Digital Signature Generation / Verification Method, Terminal, and Medium
By constructing a combination of 4-order polynomial public keys and reversible linear mappings, the security of digital signatures is enhanced, the easy-to-solve problem of the existing technology under quantum computing is solved, and high-encrypted and strong signature generation against quantum solutions is achieved.
Patent Information
- Application Number
- CN202510460776.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-04-14
AI Technical Summary
Existing digital signature technology has poor security when facing quantum computing, is easy to be cracked, and cannot effectively resist quantum attacks.
By constructing a public key construction method, the initial core mapping, interference factor and decoding factor are used to perform security enhancement, and the reversible linear mapping is used to mask it, a public key of at least 4-order polynomials is generated, and a digital signature is generated in combination with the reversible linear mapping.
The generated digital signature has higher encryption strength when facing quantum solutions, which improves the security and practicality of data information, and ensures the security and effectiveness of digital signatures.
Smart Images

Figure CN119995901B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of digital encryption, and particularly relates to a method for constructing a public key, a method for generating / verifying a digital signature, a terminal, and a computer storage medium. Background Art
[0002] Digital signature (also known as public key digital signature), as an identity authentication method based on public key encryption technology, generates a unique and forgery-proof string to verify the authenticity of the information sender and the integrity of the data. Its core relies on asymmetric encryption technology and digital digest technology, and usually includes two complementary operation processes: signature generation and verification.
[0003] Existing mainstream digital signature technologies are usually based on RSA (the problem of factoring large integers) and elliptic curve cryptography (ECC, the discrete logarithm problem on elliptic curves). However, due to the rapid development of quantum computing, quantum attack methods such as Shor's algorithm can theoretically break the above classical encryption systems in polynomial time. As a result, the digital signatures generated based on the existing technologies are easily cracked when facing quantum computing, which greatly reduces the security of the digital signature system and even faces severe challenges.
[0004] Therefore, how to construct a digital signature that can resist quantum computing attacks has become an urgent technical problem in this technical field. Summary of the Invention
[0005] In view of the above-mentioned disadvantages in the prior art, the purpose of the present invention is to provide a method for constructing a public key, a method for generating / verifying a digital signature, a terminal, and a computer storage medium, which are used to solve the problem of poor security of the existing digital signature system.
[0006] To achieve the above object and other related objects, the present invention provides a method for constructing a public key in the first aspect, including:
[0007] Randomly select an initial core mapping; wherein, the initial core mapping is an n-degree polynomial mapping that can be solved over a finite field; wherein, n is an integer not less than 4; combine a pre-constructed interference factor and a decoding factor to obtain a combined factor; use the combined factor to enhance the security of the initial core mapping to obtain an enhanced new core mapping; the interference factor is a mapping term used to perform interference encryption on the initial core mapping; the decoding factor is used to cancel the interference factor when inputting the solution information; use an invertible linear mapping to mask the new core mapping to obtain a public key.
[0008] In one embodiment of the present application, the interference factor includes a first polynomial mapping and a second polynomial mapping, and the decoding factor includes a third polynomial mapping; wherein, the first polynomial mapping, the second polynomial mapping, and the third polynomial mapping are all polynomial mappings of degree greater than or equal to 2; the degree of the third polynomial mapping is the same as that of the first polynomial mapping, and the sum of this degree and the degree of the second polynomial mapping satisfies: the sum of the two is equal to n; and, the third polynomial mapping further satisfies: when the solution information is input, it can calculate the same value as the first polynomial mapping.
[0009] In one embodiment of the present application, the method for obtaining the combination factor includes:
[0010] Compound the first polynomial mapping and the second polynomial mapping to obtain a first compound polynomial mapping; compound the second polynomial mapping and the third polynomial mapping to obtain a second compound polynomial mapping; use the polynomial mapping obtained by subtracting the second compound polynomial from the first compound polynomial as the combination factor; or include: use the polynomial mapping obtained by subtracting the third polynomial mapping from the first polynomial mapping as a third compound polynomial mapping; use the polynomial mapping obtained by compounding the second polynomial mapping and the third compound polynomial mapping as the combination factor.
[0011] In one embodiment of the present application, the implementation manner of enhancing the security of the initial core mapping through the combination factor includes:
[0012] Superimpose the initial core mapping and the combination factor to obtain a new core mapping after security enhancement, which is:
[0013]
[0014] Or the new core mapping after security enhancement is:
[0015]
[0016] Wherein, G is the new core mapping; is the first polynomial mapping; is the second polynomial mapping; is the third polynomial mapping; is the initial core mapping.
