Threshold post-quantum signature method and system based on secure multi-party computing

By adopting Shamir secret sharing and packaged secret sharing technology in the threshold quantum signature technology based on secure multi-party computing, combined with the Aigis-Sig signature algorithm, the problems of low signature efficiency and insufficient security in the existing technology are solved, and an efficient and secure multi-party post-quantum signature solution is achieved.

CN119995864AActive Publication Date: 2025-05-13SHANGHAI JIAOTONG UNIV +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510150529.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-13
Estimated Expiration
2045-02-11

AI Technical Summary

Technical Problem

Existing post-threshold quantum signature technology based on secure multi-party computing has problems of inefficiency and insufficient adaptability in improving signature security and reliability, especially in the efficiency of multi-party collaboration to generate signatures and the long-term certification security of critical infrastructure.

Method used

Shamir secret sharing and packaging secret sharing technology are adopted, combined with Aigis-Sig signature algorithm, and the quantum signature is generated through multi-party collaboration to realize the key generation, signature generation and signature verification processes, improving the efficiency and security of signatures.

Benefits of technology

It improves the efficiency of multi-party collaboration to generate signatures, reduces communication complexity, enhances the robustness of quantum threats, ensures the security of critical infrastructure and long-term certification, and realizes a decentralized trust mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995864A_ABST
    Figure CN119995864A_ABST
Patent Text Reader

Abstract

The invention provides a post-threshold quantum signature method and system based on secure multi-party computing. The method comprises a key generation process, a signature generation process and a signature verification process. Entering a key generation process to obtain a public key and a private key; the public key is a public key, and the private key is a secret key; entering a signature generation process, and sending a signature to a receiver; the receiver receives the signature and enters a signature verification process; in the receiver, only the user who holds the private key and carries out signature can pass the verification of the corresponding public key. According to the method, technologies such as Shamir secret sharing and packaging secret sharing are combined, so that the efficiency of generating the signature through multi-party cooperation is effectively improved, and the communication complexity can be reduced to 25% of the direct use of the Shamir secret sharing when the distributed private key is generated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer and Internet technology, and specifically, relates to a threshold post-quantum signature method and system based on secure multi-party computing. More specifically, it is a threshold post-quantum signature scheme based on secure multi-party computing. Background Art

[0002] With the development of quantum computing, traditional encryption methods such as RSA and ECC may become vulnerable to the powerful computing power of quantum computers. Therefore, post-quantum signature technology has become a hot topic of research.

[0003] The threshold post-quantum signature scheme based on secure multi-party computation improves the security and reliability of the signature through multi-node collaborative computing and threshold setting. However, there are still some specific difficulties and shortcomings in the existing technical solutions. On the one hand, secure multi-party computation itself is a general term for a class of cryptographic protocols, and the details involved are relatively complex and need further optimization and improvement. On the other hand, although post-quantum signature technology has certain potential in dealing with quantum computing threats, it is still in the development stage and there may be some unresolved problems in practical applications. For example, how to improve the efficiency and performance of signatures while ensuring security; how to better adapt to different application scenarios and needs; how to solve new security threats that may arise, etc. These issues require further research and exploration to promote the development and application of threshold post-quantum signature technology based on secure multi-party computation.

[0004] Patent document CN117240479A discloses a multi-party quantum signature method, device, computer equipment and storage medium. The scheme includes: obtaining the ID information of the signatory and using the ID information as a public key, wherein the signatory includes multiple signers, and the signer is used to verify the signature of the initial information after receiving the initial information to obtain the signature information and send it to the next signer; obtaining the first private key and the second private key according to the public key; obtaining the first quantum bit sequence through the signature information and the first private key of each signer; obtaining the second quantum bit sequence through the signature information and the second private key of each signer; comparing the first quantum bit sequence and the second quantum bit sequence to obtain a comparison result, and obtaining a valid multi-party signature according to the comparison result; the scheme enables the signatory to sign in an orderly manner while reducing the risk of information tampering.

[0005] However, this solution cannot generate signatures efficiently through collaboration among multiple parties, nor can it guarantee the security of critical infrastructure and long-term authentication. This problem needs to be solved urgently. Summary of the invention

[0006] In view of the defects in the prior art, the object of the present invention is to provide a threshold post-quantum signature method and system based on secure multi-party computing.

[0007] A threshold post-quantum signature method based on secure multi-party computing provided by the present invention includes: a key generation process, a signature generation process and a signature verification process;

[0008] Enter the key generation process to obtain the public key and private key; the public key is a public key, and the private key is a confidential key; enter the signature generation process, and send the signature to the recipient; the recipient receives the signature and enters the signature verification process; among the recipients, only the user who holds the private key and signs can pass the verification of the corresponding public key.

