A post-quantum secure small-size linear homomorphism signature method and system

CN119966624BActive Publication Date: 2026-08-18WUHAN VOCATIONAL COLLEGE OF SOFTWARE & ENG (WUHAN OPEN UNIV)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510136270.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2026-08-18
Estimated Expiration
2045-02-07

AI Technical Summary

Technical Problem

这些算法在解决了随机模型的安全性限制的同时,也面临着量子计算机的威胁

Benefits of technology

[0112] Based on the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solution to be protected by this invention are as follows:

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966624B_ABST
    Figure CN119966624B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of quantum security, and discloses a post-quantum secure small-size linear homomorphism signature method and system. The application prevents loss of integrity / realness of original basic data without verifying the integrity of each data item one by one, prevents cheating of a remote untrusted computing party without repeating the computing work of the computing party for verification, prevents transmission error of a computing result, and resists quantum computer attacks. The application designs a linear homomorphism signature algorithm based on a lattice under a standard model, and has the advantage of a small-size public key compared with related work.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of quantum security technology, and in particular relates to a post-quantum secure small-size linear homomorphic signature method and system. Background Technology

[0002] Against the backdrop of the gradual development of quantum computing technology, the core problem of existing linear homomorphic signature technologies lies in their security, which relies on traditional mathematical problems such as the discrete logarithm problem or RSA. These problems will fail in a quantum computing environment. Lattice cryptography, as an emerging cryptographic method, is resistant to quantum computing because the mathematical problems it relies on (such as the shortest vector problem and the nearest vector problem) remain difficult under quantum computing. However, although some linear homomorphic signature algorithms based on lattice problems have been proposed, such as Boneh and Freeman's lattice algorithm, these algorithms still need further optimization and improvement in terms of efficiency, practicality, and public key size.

[0003] Meanwhile, to address the threat of quantum computing, researchers are actively exploring new quantum-resistant cryptographic algorithms and attempting to apply them to linear homomorphic signature schemes. These efforts aim to design a linear homomorphic signature scheme that is provably secure under the Standard Model and resistant to quantum computing, thus solving the problem that existing technologies may become completely ineffective due to their reliance on traditional mathematical problems.

[0004] In the random oracle model, the hash function is treated as a completely random function, and its output cannot be predicted by an adversary. This model greatly facilitates the design of cryptographic algorithms because it simplifies the proof of security. Several linear homomorphic signature algorithms have been designed under the random oracle model, including both single-source and multi-source scenarios. However, the security of this model relies on certain probabilistic guarantees, and adversary attacks in real-world environments may deviate from the assumptions in the model, leading to security vulnerabilities.

[0005] To better reflect real-world applications, researchers have designed various linear homomorphic signature schemes within the Standard Model (without relying on random oracles). The security of these schemes is based on specific mathematical problems, such as the discrete logarithm problem or the RSA problem. Representative works include algorithms by Catalano, Fiore, and Warinschi based on bilinear groups and RSA, Freeman's algorithm, and Attrapadung and Libert's algorithm. While these algorithms address the security limitations of the stochastic model, they also face the threat of quantum computers.

[0006] In summary, while the random oracle model simplifies the security proof process, its security may not be guaranteed in real-world environments. Although algorithms under the Standard Model solve the security problem of random models, they still need to address the challenges of quantum computing. Therefore, designing a linear homomorphic signature scheme that maintains security under the Standard Model while resisting the threats of quantum computing is an important direction in current cryptographic research. Summary of the Invention

[0007] To address the problems existing in the prior art, this invention provides a post-quantum secure small-size linear homomorphic signature method and system.

[0008] This invention is implemented as follows: a post-quantum-secure small-size linear homomorphic signature method includes:

[0009] Step 1, parameter generation;

[0010] Step 2, signature generation;

[0011] Step 3, Signature verification;

[0012] Step 4, linear homomorphic computation.

[0013] Furthermore, the parameters are generated as follows:

[0014] enter

[0015] System safety parameters;

[0016] : Labels describing the data,

[0017] Output

[0018] Public Key

[0019] private key

[0020] 1) Generating device A detailed description;

[0021] Explanation 1: The upper limit on the number of plaintext and signatures included in a single data packet, where plaintext and signatures are in one-to-one correspondence;

[0022] 2) Matrix Generating device A detailed description;

[0023] enter

[0024] : For matrix The number field ; For matrix number of rows; For matrix The number of columns;

[0025] Output

[0026] matrix , ,satisfy ,and , .

[0027] 3) A detailed description of the generating apparatus;

[0028] Note: This is the first generation method: integer. Discrete Gaussian sampling generation method

[0029] enter

[0030] : For matrix The number field ; For matrix number of rows; For matrix The number of columns;

[0031] Output

[0032] , ;

[0033] ,satisfy ;

[0034] Where the matrix and Random uniform matrices on the same surface are indistinguishable;

[0035] 4) A detailed description of the generating apparatus;

[0036] Note: This is the second generation method: binary. Bernoulli generation method

[0037] enter

[0038] : For matrix The number field ; For matrix number of rows; For matrix The number of columns;

[0039] Output

[0040] , ;

[0041] ,satisfy ;

[0042] Where the matrix and The random uniform matrix on is indistinguishable.