[0017] In one embodiment of the present application, the third polynomial mapping is:
[0018]
[0019] And for any n-dimensional vector over the finite field and can both use the third polynomial mapping to calculate and obtain satisfying:
[0020]
[0021] wherein, and are respectively any n-dimensional vectors over a finite field, and y is the result vector obtained by calculating and based on the third polynomial mapping.
[0022] In an embodiment of the present application, the implementation manner of masking the new core mapping by using an invertible linear mapping includes:
[0023] Randomly select a first invertible linear mapping and a second invertible linear mapping; sequentially compose the first invertible linear mapping with the new core mapping and the second invertible linear mapping.
[0024] To achieve the above object and other related objects, the present invention provides a method for generating a digital signature in a second aspect, including:
[0025] After obtaining message data, extract the message digest in the message data; based on the private key corresponding to the public key, perform a conversion on the message digest to convert the message digest into a digital signature; wherein, the public key is obtained by using the construction method of the public key as described above arbitrarily.
[0026] In an embodiment of the present application, the private key is a set including a first invertible linear mapping, a second invertible linear mapping, an initial core mapping, a first polynomial mapping, a second polynomial mapping, and a third polynomial mapping;
[0027] The performing a conversion on the message digest based on the private key corresponding to the public key includes:
[0028] Based on the second reversible linear mapping, obtain a third reversible linear mapping; based on the third reversible linear mapping, convert the message digest into first data; based on the initial core mapping, obtain the inverse mapping of the initial core mapping; based on this inverse mapping, convert the first data into second data; based on the second data and the first polynomial mapping, by solving the third polynomial mapping, obtain third data corresponding to the second data; based on the second data and the third data, construct a data pair; based on the first reversible linear mapping, obtain a fourth reversible linear mapping; based on the fourth reversible linear mapping, convert the data pair into digital signature information; wherein, the third reversible linear mapping is the inverse mapping of the second reversible linear mapping; the fourth reversible linear mapping is the inverse mapping of the first reversible linear mapping.
[0029] To achieve the above object and other related objects, the present invention provides a method for verifying a digital signature in a third aspect, including:
[0030] After obtaining message data, extract the message digest in the message data; obtain the digital signature in the message data, use a pre-constructed public key to perform a verification calculation on the digital signature, and obtain verification information corresponding to the digital signature; compare the verification information with the message digest, and when the two are the same, determine that the digital signature is a valid digital signature; wherein, the public key is obtained based on the construction method of the public key as described above in any one.
[0031] To achieve the above object and other related objects, the present invention further provides a terminal, including: a processor and a memory; the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory, so that the terminal executes the construction method of the public key as described above in any one, or the digital signature generation method as described above in any one, or the digital signature verification method as described above.
[0032] In addition, the present invention further provides a computer storage medium, the computer storage medium stores a computer program, and when the computer program is executed by a processor, it implements the construction method of the public key as described above in any one, or the digital signature generation method as described above in any one, or the digital signature verification method as described above.
[0033] As described above, the method for constructing the public key, the method for generating / verifying the digital signature, the terminal, and the computer storage medium provided by the present invention construct an interference factor and a decoding factor, and sequentially superimpose the constructed interference factor and decoding factor on the initial core mapping that is easy to invert, so as to encrypt and strengthen the initial core mapping based on the interference factor, and use the decoding factor to eliminate the interference factor after obtaining the solution information to achieve fast decoding of the initial core mapping. As a result, the constructed public key contains the randomness of the random polynomial mapping, that is, it is difficult to directly solve the public key, and it is difficult to separate the mixed polynomial mapping, so that it is difficult to recover the private key based on the public key; and when obtaining the solution information, fast decoding of the public key can also be achieved based on the decoding factor, so that while ensuring efficient decoding, a digital signature with higher encryption strength can be generated to resist quantum solution and improve the security of data information, effectively taking into account both the security and practicality of the digital signature. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 It shows a schematic flow chart of the method for constructing the public key in an embodiment of the present invention;
[0035] Figure 2 It shows a schematic diagram of the construction method of the new core mapping in an embodiment of the present invention;
[0036] Figure 3 It shows a schematic flow chart of the method for generating the digital signature in an embodiment of the present application;
[0037] Figure 4 It shows a schematic diagram of the implementation principle of step S20 in an embodiment of the present application;
[0038] Figure 5 It shows a schematic flow chart when step S20 is executed in an embodiment of the present application;
[0039] Figure 6 It shows a schematic flow chart of the method for verifying the digital signature in an embodiment of the present application;
[0040] Figure 7 It shows a schematic diagram of the implementation principle of step S2 in an embodiment of the present application;
[0041] Figure 8 It shows a schematic diagram of the structure of the terminal in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] The following uses specific concrete examples to illustrate the implementation manners of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0043] It should be noted that the illustrations provided in the following embodiments only schematically illustrate the basic concept of the present invention. Therefore, only the components related to the present invention are shown in the drawings, rather than being drawn according to the number, shape, and size of the components in actual implementation. The types, quantities, and proportions of the components in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.
