Signature-based SM9 evidence encryption and decryption method, device and system

By combining the SM9 public-key encryption algorithm with threshold signature and evidence encryption mechanisms, the problem of signature evidence encryption, which lacks domestic cryptographic design in existing technologies, is solved. This results in a highly secure and independently controllable encryption and decryption scheme, suitable for scenarios such as time-release encryption and transaction memory pool privacy protection.

CN119966635BActive Publication Date: 2025-11-04WUHAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510126754.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-27
Publication Date
2025-11-04
Estimated Expiration
2045-01-27

AI Technical Summary

Technical Problem

Existing technologies lack signature evidence encryption methods based on domestically developed cryptographic designs, which fails to meet the security requirements of independent control.

Method used

The SM9 public-key encryption algorithm is combined with threshold signature and evidence encryption mechanism. The random number r0 is divided by t-out-of-n threshold secret sharing technology, the intermediate variable Ti is calculated, and the plaintext message is encrypted and decrypted by bilinear mapping and signature-based evidence encryption method.

Benefits of technology

It achieves high-security evidence encryption based on domestically developed cryptographic design, meets the security requirements of independent control, and ensures the confidentiality and integrity of ciphertext.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966635B_ABST
    Figure CN119966635B_ABST
Patent Text Reader

Abstract

The application discloses a signature-based SM9 evidence encryption and decryption method, device and system. i Then, the share of the intermediate variable R corresponding to s i is encrypted by using the signature-based evidence encryption idea, and the plaintext is encrypted by using R. The signature-based SM9 evidence decryption method comprises the following steps that when the decrypter obtains the signatures corresponding to a predetermined number of labels, the share of the intermediate variable R can be obtained from the ciphertext, so that the complete R is reconstructed, and the ciphertext is further decrypted to obtain the corresponding plaintext. The application has the advantages of high security, perfect function and the like, can be applied to multiple scenes such as time release encryption, threshold encryption and protection of transaction memory pool privacy, and further perfects the domestic functional type cryptographic algorithm system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security technology, in particular to a signature-based SM9 witness encryption and decryption method, device and system. BACKGROUND

[0002] Witness encryption was first proposed by Gentry et al., which is a generalization of public key encryption, where the public key can be any NP statement x, and the decryption key associated with it is the witness w corresponding to x. Users can encrypt the message m using the statement x to generate the corresponding ciphertext, and anyone who knows the witness w can decrypt the ciphertext. And when the statement x is false, no information about the plaintext can be obtained from the ciphertext. Witness encryption is a very useful tool for building encryption schemes, and the work of Gentry et al. shows that witness encryption can provide new solutions for identity-based encryption, attribute-based encryption and other cryptographic primitives.

[0003] One of the more special branches is signature-based witness encryption, which was first proposed by Hanzlik et al. The threshold signature-based witness encryption (tSWE) scheme allows encryption of plaintexts according to a set of labels and a set of verification keys of a signature scheme. Once a sufficient number of signatures corresponding to the labels are provided, anyone can effectively decrypt the SWE ciphertext using these signatures. The threshold attribute ensures that without obtaining a sufficient number of signatures corresponding to the labels, the decrypter cannot obtain any information about the plaintext from the SWE ciphertext.

[0004] There is no signature-based witness encryption method combining domestic cryptographic design in the prior art. SUMMARY

[0005] The purpose of the present application is to design a signature-based witness encryption scheme based on domestic cryptography, which meets the development needs of domestic independence and safe controllability. In view of the defects in the prior art, a signature-based SM9 witness encryption and decryption method, device and system are proposed. The specific scheme is as follows:

[0006] The first aspect provides a signature-based SM9 witness encryption method, comprising:

[0007] The encrypter divides the random number r0 of the encryption process into multiple shares s using t-out-of-n threshold secret sharing technology i , calculates a first intermediate variable T according to the signature verification key i , and calculates the ciphertext of the first intermediate variable based on the shares of the secret sharing;

[0008] The second intermediate variable R is calculated using a bilinear mapping.

