Digital signature generation / verification method, terminal and medium
By constructing a new public key construction method, combining interference factors and decoding factors to safely enhance the initial core mapping, and using reversible linear mapping to mask the public key, the problem of the existing digital signature system reducing security when facing quantum computing is solved, and a high-security digital signature system against quantum computing is realized.
Patent Information
- Application Number
- CN202510460776.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-14
AI Technical Summary
Existing digital signature systems are easily cracked when facing quantum computing, resulting in reduced security and inability to effectively resist quantum computing attacks.
By constructing a new method of public key construction, including random selection of initial core maps, combining interference factors and decoding factors for security enhancement, and masking the public key with reversible linear mapping, generating and verifying digital signatures.
Improves the security of digital signatures, enabling them to withstand quantum computing attacks, ensuring the integrity of data information during transmission and the accuracy of identity authentication.
Smart Images

Figure CN119995901A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of digital encryption, and in particular relates to a method for constructing a public key, a method for generating / verifying a digital signature, a terminal and a computer storage medium. Background Art
[0002] Digital signature (also known as public key digital signature) is an identity authentication method based on public key encryption technology. It verifies the authenticity of the sender and the integrity of the data by generating a unique and unforgeable string of characters. Its core relies on asymmetric encryption technology and digital summary technology, and usually includes two complementary operation processes: signature generation and verification.
[0003] The existing mainstream digital signature technology is usually based on RSA (large integer factorization problem) and elliptic curve cryptography (ECC, discrete logarithm problem on elliptic curve). However, due to the rapid development of quantum computing, quantum attack methods such as Shor's algorithm can theoretically crack the above classical encryption system in polynomial time. As a result, digital signatures generated based on existing technologies are easily cracked when facing quantum computing, which greatly reduces the security of the digital signature system and even faces severe challenges.
[0004] Therefore, how to construct a digital signature that can resist quantum computing attacks has become a technical problem that needs to be solved urgently in this technical field. Summary of the invention
[0005] In view of the above shortcomings in the prior art, the purpose of the present invention is to provide a public key construction method, a digital signature generation / verification method, a terminal and a computer storage medium, so as to solve the problem of poor security of the existing digital signature system.
[0006] To achieve the above-mentioned object and other related objects, the present invention provides a method for constructing a public key in a first aspect, comprising:
[0007] An initial core mapping is randomly selected; wherein the initial core mapping is an n-order polynomial mapping solvable on a finite field; wherein n is an integer not less than 4; a pre-constructed interference factor and a decoding factor are combined to obtain a combination factor; the initial core mapping is security enhanced by the combination factor to obtain an enhanced new core mapping; the interference factor is a mapping item used to perform interference encryption on the initial core mapping; the decoding factor is used to offset the interference factor when inputting solution information; the new core mapping is masked by using a reversible linear mapping to obtain a public key.
[0008] In one embodiment of the present application, the interference factor includes a first polynomial mapping and a second polynomial mapping, and the decoding factor includes a third polynomial mapping; wherein the first polynomial mapping, the second polynomial mapping and the third polynomial mapping are all polynomial mappings of degree greater than or equal to 2; the third polynomial mapping and the first polynomial mapping have the same polynomial degree, and the degree and the second polynomial mapping satisfy: the sum of the two is equal to n; and the third polynomial mapping also satisfies: when the solution information is input, the same value as the first polynomial mapping can be solved.
[0009] In one embodiment of the present application, the method for obtaining the combination factor includes:
[0010] The first polynomial mapping and the second polynomial mapping are compounded to obtain a first composite polynomial mapping; the second polynomial mapping and the third polynomial mapping are compounded to obtain a second composite polynomial mapping; the polynomial mapping obtained by subtracting the first composite polynomial from the second composite polynomial is used as the combination factor; or including: the polynomial mapping obtained by subtracting the first polynomial mapping from the third polynomial mapping is used as the third composite polynomial mapping; the polynomial mapping obtained by compounding the second polynomial mapping with the third composite polynomial is used as the combination factor.
[0011] In one embodiment of the present application, the implementation method of security enhancement of the initial core mapping by combining factors includes:
[0012] The initial core mapping is superimposed with the combination factor to obtain a new core mapping after security enhancement, which is:
[0013]
[0014] Or the new core mapping after the security enhancement is:
[0015]
[0016] Wherein, G is the new core mapping; is the first polynomial mapping; is the second polynomial mapping; is the third polynomial mapping; is the initial core mapping.