[0009] Preferably, the key generation process includes:

[0010] Step A1: Let all signatories randomly generate signature matrices;

[0011] Step A2: All signatories are required to secretly share the signature matrix to obtain a shared secret;

[0012] Step A3: All signatories are required to obtain a sub-secret corresponding to the shared secret;

[0013] Step A4: Based on the sub-secret, all the signatories are required to calculate the shared secret to obtain a calculation result;

[0014] Step A5: Generate a key based on the calculated result;

[0015] Step A6: Based on the secret key, publish the public key of the signature;

[0016] In step A1, the signature matrix is ​​A, and the matrix of the i-th signer is A_i; each element in the signature matrix is ​​randomly generated from a finite ring, namely R_q;

[0017] In step A2, the shared secret is [A];

[0018] The mathematical expression of the shared secret is:

[0019] Where n is the number of signature participants; [A_1] represents the sub-secret of the first signatory; [A_n] represents the sub-secret of the nth signatory; the sub-secrets include the first sub-secret and the second sub-secret;

[0020] In step A4, the mathematical expression of the calculation result is:

[0021] [t]=[A]*[s1]+[s2]

[0022] Wherein, [t] represents the shared secret of the intermediate calculation result in the process of generating the signature; the symbol * represents matrix and vector multiplication, where the multiplication is calculated using the corresponding multiplication protocol of the secret sharing protocol; [s1] represents the first sub-secret, and [s2] represents the second sub-secret, where s1 is a vector of length l, s2 is a vector of length k, and l and k both represent constants.

[0023] Preferably, the step A6 includes:

[0024] Step A6.1: All signatories are required to generate a secret sharing of 0 on the ring, i.e., [0]; the degree of the secret sharing is n-1;

[0025] Step A6.2: All signatories are asked to calculate the reconstruction result and generate the signed public key;

[0026] In step A6.1, the ring 0 is the zero element in the polynomial ring where the current calculation is located;

[0027] In step A6.2, the mathematical expression of the reconstruction result is:

[0028] [t]=[t]+[0]

[0029] Where [t] represents the element t of the secret share, t represents a part of the public key, i.e., the reconstruction result; [0] represents the secret share of 0 on the ring, i.e., the 0th element of the secret share with degree n-1;

[0030] The mathematical expression of the public key is:

[0031] t=A*s1+s2

[0032] Here, t represents a part of the public key.

[0033] Preferably, the signature generation process includes:

[0034] Step B1: randomly generate a vector [y];

[0035] Step B2: Calculate the vector [y] through a secure multi-party computing protocol to obtain [w];

[0036] Step B3: Based on the [w], [c] is calculated by a secure multi-party computing protocol;

[0037] Step B4: Calculate [z] based on the vectors [y] and [c];

[0038] Step B5: through the secure multi-party computing comparison protocol, determine whether the infinite norm of [z] is greater than or equal to gamma_2-beta. If the result is yes, re-execute step B1; if the result is no, share and calculate z and c to obtain the calculation result; gamma_2-beta is a security parameter;

[0039] Step B6: Based on the calculation result, output a signature, the signature being sigma, sigma=(z, c);

[0040] In step B1, the length of vector [y] is 1;

[0041] In step B2, the mathematical expression of [w] is:

[0042] [w]=A[y]

[0043] Where [w] represents the state of secret sharing; [y] is the vector [y];

[0044] In step B3, the mathematical expression of [c] is:

[0045] [c]=H1(HighBits([w],2*gamma_2)||mu)

[0046] Where [c] represents the calculation result of the secure multi-party computing protocol, c represents another element of the signature, H1 represents the hash function, mu represents the message, HighBits represents the function of taking the high bits, gamma_2 represents the security parameter of the MSIS problem, and || represents the concatenation of two strings.

[0047] In step B4, the expression of [z] is:

[0048] [z]=[y]+[c][s_1]

[0049] Among them, [z] represents the intermediate result of the calculation, z represents an element of a signature; and [s_1] represents the secret sharing of the private key.

[0050] Preferably, the signature verification process includes:

[0051] Step C1: Set the public key to pk, the message to mu, and the signature to sigma;

[0052] Step C2: Determine whether the infinite norm of z is less than gamma_1-beta, and c is equal to H1(HighBits(Az-ct,2*gamma_2)||mu); if the result is yes, the signature verification is successful; if the result is no, the signature is illegal; wherein gamma_1-beta represents another security parameter; A represents the signature matrix; z represents an element of one signature; c represents an element of another signature; t represents an intermediate calculation result in the process of generating the signature.

[0053] According to the present invention, a threshold post-quantum signature system based on secure multi-party computing is provided, comprising:

[0054] Key generation module, signature generation module and signature verification module;

[0055] The key generation module is used to generate a key; the signature generation module is used to generate a signature; the signature verification module is used to verify the signature;

[0056] The key generation module is triggered to obtain a public key and a private key; the public key is a public key, and the private key is a confidential key; the signature generation module is triggered to send the signature to the recipient; the recipient receives the signature and triggers the signature verification module; among the recipients, only users who hold the private key and sign can pass the verification of the corresponding public key.

