Three-party collaborative SM2 signature generation method
By using the secret sharing technology of pseudo-random functions and shared keys in the three-party collaborative SM2 signature generation method, the problem of difficulty in balancing security, reliability and performance in the three-party environment is solved in the existing technology, and a safe, reliable and fast digital signature generation is achieved, and one party is tolerated to be disconnected or committed evil.
Patent Information
- Application Number
- CN202510054802.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-05-06
AI Technical Summary
When the existing technology applies collaborative signature technology, it is impossible to effectively balance security, reliability and performance, especially in a tripartite environment, it is difficult to ensure the safety and reliability of quickly generating digital signatures.
The three-party collaborative SM2 signature generation method is adopted. Through pseudo-random functions and shared secret keys, the three participants generate secret sharing of the signature private keys, and restore the secret value to be shared by copying the secret sharing technology, and calculate the intermediate parameters to generate the complete signature. If one party is disconnected, the other two parties use the two parties' additive secret sharing technology to generate a new signature private key secret sharing.
It realizes the ability to generate digital signatures safely, reliably and quickly in a three-party environment, tolerate one party being disconnected or committing evil, and can still generate a complete digital signature, optimize the communication volume between participants, and improve communication efficiency and system performance.
Smart Images

Figure CN119945672A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a three-party collaborative SM2 signature generation method. Background Art
[0002] SM2 is an algorithm that uses elliptic curve cryptography to implement digital signatures. It provides a secure and efficient digital signature method based on the mathematical properties of elliptic curves. Digital signature technology is widely used in fields such as cryptocurrency, digital certificates, and secure communications. Similar to traditional signatures, it simulates the function of paper signatures or seals through specific cryptographic algorithms to ensure the integrity, authenticity, and non-repudiation of digital resources. SM2 signature technology is safe in theory, but it may face some threats and attacks in practical applications. The most serious security threat is the leakage of private keys. If the private key is leaked, hackers or attackers can use the private key to generate valid signatures and impersonate legitimate users to conduct fraudulent activities. Therefore, it is crucial to protect the security of private keys.
[0003] Collaborative signature technology allows multiple parties to jointly generate keys, preventing any single entity or a small number of colluders from obtaining the complete private key without permission. Multiple signers jointly complete the signature to ensure that multiple parties agree and authorize the content of the signature, preventing a single entity from abusing the signing authority. This technology is very useful in scenarios that require the participation and consent of multiple parties, such as multi-party contracts, multi-party authorization, etc. However, collaborative signature technology may also increase complexity and computational costs. Existing technologies cannot guarantee a balance in security, reliability, and performance when applying these technologies. Summary of the invention
[0004] The purpose of the present invention is to overcome the deficiencies in the prior art and provide a three-party collaborative SM2 signature generation method that fully balances the security requirements and performance requirements of collaborative signature technology to ensure that digital signatures are generated safely, reliably and quickly in a three-party environment.
[0005] To achieve the above object, the present invention is implemented by adopting the following technical solutions: The present invention provides a three-party collaborative SM2 signature generation method, comprising: Using the pseudo-random function and the obtained shared key, the three parties respectively generate a secret share of the first signature private key, and generate a first signature verification public key according to the secret share of the first signature private key; The three parties use the replicated secret sharing technology to recover the secret value to be shared, calculate the intermediate parameters of the first complete signature according to the secret value to be shared, and obtain the first complete signature according to the message to be signed, the first signature verification public key and the intermediate parameters of the first complete signature; If one participant is offline or corrupted by an adversary, the other two participants use a two-party additive secret sharing technique to generate a secret share of the second signature private key, and generate a second signature verification public key based on the secret share of the second signature private key; The other two participants calculate the intermediate parameters of the second complete signature, and obtain the second complete signature according to the message to be signed, the second signature verification public key, and the intermediate parameters of the second complete signature.