[0017] In one embodiment of the present application, the third polynomial mapping is:
[0018]
[0019] And for any n-dimensional vector over a finite field and , can be solved using the third polynomial mapping to obtain ,satisfy:
[0020]
[0021] in, and are any n-dimensional vectors on the finite field, y is a mapping based on the third polynomial and The result vector obtained after solving.
[0022] In one embodiment of the present application, the implementation method of using a reversible linear mapping to mask the new core mapping includes:
[0023] A first reversible linear mapping and a second reversible linear mapping are randomly selected; and the first reversible linear mapping, the new core mapping, and the second reversible linear mapping are sequentially compounded.
[0024] To achieve the above-mentioned and other related purposes, the present invention provides a method for generating a digital signature in a second aspect, comprising:
[0025] After obtaining the message data, extract the message digest in the message data; based on the private key corresponding to the public key, convert the message digest into a digital signature; wherein the public key is obtained based on any of the public key construction methods described above.
[0026] In one embodiment of the present application, the private key is a set including a first reversible linear mapping, a second reversible linear mapping, an initial core mapping, a first polynomial mapping, a second polynomial mapping, and a third polynomial mapping;
[0027] The converting of the message digest based on the private key corresponding to the public key includes:
[0028] Based on the second reversible linear mapping, a third reversible linear mapping is obtained; based on the third reversible linear mapping, the message digest is converted into first data; based on the initial core mapping, an inverse mapping of the initial core mapping is obtained; based on the inverse mapping, the first data is converted into second data; based on the second data and the first polynomial mapping, third data corresponding to the second data is obtained by solving the third polynomial mapping; based on the second data and the third data, a data pair is constructed; based on the first reversible linear mapping, a fourth reversible linear mapping is obtained; based on the fourth reversible linear mapping, the data pair is converted into digital signature information; wherein, the third reversible linear mapping is the inverse mapping of the second reversible linear mapping; the fourth reversible linear mapping is the inverse mapping of the first reversible linear mapping.
[0029] To achieve the above-mentioned and other related purposes, the present invention provides a digital signature verification method in a third aspect, comprising:
[0030] After obtaining the message data, extract the message digest in the message data; obtain the digital signature in the message data, use the pre-constructed public key to perform verification calculation on the digital signature, and obtain verification information corresponding to the digital signature; compare the verification information with the message digest, and when the two are the same, determine that the digital signature is a valid digital signature; wherein the public key is obtained based on any of the public key construction methods described above.
[0031] To achieve the above-mentioned purpose and other related purposes, the present invention also provides a terminal, including: a processor and a memory; the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory, so that the terminal executes any of the above-mentioned methods for constructing a public key, or any of the above-mentioned methods for generating a digital signature, or any of the above-mentioned methods for verifying a digital signature.
[0032] In addition, the present invention also provides a computer storage medium, which stores a computer program. When the computer program is executed by a processor, it implements any of the methods for constructing a public key as described above, or any of the methods for generating a digital signature as described above, or any of the methods for verifying a digital signature as described above.
[0033] As described above, the public key construction method, digital signature generation / verification method, terminal and computer storage medium provided by the present invention construct interference factors and decoding factors, and superimpose the constructed interference factors and decoding factors with the initial core mapping that is easy to invert in turn, so as to encrypt and strengthen the initial core mapping based on the interference factors, and use the decoding factors to eliminate the interference factors after obtaining the solution information to achieve fast decoding of the initial core mapping, so that the constructed public key contains the randomness of the random polynomial mapping, that is, the public key is difficult to solve directly, and the mixed polynomial mapping is difficult to separate, so that it is difficult to recover the private key based on the public key; and, when the solution information is obtained, the public key can also be quickly decoded based on the decoding factors, so that while ensuring efficient decoding, a digital signature with higher encryption strength can be generated to resist quantum solution and improve the security of data information, effectively taking into account the security and practicality of the digital signature. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 Shown is a schematic diagram of a process of constructing a public key according to an embodiment of the present invention;
[0035] Figure 2 Shown is a schematic diagram of a method for constructing a new core mapping in an embodiment of the present invention;
[0036] Figure 3 Shown is a flow chart of a method for generating a digital signature in an embodiment of the present application;
[0037] Figure 4 Shown is a schematic diagram of the implementation principle of step S20 in an embodiment of the present application;
[0038] Figure 5 It is a schematic diagram of the process of executing step S20 in one embodiment of the present application;
[0039] Figure 6 Shown is a flow chart of a digital signature verification method described in an embodiment of the present application;
[0040] Figure 7 Shown is a schematic diagram of the implementation principle of step S2 in an embodiment of the present application;
[0041] Figure 8 Shown is a schematic diagram of the structure of the terminal described in the embodiment of the present application. DETAILED DESCRIPTION
[0042] The following describes the embodiments of the present invention by specific examples, and those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict.
