Anti-quantum electronic signature generation method, anti-quantum electronic signature verification method and anti-quantum electronic signature verification device
By improving the oil space structure in the unbalanced oil and vinegar algorithm, quantum-resistant electronic signatures are generated, which solves the problems of excessive public key size and insufficient security in the prior art, and achieves efficient and secure electronic signature generation.
Patent Information
- Application Number
- CN202311568650.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-22
- Publication Date
- 2025-05-23
AI Technical Summary
In the prior art, electronic signature algorithms such as RSA and ECC are unsafe under quantum computer attack resistance, and the public key size of the multivariate public key cryptographic signature algorithm is too large, which affects efficiency.
A quantum-resistant electronic signature generation method is proposed, and a public key and private key are generated based on the target unbalanced oil and vinegar algorithm. By improving the size of the oil space, changing the center map, reducing the public key size, and maintaining high security.
It effectively reduces the size of the public key and improves security, making the attack scheme based on the existing unbalanced oil and vinegar signature algorithm invalid and has the characteristics of resisting quantum computers.
Smart Images

Figure CN120034318A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to a quantum-resistant electronic signature generation method, verification method and device. Background Art
[0002] A quantum computer is a physical device that follows the laws of quantum mechanics to perform high-speed mathematical and logical operations, store and process quantum information. Under the attack of quantum computers, many commonly used cryptographic algorithms such as the asymmetric algorithm RSA (Ron Rivest, Adi Shamir, Leonard Adleman) and elliptic curve cryptography (ECC) are not safe, and the importance of research on quantum-resistant cryptography is increasing day by day.
[0003] In electronic signatures, multivariate public key cryptography (MPKC) signature algorithms started relatively early in post-quantum cryptography, and corresponding research has been carried out extensively. The main improvements are concentrated on the construction and selection of central mappings, such as Hidden Field Equations (HFE) signatures, Unbalanced Oil and Vinegar (UOV) signatures, Rainbow signatures, and other signature algorithms. However, although these signature algorithms have improved security to a certain extent, they also have the problem of excessively large public key sizes. Summary of the invention
[0004] In view of this, the present disclosure proposes a quantum-resistant electronic signature generation method, an electronic signature verification method, an electronic signature generation device, an electronic signature verification device, an electronic device, and a computer-readable storage medium.
[0005] According to one aspect of the present disclosure, a method for generating a quantum-resistant electronic signature is provided, which is applied to a terminal for generating a signature, and the method includes:
[0006] Generate a public key and a private key based on a target unbalanced oil and vinegar algorithm; wherein the variables in the target unbalanced oil and vinegar algorithm include a plurality of first oil variables, a plurality of second oil variables and a plurality of vinegar variables; the number of the first oil variables is greater than the number of the second oil variables;
[0007] Get the target message;
[0008] Signing the target message using the private key to generate a target signature;
[0009] The target message, the target signature and the public key are sent to a terminal for verifying the signature, so that the terminal for verifying the signature verifies the target signature using the target message and the public key.
[0010] In one possible implementation, the multivariate quadratic polynomial corresponding to the central mapping of the target unbalanced oil-vinegar algorithm includes a product term of the oil variable and the vinegar variable, a product term of the oil variable and the oil variable, and a product term of the vinegar variable and the vinegar variable, wherein the oil variable includes the first oil variable and the second oil variable.
[0011] In a possible implementation, the generating of a private key based on a target unbalanced oil-vinegar algorithm includes:
[0012] Randomly generate a first matrix and a second matrix, wherein the number of rows of the first matrix and the number of columns of the second matrix are the same as the number of variables in the target unbalanced oil and vinegar algorithm, and the number of columns of the first matrix and the number of rows of the second matrix are the same as the number of the second oil variables;
[0013] Randomly generate a preset number of third matrices, wherein the third matrix is a circulant matrix, and the number of rows and the number of columns of the third matrix are the same as the number of the second oil variables, and the preset number is the number of the first oil variables;
[0014] Randomly generate a preset number of fourth matrices, wherein the number of rows and the number of rows of the fourth matrix are the same as the number of variables in the target unbalanced oil and vinegar algorithm;
[0015] A reversible matrix is randomly generated; and the first matrix, the second matrix, the preset number of third matrices, the preset number of fourth matrices and the reversible matrix are used as the private key.