[0043] Furthermore, the signature generation:

[0044] enter

[0045] Public Key ;

[0046] private key ;

[0047] Plain text message awaiting signature ;

[0048] :Describe the labels for the data (e.g., "municipal employee wages"),

[0049] Plain text message Serial number in the dataset

[0050] Output

[0051] Successful execution, output signature.

[0052] Execution failed, output " "

[0053] 1) Signature generation device Detailed description; such as Figure 8 As shown;

[0054] 2) Trapdoor expansion device A detailed description;

[0055] enter

[0056] matrix ;

[0057] ;

[0058] Output

[0059] ,satisfy ;

[0060] 3) From the trapdoor Generate orthogonal lattice A detailed description of the lattice's device:

[0061] enter

[0062] matrix It is a matrix The lattice base;

[0063] It is a matrix of Trapping door;

[0064] Output

[0065] ,satisfy ;

[0066] Detailed description;

[0067] Similarly, .

[0068] Furthermore, the signature verification:

[0069] enter

[0070] Public Key ;

[0071] : Labels describing the data,

[0072] Plain text message and the corresponding signature ;

[0073] linear functions Description: .

[0074] Output

[0075] Verification successful, output "1"

[0076] Verification failed, output " ".

[0077] Furthermore, the linear homomorphic computation:

[0078] Linear homomorphic computing devices:

[0079] enter

[0080] Public Key ;

[0081] :Describe the labels for the data (e.g., "municipal employee wages"),

[0082] linear functions Description:

[0083] Data Tags The set of labeled data and a corresponding set of signatures linear combination

[0084] Plain text message In the dataset The serial number in

[0085] Output

[0086] Successful execution, output data labels The set of labeled data A corresponding set of signatures linear combination

[0087] Execution failed, output " ".

[0088] Furthermore, the linear homomorphic computing device .

[0089] Another object of the present invention is to provide a post-quantum-secure small-size linear homomorphic signature system comprising:

[0090] The parameter generation module is used for parameter generation.

[0091] The signature generation module is used for signature generation.

[0092] The signature verification module is used for signature verification.

[0093] The computation module is used for linear homomorphic computation.

[0094] Another object of the present invention is to provide a computer device including a memory and a processor, the memory storing a computer program that, when executed by the processor, causes the processor to perform the steps of the post-quantum-secure small-size linear homomorphic signature method.

[0095] Another object of the present invention is to provide a computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to perform the steps of the post-quantum-secure small-size linear homomorphic signature method.

[0096] Another object of the present invention is to provide an information data processing terminal for implementing the post-quantum secure small-size linear homomorphic signature system.

[0097] This invention also provides, for recording data tags as The dataset size is Within the framework of the Standard Model and post-quantum security, the publicly available work related to this patent includes the following two items:

[0098] [CLQ16]

[0099] (1) Its public key is matrices and A vector; it needs to be for each and Two random matrices are chosen as the public key, so it is A matrix.

[0100] (2) The signature is times the size A dimensional vector. This is for two reasons:

[0101] First, regarding the public key... random matrices The signature was not aggregated; it was used independently and pieced together as a whole. of; here The dimension is dimension;

[0102] Secondly, precisely because The dimension is The signature obtained during the signing process Its dimensions are of Double the size.

[0103] [LXYHL20]

[0104] Its public key is matrices and A vector; under the same security parameters Below, the signature is times the size 1-dimensional vector, this patent only requires 1 3D vector. The left side of the diagram below shows the parameter generation process, and the right side shows the signature process. Detailed analysis, cost, and comparison are provided below:

[0105] (1) Public key generation is based on two random matrices And the so-called "full-rank difference hash function"

[0106] This hash function requires that for two different data tags , Poor requirements It is still at full rank, that is, its rank is .

[0107] (2) In Construct the full-rank case / assumption. This allows it to incorporate security proofs during the process. ,thereby ,here yes A random square matrix of dimension, thus obtaining They are uniform and indistinguishable.

[0108] (3) The cost of introducing a difference full-rank hash function is that [LXYHL20] has to introduce another traditional signature algorithm in homomorphic signatures. The signature (therefore [LXYHL20] requires two different private keys) In order to achieve The signatures are authenticated separately; this results in two signature components, which are... :here It is a plain text message The true homomorphic signature, and It uses traditional signature algorithms to... The signature.

[0109] In summary,

[0110] First, although the public key matrix of [LXYHL20] becomes a constant of 2, it still requires the construction of two public key systems to achieve [the desired level of control]. Separate signature authentication;

[0111] Secondly, parameter generation only needs to be done once, while the signature is done multiple times after the system is established, resulting in a greater overhead due to the computation, generation, storage, transmission, and verification of twice the signature size each time.

