Anti-malicious enemy three-party collaborative SM2 digital signature generation method and system

By using technical means of copying secret sharing and multiplication triple verification protocols in the tripartite collaborative signature system, the problem that collaborative signature technology in the existing technology is difficult to balance security, reliability and performance, and efficient and secure digital signature generation and verification are achieved.

CN119921957AActive Publication Date: 2025-05-02WUHAN UNIV
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510019152.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-05-02
Estimated Expiration
2045-01-07

AI Technical Summary

Technical Problem

The prior art is difficult to balance security, reliability and performance when applying collaborative signature technology, especially in preventing private key leakage and malicious attacks.

Method used

A three-party collaborative SM2 digital signature generation method based on the anti-malignant adversary of copy secret sharing is adopted to generate secret sharing of the signature private key through pseudo-random functions and shared keys, and a multiplication triple verification protocol is used for security verification to ensure the integrity and verification of the signature.

Benefits of technology

It realizes the rapid, safe and reliable generation of digital signatures in a three-party environment, and can promptly discover and hold malicious opponents accountable, ensuring the security and efficiency of signatures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119921957A_ABST
    Figure CN119921957A_ABST
Patent Text Reader

Abstract

The invention discloses an anti-malicious enemy three-party collaborative SM2 digital signature generation method and system, and the method comprises the steps: three-party collaborative key generation and three-party collaborative signatures, and can timely find whether a malicious enemy deviates from a protocol set in a protocol execution process. And after the agreement is terminated due to the attack behavior of the malicious opponent, responsibility investigation can be carried out on the discovering party. According to the scheme, the three parties share the collaborative signature based on the copy secret, the multiplication triple is used for security verification, the security, reliability and performance of the collaborative signature technology are fully considered, the security level of resisting malicious opponent attacks is achieved, meanwhile, it is guaranteed that the digital signature is safely, reliably and rapidly generated in the three-party environment, and the security is improved. And the balance between key generation and signature efficiency is satisfied. The method has the advantages of high security, high flexibility, high performance and the like, and can be applied to any application scene supporting secure multi-party computing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to an efficient three-party collaborative SM2 digital signature generation method and system for resisting malicious adversaries. Background Art

[0002] SM2 is an algorithm that uses elliptic curve cryptography to implement digital signatures. It provides a secure and efficient digital signature method based on the mathematical properties of elliptic curves. Digital signature technology is widely used in fields such as cryptocurrency, digital certificates, and secure communications. Similar to traditional signatures, it simulates the function of paper signatures or seals through specific cryptographic algorithms to ensure the integrity, authenticity, and non-repudiation of digital resources. SM2 signature technology is safe in theory, but it may face some threats and attacks in practical applications. The most serious security threat is the leakage of private keys. If the private key is leaked, hackers or attackers can use the private key to generate valid signatures and impersonate legitimate users to conduct fraudulent activities. Therefore, it is crucial to protect the security of private keys.

[0003] Collaborative signature technology allows multiple parties to jointly generate keys, preventing any single entity or a small number of colluders from obtaining the complete private key without permission. Multiple signers jointly complete the signature to ensure that multiple parties agree and authorize the content of the signature, preventing a single entity from abusing the signing authority. This technology is very useful in scenarios that require the participation and consent of multiple parties, such as multi-party contracts, multi-party authorization, etc. However, collaborative signature technology may also increase complexity and computational costs. Existing technologies cannot guarantee a balance in security, reliability, and performance when applying these technologies. Summary of the invention

[0004] The present invention proposes a three-party collaborative SM2 digital signature generation method and system based on copy secret sharing that is resistant to malicious adversaries. The present invention can timely discover whether the malicious adversary deviates from the established steps of the protocol during the execution of the protocol, and can hold the malicious party accountable after the malicious adversary's attack behavior causes the termination of the protocol. The security, reliability and performance of the collaborative signature technology are fully considered to achieve a security level that can resist attacks from malicious adversaries, while ensuring that digital signatures are generated safely, reliably and quickly in a three-party environment, meeting the balance between key generation and signature efficiency.

[0005] The technical solution adopted by the present invention is as follows:

[0006] The first aspect provides a method for generating a three-party collaborative SM2 digital signature against malicious adversaries, comprising:

[0007] The three parties use a pseudo-random function and a shared key to generate a secret share of the signature private key, and jointly generate a signature verification public key based on the password sharing of the signature private key held by each party;

[0008] The three parties use the replicated secret sharing technology to recover the secret value to be shared, calculate the intermediate variables of the complete signature through interaction, and obtain the complete signature based on the message to be signed, the signature verification public key and the intermediate variables of the complete signature.