[0044] To better understand the technical content of the present invention, the following terms will be explained;
[0045] 1) Public key, which is a publicly disclosed encryption key used to encrypt data or verify signatures;
[0046] 2) Private key, which is a confidential decryption key containing trapdoor information and is used to decrypt or generate digital signatures
[0047] In view of the prior art, when facing quantum computing, the digital signatures constructed by existing digital signature methods are often easily cracked; for this, although the public key cryptography based on multivariate polynomials (Multivariate Public Key Cryptography, MPKC) has been proposed currently; specifically, the public key construction method of the multivariate public key cryptosystem usually first constructs an invertible high-dimensional mapping F as the secret core mapping, and then randomly selects a secret and invertible linear mapping (or affine) to cover the core mapping to generate the public key, that is, the generated public key is P = S F T; where S and T are invertible linear mappings (or affine); however, in existing mainstream construction methods, the core mapping F is a quadratic polynomial function, and usually, it is deformed based on several known categories of invertible quadratic polynomial mappings that can be efficiently solved. However, most of the existing mainstream schemes have been cracked, resulting in the public keys constructed by the existing construction methods being unable to resist known attack means, and thus the security is greatly reduced.
[0048] In addition, although there are also some construction methods in the prior art that directly compound two quadratic polynomial mappings through function composition to obtain a quartic polynomial mapping; however, the trapdoor scheme of directly compounding two quadratic polynomial mappings is easily reversely decomposed, resulting in very poor security.
[0049] Based on this, to better solve the above technical problems, that is, to provide a method that can not only resist quantum computing, but also achieve a suitable size of public key data while ensuring security, so as to facilitate fast processing and solution, the present invention provides a method for constructing a public key in the first aspect, which is used to construct a public key structure that can be used to resist quantum solution.
[0050] Among them, the public key is a polynomial of at least 4 degrees or more, that is, the public key is an n-degree polynomial, and n is an integer not less than 4.
[0051] For the convenience of understanding the technical solution of the present application, the following embodiments take a 4-degree polynomial (n equals 4) as an example to elaborate in detail on the implementation method and principle of the method of the present application; it should be noted that for polynomials of more than 4 degrees, such as 5-degree polynomials or 6-degree polynomials, those skilled in the art can easily understand the implementation method of the present invention in the case of polynomials of more than 4 degrees based on the content disclosed in the present application.
[0052] Please refer to Figure 1 , which shows the schematic flowchart of the public key construction method provided in the embodiment of the present application; as Figure 1 shown, the method includes the following steps:
[0053] S100, randomly select a reversible 4-degree polynomial mapping as the initial core mapping;
[0054] Among them, the polynomial mapping is an efficiently solvable 4-degree polynomial mapping over a finite field, which is:
[0055]
[0056] Among them, F ( x ) each dimensional component is a polynomial of no more than 4 degrees; GF ( q ) represents a finite field containing q elements, GF ( q ) n represents the n-dimensional vector space over this finite field; in this embodiment, n equals 4.
[0057] It should be noted that the efficiently solvable is used to characterize that the polynomial mapping is a mapping function with an efficient solution method, that is, it can be solved within the time range of milliseconds; and, in the present application, there are a sufficient number of such efficiently solvable 4-degree polynomial mappings among the known polynomial mappings over finite fields.
[0058] Specifically, two different mapping functions are randomly selected from several classes of invertible quadratic polynomial mappings that can be efficiently solved; after the two different mapping functions are composed, an invertible quartic polynomial mapping is obtained; and this quartic polynomial mapping is used as the initial core mapping.
[0059] It should be noted that when n is greater than 4, that is, when the initial core mapping is a polynomial mapping of degree greater than 4, its construction method is as follows:
[0060] A first mapping function and a second mapping function are randomly selected from several classes of invertible polynomial mappings of degree greater than 2 that can be efficiently solved; the sum of the polynomial degrees of the first mapping function and the second mapping function is equal to n; after the two different mapping functions are composed, an invertible n-degree polynomial mapping is obtained as the initial core mapping.