[0112] Based on the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solution to be protected by this invention are as follows:

[0113] First, existing linear homomorphic signature methods are mostly based on traditional mathematical problems such as the discrete logarithm problem or RSA, which will fail in a quantum computing environment. This invention, by introducing a design framework based on lattice theory, provides a small-sized linear homomorphic signature scheme under the Standard Model that is quantum-safe, significantly enhancing its resistance to quantum computing attacks and solving the problem that existing technologies cannot meet quantum security requirements.

[0114] Existing quantum-resistant signature schemes often suffer from excessively large public key sizes, limiting their application in environments with limited storage and communication resources. This invention optimizes the signature scheme design, significantly reducing the public key size, making it more suitable for practical industrial scenarios and distributed systems, thus solving the bottleneck problem of excessively large public key sizes in existing technologies.

[0115] Linear homomorphic signature schemes under the standard model typically suffer from low efficiency, making it difficult to simultaneously meet the performance requirements of security and practical industrial applications. This invention optimizes the design process of signature generation, verification, and homomorphic computation, improving computational efficiency while ensuring strict security, thus resolving the contradiction between performance and security in existing technologies.

[0116] Existing linear homomorphic signature schemes lack flexibility in handling large-scale data and complex linear calculations, limiting their application in multi-data source and multi-computation scenarios. This invention designs a more efficient linear combinatorial signature calculation mechanism, enabling greater flexibility and adaptability in data manipulation and signature computation, significantly improving the practicality and scalability of the scheme in real-world industrial applications.

[0117] Secondly, based on the concept that "data is the fifth major factor of production," this invention proposes a technical solution for measuring abstract computation in a low-cost, publicly verifiable manner. In traditional factors of production, the value of land and capital can be directly reflected through market pricing. However, for abstract computation, its results must first be "measured" before a transaction can take place. Just as a supermarket uses a scale to weigh apples, data and computation also require a reliable "measurement" mechanism to commodify computation within a collaborative and market-driven environment. With the accelerated development of the digital society, the separation between data owners, computation providers, and users of computation results is becoming increasingly apparent. The ability to measure computation results in a "correct, verifiable, and low-cost" manner will directly determine whether computation can become a tradable commodity.

[0118] To meet the two key requirements of "correctness" and "verifiability," this invention starts with the simplest yet most universal linear computation, cleverly combining "computation" and "signature" by introducing linear homomorphic signature technology. Specifically, without needing the private key for signing the original data, the computation provider can perform arbitrary linear function calculations on the original data, simultaneously producing a signed result. The user only needs to use the public key to quickly verify the result returned by the computation provider. If the verification passes, it indicates that the result mathematically matches the linear relationship of the original data and has not been tampered with; the correctness of the calculation can be confirmed without comparing each piece of original data individually. This low-cost and publicly verifiable feature streamlines the entire process from "computation → measurement → transaction," providing solid technical support for the commercialization of computation.

[0119] This invention not only pioneers a new path for the commercialization of computing in terms of concept, but also achieves comprehensive advantages over similar technologies in terms of specific implementation details. The system of this invention no longer requires the use of "two coupled signature systems nested together," achieving linear homomorphic signature functionality with a single solution. These technical characteristics not only fill the gap in the field of "computational verifiability and commercialization" both domestically and internationally, but also provide a more efficient and low-cost solution for future large-scale computing applications in government, scientific research, and commerce.

[0120] Previously, it was widely believed that to obtain reliable computational results, one must first possess all the data and perform the computation independently. This has become a significant obstacle in today's world of increasing demands for cloud computing, big data, and privacy protection. This invention breaks the technological bias of "data possession is required for computation" by optimizing key parameters such as public keys, signature size, and system settings. It allows the computing party to perform correct and verifiable linear computations without needing the private key to sign the original data, and the user can quickly verify its correctness using only the public key. This enables abstract computation to truly enter the market in a "verifiable and low-cost" manner, achieving a leap from zero to one in the commercialization of computing. This not only achieves comprehensive technological optimization but also opens up new development space for data applications, cloud collaboration, and privacy-preserving computation in the digital economy era. Attached Figure Description

[0121] Figure 1 This is a flowchart of a small-size linear homomorphic signature method with post-quantum security provided in an embodiment of the present invention.

[0122] Figure 2 This is a block diagram of a small-size linear homomorphic signature system with post-quantum security provided in an embodiment of the present invention.

[0123] Figure 3 This is the generation device provided in the embodiments of the present invention. A detailed description diagram.

[0124] Figure 4 This is the matrix provided in the embodiments of the present invention. Generating device A detailed description diagram.

[0125] Figure 5 This is provided by the embodiments of the present invention. A detailed diagram of the generating apparatus.

[0126] Figure 6 This is provided by the embodiments of the present invention. A detailed diagram of the generating apparatus.

[0127] Figure 7 This is a detailed description diagram of the signature generation device provided in an embodiment of the present invention.

[0128] Figure 8 This is a signature generation device provided in the embodiments of the present invention. A detailed description diagram.

[0129] Figure 9 This is the trapdoor expansion device provided in the embodiments of the present invention. A detailed description diagram.

[0130] Figure 10 This is a trapdoor provided in an embodiment of the present invention. Generate orthogonal lattice A detailed diagram illustrating the lattice's apparatus.