[0043] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present invention, and thus the drawings only show components related to the present invention rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed arbitrarily, and the component layout may also be more complicated.
[0044] In order to better understand the technical content of the present invention, the following terms will be explained below;
[0045] 1) Public key, which is a public encryption key used to encrypt data or verify signatures;
[0046] 2) Private key, which is a confidential decryption key containing trapdoor information and is used to decrypt or generate digital signatures
[0047] In the existing technology, when facing quantum computing, the digital signature constructed by the existing digital signature method is often easily cracked; in this regard, although a public key cryptography based on multivariate polynomials (Multivariate Public Key Cryptography, MPKC) has been proposed; specifically, the public key construction method of the multivariate public key cryptography system is usually to first construct a reversible high-dimensional mapping F as a secret core mapping, and then randomly select a secret and reversible linear mapping (or affine) to mask the core mapping to generate a public key, that is, the generated public key is P=S F T; where S and T are reversible linear mappings (or affine); however, in the existing mainstream construction methods, the core mapping F is a quadratic polynomial function, and is usually a deformation based on several known large classes of reversible quadratic polynomial mappings that can be efficiently solved. However, most of the existing mainstream schemes have been cracked, resulting in the public key constructed by the existing construction method being unable to resist known attack methods, thereby greatly reducing security.
[0048] Furthermore, although there are some construction methods in the prior art that directly combine two quadratic polynomial mappings to obtain a quadratic polynomial mapping through function composition, however, this trapdoor scheme of directly combining two quadratic polynomial mappings is easily decomposed in reverse, resulting in poor security.
[0049] Based on this, in order to better solve the above technical problems, that is, to provide a method that can not only resist quantum computing but also achieve a suitable size of public key data while ensuring security, so as to facilitate rapid processing and solving, the present invention provides a public key construction method in a first aspect, which is used to construct a public key structure that can be used to resist quantum solving.
[0050] The public key is a polynomial of at least degree 4, that is, the public key is an n-degree polynomial, where n is an integer not less than 4.
[0051] To facilitate understanding of the technical solution of the present application, the following embodiments take a 4th-order polynomial (n equals 4) as an example to explain in detail the implementation method and principle of the method of the present application; it should be noted that for polynomials greater than 4, such as 5th-order polynomials or 6th-order polynomials, etc., those skilled in the art can easily understand the implementation method of the present invention in the case of polynomials greater than 4th order based on the contents disclosed in the present application.
[0052] See also Figure 1 , showing a schematic diagram of the process of the public key construction method provided in the embodiment of the present application; Figure 1 As shown, the method comprises the following steps:
[0053] S100, randomly selecting a reversible 4th-order polynomial mapping as the initial core mapping;
[0054] The polynomial mapping is a 4th-order polynomial mapping that can be efficiently solved on a finite field, which is:
[0055]
[0056] in, F ( x ) is a polynomial of degree not greater than 4; GF ( q ) means including q elements, GF ( q ) n represents an n-dimensional vector space on the finite field; in this embodiment, n is equal to 4.
[0057] It should be noted that the efficiently solvable function is used to characterize the polynomial mapping, and an efficient solution method exists for the mapping function, that is, the mapping function can be solved within a millisecond time range; and, in the present application, there is a sufficient number of such efficiently solvable fourth-order polynomial mappings on known finite fields.
[0058] Specifically, two different mapping functions are randomly selected from several types of reversible quadratic polynomial mappings that can be efficiently solved; after the two different mapping functions are combined, a reversible quadratic polynomial mapping is obtained; and the quadratic polynomial mapping is used as the initial core mapping.