[0057] Preferably, the key generation module includes:

[0058] Module A1: Let all signatories randomly generate signature matrices;

[0059] Module A2: All signatories are required to secretly share the signature matrix to obtain a shared secret;

[0060] Module A3: enabling all signatories to obtain a sub-secret corresponding to the shared secret;

[0061] Module A4: Based on the sub-secret, all the signatories are required to calculate the shared secret to obtain a calculation result;

[0062] Module A5: Generate a key based on the calculated result;

[0063] Module A6: Based on the secret key, publish the public key of the signature;

[0064] In the module A1, the signature matrix is ​​A, and the matrix of the i-th signer is A_i; each element in the signature matrix is ​​randomly generated from a finite ring, namely R_q;

[0065] In the module A2, the shared secret is [A];

[0066] The mathematical expression of the shared secret is:

[0067] Where n is the number of signature participants; [A_1] represents the sub-secret of the first signatory; [A_n] represents the sub-secret of the nth signatory; the sub-secrets include the first sub-secret and the second sub-secret;

[0068] In the module A4, the mathematical expression of the calculation result is:

[0069] [t]=[A]*[s1]+[s2]

[0070] Wherein, [t] represents the shared secret of the intermediate calculation result in the process of generating the signature; the symbol * represents matrix and vector multiplication, where the multiplication is calculated using the corresponding multiplication protocol of the secret sharing protocol; [s1] represents the first sub-secret, and [s2] represents the second sub-secret, where s1 is a vector of length l, s2 is a vector of length k, and l and k both represent constants.

[0071] Preferably, the module A6 includes:

[0072] Module A6.1: All signatories generate a secret share of 0 on the ring, i.e., [0]; the degree of the secret share is n-1;

[0073] Module A6.2: All signatories are required to calculate the reconstruction result and generate the signed public key;

[0074] In the module A6.1, the ring 0 is the zero element in the polynomial ring where the current calculation is located;

[0075] In the module A6.2, the mathematical expression of the reconstruction result is:

[0076] [t]=[t]+[0]

[0077] Where [t] represents the element t of the secret share, t represents a part of the public key, i.e., the reconstruction result; [0] represents the secret share of 0 on the ring, i.e., the 0th element of the secret share with degree n-1;

[0078] The mathematical expression of the public key is:

[0079] t=A*s1+s2

[0080] Here, t represents a part of the public key.

[0081] Preferably, the signature generation module includes:

[0082] Module B1: Randomly generate vector [y];

[0083] Module B2: Calculate the vector [y] through a secure multi-party computing protocol to obtain [w];

[0084] Module B3: Based on the [w], [c] is calculated by a secure multi-party computing protocol;

[0085] Module B4: Calculate [z] based on the vectors [y] and [c];

[0086] Module B5: through the secure multi-party computing comparison protocol, determine whether the infinite norm of [z] is greater than or equal to gamma_2-beta. If the result is yes, re-trigger the work of module B1; if the result is no, share and calculate z and c to obtain the calculation result; gamma_2-beta is a security parameter;

[0087] Module B6: Based on the calculation result, output a signature, the signature is sigma, sigma = (z, c);

[0088] In the module B1, the length of the vector [y] is 1;

[0089] In the module B2, the mathematical expression of [w] is:

[0090] [w]=A[y]

[0091] Where [w] represents the state of secret sharing; [y] is the vector [y];

[0092] In step B3, the mathematical expression of [c] is:

[0093] [c]=H1(HighBits([w],2*gamma_2)||mu)

[0094] Where [c] represents the calculation result of the secure multi-party computing protocol, c represents another element of the signature, H1 represents the hash function, mu represents the message, HighBits represents the function of taking the high bits, gamma_2 represents the security parameter of the MSIS problem, and || represents the concatenation of two strings.

[0095] In the module B4, the expression of [z] is:

[0096] [z]=[y]+[c][s_1]

[0097] Among them, [z] represents the intermediate result of the calculation, z represents an element of a signature; and [s_1] represents the secret sharing of the private key.

[0098] Preferably, the signature verification module includes:

[0099] Module C1: Set the public key to pk, the message to mu, and the signature to sigma;

[0100] Module C2: Determine whether the infinite norm of z is less than gamma_1-beta, and c is equal to H1(HighBits(Az-ct,2*gamma_2)||mu); if the result is yes, the signature verification is successful; if the result is no, the signature is illegal; wherein, gamma_1-beta represents another security parameter; A represents the signature matrix; z represents an element of one signature; c represents an element of another signature; t represents the intermediate calculation result in the process of generating the signature.

