first identity identifier based on the negotiation parameters.
[0062] Specifically, the sender and the receiver negotiate in advance to obtain the negotiation parameters of Elliptic Curve Cryptography (ECC). The negotiation parameters include the finite field F p , where p is a prime number; the elliptic curve E p The parameters a and b of (a,b) determine a specific elliptic curve, whose equation is expressed as y 2 =x 3 +ax+b, a, b belong to the finite field F p ; The base point G=(x0,y0) on the elliptic curve and the order n of the base point, where n is a prime number of w bits; performing exponential operations on the elliptic curve using the base point G and any value in the set N-1 (the set of all natural numbers from 1 to n-1) can yield a point on the elliptic curve; the point O at infinity, which is the identity element of the elliptic curve additive group; the auxiliary factor h (whose value is equal to the number of all points on the elliptic curve divided by n); the key length klen, which is set to the length of the message transmitted by the oblivious transfer protocol.
[0063] Generate the sender's long-term first key pair (sk S ,pk S ) and the first identity identifier h S Among them, two random numbers sk are uniformly randomly selected from the set N-1 S ,sk R , respectively as the long-term private keys required by the sender and receiver of the oblivious transfer protocol. Using the base point G and sk S ,sk R Perform elliptic curve exponential operations to obtain pkS =sk S G=(x S ,y S ), pk R =sk R G=(x R ,y R ), pk S and pk R As the long-term public key of the sender and the receiver respectively. The sender’s first identity identifier h is calculated by hashing S , optional, use the national secret SM3 to calculate the first identity h S ,h S =SM3(l IDS ,ID S ,a,b,x0,y0,x S ,y S ), where l IDS Indicates the sender's ID S Length, h S The length of the .
[0064] Step S220: Generate a first random point based on the elliptic curve in the negotiation parameters; and transmit the first random point to the receiver.
[0065] Specifically, in the first round of message transmission between the sender and the receiver, based on the elliptic curve in the negotiation parameters, the sender generates a first random point on the elliptic curve, and transmits the first random point to the receiver. The receiver uses the first random point to generate a random key, which can be used for message decryption.
[0066] Among them, using the first random number r S ∈[1,n-1], generate the first random point P on the elliptic curve S =r S G = (x1, y1), where r S G represents taking G as the base point, according to the first random number r S Compute a point on an elliptic curve.
[0067] Step S230, obtaining the second random point and the third random point transmitted by the receiver.
[0068] Specifically, in the oblivious transmission, the operations performed in the sender and the receiver are symmetrical. Accordingly, the receiver generates the associated second random point and the third random point using the elliptic curve and transmits them to the sender. The second random point and the third random point are used to subsequently generate two corresponding random keys at the sender.
[0069] It should be noted that in the first round of message transmission between the sender and the receiver, since the first round of messages sent by both parties do not depend on the messages sent by the other party, the sender transmits the first random point and the receiver transmits the second random point and the third random point simultaneously.
[0070] Step S240: Generate a first verification point and a second verification point using a key negotiation algorithm based on the first random point, the second random point, the third random point, the negotiation parameters, the first key pair, and the first identity identifier.
[0071] Specifically, the sender uses the key agreement algorithm to perform local calculations to generate two verification points related to the message transmission between the sender and the receiver. A random key can be further generated based on the verification points, and the random key can be used for the second round of message transmission between the sender and the receiver. Among them, the key agreement algorithm includes but is not limited to the national secret SM2, the elliptic curve Diffie-Hellman (Diffie-Hellman key exchange) algorithm, the elliptic curve ElGamal algorithm (an asymmetric encryption algorithm) and other key agreement algorithms based on elliptic curve cryptography.
[0072] Based on the second random point, the third random point and the two random functions, a first temporary random point and a second temporary random point are generated that are correlated with the second random point and the third random point. Correspondingly, the first temporary random point and the second temporary random point are also associated with each other, and then the first verification point and the second verification point that are associated are calculated using the key agreement algorithm. Since the second random point and the third random point are transmitted by the receiver, it is also necessary to first verify whether the first temporary random point and the second temporary random point satisfy the equation of the elliptic curve. If not, the execution is terminated; if satisfied, the first verification point and the second verification point are generated based on the first temporary random point and the second temporary random point.
[0073] Step S250, using the infinity point of the elliptic curve to verify the validity of the first verification point and the second verification point; and generating a first random key and a second random key based on the first verification point and the second verification point that have passed the validity verification.
[0074] Specifically, since the infinity point of the elliptic curve has a characteristic: when a point on the elliptic curve is added to the infinity point, the result is still the point itself. The first verification point and the second verification point are verified using the infinity point. If the first verification point and the second verification point are infinity points, the validity verification fails, and the random keys generated based on the first verification point and the second verification point are not random and are invalid. Therefore, the first random key and the second random key are generated based on the first verification point and the second verification point that pass the validity verification, and the first random key and the second random key can be used for the second round of message transmission by the sender.