[0016] In a possible implementation, the generating of a public key based on a target unbalanced oil-vinegar algorithm includes:
[0017] constructing a center map according to the first matrix, the second matrix, the preset number of third matrices, and the preset number of fourth matrices;
[0018] A composite mapping of the reversible matrix and the central mapping is used as the public key.
[0019] In a possible implementation manner, constructing a center mapping according to the first matrix, the second matrix, the preset number of third matrices, and the preset number of fourth matrices includes:
[0020] Multiplying the first matrix, the target third matrix and the second matrix to determine a product corresponding to the target third matrix; wherein the target third matrix is any matrix among the preset number of third matrices;
[0021] The product corresponding to the target third matrix and the target fourth matrix are summed to obtain a target multivariate quadratic polynomial corresponding to the central mapping; wherein the target fourth matrix is a matrix corresponding to the target third matrix among the preset number of fourth matrices.
[0022] In a possible implementation manner, the using the private key to sign the target message to generate a target signature includes:
[0023] Processing the target message to generate a corresponding hash value;
[0024] Randomly generate a first vector and a second vector, wherein the number of elements in the first vector is the same as the number of the second oil variables; the number of elements in the second vector is the same as the number of the vinegar variables;
[0025] Assign each element in the second vector to the vinegar variable to obtain the value of the vinegar variable;
[0026] Establishing a system of equations according to the first vector, the first matrix, the second matrix, the preset number of third matrices, the preset number of fourth matrices, and the hash value;
[0027] Substituting the value of the vinegar variable into the equation group and solving it to obtain the value of the oil variable;
[0028] The target signature is generated according to the value of the oil variable, the value of the vinegar variable and the reversible matrix.
[0029] According to another aspect of the present disclosure, a quantum-resistant electronic signature verification method is provided, which is applied to a terminal for verifying a signature, and the method includes:
[0030] Receive a target message, a target signature and a public key; wherein the public key is generated based on a target unbalanced oil-vinegar algorithm, and variables in the target unbalanced oil-vinegar algorithm include a plurality of first oil variables, a plurality of second oil variables and a plurality of vinegar variables; the number of the first oil variables is greater than the number of the second oil variables;
[0031] Performing a calculation using the public key and the target message to obtain a calculation result;
[0032] The operation result is compared with the target signature. If the operation result is the same as the target signature, the verification result is verification passed; otherwise, the verification result is verification failed.
[0033] In one possible implementation, the multivariate quadratic polynomial corresponding to the central mapping of the target unbalanced oil-vinegar algorithm includes a product term of the oil variable and the vinegar variable, a product term of the oil variable and the oil variable, and a product term of the vinegar variable and the vinegar variable, wherein the oil variable includes the first oil variable and the second oil variable.
[0034] According to another aspect of the present disclosure, a quantum-resistant electronic signature generation device is provided, which is applied to a terminal for generating a signature, and the device includes:
[0035] A public-private key pair module, used to generate a public key and a private key based on a target unbalanced oil-vinegar algorithm; wherein the variables in the target unbalanced oil-vinegar algorithm include a plurality of first oil variables, a plurality of second oil variables and a plurality of vinegar variables; the number of the first oil variables is greater than the number of the second oil variables;
[0036] An acquisition module is used to acquire target messages;
[0037] A signature module, used to sign the target message using the private key to generate a target signature;
[0038] The sending module is used to send the target message, the target signature and the public key to the terminal for verifying the signature, so that the terminal for verifying the signature verifies the target signature using the target message and the public key.
[0039] In one possible implementation, the multivariate quadratic polynomial corresponding to the central mapping of the target unbalanced oil-vinegar algorithm includes a product term of the oil variable and the vinegar variable, a product term of the oil variable and the oil variable, and a product term of the vinegar variable and the vinegar variable, wherein the oil variable includes the first oil variable and the second oil variable.
[0040] In a possible implementation, the public-private key pair module is also used to: randomly generate a first matrix and a second matrix, wherein the number of rows of the first matrix and the number of columns of the second matrix are the same as the number of variables in the target unbalanced oil and vinegar algorithm, and the number of columns of the first matrix and the number of rows of the second matrix are the same as the number of the second oil variables; randomly generate a preset number of third matrices, wherein the third matrix is a circulant matrix, and the number of rows and columns of the third matrix are the same as the number of the second oil variables, and the preset number is the number of the first oil variables; randomly generate a preset number of fourth matrices, wherein the number of rows and the number of rows of the fourth matrix are the same as the number of variables in the target unbalanced oil and vinegar algorithm; randomly generate a reversible matrix; and use the first matrix, the second matrix, the preset number of third matrices, the preset number of fourth matrices and the reversible matrix as the private key.