[0006] Optionally, using a pseudo-random function and an acquired shared key, the three parties respectively generate a secret share of the first signature private key, and generate a first signature verification public key according to the secret share of the first signature private key, including: Each participant initializes a counter and generates a shared key according to a preset initialization ideal function; Each participant calculates a secret share of the first signature private key using a pseudo-random function and a shared key; Each participant calculates the components of the first signature verification public key based on the secret sharing of the first signature private key, and sends the components of the first signature verification public key to other participants; Each participant determines whether the components of its own first signature verification public key are consistent with the components of the received first signature verification public key; if the components of each first signature verification public key are consistent, the components of the first signature verification public key are valid, and the first signature verification public key is calculated based on the components of the first signature verification public key; otherwise, the components of the first signature verification public key are invalid and the protocol terminates.
[0007] Optionally, each participant calculates a secret share of the first signature private key using a pseudo-random function and a shared key, including: First Party calculate and , the second party calculate and , third party calculate and ; in, , Indicates the first party The secret sharing of the calculated first signature private key; , Indicates the second party The secret sharing of the calculated first signature private key; , Indicates the third party The secret sharing of the calculated first signature private key; , Indicates the first party The generated shared key; , Indicates the second party The generated shared key; , Indicates the third party The generated shared key; Indicates the first party The corresponding counter; Indicates the second party The corresponding counter; Indicates the third party The corresponding counter; Represents a pseudorandom function.
[0008] Optionally, the three parties use a secret sharing technology to recover the secret value to be shared, calculate the intermediate parameter of the first complete signature according to the secret value to be shared, and obtain the first complete signature according to the message to be signed, the first signature verification public key, and the intermediate parameter of the first complete signature, including: Each participant updates the counter and uses the pseudo-random function and the shared key to calculate the first random number Secret sharing; Each participant is based on the first random number Calculate the components of the first signature parameter by secret sharing, and send the components of the first signature parameter to other participants; Each participant determines whether the components of its own first signature parameter are consistent with the components of the received first signature parameter; if the components of each first signature parameter are consistent, the components of the first signature parameter are valid, and the first signature parameter is calculated based on the components of the first signature parameter; otherwise, the components of the first signature parameter are invalid, and the protocol terminates; Each participant updates the counter again and uses the pseudo-random function and the shared key to calculate the second random number Secret sharing; Each participant uses the first signature parameter and the first random number Secret sharing and second random number Secret sharing, calculate the first intermediate parameter The first intermediate parameter The weight is sent to other participants; Each participant shares the first signature private key and the second random number Secret sharing, calculate the second intermediate parameter The second intermediate parameter The weight is sent to other participants; Each participant is based on the first intermediate parameter The component and the second intermediate parameter , calculate the components of the second signature parameter, and send the components of the second signature parameter to other participants; A second signature parameter is calculated according to the components of the first signature parameter and the components of the second signature parameter, and a first complete signature is obtained according to the first signature parameter and the second signature parameter.
[0009] Optionally, each participant may generate a first signature parameter and a first random number. Secret sharing and second random number Secret sharing, calculate the first intermediate parameter The first intermediate parameter The components are sent to other participants, including: First Party calculate , the second party calculate , third party calculate ; First Party Will Send to third party , the second party Will Sent to the first party , third party Will Send to the second party ; in, Indicates the first party The first intermediate parameter of the calculation The amount of Indicates the second party The first intermediate parameter of the calculation The amount of Indicates the third party The first intermediate parameter of the calculation The weight of , Indicates the first party The first random number Secret sharing; , Indicates the second party The first random number Secret sharing; , Indicates the third party The first random number Secret sharing; , Indicates the first party The second random number Secret sharing; , Indicates the second party The second random number Secret sharing; , Indicates the third party The second random number Secret sharing; Indicates the first signature parameter.
[0010] Optionally, each participant shares the first signature private key and the second random number Secret sharing, calculate the second intermediate parameter The second intermediate parameter The components are sent to other participants, including: First Party calculate , the second party calculate , third party calculate ; First Party Will Send to the second party separately and third parties , the second party Will Sent to the first party and third parties , third party Will Sent to the first party and the second party ; in, Indicates the first party The second intermediate parameter of the calculation The amount of Indicates the second party The second intermediate parameter of the calculation The amount of Indicates the third party The second intermediate parameter of the calculation The amount of , Indicates the first party The secret sharing of the calculated first signature private key; , Indicates the second party The secret sharing of the calculated first signature private key; , Indicates the third party The secret sharing of the calculated first signature private key; , Indicates the first party The second random number Secret sharing; , Indicates the second party The second random number Secret sharing; , Indicates the third party The second random number Secret sharing; Indicates the first signature parameter.