[0075] It should be noted that in this embodiment, the two random keys generated by the sender are associated with each other, but the key is not directly determined by the second random point and the third random point sent by the sender, and it is also random, which ensures the security of the key and can be applied to the basic oblivious transmission of two-choice, that is, the sender sends two messages (m0, m1), the receiver selects an input (usually 0 or 1), and obtains the corresponding output information (m0 or m1) according to the input. Furthermore, the basic oblivious protocol can be expanded to N-choice oblivious transmission, that is, the sender sends N messages, the receiver selects an input and obtains the corresponding output information, and accordingly, it can be expanded to generate N random keys corresponding to the sender. In order to improve the efficiency of oblivious transmission, batch transmission and parallel transmission can also be adopted on the basis of the above basic oblivious transmission.
[0076] Through the above steps, the message validity can be verified on the first verification point and the second verification point using the infinity point of the elliptic curve in the key agreement algorithm, and the message verifiability is achieved in the oblivious transmission method, thereby avoiding invalid calculations. Moreover, even if there is a malicious message sender in the oblivious transmission, the receiver will not receive an erroneous message after the message validity verification, thereby improving the calculation efficiency and reliability.
[0077] In some embodiments, the step S240 generates the first verification point and the second verification point by using a key agreement algorithm based on the first random point, the second random point, the third random point, the negotiation parameter, the first key pair and the first identity identifier, including the following steps:
[0078] Step S241, generating a first temporary random point and a second temporary random point based on the second random point, the third random point and the random function.
[0079] Specifically, two different random functions f0 and f1 are generated in advance, wherein the random functions f0 and f1 are used to convert the elliptic curve E p A point (a,b) is randomly mapped to E p Another point on (a,b).
[0080] The following is to generate the first temporary random point P R,0 and the second temporary random point P R,1 Calculation method:
[0081]
[0082] Among them, R0 is the second random point; R1 is the third random point.
[0083] Step S242, using the key agreement algorithm, calculate the first random point and verify the first temporary random point and the second temporary random point that satisfy the elliptic curve to generate a first verification point and a second verification point.
[0084] Specifically, since the second random point and the third random point are transmitted by the receiver, it is necessary to first verify whether the first temporary random point and the second temporary random point satisfy the equation of the elliptic curve. If not, the execution is terminated; if they are satisfied, the first verification point and the second verification point are generated according to the first temporary random point and the second temporary random point. Taking the key agreement algorithm of SM2 as an example, the GenPoint point generation algorithm of SM2 is used to calculate the first verification point P0=GenPoint(r S ,P S ,P R,0 ,sk S ,pk R ) and the second verification point P1=GenPoint(r S ,P S ,P R,1 ,sk S ,pk R ), where r S is the first random number; P S is the first random point; P R,0 is the first temporary random point; P R,1 is the second temporary random point; sk S , pk S The sender's private key and public key, sk R , pk R The private and public keys of the recipient.
[0085] In this embodiment, two efficient random functions are used to replace the complex cryptographic tools in existing similar schemes, such as batch N-dimensional one-time programmable public functions, so the computational efficiency is high when generating the first verification point and the second verification point, thereby achieving a significant improvement in both computation and communication. In addition, the randomness of the first temporary random point and the second temporary random point is also guaranteed to improve the security of the subsequent generation of random keys.
[0086] In some embodiments, the key agreement algorithm is used in step S242 to calculate the first random point and the first temporary random point and the second temporary random point that verify the elliptic curve to generate the first verification point and the second verification point, including the following steps:
[0087] Analyze the first random point, the first temporary random point, and the second temporary random point to obtain coordinate data;
[0088] Extract the horizontal coordinate from the coordinate data and convert the horizontal coordinate into an integer;
[0089] A first verification point and a second verification point are calculated based on the converted horizontal coordinate, the first identity identifier, the first temporary random point, the second temporary random point and the first key pair.
[0090] Specifically, taking the national secret SM2 algorithm as an example, the specific execution process of the point generation algorithm GenPoint is as follows: First, verify the first temporary random point P R,0 and the second temporary random point P R,1 Does it satisfy the equation of the elliptic curve? If not, the execution is terminated; if it is satisfied, the first random point P is S , the first temporary random point P R,0 , the second temporary random point P R,1 Parse it into the form of horizontal and vertical coordinates to obtain the coordinate data, which can be expressed as (x1, y1), (x2, y2), (x3, y3). Take the domain elements x1, x2, x3 from the horizontal coordinates, and convert the data types of x1, x2, x3 from bits to integers, that is, perform the following calculations:
[0091]
[0092] Among them, " ̄" indicates data type conversion; w indicates the number of bits to be converted; "+" indicates addition; "&" indicates that the strings on the left and right sides of "&" are logically ANDed bit by bit from high bit to low bit according to the number of bits to be converted, and the values of the corresponding bits are added. For example, x1 is an 8-bit string 1111000, and the string 11111111 after "&" operation conversion is 11110000, and the corresponding integer is 2^7+1×2^6+1×2^5+1×2^4+0×2^3+0×2^2+0×2^1+0×2^0=240.