[0061] S200, obtain the pre-constructed interference factor and decoding factor; combine the pre-constructed interference factor and decoding factor to obtain a combined factor; through this combined factor, perform security enhancement on the initial core mapping to obtain an enhanced new core mapping;
[0062] Among them, the interference factor is a mapping term used to perform interference encryption on the initial core mapping to prevent the initial core mapping from being easily cracked;
[0063] The decoding factor can calculate the same value as the mapping term corresponding to the interference factor when the input solution information is provided, thereby eliminating the interference factor.
[0064] In an embodiment of the present application, the interference factor includes a first polynomial mapping and a second polynomial mapping; the decoding factor includes a third polynomial mapping;
[0065] Among them, the first polynomial mapping, the second polynomial mapping, and the third polynomial mapping are all polynomial mappings of degree greater than or equal to 2;
[0066] The polynomial degree of the third polynomial mapping is the same as that of the second polynomial mapping, and the sum of this polynomial degree and the degree of the first polynomial mapping satisfies: the sum of the two is equal to n;
[0067] And, the third polynomial mapping also satisfies: it can calculate the same value as the first polynomial mapping when the input solution information is provided; in the present application, the solution information is the value obtained by calculating the message digest using the private key.
[0068] Specifically, the construction method of the new core mapping is as Figure 2 shown, including the following sub-steps:
[0069] Randomly construct a first polynomial mapping and a second polynomial mapping, both of which are quadratic polynomial mappings over a finite field, that is:
[0070]
[0071]
[0072] where is the first polynomial mapping; is the second polynomial mapping; each dimensional component in the first polynomial mapping and the second polynomial mapping is a polynomial of at most degree 2, and the coefficients in the polynomial mapping are randomly selected coefficients;
[0073] Composite the first polynomial mapping and the second polynomial mapping to obtain a first composite polynomial, , ; where is the input value; is the symbol of the composite operation.
[0074] Construct a third polynomial mapping with an efficient solution method, the third polynomial mapping is a quadratic polynomial mapping over a finite field, and satisfies that when inputting the solution information, it can calculate the same value as the first polynomial mapping, so as to cancel the interference factor;
[0075] Composite the second polynomial mapping and the third polynomial mapping to obtain a second composite polynomial, which is , ; where is the input value; and this is the same value as the input value of the first polynomial mapping.
[0076] After obtaining the first composite polynomial and the second composite polynomial, take the polynomial mapping after subtracting the second composite polynomial from the first composite polynomial as the combined factor, which is:
[0077]
[0078] As Figure 2 shown, superimpose the initial core mapping with the combined factor to obtain a new core mapping after security enhancement, which is:
[0079]
[0080] where G is the new core mapping after security enhancement; F is the initial core mapping; is the first polynomial mapping; is the second polynomial mapping; is the third polynomial mapping.
[0081] It should be noted that in this embodiment, both the first composite polynomial and the second composite polynomial are 4th-degree polynomial mappings; when the initial core mapping is a polynomial mapping of degree greater than 4 (n > 4), then both the first composite polynomial and the second composite polynomial are also polynomial mappings of degree greater than 4; for example, when n is 6, that is, when the initial core mapping is a 6th-degree polynomial mapping, the first polynomial mapping is a 2nd-degree polynomial mapping, the second polynomial mapping is a 4th-degree polynomial mapping, the third polynomial mapping is a 2nd-degree polynomial mapping, and both the first composite polynomial and the second composite polynomial are 6th-degree polynomial mappings.
[0082] In some other embodiments, the combined factor can also be obtained in the following manner, including:
[0083] Taking the polynomial mapping obtained by subtracting the third polynomial mapping from the first polynomial mapping as the third composite polynomial mapping; taking the polynomial mapping obtained by composing the second polynomial mapping with the third composite polynomial as the combined factor, which is:
[0084]
[0085] Then, the initial core mapping is superimposed with the combined factor to obtain a new core mapping after security enhancement, which is:
[0086]
[0087] where, G is the new core mapping after security enhancement; F is the initial core mapping; is the first polynomial mapping; is the second polynomial mapping; is the third polynomial mapping.