[0041] In a possible implementation, the public-private key pair module is further used to: construct a central mapping based on the first matrix, the second matrix, the preset number of third matrices and the preset number of fourth matrices; and use the composite mapping of the reversible matrix and the central mapping as the public key.
[0042] In a possible implementation, the public-private key pair module is further used to: multiply the first matrix, the target third matrix and the second matrix to determine the product corresponding to the target third matrix; wherein the target third matrix is any matrix among the preset number of third matrices; sum the product corresponding to the target third matrix and the target fourth matrix to obtain the target multivariate quadratic polynomial corresponding to the central mapping; wherein the target fourth matrix is a matrix among the preset number of fourth matrices corresponding to the target third matrix.
[0043] In a possible implementation, the signature module is further used to: process the target message to generate a corresponding hash value; randomly generate a first vector and a second vector, wherein the number of elements in the first vector is the same as the number of the second oil variable; the number of elements in the second vector is the same as the number of the vinegar variable; assign each element in the second vector to the vinegar variable to obtain the value of the vinegar variable; establish a system of equations based on the first vector, the first matrix, the second matrix, the preset number of third matrices, the preset number of fourth matrices and the hash value; substitute the value of the vinegar variable into the system of equations for solving to obtain the value of the oil variable; generate the target signature based on the value of the oil variable, the value of the vinegar variable and the reversible matrix.
[0044] According to another aspect of the present disclosure, a quantum-resistant electronic signature verification device is provided, which is applied to a terminal for verifying a signature, and the device includes:
[0045] a receiving module, configured to receive a target message, a target signature and a public key; wherein the public key is generated based on a target unbalanced oil-vinegar algorithm, wherein variables in the target unbalanced oil-vinegar algorithm include a plurality of first oil variables, a plurality of second oil variables and a plurality of vinegar variables; and the number of the first oil variables is greater than the number of the second oil variables;
[0046] A calculation module, used to perform calculation using the public key and the target message to obtain a calculation result;
[0047] The verification module is used to compare the operation result with the target signature. If the operation result is the same as the target signature, the verification result is verification passed; otherwise, the verification result is verification failed.
[0048] In one possible implementation, the multivariate quadratic polynomial corresponding to the central mapping of the target unbalanced oil-vinegar algorithm includes a product term of the oil variable and the vinegar variable, a product term of the oil variable and the oil variable, and a product term of the vinegar variable and the vinegar variable, wherein the oil variable includes the first oil variable and the second oil variable.
[0049] According to another aspect of the present disclosure, an electronic device is provided, comprising: a processor; a memory for storing processor executable instructions; wherein the processor is configured to implement the above-mentioned quantum-resistant electronic signature generation method or quantum-resistant electronic signature verification method when executing the instructions stored in the memory.
[0050] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which computer program instructions are stored, wherein the computer program instructions, when executed by a processor, implement the above-mentioned quantum-resistant electronic signature generation method or quantum-resistant electronic signature verification method.
[0051] According to another aspect of the present disclosure, a computer program product is provided, including a computer-readable code, or a non-volatile computer-readable storage medium carrying the computer-readable code. When the computer-readable code runs in a processor of an electronic device, the processor in the electronic device executes the above-mentioned quantum-resistant electronic signature generation method or quantum-resistant electronic signature verification method.
[0052] Through various aspects of the embodiments of the present disclosure, on the basis of the existing unbalanced oil-vinegar signature algorithm, by improving the size of the oil space, the center mapping in the existing unbalanced oil-vinegar signature algorithm is transformed, and the variables in the improved target unbalanced oil-vinegar algorithm include multiple first oil variables, multiple second oil variables and multiple vinegar variables. The target unbalanced oil-vinegar algorithm no longer has the same oil space as the existing unbalanced oil-vinegar signature algorithm, so that the attack schemes designed based on the oil space structure in the existing unbalanced oil-vinegar signature algorithm are invalid, and the size of the public key generated under the oil space is small; in addition, the target unbalanced oil-vinegar algorithm is used to generate a public key based on the target unbalanced oil-vinegar algorithm. The target message is signed with the private key to generate the target signature, and the target message, the target signature and the public key are sent to the terminal for verifying the signature, so that the terminal for verifying the signature verifies the target signature using the target message and the public key. The above process of generating the electronic signature and verifying the signature by the terminal for verifying the signature is still similar to the existing unbalanced oil and vinegar signature algorithm, and therefore still has the characteristics of short signature and high efficiency in the multivariate signature algorithm, and its security still depends on the solution of the multivariate equation group, and it is difficult to forge the signature, and it still has the characteristics of resisting quantum computers; thereby achieving higher security while reducing the size of the public key.