[0093] Secondly, the following intermediate variable t is performed R1 and t R2 calculate:
[0094]
[0095] Among them, r S is the first random number; sk S is the sender's private key; n is the order of the base point; mod represents the modulo operation.
[0096] Then, the coordinates (x v 0 ,y v 0 ) and (x v 1 ,y v1 ):
[0097]
[0098] Where h is the auxiliary factor; t R1 and t R2 is the intermediate variable; P R,0 and P R,1 is the first temporary random point and the second temporary random point; pk R is the recipient's public key; is the horizontal coordinate after transformation.
[0099] In this embodiment, the first verification point and the second verification point are generated by the point generation algorithm GenPoint of the national secret SM2, so as to use the infinity point for validity verification in the subsequent process, thus realizing the validity verification in the oblivious transmission. In addition, since the key length of the cryptographic algorithm based on the elliptic curve is relatively short, the information length of the first round of communication in the oblivious transmission is relatively short, which can reduce the communication volume by about half compared with the protocol based on assumptions such as RSA (asymmetric encryption algorithm), thereby improving the computing efficiency.
[0100] In some embodiments, generating the first random key and the second random key based on the first verification point and the second verification point that pass the validity verification in step S250 includes:
[0101] If the first verification point P0 and the second verification point P1 are the infinite points on the elliptic curve, the verification fails and the negotiation fails. If the first verification point P0 and the second verification point P1 are not the infinite points on the elliptic curve, the verification passes and the above coordinates x v 0 ,y v 0 ,x v 1 ,y v 1 The data type is converted into a bit string, and the first random key k0 and the second random key k1 are calculated and generated according to the first verification point and the second verification point:
[0102]
[0103] Among them, h S is the first identity identifier of the sender; R It is the second identity identifier of the recipient; klen indicates the password length; GenKey is the key generation algorithm of SM2.
[0104] In this embodiment, the first random key and the second random key are generated according to the first verification point and the second verification point that have passed the validity verification, so that the generated random keys have relevance and validity, while also ensuring random security, and can be applicable to message encryption in inadvertent transmission.
[0105] In some of the embodiments, it also includes:
[0106] The first message and the second message are encrypted based on the first random key and the second random key; and the encrypted first message and the second message are transmitted to the receiving party.
[0107] Specifically, in the second round of messages between the sender and the receiver, the input first message and the second message are encrypted using the above first random key and the second random key.
[0108] The encryption process of the encrypted first message a0 and the encrypted second message a1 is calculated as follows:
[0109]
[0110] in, represents a string XOR operation; k0 and k1 are the first random key and the second random key; m0 and m1 are the first message and the second message.
[0111] The first message and the second message may be private data interacted in different secure multi-party computing scenarios. For example, in secure multi-party computing scenarios such as joint marketing in the financial field and data sharing in the medical field, the private data may be credit information or medical information authorized for use by users or relevant institutions.
[0112] In this embodiment, the input message is encrypted using two generated random keys. Since the random keys k0 and k1 generated in the first round of transmission are only used once, this operation is a one-time one-key encryption, which has higher security.
[0113] In this embodiment, a method for verifiable oblivious transmission of messages based on a national encryption algorithm is also provided, and the method is applied to a receiver. Figure 3 is a flow chart of the method for verifiable oblivious transmission of messages based on the national encryption algorithm in this embodiment, such as Figure 3 As shown, the method comprises the following steps:
[0114] Step S310: Generate a second key pair and a second identity identifier based on the negotiation parameters.
[0115] Specifically, the sender and the receiver negotiate in advance to obtain the negotiation parameters of Elliptic Curve Cryptography (ECC). The negotiation parameters include the finite field Fp , where p is a prime number; the elliptic curve E p The parameters a and b of (a,b) determine a specific elliptic curve, whose equation is expressed as y 2 =x 3 +ax+b, a, b belong to the finite field F p ; The base point G=(x0,y0) on the elliptic curve and the order n of the base point, where n is a prime number of w bits; performing exponential operations on the elliptic curve using the base point G and any value in the set N-1 (the set of all natural numbers from 1 to n-1) can yield a point on the elliptic curve; the point O at infinity, which is the identity element of the elliptic curve additive group; the auxiliary factor h (whose value is equal to the number of all points on the elliptic curve divided by n); the key length klen, which is set to the length of the message transmitted by the oblivious transfer protocol.
[0116] Generate the recipient's long-term second key pair (sk R ,pk R ) and the second identity identifier h R Among them, two random numbers sk are uniformly randomly selected from the set N-1 S ,sk R , respectively as the long-term private keys required by the sender and receiver of the oblivious transfer protocol. Using the base point G and sk S ,sk R Perform elliptic curve exponential operations to obtain pk S =sk S G=(x S ,y S ), pk R =sk R G=(x R ,y R ), pk S and pk R As the long-term public key of the sender and the receiver respectively. The sender’s second identity identifier h is calculated by hashing R , optional, use the national secret SM3 to calculate the second identity h R ,h R =SM3(l IDR ,ID R ,a,b,x0,y0,x R ,y R ), where l IDR Indicates the recipient's identity identifier ID R Length, h R The length of the .