[0009] In one implementation, three parties generate a secret share of a signature private key using a pseudo-random function and a shared key, and jointly generate a signature verification public key based on the cryptographic share of the signature private key held by each party, including:

[0010] Each participant initializes a counter and generates their own shared key based on the initialization ideal function;

[0011] Each participant uses a pseudo-random function and the shared key they hold to calculate the secret share of the signature private key;

[0012] Each participant calculates the public key component based on the password of the signature private key held by each participant, and sends the calculated public key component to other participants;

[0013] Each participant determines whether the public key component is valid based on whether the public key component calculated by itself is consistent with the received component. If each public key component is consistent, it indicates that each participant has honestly executed the protocol and the public key component is valid. At this time, the public signature verification public key is calculated based on each public key component. If there is an inconsistency in the public key components, it means that there is a malicious participant who dishonestly executes the protocol, the public key component is invalid, and the protocol terminates.

[0014] In one embodiment, the three parties use the replicated secret sharing technique to recover the secret value to be shared, calculate the intermediate variable of the complete signature through interaction, and use the multiplication triple verification protocol π Mult-TripleVerify Verification is performed, and if it passes, the complete signature is obtained based on the message to be signed, the signature verification public key, and the intermediate variables of the complete signature, including:

[0015] Each participant updates the counter and uses a pseudo-random function and the shared key to calculate the secret share of the random number k;

[0016] Each participant calculates the signature parameter component based on the secret sharing of the random number k held by each party, and sends the signature parameter component calculated by itself to other participants. Each participant determines the validity of the signature parameter component based on whether the signature parameter component calculated by itself is consistent with the received signature parameter component. If each signature parameter component is consistent, it means that each participant has honestly executed the protocol, the signature parameter component is valid, and the first signature parameter is calculated based on the signature parameter component. If there is a signature parameter inconsistency, it means that there is a malicious participant who dishonestly executes the protocol, the signature parameter component is invalid, and the protocol terminates;

[0017] Each participant updates the counter and uses the pseudo-random function and the shared key to calculate the secret share of the random number ρ;

[0018] Each participant calculates the intermediate parameter α component based on the secret sharing of the shared key and random number ρ held by each party;

[0019] Each participant sends the intermediate parameter α component to other participants and uses the multiplication triple to verify the protocol π Mult-TripleVerify Verify and proceed to the next step if passed;

[0020] Each participant calculates the intermediate parameter β component based on the first signature parameter, the hash function, and the secret sharing of the signature private key held by each participant, and sends the intermediate parameter β component calculated by itself to other participants, and calculates the intermediate parameter according to the intermediate parameter β component;

[0021] Each participant calculates the signature parameter component based on the intermediate parameter β and the intermediate parameter α components, and sends the calculated signature parameter component to other participants, using the multiplication triple verification protocol π Mult-TripleVerify Verification is performed, and after verification, the second signature parameter is calculated based on all signature parameter components, and the first signature parameter and the second signature parameter constitute a three-party collaborative generation of a complete signature.

[0022] In one embodiment, the pseudo-random function is F(·), and each participant uses the pseudo-random function and the shared key held to calculate the secret sharing of the signature private key, including:

[0023] The first participant P1 calculates x1=F(k 13 + count1) and x2 = F(k 12 + count1), the second participant P2 calculates x2 = F(k 12 + count2) and x3 = F(k 23 + count2), the third party P3 calculates x1 = F(k 13 + count3) and x3 = F(k 23+count3), where x1 and x2 are the secret shares of the signature private key calculated by the first participant, k 13 and k 12 is the shared key held by the first participant, count1 is the counter corresponding to the first participant, k 12 and k 23 is the shared key held by the second participant, count2 is the counter corresponding to the second participant, x2 and x3 are the secret sharing of the signature private key calculated by the second participant, count3 is the counter corresponding to the third participant, k 13 and k 23 is the shared key held by the third party, and x1 and x3 are the secret sharing of the signature private key calculated by the third party.

[0024] In one embodiment, each participant calculates the intermediate parameter β component based on the first signature parameter, the hash function, and the secret sharing of the signature private key held by each participant, and sends the intermediate parameter β component calculated by itself to other participants, including:

[0025] The first party P1 calculates Then calculate the intermediate parameter β component β1=h1ρ1+h1ρ2+h2ρ1, where h1 and h2 are the intermediate parameters calculated by the first participant, ρ1 and ρ2 are the secret sharing of the random number ρ calculated by the first participant; H(·) is the cryptographic function derived from the cryptographic hash function, m is the message to be signed, and x1 and x2 are the secret sharing of the signature private key calculated by the first participant;

[0026] The second party P2 calculates Calculate the intermediate parameter β component β2=h2ρ2+h2ρ3+h3ρ2, where h3 and h2 are the intermediate parameters calculated by the second participant, ρ2 and ρ3 are the secret sharing of the random number ρ calculated by the second participant; x3 and x2 are the secret sharing of the signature private key calculated by the second participant;

[0027] Third-party P3 calculation Calculate the intermediate parameter β component β3=h3ρ3+h3ρ1+h1ρ3, where h1 and h3 are the intermediate parameters calculated by the third party, ρ3 and ρ1 are the secret sharing of the random number ρ calculated by the third party; x1 and x3 are the secret sharing of the signature private key calculated by the third party;

[0028] The first participant will send the intermediate parameter β component β1 to the second and third participants, the second participant will send the intermediate parameter β component β2 to the first and third participants, and the third participant will send the intermediate parameter β component β3 to the first and second participants. Then each participant P iHolds (β1,β2,β3).