[0053] Further features and aspects of the present disclosure will become apparent from the following detailed description of exemplary embodiments with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate exemplary embodiments, features, and aspects of the disclosure and, together with the description, serve to explain the principles of the disclosure.
[0055] Figure 1 A schematic diagram of the structure of an electronic signature system according to an embodiment of the present disclosure is shown.
[0056] Figure 2 A flow chart of a method for generating an electronic signature according to an embodiment of the present disclosure is shown.
[0057] Figure 3 A flow chart of a method for generating a public key and a private key according to an embodiment of the present disclosure is shown.
[0058] Figure 4 A flow chart of a method for generating a target signature according to an embodiment of the present disclosure is shown.
[0059] Figure 5 A flowchart of a quantum-resistant electronic signature verification method according to an embodiment of the present disclosure is shown.
[0060] Figure 6 A structural diagram of a quantum-resistant electronic signature generation device according to an embodiment of the present disclosure is shown.
[0061] Figure 7 A structural diagram of a quantum-resistant electronic signature verification device according to an embodiment of the present disclosure is shown.
[0062] Figure 8 A schematic structural diagram of an electronic device according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0063] Various exemplary embodiments, features and aspects of the present disclosure will be described in detail below with reference to the accompanying drawings. The same reference numerals in the accompanying drawings represent elements with the same or similar functions. Although various aspects of the embodiments are shown in the accompanying drawings, the drawings are not necessarily drawn to scale unless otherwise specified.
[0064] References to "one embodiment" or "some embodiments" etc. described in this specification mean that one or more embodiments of the present disclosure include specific features, structures or characteristics described in conjunction with the embodiment. Thus, the phrases "exemplary", "in one embodiment", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0065] In the present disclosure, "at least one" means one or more, and "plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: including the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or plural.
[0066] In addition, in order to better illustrate the present disclosure, numerous specific details are given in the following specific embodiments. It should be understood by those skilled in the art that the present disclosure can also be implemented without certain specific details. In some examples, methods, means, components and circuits well known to those skilled in the art are not described in detail in order to highlight the subject matter of the present disclosure.
[0067] For ease of understanding, the following first provides an exemplary description of the application scenarios of the quantum-resistant electronic signature generation and verification scheme in the embodiments of the present disclosure.
[0068] Figure 1 FIG. 2 shows a schematic diagram of the structure of an electronic signature system according to an embodiment of the present disclosure. Figure 1As shown, the electronic signature system may include: a first terminal 10 and a second terminal 20; wherein the first terminal 10 may also be referred to as a terminal for generating electronic signatures. The first terminal 10 uses a signature algorithm to generate its own public key pair, namely a public key and a private key, wherein the private key is a key known only to the first terminal 10 and is used to sign the message to be sent; the public key is a key used to verify the electronic signature, and the public key can be publicly shared. The first terminal 10 can send its own public key to other terminals (including the second terminal 20). The first terminal 10 uses its own private key to process the message, generates an electronic signature, and then sends the electronic signature and the message to the second terminal 20; the second terminal 20 may also be referred to as a terminal for verifying the electronic signature. After receiving the electronic signature and message sent by the first terminal 10, the second terminal 20 uses the above-mentioned received public key of the first terminal 10 to process the electronic signature and the received message, and verify the validity of the electronic signature, thereby proving that the received electronic signature and message are sent by the first terminal 10.
[0069] Exemplarily, the electronic signature system may also include: a secure third-party institution 30, such as a Certificate Authority (CA), which is used to authenticate the legitimacy of the public key. For example, a certificate for the public key of the first terminal 10 may be generated to bind the first terminal 10 to its own public key. The first terminal 10 may send the authenticated public key to other terminals (including the second terminal 20); after receiving the message and the electronic signature, the second terminal 20 may process the electronic signature and the received message using the authenticated public key to verify the validity of the electronic signature.