[0117] Step S320: Generate a second random point and a third random point based on the elliptic curve in the negotiation parameters; and transmit the second random point and the third random point to the sender.
[0118] Specifically, in the first round of message transmission between the sender and the receiver, based on the elliptic curve in the negotiation parameters, the second random point and the third random point of the receiver on the elliptic curve are generated, and the second random point and the third random point are transmitted to the sender. The sender uses the second random point and the third random point to generate a random key, which can be used for message encryption.
[0119] First, uniformly select the second random number r R ∈[1,n-1], generate the fourth random point P on the elliptic curve R =r R G=(x2,y2). Next, randomly select a value r from the set N-1. 1-c , calculate the corresponding point R on the elliptic curve based on the base point G 1-c Then, using the fourth random point P R and the random function f c Calculate another point R c =P R -f c (R 1-c ), the second random point R0 and the third random point R1 associated with the input bit index c (c is 0 or 1) of the receiver are generated and sent to the sender, and the second random point and the third random point are associated with each other.
[0120] Step S330, obtaining the first random point transmitted by the sender.
[0121] Specifically, in the oblivious transmission, the operations performed in the sender and the receiver are symmetrical. Accordingly, the sender generates a first random point using an elliptic curve and transmits it to the sender. The first random point is used to subsequently generate a corresponding random key at the receiver.
[0122] It should be noted that in the first round of message transmission between the sender and the receiver, since the first round of messages sent by both parties do not depend on the messages sent by the other party, the sender transmits the first random point and the receiver transmits the second random point and the third random point simultaneously.
[0123] Step S340: Generate a third verification point using a key negotiation algorithm based on the first random point, the negotiation parameter, the second key pair and the second identity identifier.
[0124] Specifically, the receiver uses the key agreement algorithm to perform local calculations to generate a third verification point related to the message transmitted between the sender and the receiver. A random key can be further generated based on the verification point, and the random key can be used for the second round of message transmission between the sender and the receiver. Among them, the key agreement algorithm includes but is not limited to the national secret SM2, the elliptic curve Diffie-Hellman (Diffie-Hellman key exchange) algorithm, the elliptic curve ElGamal algorithm (an asymmetric encryption algorithm) and other key agreement algorithms based on elliptic curve cryptography.
[0125] Since the first random point is transmitted by the sender, it is also necessary to verify whether the first random point satisfies the equation of the elliptic curve. If not, the execution is terminated; if it is satisfied, the third verification point is generated based on the first random point.
[0126] Step S350, using the infinity point of the elliptic curve to verify the validity of the third verification point; and generating a third random key based on the third verification point that passes the validity verification.
[0127] Specifically, since the infinity point of the elliptic curve has a characteristic: when a point on the elliptic curve is added to the infinity point, the result is still the point itself. The third verification point is verified using the infinity point. If the third verification point is an infinity point, it fails the validity verification, and the random key generated based on the third verification point is not random and is invalid. Therefore, the third random key is generated based on the third verification point that passes the validity verification. The receiver calculates the one of the two keys generated by the sender with index c, that is, the third random key, which is used to decrypt the message received in the second round.
[0128] Through the above steps, the message validity can be verified on the third verification point using the infinity point of the elliptic curve in the key agreement algorithm, and the message verifiability is achieved in the oblivious transmission method, thereby avoiding invalid calculations and improving calculation efficiency and reliability.
[0129] In some embodiments, the step S340 generates the third verification point using a key agreement algorithm based on the first random point, the negotiation parameter, the second key pair, and the second identity identifier, including the following steps:
[0130] Step S341, parsing the first random point that satisfies the elliptic curve to obtain coordinate data;
[0131] Step S342, extracting the horizontal coordinate in the coordinate data, and converting the horizontal coordinate into an integer;
[0132] Step S343, calculating a third verification point based on the converted horizontal coordinate, the second identity identifier, the first random point and the second key pair.
[0133] Specifically, verify the first random point P S Does it satisfy the equation of the elliptic curve? If not, the execution is terminated; if it is satisfied, the first random point P is S and the fourth random point P R Parse it into the form of horizontal and vertical coordinates to obtain the coordinate data, which can be expressed as (x1, y1). Take the domain elements x1 and x2 from the horizontal coordinates, and convert the data types of x1 and x2 from bits to integers, that is, perform the following calculations:
[0134]
[0135] Among them, " ̄" indicates data type conversion; w indicates the number of bits to be converted; "+" indicates addition; "&" indicates that the strings on the left and right sides of "&" are logically ANDed bit by bit from high bit to low bit according to the number of bits to be converted, and the values of the corresponding bits are added. For example, x1 is an 8-bit string 1111000, and the string 11111111 after "&" operation conversion is 11110000, and the corresponding integer is 2^7+1×2^6+1×2^5+1×2^4+0×2^3+0×2^2+0×2^1+0×2^0=240.