[0029] Based on the same inventive concept, the second aspect of the present invention provides a three-party collaborative SM2 signature generation system, including:

[0030] The three-party collaborative key generation module is used for the three parties to generate a secret sharing of the signature private key using a pseudo-random function and a shared key, and to jointly generate a signature verification public key based on the password sharing of the signature private key held by each party;

[0031] The three-party collaborative signature module is used for the three parties to use the replicated secret sharing technology to recover the secret value to be shared, calculate the intermediate variables of the complete signature through interaction, and obtain the whole signature based on the message to be signed, the signature verification public key and the intermediate variables of the complete signature;

[0032] Based on the same inventive concept, the third aspect of the present invention provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the three-party collaborative SM2 digital signature generation method against malicious adversaries described in the first aspect is implemented.

[0033] Based on the same inventive concept, the fourth aspect of the present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory and run on the processor. When the processor executes the program, it implements the three-party collaborative SM2 digital signature generation method against malicious adversaries described in the first aspect.

[0034] Compared with the prior art, the advantages and beneficial technical effects of the present invention are as follows:

[0035] The present invention provides a three-party collaborative SM2 digital signature generation method that is resistant to malicious adversaries. It can promptly detect whether the malicious adversary deviates from the established steps of the protocol during the execution of the protocol, and can hold the malicious party accountable after the malicious adversary's attack behavior causes the termination of the protocol. The three parties in this scheme use multiplication triples for security verification based on the replicated secret sharing collaborative signature, fully considering the security, reliability and performance of the collaborative signature technology, achieving a security level that can resist attacks from malicious adversaries, while ensuring that digital signatures are generated safely, reliably and quickly in a three-party environment, meeting the balance between key generation and signature efficiency. The sharing of the secret component in the three-party signature is optimized, which reduces the amount of communication between the participants and improves communication efficiency. At the same time, a parallel strategy can be used to improve system performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0037] Figure 1 A flowchart of a three-party collaborative key generation protocol provided by an embodiment of the present invention;

[0038] Figure 2 A flowchart of a three-party collaborative signature protocol provided by an embodiment of the present invention;

[0039] Figure 3 The overall framework diagram of the three-party collaborative SM2 signature generation system against malicious adversaries provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0040] Although collaborative signature techniques are very useful in scenarios where multiple parties need to participate and agree, they may also increase complexity and computational cost because multiple signature parts need to be managed and the security of the signatures is not compromised when they are merged. Therefore, when applying these techniques, the balance between security, reliability, and performance needs to be carefully considered.

[0041] Based on the above considerations, the present invention designs a three-party collaborative SM2 digital signature generation method and system based on replicated secret sharing that is resistant to malicious adversaries. It can promptly detect whether a malicious adversary deviates from the established steps of the protocol during the execution of the protocol, and can hold the malicious party accountable after the malicious adversary's attack behavior causes the termination of the protocol. The three parties in this solution use a multiplication triplet for security verification based on replicated secret sharing, fully considering the security, reliability and performance of the collaborative signature technology, achieving a security level that can resist attacks from malicious adversaries, while ensuring that digital signatures are generated safely, reliably and quickly in a three-party environment, meeting the balance between key generation and signature efficiency.

[0042] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0043] Embodiment 1

[0044] The present invention discloses a three-party collaborative SM2 digital signature generation method for resisting malicious adversaries, comprising:

[0045] The three parties use a pseudo-random function and a shared key to generate a secret share of the signature private key, and jointly generate a first signature verification public key based on the cryptographic share of the signature private key held by each party;

[0046] The three parties use the replicated secret sharing technology to recover the secret value to be shared, and interactively calculate the intermediate variables of the complete signature, and obtain the complete signature based on the message to be signed, the signature verification public key and the intermediate variables of the complete signature.

[0047] To ensure universality, the parameters of the present invention are selected to be consistent with the standard parameters of the SM2 signature algorithm. The specific symbols are described as follows:

[0048] P1, P2, P3: first party, second party, third party;

[0049] q: a large prime number.

[0050] The set of integers consisting of 1, 2, …, q-1.

[0051] The elliptic curve group of order N.

[0052] G: elliptic curve Generator.

[0053] x i :Participant P i The signature private key.

[0054] Q: Digital signature verification public key.

[0055] k·P: k times the point P on the elliptic curve, where k is a positive integer.

[0056] H(·): A cryptographic function derived from a cryptographic hash function.

[0057] Initialize the ideal function and generate the seed key for replicating the secret share.

[0058] F(·): pseudo-random function PRF.

[0059] An algorithm for generating zero-knowledge proofs of statements about discrete logarithmic relations.

[0060] Zero-knowledge proof of discrete logarithm relations.

