Multi-party collaborative signature and decryption method and system
Through multi-party collaborative signature and decryption methods, the private key components of the client and server are irreversible to calculate and generate collaborative public keys, which solves the problems of the SM2 algorithm private keys being easily attacked and the security risks of pure software key management solutions, and realizes high-security signature and decryption operations.
Patent Information
- Application Number
- CN202411886336.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, the private key of the SM2 algorithm is vulnerable to malware attacks, and the pure software key management solution has problems such as key leakage and data analysis inconsistent, resulting in security risks.
Through multi-party collaborative signature and decryption methods, the client and the server generate private key components respectively, and generate collaborative public keys through encoding and collaborative interaction processing, performing irreversible calculations and data transmission, ensuring that both the client and the server do not understand the other party’s private key components.
It realizes the signature and decryption operations without leaking the real private key, improves the security of the key, prevents the problem of inconsistent private key leakage and data parsing, and is suitable for devices that are inconvenient to use the hardware password module.
Smart Images

Figure CN119945666A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and in particular relates to a method and system for multi-party collaborative signing and decryption. Background Art
[0002] The SM2 elliptic curve algorithm is an asymmetric encryption algorithm with a wide range of applications: signature calculation, signature verification calculation, encryption calculation and decryption calculation. It is used in many fields such as identity authentication, data encryption, digital certificates, etc. The SM2 algorithm is based on the elliptic curve discrete logarithm problem (ECDLP), which provides higher security and has higher efficiency than the traditional RSA algorithm. The SM2 key is generated by software and stored on the local device, which makes the private key vulnerable to malware attacks. For example, an attacker can steal the private key and password stored in the user's local device through a Trojan program, thereby obtaining the user's signature private key, which poses a very high security threat. In addition, there are two fundamental problems with pure software key management solutions: First, the software can see the key. Once the software has a vulnerability, the hacker can directly take the key; second, the software generally imports the key when the hardware becomes a board or a whole machine. If the key is in the software, the software image and the key can be copied to other identical devices during the production process. Although the security of software cryptographic modules meets certain requirements and supports technologies such as key sharding storage to improve security, in actual applications, it still needs to face problems such as encoding / decoding inconsistency, which may cause the encrypted data to be unable to be correctly parsed between the software and hardware ends. Therefore, although the software cryptographic module provides a certain degree of security, in the absence of a hardware cryptographic module, the storage and management of keys still have great security risks. Summary of the invention
[0003] In order to solve the above problems existing in the prior art, the present invention provides a method and system for multi-party collaborative signing and decryption. The purpose of the present invention can be achieved through the following technical solutions:
[0004] A multi-party collaborative signing and decryption method, comprising:
[0005] S1: Obtain the private key component of the user, use the private key component as the client private key component and encode it to obtain public key component data, and pass the public key component data to the collaborative signature server; obtain the private key component of the collaborative signature server, perform collaborative interaction processing based on the public key component data and the private key component of the collaborative signature server to obtain initial public key data, verify the validity of the initial public key data, and publish the verified initial public key data as the collaborative public key;
[0006] S2: The client generates a first random number, performs a point multiplication operation on the first random number and the base point of the elliptic curve to obtain a first random variable, and sends the encoded data of the digest of the client's data to be signed and the first random variable to the collaborative signature server; after receiving the data, the collaborative signature server generates a second random number and a third random number, calculates signature intermediate data according to the second random number, the third random number, the encoded data and the first random variable, and returns the signature intermediate data to the client; the client calculates the collaborative signature data according to the signature intermediate data and the collaborative private key component of the collaborative public key through the private key signing process of the national secret SM2 algorithm;
[0007] S3: Obtain ciphertext data through the client, extract the bit string of the first collaborative decryption segment in the ciphertext data and verify its validity. If the verification is successful, perform a modular inverse calculation on the client's private key component to obtain the first collaborative decryption component data and send it to the server. The server performs a modular inverse calculation on the first collaborative decryption component data in combination with the server's private key component to obtain the second collaborative decryption component data and send it to the client. The client decrypts the second collaborative decryption component data to obtain a plaintext output.
[0008] Specifically, the private key component of the client and the private key component of the collaborative signature server are random numbers that conform to the national encryption SM2 private key value range.
[0009] Specifically, the encoding processing method is: according to Fermat's little theorem, the encrypted plaintext calculation process is irreversibly transformed according to the order of the elliptic curve in the SM2 algorithm, and the calculation formula is:
[0010]
[0011] Among them, PA is the public key component data, d 1 is the private key component of the client, n is the order of the elliptic curve in the SM2 algorithm, and G is the base point of the elliptic curve.