[0136] Secondly, the following intermediate variable t is performed S calculate:
[0137]
[0138] Among them, r R is the second random number; sk R is the recipient's private key; n is the order of the base point; mod represents the modulo operation.
[0139] Then, calculate the third verification point P on the elliptic curve c Coordinate (x u ,y u ):
[0140]
[0141] Where h is the auxiliary factor; t S is the intermediate variable; P S is the first random point; pk S Sender's public key; is the horizontal coordinate after transformation.
[0142] In this embodiment, the third verification point is generated to verify the validity of the infinity point in the future, thus realizing the validity verification in the oblivious transmission. In addition, since the key length of the cryptographic algorithm based on the elliptic curve is relatively short, the information length of the first round of communication in the oblivious transmission is relatively short, which can reduce the communication volume by about half compared with the protocol based on assumptions such as RSA (asymmetric encryption algorithm), thereby improving the computing efficiency.
[0143] In some embodiments, the step S350 uses the infinity point of the elliptic curve to verify the validity of the third verification point; and generates a third random key based on the third verification point that passes the validity verification, including:
[0144] If the third verification point P is verified c is a point at infinity on the elliptic curve, the verification fails and the negotiation fails. c If it is not a point at infinity on the elliptic curve, the verification is successful. u ,y u The data type is converted into a bit string, and a third random key k is generated based on the third verification point. c :
[0145]
[0146] Among them, h S is the first identity identifier of the sender; R It is the second identity identifier of the recipient; klen indicates the password length; GenKey is the key generation algorithm of SM2.
[0147] In this embodiment, a third random key is generated based on the third verification point that has passed the validity verification, so that the receiver calculates the one with index c among the two keys generated by the sender, that is, the third random key, which is used to decrypt the message received in the second round.
[0148] In some embodiments, the method further comprises:
[0149] Obtaining a first message and a second message transmitted by a sender;
[0150] Based on the third random key, the first message or the second message is correspondingly selected for decryption to obtain the first message or the second message.
[0151] Specifically, in the second round of messages between the sender and the receiver, the input first message or second message is decrypted using the third random key and the receiver's index c.
[0152] The decryption process is calculated as follows:
[0153]
[0154] in, Indicates string XOR operation; k c is the third random key; the index c takes the value of 0 or 1, m c is one of the first message and the second message.
[0155] The present embodiment is described and illustrated below through preferred embodiments.
[0156] This embodiment provides a flowchart of a method for verifiable oblivious transmission of a message based on a national encryption algorithm, the method comprising the following steps:
[0157] Step S410: The sender and the receiver negotiate in advance to obtain negotiation parameters.
[0158] Figure 4 It is a schematic diagram of two rounds of message transmission between the sender and the receiver, such as Figure 4 As shown, the two parties negotiate parameters in advance, and the negotiated parameters include the finite field F p , where p is a prime number; the elliptic curve E p The parameters a and b of (a,b) determine a specific elliptic curve, whose equation is expressed as y 2 =x 3 +ax+b, a, b belong to the finite field F p ; The base point G=(x0,y0) on the elliptic curve and the order n of the base point, where n is a prime number of w bits; performing exponential operations on the elliptic curve using the base point G and any value in the set N-1 (the set of all natural numbers from 1 to n-1) can yield a point on the elliptic curve; the point O at infinity, which is the identity element of the elliptic curve additive group; the auxiliary factor h (whose value is equal to the number of all points on the elliptic curve divided by n); the key length klen, which is set to the length of the message transmitted by the oblivious transfer protocol.
[0159] Step S420: Generate a first key pair and a first identity identifier of the sender, and a second key pair and a second identity identifier of the receiver based on the negotiation parameters.
[0160] like Figure 4 As shown, at the sender and the receiver, two random numbers sk are selected from the set N-1 S ,sk R As the private key, perform elliptic curve exponentiation to obtain the public key pk S =sk S G=(x S ,y S ), pk R =sk R G=(x R ,yR ), and use the national secret SM3 to calculate the first identity identifier h S =SM3(l IDS ,ID S ,a,b,x0,y0,x S ,y S ) and h R =SM3(l IDR ,ID R ,a,b,x0,y0,x R ,y R ).
[0161] Step S430: The sender selects a random number to generate a first random point on the elliptic curve, and sends it to the receiver.
[0162] like Figure 4 As shown, a value r is randomly selected from the set N-1 S , generate the first random point P on the elliptic curve S =r S G=(x1,y1).
[0163] Step S440: The receiver selects a random number to generate a second random point, a third random point, and a fourth random point on the elliptic curve, and sends the second random point and the third random point to the sender.