[0061] π Mult-TripleVerify : A verification protocol for multiplicative triples.

[0062] m: The message to be signed.

[0063] Specifically, the three-party collaborative SM2 digital signature generation method for resisting malicious adversaries proposed in the present invention includes three-party collaborative key generation and three-party collaborative signing steps.

[0064] In one embodiment, the three-party collaborative key generation step includes: the three signing parties initialize the ideal function The participants use the pseudo-random function F(·) and the shared key to generate the secret sharing of the signature private key, and jointly generate a publicly publishable signature verification public key Q (signature verification public key). Each signing participant is denoted as P i (i∈{1,2,3}). See Figure 1 , which can be achieved through the following steps:

[0065] a) Each participant P i Initialize the corresponding counter count i , and based on the ideal function Generate their own shared keys, P1 holds the shared key (k 12 ,k 13 ), P2 holds the shared key (k 12 ,k 23 ), P3 holds the shared key (k 13 ,k 23 ). The random number k 12 ,k 23 ,

[0066] b) Each participant P i The secret sharing of the signature private key is calculated using the pseudo-random function F(·) and the shared key held.

[0067] P1 calculates the secret share of the private key x where x1 = F(k 13 + count1) and x2 = F(k 12 + count1), then calculate and Q2 = x2·G, send the message (complement, 1, Q1, x1) to the ideal function (It can be seen as P1 sending the commitment com of the public key share Q1 and its discrete logarithm relationship zero-knowledge proof π1 to P2.

[0068] c) P2 receives the ideal function After receiving the message (proof-receipt, 1), update the counter count and ensure the consistency of count. Calculate where x2 = F(k 12 + count2) and x3 = F(k23 + count2), calculate Q2 = x2·G and Q3 = x3·G, then send the message (complement, 2, Q2, x2) to the ideal function It can be viewed as P2 sending a commitment com of the public key share Q2 and its discrete logarithmic relationship, zero-knowledge proof π2, to P3.

[0069] d) P3 receives the ideal function After receiving the message (proof-receipt, 2), update the counter count and ensure the consistency of count, and calculate where x1 = F(k 13 + count3) and x3 = F(k 23 + count3). Calculate Q1=x1·G and Q3=x3·G. Then send the message (prove,3,Q3,x3) to the ideal function It can be regarded as sending the zero-knowledge proof π3 of the public key share Q3 and its discrete logarithm relationship to P1.

[0070] e) When participant P1 receives the ideal function After receiving the message (proof,3,Q3), verify whether the zero-knowledge proof is legal. If the zero-knowledge proof is illegal, it means that participant P3 maliciously tampered with the protocol process and sent an incorrect public key share Q′3 and Q′3≠Q3. According to the message sid=3, participant P3 can be held accountable and the protocol process is terminated. If the zero-knowledge proof is legal, it means that participant P3 follows the protocol process and the public key share Q3 sent satisfies the discrete logarithm relationship Q3=x3·G. At this time, participant P1 holds a legal signature public key share Q1, Q2, Q3, and calculates and stores the complete signature public key Q=Q1+Q2+Q3. Participant P1 sends the message (decom-proof,1) to the ideal function

[0071] f) When participant P2 receives the ideal function After receiving the message (decom-proof, 1, Q1), verify whether the zero-knowledge proof is legal. If the zero-knowledge proof is illegal, it means that participant P1 maliciously tampered with the protocol process and sent an incorrect public key share Q′1 and Q′1≠Q1. According to the message sid=1, participant P1 can be held accountable and the protocol process is terminated. If the zero-knowledge proof is legal, it means that participant P1 follows the protocol process and the public key share Q1 sent satisfies the discrete logarithm relationship Q1=x1·G. At this time, participant P2 holds a legal signature public key share Q1, Q2, Q3, and calculates and stores the complete signature public key Q=Q1+Q2+Q3. Participant P2 sends the message (decom-proof, 2) to the ideal function

[0072] g) When participant P3 receives the ideal function After receiving the message (decom-proof, 2, Q2), verify whether the zero-knowledge proof is legal. If the zero-knowledge proof is illegal, it means that the participant P2 maliciously tampered with the protocol process and sent an incorrect public key share Q. ′ 2 and Q ′ 2≠Q2, according to the message sid=2, the participant P2 can be held accountable and the protocol process is terminated. If the zero-knowledge proof proof is legal, it means that the participant P2 follows the protocol process, and the public key share Q2 sent satisfies the discrete logarithm relationship Q2=x2·G. At this time, the participant P3 holds the legal signature public key shares Q1, Q2, Q3, and calculates and stores the complete signature public key Q=Q1+Q2+Q3.

[0073] It should be noted that Represents an operation of finding a secret share or secret sharing, by which the secret share held by a participant is calculated.