[0012] Specifically, the collaborative interaction processing method is: executing a private key exchange protocol based on the discrete logarithm problem at the collaborative signature server, through which the collaborative signature server and the client generate a temporary session key, and the collaborative signature server uses the session key to encrypt the public key component data to generate initial public key data, and the calculation formula is:
[0013]
[0014] Among them, P is the initial public key data, d 2 is the private key component of the server, It is the collaborative private key component.
[0015] Specifically, the validity verification method is: verify whether the generated initial public key data is a point at infinity in the elliptic curve algorithm corresponding to the checkpoint coordinates in the SM2 algorithm, and the judgment basis of the point at infinity is whether the coordinates of the corresponding checkpoint in the projective coordinate system are (0,0,0) or (1,0,0); if it is verified to be a point at infinity, the collaborative signature server regenerates the private key component until the generated public key is not a point at infinity; wherein the private key components of the client and the collaborative signature server do not perform plaintext interactive calculations.
[0016] Specifically, the signature intermediate data includes an identification signature component, a first signature component, and a second signature component, and the calculation formula is:
[0017]
[0018] s 1 =d 2 k 3 ,
[0019] s 2 =d 2 (r+k 2 )mod(n),
[0020] Among them, r is the identification signature component, k 2 is the second random number, k 3 is the third random number, Q 1 is the first random variable, e is the coded data that can identify the summary of the data to be signed, s 1 is the first signature component, s 2 is the second signature component, d 2 is the private key component of the server, for The horizontal coordinate of the corresponding point of the random variable in the elliptic curve.
[0021] Specifically, the collaborative signature data includes an identification signature component and a signature output component value. The signature output component value is obtained by substituting the collaborative private key component of the collaborative public key into the private key in the calculation process through the private key signing process of the national secret SM2 algorithm. The calculation formula is:
[0022] s=d 1 *d 2 (k 1 *k 3 +k 2 )-r+d 1 *d 2 *r,
[0023] Among them, s is the signature output component value, k 1 is the second random number.
[0024] Specifically, the decryption processing method is: the client converts the bit string data type of the first collaborative decryption segment in the ciphertext data into a point on the elliptic curve according to the second collaborative decryption component data and performs validity verification. If the verification passes, the corresponding point coordinate information on the elliptic curve is converted into a bit string data type and the key data is derived. The calculation formula is:
[0025] t=KDF(x 2 ||y2,klen),
[0026] Where t is the derived key data, KDF is the key derivation function, (x2, y2) is the coordinate data of the corresponding point on the elliptic curve, and klen is the key data length;
[0027] If the derived key data is not 0, the data of the second collaborative decryption segment of the ciphertext data is extracted and XORed with the derived key data to obtain the first plaintext data; the corresponding point coordinate data on the elliptic curve is connected with the first plaintext data and a hash operation is performed to obtain a hash value. If the hash value is the same as the data of the third collaborative decryption segment of the ciphertext data, the first plaintext data is output as plaintext.
[0028] Specifically, in the hash operation, the operation expression after the first plaintext data and the coordinate data are connected is: u=Hash(x2||M′||y2) where u is the hash value and M′ is the first plaintext data.
[0029] A multi-party collaborative signature and decryption system, comprising a collaborative key generation module, a collaborative signature calculation module, and a collaborative decryption calculation module;
[0030] The collaborative key generation module is used to obtain the private key component of the user, use the private key component as the client private key component and perform encoding processing to obtain public key component data, and transmit the public key component data to the collaborative signature server; obtain the private key component of the collaborative signature server, perform collaborative interaction processing based on the public key component data and the private key component of the collaborative signature server to obtain initial public key data, verify the validity of the initial public key data, and publish the verified initial public key data as the collaborative public key;
[0031] The collaborative signature calculation module generates a first random number on the client, performs a point multiplication operation on the first random number and the base point of the elliptic curve to obtain a first random variable, and sends the encoded data of the digest of the client's data to be signed and the first random variable to the collaborative signature server; after receiving the data, the collaborative signature server generates a second random number and a third random number, calculates signature intermediate data according to the second random number, the third random number, the encoded data and the first random variable, and returns the signature intermediate data to the client; the client calculates the collaborative signature data according to the signature intermediate data and the collaborative private key component of the collaborative public key through the private key signing process of the national secret SM2 algorithm;
[0032] The collaborative decryption calculation module is used to obtain ciphertext data through the client, extract the bit string of the first collaborative decryption segment in the ciphertext data and perform validity verification. If the verification passes, a modular inverse calculation is performed through the client's private key component to obtain the first collaborative decryption component data and send it to the server. The server performs a modular inverse calculation on the first collaborative decryption component data in combination with the server's private key component to obtain the second collaborative decryption component data and sends it to the client. The client decrypts the second collaborative decryption component data to obtain a plaintext output.