[0164] like Figure 4 As shown, two values r are randomly selected from the set N-1 R and r 1-c , generate a fourth random point P on the elliptic curve R =r R G=(x2,y2), then calculate another random point R c =P R -f c (R 1-c ), the index c takes the value 0 or 1, and the second random point R0 and the third random point R1 are obtained.
[0165] In step S450, the sender performs local calculation and generates a first random key and a second random key using a key agreement algorithm based on the first random point, the second random point, the third random point, the negotiation parameters, the first key pair and the first identity identifier.
[0166] like Figure 4 As shown, calculate the first temporary random point P R,0 and the second temporary random point P R,1 :
[0167]
[0168] Then use the national secret SM2 to calculate the first verification point P0=GenPoint(r S ,P S ,P R,0 ,sk S ,pk S ) and the second verification point P1=GenPoint(r S ,P S ,P R,1 ,sk R ,pk R ). Finally, a first random key k0 and a second random key k1 are generated according to the first verification point and the second verification point that have passed the validity verification.
[0169]
[0170] Step S460: The receiver performs local calculation and generates a third random key using a key agreement algorithm based on the first random point, the negotiation parameter, the second key pair, and the second identity identifier.
[0171] like Figure 4 As shown, calculate the intermediate variable t S :
[0172]
[0173] Reusing the intermediate variable t S Calculate the third verification point P c Coordinate (x u ,y u ):
[0174]
[0175] Finally, according to the third verification point P that has passed the validity verification c Generate a third random key k c .
[0176]
[0177] Step S470: encrypt the first message and the second message based on the first random key and the second random key; and transmit the encrypted first message and the second message to the recipient.
[0178] like Figure 4 As shown, in the second round of message transmission, the sender encrypts the input first message and the second message. The encrypted first message a0 and the encrypted second message a1 are as follows.
[0179]
[0180] Step S480: Based on the third random key, the first message or the second message is correspondingly selected for decryption to obtain the first message or the second message.
[0181] like Figure 4 As shown, in the second round of message transmission, the receiver uses the third random key k c and the receiver's index c, to decrypt the input first message or second message.
[0182]
[0183] It should be noted that the steps shown in the above process or the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here. For example, steps S430 and S440 can also be executed synchronously.
[0184] In this embodiment, in the key agreement algorithm of SM2, the infinity point of the elliptic curve is used to verify the message validity of the first verification point and the second verification point, so that the message verifiability is achieved in the oblivious transmission method, thereby avoiding invalid calculations. At the same time, the efficient SM2 key agreement algorithm and one-time pad calculation are utilized, and the length of the message transmitted by the key agreement protocol on the elliptic curve expressed as a string is also shorter, thereby improving the calculation efficiency and reliability.
[0185] In this embodiment, a message verifiable oblivious transmission system based on a national secret algorithm is also provided, which is used to implement the above embodiments and preferred implementation modes, and will not be repeated hereafter. The terms "module", "unit", "subunit", etc. used below can implement a combination of software and / or hardware for a predetermined function. Although the system described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0186] Figure 5 is a structural block diagram of the message verifiable oblivious transmission system based on the national secret algorithm in this embodiment, such as Figure 5 As shown, the system includes:
[0187] A first negotiation module 10, configured to generate a first key pair and a first identity identifier based on negotiation parameters;
[0188] The first verification module 20 is used to generate a first random point based on the elliptic curve in the negotiation parameters; and transmit the first random point to the receiver; obtain the second random point and the third random point transmitted by the receiver; based on the first random point, the second random point, the third random point, the negotiation parameters, the first key pair and the first identity identifier, generate a first verification point and a second verification point using a key negotiation algorithm; and verify the validity of the first verification point and the second verification point using the infinity point of the elliptic curve;
[0189] The first generating module 30 is configured to generate a first random key and a second random key based on a first verification point and a second verification point that have passed validity verification.
[0190] Through the system provided in this embodiment, it is possible to use the infinity point of the elliptic curve to verify the message validity of the first verification point and the second verification point in the key agreement algorithm, thereby realizing message verifiability in the oblivious transmission method, thereby avoiding invalid calculations and improving calculation efficiency and reliability.
[0191] In some embodiments, the first verification module 20 is further configured to:
[0192] Based on the second random point, the third random point and the random function, a first temporary random point and a second temporary random point are generated; using the key agreement algorithm, the first random point and the first temporary random point and the second temporary random point that verify that they satisfy the elliptic curve are calculated to generate a first verification point and a second verification point.
[0193] In some embodiments, the first verification module 20 is further configured to:
[0194] The first random point, the first temporary random point and the second temporary random point are parsed to obtain coordinate data; the horizontal coordinate in the coordinate data is extracted and converted into an integer; based on the converted horizontal coordinate, the first identity identifier, the first temporary random point, the second temporary random point and the first key pair, the first verification point and the second verification point are calculated.
[0195] In some of the embodiments, the system further includes: a first message transmission module, configured to:
[0196] The first message and the second message are encrypted based on the first random key and the second random key; and the encrypted first message and the second message are transmitted to the receiving party.