[0088] In order to enable the third polynomial mapping to perform fast calculation when inputting the solution information; in a specific embodiment, the third polynomial mapping is:
[0089]
[0090] And for any n-dimensional vector and over the finite field, the third polynomial mapping can be used to perform the calculation to obtain the result vector of the calculation , that is, satisfying:
[0091]
[0092] That is, by substituting the n-dimensional vector and into the above formula, the result vector can be efficiently calculated.
[0093] In a specific embodiment, the third polynomial mapping is an invertible quadratic polynomial mapping over a finite field, which is:
[0094] ,
[0095] Then set .
[0096] In another specific embodiment, the third polynomial mapping is a triangular map, which is:
[0097]
[0098] Wherein, , , and each is a random quadratic polynomial.
[0099] S300. Use an invertible linear mapping to mask the new core mapping to obtain a public key.
[0100] Specifically, randomly select a first invertible linear mapping and a second invertible linear mapping, that is:
[0101] ;
[0102]
[0103] Wherein, L1 is the first invertible linear mapping over the finite field, and L2 is the second invertible linear mapping over the finite field;
[0104] After obtaining the first invertible linear mapping and the second invertible linear mapping, sequentially compose the first invertible linear mapping with the new core mapping and the second invertible linear mapping to obtain a third composite mapping; use this third composite mapping as the public key.
[0105] More specifically, use L1 and L2 to mask G and calculate a quartic polynomial mapping, which is:
[0106]
[0107] Take P as the publicly disclosed public key; when obtaining the public key, take the first invertible linear mapping, the second invertible linear mapping, the initial core mapping, the first polynomial mapping, the second polynomial mapping, and the third polynomial mapping together as the private key, that is, take as the private key for confidentiality.
[0108] For the public key construction method provided by this application, when receiving the input solution information, by resolving the third polynomial mapping, a value identical to the first polynomial mapping can be obtained, thereby eliminating the interference factor, that is, achieving and the mutual cancellation of both, to restore and obtain the quartic polynomial mapping F, so that while strengthening the encryption of the initial core mapping in the public key, fast resolution of the public key can be achieved.
[0109] To solve the technical problems existing in the prior art, this application also provides a method for generating a digital signature, which is used to generate a digital signature with higher encryption strength for the message data to be transmitted, aiming to counter quantum resolution to ensure the integrity of the message data during transmission and the accuracy of identity authentication.
[0110] Please refer to Figure 3 , which shows a schematic flowchart of the method for generating the digital signature provided by the present invention in an embodiment; as Figure 3 shown, this generation method includes the following steps:
[0111] S10, after obtaining the message data, extract the message digest in the message data;
[0112] Specifically, using the information extraction method, perform information extraction on the received message data (such as files, etc.) to obtain the digest information contained in the message data.
[0113] In a specific embodiment, use the hash algorithm to extract the hash value of the message data, and take the extracted hash value as the digest information corresponding to the message data.
[0114] Among them, the digest information is an n-dimensional vector in a finite field , that is:
[0115] z = (z1, z2, …… z m )
[0116] = H(z)
[0117] = (z1 , z2 , …… z m )
[0118] In the formula, z is the message data; z1, z2, z3... z m are respectively each character in the message data; H( ) is the hash algorithm; is the digest information.
[0119] S20. Based on the private key corresponding to the public key, perform a transformation on the message digest to convert the message digest into a digital signature;
[0120] Wherein, the private key is adapted to the public key constructed in the above embodiment and is a set including the first reversible linear mapping, the second reversible linear mapping, the initial core mapping, the first polynomial mapping, the second polynomial mapping, and the third polynomial mapping.
[0121] In a specific embodiment, the implementation principle of step S20 is as Figure 4 shown. In combination with this implementation principle, the specific execution steps of this step S20 are elaborated; as Figure 5 shown, step S20 includes the following sub-steps:
[0122] S21. Based on the second reversible linear mapping, obtain a third reversible linear mapping; based on the third reversible linear mapping, convert the message digest into first data;
[0123] Wherein, the first data is an n-dimensional vector on the finite field .
[0124] The third reversible linear mapping is the inverse mapping of the second reversible linear mapping.
[0125] Specifically, take the inverse of the second reversible linear mapping to obtain the third linear mapping; use the third linear mapping to perform a transformation process on the message digest to obtain the first data, which is:
[0126]
[0127] In the formula, is the third linear mapping, which is the inverse mapping of the second linear mapping ; is the first data.