[0009] Use a signature-based evidence encryption method to s i The corresponding share of the second intermediate variable R is encrypted, and R is used to encrypt the plaintext message.

[0010] In one implementation, the encryptor divides the random number r0 generated during the encryption process into multiple shares s using a t-out-of-n threshold secret sharing technique. i ,include:

[0011] For i∈[t-1], select randomly Generate the corresponding t-1 order polynomial Where t is the threshold value;

[0012] For i∈[n]:

[0013] Calculate the secret sharing result s of r0 i =f(ξ i ), where ξ i =H2(vk i ), vk i Indicates the signature verification key, ξ i H2(·) represents the hash value calculated based on the signature verification key, H2(·) represents the cryptographic function derived from the cryptographic hash function, and n represents the number of signature verification public keys.

[0014] Calculate the first intermediate variable Among them, tag i The label is represented by H1(·), which represents the cryptographic function derived from the cryptographic hash function, and g0 represents the cyclic group. A generator;

[0015] The ciphertext for calculating the first intermediate variable based on the share of secret sharing.

[0016] In one implementation, a signature-based evidence encryption method is used to s i The corresponding second intermediate variable R is encrypted, and the plaintext message is encrypted using R, including:

[0017] Different algorithms based on key derivation functions are used to calculate the derived key;

[0018] The step of determining whether to return to the step of calculating the secret sharing result of r0 is based on the bits of the derived key. If the preset length of the derived key is a string of all zero bits, then the step of calculating the secret sharing result of r0 is returned.

[0019] Otherwise, the plaintext message is encrypted using the derived key to obtain the intermediate ciphertext;

[0020] According to the derived key and the intermediate ciphertext, the message authentication ciphertext of the encryption process is obtained;

[0021] According to the ciphertext of the first intermediate variable, the intermediate ciphertext and the message authentication ciphertext of the encryption process, the final ciphertext is obtained.

[0022] Based on the same inventive concept, the second aspect of the present application provides a signature-based SM9 evidence decryption method, which is realized based on the signature-based SM9 evidence encryption method of the first aspect. The decryption method comprises:

[0023] After the decrypter obtains the signatures corresponding to a predetermined number of tags, the decrypter obtains the share of the second intermediate variable R from the final ciphertext and reconstructs the complete R based on the share of the second intermediate variable R.

[0024] The final ciphertext is decrypted using the second intermediate variable to obtain the corresponding message plaintext.

[0025] In an embodiment, after the decrypter obtains the signatures corresponding to a predetermined number of tags, the decrypter obtains the share of the second intermediate variable R from the final ciphertext and reconstructs the complete R based on the share of the second intermediate variable R, comprising:

[0026] For i∈[n], calculate ξ i =H2(vk i ), vk i represents a signature verification key, H2(·) represents a cryptographic function derived from a cryptographic hash function, ξ i represents a hash value calculated based on the signature verification key

[0027] For i∈[n], calculate the Lagrange interpolation coefficient I represents a set of integers with a size of t, and j is an index different from i;

[0028] Calculate the aggregated ciphertext is a component of the final ciphertext;

[0029] Calculate the aggregated signature σ * =∏ i∈[n] σ i , σ i represents the signature corresponding to the tag tag i ;

[0030] Calculate the intermediate variable represents the share of the second intermediate variable R.

[0031] In an embodiment, the final ciphertext is decrypted using the second intermediate variable to obtain the corresponding message plaintext, comprising:

[0032] The derived key is calculated by using different key derivation function based algorithms;

[0033] The intermediate ciphertext is decrypted according to the derived key to obtain the message plaintext;

[0034] The message authentication ciphertext of the decryption process is obtained according to the derived key and the decrypted intermediate ciphertext;

[0035] The message authentication ciphertext of the decryption process is verified with the message authentication ciphertext of the encryption process, if they are equal, the message plaintext is output, otherwise, is output.