[0011] Optionally, the first complete signature is ,in: ; ; ; ; ; in, Represents the first signature parameter; Represents the sum of the components of the first signature parameter The horizontal axis of represents a cryptographic function derived from a cryptographic hash function; Represents the message to be signed; Indicates the participants Calculate the components of the first signature parameter; Represents the second signature parameter; Indicates the participants the components of the calculated second signature parameters; Indicates the participants The first intermediate parameter of the calculation The amount of Indicates the participants The second intermediate parameter of the calculation The amount.
[0012] Optionally, if one of the participants is offline or corrupted by a malicious adversary, two-party additive secret sharing is used to replace the duplicate secret sharing, and the other two participants respectively generate secret sharing of the second signature private key, and generate the second signature verification public key according to the secret sharing of the second signature private key, including: The other two participants each randomly select an integer as the secret share of their own second signature private key, calculate the components of the second signature verification public key and its corresponding zero-knowledge proof based on the secret share of their own second signature private key, and send the components of the second signature verification public key and its corresponding zero-knowledge proof to the other party; The other two participants verify in turn whether the received zero-knowledge proof is legal; if it is legal, the second signature verification public key is calculated based on the components of the second signature verification public key; otherwise, the protocol terminates.
[0013] Optionally, the other two participants calculate the intermediate parameters of the second complete signature, and obtain the second complete signature according to the message to be signed, the second signature verification public key, and the intermediate parameters of the second complete signature, including: The other two participants each randomly select two integers, calculate the components of the third signature parameter and their corresponding zero-knowledge proof, and send the components of the third signature parameter and their corresponding zero-knowledge proof to the other party; The other two participants verify in turn whether the received zero-knowledge proof is legal; if it is legal, the third signature parameter is calculated based on the components of the third signature parameter; otherwise, the protocol terminates; Using the ideal function, the other two participants obtain the first calculation result based on the two randomly selected integers and the third signature parameter, and calculate the third intermediate parameter based on the first calculation result. The third intermediate parameter The weight is sent to the other party; Using the ideal function, the other two participants obtain the second calculation result based on the two randomly selected integers and the secret sharing of the second signature private key, and calculate the fourth intermediate parameter based on the second calculation result. The fourth intermediate parameter The weight is sent to the other party; According to the third intermediate parameter The components and the fourth intermediate parameter The fourth signature parameter is calculated, and the second complete signature is obtained according to the third signature parameter and the fourth signature parameter.
[0014] Optionally, the second complete signature is ,in: ; ; ; ; ; ; ; in, Represents the third signature parameter; The sum of the components representing the third signature parameter The horizontal axis of represents a cryptographic function derived from a cryptographic hash function; Represents the message to be signed; Indicates the first party the components of the calculated third signature parameter; Indicates the second party the components of the calculated third signature parameter; Indicates the fourth signature parameter; , Indicates the first party The third intermediate parameter of the calculation The fourth intermediate parameter The weight of , Indicates the second party The third intermediate parameter of the calculation The fourth intermediate parameter The weight of Represents large prime numbers; Indicates the first party Two integers chosen randomly; , Indicates the second party Two integers chosen randomly; , represents the first calculation result; , Respectively represent the first party and the second party The secret sharing of the calculated second signature private key; , Indicates the second calculation result.
[0015] Compared with the prior art, the present invention has the following beneficial effects: The present invention can enable three parties to collaboratively generate a complete digital signature, and can also tolerate the situation where one party is offline or does evil (inadvertently or corrupted by a malicious adversary). Any two participating parties can recover the secret value. When one party is offline, the remaining two parties still hold all shares for secret sharing, thereby collaboratively generating a complete digital signature, fully balancing the security requirements and performance requirements of collaborative signature technology, and ensuring the safe, reliable and fast generation of digital signatures in a three-party environment; relying on the security of zero-knowledge proof and secure multi-party computing protocols, the correctness and privacy of three-party collaborative signatures can be met, the sharing of secret components in the three-party signature is optimized, the communication volume between the participating parties is reduced, and communication efficiency is improved. At the same time, a parallel strategy can be adopted to improve system performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 The figure is a flow chart of a three-party collaborative SM2 signature generation method according to an embodiment of the present invention. DETAILED DESCRIPTION
[0017] The technical solution of the present invention is described in detail below through the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solution of the present invention, rather than limitations on the technical solution of the present invention. The embodiments of the present invention and the technical features in the embodiments may be combined with each other unless there is a conflict.