[0131] Figure 11 This is the signature verification device provided in the embodiments of the present invention. A detailed description diagram.

[0132] Figure 12 This is a linear homomorphic computing device provided in the embodiments of the present invention. A detailed description diagram.

[0133] Figure 13 This is a statistical chart of the distribution of private keys provided in an embodiment of the present invention.

[0134] Figure 14 This is a verification diagram of linear homomorphic computation signature provided in an embodiment of the present invention.

[0135] Figure 15 This is a graph showing the average running time of each stage of the algorithm under different security levels, as provided in the embodiments of the present invention.

[0136] Figure 16 These are schematic diagrams illustrating the general effects of the present invention as provided in the embodiments of the present invention.

[0137] Figure 17 This is a comparison diagram of the four stages of operation provided in the embodiments of the present invention. Detailed Implementation

[0138] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0139] In distributed payroll systems, companies need to sign employee payroll details and submit them to the blockchain network while ensuring data integrity. However, traditional signature schemes lack sufficient security against quantum computing attacks and are ill-suited for future needs. This invention provides a secure and reliable solution for distributed payroll through a post-quantum-secure linear homomorphic signature method based on lattice theory. The system administrator first generates public and private keys. The public key is distributed to the payroll management and accounting modules, while the private key is used to sign each employee's payroll details to ensure data immutability.

[0140] The payroll management module generates a corresponding signature based on each employee's payroll details. Specifically, payroll details include data such as base salary, bonuses, and tax rates. After signing the details using a private key, the system ensures that the generated signature is both small in size and meets post-quantum security requirements. Signed payroll data can be securely stored and transmitted, preventing tampering or forgery in distributed networks. Simultaneously, the efficiency of the signing method reduces system resource consumption, making it suitable for widespread application in enterprise distributed environments.

[0141] In the payroll calculation process, the linear homomorphic property of this invention enables the system to directly perform linear calculations on signed payroll data, such as calculating total payroll, tax deductions, or calculating average wages. Without accessing the original data, the system can quickly output calculation results and generate new signatures through linear combination of signatures. This feature not only improves calculation efficiency but also avoids the risk of exposing the original data in traditional methods.

[0142] Finally, before submitting payroll details and calculation results to the blockchain, the system uses a public key to verify all signatures, ensuring data integrity and authenticity. After successful verification, the data is written to the blockchain for employees and the company to access. This invention's post-quantum-secure linear homomorphic signature scheme improves the security, efficiency, and flexibility of the payroll payment system while providing strong support for distributed payment scenarios.

[0143] I. Linear Homomorphic Signatures:

[0144] 1. Functional description of linear homomorphic signature schemes

[0145] A linear homomorphic signature scheme:

[0146] For a Plaintext vector A linear homomorphic signature yields a signature. ;here It is a finite field;

[0147] Remember a group indivual Plaintext vector Its corresponding The signature is The linear homomorphic property states that: given... Signature Anyone (without a private key) All of these can produce A linear space generated by plaintext vectors any vector in The signature; and cannot generate a linear space. any vector other than The signature.

[0148] A real-world application scenario is as follows:

[0149] The Municipal Finance Bureau maintains salary records for all current employees in the city. ,here This refers to the total number of "all employees".

[0150] The finance bureau signs off on each person's salary to verify the accuracy and completeness of the salary data, forming the following triplets:

[0151]

[0152] The table is then stored on a remote cloud server for relevant departments to use for in-depth macroeconomic data calculation and mining. The plaintext signature here... This ensured the authenticity and completeness of the original data on the monthly income of employed persons in the city.

[0153] Average monthly income of all employed persons in the city:

[0154] To prevent remote cloud servers from deceiving consumers without proper calculations, such as arbitrarily returning figures like "the city's average wage is 7835" without calculations, thus distorting macroeconomic data and affecting decision-making;

[0155] The linear homomorphic signature technique solves this problem as follows:

[0156] The remote cloud server returned a signature. ;

[0157] receive Then, based on the verification algorithm of linear homomorphic signatures, if the verification passes, it can be confirmed that the remote cloud server has truly and correctly calculated the average monthly income of employed persons in the city. It is not necessary to verify the authenticity of the salaries of all employees one by one, i.e., to verify them individually. The authenticity and integrity of.

[0158] II. Terminology Explanation: Basic Concepts and Conclusions Related to Cases

[0159] 1, one The grid of wei is A subgroup of additive elements of medium full rank; a Integer lattice of dimension that is An additive subgroup of full rank in ;

[0160] Equivalent land, grid is Linearly independent vectors Generated, among which ; Called grid The generating basis. There are infinitely many sets of generating basis that generate the same lattice. . Representing vectors The second-order paradigm.

[0161] 2. For integers , OK Column matrix Definition Orthogonal grid One of its cosets is defined as: ,in satisfy , .

[0162] 3. Let the set of vectors be denoted as . ,So The normal form representing its longest vector is, i.e. . express The set of vectors formed by orthogonalizing vectors in the middle using GramSchmidt.