[0036] Based on the same inventive concept, the third aspect of the present application provides a signature-based SM9 evidence encryption device, comprising:

[0037] The secret sharing module is configured to divide the random number r0 of the encryption process into multiple shares s i , calculate a first intermediate variable T i based on the verification key, and calculate the ciphertext of the first intermediate variable based on the secret shared shares;

[0038] The intermediate variable calculation module is configured to calculate a second intermediate variable R by using a bilinear mapping;

[0039] The encryption module is configured to encrypt the shares of the second intermediate variable R corresponding to s i by using a signature-based evidence encryption method, and encrypt the plaintext message by using R.

[0040] Based on the same inventive concept, the fourth aspect of the present application provides a signature-based SM9 evidence decryption device, which is realized based on the encryption device of the third aspect, and the decryption device comprises:

[0041] The intermediate variable reconstruction module is configured to obtain the shares of the second intermediate variable R from the final ciphertext after the decrypter obtains a predetermined number of signatures corresponding to the labels, and reconstruct the complete R based on the shares of the second intermediate variable R;

[0042] The decryption module is configured to decrypt the final ciphertext by using the second intermediate variable to obtain the corresponding message plaintext.

[0043] Based on the same inventive concept, the fifth aspect of the present application provides a signature-based SM9 evidence encryption and decryption system, comprising the signature-based SM9 evidence encryption device of the third aspect and the signature-based SM9 evidence decryption device of the fourth aspect.

[0044] Based on the same inventive concept, the sixth aspect of the present application provides a computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor implements the signature-based SM9 evidence encryption method according to the first aspect and the signature-based SM9 evidence decryption method according to the second aspect when executing the program.

[0045] Compared with the prior art, the present application has the following advantages and beneficial technical effects: (1) direct design based on the national standard SM9 public key encryption algorithm; (2) security directly depends on the security of the national standard SM9 public key encryption algorithm; (3) the signature-based evidence encryption scheme meets the security requirements of independent controllability; (4) the confidentiality and integrity of the ciphertext are guaranteed. BRIEF DESCRIPTION OF DRAWINGS

[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.

[0047] Figure 1 The flowchart of the signature-based SM9 evidence encryption method provided by the embodiment of the present application is shown in

[0048] Figure 2 The flowchart of the signature-based SM9 evidence decryption method provided by the embodiment of the present application is shown in

[0049] Figure 3 The specific implementation flowchart of the signature-based SM9 evidence encryption and decryption system provided by the embodiment of the present application is shown in DETAILED DESCRIPTION

[0050] In order to make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0051] Embodiment one

[0052] The present application discloses a signature-based SM9 evidence encryption method, please see Figure 1 , comprising:

[0053] S101: The encrypter divides the random number r0 of the encryption process into multiple shares s using t-out-of-n threshold secret sharing technology i , calculates a first intermediate variable T according to the signature verification key i , and calculates the ciphertext of the first intermediate variable based on the shares of the secret sharing;

[0054] S102: Calculate the second intermediate variable R using the bilinear mapping;

[0055] S103: Encrypt the share of the second intermediate variable R corresponding to s i using the signature-based evidence encryption method, and encrypt the plaintext message using R.

[0056] SM9 cryptographic algorithm is the first identity-based cryptographic algorithm independently developed by China, which was released by the State Cryptography Administration on March 28, 2016. For details, please refer to “SM9 Identity-Based Cryptographic Algorithm”. The algorithm has been included in China's algorithm standard GB / T 38635-2020. This algorithm has extremely important significance for China's information security construction.

[0057] The present application designs a signature-based SM9 evidence encryption method and encryption system, which combines threshold signature and evidence encryption mechanism on the basis of SM9 public key encryption algorithm, and can decrypt the plaintext information from the ciphertext when a predetermined number of labels corresponding to the signature are obtained. This scheme further improves the domestic functional cryptographic algorithm system.

[0058] To ensure universality, the parameters of the present application are consistent with the standard parameters of the SM9 signature algorithm. The specific symbol description is as follows:

[0059] q: large prime number.

[0060] The integer set consisting of 0, 1, 2,..., q-1.

[0061] Cyclic group of order prime q.

[0062] Cyclic group of order prime q.

[0063] Cyclic group of order prime q.