[0018] The term "and / or" is only a description of the association relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " generally indicates that the related objects are in an "or" relationship.
[0019] Example 1
[0020] like Figure 1 As shown, this embodiment introduces a three-party collaborative SM2 signature generation method, which specifically includes the following steps: Step 1: Using a pseudo-random function and the obtained shared key, the three parties generate a secret share of the first signature private key respectively, and generate a first signature verification public key according to the secret share of the first signature private key; Step 2: The three parties use the replicated secret sharing technology to recover the secret value to be shared, calculate the intermediate parameters of the first complete signature according to the secret value to be shared, and obtain the first complete signature according to the message to be signed, the first signature verification public key and the intermediate parameters of the first complete signature; Step 3: If one participant is offline or corrupted by the adversary, the other two participants use two-party additive secret sharing technology to generate a secret share of the second signature private key, and generate a second signature verification public key based on the secret share of the second signature private key; Step 4: The other two participants calculate the intermediate parameters of the second complete signature, and obtain the second complete signature according to the message to be signed, the second signature verification public key and the intermediate parameters of the second complete signature.
[0021] When this embodiment is applied, in a three-party environment, only any two parties need to be online to generate a complete digital signature, thereby ensuring the flexibility of the digital signature; the security dependency directly relies on the security of multi-prover zero-knowledge proof and secure multi-party computing protocol, which can meet the correctness and privacy of the three-party collaborative signature; the sharing of the secret component in the three-party signature is optimized, reducing the communication volume between the participants and improving the communication efficiency, and at the same time, a parallel strategy can be adopted to improve the system performance.
[0022] Example 2
[0023] like Figure 1 As shown, based on Example 1, this example introduces a three-party collaborative SM2 signature generation method. To ensure universality, the parameter selection of this example is consistent with the standard parameters of the SM2 signature algorithm. The specific symbols are described as follows: , : Participants, among which, , , : The first party, the second party, the third party; : a large prime number; :From 1, 2, ..., The set of integers composed of; :Order The elliptic curve group of ; : Elliptic Curve Generators; : Elliptic Curve On point times of, is a positive integer; : A cryptographic function derived from a cryptographic hash function; : Initialize the ideal function and generate the seed key for copying secret sharing; : Pseudo-random function PRF; : A zero-knowledge proof algorithm for generating statements about discrete logarithmic relations; : Zero-knowledge proof of discrete logarithm relations; : The message to be signed.
[0024] The method includes three-party collaborative key generation, three-party collaborative signature generation, two-party collaborative key generation and two-party collaborative signature generation, and specifically includes the following steps: Step 1: Using the pseudo-random function and the obtained shared key, the three parties generate the secret sharing of the first signature private key respectively, and generate the first signature verification public key according to the secret sharing of the first signature private key, specifically: Each participant Initialize the corresponding counter , and based on the preset initialization ideal function Generate their own shared secret key, Holds a shared key , Holds a shared key , Holds a shared key . The random number .
[0025] Each participant Using pseudo-random functions The secret sharing of the first signature private key is calculated with the shared key held, that is, calculate and , calculate and , calculate and ; in, , Indicates the first party The secret sharing of the calculated first signature private key; , Indicates the second party The secret sharing of the calculated first signature private key; , Indicates the third party The secret sharing of the calculated first signature private key; , Indicates the first party The generated shared key; , Indicates the second party The generated shared key; , Indicates the third party The generated shared secret key.
[0026] Each participant The components of the first signature verification public key are calculated based on the secret sharing of the first signature private key held by each party, and the components of the first signature verification public key are sent to other participants, that is, calculate and , calculate and , calculate and , Participants Will Send to participants , Participants Will Send to participants , Participants Will Send to participants .