[0128] S22. Based on the initial core mapping, obtain the inverse mapping of the initial core mapping; based on this inverse mapping, convert the first data into second data;
[0129] Wherein, the second data is an n-dimensional vector on the finite field , that is:
[0130] x = (x1, x2, ……, x n )
[0131] Specifically, invert the initial core mapping to obtain the inverse mapping F -1 corresponding to the initial core mapping; input the first data into this inverse mapping F -1 for calculation to obtain the calculation result corresponding to the first data; use this calculation result as the second data, that is:
[0132]
[0133] In the formula, F -1 is the inverse mapping of the initial core mapping; is the first data; x is the second data.
[0134] S23. Based on the second data and the first polynomial mapping, perform calculation through the third polynomial mapping to obtain the third data corresponding to the second data;
[0135] wherein, the third data is another n-dimensional vector different from the second data on the finite field , and is:
[0136]
[0137] Specifically, use the second data as the input of the third polynomial mapping and the first polynomial mapping as the output of the third polynomial mapping; perform calculation on the third polynomial mapping to obtain the corresponding third data, which is:
[0138]
[0139] In the formula, is the third polynomial mapping; is the second data; is the third data; wherein,
[0140] = ( 1, 2, ……, n )
[0141] = ( 1, 2, ……, n ).
[0142] It should be noted that in this embodiment, and The combination is the solution information in the above embodiments.
[0143] S24, based on the second data and the third data, construct them into a data pair; based on the first invertible linear mapping, obtain a fourth invertible linear mapping; based on the fourth invertible linear mapping, convert the data pair into digital signature information.
[0144] Among them, the fourth invertible linear mapping is the inverse mapping of the first invertible linear mapping;
[0145] The digital signature information is a 2n-dimensional vector over a finite field, that is, a vector belonging to in the vector.
[0146] Specifically, combine the second data and the third data to obtain a set of data pairs as intermediate results;
[0147] Find the inverse of the first invertible linear mapping and use the obtained inverse mapping as the fourth linear mapping, that is :
[0148] Input the data pair into the fourth linear mapping to perform a conversion on the data pair using this fourth linear mapping, and use the conversion result as the digital signature information, that is:
[0149]
[0150] In the formula, (x, y) is the data pair; is the fourth linear mapping; is the digital signature information corresponding to the message digest , and is
[0151] = ( 1 , 2 , ……, n ).
[0152] Based on the same inventive concept, the present application also provides a method for verifying a digital signature, which is used to verify the digital signature to ensure that the digital signature is a valid signature.
[0153] In this embodiment, the method for verifying the digital signature is as Figure 6 shown, and includes:
[0154] S1, after obtaining the message data, extract the message digest in the message data;
[0155] Specifically, an information extraction method is used to perform information extraction on the obtained message data (such as files, etc.) to obtain the message digest contained in the message data.
[0156] In a specific embodiment, a hash algorithm is used to extract the hash value of the message data, and the extracted hash value is used as the message digest corresponding to the message data.
[0157] Wherein, the message digest is an n-dimensional vector within a finite field , that is:
[0158] z = (z1, z2, z3... z m )
[0159] = H(z)
[0160] In the formula, z is the message data; z1, z2, z3... z m are respectively the characters in the message data; H( ) is the hash algorithm; is the message digest.
[0161] S2. Obtain the digital signature in the message data, and use the pre-constructed public key to perform verification calculation on the digital signature to obtain the verification information corresponding to the digital signature;
[0162] Wherein, the public key is the public key constructed based on the public key construction method provided in the above embodiment;
[0163] Specifically, obtain the digital signature corresponding to the message data ; after obtaining the digital signature and the message digest , use the public key to perform calculation on the digital signature to obtain the calculation result , the implementation principle of this step is as Figure 7 shown, and the specific implementation process is the reverse execution process of step S20, which will not be elaborated here.
[0164] S3. Compare the verification information with the message digest. When the two are the same, it is determined that the digital signature is a valid digital signature.
[0165] Specifically, compare the calculation result obtained in step S2 with the message digest ; if the two are the same, it indicates that the digital signature is a valid digital signature; otherwise, it indicates that the digital signature is an invalid digital signature.
[0166] Based on the same inventive concept, the public key construction method, the digital signature generation method, or the digital signature verification method provided in the above embodiments of the present invention can be implemented on the terminal side or the server side.
[0167] Please refer to Figure 8 , which is an optional hardware structure schematic diagram of the electronic terminal 700 provided in the embodiments of the present invention. The electronic terminal 700 may be a live broadcast machine, a camera, a mobile phone, a computer device, a tablet device, a personal digital processing device, a factory background processing device, etc. that integrates photo-taking / camera functions. The electronic terminal 700 includes: at least one processor 701, a memory 702, at least one network interface 704, and a user interface 706. Each component in the device is coupled together through a bus system 705. It can be understood that the bus system 705 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 705 also includes a power bus, a control bus, and a status signal bus.