[0033] The beneficial effects of the present invention are:
[0034] Through the asymmetric collaborative algorithm, private keys can be generated on both the client and the server at the same time. Irreversible calculations can be performed when signing and decrypting, and intermediate data can be transferred. The client and the server can perform collaborative public key generation, collaborative signing, and collaborative decryption without knowing each other's private key components. The generated public key is used to verify the collaborative signature data, encrypt the plaintext data to be encrypted, and use collaborative decryption to verify the encrypted data. As long as the client and the server do not collude, there is no way to recover the real SM2 private key. In the case that the attacker can only break into one of the participants at most, the attacker has no way to recover the complete SM2 private key. Thus, the security of the key is guaranteed; the client and the server each save their own private key components, and the inverse operation cannot be performed on the data involved in the calculation of the private key. It is guaranteed that even if the client private key component is leaked, the real private key will not be leaked. The real private key data in the user's usage scenario is protected. This technology can be used on the client side of the software, such as mobile phones, IoT terminals, and other devices that are not convenient to use hardware password modules. To a certain extent, the user's private key security is guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to facilitate understanding by those skilled in the art, the present invention is further described below with reference to the accompanying drawings.
[0036] Figure 1 A schematic diagram of a flow chart of a multi-party collaborative signing and decryption method of the present invention;
[0037] Figure 2 It is a schematic diagram of the process of the collaborative key generation module of the present invention;
[0038] Figure 3 It is a flowchart of the collaborative signature calculation module of the present invention;
[0039] Figure 4 It is a schematic diagram of the process flow of the collaborative decryption calculation module of the present invention; DETAILED DESCRIPTION
[0040] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the specific implementation methods, structures, features and effects of the present invention are described in detail below in conjunction with the accompanying drawings and preferred embodiments.
[0041] See also Figure 1-4 , a multi-party collaborative signing and decryption method, comprising:
[0042] S1: Obtain the private key component of the user, use the private key component as the client private key component and encode it to obtain public key component data, and pass the public key component data to the collaborative signature server; obtain the private key component of the collaborative signature server, perform collaborative interaction processing based on the public key component data and the private key component of the collaborative signature server to obtain initial public key data, verify the validity of the initial public key data, and publish the verified initial public key data as the collaborative public key;
[0043] S2: The client generates a first random number, performs a point multiplication operation on the first random number and the base point of the elliptic curve to obtain a first random variable, and sends the encoded data of the digest of the client's data to be signed and the first random variable to the collaborative signature server; after receiving the data, the collaborative signature server generates a second random number and a third random number, calculates signature intermediate data according to the second random number, the third random number, the encoded data and the first random variable, and returns the signature intermediate data to the client; the client calculates the collaborative signature data according to the signature intermediate data and the collaborative private key component of the collaborative public key through the private key signing process of the national secret SM2 algorithm;
[0044] S3: Obtain ciphertext data through the client, extract the bit string of the first collaborative decryption segment in the ciphertext data and verify its validity. If the verification is successful, perform a modular inverse calculation on the client's private key component to obtain the first collaborative decryption component data and send it to the server. The server performs a modular inverse calculation on the first collaborative decryption component data in combination with the server's private key component to obtain the second collaborative decryption component data and send it to the client. The client decrypts the second collaborative decryption component data to obtain a plaintext output.
[0045] Specifically, the private key component of the client and the private key component of the collaborative signature server are random numbers that conform to the national encryption SM2 private key value range.
[0046] Specifically, the encoding processing method is: according to Fermat's little theorem, the encrypted plaintext calculation process is irreversibly transformed according to the order of the elliptic curve in the SM2 algorithm, and the calculation formula is:
[0047]
[0048] Among them, PA is the public key component data, d 1 is the private key component of the client, n is the order of the elliptic curve in the SM2 algorithm, and G is the base point of the elliptic curve.
[0049] Specifically, the collaborative interaction processing method is: executing a private key exchange protocol based on the discrete logarithm problem at the collaborative signature server, through which the collaborative signature server and the client generate a temporary session key, and the collaborative signature server uses the session key to encrypt the public key component data to generate initial public key data, and the calculation formula is:
[0050]
[0051] Among them, P is the initial public key data, d 2 is the private key component of the server, It is the collaborative private key component.