[0074] In one embodiment, the three-party collaborative signing step includes: the three signing parties jointly execute a distributed signature generation protocol, use a replicated secret sharing technique to recover the secret value to be shared, and use an ideal function Interactively compute intermediate variables and use multiplication triples to verify the protocol π Mult-TripleVerify Verify, and finally calculate the complete signature value σ=(r,s). Figure 2 , which can be achieved through the following steps:

[0075] a) Each participant P i Update counter count i , and uses the pseudo-random function F(·) and the shared key held to calculate the secret sharing of the random number k. Participant P1 calculates where k1 = F(k 13 + count1) and k2 = F(k12 + count1), calculate Where R1 = k1·G and R2 = k2·G, send the message (compare,1,R1,k1) to the ideal function (It can be seen as P1 sending the commitment com of the signature parameter share R1 and its discrete logarithm relationship zero-knowledge proof π1 to P2.

[0076] b) Calculation by Party P2 where k2 = F(k 12 + count2) and k3 = F(k 23 + count2), calculate Where R2 = k2·G and R3 = k3·G, then send the message (compare,2,R2,k2) to the ideal function (It can be seen as P2 sending the commitment com of the signature parameter share R2 and its discrete logarithm relationship zero-knowledge proof π2 to P3.

[0077] c) Participant P3 calculation where k1 = F(k 13 + count3) and k3 = F(k 23 + count3), calculate Where R1 = k1·G and R3 = k3·G, send the message (prove, 3, R3, k3) to the ideal function (It can be seen as P3 sending the zero-knowledge proof π3 of the signature parameter share R3 and its discrete logarithm relationship to P1.

[0078] d) When participant P1 receives the ideal function After receiving the message (proof,3,R3), verify whether the zero-knowledge proof is legal. If the zero-knowledge proof is illegal, it means that participant P3 maliciously tampered with the protocol process and sent an incorrect signature parameter share R′3 and R′3≠R3. According to the message sid=3, participant P3 can be held accountable and the protocol process is terminated. If the zero-knowledge proof is legal, it means that participant P3 follows the protocol process and the public key share R3 sent satisfies the discrete logarithm relationship R3=k3·G. At this time, participant P1 holds the legal signature parameter shares R1, R2, and R3, and calculates and stores the complete signature parameters R=R1+R2+R3. Participant P1 sends the message (decom-proof,1) to the ideal function It can be considered that P1 sends the zero-knowledge proof π1 of the signature parameter R1 and its discrete logarithm relationship to P2.

[0079] e) When participant P2 receives the ideal function After receiving the message (decom-proof, 1, R1), verify whether the zero-knowledge proof is legal. If the zero-knowledge proof is illegal, it means that participant P1 maliciously tampered with the protocol process and sent an incorrect signature parameter share R′1 and R′1≠R1. According to the message sid=1, participant P1 can be held accountable and the protocol process is terminated. If the zero-knowledge proof is legal, it means that participant P1 follows the protocol process and the signature parameter share R1 sent satisfies the discrete logarithm relationship R1=k1·G. At this time, participant P2 holds the legal signature parameter shares R1, R2, and R3, and calculates and stores the complete signature parameter R=R1+R2+R3. Participant P2 sends the message (decom-proof, 2) to the ideal function It can be considered that P1 sends the zero-knowledge proof π2 of the signature parameter R2 and its discrete logarithm relationship to P2.

[0080] f) When participant P3 receives the ideal function After receiving the message (decom-proof,2,R2), verify whether the zero-knowledge proof is legal. If the zero-knowledge proof is illegal, it means that participant P1 maliciously tampered with the protocol process and sent an incorrect signature parameter share R′2 and R′2≠R2. According to the message sid=2, participant P2 can be held accountable and the protocol process is terminated. If the zero-knowledge proof is legal, it means that participant P2 follows the protocol process and the public key share R2 sent satisfies the discrete logarithm relationship R2=k2·G. At this time, participant P2 holds the legal signature parameter shares R1, R2, R3, and calculates and stores the complete signature parameter R=R1+R2+R3.

[0081] g) After the above steps, the signature parameter r = R x +H(m)(R x is the value of the horizontal axis of R). Each participant P i Update counter count i , and use the pseudo-random function F(·) and the shared key to calculate the secret sharing of the random number ρ. Where ρ1=F(k 13 + count1) and ρ2=F(k 12 + count1), P2 calculation Where ρ2=F(k 12 + count2) and ρ3=F(k 23 + count2), P3 calculation Where ρ1=F(k 13 + count3) and ρ3=F(k 23 + count3).

[0082] h) Each participant Pi Calculate the intermediate parameter α component Participant P1 calculation Participant P2 calculation Participant P3 calculation And the participant P i The weight α will be held i Send to P i-1 . So far, participant P1 holds (α1, α2), participant P1 holds (α2, α3), and participant P3 holds (α1, α3).

[0083] i) For P i Shares held and Participants P1, P2, and P3 jointly execute the multiplication triple verification protocol π Mult-TripleVerify , if the output is accept, it means that each participant honestly calculates the share α i If the output is ⊥, it means that there is a malicious party tampering with the share α i , the Agreement is terminated.