[0059] It should be noted that when n is greater than 4, that is, when the initial core mapping is a polynomial mapping greater than degree 4, its construction method is:
[0060] A first mapping function and a second mapping function are randomly selected from several types of reversible polynomial mappings of degree 2 or above that can be efficiently solved; the sum of the polynomial degrees of the first mapping function and the second mapping function is equal to n; after compounding two different mapping functions, a reversible n-degree polynomial mapping is obtained as the initial core mapping.
[0061] S200, obtaining a pre-constructed interference factor and a decoding factor; combining the pre-constructed interference factor and the decoding factor to obtain a combined factor; performing security enhancement on the initial core mapping through the combined factor to obtain an enhanced new core mapping;
[0062] The interference factor is a mapping item used to perform interference encryption on the initial core mapping to prevent the initial core mapping from being easily cracked;
[0063] The decoding factor can be solved to obtain a value identical to the mapping item corresponding to the interference factor when the solution information is input, thereby eliminating the interference factor.
[0064] In one embodiment of the present application, the interference factor includes a first polynomial mapping and a second polynomial mapping; the decoding factor includes a third polynomial mapping;
[0065] Wherein, the first polynomial mapping, the second polynomial mapping and the third polynomial mapping are all polynomial mappings of degree greater than or equal to 2;
[0066] The third polynomial mapping and the second polynomial mapping have the same polynomial degree, and the polynomial degree and the degree of the first polynomial mapping satisfy: the sum of the two is equal to n;
[0067] Furthermore, the third polynomial mapping also satisfies: when the solution information is input, the same value as the first polynomial mapping can be solved; in the present application, the solution information is the value obtained after solving the message digest using the private key.
[0068] Specifically, the new core mapping is constructed as follows: Figure 2 As shown, it includes the following sub-steps:
[0069] Randomly construct the first polynomial mapping and the second polynomial mapping, both of which are second-degree polynomial mappings over a finite field, namely:
[0070]
[0071]
[0072] in, is the first polynomial mapping; is a second polynomial mapping; each dimensional component in the first polynomial mapping and the second polynomial mapping is a polynomial of at most degree 2, and the coefficients in the polynomial mapping are randomly selected coefficients;
[0073] Compounding the first polynomial mapping and the second polynomial mapping to obtain a first compound polynomial, , ; in, is the input value; The symbol for compound operations.
[0074] Constructing a third polynomial mapping for which an efficient solution method exists, the third polynomial mapping is a quadratic polynomial mapping over a finite field, and satisfies that when solution information is input, the same value as the first polynomial mapping can be solved, thereby offsetting the interference factor;
[0075] The second polynomial mapping is combined with the third polynomial mapping to obtain a second composite polynomial, which is , ;in, is the input value; and the The input value mapped with the first polynomial are the same value.
[0076] After obtaining the first composite polynomial and the second composite polynomial, a polynomial obtained by subtracting the first composite polynomial from the second composite polynomial is mapped as the combination factor, which is:
[0077]
[0078] like Figure 2 As shown, the initial core mapping is superimposed with the combination factor to obtain a new core mapping after security enhancement, which is:
[0079]
[0080] in, G New core mapping for security enhancements; F is the initial core mapping; is the first polynomial mapping; is the second polynomial mapping; is the third polynomial mapping.
[0081] It should be noted that, in this embodiment, the first composite polynomial and the second composite polynomial are both 4th-order polynomial mappings; when the initial core mapping is a polynomial mapping greater than 4th order (n is greater than 4), the first composite polynomial and the second composite polynomial are also polynomial mappings greater than 4th order; illustratively, when n is 6, that is, when the initial core mapping is a 6th-order polynomial mapping, the first polynomial mapping is a 2nd degree polynomial mapping, the second polynomial mapping is a 4th degree polynomial mapping, the third polynomial mapping It is a second-order polynomial mapping, and the first composite polynomial and the second composite polynomial are both sixth-order polynomial mappings.
[0082] In some other embodiments, the combination factor may also be obtained in the following ways, including:
[0083] The polynomial mapping obtained by subtracting the first polynomial mapping from the third polynomial mapping is used as the third composite polynomial mapping; the polynomial mapping obtained by composite the second polynomial mapping with the third composite polynomial is used as the combination factor:
[0084]
[0085] Then the initial core mapping is superimposed with the combination factor to obtain a new core mapping after security enhancement, which is:
[0086]
[0087] in, G New core mapping for security enhancements; F is the initial core mapping; is the first polynomial mapping; is the second polynomial mapping; is the third polynomial mapping.