[0197] Figure 6 is a structural block diagram of a message verifiable oblivious transmission system based on a national secret algorithm in another embodiment, such as Figure 6 As shown, the system includes:
[0198] A second negotiation module 40, configured to generate a second key pair and a second identity identifier based on the negotiation parameters;
[0199] The second verification module 50 is used to generate a second random point and a third random point based on the elliptic curve in the negotiation parameters; and transmit the second random point and the third random point to the sender; obtain the first random point transmitted by the sender; generate a third verification point using the key negotiation algorithm based on the first random point, the negotiation parameters, the second key pair and the second identity identifier; and verify the validity of the third verification point using the infinity point of the elliptic curve;
[0200] The second generating module 60 is used to generate a third random key based on a third verification point that passes the validity verification.
[0201] Through the system provided in this embodiment, the message validity can be verified on the third verification point using the infinity point of the elliptic curve in the key agreement algorithm, and the message verifiability is achieved in the oblivious transmission method, thereby avoiding invalid calculations and improving calculation efficiency and reliability.
[0202] In some of the embodiments, the second verification module 50 is further configured to:
[0203] The first random point that satisfies the verification of the elliptic curve is parsed to obtain coordinate data; the horizontal coordinate in the coordinate data is extracted and converted into an integer; based on the converted horizontal coordinate, the second identity identifier, the first random point and the second key pair, a third verification point is calculated.
[0204] In some of the embodiments, the system further includes: a second message transmission module, configured to:
[0205] Obtaining a first message and a second message transmitted by the sender;
[0206] Based on the third random key, the first message or the second message is correspondingly selected for decryption to obtain the first message or the second message.
[0207] It should be noted that the above modules can be functional modules or program modules, and can be implemented by software or hardware. For modules implemented by hardware, the above modules can be located in the same processor; or the above modules can be located in different processors in any combination.
[0208] In this embodiment, a computer device is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0209] Optionally, the computer device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0210] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation modes, and will not be repeated in this embodiment.
[0211] In addition, in combination with the method for oblivious transmission of a message based on a national secret algorithm provided in the above embodiments, a storage medium may also be provided in this embodiment for implementation. The storage medium stores a computer program; when the computer program is executed by a processor, any one of the methods for oblivious transmission of a message based on a national secret algorithm in the above embodiments is implemented.
[0212] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0213] It should be understood that the specific embodiments described herein are only used to explain the application, rather than to limit it. Based on the embodiments provided in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the protection scope of this application.
[0214] Obviously, the drawings are only some examples or embodiments of the present application. For ordinary technicians in the field, the present application can also be applied to other similar situations based on these drawings without creative work. In addition, it is understandable that although the work done in this development process may be complicated and lengthy, for ordinary technicians in the field, certain changes in design, manufacturing or production based on the technical content disclosed in this application are only conventional technical means and should not be regarded as insufficient content disclosed in this application.
[0215] The term "embodiment" in this application refers to a specific feature, structure or characteristic described in conjunction with the embodiment that can be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily mean the same embodiment, nor does it mean that it is mutually exclusive with other embodiments and is independent or optional. It is clearly or implicitly understood by those of ordinary skill in the art that the embodiments described in this application can be combined with other embodiments without conflict.
[0216] The above-mentioned embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of patent protection. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the scope of protection of the present application. Therefore, the scope of protection of the present application shall be subject to the attached claims.
Claims
1. A method for verifiable oblivious transmission of messages based on a national secret algorithm, characterized in that: include: generating a first key pair and a first identity identifier, and a second key pair and a second identity identifier based on the negotiated parameters; Based on the elliptic curve in the negotiation parameters, generate a first random point; and transmitting the first random point to a receiver; Obtaining a second random point and a third random point transmitted by the receiver; Generate a first temporary random point and a second temporary random point based on the second random point, the third random point and a random function; The first verification point P0 and the second verification point P1 are calculated in the following way: P0=GenPoint(r S ,P S ,P R,0 ,sk S ,pk R ); P1=GenPoint(r S ,P S ,P R,1 ,sk S ,pk R ); Among them, r S is the first random number; P S is the first random point; P R,0 is the first temporary random point; P R,1 is the second temporary random point; sk S is the sender's private key of the first key pair, pk R is the recipient's public key of the second key pair; GenPoint is the point generation algorithm of SM2; Using the infinity point of the elliptic curve, verify the validity of the first verification point and the second verification point; and generate a first random key and a second random key based on the first verification point and the second verification point that have passed the validity verification; specifically, calculate the first random key k0 and the second random key k1 in the following manner: Among them, h S is the first identity identifier of the sender; R is the second identity identifier of the recipient; klen indicates the password length; GenKey is the key generation algorithm of SM2; (x v 0 ,y v 0 ) and (x v 1 ,y v 1 ) are the coordinates of the first verification point P0 and the second verification point P1.