[0101] Compared with the prior art, the present invention has the following beneficial effects:

[0102] 1. The present invention effectively improves the efficiency of multi-party collaborative signature generation by adopting Shamir secret sharing combined with packaged secret sharing and other technologies. When generating distributed private keys, the communication complexity can be reduced to 25% of directly using Shami secret sharing. Specifically, its value depends on the specific values ​​of the parameter t and the number of packaged secrets k under the condition of ensuring security. Therefore, the present invention realizes a secure multi-party post-quantum signature scheme that is resistant to quantum computing attacks.

[0103] 2. The present invention realizes a decentralized trust mechanism by combining the anti-quantum attack capability of the Aigis-Sig signature algorithm with the characteristics of multi-party secure computing, solves the risk of single point failure in traditional certificate authentication, and can resist the failure of up to t nodes or being hacked by attackers when the n-party signature threshold is set to t, thereby enhancing the elasticity and reliability of the certificate authentication system.

[0104] 3. The present invention adopts a method of multi-party collaboration to generate post-quantum signatures, which not only inherits the anti-quantum computing characteristics of post-quantum signatures, but also disperses attack targets through multi-party collaboration. Originally, attackers only needed to break through one central node, but now they need to break through t+1 nodes to achieve the attack effect, which improves the robustness against quantum threats and ensures the security of critical infrastructure and long-term authentication.

[0105] 4. The multi-party post-quantum signature scheme of the present invention enhances the trust level of key systems, namely financial systems and military systems, through its distributed and quantum attack-resistant characteristics, and meets the stringent requirements for certificate authentication in these high-security fields.

[0106] 5. The present invention adopts Shamir secret sharing technology and packaged secret sharing technology to realize a multi-party post-quantum signature that is resistant to quantum attacks and has high security and a decentralized trust mechanism. BRIEF DESCRIPTION OF THE DRAWINGS

[0107] Other features, objects and advantages of the present invention will become more apparent from the detailed description of non-limiting embodiments made with reference to the following drawings:

[0108] Figure 1 A schematic diagram of a key generation process provided by the present invention;

[0109] Figure 2 A schematic diagram of the signature generation process provided by the present invention;

[0110] Figure 3 This is a schematic diagram of the signature process provided by the present invention. DETAILED DESCRIPTION

[0111] The present invention is described in detail below in conjunction with specific embodiments. The following embodiments will help those skilled in the art to further understand the present invention, but are not intended to limit the present invention in any form. It should be noted that, for those of ordinary skill in the art, several changes and improvements can also be made without departing from the concept of the present invention. These all belong to the protection scope of the present invention.

[0112] A threshold post-quantum signature method based on secure multi-party computing provided by the present invention includes: a key generation step, a signature generation step, and a signature verification step;

[0113] First, the key is generated, and the public key and private key are generated. The private key is confidential, and the public key can be made public. All people holding the private key sign the signature file together. After sending the file and signature to the recipient, the recipient can use the public key and file to verify the signature calculation. Only the signature of the person holding the private key can pass the verification of the corresponding public key.

[0114] The key generation step includes:

[0115] Step A1: Let all signatories randomly generate signature matrices;

[0116] Step A2: All the signatories are required to secretly share the signature matrix to obtain a shared secret;

[0117] Step A3: enabling the participating party to obtain a sub-secret corresponding to the shared secret;

[0118] Step A4: Instruct all the signatories to calculate the shared secret and obtain a calculation result;

[0119] Step A5: Generate a key based on the calculation result;

[0120] Step A6: Based on the secret key, publish the signed public key.

[0121] In step A1, the signature matrix is ​​A, and the matrix of the i-th signer is A_i; each element in the signature matrix is ​​randomly generated from a finite ring, namely R_q;

[0122] In step A2, the shared secret is [A];

[0123] The mathematical expression of [A] is:

[0124] [A]=[A_1]+…+[A_n]

[0125] Where n is the number of signing participants; [A_1] represents the sub-secret of the first signing party; and [A_n] represents the sub-secret of the nth signing party.

[0126] In step A3, the sub-secrets include: sub-secret [s1] and sub-secret [s2]; wherein s1 is a vector of length l, and s2 is a vector of length k;

[0127] In step A3, the participants are all the signatories;

[0128] In step A4, the mathematical expression of the calculation result is:

[0129] [t]=[A]*[s1]+[s2]

[0130] Wherein, [t] represents the shared secret of the intermediate calculation result in the process of generating the signature; the symbol * represents matrix and vector multiplication, where the multiplication is calculated using the corresponding multiplication protocol of the secret sharing protocol.

[0131] In the step A6, it includes:

[0132] Step A6.1: All signatories are required to generate a secret share of 0 on the ring, i.e. [0]; the degree of the secret share is n-1.