[0088] In order to enable the third polynomial mapping to be quickly solved when the solution information is input; in a specific embodiment, the third polynomial mapping is:
[0089]
[0090] And for any n-dimensional vector over a finite field and , can be solved using the third polynomial mapping to obtain the solved result vector , that is, satisfying:
[0091]
[0092] That is, by transforming the n-dimensional vector and Input into the above formula, and the result vector can be efficiently solved. .
[0093] In a specific implementation, the third polynomial mapping is a reversible quadratic polynomial mapping over a finite field, which is:
[0094] ,
[0095] Then set .
[0096] In another specific implementation, the third polynomial mapping is a triangular map, which is:
[0097]
[0098] in, , , each is a random quadratic polynomial.
[0099] S300, using a reversible linear mapping, masking the new core mapping to obtain a public key.
[0100] Specifically, the first reversible linear mapping and the second reversible linear mapping are randomly selected, that is:
[0101] ;
[0102]
[0103] Among them, L 1 is the first reversible linear map over a finite field, L 2 is the second reversible linear map over a finite field;
[0104] After obtaining the first reversible linear mapping and the second reversible linear mapping, the first reversible linear mapping, the new core mapping, and the second reversible linear mapping are sequentially compounded to obtain a third compound mapping; and the third compound mapping is used as a public key.
[0105] More specifically, using L 1 and L 2 Mask G and calculate the 4th-order polynomial mapping, which is:
[0106]
[0107] Take P as the public key; while obtaining the public key, take the first reversible linear mapping, the second reversible linear mapping, the initial core mapping, the first polynomial mapping, the second polynomial mapping and the third polynomial mapping as the private key, that is, A private key for confidentiality.
[0108] The public key construction method provided in the present application, when receiving the input solution information, solves the third polynomial mapping to obtain the same value as the first polynomial mapping, thereby eliminating the interference factor, that is, achieving and The two cancel each other out to restore the 4th-order polynomial mapping F, so that the public key can be quickly solved while the initial core mapping in the public key is strongly encrypted.
[0109] In order to solve the technical problems existing in the prior art, the present application also provides a method for generating a digital signature, which is used to generate a digital signature with higher encryption strength for the message data to be transmitted, aiming to resist quantum computing to ensure the integrity of the message data during the transmission process and the accuracy of identity authentication.
[0110] See also Figure 3 , showing a flow chart of the method for generating a digital signature provided by the present invention in one embodiment; Figure 3 As shown, the generation method includes the following steps:
[0111] S10, after acquiring the message data, extracting a message digest from the message data;
[0112] Specifically, the information extraction method is used to perform information extraction on received message data (such as files, etc.) to obtain summary information contained in the message data.
[0113] In a specific embodiment, a hash algorithm is used to extract a hash value from the message data, and the extracted hash value is used as summary information corresponding to the message data.
[0114] The summary information is an n-dimensional vector in a finite field. ,Right now:
[0115] z=(z 1 ,z 2 ,……z m )
[0116] =H(z)
[0117] =(z 1 ,z 2 ,……z m )
[0118] Where z is the message data; 1 , z 2 , z 3 ……z m are the characters in the message data respectively; H( ) is a hash algorithm; For summary information.
[0119] S20, converting the message digest based on the private key corresponding to the public key to convert the message digest into a digital signature;
[0120] Among them, the private key is adapted to the public key constructed in the above embodiment, and is a set including the first reversible linear mapping, the second reversible linear mapping, the initial core mapping, the first polynomial mapping, the second polynomial mapping and the third polynomial mapping.
[0121] In a specific embodiment, the implementation principle of step S20 is as follows: Figure 4 As shown, the specific execution steps of step S20 are described in detail in combination with the implementation principle; Figure 5 As shown, step S20 includes the following sub-steps:
[0122] S21, based on the second reversible linear mapping, obtaining a third reversible linear mapping; based on the third reversible linear mapping, converting the message digest into first data;
[0123] Wherein, the first data is a finite field n-dimensional vector on .
[0124] The third reversible linear mapping is an inverse mapping of the second reversible linear mapping.
[0125] Specifically, the second reversible linear mapping is inverted to obtain the third linear mapping; the message digest is converted using the third linear mapping to obtain the first data, which is:
[0126]
[0127] In the formula, is the third linear mapping, is the second linear mapping The inverse mapping of is the first data.