[0084] j) Calculation by Party P1 Calculate the intermediate parameter β component β1=h1ρ1+h1ρ2+h2ρ1, and participant P2 calculates Calculate the intermediate parameter β component β2=h2ρ2+h2ρ3+h3ρ2, and participant P3 calculates Calculate the intermediate parameter β component β3 = h3ρ3 + h3ρ1 + h1ρ3. And the participant P i The weight held i Send to P i-1 . So far, participant P1 holds (β1, β2), participant P2 holds (β2, β3), and participant P3 holds (β1, β3). Among them, ρ=ρ1+ρ2+ρ3;

[0085] k) For P i Shares held and Participants P1, P2, and P3 jointly execute the multiplication triple verification protocol π Mult-TripleVerify If the output is accept, it means that each participant honestly calculates the share β i If the output is ⊥, it means that there is a malicious party tampering with the share β i , the Agreement is terminated.

[0086] l) Each participant P i The intermediate parameter β component β i Sent to participant P i+1That is, participant P1 sends β1 to participant P2, participant P2 sends β2 to participant P3, and participant P3 sends β3 to participant P1. i Hold the intermediate parameter β components β1, β2, β3, calculate the intermediate parameters And calculate β -1 modq.

[0087] m) Participant P1 calculates the signature parameter component s1 = α1β -1 ,s2=α2β -1 , participant P2 calculates the signature parameter component s2 = α2β -1 ,s3=α3β -1 , participant P3 calculates the signature parameter component s1=α1β -1 ,s3=α3β -1 , and the participant P i Will hold the signature parameter component s i Sent to participant P i+1 , that is, participant P1 sends s1 to participant P2, participant P2 sends s2, to participant P3, and participant P3 sends s3 to participant P1. i Hold the signature parameter components s1, s2, s3 and calculate the second signature parameter The three parties collaborate to generate a complete signature {r,s}.

[0088] In general, the present invention has the following advantages and beneficial effects compared with the prior art:

[0089] 1. To resist malicious adversaries, the system introduces consistency checks and accountability mechanisms, so that the system can detect malicious behavior of malicious participants in a timely manner. When the protocol is terminated, the identity of the corresponding participant that caused the execution failure can be returned to facilitate subsequent accountability, ensuring the flexibility and robustness of digital signatures.

[0090] 2. Security. Security dependency directly relies on the security of multi-prover zero-knowledge proof and secure multi-party computing protocol, which can meet the correctness and privacy of three-party collaborative signature.

[0091] 3. High performance: Optimizes the sharing of secret components in the three-party signature, reduces the amount of communication between the participants, improves communication efficiency, and can adopt parallel strategies to improve system performance.

[0092] Embodiment 2

[0093] Based on the same inventive concept, this embodiment discloses a three-party collaborative SM2 signature generation system, see Figure 3 ,include:

[0094] The three-party collaborative key generation module 101 is used for the three parties to generate a secret sharing of a signature private key using a pseudo-random function and a shared key, and to jointly generate a first signature verification public key based on the password sharing of the signature private key held by each party;

[0095] The three-party collaborative signature module 102 is used for the three parties to use the replicated secret sharing technology to recover the secret value to be shared, calculate the intermediate variable of the complete signature through interaction, and obtain the complete signature based on the message to be signed, the signature verification public key and the intermediate variable of the complete signature;

[0096] The three-party collaborative key generation module 101 is used to execute the three-party collaborative key generation steps or protocols, and the three-party collaborative signature module 102 is used to execute the three-party collaborative signature steps or protocols.

[0097] Since the system introduced in the second embodiment of the present invention is a system used to implement the three-party collaborative SM2 digital signature generation method against malicious adversaries in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, the person skilled in the art can understand the specific structure and deformation of the system, so it is not repeated here. All systems used in the method in the first embodiment of the present invention belong to the scope of protection of the present invention.

[0098] Embodiment 3

[0099] Based on the same inventive concept, the present invention further provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the method described in the first embodiment is implemented.

[0100] Since the computer-readable storage medium introduced in the third embodiment of the present invention is the computer-readable storage medium used to implement the three-party collaborative SM2 digital signature generation method against malicious adversaries in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, the person skilled in the art can understand the specific structure and deformation of the computer-readable storage medium, so it is not repeated here. All computer-readable storage media used in the method of the first embodiment of the present invention belong to the scope of protection of the present invention.

[0101] Embodiment 4

[0102] The present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in Embodiment 1 when executing the program.

[0103] Since the computer device introduced in the fourth embodiment of the present invention is a computer device used to implement the three-party collaborative SM2 digital signature generation method against malicious adversaries in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, the person skilled in the art can understand the specific structure and deformation of the computer device, so it is not repeated here. All computer devices used in the method of the first embodiment of the present invention belong to the scope of protection of the present invention.