[0064] e: bilinear mapping

[0065] g0: generator of cyclic group .

[0066] g1: generator of cyclic group .

[0067] g t : cyclic group one generator of the cyclic group.

[0068] h u : u times of the group element h.

[0069] n: number of verification public keys.

[0070] [n]: a set of integers consisting of 1, 2,..., n.

[0071] t: threshold value.

[0072] I: a set of integers with size t.

[0073] f(x): a t-1 order polynomial where r i is a polynomial coefficient.

[0074] H1(·): a cryptographic function derived from a cryptographic hash function, which is

[0075] H2(·): a cryptographic function derived from a cryptographic hash function, which is

[0076] KDF(·): a key derivation function.

[0077] K: a key derived by KDF(·), where K = K1 || K2, K1 is used for encryption of the message m, and K2 is used for the message authentication code function MAC(·).

[0078] MAC(·): a message authentication code function.

[0079] Enc(·), Dec(·): encryption algorithm and decryption algorithm of a block cipher algorithm.

[0080] pp: public system parameter.

[0081] sk: signature private key of the signer.

[0082] vk: verification public key of the signer, which is calculated as

[0083] m: message to be encrypted (plain text message).

[0084] c: ciphertext c = ((c 1,i ) i∈[n] , c2, c3) after encryption of the message m.

[0085] R, T i : intermediate variables in the encryption process.

[0086] tagi : the tag used by the encryption message m.

[0087] σ i : the tag tag i corresponding signature

[0088] l i (·): Lagrange interpolation basis function.

[0089] In an embodiment, the encrypter divides the random number r0 of the encryption process into multiple shares s i , including:

[0090] For i∈[t-1], randomly select Generate the corresponding t-1 order polynomial Where t is the threshold value;

[0091] For i∈[n]:

[0092] Calculate the secret sharing result s i of r0 i , where ξ i =H2(vk i ), vk i represents the signature verification key, ξ i represents the hash value calculated based on the signature verification key, and H2(·) represents a cryptographic function derived from a cryptographic hash function;

[0093] Calculate the first intermediate variable Where tag i represents the tag, H1(·) represents a cryptographic function derived from a cryptographic hash function, and g0 represents a generator of a cyclic group ;

[0094] Based on the shares of the secret sharing, calculate the ciphertext of the first intermediate variable

[0095] In an embodiment, the second intermediate variable R corresponding to s i is encrypted using a signature-based evidence encryption method, and the plaintext message is encrypted using R, including:

[0096] Different algorithms based on key derivation functions are used to calculate the derived key;

[0097] According to the bits of the derived key, it is determined whether to return to the step of calculating the secret sharing result of r0. If the preset length of the bits of the derived key is a full zero bit string, the step of calculating the secret sharing result of r0 is returned to;

[0098] Otherwise, the plaintext message is encrypted using the derived key to obtain an intermediate ciphertext;

[0099] According to the derived key and the intermediate ciphertext, message authentication ciphertext of the encryption process is obtained;

[0100] According to the ciphertext of the first intermediate variable, the intermediate ciphertext and the message authentication ciphertext of the encryption process, the final ciphertext is obtained.

[0101] In the implementation process, different algorithms based on key derivation function include sequence cipher algorithm based on key derivation function and block cipher algorithm combined with key derivation function

[0102] The evidence encryption can be specifically implemented through the following steps:

[0103] Step 1: For i∈[t-1], randomly select Generate the corresponding t-1 order polynomial

[0104] Step 2: For i∈[n]:

[0105] 1) Calculate the secret sharing result s of r0 i = f(ξ i ), wherein ξ i = H2(vk i ).

[0106] 2) Calculate the first intermediate variable

[0107] 3) Calculate the ciphertext of the first intermediate variable

[0108] Step 3: Calculate the second intermediate variable

[0109] Step 4: According to the encryption method, classification is carried out:

[0110] a) If the sequence cipher algorithm based on the key derivation function is used:

[0111] (i) Calculate the derived key K = KDF((c 1,i ) i∈[n] || R || tag, klen). Wherein || represents splicing, klen = m len + mac len , m len is the bit length of the message, mac len is the key length in the function MAC() function. Let K1 be the leftmost m len bit of K, and K2 be the remaining mac lenbits. If K1 is a string of all zero bits, return to Step 2.