[0168] Among them, the user interface 706 may include a display, a keyboard, a mouse, a trackball, a click gun, a button, a button, a touchpad, or a touch screen, etc.
[0169] It can be understood that the memory 702 may be a volatile memory or a non-volatile memory, and may also include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM, Read Only Memory), a programmable read-only memory (PROM, Programmable Read-Only Memory), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM, Static Random Access Memory), synchronous static random access memory (SSRAM, Synchronous Static Random Access Memory). The memory described in the embodiments of the present invention is intended to include but not be limited to these and any other suitable categories of memory.
[0170] The memory 702 in the embodiments of the present invention is used to store various types of data to support the operation of the electronic terminal 700. Examples of such data include: any executable programs for operations on the electronic terminal 700, such as the operating system 7021 and application programs 7022; the operating system 7021 contains various system programs, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks. The application programs 7022 may include various application programs, such as a MediaPlayer, a Browser, etc., for implementing various application services. The method for constructing the public key, or the method for generating the digital signature, or the method for verifying the digital signature in the embodiments of the present invention may be included in the application programs 7022.
[0171] The methods disclosed in the above embodiments of the present invention can be applied to the processor 701 or implemented by the processor 701. The processor 701 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor 701 or instructions in software form. The above-mentioned processor 701 may be a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 701 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor 701 may be a microprocessor or any conventional processor, etc. Combining the steps of the accessory optimization method provided in the embodiments of the present invention can be directly embodied as being completed by the hardware decoding processor, or by a combination of the hardware and software modules in the decoding processor. The software module may be located in a storage medium, and this storage medium is located in the memory. The processor reads the information in the memory and combines its hardware to complete the steps of the foregoing method.
[0172] In an exemplary embodiment, the electronic terminal 700 may be one or more application-specific integrated circuits (ASICs, Application Specific Integrated Circuit), DSPs, programmable logic devices (PLDs, ProgrammableLogic Device), complex programmable logic devices (CPLDs, Complex Programmable LogicDevice) for executing the foregoing methods.
[0173] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the program is called by a processor, it implements the public key construction method described above, or implements the digital signature generation method described above, or implements the steps in the digital signature verification method described above.
[0174] Among them, a computer-readable storage medium can be a tangible device that can hold and store instructions used by an instruction execution device. A computer-readable storage medium can be, for example (but not limited to), an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the above. More specific examples (non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memories), static random access memories (SRAM), portable compact disk read-only memories (CD-ROMs), digital versatile disks (DVDs), memory sticks, floppy disks, and mechanical encoding devices.
[0175] The computer-readable program described herein can be downloaded from the computer-readable storage medium to various computing / processing devices, or downloaded to an external computer or external storage device through a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network adapter or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.
[0176] In summary, the public key construction method, digital signature generation / verification method, terminal, and computer storage medium provided by this application mix an easily invertible polynomial function and a random polynomial mapping in a clever way, so that the constructed public key contains the randomness of the random polynomial mapping, making the public key difficult to directly solve; and making it difficult to separate the mixed polynomial function from the polynomial mapping, thus making it difficult to recover the private key based on the public key. Digital signatures with higher encryption strength can be generated to counter quantum computing and improve the security of data information.
[0177] The above embodiments are only illustrative of the principles and effects of the present invention, and are not used to limit the present invention. Any person familiar with this technology can modify or change the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or changes made by those with ordinary knowledge in the technical field without departing from the spirit and technical ideas disclosed by the present invention should still be covered by the claims of the present invention.
Claims
1. A method for constructing a public key, characterized in that, Including: Randomly select an initial core mapping; wherein, the initial core mapping is an n-degree polynomial mapping that can be solved over a finite field; where n is an integer not less than 4; Combine the pre-constructed interference factor and decoding factor to obtain a combined factor; enhance the security of the initial core mapping by superimposing the combined factor to obtain an enhanced new core mapping; the interference factor is a mapping term used for interference encryption of the initial core mapping, including a first polynomial mapping and a second polynomial mapping; the decoding factor is used to cancel the interference factor when inputting the solution information, including a third polynomial mapping; Use an invertible linear mapping to mask the new core mapping to obtain a public key; The obtaining method of the combined factor includes: Compound the first polynomial mapping and the second polynomial mapping to obtain a first compound polynomial mapping; compound the second polynomial mapping and the third polynomial mapping to obtain a second compound polynomial mapping; use the polynomial mapping obtained by subtracting the second compound polynomial from the first compound polynomial as the combined factor; wherein, the first polynomial mapping, the second polynomial mapping, and the third polynomial mapping are all polynomial mappings of degree greater than or equal to 2; and the degree of the third polynomial mapping is the same as that of the first polynomial mapping, and the sum of this degree and the degree of the second polynomial mapping is equal to n; and, the third polynomial mapping also satisfies: when inputting the solution information, it can calculate the same value as the first polynomial mapping.