[0027] in, Indicates the first party Calculate a component of the first signature verification public key; Indicates the second party Calculate a component of the first signature verification public key; Indicates the third party The first signature computed verifies the public key component.
[0028] Each participant Will hold two copies of the first signature verification public key and , based on which the first signature verification public key is verified and , and , and If the components of each first signature verification public key are consistent, it means that each participant has honestly executed the protocol, the components of the first signature verification public key are valid, and the first signature verification public key is calculated. ; If there is an inconsistency in the components of the first signature verification public key, it means that there is a malicious party who dishonestly executes the protocol, the component of the first signature verification public key is invalid, and the protocol (three-party collaborative key generation step) is terminated.
[0029] Step 2: The three parties use the replicated secret sharing technology to restore the secret value to be shared, calculate the intermediate parameters of the first complete signature based on the secret value to be shared, and obtain the first complete signature based on the message to be signed, the first signature verification public key and the intermediate parameters of the first complete signature, specifically: Each participant Update the corresponding counter , using a pseudo-random function The first random number is calculated using the shared key Secret sharing, that is calculate and , calculate and , calculate and .
[0030] in, , Indicates the first party The first random number Secret sharing; , Indicates the second party The first random number Secret sharing; , Indicates the third party The first random number Secret sharing.
[0031] Each participant According to the first random number held by each The secret sharing of the first signature parameter is calculated The first signature parameter is sent to other participants, namely the first participant calculate and , the second party calculate and , third party calculate and , Participants Will Send to participants , Participants Will Send to participants , Participants Will Send to participants .
[0032] in, Indicates the first party Calculate the first signature parameter The amount of Indicates the second party Calculate the first signature parameter The weight of Indicates the third party Calculate the first signature parameter The amount.
[0033] Each participant Will hold two copies of the first signature parameter The amount and , and verify the first signature parameter accordingly The amount and , and , and If the components of each first signature parameter are consistent, it means that each participant honestly executes the protocol, the components of the first signature parameter are valid, and the first signature parameter is calculated. , The value of the abscissa, where the components of the first signature parameter are summed , Indicates the participants The components of the first signature parameter are calculated; if there is an inconsistency in the components of the first signature parameter, it means that there is a malicious party who dishonestly executes the protocol, the components of the first signature parameter are invalid, and the protocol terminates.
[0034] Each participant Update the corresponding counter again , using a pseudo-random function The second random number is calculated using the shared key Secret sharing, that is calculate and , calculate and , calculate and ; in, , Indicates the first party The second random number Secret sharing; , Indicates the second party The second random number Secret sharing; , Indicates the third party The second random number Secret sharing.
[0035] Each participant According to the first signature parameter, the first random number Secret sharing and second random number Secret sharing, calculate the first intermediate parameter number The first intermediate parameter The components are sent to other participants, that is, calculate , calculate , calculate ; First Party Will Send to third party , the second party Will Sent to the first party , third party Will Send to the second party ; in, Indicates the first party The first intermediate parameter of the calculation The weight of Indicates the second party The first intermediate parameter of the calculation The weight of Indicates the third party The first intermediate parameter of the calculation The amount.
[0036] Each participant shares the first signature private key and the second random number Secret sharing, calculate the second intermediate parameter The second intermediate parameter The components are sent to other participants, that is, calculate , calculate , calculate ; First Party Will Send to the second party separately and third parties , the second party Will Sent to the first party and third parties , third party Will Sent to the first party and the second party ; in, Indicates the first party The second intermediate parameter of the calculation The weight of Indicates the second party The second intermediate parameter of the calculation The weight of Indicates the third party The second intermediate parameter of the calculation The amount.
[0037] Each participant is based on the first intermediate parameter The component and the second intermediate parameter , calculate the component of the second signature parameter, and send the component of the second signature parameter to other participants, that is, calculate and , calculate and , calculate and ;in, , Indicates the participants The second intermediate parameter of the calculation , and calculate , Represents large prime numbers.
[0038] Will Send to , Will Send to , Will Send to .
[0039] At this point, each participant Both hold the component of the second signature parameter .
[0040] Calculate the second signature parameter based on the components of the first signature parameter and the components of the second signature parameter ,in, , a first complete signature is obtained according to the first signature parameter and the second signature parameter, wherein the first complete signature is .