[0133] Step A6.2: Let all signers calculate [t] and obtain the reconstruction result;

[0134] Step A6.3: Generate a signed public key based on the reconstruction result;

[0135] In step A6.1, the zero on the ring is the zero element in the polynomial ring where the current calculation is located. A zero element on the ring is defined as any element multiplied by it is equal to itself.

[0136] In step A6.2, the expression of [t] is:

[0137] [t]=[t]+[0]

[0138] Where [t] represents the element t of the secret share, and t represents a part of the public key; [0] represents the vector composed of 0 elements of the secret share with degree n-1, and 0 represents the zero element on the ring;

[0139] The reconstruction result is t.

[0140] In step A6.3, the public key of the signature is (A, t); the mathematical expression of (A, t) is:

[0141] t=A*s1+s2

[0142] Among them, t represents a part of the public key, which can be combined with another part of the public key to form the public key, that is, (A, t).

[0143] The signature generation step includes:

[0144] Step B1: randomly generate a vector [y];

[0145] Step B2: Calculate the vector [y] through a secure multi-party computing protocol to obtain [w];

[0146] Step B3: Based on the [w], [c] is calculated by a secure multi-party computing protocol;

[0147] Step B4: Calculate [z] based on the vectors [y] and [c];

[0148] Step B5: Use the secure multi-party computation comparison protocol to determine whether the infinite norm of [z] is greater than or equal to gamma_2-beta. If yes, re-execute step B1; if no, share and calculate z and c to obtain the calculation result.

[0149] Step B6: Based on the calculation result, output a signature, the signature being sigma, sigma = (z, c).

[0150] In step B1, the length of vector [y] is l;

[0151] Each element of the vector [y] is randomly generated from a finite ring R_q and is infinitely smaller than gamma_1-1; the gamma_1-1 is the value of the security parameter gamma1 minus 1.

[0152] In step B2, the mathematical expression of [w] is:

[0153] [w]=A[y]

[0154] Where [w] represents the state of secret sharing;

[0155] In step B3, the expression of [c] is:

[0156] [c]=H1(HighBits([w],2*gamma_2)||mu)

[0157] Among them, H1 represents the hash function; mu represents the message; HighBits represents the function of taking the high bits; gamma_2 represents the security parameter of the MSIS problem; * represents the multiplication sign; || represents the concatenation of two strings;

[0158] In step B4, the expression of [z] is:

[0159] [z]=[y]+[c][s_1]

[0160] Where [z] represents the intermediate result of the calculation; [s_1] represents the secret sharing of the private key;

[0161] In step B5, gamma_2-beta is a safety parameter, specifically indicating a condition that needs to be met in order to ensure safety;

[0162] Specifically, in gamma_2-beta, gamma_2 and beta are both safety parameters, where beta is the safety parameter for solving the SIS problem of LWE, and gamma_2 is the safety parameter for the MSIS problem;

[0163] The signature verification step includes:

[0164] Step C1: Assume that the public key is pk, the message is mu, and the signature is sigma; specifically, pk = (A, t), signature sigma = (z, c):

[0165] Step C2: Determine whether the infinite norm of z is less than gamma_1-beta, and c is equal to H1(HighBits(Az-ct,2*gamma_2)||mu); if the result is yes, the signature verification is successful; if the result is no, the signature is illegal; wherein gamma_1-beta represents another security parameter; A represents the signature matrix; z represents an element of one signature; c represents an element of another signature; t represents an intermediate calculation result in the process of generating the signature.

[0166] Specifically, c is the plaintext corresponding to the secret share [c], and H1(HighBits(Az-ct,2gamma_2)||mu) is a way to directly calculate the plaintext.

[0167] The key generation algorithm is the key generation step.

[0168] The key generation step comprises:

[0169] Step 1: All signatories randomly generate a matrix of length k and width w, i.e. A. Each element in the matrix is ​​randomly generated from a finite ring R_q. The matrix generated by signatory i is denoted as A_i.

[0170] Step 2: All signatories share the matrix generated in the first step with other participants through Shamir secret sharing and packaged secret sharing technology. Assuming that the parameter of packaged secret sharing is t, the total number of signatories is n, and the number of packages of packaged secret sharing is k, all signatories use a packaged secret sharing polynomial of t+k-1 to package the corresponding coefficients of k elements in the matrix A at one time. Specifically, the corresponding position coefficients of the ring elements represented by the polynomial.

[0171] Step 3: Use square brackets to represent the secret after packaged secret sharing, and each participant will get the corresponding sub-secret. In the above operation, each signatory i generates A_i and shares it with other participants through Shamir secret sharing and packaged secret sharing. The other signatory parties will get the sub-secret [A_i] of A_i.

[0172] Step 4: All signatories calculate [A];

[0173] The mathematical expression of [A] is:

[0174] [A]=[A_1]+…+[A_n]

[0175] Where n is the number of signing participants.

[0176] Step 5: All signatories send their respective [A] to other signatories, and other signatories calculate the matrix A through secret sharing reconstruction technology.