[0163] 4. [BF11 Theorem 3.2] Probabilistic Polynomial-Time Algorithm The input consists of three positive integers greater than 1. satisfy Output a matrix Passive A short generating base And it has the following properties:

[0164] and A uniformly distributed matrix is ​​statistically indistinguishable.

[0165] ,

[0166] 5. Lattice Discrete Gaussian Distribution [MR04, GPV08]: ... Centered on, for any , Gaussian function Defined as ; accompany the collection Above, with A discrete Gaussian distribution with standard deviation is denoted as . ,in .

[0167] 6. For Vig Its dual lattice ;

[0168] 7, Vig smoothing parameters For real numbers , Defined as .here It is grid The dual case.

[0169] Theorem 1 [GPV08, Lemma 5.3] For a matrix , prime number And satisfy of There exists a negligible function. With a very high probability .

[0170] Theorem 2 [CHKP10 Lemma 2.4]. For a matrix ,make yes A generating base, let as well as Then we have:

[0171] (1). [GPV08, Lemma 2.11]: There is a probabilistic polynomial-time algorithm. It follows a discrete Gaussian distribution with a very high probability. To output a vector .

[0172] (2). [MR04, Lemma 4.4]: .

[0173] like Figure 1 As shown, the present invention provides a post-quantum-secure small-size linear homomorphic signature method and system, which includes the following steps:

[0174] S101, parameter generation;

[0175] S102, Signature generation;

[0176] S103, Signature Verification;

[0177] S104, linear homomorphic computation.

[0178] Parameter generation provided in this embodiment of the invention:

[0179] enter

[0180] System safety parameters;

[0181] : Labels describing the data,

[0182] Output

[0183] Public Key

[0184] private key

[0185] 1) Generating device A detailed description;

[0186] Explanation 1: The upper limit on the number of plaintext and signatures included in a single data packet, where plaintext and signatures are in one-to-one correspondence;

[0187] 2) Matrix Generating device A detailed description;

[0188] enter

[0189] : For matrix The number field ; For matrix number of rows; For matrix The number of columns;

[0190] Output

[0191] matrix , ,satisfy ,and , .

[0192] 3) A detailed description of the generating apparatus;

[0193] Note: This is the first generation method: using integers. Discrete Gaussian sampling generator matrix Method

[0194] enter

[0195] : For matrix The number field ; For matrix number of rows; For matrix The number of columns;

[0196] Output

[0197] , ;

[0198] ,satisfy ;

[0199] Where the matrix and Random uniform matrices on the same surface are indistinguishable;

[0200] 4) A detailed description of the generating apparatus;

[0201] Note: This is the second type of generated matrix. Method: Binary Bernoulli generation method

[0202] enter

[0203] : For matrix The number field ; For matrix number of rows; For matrix The number of columns;

[0204] Output

[0205] , ;

[0206] ,satisfy ;

[0207] Where the matrix and The random uniform matrix on is indistinguishable.

[0208] The signature generation provided in this embodiment of the invention:

[0209] enter

[0210] Public Key ;

[0211] private key ;

[0212] Plain text message awaiting signature ;

[0213] :Describe the labels for the data (e.g., "municipal employee wages"),

[0214] Plain text message Serial number in the dataset

[0215] Output

[0216] Successful execution, output signature.

[0217] Execution failed, output " "

[0218] 1) Signature generation device Detailed description; such as Figure 8 As shown;

[0219] 2) Trapdoor expansion device A detailed description;

[0220] enter

[0221] matrix ;

[0222] ;

[0223] Output

[0224] ,satisfy ;

[0225] 3) From the trapdoor Generate orthogonal lattice A detailed description of the lattice's device:

[0226] enter

[0227] matrix It is a matrix The lattice base;

[0228] It is a matrix of Trapping door;

[0229] Output

[0230] ,satisfy ;

[0231] Detailed description;

[0232] Similarly, .

[0233] The signature verification provided in this embodiment of the invention:

[0234] enter

[0235] Public Key ;

[0236] : Labels describing the data,

[0237] Plain text message and the corresponding signature ;

[0238] linear functions Description: .

[0239] Output

[0240] Verification successful, output "1"

[0241] Verification failed, output " ".

[0242] The linear homomorphic computation provided in this embodiment of the invention:

[0243] Linear homomorphic computing devices:

[0244] enter

[0245] Public Key ;

[0246] :Describe the labels for the data (e.g., "municipal employee wages"),

[0247] linear functions Description:

[0248] Data Tags The set of labeled data and a corresponding set of signatures linear combination

[0249] Plain text message Serial number in the dataset

[0250] Output

[0251] Successful execution, output data labels The set of labeled data A corresponding set of signatures linear combination

[0252] Execution failed, output " ".

[0253] The linear homomorphic computing device provided in this embodiment of the invention .

[0254] like Figure 2 As shown, an embodiment of the present invention provides a small-size linear homomorphic signature system with post-quantum security, comprising:

[0255] The parameter generation module is used for parameter generation.

[0256] The signature generation module is used for signature generation.

[0257] The signature verification module is used for signature verification.

[0258] The computation module is used for linear homomorphic computation.