[0112] (ii) Compute the intermediate ciphertext

[0113] b) If a block cipher algorithm using a key derivation function is used:

[0114] (i) Compute the derived key K = KDF((c 1,i ) i∈[n] || R || tag, klen). Where || denotes concatenation, klen = bc len + mac len , bc len is the bit length of the key in the block cipher algorithm, mac len is the key length in the function MAC(). Let K1 be the leftmost bc len bits of K, K2 be the remaining mac len bits. If K1 is a string of all zero bits, return to Step 2.

[0115] (ii) Compute the intermediate ciphertext c2 = Enc(K1, m).

[0116] Step 5: Compute the message authentication ciphertext c3 = MAC(K2, c2).

[0117] Step 6: Output the final ciphertext c = ((c 1,i ) i∈[n] , c2, c3).

[0118] Embodiment Two

[0119] Based on the same inventive concept, the embodiment discloses a signature-based SM9 evidence decryption method, which is based on the signature-based SM9 evidence encryption method of embodiment one. Please refer to Figure 2 , the decryption method comprises:

[0120] S201: After obtaining a predetermined number of signatures corresponding to labels, the decrypter obtains a share of the second intermediate variable R from the final ciphertext, and reconstructs the complete R based on the share of the second intermediate variable R;

[0121] S202: The final ciphertext is decrypted using the second intermediate variable to obtain the corresponding message plaintext.

[0122] In an embodiment, after obtaining a predetermined number of signatures corresponding to labels, the decrypter obtains a share of the second intermediate variable R from the final ciphertext, and reconstructs the complete R based on the share of the second intermediate variable R, comprising:

[0123] For i∈[n], compute ξ i = H2(vk i ), vk i denotes the verification key, H2(·) denotes a cryptographic function derived from a cryptographic hash function, ξ i denotes a hash value computed based on the verification key

[0124] For i∈[n], compute Lagrange interpolation coefficients I denotes a set of integers of size t, j is an index different from i;

[0125] Compute the aggregated ciphertext is a component of the final ciphertext;

[0126] Compute the aggregated signature σ * =∏ i∈[n] σ i , σ i denotes the signature corresponding to the label tag i ;

[0127] Compute the intermediate variable denotes a share of the second intermediate variable R.

[0128] In an embodiment, the final ciphertext is decrypted using the second intermediate variable to obtain the corresponding message plaintext, comprising:

[0129] A derived key is computed using a different algorithm based on a key derivation function;

[0130] The intermediate ciphertext is decrypted according to the derived key to obtain the message plaintext;

[0131] According to the derived key and the decrypted intermediate ciphertext, the message authentication ciphertext of the decryption process is obtained;

[0132] Verify whether the message authentication ciphertext of the decryption process is equal to the message authentication ciphertext of the encryption process, if equal, output the message plaintext, otherwise, output ⊥.

[0133] In the specific implementation process, the evidence decryption can be implemented through the following steps:

[0134] Input the ciphertext c = ((c 1,i ) i∈[n] , c2, c3), the signature (σ i ) i∈[I] wherein The decrypter performs the following steps:

[0135] Step 1: For i∈[n], compute ξ i = H2(vki ).

[0136] Step 2: For i ∈ [n], compute Lagrange interpolation coefficients

[0137] Step 3: Compute aggregated ciphertext

[0138] Step 4: Compute aggregated signature σ * = Πi∈ [n] σ i .

[0139] Step 5: Compute intermediate variables

[0140] Step 6: Classify according to encryption method:

[0141] a) If a sequential cipher algorithm based on a key derivation function is used

[0142] (i) Compute the derived key K = KDF((c 1,i ) i∈[n || R || tag, klen). Where || denotes concatenation, klen = m len + mac len , m len is the bit length of the message, mac len is the key length in the function MAC(). Let K1 be the leftmost m len bits of K, K2 be the remaining mac len bits.