[0041] Step 3: If one participant is offline or corrupted by the adversary, the other two participants use the two-party additive secret sharing technique to generate the secret sharing of the second signature private key, and generate the second signature verification public key based on the secret sharing of the second signature private key, specifically: If the third party Lost connection or corrupted by malicious adversaries, exist Randomly select an integer from As the secret sharing of its own second signature private key, exist Randomly select an integer from The secret shared as its own second signature private key.
[0042] Based on the secret sharing of its own second signature private key Calculate the second signature verification public key component And its corresponding zero-knowledge proof , the second signature verification public key component And its corresponding zero-knowledge proof Send to ; Based on the secret sharing of its own second signature private key Calculate the second signature verification public key component And its corresponding zero-knowledge proof , the second signature verification public key component And its corresponding zero-knowledge proof Send to .
[0043] in, is an integer order of an elliptic curve The base point, Used to generate zero-knowledge proofs, is a set of integers.
[0044] Received of , back, Received of , After that, verify the zero-knowledge proof in turn and Is it legal? If the verification is successful, it is legal, then calculate the second signature verification public key , and otherwise, the Agreement shall terminate.
[0045] Step 4: The other two participants calculate the intermediate parameters of the second complete signature, and obtain the second complete signature according to the message to be signed, the second signature verification public key and the intermediate parameters of the second complete signature, specifically: exist Randomly select two integers from , calculate the components of the third signature parameter And its corresponding zero-knowledge proof , the component of the third signature parameter And its corresponding zero-knowledge proof Send to ; exist Randomly select two integers from , calculate the components of the third signature parameter And its corresponding zero-knowledge proof , the component of the third signature parameter And its corresponding zero-knowledge proof Send to .
[0046] Received of back, Received of After that, verify the zero-knowledge proof in turn and Is it legal? If the verification is successful, it is legal, then calculate the third signature parameter , The sum of the components representing the third signature parameter The horizontal axis of .
[0047] Calculate the first intermediate variable The amount ,Will and Enter the ideal function , output the component of the first calculation result , the component of the first calculation result Send to , Calculate the first intermediate variable The amount ,Will and Enter the ideal function , output the component of the first calculation result , the component of the first calculation result Send to ,in, satisfy .
[0048] Ideal function Defined as ,in ; In the formula, , , , , , Respectively represent any given integer.
[0049] Calculate the third intermediate parameter The amount , the third intermediate parameter The amount Send to ; Calculate the third intermediate parameter The amount , the third intermediate parameter The amount Send to .
[0050] Calculate the second intermediate variable The amount ,Will and Enter the ideal function , output the component of the second calculation result , the component of the second calculation result Send to , Calculate the second intermediate variable The amount ,Will and Enter the ideal function , output the component of the second calculation result , the component of the second calculation result Send to ,in, satisfy .
[0051] Calculate the fourth intermediate parameter The amount , the fourth intermediate parameter The amount Send to ; Calculate the fourth intermediate parameter The amount , the fourth intermediate parameter The amount Send to .
[0052] According to the third intermediate parameter The components and the fourth intermediate parameter Components, calculate the fourth signature parameter , get the second complete signature based on the third signature parameter and the fourth signature parameter .
[0053] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A three-party collaborative SM2 signature generation method, characterized in that: include: Using the pseudo-random function and the obtained shared key, the three parties respectively generate a secret share of the first signature private key, and generate a first signature verification public key according to the secret share of the first signature private key; The three parties use the replicated secret sharing technology to recover the secret value to be shared, calculate the intermediate parameters of the first complete signature according to the secret value to be shared, and obtain the first complete signature according to the message to be signed, the first signature verification public key and the intermediate parameters of the first complete signature; If one participant is offline or corrupted by an adversary, the other two participants use a two-party additive secret sharing technique to generate a secret share of the second signature private key, and generate a second signature verification public key based on the secret share of the second signature private key; The other two participants calculate the intermediate parameters of the second complete signature, and obtain the second complete signature according to the message to be signed, the second signature verification public key, and the intermediate parameters of the second complete signature.