[0052] Specifically, the validity verification method is: verify whether the generated initial public key data is a point at infinity in the elliptic curve algorithm corresponding to the checkpoint coordinates in the SM2 algorithm, and the judgment basis of the point at infinity is whether the coordinates of the corresponding checkpoint in the projective coordinate system are (0,0,0) or (1,0,0); if it is verified to be a point at infinity, the collaborative signature server regenerates the private key component until the generated public key is not a point at infinity; wherein the private key components of the client and the collaborative signature server do not perform plaintext interactive calculations.
[0053] In this embodiment, the collaborative signature server is responsible for processing the signature request sent by the client, including receiving the signature request data packet from the client, parsing the information in the request data packet, and performing the corresponding signature operation according to the request content. After completing the signature operation, the collaborative signature server sends the generated signature result back to the client through a secure channel to ensure the security and integrity of the signature process. In addition, multiple participants are allowed to jointly complete the decryption operation of encrypted data, thereby achieving secure sharing and access of data without leaking their respective private keys.
[0054] Specifically, the signature intermediate data includes an identification signature component, a first signature component, and a second signature component, and the calculation formula is:
[0055]
[0056] s 1 =d 2 k 3 ,
[0057] s 2 =d 2 (r+k 2 )mod(n),
[0058] Among them, r is the identification signature component, k 2 is the second random number, k 3 is the third random number, Q 1 is the first random variable, e is the coded data that can identify the summary of the data to be signed, s 1 is the first signature component, s 2 is the second signature component, d 2 is the private key component of the server, for The horizontal coordinate of the corresponding point of the random variable in the elliptic curve.
[0059] Specifically, the collaborative signature data includes an identification signature component and a signature output component value. The signature output component value is obtained by substituting the collaborative private key component of the collaborative public key into the private key in the calculation process through the private key signing process of the national secret SM2 algorithm. The calculation formula is:
[0060] s=d 1 *d 2 (k 1 *k 3 +k 2 )-r+d 1 *d 2 *r,
[0061] Among them, s is the signature output component value, k 1 is the second random number.
[0062] Specifically, the decryption processing method is: the client converts the bit string data type of the first collaborative decryption segment in the ciphertext data into a point on the elliptic curve according to the second collaborative decryption component data and performs validity verification. If the verification passes, the corresponding point coordinate information on the elliptic curve is converted into a bit string data type and the key data is derived. The calculation formula is:
[0063] t=KDF(x2||y2,klen),
[0064] Where t is the derived key data, KDF is the key derivation function, (x2, y2) is the coordinate data of the corresponding point on the elliptic curve, and klen is the key data length;
[0065] If the derived key data is not 0, the data of the second collaborative decryption segment of the ciphertext data is extracted and XORed with the derived key data to obtain the first plaintext data; the corresponding point coordinate data on the elliptic curve is connected with the first plaintext data and a hash operation is performed to obtain a hash value. If the hash value is the same as the data of the third collaborative decryption segment of the ciphertext data, the first plaintext data is output as plaintext.
[0066] Specifically, in the hash operation, the operation expression after the first plaintext data and the coordinate data are connected is: u=Hash(x2||M′||y2) where u is the hash value and M′ is the first plaintext data.
[0067] A multi-party collaborative signature and decryption system, comprising a collaborative key generation module, a collaborative signature calculation module, and a collaborative decryption calculation module;
[0068] The collaborative key generation module is used to obtain the private key component of the user, use the private key component as the client private key component and perform encoding processing to obtain public key component data, and transmit the public key component data to the collaborative signature server; obtain the private key component of the collaborative signature server, perform collaborative interaction processing based on the public key component data and the private key component of the collaborative signature server to obtain initial public key data, verify the validity of the initial public key data, and publish the verified initial public key data as the collaborative public key;
[0069] The collaborative signature calculation module generates a first random number on the client, performs a point multiplication operation on the first random number and the base point of the elliptic curve to obtain a first random variable, and sends the encoded data of the digest of the client's data to be signed and the first random variable to the collaborative signature server; after receiving the data, the collaborative signature server generates a second random number and a third random number, calculates signature intermediate data according to the second random number, the third random number, the encoded data and the first random variable, and returns the signature intermediate data to the client; the client calculates the collaborative signature data according to the signature intermediate data and the collaborative private key component of the collaborative public key through the private key signing process of the national secret SM2 algorithm;
[0070] The collaborative decryption calculation module is used to obtain ciphertext data through the client, extract the bit string of the first collaborative decryption segment in the ciphertext data and perform validity verification. If the verification passes, a modular inverse calculation is performed through the client's private key component to obtain the first collaborative decryption component data and send it to the server. The server performs a modular inverse calculation on the first collaborative decryption component data in combination with the server's private key component to obtain the second collaborative decryption component data and sends it to the client. The client decrypts the second collaborative decryption component data to obtain a plaintext output.