[0104] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0105] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0106] Although preferred embodiments of the present invention have been described, additional changes and modifications may be made to these embodiments by those skilled in the art once the basic creative concepts are known. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention. Obviously, those skilled in the art may make various changes and modifications to the embodiments of the present invention without departing from the spirit and scope of the embodiments of the present invention. Thus, if these modifications and variations of the embodiments of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. A three-party collaborative SM2 digital signature generation method against malicious adversaries, characterized in that: include: The three parties use a pseudo-random function and a shared key to generate a secret share of the signature private key, and jointly generate a signature verification public key based on the password sharing of the signature private key held by each party; The three parties use the replicated secret sharing technology to recover the secret value to be shared, calculate the intermediate variables of the complete signature through interaction, use the multiplication triplet verification protocol, and finally obtain the complete signature based on the message to be signed, the signature verification public key and the intermediate variables of the complete signature.

2. The method for generating a three-party collaborative SM2 digital signature against malicious adversaries as claimed in claim 1, characterized in that: The three parties use a pseudo-random function and a shared key to generate a secret share of the signature private key, and jointly generate a signature verification public key based on the password sharing of the signature private key held by each party, including: Each participant initializes a counter and generates their own shared key based on the initialization ideal function; Each participant uses a pseudo-random function and the shared key they hold to calculate the secret share of the signature private key; Each participant calculates the public key component based on the password of the signature private key held by each participant, and sends the calculated public key component to other participants; Each participant determines whether the public key component is valid based on whether the public key component calculated by itself is consistent with the received component. If each public key component is consistent, it indicates that each participant has honestly executed the protocol and the public key component is valid. At this time, the public signature verification public key is calculated based on each public key component. If there is an inconsistency in the public key components, it means that there is a malicious participant who dishonestly executes the protocol, the public key component is invalid, and the protocol terminates.

3. The method for generating a three-party collaborative SM2 digital signature against malicious adversaries as claimed in claim 1, characterized in that: The three parties use the replicated secret sharing technique to recover the secret value to be shared, calculate the intermediate variable of the complete signature through interaction, and obtain the complete signature based on the message to be signed, the signature verification public key and the intermediate variable of the complete signature, including: Each participant updates the counter and uses a pseudo-random function and the shared key to calculate the secret share of the random number k; Each participant calculates the signature parameter component based on the secret sharing of the random number k held by each party, and sends the signature parameter component calculated by itself to other participants. Each participant determines the validity of the signature parameter component based on whether the signature parameter component calculated by itself is consistent with the received signature parameter component. If each signature parameter component is consistent, it means that each participant has honestly executed the protocol, the signature parameter component is valid, and the first signature parameter is calculated based on the signature parameter component. If there is a signature parameter inconsistency, it means that there is a malicious participant who dishonestly executes the protocol, the signature parameter component is invalid, and the protocol terminates; Each participant updates the counter and uses the pseudo-random function and the shared key to calculate the secret share of the random number ρ; Each participant calculates the intermediate parameter α component based on the first signature parameter, the shared key held by each party, and the secret sharing of the random number ρ; Each participant sends the intermediate parameter α component to other participants and uses the multiplication triple to verify the protocol π Mult-TripleVerify Verify and proceed to the next step if passed; Each participant calculates the intermediate parameter β component based on the secret sharing of the signature private key held by each participant, and sends the intermediate parameter β component calculated by itself to other participants; Each participant calculates the signature parameter component based on the intermediate parameter β component and sends the calculated signature parameter component to other participants, using the multiplication triple verification protocol π Mult-TripleVerify Verification is performed, and after verification, the second signature parameter is calculated based on all signature parameter components, and the first signature parameter and the second signature parameter constitute a three-party collaborative generation of a complete signature.

4. The method for generating a three-party collaborative SM2 digital signature against malicious adversaries as claimed in claim 2, characterized in that: The pseudo-random function is F(·). Each participant uses the pseudo-random function and the shared key held to calculate the secret sharing of the signature private key, including: The first participant P1 calculates x1=F(k 13 + count1) and x2 = F(k 12 + count1), the second participant P2 calculates x2 = F(k 12 + count2) and x3 = F(k 23 + count2), the third party P3 calculates x1 = F(k 13 + count3) and x3 = F(k 23 +count3), where x1 and x2 are the secret shares of the signature private key calculated by the first participant, k 13 and k 12 is the shared key held by the first participant, count1 is the counter corresponding to the first participant, k 12 and k 23 is the shared key held by the second participant, count2 is the counter corresponding to the second participant, x2 and x3 are the secret sharing of the signature private key calculated by the second participant, count3 is the counter corresponding to the third participant, k 13 and k 23 is the shared key held by the third party, and x1 and x3 are the secret sharing of the signature private key calculated by the third party.