[0128] S22, based on the initial core mapping, obtaining an inverse mapping of the initial core mapping; based on the inverse mapping, converting the first data into second data;
[0129] Wherein, the second data is a finite field An n-dimensional vector on , that is:
[0130] x=(x 1 ,x 2 ,……,x n )
[0131] Specifically, the initial core mapping is inverted to obtain the inverse mapping F corresponding to the initial core mapping -1 ; Input the first data into the inverse mapping F -1 , and obtain a solution result corresponding to the first data; and use the solution result as the second data, that is:
[0132]
[0133] In the formula, F -1 is the inverse mapping of the initial core mapping; is the first data; x is the second data.
[0134] S23, based on the second data and the first polynomial mapping, performing a calculation through the third polynomial mapping to obtain third data corresponding to the second data;
[0135] Wherein, the third data is a finite field On the other hand, another n-dimensional vector different from the second data is:
[0136]
[0137] Specifically, the second data is used as the input of the third polynomial mapping, and the first polynomial mapping is used as the output of the third polynomial mapping; by solving the third polynomial mapping, the corresponding third data is obtained, which is:
[0138]
[0139] In the formula, is the third polynomial mapping; is the second data; is the third data; wherein,
[0140] =( 1 , 2 ,……, n )
[0141] =( 1 , 2 ,……, n ).
[0142] It should be noted that, in this embodiment, and The combination of is the solution information in the above embodiment.
[0143] S24, constructing a data pair based on the second data and the third data; obtaining a fourth reversible linear mapping based on the first reversible linear mapping; and converting the data pair into digital signature information based on the fourth reversible linear mapping.
[0144] Wherein, the fourth reversible linear mapping is an inverse mapping of the first reversible linear mapping;
[0145] The digital signature information is a 2n-dimensional vector on a finite field, that is, The vector in .
[0146] Specifically, the second data and the third data are combined to obtain a set of data pairs as an intermediate result;
[0147] For the first reversible linear mapping Inverse, and use the obtained inverse mapping as the fourth linear mapping, that is, :
[0148] The data pair is input into the fourth linear mapping, so as to perform conversion on the data pair using the fourth linear mapping, and the conversion result is used as the digital signature information, that is:
[0149]
[0150] Where (x, y) is a data pair; is the fourth linear mapping; For message digest The digital signature information is
[0151] =( 1 , 2 ,……, n ).
[0152] Based on the same inventive concept, the present application also provides a digital signature verification method for verifying a digital signature to ensure that the digital signature is a valid signature.
[0153] In this embodiment, the digital signature verification method is as follows: Figure 6 As shown, including:
[0154] S1, after acquiring message data, extracting a message digest from the message data;
[0155] Specifically, the information extraction method is used to perform information extraction on the acquired message data (such as a file, etc.) to obtain a message digest contained in the message data.
[0156] In a specific embodiment, a hash algorithm is used to extract a hash value from the message data, and the extracted hash value is used as a message digest corresponding to the message data.
[0157] The message digest is an n-dimensional vector in a finite field. ,Right now:
[0158] z=(z 1 , z 2 , z 3 ……z m )
[0159] =H(z)
[0160] Where z is the message data; 1 , z 2 , z 3 ……z m are the characters in the message data respectively; H( ) is the hash algorithm; Is the message digest.
[0161] S2, obtaining a digital signature in the message data, performing a verification calculation on the digital signature using a pre-built public key, and obtaining verification information corresponding to the digital signature;
[0162] Wherein, the public key is a public key constructed based on the public key construction method provided in the above embodiment;
[0163] Specifically, obtain the digital signature corresponding to the message data ; To obtain the digital signature and the message digest Then, use the public key to sign the digital Perform calculations and obtain calculation results The implementation principle of this step is as follows Figure 7 As shown, the specific implementation process is the reverse execution process of step S20, which will not be repeated here.
[0164] S3, comparing the verification information with the message digest, and when the two are the same, determining that the digital signature is a valid digital signature.
[0165] Specifically, the calculation result obtained in step S2 is With the message digest A comparison is performed; if the two are the same, the digital signature is characterized as a valid digital signature; otherwise, the digital signature is characterized as an invalid digital signature.
[0166] Based on the same technical concept, the public key construction method, the digital signature generation method, or the digital signature verification method provided in the above embodiments of the present invention can be implemented on the terminal side or the server side.