[0070] Exemplarily, the message can be any type of data such as email, installation package, image, document, etc., which is not limited to this. Exemplarily, the first terminal 10 and the second terminal 20 can be electronic devices or components with data processing functions such as personal computers, smart phones, wearable devices, servers, processors, etc. As an example, the first terminal 10 is the computer of user A, and the second terminal 20 is the computer of user B. In the scenario where user A sends an email to user B, the email is the message; user A's computer generates a public-private key pair through a signature algorithm, and shares the authenticated public key with user B. User A's computer processes the email using the private key to generate an electronic signature, and then sends the email and the electronic signature together to user B's computer. After receiving the email and the electronic signature, user B's computer uses user A's public key to process the electronic signature and the email to verify the validity of the electronic signature. As another example, the first terminal 10 is the service provider's server, and the second terminal 20 is the computer of user C. In a scenario where user C needs to download a software installation package, the software installation package is the message; user C can download the service provider's software installation package online, and the server can generate a public-private key pair through a signature algorithm, and share the authenticated public key with user C. The server uses the private key to process the software installation package and generate an electronic signature, and then sends the software installation package and the electronic signature to user C's computer. After receiving the software installation package and the electronic signature, user C's computer uses the service provider's public key to process the electronic signature and the software installation package to verify the validity of the electronic signature.
[0071] The above-mentioned signature algorithm can be a multivariate public key cryptographic signature algorithm, which is a quantum-resistant public key cryptographic signature method. The private key is composed of a multivariate quadratic polynomial group that is easy to calculate the inverse and a reversible linear transformation that conceals its structure. The result of the multivariate quadratic polynomial group and the reversible linear transformation is used as the public key. The security of the multivariate public key cryptographic signature algorithm is based on the difficulty of solving non-deterministic polynomials (NP) in the multivariate quadratic polynomial (MQ) problem. In order to improve the security against quantum computers, signature algorithms such as hidden field equations, unbalanced vinegar, and rainbow have emerged. The improvements of these signature algorithms focus on the construction and selection of central mappings. These signature algorithms have the advantage of fast calculation speed, but also have the defect of too large public keys.
[0072] In order to solve the above technical problems, the embodiments of the present disclosure propose a quantum-resistant electronic signature generation method and verification method based on multivariables (see below for specific description), which can be used for electronic signatures that require high security and are resistant to quantum computers. Considering that the central mapping of the existing unbalanced oil-vinegar signature algorithm has oil space and vinegar space, once the oil space is known, finding a signature is a process of solving a set of linear equations, and many attack schemes are generated by finding the oil space. In the quantum-resistant electronic signature generation method and verification method provided by the embodiments of the present disclosure, on the basis of the unbalanced oil-vinegar signature algorithm, the oil space is improved to transform the central mapping in the original unbalanced oil-vinegar signature scheme, so that the attack scheme based on the existing unbalanced oil-vinegar structure is invalidated to improve its security, while achieving the purpose of reducing the size of the public key.
[0073] It should be noted that the above-mentioned application scenarios described in the embodiments of the present disclosure are intended to more clearly illustrate the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Ordinary technicians in this field can know that the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems when other similar or new scenarios emerge.
[0074] The following is a detailed description of the quantum-resistant electronic signature generation method provided by the embodiments of the present disclosure.
[0075] Figure 2 A flowchart of a method for generating an electronic signature according to an embodiment of the present disclosure is shown. The method can be applied to a terminal for generating an electronic signature, for example, Figure 1 The first terminal 10 in the electronic signature system, such as Figure 2 As shown, the method may include the following steps:
[0076] Step 201: Generate a public key and a private key based on a target unbalanced algorithm.
[0077] Among them, the variables in the target unbalanced oil and vinegar algorithm include multiple first oil variables, multiple second oil variables and multiple vinegar variables; the number of the first oil variables is greater than the number of the second oil variables.