2. The method for verifiable oblivious transmission of messages based on a national secret algorithm according to claim 1 is characterized in that: Also includes: Encrypting the first message and the second message based on the first random key and the second random key; And transmit the encrypted first message and second message to the receiving party.
3. A method for verifiable oblivious transmission of messages based on a national secret algorithm, characterized in that: include: generating a second key pair and a second identity identifier, and the first key pair and the first identity identifier based on the negotiated parameters; Based on the elliptic curve in the negotiation parameters, generate a second random point and a third random point; and transmitting the second random point and the third random point to a sender; Obtaining a first random point transmitted by the sender; The third verification point P is calculated using the following method: c Coordinate (x u ,y u ): The following intermediate variable t S calculate: Among them, r R is the second random number; sk R is the recipient's private key of the second key pair; n is the order of the base point; mod represents the modulus operation; The fourth random point P R The converted horizontal coordinate, the fourth random point is generated on the elliptic curve using the second random number; Where h is the auxiliary factor; t S is the intermediate variable; P S is the first random point; pk S is the sender's public key of the first key pair; is the first random point P S The transformed horizontal axis; The validity of the third verification point is verified by using the infinity point of the elliptic curve; and a third random key is generated based on the third verification point that has passed the validity verification; the third random key k is calculated specifically by the following method: c : Among them, h S is the first identity identifier of the sender; R It is the second identity identifier of the recipient; klen indicates the password length; GenKey is the key generation algorithm of SM2.
4. The method for verifiable oblivious transmission of messages based on a national secret algorithm according to claim 3 is characterized in that: Also includes: Obtaining a first message and a second message transmitted by the sender; Based on the third random key, the first message or the second message is correspondingly selected for decryption to obtain the first message or the second message.
5. A message verifiable oblivious transmission system based on a national secret algorithm, characterized in that: include: A first negotiation module, configured to generate a first key pair and a first identity identifier, and a second key pair and a second identity identifier based on negotiation parameters; A first verification module, configured to generate a first random point based on the elliptic curve in the negotiation parameters; and transmitting the first random point to a receiver; obtaining a second random point and a third random point transmitted by the receiver; and generating a first temporary random point and a second temporary random point based on the second random point, the third random point and a random function; The first verification point P0 and the second verification point P1 are calculated in the following way: P0=GenPoint(r S ,P S ,P R,0 ,sk S ,pk R ); P1=GenPoint(r S ,P S ,P R,1 ,sk S ,pk R ); Among them, r S is the first random number; P S is the first random point; P R,0 is the first temporary random point; P R,1 is the second temporary random point; sk S is the sender's private key of the first key pair, pk R is the public key of the recipient of the second key pair; GenPoint is the point generation algorithm of SM2; the validity of the first verification point and the second verification point are verified by using the infinity point of the elliptic curve; The first generating module is used to generate a first random key and a second random key based on the first verification point and the second verification point that have passed the validity verification; specifically, the first random key k0 and the second random key k1 are calculated in the following manner: Among them, h S is the first identity identifier of the sender; R is the second identity identifier of the recipient; klen indicates the password length; GenKey is the key generation algorithm of SM2; (x v 0 ,y v 0 ) and (x v 1 ,y v 1 ) are the coordinates of the first verification point P0 and the second verification point P1.
6. A message verifiable oblivious transmission system based on a national secret algorithm, characterized in that: include: A second negotiation module, configured to generate a second key pair and a second identity identifier, as well as the first key pair and the first identity identifier based on the negotiation parameters; A second verification module, configured to generate a second random point and a third random point based on the elliptic curve in the negotiation parameters; and transmit the second random point and the third random point to the sender; Obtaining a first random point transmitted by the sender; The third verification point P is calculated using the following method: c Coordinate (x u ,y u ): The following intermediate variable t S calculate: Among them, r R is the second random number; sk R is the recipient's private key of the second key pair; n is the order of the base point; mod represents the modulus operation; The fourth random point P R The converted horizontal coordinate, the fourth random point is generated on the elliptic curve using the second random number; Where h is the auxiliary factor; t S is the intermediate variable; P S is the first random point; pk S is the sender's public key of the first key pair; is the first random point P S The converted horizontal coordinate; using the infinity point of the elliptic curve to verify the validity of the third verification point; The second generation module is used to generate a third random key based on a third verification point that has passed the validity verification; specifically, the third random key k is calculated in the following manner: c : Among them, h S is the first identity identifier of the sender; R It is the second identity identifier of the recipient; klen indicates the password length; GenKey is the key generation algorithm of SM2.
7. A computer device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to execute the message verifiable oblivious transmission method based on the national secret algorithm as described in any one of claims 1 to 2, or claims 3 to 4.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for verifiable oblivious transmission of messages based on a national secret algorithm as described in any one of claims 1 to 2, or claims 3 to 4 are implemented.
Citation Information
Patent Citations
SM2-based certificateless key generation method and device, electronic equipment and medium
CN113190862A
Data casual transmission method and device, electronic equipment and storage medium
CN113259329A