[0143] (ii) Compute the plaintext after decryption of the ciphertext c2

[0144] b) If a block cipher algorithm combined with a key derivation function is used

[0145] (i) Compute the derived key K = KDF((c 1,i ) i∈[n] || R || tag, klen). Where || denotes concatenation, klen = bc len + mac len , bc len is the bit length of the key in the block cipher algorithm, mac len is the key length in the function MAC(). Let K1 be the leftmost bc len bits of K, K2 be the remaining mac len bits.

[0146] (ii) Compute the plaintext (message plaintext) m after decryption of the ciphertext c2, m = Dec(K1, c2).

[0147] Step 7: Recompute the message authentication ciphertext c'3 of the decryption process, c'3 = MAC(K2, c2).

[0148] Step 8: Verify c'3, if c'3 ≠ c3, output ⊥, otherwise output m.

[0149] The application discloses a signature-based SM9 evidence encryption method and an encryption system. i Then, the signature-based evidence encryption idea is used to encrypt the shares of the intermediate variable R corresponding to s i corresponding to s , and the plaintext is encrypted by using R. 2) When the decrypter obtains a predetermined number of labels corresponding to the signature, the decrypter can obtain the shares of the intermediate variable R from the ciphertext, thereby reconstructing the complete R, and further decrypting the ciphertext to obtain the corresponding plaintext. The application has the advantages of high security, perfect functions, and the like, can be applied to multiple scenes such as time release encryption, threshold encryption and protection of transaction memory pool privacy, and further perfects the domestic functional cryptographic algorithm system.

[0150] Embodiment three

[0151] Based on the same inventive concept, the embodiment discloses a signature-based SM9 evidence encryption device, which comprises:

[0152] A secret sharing module is configured to divide a random number r0 of an encryption process into multiple shares s i by using a t-out-of-n threshold secret sharing technology, calculate a first intermediate variable T i according to a signature verification key, and encrypt the ciphertext of the first intermediate variable based on the shares of the secret sharing.

[0153] An intermediate variable calculation module is configured to calculate a second intermediate variable R by using a bilinear mapping.

[0154] An encryption module is configured to encrypt the shares of the second intermediate variable R corresponding to s i by using a signature-based evidence encryption method, and encrypt a plaintext message by using R.

[0155] Since the device introduced in the embodiment three of the present application is the device used for implementing the signature-based SM9 evidence encryption method in the embodiment one of the present application, the specific structure and deformation of the device can be understood by those skilled in the art based on the method introduced in the embodiment one of the present application, and thus will not be described here again. Any device used in the method in the embodiment one of the present application belongs to the scope of the present application.

[0156] Embodiment four

[0157] Based on the same inventive concept, the embodiment discloses a signature-based SM9 evidence decryption device, which is realized based on the encryption device in the embodiment three. The decryption device comprises:

[0158] An intermediate variable reconstruction module is configured to obtain the share of the second intermediate variable R from the final ciphertext after the decrypter obtains the signatures corresponding to the predetermined number of labels, and reconstruct the complete R based on the share of the second intermediate variable R.

[0159] A decryption module is configured to decrypt the final ciphertext by using the second intermediate variable to obtain the corresponding message plaintext.

[0160] Since the device introduced in the embodiment four of the present application is the device used for implementing the signature-based SM9 evidence decryption method in the embodiment two of the present application, the specific structure and deformation of the device can be understood by those skilled in the art based on the method introduced in the embodiment two of the present application, and thus will not be described here again. Any device used in the method in the embodiment two of the present application belongs to the scope of the present application.

[0161] Embodiment five

[0162] Based on the same inventive concept, the embodiment discloses a signature-based SM9 evidence encryption and decryption system, which comprises the signature-based SM9 evidence encryption device in the embodiment three and the signature-based SM9 evidence decryption device in the embodiment four.

[0163] Please refer to Figure 3 The specific implementation flowchart of the signature-based SM9 evidence encryption and decryption system provided in the embodiment of the present application is shown in the figure. The encrypter is the signature-based SM9 evidence encryption device, and the decrypter is the signature-based SM9 evidence decryption device.