[0259] Another object of the present invention is to provide a computer device including a memory and a processor, the memory storing a computer program that, when executed by the processor, causes the processor to perform the steps of the post-quantum-secure small-size linear homomorphic signature method.

[0260] Another object of the present invention is to provide a computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to perform the steps of the post-quantum-secure small-size linear homomorphic signature method.

[0261] Another object of the present invention is to provide an information data processing terminal for implementing the post-quantum secure small-size linear homomorphic signature system.

[0262] Specific implementation of the present invention:

[0263]

[0264] I. (Primary Unit) Parameter Generation Device

[0265] enter

[0266] System safety parameters;

[0267] : Labels describing the data,

[0268] Output

[0269] Public Key

[0270] private key

[0271] 1. Generating device Detailed description; such as Figure 3 As shown;

[0272] Explanation 1: The upper limit on the number of plaintext and signatures included in a single data packet, where plaintext and signatures are in one-to-one correspondence;

[0273] 2. (Secondary device) matrix Generating device Detailed description; such as Figure 4 As shown;

[0274] enter

[0275] : For matrix The number field ; For matrix number of rows; For matrix The number of columns;

[0276] Output

[0277] matrix , ,satisfy ,and , .

[0278] 3. (Secondary device) A detailed description of the generating device; such as Figure 5 As shown;

[0279] Note: This is the first generation method: integer. Discrete Gaussian sampling generation method

[0280] enter

[0281] : For matrix The number field ; For matrix number of rows; For matrix The number of columns;

[0282] Output

[0283] , ;

[0284] ,satisfy .

[0285] Where the matrix and Random uniform matrices on the same surface are indistinguishable;

[0286] 4. (Secondary device) A detailed description of the generating device; such as Figure 6 As shown;

[0287] Note: This is the second generation method: binary. Bernoulli generation method

[0288] enter

[0289] : For matrix The number field ; For matrix number of rows; For matrix The number of columns;

[0290] Output

[0291] , ;

[0292] ,satisfy .

[0293] Where the matrix and Random uniform matrices on the same surface are indistinguishable;

[0294] II. (Level 1 Device) Detailed description of the signature generation device; such as Figure 7 As shown;

[0295] enter

[0296] Public Key ;

[0297] private key ;

[0298] Plain text message awaiting signature ;

[0299] :Describe the labels for the data (e.g., "municipal employee wages"),

[0300] Plain text message Serial number in the dataset

[0301] Output

[0302] Successful execution, output signature.

[0303] Execution failed, output " "

[0304] 1. Signature generation device Detailed description; such as Figure 8 As shown;

[0305] 2. (Secondary device) Trap door expansion device Detailed description; such as Figure 9 As shown;

[0306] enter

[0307] matrix ;

[0308] .

[0309] Output

[0310] ,satisfy .

[0311] 3. (Secondary device) From the trapdoor Generate orthogonal lattice A detailed description of the lattice's device:

[0312] enter

[0313] matrix It is a matrix The lattice base;

[0314] It is a matrix of A trapdoor.

[0315] Output

[0316] ,satisfy .

[0317] Detailed description

[0318] Similarly, ;like Figure 10 As shown;

[0319] III. (Level 1 Device) Signature Verification Device

[0320] enter

[0321] Public Key ;

[0322] :Describe the labels for the data (e.g., "municipal employee wages"),

[0323] Plain text message and the corresponding signature ;

[0324] linear functions Description: .

[0325] Output

[0326] Verification successful, output "1"

[0327] Verification failed, output " "

[0328] 1. Signature verification device Detailed description; such as Figure 11 As shown;

[0329] IV. (Level 1 Device) Linear Homomorphic Computing Device

[0330] enter

[0331] Public Key ;

[0332] :Describe the labels for the data (e.g., "municipal employee wages"),

[0333] linear functions Description:

[0334] Data Tags The set of labeled data and a corresponding set of signatures linear combination

[0335] Plain text message Serial number in the dataset

[0336] Output

[0337] Successful execution, output data labels The set of labeled data A corresponding set of signatures linear combination

[0338] Execution failed, output " "

[0339] 1. Linear homomorphic computing device Detailed description; such as Figure 12 As shown.

[0340] I. The authenticity of linear computation in a three-party ("data provider, computer, and data user") scenario is publicly verifiable.

[0341] my country has clearly stated that data is the fifth major factor of production, and data must circulate to generate value. Static, isolated data cannot realize its value. How to leverage data circulation and its role in allocating factors of production across society is the core issue of the digital economy. The integrity / authenticity of basic raw data and the verifiability of calculations based on data are key foundational technologies to ensure the correct implementation of the digital economy.

[0342] This patent is a foundational patent for commercializing computing from scratch, and it targets scenarios involving three parties, explained as follows:

[0343] The data provider provides the basic raw data and ensures the integrity of the raw data through cryptographic signing; it can be any department, enterprise, or institution in the national economy that possesses data, depending on the specific business scenario.