[0071] The computer storage medium of the embodiment of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples (non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, device or device.
[0072] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, which carry computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0073] The program code included on the computer readable medium can be transmitted with any appropriate medium, including but not limited to wireless, electric wire, optical cable, RF, etc., or any suitable combination of the above. The computer program code for performing the operation of the present invention can be written in one or more programming languages or their combinations, and the programming language includes object-oriented programming languages-such as Java, Smalltalk, C++, and also includes conventional procedural programming languages-such as "C" language or similar programming languages. The program code can be executed completely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer and partially on the remote computer, or completely on the remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, using an Internet service provider to connect through the Internet).
[0074] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any form. Although the present invention has been disclosed as a preferred embodiment as above, it is not used to limit the present invention. Any technical personnel in this field can make some changes or modify the technical contents disclosed above into equivalent embodiments without departing from the scope of the technical solution of the present invention. However, any simple modification, equivalent change and modification made to the above embodiments according to the technical essence of the present invention without departing from the content of the technical solution of the present invention still fall within the scope of the technical solution of the present invention.
Claims
1. A multi-party collaborative signing and decryption method, characterized in that: include: S1: Obtain the user's private key component, use the private key component as the client private key component and encode it to obtain public key component data, and transmit the public key component data to the collaborative signature server; Acquire the private key component of the collaborative signature server, perform collaborative interaction processing on the public key component data and the private key component of the collaborative signature server to obtain initial public key data, verify the validity of the initial public key data, and publish the verified initial public key data as a collaborative public key; S2: The client generates a first random number, performs a point multiplication operation on the first random number and the base point of the elliptic curve to obtain a first random variable, and sends the encoded data of the digest of the client's data to be signed and the first random variable to the collaborative signature server; after receiving the data, the collaborative signature server generates a second random number and a third random number, calculates signature intermediate data according to the second random number, the third random number, the encoded data and the first random variable, and returns the signature intermediate data to the client; The client calculates the collaborative signature data according to the collaborative private key component of the collaborative public key and the signature intermediate data through the private key signature process of the national secret SM2 algorithm; S3: Obtain ciphertext data through the client, extract the bit string of the first collaborative decryption segment in the ciphertext data and verify its validity. If the verification is successful, perform a modular inverse calculation on the client's private key component to obtain the first collaborative decryption component data and send it to the server. The server performs a modular inverse calculation on the first collaborative decryption component data in combination with the server's private key component to obtain the second collaborative decryption component data and send it to the client. The client decrypts the second collaborative decryption component data to obtain a plaintext output.
2. The multi-party collaborative signing and decryption method according to claim 1, characterized in that: The private key component of the client and the private key component of the collaborative signature server are random numbers that conform to the national encryption SM2 private key value range.
3. The multi-party collaborative signing and decryption method according to claim 1, characterized in that: The encoding processing method is: according to Fermat's little theorem, the encrypted plaintext calculation process is irreversibly transformed according to the order of the elliptic curve in the SM2 algorithm, and the calculation formula is: Among them, PA is the public key component data, d1 is the private key component of the client, n is the order of the elliptic curve in the SM2 algorithm, and G is the base point of the elliptic curve.
4. The multi-party collaborative signing and decryption method according to claim 3, characterized in that: The collaborative interaction processing method is: a private key exchange protocol based on the discrete logarithm problem is executed on the collaborative signature server. Through the private key exchange protocol, the collaborative signature server and the client generate a temporary session key. The collaborative signature server uses the session key to encrypt the public key component data to generate initial public key data. The calculation formula is: Among them, P is the initial public key data, d2 is the private key component of the server, It is the collaborative private key component.
5. The multi-party collaborative signing and decryption method according to claim 1, characterized in that: The validity verification method is: verify whether the coordinates of the checkpoint corresponding to the elliptic curve algorithm in the SM2 algorithm generated by the initial public key data are infinite points, and the determination criterion of the infinite point is whether the coordinates of the corresponding checkpoint in the projective coordinate system are (0,0,0) or (1,0,0); if it is verified to be an infinite point, the collaborative signature server regenerates the private key component until the generated public key is not an infinite point; The private key components of the client and the collaborative signature server are not calculated in plain text.