[0177] Step 6: All signatories use Shamir secret sharing and packaged secret sharing technology, and multiple signatories jointly randomly generate a signed private key s1 and a signed private key s2, where s1 is a vector of length l and s2 is a vector of length k.

[0178] Each signatory obtains the sub-secret [s1] and sub-secret [s2] of vector s1 and vector s2, where each element in vector s1 and vector s2 is selected from the ring R_q whose infinite norm is less than or equal to η.

[0179] Step 6: All signatories use the method of step 3 to locally pack the coefficients of the k elements in the matrix A with a polynomial of local cost k-1. And calculate [t] = [A] * [s_1] + [s_2] according to the multiplication rule of the ring elements, that is, the multiplication of the polynomial.

[0180] Step 7: All signatories jointly generate a secret share [0] of 0 on the ring, and the degree of the secret share is n-1.

[0181] Step 8: All signatories jointly calculate [t] = [t] + [0] and then disclose [t] to other participants. All signatories calculate t through secret sharing reconstruction technology.

[0182] Step nine, (A, t) is published as the public key of the signature.

[0183] The signature generation algorithm is the signature generation step.

[0184] The signature generation step includes: assuming that the message mu is to be signed:

[0185] Step 1: All signatories jointly randomly generate a vector [y] of length l. Each element of vector [y] is randomly generated from a finite ring R_q and satisfies that the infinite norm is less than gamma_1-1; where the symbol - represents subtraction and gamma_1 is a security parameter.

[0186] Step 2: All participants jointly pass the secure multi-party computing protocol [w] = A[y].

[0187] Step 3: All participants jointly calculate [c] = H1(HighBits([w], 2*gamma_2)||mu) through the secure multi-party computing protocol. gamma_2 is the security parameter of the MSIS problem, HighBits is a function that takes high-order bits, and ([w], 2*gamma_2) means taking gamma_2 bits starting from the high-order bits of the coefficients of each polynomial (ring elements can be regarded as polynomials) in the vector w. Since [w] is a state of being shared in secret, the secure multi-party computing protocol is used to first decompose the coefficient vector of [w] during calculation, and then take it from the high-order bits. H1 is the specified hash function.

[0188] Step 4: All participants calculate [z] = [y] + [c] [s_1]

[0189] Step 5: All participants use the secure multi-party computation comparison protocol to determine whether the infinite norm of [z] is greater than or equal to gamma_1-beta and whether LowBits(A[y]-[c][s_2],2gamma_2) is greater than or equal to gamma_2-beta. If either of the two is true, start again from the first step. Otherwise, all participants distribute [z], [c] to other participants, and all participants calculate z and c through secret sharing reconstruction technology.

[0190] Step 6: All participants output signature sigma = (z, c).

[0191] The signature verification algorithm is the signature verification step.

[0192] The signature verification step comprises:

[0193] Assume that the given public key pk = (A, t), the message is mu, and the signature sigma = (z, c):

[0194] Step 1: The signature verifier calculates whether the infinite norm of z is less than gamma_1-beta and whether c is equal to H1(HighBits(Az-ct,2gamma_2)||mu). If both equations hold, the signature verification is successful. Otherwise, the signature is considered illegal.

[0195] The present invention also provides a threshold post-quantum signature system based on secure multi-party computation. The threshold post-quantum signature system based on secure multi-party computation can be implemented by executing the process steps of the threshold post-quantum signature method based on secure multi-party computation, that is, those skilled in the art can understand the threshold post-quantum signature method based on secure multi-party computation as a preferred implementation of the threshold post-quantum signature system based on secure multi-party computation.

[0196] Those skilled in the art know that, in addition to realizing the system and its various devices, modules, and units provided by the present invention in a purely computer-readable program code, it is entirely possible to realize the same functions in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, the system and its various devices, modules, and units provided by the present invention can be considered as a hardware component, and the devices, modules, and units included therein for realizing various functions can also be regarded as structures within the hardware component; the devices, modules, and units for realizing various functions can also be regarded as both software modules for realizing the method and structures within the hardware component.

[0197] The above describes the specific embodiments of the present invention. It should be understood that the present invention is not limited to the above specific embodiments, and those skilled in the art can make various changes or modifications within the scope of the claims, which does not affect the essence of the present invention. In the absence of conflict, the embodiments of the present application and the features in the embodiments can be combined with each other arbitrarily.

Claims

1. A threshold post-quantum signature method based on secure multi-party computation, characterized in that: include: Key generation process, signature generation process and signature verification process; Enter the key generation process and obtain the public key and private key; The public key is a public key, and the private key is a confidential key; Enter the signature generation process and send the signature to the recipient; the recipient receives the signature and enters the signature verification process; among the recipients, only the user who holds the private key and signs can pass the verification of the corresponding public key.