[0344] The data user needs the computer to calculate a specific linear function based on remote baseline data. It can be a department, enterprise, or institution, depending on the specific business scenario;

[0345] A computing provider is a commercial operator that stores massive amounts of basic raw data, possesses powerful computing devices and equipment, and legally provides computing results to the entire society. It can be a data center, a data exchange, a cloud computing provider, etc., depending on the specific business scenario.

[0346] A real-world application example is as follows:

[0347] The Municipal Finance Bureau maintains salary records for all current employees in the city. ,here This refers to the total number of "all employees".

[0348] The Municipal Finance Bureau signs off on each person's salary to verify the authenticity and completeness of the salary data, forming the following triplets:

[0349]

[0350] As required by regulations, the Municipal Finance Bureau uploaded this form to a remote cloud server for relevant departments to use for in-depth macroeconomic data calculation and analysis. The plaintext signature here... This ensured the authenticity and completeness of the original data on the monthly income of employed persons in the city.

[0351] One day, calculate the average monthly income of all employed persons in the city:

[0352] To prevent remote cloud servers from deceiving or transmitting errors without proper calculation, such as a remote cloud server arbitrarily returning "the city's average wage is 7835" without calculation, thus distorting macroeconomic data and affecting decision-making;

[0353] The linear homomorphic signature technique solves this problem as follows:

[0354] The remote cloud server returned a signature. ;

[0355] receive Then, based on the verification algorithm of linear homomorphic signatures, if the verification passes, it can be confirmed that the remote cloud server has truly and correctly calculated the average monthly income of employed persons in the city. It is not necessary to verify the authenticity of the salaries of all employees one by one, i.e., to verify them individually. The authenticity and integrity of.

[0356] Application effect: If the verification algorithm of linear homomorphic signature passes...

[0357] 1. It eliminates the loss of integrity / authenticity of the original basic data, without the need to verify the integrity of each data entry individually.

[0358] 2. It eliminates the possibility of deception by untrusted remote computing parties who have not performed the calculations, thus eliminating the need to repeat the computing party's calculations for verification.

[0359] 3. Eliminates errors in the transmission of calculation results

[0360] 4. Resistant to quantum computer attacks.

[0361] I. Specific application areas or related products of this invention.

[0362] This invention has specific applications in the digital economy, such as outsourced computing in the current cloud computing industry, and future data exchanges / centers in the "Eastern Data, Western Computing" industry. Additionally, this invention can be applied to network coding to prevent data corruption attacks in network communication and protect data security.

[0363] II. Evidence related to the technical effects obtained by the embodiments of the present invention.

[0364] The operating environment of this patent on a desktop PC is as follows:

[0365] (1) The model of the machine is ThinkCentre M910z, the processor model is Intel Core i5-7500(vPro) (CORE i5, 3.4GHz), the operating system is Windows 10 Professional Edition, and the memory is 16G;

[0366] (2) The development language is Python, and the development tools used are PyCharm + Anaconda3 (64-bit);

[0367] (3) In this experiment, the main safety parameters tested were 𝑛 = 128, 𝑛 = 256, and 𝑛 = 512. The experimental parameters when 𝑛 = 256 are shown in the table below:

[0368]

[0369] Under the above experimental conditions and parameters, the experimental results are as follows:

[0370] (1) Matrix: Each row is linearly independent

[0371]

[0372] (2) Private key SK: generated by discrete Gaussian sampling

[0373]

[0374] (3) Statistics on the distribution of private keys Figure 13The private key distribution follows a discrete Gaussian distribution, with values ​​oscillating around the expected value, which is in line with expectations.

[0375] (4) To signature

[0376]

[0377] (5) Verification of signatures for linear homomorphic computation (Figure 14);

[0378] (6) Average running time of each stage of the algorithm under different security levels (unit: seconds) Figure 15 ;

[0379] The data above shows that, in the various stages of the linear homomorphic signature in this paper, the linear computation of 𝐸𝑣𝑎l𝑢𝑎𝑡𝑒() does not increase significantly with the increase of dimension, while the running time of the other three stages increases significantly, with the 𝑆𝑖𝑔𝑛() stage showing the most significant increase, because a large amount of computation is required in this stage.

[0380] The general effects of this invention are as follows: Figure 16 Show.

[0381] The operation of the four stages is as follows: Figure 17 As shown.

[0382] It should be noted that embodiments of the present invention can be implemented using hardware, software, or a combination of both. The hardware portion can be implemented using dedicated logic; the software portion can be stored in memory and executed by a suitable instruction execution system, such as a microprocessor or dedicated-design hardware. Those skilled in the art will understand that the above-described devices and methods can be implemented using computer-executable instructions and / or included in processor control code, for example, such code provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The devices and modules of the present invention can be implemented using hardware circuitry such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, or programmable hardware devices such as field-programmable gate arrays, programmable logic devices, etc., or using software executed by various types of processors, or using a combination of the above-described hardware circuitry and software, such as firmware.