2. The three-party collaborative SM2 signature generation method according to claim 1 is characterized in that: Using the pseudo-random function and the obtained shared key, the three parties respectively generate a secret share of the first signature private key, and generate a first signature verification public key according to the secret share of the first signature private key, including: Each participant initializes a counter and generates a shared key according to a preset initialization ideal function; Each participant calculates a secret share of the first signature private key using a pseudo-random function and a shared key; Each participant calculates the components of the first signature verification public key based on the secret sharing of the first signature private key, and sends the components of the first signature verification public key to other participants; Each participant determines whether the components of its own first signature verification public key are consistent with the components of the received first signature verification public key; if the components of each first signature verification public key are consistent, the components of the first signature verification public key are valid, and the first signature verification public key is calculated based on the components of the first signature verification public key; otherwise, the components of the first signature verification public key are invalid and the protocol terminates.
3. The three-party collaborative SM2 front generation method according to claim 2 is characterized in that: Each participant uses a pseudo-random function and a shared key to calculate the secret share of the first signature private key, including: First Party calculate and , the second party calculate and , third party calculate and ; in, , Indicates the first party The secret sharing of the calculated first signature private key; , Indicates the second party The secret sharing of the calculated first signature private key; , Indicates the third party The secret sharing of the calculated first signature private key; , Indicates the first party The generated shared key; , Indicates the second party The generated shared key; , Indicates the third party The generated shared key; Indicates the first party The corresponding counter; Indicates the second party The corresponding counter; Indicates the third party The corresponding counter; Represents a pseudorandom function.
4. The three-party collaborative SM2 signature generation method according to claim 1 is characterized in that: The three parties use secret sharing technology to recover the secret value to be shared, calculate the intermediate parameters of the first complete signature according to the secret value to be shared, and obtain the first complete signature according to the message to be signed, the first signature verification public key and the intermediate parameters of the first complete signature, including: Each participant updates the counter and uses the pseudo-random function and the shared key to calculate the first random number Secret sharing; Each participant is based on the first random number Calculate the components of the first signature parameter by secret sharing, and send the components of the first signature parameter to other participants; Each participant determines whether the components of its own first signature parameter are consistent with the components of the received first signature parameter; if the components of each first signature parameter are consistent, the components of the first signature parameter are valid, and the first signature parameter is calculated based on the components of the first signature parameter; otherwise, the components of the first signature parameter are invalid, and the protocol terminates; Each participant updates the counter again and uses the pseudo-random function and the shared key to calculate the second random number Secret sharing; Each participant uses the first signature parameter and the first random number Secret sharing and second random number Secret sharing, calculate the first intermediate parameter The first intermediate parameter The weight is sent to other participants; Each participant shares the first signature private key and the second random number Secret sharing, calculate the second intermediate parameter The second intermediate parameter The weight is sent to other participants; Each participant is based on the first intermediate parameter The component and the second intermediate parameter , calculate the components of the second signature parameter, and send the components of the second signature parameter to other participants; A second signature parameter is calculated according to the components of the first signature parameter and the components of the second signature parameter, and a first complete signature is obtained according to the first signature parameter and the second signature parameter.
5. The three-party collaborative SM2 signature generation method according to claim 4 is characterized in that: Each participant uses the first signature parameter and the first random number Secret sharing and second random number Secret sharing, calculate the first intermediate parameter The first intermediate parameter The components are sent to other participants, including: First Party calculate , the second party calculate , third party calculate ; First Party Will Send to third party , the second party Will Sent to the first party , third party Will Send to the second party ; in, Indicates the first party The first intermediate parameter of the calculation The weight of Indicates the second party The first intermediate parameter of the calculation The weight of Indicates the third party The first intermediate parameter of the calculation The amount of , Indicates the first party The first random number Secret sharing; , Indicates the second party The first random number Secret sharing; , Indicates the third party The first random number Secret sharing; , Indicates the first party The second random number Secret sharing; , Indicates the second party The second random number Secret sharing; , Indicates the third party The second random number Secret sharing; Indicates the first signature parameter.