2. The threshold post-quantum signature method based on secure multi-party computing according to claim 1 is characterized in that: The key generation process includes: Step A1: Let all signatories randomly generate signature matrices; Step A2: All signatories are required to secretly share the signature matrix to obtain a shared secret; Step A3: All signatories are required to obtain a sub-secret corresponding to the shared secret; Step A4: Based on the sub-secret, all the signatories are required to calculate the shared secret to obtain a calculation result; Step A5: Generate a key based on the calculated result; Step A6: Based on the secret key, publish the public key of the signature; In step A1, the signature matrix is ​​A, and the matrix of the i-th signer is A_i; each element in the signature matrix is ​​randomly generated from a finite ring, namely R_q; In step A2, the shared secret is [A]; The mathematical expression of the shared secret is: Where n is the number of signature participants; [A_1] represents the sub-secret of the first signatory; [A_n] represents the sub-secret of the nth signatory; the sub-secrets include the first sub-secret and the second sub-secret; In step A4, the mathematical expression of the calculation result is: [t]=[A]*[s1]+[s2] Wherein, [t] represents the shared secret of the intermediate calculation result in the process of generating the signature; the symbol * represents matrix and vector multiplication, where the multiplication is calculated using the corresponding multiplication protocol of the secret sharing protocol; [s1] represents the first sub-secret, and [s2] represents the second sub-secret, where s1 is a vector of length l, s2 is a vector of length k, and l and k both represent constants.

3. The threshold post-quantum signature method based on secure multi-party computing according to claim 2 is characterized in that: In the step A6, it includes: Step A6.1: All signatories are required to generate a secret sharing of 0 on the ring, i.e., [0]; the degree of the secret sharing is n-1; Step A6.2: All signatories are asked to calculate the reconstruction result and generate the signed public key; In step A6.1, the ring 0 is the zero element in the polynomial ring where the current calculation is located; In step A6.2, the mathematical expression of the reconstruction result is: [t]=[t]+[0] Where [t] represents the element t of the secret share, t represents a part of the public key, i.e., the reconstruction result; [0] represents the secret share of 0 on the ring, i.e., the 0th element of the secret share with degree n-1; The mathematical expression of the public key is: t=A*s1+s2 Here, t represents a part of the public key.

4. The threshold post-quantum signature method based on secure multi-party computation according to claim 3 is characterized in that: The signature generation process includes: Step B1: randomly generate a vector [y]; Step B2: Calculate the vector [y] through a secure multi-party computing protocol to obtain [w]; Step B3: Based on the [w], [c] is calculated by a secure multi-party computing protocol; Step B4: Calculate [z] based on the vectors [y] and [c]; Step B5: through the secure multi-party computing comparison protocol, determine whether the infinite norm of [z] is greater than or equal to gamma_2-beta. If the result is yes, re-execute step B1; if the result is no, share and calculate z and c to obtain the calculation result; gamma_2-beta is a security parameter; Step B6: Based on the calculation result, output a signature, the signature being sigma, sigma=(z, c); In step B1, the length of vector [y] is 1; In step B2, the mathematical expression of [w] is: [w]=A[y] Where [w] represents the state of secret sharing; [y] is the vector [y]; In step B3, the mathematical expression of [c] is: [c]=H1(HighBits([w],2*gamma_2)||mu) Where [c] represents the calculation result of the secure multi-party computing protocol, c represents another element of the signature, H1 represents the hash function, mu represents the message, HighBits represents the function of taking the high bits, gamma_2 represents the security parameter of the MSIS problem, and || represents the concatenation of two strings. In step B4, the expression of [z] is: [z]=[y]+[c][s_1] Among them, [z] represents the intermediate result of the calculation, z represents an element of a signature; and [s_1] represents the secret sharing of the private key.

5. The threshold post-quantum signature method based on secure multi-party computation according to claim 1 is characterized in that: The signature verification process includes: Step C1: Set the public key to pk, the message to mu, and the signature to sigma; Step C2: Determine whether the infinite norm of z is less than gamma_1-beta, and c is equal to H1(HighBits(Az-ct,2*gamma_2)||mu); if the result is yes, the signature verification is successful; if the result is no, the signature is illegal; wherein gamma_1-beta represents another security parameter; A represents the signature matrix; z represents an element of one signature; c represents an element of another signature; t represents an intermediate calculation result in the process of generating the signature.

6. A threshold post-quantum signature system based on secure multi-party computation, characterized in that: include: Key generation module, signature generation module and signature verification module; The key generation module is used to generate a key; The signature generation module is used to generate a signature; The signature verification module is used to verify the signature; The key generation module is triggered to obtain a public key and a private key; the public key is a public key, and the private key is a confidential key; the signature generation module is triggered to send the signature to the recipient; the recipient receives the signature and triggers the signature verification module; among the recipients, only users who hold the private key and sign can pass the verification of the corresponding public key.