2. The method for constructing a public key according to claim 1, wherein The obtaining method of the combined factor can also be replaced by: Use the polynomial mapping obtained by subtracting the first polynomial mapping from the third polynomial mapping as a third compound polynomial mapping; Use the polynomial mapping obtained by compounding the second polynomial mapping and the third compound polynomial mapping as the combined factor.
3. The method for constructing a public key according to claim 1, wherein The enhanced new core mapping after security enhancement is: G = F + R2 ° R1 - R2 ° T Or the enhanced new core mapping after security enhancement is: G = F + R2 ° (R1 - T) Wherein, G is the new core mapping; R1 is the first polynomial mapping; R2 is the first polynomial mapping; T is the third polynomial mapping; F is the initial core mapping; ° is the compound operation of the mapping.
4. The method for constructing a public key according to claim 1, characterized in that The third polynomial mapping is: T(x,y) ∶ GF(q) n × GF(q) n → GF(q) n And for any n-dimensional vectors x and u over the finite field, the third polynomial mapping can be used to calculate and obtain y, satisfying: u = T(x, y) Wherein, x and u are respectively any n-dimensional vectors over the finite field, and y is the result vector obtained by calculating x and u based on the third polynomial mapping.
5. The method for constructing a public key according to claim 1, wherein The implementation method of using an invertible linear mapping to mask the new core mapping includes: Randomly select a first invertible linear mapping and a second invertible linear mapping; Compound the first invertible linear mapping, the new core mapping, and the second invertible linear mapping in sequence.
6. A method for generating a digital signature, characterized in that, Including: After obtaining the message data, extract the message digest in the message data; Perform a transformation on the message digest based on the private key corresponding to the public key, and transform the message digest into a digital signature; Wherein, the public key is obtained by the construction method of the public key according to any one of claims 1 to 5.
7. The method for generating a digital signature according to claim 6, wherein Including: The private key is a set including a first reversible linear mapping, a second reversible linear mapping, an initial core mapping, a first polynomial mapping, a second polynomial mapping, and a third polynomial mapping; The performing a transformation on the message digest based on the private key corresponding to the public key includes: Obtain a third reversible linear mapping based on the second reversible linear mapping; based on the third reversible linear mapping, transform the message digest into first data; Obtain the inverse mapping of the initial core mapping based on the initial core mapping; based on the inverse mapping, transform the first data into second data; Based on the second data and the first polynomial mapping, obtain third data corresponding to the second data by solving the third polynomial mapping; Construct a data pair based on the second data and the third data; obtain a fourth reversible linear mapping based on the first reversible linear mapping; based on the fourth reversible linear mapping, transform the data pair into digital signature information; Wherein, the third reversible linear mapping is the inverse mapping of the second reversible linear mapping; the fourth reversible linear mapping is the inverse mapping of the first reversible linear mapping.
8. A method for verifying a digital signature, characterized in that, Including: After obtaining the message data, extract the message digest in the message data; Obtain the digital signature in the message data, perform a verification calculation on the digital signature using the pre-constructed public key, and obtain verification information corresponding to the digital signature; Compare the verification information with the message digest, and when the two are the same, determine that the digital signature is a valid digital signature; wherein, The public key is obtained by the construction method of the public key according to any one of claims 1 to 5.
9. A terminal, characterized in that, Including: A processor and a memory; The memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory, so that the terminal executes the construction method of the public key according to any one of claims 1 to 5, or the generation method of the digital signature according to claim 6 or 7, or the verification method of the digital signature according to claim 8.
10. A computer storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the construction method of the public key according to any one of claims 1 to 5, or the generation method of the digital signature according to claim 6 or 7, or the verification method of the digital signature according to claim 8.
Citation Information
Patent Citations
Improved multi-variable public key cryptogram encryption and decryption scheme
CN103501227A
Electronic signature method and device
CN118827045A