[0078] The target unbalanced oil-vinegar algorithm is an improved algorithm based on the existing unbalanced oil-vinegar signature algorithm, wherein the space where the variables are located in the existing unbalanced oil-vinegar signature algorithm can be divided into the oil space where the oil variable is located and the vinegar space where the vinegar variable is located. In the embodiment of the present disclosure, the oil space is improved to divide the oil variable into a first oil variable and a second oil variable. Among them, the number of vinegar variables, the number of first oil variables and the number of second oil variables can be set according to demand. For example, the number of vinegar variables, the number of first oil variables and the number of second oil variables can be set by comprehensively considering factors such as safety and computing performance. Among them, the number of the first oil variable can be a larger value, the second oil variable can be a smaller value, and the number of vinegar variables can be not less than twice the number of the first oil variables. For example, the number of the first oil variable is 50, the number of the second oil variable is 3, and the number of vinegar variables is 110.
[0079] Exemplarily, a matrix for constructing a central mapping can be randomly generated based on a preset number of variables, the number of vinegar variables, and the number of oil variables (including the number of first oil variables and the number of second oil variables). The central mapping can be represented in the form of multiple multivariate quadratic polynomials, where the number of multivariate quadratic polynomials is the same as the number of first oil variables. After constructing the central mapping, the public key and the private key can be obtained.
[0080] Exemplarily, the multivariate quadratic polynomial corresponding to the center mapping of the target unbalanced oil-vinegar algorithm includes a product term of the oil variable and the vinegar variable, a product term of the oil variable and the oil variable, and a product term of the vinegar variable and the vinegar variable, wherein the oil variable includes the first oil variable and the second oil variable. This is different from the multivariate quadratic polynomial corresponding to the center mapping of the existing unbalanced oil-vinegar algorithm, which includes a product term of the oil variable and the vinegar variable, a product term of the vinegar variable and the vinegar variable, but does not include a product term of the oil variable and the oil variable. In the disclosed embodiment, the oil space is improved so that the multivariate quadratic polynomial can also include a product term of the oil variable and the oil variable, thereby effectively reducing the size of the public key.
[0081] Step 202: Get the target message.
[0082] The target message is the message to be signed.
[0083] Exemplarily, the terminal generating the electronic signature obtains the target message in response to the user's operation on the input interface of the terminal. For example, in response to the user's operation of writing an email through a computer interface, the computer can obtain the email.
[0084] Step 203: Use the private key to sign the target message to generate a target signature.
[0085] Step 204: Send the target message, the target signature, and the public key to the signature verification terminal, so that the signature verification terminal verifies the target signature using the target message and the public key.
[0086] Exemplarily, after generating the above-mentioned public key, the terminal that generates the signature can first send the public key to the authentication center. After the authentication center authenticates the legitimacy of the public key, it sends the authenticated public key to the terminal that verifies the signature. The terminal that verifies the signature saves the public key of the terminal that generates the signature locally; then, after generating the above-mentioned target signature, the terminal that generates the signature can send the target message and the target signature to the terminal that verifies the signature. After receiving the target message and the target signature, the terminal that verifies the signature can use the locally stored public key of the terminal that generates the signature to process the target signature and the target message to verify the validity of the target signature.
[0087] In this way, through the above steps 201-204, the terminal that generates the signature realizes the signing of the target message, and then the terminal that verifies the signature can verify the signature, thereby ensuring the security of the target message. For example, in a scenario where a user needs to download a software installation package from a server, since the software installation package may be tampered with by other persons, or other persons may impersonate the identity of the service provider; therefore, the server can generate a public key and a private key through the target unbalanced oil and vinegar algorithm, and share the authenticated public key with the user; then, the server processes the software installation package using the private key and generates an electronic signature to indicate that the software installation package comes from the service provider through the electronic signature, and the service provider sends the software installation package and the electronic signature to the user through the server, so that after the user receives the software installation package and the electronic signature, the user can verify that the electronic signature is the service provider's signature through the service provider's public key.