7. The threshold post-quantum signature system based on secure multi-party computation according to claim 6 is characterized in that: The key generation module includes: Module A1: Let all signatories randomly generate signature matrices; Module A2: All signatories are required to secretly share the signature matrix to obtain a shared secret; Module A3: enabling all signatories to obtain a sub-secret corresponding to the shared secret; Module A4: Based on the sub-secret, all the signatories are required to calculate the shared secret to obtain a calculation result; Module A5: Generate a key based on the calculated result; Module A6: Based on the secret key, publish the public key of the signature; In the module A1, the signature matrix is ​​A, and the matrix of the i-th signer is A_i; each element in the signature matrix is ​​randomly generated from a finite ring, namely R_q; In the module A2, the shared secret is [A]; The mathematical expression of the shared secret is: Where n is the number of signature participants; [A_1] represents the sub-secret of the first signatory; [A_n] represents the sub-secret of the nth signatory; the sub-secrets include the first sub-secret and the second sub-secret; In the module A4, the mathematical expression of the calculation result is: [t]=[A]*[s1]+[s2] Wherein, [t] represents the shared secret of the intermediate calculation result in the process of generating the signature; the symbol * represents matrix and vector multiplication, where the multiplication is calculated using the corresponding multiplication protocol of the secret sharing protocol; [s1] represents the first sub-secret, and [s2] represents the second sub-secret, where s1 is a vector of length l, s2 is a vector of length k, and l and k both represent constants.

8. The threshold post-quantum signature system based on secure multi-party computation according to claim 7 is characterized in that: The module A6 includes: Module A6.1: All signatories generate a secret share of 0 on the ring, i.e., [0]; the degree of the secret share is n-1; Module A6.2: All signatories are required to calculate the reconstruction result and generate the signed public key; In the module A6.1, the ring 0 is the zero element in the polynomial ring where the current calculation is located; In the module A6.2, the mathematical expression of the reconstruction result is: [t]=[t]+[0] Where [t] represents the element t of the secret share, t represents a part of the public key, i.e., the reconstruction result; [0] represents the secret share of 0 on the ring, i.e., the 0th element of the secret share with degree n-1; The mathematical expression of the public key is: t=A*s1+s2 Here, t represents a part of the public key.

9. The threshold post-quantum signature system based on secure multi-party computation according to claim 8, characterized in that: The signature generation module includes: Module B1: Randomly generate vector [y]; Module B2: Calculate the vector [y] through a secure multi-party computing protocol to obtain [w]; Module B3: Based on the [w], [c] is calculated by a secure multi-party computing protocol; Module B4: Calculate [z] based on the vectors [y] and [c]; Module B5: through the secure multi-party computing comparison protocol, determine whether the infinite norm of [z] is greater than or equal to gamma_2-beta. If the result is yes, re-trigger the work of module B1; if the result is no, share and calculate z and c to obtain the calculation result; gamma_2-beta is a security parameter; Module B6: Based on the calculation result, output a signature, the signature is sigma, sigma = (z, c); In the module B1, the length of the vector [y] is 1; In the module B2, the mathematical expression of [w] is: [w]=A[y] Where [w] represents the state of secret sharing; [y] is the vector [y]; In step B3, the mathematical expression of [c] is: [c]=H1(HighBits([w],2*gamma_2)||mu) Where [c] represents the calculation result of the secure multi-party computing protocol, c represents another element of the signature, H1 represents the hash function, mu represents the message, HighBits represents the function of taking the high bits, gamma_2 represents the security parameter of the MSIS problem, and || represents the concatenation of two strings. In the module B4, the expression of [z] is: [z]=[y]+[c][s_1] Among them, [z] represents the intermediate result of the calculation, z represents an element of a signature; and [s_1] represents the secret sharing of the private key.

10. The threshold post-quantum signature system based on secure multi-party computation according to claim 9 is characterized in that: In the signature verification module, include: Module C1: Set the public key to pk, the message to mu, and the signature to sigma; Module C2: Determine whether the infinite norm of z is less than gamma_1-beta, and c is equal to H1(HighBits(Az-ct,2*gamma_2)||mu); if the result is yes, the signature verification is successful; if the result is no, the signature is illegal; wherein, gamma_1-beta represents another security parameter; A represents the signature matrix; z represents an element of one signature; c represents an element of another signature; t represents the intermediate calculation result in the process of generating the signature.

Citation Information

Patent Citations

  • Multi-party quantum signature method and device, computer equipment and storage medium

    CN117240479A

  • Post-quantum multi-node threshold signature method and system

    CN114117549A

  • Efficient anti-quantum threshold signature method and system

    CN118157865A

  • Combined Digital Signature Algorithms for Security Against Quantum Computers

    US20210377049A1

  • Digital signature thresholding method and apparatus

    WO2023093278A1