6. The multi-party collaborative signing and decryption method according to claim 1, characterized in that: The signature intermediate data includes an identification signature component, a first signature component, and a second signature component, and the calculation formula is: s1=d2k3, s2=d2(r+k2)mod(n), Where r is the identification signature component, k2 is the second random number, k3 is the third random number, Q1 is the first random variable, e is the encoded data of the digest of the data to be signed, s1 is the first signature component, s2 is the second signature component, and d2 is the private key component of the server. for The horizontal coordinate of the corresponding point of the random variable in the elliptic curve.
7. The multi-party collaborative signing and decryption method according to claim 1, characterized in that: The collaborative signature data includes an identification signature component and a signature output component value. The signature output component value is obtained by substituting the collaborative private key component of the collaborative public key into the private key in the calculation process through the private key signature process of the national secret SM2 algorithm. The calculation formula is: s=d1*d2(k1*k3+k2)-r+d1*d2*r, Among them, s is the signature output component value, and k1 is the second random number.
8. The multi-party collaborative signing and decryption method according to claim 1, characterized in that: The decryption processing method is: the client converts the bit string data type of the first collaborative decryption segment in the ciphertext data into a point on the elliptic curve according to the second collaborative decryption component data and performs validity verification. If the verification passes, the corresponding point coordinate information on the elliptic curve is converted into a bit string data type and key data is derived. The calculation formula is: t=KDF(x2||y2,klen), Where t is the derived key data, KDF is the key derivation function, (x2, y2) is the coordinate data of the corresponding point on the elliptic curve, and klen is the key data length; If the derived key data is not 0, the data of the second collaborative decryption segment of the ciphertext data is extracted and XORed with the derived key data to obtain the first plaintext data; the corresponding point coordinate data on the elliptic curve is connected with the first plaintext data and a hash operation is performed to obtain a hash value. If the hash value is the same as the data of the third collaborative decryption segment of the ciphertext data, the first plaintext data is output as plaintext.
9. The multi-party collaborative signing and decryption method according to claim 8, characterized in that: In the hash operation, the operation expression after the first plaintext data and the coordinate data are connected is: u=Hash(x2||M′||y2), where u is the hash value and M′ is the first plaintext data.
10. A multi-party collaborative signing and decryption system, used to execute the method according to claims 1-9, characterized in that: It includes collaborative key generation module, collaborative signature calculation module and collaborative decryption calculation module; The collaborative key generation module is used to obtain the user's private key component, use the private key component as the client private key component and encode it to obtain public key component data, and transmit the public key component data to the collaborative signature server; Acquire the private key component of the collaborative signature server, perform collaborative interaction processing on the public key component data and the private key component of the collaborative signature server to obtain initial public key data, verify the validity of the initial public key data, and publish the verified initial public key data as a collaborative public key; The collaborative signature calculation module generates a first random number on the client, performs a point multiplication operation on the first random number and a base point of the elliptic curve to obtain a first random variable, and sends the encoded data of the digest of the client's data to be signed and the first random variable to the collaborative signature server; after receiving the data, the collaborative signature server generates a second random number and a third random number, calculates signature intermediate data according to the second random number, the third random number, the encoded data and the first random variable, and returns the signature intermediate data to the client; The client calculates the collaborative signature data according to the collaborative private key component of the collaborative public key and the signature intermediate data through the private key signature process of the national secret SM2 algorithm; The collaborative decryption calculation module is used to obtain ciphertext data through the client, extract the bit string of the first collaborative decryption segment in the ciphertext data and perform validity verification. If the verification passes, a modular inverse calculation is performed through the client's private key component to obtain the first collaborative decryption component data and send it to the server. The server performs a modular inverse calculation on the first collaborative decryption component data in combination with the server's private key component to obtain the second collaborative decryption component data and sends it to the client. The client decrypts the second collaborative decryption component data to obtain a plaintext output.
Citation Information
Patent Citations
Collaborative signature and decryption method, apparatus and system of SM2 algorithm
CN107196763A
Method for realizing multi-party collaborative identity authentication and key negotiation processing in cloud environment based on domestic commercial cryptographic algorithm
CN117527229A
Cited By
Anti-quantum collaborative signature method and anti-quantum collaborative signature system
CN120710685A