[0167] See also Figure 8 , is an optional hardware structure diagram of an electronic terminal 700 provided in an embodiment of the present invention. The electronic terminal 700 may be a live broadcast machine, a camera, a mobile phone, a computer device, a tablet device, a personal digital processing device, a factory background processing device, etc. that integrates photo / video functions. The electronic terminal 700 includes: at least one processor 701, a memory 702, at least one network interface 704 and a user interface 706. The various components in the device are coupled together through a bus system 705. It can be understood that the bus system 705 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 705 also includes a power bus, a control bus and a status signal bus.
[0168] The user interface 706 may include a display, a keyboard, a mouse, a trackball, a click gun, keys, buttons, a touch pad or a touch screen.
[0169] It is understood that the memory 702 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), which is used as an external cache. By way of exemplary but not limiting explanation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM). The memory described in the embodiments of the present invention is intended to include but is not limited to these and any other suitable categories of memory.
[0170] The memory 702 in the embodiment of the present invention is used to store various categories of data to support the operation of the electronic terminal 700. Examples of these data include: any executable program used to operate on the electronic terminal 700, such as an operating system 7021 and an application 7022; the operating system 7021 includes various system programs, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks. The application 7022 can include various applications, such as a media player (MediaPlayer), a browser (Browser), etc., for implementing various application services. The public key construction method, the digital signature generation method, or the digital signature verification method implementing the embodiment of the present invention can be included in the application 7022.
[0171] The method disclosed in the above embodiment of the present invention can be applied to the processor 701, or implemented by the processor 701. The processor 701 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit in the processor 701 or the instruction in the form of software. The above processor 701 may be a general processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor 701 can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiment of the present invention. The general processor 701 may be a microprocessor or any conventional processor, etc. In combination with the steps of the accessory optimization method provided in the embodiment of the present invention, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in a memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
[0172] In an exemplary embodiment, the electronic terminal 700 may be implemented by one or more application specific integrated circuits (ASIC), DSP, programmable logic device (PLD), complex programmable logic device (CPLD) to execute the aforementioned method.
[0173] An embodiment of the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when called by a processor, implements the public key construction method as described above, or the digital signature generation method as described above, or the steps in the digital signature verification method as described above.
[0174] Among them, the computer-readable storage medium can be a tangible device that can hold and store instructions used by the instruction execution device. The computer-readable storage medium can be, for example, (but not limited to) an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the above. More specific examples of computer-readable storage media (a non-exhaustive list) include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, and a mechanical encoding device.
[0175] The computer-readable program described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. A network adapter card or a network interface in each computing / processing device receives computer-readable program instructions from the network and forwards the computer-readable program instructions to a computer-readable storage medium stored in each computing / processing device.
[0176] In summary, the public key construction method, digital signature generation / verification method, terminal and computer storage medium provided by the present application, by mixing the easily inverted polynomial function and the random polynomial mapping in a clever way, the constructed public key contains the randomness of the random polynomial mapping, that is, the public key is difficult to solve directly; and the mixed polynomial function and the polynomial mapping are difficult to be separated, so that it is difficult to recover the private key based on the public key. Generate a digital signature with higher encryption strength to resist quantum solution and improve the security of data information.
[0177] The above embodiments are merely illustrative of the principles and effects of the present invention, and are not intended to limit the present invention. Anyone familiar with the art may modify or alter the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or alterations made by a person of ordinary skill in the art without departing from the spirit and technical concept disclosed by the present invention shall still be covered by the claims of the present invention.
Claims
1. A method for constructing a public key, characterized in that: include: Randomly select an initial core mapping; wherein the initial core mapping is an n-order polynomial mapping that can be solved on a finite field; wherein n is an integer not less than 4; The pre-constructed interference factor and the decoding factor are combined to obtain the combined factor; the initial core mapping is security enhanced by the combined factor to obtain an enhanced new core mapping; the interference factor is a mapping item used to perform interference encryption on the initial core mapping; the decoding factor is used to offset the interference factor when inputting the solution information; The new core mapping is masked using a reversible linear mapping to obtain a public key.
2. The method for constructing a public key according to claim 1, characterized in that: The interference factor includes a first polynomial mapping and a second polynomial mapping, and the decoding factor includes a third polynomial mapping; wherein, The first polynomial mapping, the second polynomial mapping and the third polynomial mapping are all polynomial mappings of degree greater than or equal to 2; The third polynomial mapping and the first polynomial mapping have the same polynomial degree, and the third polynomial mapping and the second polynomial mapping satisfy: the sum of the two is equal to n; and, The third polynomial mapping also satisfies that: when the solution information is input, the same value as the first polynomial mapping can be solved.