5. The method for generating a three-party collaborative SM2 digital signature against malicious adversaries as claimed in claim 3, characterized in that: Each participant calculates the intermediate parameter β component based on the first signature parameter, the hash function, and the secret sharing of the signature private key held by each participant, and sends the intermediate parameter β component calculated by itself to other participants, including: The first party P1 calculates Then calculate the intermediate parameter β component β1=h1ρ1+h1ρ2+h2ρ1, where h1 and h2 are the intermediate parameters calculated by the first participant, ρ1 and ρ2 are the secret sharing of the random number ρ calculated by the first participant; H(·) is the cryptographic function derived from the cryptographic hash function, m is the message to be signed, and x1 and x2 are the secret sharing of the signature private key calculated by the first participant; The second party P2 calculates Calculate the intermediate parameter β component β2=h2ρ2+h2ρ3+h3ρ2, where h3 and h2 are the intermediate parameters calculated by the second participant, ρ2 and ρ3 are the secret sharing of the random number ρ calculated by the second participant; x3 and x2 are the secret sharing of the signature private key calculated by the second participant; Third-party P3 calculation Calculate the intermediate parameter β component β3=h3ρ3+h3ρ1+h1ρ3, where h1 and h3 are the intermediate parameters calculated by the third party, ρ3 and ρ1 are the secret sharing of the random number ρ calculated by the third party; x1 and x3 are the secret sharing of the signature private key calculated by the third party; The first participant will send the intermediate parameter β component β1 to the second and third participants, the second participant will send the intermediate parameter β component β2 to the first and third participants, and the third participant will send the intermediate parameter β component β3 to the first and second participants. Then each participant P i Holds (β1,β2,β3).

6. A three-party collaborative SM2 digital signature generation system against malicious adversaries, characterized in that: include: The three-party collaborative key generation module is used for the three parties to generate a secret sharing of the signature private key using a pseudo-random function and a shared key, and to jointly generate a signature verification public key based on the password sharing of the signature private key held by each party; The three-party collaborative signature module is used by three parties to use the replicated secret sharing technology to recover the secret value to be shared, calculate the intermediate variable of the complete signature through interaction, and use the multiplication triple verification protocol π Mult-TripleVerify Verification is performed, and after verification, the complete signature is obtained based on the message to be signed, the signature verification public key, and the intermediate variable of the complete signature.

7. The three-party collaborative SM2 digital signature generation system against malicious adversaries as claimed in claim 6, characterized in that: The three-party collaborative key generation module is specifically used for: Each participant initializes a counter and generates their own shared key based on the initialization ideal function; Each participant uses a pseudo-random function and the shared key they hold to calculate the secret share of the signature private key; Each participant calculates the public key component based on the password of the signature private key held by each participant, and sends the calculated public key component to other participants; Each participant determines whether the public key component is valid based on whether the public key component calculated by itself is consistent with the received component. If each public key component is consistent, it indicates that each participant has honestly executed the protocol and the public key component is valid. At this time, the public signature verification public key is calculated based on each public key component. If there is an inconsistency in the public key components, it means that there is a malicious participant who dishonestly executes the protocol, the public key component is invalid, and the protocol terminates.

8. The three-party collaborative SM2 digital signature generation system against malicious adversaries as claimed in claim 6, characterized in that: The three-party collaborative signature module is specifically used for: Each participant updates the counter and uses a pseudo-random function and the shared key to calculate the secret share of the random number k; Each participant calculates the signature parameter component based on the secret sharing of the random number k held by each party, and sends the signature parameter component calculated by itself to other participants. Each participant determines the validity of the signature parameter component based on whether the signature parameter component calculated by itself is consistent with the received signature parameter component. If each signature parameter component is consistent, it means that each participant has honestly executed the protocol, the signature parameter component is valid, and the first signature parameter is calculated based on the signature parameter component. If there is a signature parameter inconsistency, it means that there is a malicious participant who dishonestly executes the protocol, the signature parameter component is invalid, and the protocol terminates; Each participant updates the counter and uses the pseudo-random function and the shared key to calculate the secret share of the random number ρ; Each participant calculates the intermediate parameter α component based on the first signature parameter, the shared key held by each party, and the secret sharing of the random number ρ; Each participant sends the intermediate parameter α component to other participants and uses the multiplication triple to verify the protocol π Mult-TripleVerify Verify and proceed to the next step if passed; Each participant calculates the intermediate parameter β component based on the secret sharing of the signature private key held by each participant, and sends the intermediate parameter β component calculated by itself to other participants; Each participant calculates the signature parameter component based on the intermediate parameter β component and sends the calculated signature parameter component to other participants, using the multiplication triple verification protocol π Mult-TripleVerify Verification is performed, and after verification, the second signature parameter is calculated based on all signature parameter components. The first signature parameter and the second signature parameter constitute a three-party collaborative generation of a complete signature.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method for generating a three-party collaborative SM2 digital signature against malicious adversaries as described in any one of claims 1 to 5 is implemented.

10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the method for generating a three-party collaborative SM2 digital signature against malicious adversaries as described in any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • SM2 digital signature method based on two-party collaboration

    CN108667627A

  • Method for multi-party associated generation of SM2 digital signature

    CN109474422A

  • Method for jointly generating SM2 digital signature by multiple parties

    CN109547199A

  • SM2 collaborative signature method

    CN110278088A

  • Collaborative signature method, device and system based on SM2 algorithm, and medium

    CN111130804A