[0164] In general, the present application discloses a signature-based SM9 evidence encryption and decryption method and system. The system comprises the following steps: 1) the encrypter divides the random number r0 of the encryption process into multiple shares s i Then, the signature-based evidence encryption idea is used to encrypt s i The share of the intermediate variable R corresponding to s The plaintext is encrypted and encrypted by R. 2) When the decrypter obtains the signatures corresponding to a predetermined number of tags, the share of the intermediate variable R in the ciphertext can be obtained, so that the complete R is reconstructed, and the ciphertext is further decrypted to obtain the corresponding plaintext. The present application has the advantages of high security, perfect function, etc., and can be applied to time-release encryption, threshold encryption and protection of transaction memory pool privacy and other scenes, and the scheme further perfects the domestic functional cryptographic algorithm system.

[0165] Embodiment six

[0166] Based on the same inventive concept, the present application also provides a computer device comprising a memory, a processor and a computer program stored on the memory and executable on the processor, wherein the processor implements the signature-based SM9 evidence encryption method of embodiment one and the signature-based SM9 evidence decryption method of embodiment two when executing the program.

[0167] Since the computer device introduced in embodiment six of the present application is the computer device used to implement the signature-based SM9 evidence encryption method in embodiment one and the signature-based SM9 evidence decryption method in embodiment two of the present application, the specific structure and modifications of the computer device can be understood by those skilled in the art based on the methods introduced in embodiments one or two of the present application, and therefore will not be described here. Any computer device used by the methods of embodiments one or two of the present application belongs to the scope of the present application.

[0168] Those skilled in the art will appreciate that embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.

[0169] The present application is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The function specified in one flow or multiple flows and / or blocks Figure 1 The device that implements the function specified in one flow or multiple flows and / or blocks.

[0170] While the preferred embodiments of the application have been described, additional variations and modifications can be made to these embodiments by those skilled in the art once they have the benefit of the foregoing description without departing from the spirit and scope of the application. Accordingly, it is intended that the appended claims be interpreted as including all such variations and modifications as fall within the scope of the present application. It is apparent that those skilled in the art can modify and adapt the preferred embodiments of the application without departing from the spirit and scope of the application. It is therefore intended that the present application shall not be limited to the particular embodiments described but shall include all modifications and adaptations within the scope and spirit of the present application.

Claims

1. A signature-based SM9 evidence encryption method, characterized in that, The method comprises: Random number for encryption process by encrypter Splitting into multiple shares using t-out-of-n threshold secret sharing technique Computing a first intermediate variable from the verification key Computing a ciphertext of the first intermediate variable based on the shares of the secret share The second intermediate variable is calculated using bilinear mapping. , ,in, , , These are parameters in the SM9 signature algorithm. It is a bilinear mapping. Cyclic group generator, Cyclic group Generators; Using a signature-based evidence encryption method on The corresponding second intermediate variable Shares are encrypted, and the Plain text message is encrypted.

2. The signature-based SM9 witness encryption method according to claim 1, wherein, Random number for encryption process by encrypter Splitting into multiple shares using t-out-of-n threshold secret sharing technique , comprising: For , randomly select , generate the corresponding order polynomial , where is a threshold value; For : Computing a secret share result wherein , denotes a verification key, denotes a hash value computed based on the verification key, denotes a cryptographic function derived by a cryptographic hash function, denotes a number of verification public keys; computing a first intermediate variable wherein, denotes a label, denotes a cryptographic function derived from a cryptographic hash function, denotes a cyclic group of one generator; Ciphertext for computing a first intermediate variable based on shares of a secret .

3. The signature-based SM9 witness encryption method according to claim 2, wherein, Utilizing encrypting the plaintext message, comprising: Based on the second intermediate variable Different key derivation function based algorithms are employed to calculate the derived keys; According to the bits of the derived key, it is determined whether to return to the step of calculating the secret sharing result If the bits of the preset length of the derived key are all zero bit strings, it is returned to the step of calculating the secret sharing result ​ Otherwise, encrypt the plaintext message by using the derived key to obtain intermediate ciphertext; According to the derived key and the intermediate ciphertext, obtain the message authentication ciphertext of the encryption process; According to the ciphertext of the first intermediate variable, the intermediate ciphertext and the message authentication ciphertext of the encryption process, obtain the final ciphertext.