3. The method for constructing a public key according to claim 2, characterized in that: The method for obtaining the combination factor includes: Compounding the first polynomial mapping and the second polynomial mapping to obtain a first compound polynomial mapping; Combining the second polynomial mapping with the third polynomial mapping to obtain a second composite polynomial mapping; Mapping a polynomial obtained by subtracting the first composite polynomial from the second composite polynomial as the combining factor; or comprising: subtracting the first polynomial mapping from the third polynomial mapping to obtain a polynomial mapping as a third composite polynomial mapping; The polynomial mapping obtained by combining the second polynomial mapping and the third composite polynomial is used as the combining factor.
4. The method for constructing a public key according to claim 1, characterized in that: The implementation method of performing security enhancement on the initial core mapping by combining factors includes: The initial core mapping is superimposed with the combination factor to obtain a new core mapping after security enhancement, which is: ; Or the new core mapping after the security enhancement is: ; Wherein, G is the new core mapping; is the first polynomial mapping; is the second polynomial mapping; is the third polynomial mapping; is the initial core mapping.
5. The method for constructing a public key according to claim 2, characterized in that: The third polynomial mapping is: ; And for any n-dimensional vector over a finite field and , can be solved using the third polynomial mapping to obtain ,satisfy: ; in, and are any n-dimensional vectors on the finite field, y is a mapping based on the third polynomial and The result vector obtained after solving.
6. The method for constructing a public key according to claim 1, characterized in that: The implementation method of masking the new core mapping by using a reversible linear mapping includes: Randomly selecting a first reversible linear mapping and a second reversible linear mapping; The first reversible linear mapping, the new core mapping, and the second reversible linear mapping are sequentially compounded.
7. A method for generating a digital signature, characterized in that: include: After acquiring the message data, extracting a message digest from the message data; Based on the private key corresponding to the public key, convert the message digest into a digital signature; Wherein, the public key is obtained based on the public key construction method described in any one of claims 1 to 6.
8. The method for generating a digital signature according to claim 7, characterized in that: include: The private key is a set including a first reversible linear mapping, a second reversible linear mapping, an initial core mapping, a first polynomial mapping, a second polynomial mapping and a third polynomial mapping; The converting of the message digest based on the private key corresponding to the public key includes: Based on the second reversible linear mapping, obtaining a third reversible linear mapping; based on the third reversible linear mapping, converting the message digest into first data; Based on the initial core mapping, obtaining an inverse mapping of the initial core mapping; based on the inverse mapping, converting the first data into second data; Based on the second data and the first polynomial mapping, obtaining third data corresponding to the second data by solving the third polynomial mapping; Based on the second data and the third data, construct a data pair; based on the first reversible linear mapping, obtain a fourth reversible linear mapping; based on the fourth reversible linear mapping, convert the data pair into digital signature information; The third reversible linear mapping is the inverse mapping of the second reversible linear mapping; and the fourth reversible linear mapping is the inverse mapping of the first reversible linear mapping.
9. A method for verifying a digital signature, characterized in that: include: After acquiring the message data, extracting a message digest from the message data; Obtaining a digital signature in the message data, performing a verification calculation on the digital signature using a pre-built public key, and obtaining verification information corresponding to the digital signature; The verification information is compared with the message digest, and when the two are the same, the digital signature is determined to be a valid digital signature; wherein, The public key is obtained based on the public key construction method described in any one of claims 1 to 6.
10. A terminal, characterized in that: include: Processor and memory; The memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory, so that the terminal executes the method for constructing a public key as described in any one of claims 1 to 6, or the method for generating a digital signature as described in claim 7 or 8, or the method for verifying a digital signature as described in claim 9.
11. A computer storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, it implements the method for constructing a public key as described in any one of claims 1 to 6, or the method for generating a digital signature as described in claim 7 or 8, or the method for verifying a digital signature as described in claim 9.
Citation Information
Patent Citations
Improved multi-variable public key cryptogram encryption and decryption scheme
CN103501227A
Efficient communication information processing method
CN107786662A
Automatic resolving system for universal optimal control problem
CN118348780A
Electronic signature method and device
CN118827045A
Efficient Multivariate Signature Generation
US20130129090A1