6. The three-party collaborative SM2 signature generation method according to claim 4 is characterized in that: Each participant shares the first signature private key and the second random number Secret sharing, calculate the second intermediate parameter The second intermediate parameter The components are sent to other participants, including: First Party calculate , the second party calculate , third party calculate ; First Party Will Send to the second party separately and third parties , the second party Will Sent to the first party and third parties , third party Will Sent to the first party and the second party ; in, Indicates the first party The second intermediate parameter of the calculation The amount of Indicates the second party The second intermediate parameter of the calculation The amount of Indicates the third party The second intermediate parameter of the calculation The amount of , Indicates the first party The secret sharing of the calculated first signature private key; , Indicates the second party The secret sharing of the calculated first signature private key; , Indicates the third party The secret sharing of the calculated first signature private key; , Indicates the first party The second random number Secret sharing; , Indicates the second party The second random number Secret sharing; , Indicates the third party The second random number Secret sharing; Indicates the first signature parameter.
7. The three-party collaborative SM2 signature generation method according to claim 4 is characterized in that: The first complete signature is ,in: ; ; ; ; ; in, Represents the first signature parameter; Represents the sum of the components of the first signature parameter The horizontal axis of represents a cryptographic function derived from a cryptographic hash function; Represents the message to be signed; Indicates the participants Calculate the components of the first signature parameter; Represents the second signature parameter; Indicates the participants the components of the calculated second signature parameters; Indicates the participants The first intermediate parameter of the calculation The amount of Indicates the participants The second intermediate parameter of the calculation The amount.
8. The three-party collaborative SM2 signature generation method according to claim 1 is characterized in that: If one participant is offline or corrupted by a malicious adversary, the two-party additive secret sharing is used to replace the duplicate secret sharing. The other two participants generate the secret sharing of the second signature private key respectively, and generate the second signature verification public key based on the secret sharing of the second signature private key, including: The other two participants each randomly select an integer as the secret share of their own second signature private key, calculate the components of the second signature verification public key and its corresponding zero-knowledge proof based on the secret share of their own second signature private key, and send the components of the second signature verification public key and its corresponding zero-knowledge proof to the other party; The other two participants verify in turn whether the received zero-knowledge proof is legal; if it is legal, the second signature verification public key is calculated based on the components of the second signature verification public key; otherwise, the protocol terminates.
9. The three-party collaborative SM2 signature generation method according to claim 1 is characterized in that: The other two participants calculate the intermediate parameters of the second complete signature, and obtain the second complete signature according to the message to be signed, the second signature verification public key and the intermediate parameters of the second complete signature, including: The other two participants each randomly select two integers, calculate the components of the third signature parameter and their corresponding zero-knowledge proof, and send the components of the third signature parameter and their corresponding zero-knowledge proof to the other party; The other two participants verify in turn whether the received zero-knowledge proof is legal; if it is legal, the third signature parameter is calculated based on the components of the third signature parameter; otherwise, the protocol terminates; Using the ideal function, the other two participants obtain the first calculation result based on the two randomly selected integers and the third signature parameter, and calculate the third intermediate parameter based on the first calculation result. The third intermediate parameter The weight is sent to the other party; Using the ideal function, the other two participants obtain the second calculation result based on the two randomly selected integers and the secret sharing of the second signature private key, and calculate the fourth intermediate parameter based on the second calculation result. The fourth intermediate parameter The weight is sent to the other party; According to the third intermediate parameter The components and the fourth intermediate parameter The fourth signature parameter is calculated, and the second complete signature is obtained according to the third signature parameter and the fourth signature parameter.
10. The three-party collaborative SM2 signature generation method according to claim 9 is characterized in that: The second complete signature is ,in: ; ; ; ; ; ; ; in, Indicates the third signature parameter; The sum of the components representing the third signature parameter The horizontal axis of represents a cryptographic function derived from a cryptographic hash function; Represents the message to be signed; Indicates the first party the components of the calculated third signature parameter; Indicates the second party the components of the calculated third signature parameter; Indicates the fourth signature parameter; , Indicates the first party The third intermediate parameter of the calculation The fourth intermediate parameter The amount of , Indicates the second party The third intermediate parameter of the calculation The fourth intermediate parameter The amount of Represents large prime numbers; Indicates the first party Two integers chosen randomly; , Indicates the second party Two integers chosen randomly; , represents the first calculation result; , Respectively represent the first party and the second party The secret sharing of the calculated second signature private key; , Indicates the second calculation result.