[0383] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications, equivalent substitutions, and improvements made by those skilled in the art within the scope of the technology disclosed in the present invention, and within the spirit and principles of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A post-quantum-secure small-size linear homomorphic signature method, characterized in that, The post-quantum-secure small-size linear homomorphic signature method includes the following steps: 1) Parameter generation: Generate the system's public and private keys; 2) Signature generation: Generate a signature based on the plaintext message to be signed, data tag, and sequence number; 3) Signature verification: Verify the input signature and plaintext message, and output the verification result; 4) Linear Homomorphic Computation: Calculates a linear combination of a set of signatures and plaintext messages, and outputs the signature result of the linear combination; The parameters are generated as follows: enter System safety parameters; : The upper limit parameter for the label length of the data. ; Output Public Key ; private key ; 1) Generating device A detailed description; Based on the input security parameters and the maximum tag length parameter First, determine the system input as Based on this, select a modulus that meets the preset conditions. and ,in And satisfy , And satisfy and determine the parameters ; Subsequently, the system parameters are calculated based on the stated parameters. and parameters ; Based on the parameters Generate matrix and its corresponding matrix ,satisfy ; At the same time, randomly generated vectors as well as matrix ; Furthermore, based on the parameters Generating matrix pairs , where the matrix ,matrix And satisfy the matrix relationship: ; in ; The final output includes the system's public and private keys, where the public key is: ; The private key is: ; The upper limit on the number of plaintext and signatures included in a single data packet, where plaintext and signatures are in one-to-one correspondence; 2) Matrix Generating device A detailed description; enter : For matrix The number field ; For matrix number of rows; For matrix The number of columns; Output matrix , ,satisfy ,and , ; 3) A detailed description of the generating apparatus; This is the first generation method: integers. Discrete Gaussian sampling generation method enter : For matrix The number field ; For matrix number of rows; For matrix The number of columns; First, perform step 2-1 to randomly generate a matrix. ,in Simultaneously execute step 2-2, in the integer field. Perform discrete Gaussian sampling on the matrix to generate the matrix. The sampling relation is written as ; Then proceed to step 3 to calculate. ; Output , ; ,satisfy ; Where the matrix and Random uniform matrices on the same surface are indistinguishable; 4) A detailed description of the generating apparatus; This is the second generation method: binary. Bernoulli generation method enter : For matrix The number field ; For matrix number of rows; For matrix The number of columns; First, perform step 2-1 to randomly generate a matrix. ,in ; Simultaneously execute step 2-2, in the set Bernoulli sampling is performed on the matrix to generate the matrix. Its form is: ; Then proceed to step 3 to calculate: ; Output , ; ,satisfy ; Where the matrix and Random uniform matrices on the same surface are indistinguishable; Linear homomorphic computing device enter Public Key ; : Labels describing the data, ; linear functions Description: ; Data Tags The set of labeled data and a corresponding set of signatures linear combination ; Plain text message Serial number in the dataset Output Successful execution, output the signature. ; Execution failed, output " ".

2. The linear homomorphic signature method according to claim 1, wherein, Parameter generation includes the following steps: Input system security parameters that describe the maximum length of the data tag; Generate a public key and a private key, where the public key includes system parameters. A set of vectors describing messages and signatures. and matrix sets 1. The private key is a secret matrix generated by the system.

3. The linear homomorphic signature method according to claim 2, wherein, Public key generation includes the following steps: Use a matrix generator to generate a matrix. And there exists a corresponding lattice basis; Generate another matrix using discrete Gaussian sampling. This matrix is ​​connected to the first matrix through a mathematical relationship. ,satisfy .

4. The linear homomorphic signature method according to claim 3, wherein, Signature generation includes the following steps: Enter the public key, private key, plaintext message to be signed, data tag, and sequence number; Expand using the private key to generate a new matrix. The matrix satisfies ; Based on the expanded private key, a corresponding signature is generated in conjunction with the message to be signed.

5. The linear homomorphic signature method according to claim 4, wherein, Signature verification includes the following steps: enter: Public Key ; : Labels describing the data, Plain text message and the corresponding signature ; linear functions Description: ; Output Verification successful, output "1"; Validation failed, output " ".

6. The linear homomorphic signature method according to claim 5, wherein, Linear homomorphic computation includes the following steps: Input the public key, data tag, description of the linear function, a set of plaintext messages and their corresponding signatures; The plaintext message and its corresponding signature are weighted and linearly combined according to the description of a linear function to generate the combined signature result.

7. The linear homomorphic signature method according to claim 6, wherein, The linear homomorphic computing device is implemented through a computing module. The inputs include a public key, a private key, a plaintext message, a data tag, and a sequence number. The output is a combined signature or a failure indication.

8. A post-quantum-secure small-size linear homomorphic signature system implementing the post-quantum-secure small-size linear homomorphic signature method as described in any one of claims 1 to 6, characterized in that, The post-quantum-secure small-size linear homomorphic signature system includes: The parameter generation module is used for parameter generation. The signature generation module is used for signature generation. The signature verification module is used for signature verification. The computation module is used for linear homomorphic computation.

9. A computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to perform the steps of the post-quantum-secure small-size linear homomorphic signature method as described in any one of claims 1 to 6.

10. An information data processing terminal, characterized in that, The information data processing terminal is used to implement the small-size linear homomorphic signature system with post-quantum security as described in claim 8.