4. A signature-based SM9 evidence decryption method, characterized in that, The signature-based SM9 witness encryption method implementation according to any one of claims 1 to 3, the decryption method comprises: The decrypter obtains the second intermediate variable from the final ciphertext after obtaining the signatures corresponding to a predetermined number of tags , and reconstructs the complete based on the share of the second intermediate variable ​ Decrypt the final ciphertext by using the second intermediate variable to obtain the corresponding message plaintext.

5. The signature-based SM9 evidence decryption method according to claim 4, characterized in that, The decrypter obtains the second intermediate variable from the final ciphertext after obtaining the signatures corresponding to a predetermined number of tags , and reconstructs the complete based on the share of the second intermediate variable , comprising: For , a verification key is calculated , denotes a verification key, denotes a cryptographic function derived from a cryptographic hash function, denotes a hash value calculated based on the verification key For , the Lagrange interpolation coefficients , denote a set of integers of size , is an index different from . Computing aggregate ciphertext , is a component of the final ciphertext; Computing an aggregated signature , Indicative label corresponding signature; Computing an intermediate variable , denotes a share of a second intermediate variable .

6. The signature-based SM9 evidence decryption method according to claim 4, wherein, Decrypt the final ciphertext by using the second intermediate variable to obtain the corresponding message plaintext, comprising: Based on the second intermediate variable The derived key is calculated using different algorithms based on a key derivation function; According to the derived key, decrypt the intermediate ciphertext to obtain the message plaintext; According to the derived key and the decrypted intermediate ciphertext, obtain the message authentication ciphertext of the decryption process; whether the message authentication cipher of the decryption process is equal to the message authentication cipher of the encryption process, and if equal, outputting the message plaintext, otherwise, outputting .

7. A signature-based SM9 evidence encryption device, characterized in that, The encryption device implementation according to claim 7, the decryption device comprises: a secret sharing module for encrypter to encrypt the random number of the encryption process split into multiple shares using a t-out-of-n threshold secret sharing technique , calculate a first intermediate variable according to the verification key , and calculate the ciphertext of the first intermediate variable based on the shares of the secret sharing; An intermediate variable calculation module is configured to calculate a second intermediate variable by using a bilinear mapping , wherein, , , is a parameter in the SM9 signature algorithm, is a bilinear mapping, is a generator of a cyclic group , and is a generator of a cyclic group . An encryption module for encrypting shares of a second intermediate variable corresponding to a plaintext message using a signature-based witness encryption method. An encryption module for encrypting shares of a second intermediate variable corresponding to a plaintext message using a signature-based witness encryption method. An encryption module for encrypting shares of a second intermediate variable corresponding to a plaintext message using a signature-based witness encryption method.

8. A signature-based SM9 evidence decryption apparatus, characterized in that, The decryption module is used for decrypting the final ciphertext by using the second intermediate variable to obtain the corresponding message plaintext. an intermediate variable reconstruction module for obtaining a second intermediate variable from the final ciphertext after the decrypter obtains a predetermined number of signatures corresponding to labels ; and reconstructing the complete based on the share of the second intermediate variable ; The signature-based SM9 witness encryption device according to claim 7 and the signature-based SM9 witness decryption device according to claim 8.

9. A signature-based SM9 evidence encryption and decryption system, characterized in that, The processor implements the signature-based SM9 witness encryption method according to any one of claims 1 to 3 and the signature-based SM9 witness decryption method according to any one of claims 4 to 6 when the processor executes the program.

10. A computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, ​

Citation Information

Patent Citations

  • SM9 key generation method, device and system and readable storage medium

    CN111901111A

  • Certificateless threshold signcryption method under secret sharing mechanism

    CN112260830A