[0088] In the embodiments of the present disclosure, based on the existing unbalanced oil-vinegar signature algorithm, by improving the size of the oil space, the central mapping in the existing unbalanced oil-vinegar signature algorithm is transformed. The variables in the improved target unbalanced oil-vinegar algorithm include multiple first oil variables, multiple second oil variables, and multiple vinegar variables. There is no longer an oil space in the target unbalanced oil-vinegar algorithm that is the same as that in the existing unbalanced oil-vinegar signature algorithm, making all attack schemes designed based on the oil space structure in the existing unbalanced oil-vinegar signature algorithm ineffective, and the public key size generated under this oil space is smaller. In addition, the private key generated based on the target unbalanced oil-vinegar algorithm is used to sign the target message to generate a target signature, and the target message, the target signature, and the public key are sent to the terminal for signature verification, so that the terminal for signature verification uses the target message and the public key to verify the target signature. The process of generating the electronic signature and the terminal for signature verification to perform signature verification is still similar to that of the existing unbalanced oil-vinegar signature algorithm. Therefore, it still has the characteristics of short signatures and high efficiency in the multi-variable signature algorithm. Its security still depends on the problem of solving multi-variable equations, and it is difficult to forge signatures, and it still has the characteristic of resisting quantum computers; thus, it has higher security while reducing the public key size.
[0089] The following describes the specific process of generating the public key and the private key based on the target unbalanced oil-vinegar algorithm in step 201 above.
[0090] Figure 3 The flowchart of a method for generating a public key and a private key according to an embodiment of the present disclosure is shown, as Figure 3 shown, the method may include the following steps:
[0091] Step 301, randomly generate a first matrix and a second matrix, where the number of rows of the first matrix and the number of columns of the second matrix are both the same as the number of variables in the target unbalanced oil-vinegar algorithm, and the number of columns of the first matrix and the number of rows of the second matrix are both the same as the number of second oil variables.
[0092] Exemplarily, a first matrix and a second matrix can be randomly generated over a finite field.
[0093] For example, the first matrix and the second matrix can be represented by the following formula (1):
[0094]
[0095] where A is the first matrix and B is the second matrix; represents a finite field of order q; n represents the number of variables in the target unbalanced oil-vinegar algorithm, that is, the number of all oil variables and vinegar variables; r represents the number of second oil variables; Represents an n*r order matrix ring, in which the number of rows of the matrix is n and the number of columns is r, and the elements of the matrix are in a finite field In, the first matrix A is the matrix in the matrix ring; Represents a matrix of order r*n in a matrix ring, where the number of rows in the matrix ring is r and the number of columns is n, and the elements of the matrix are in a finite field In, the second matrix B is the matrix in the matrix ring; wherein, q, n, r are all positive integers, and the specific values of q, n, r can be set as required and are not limited to this.
[0096] Step 302: randomly generate a preset number of third matrices, wherein the third matrix is a circulant matrix, and the number of rows and columns of the third matrix are the same as the number of the second oil variables, and the preset number is the number of the first oil variables.
[0097] Among them, each element of the row vector in the circulant matrix is the result of shifting each element of the previous row vector right by one position in turn.
[0098] For example, in a finite field m third matrices of order r*r are randomly generated, and the m third matrices can be expressed as: J 1 ,…,J m , where m represents the number of first oil variables and r represents the number of second oil variables.
[0099] Step 303: randomly generate a preset number of fourth matrices, wherein the number of rows and the number of rows of the fourth matrix are the same as the number of variables in the target unbalanced oil and vinegar algorithm.
[0100] For example, in a finite field m fourth matrices of order n*n are randomly generated, and the m fourth matrices can be expressed as: F 1 ,…,F m , where m represents the number of first oil variables and n represents the number of variables in the target unbalanced oil-vinegar algorithm.
[0101] Exemplarily, the polynomial corresponding to the fourth matrix is an oil-vinegar quadratic polynomial; the definition of the oil-vinegar quadratic polynomial is as follows:
[0102] The following formula (2) shows that in a finite field The last special type of multivariate quadratic polynomial f (also called quadratic multivariate polynomial):
[0103]
[0104] Among them, x 1 ,…,x nrepresents the n variables in the multivariate quadratic polynomial f; n is the number of variables in the unbalanced oil and vinegar algorithm, o represents the number of oil variables in n variables; a ij Represents the polynomial x i x j coefficients; x represents a vector composed of n variables, x′ is the transposed vector of vector x, and F′ represents the center mapping (also called the center mapping matrix); where each variable and coefficient a ij All in finite fields Inside. You can know the center mapping The o×o square in the upper left corner is 0 o×o , represents a matrix of order n*n in the matrix ring; the multivariable quadratic polynomial f represented by formula (2) can be called a (o,v)-quadratic polynomial, i.e., an oil-vinegar quadratic polynomial, where v represents the number of vinegar variables in n variables and satisfies v=no.
[0105] Step 304: randomly generate a reversible matrix; and use the first matrix, the second matrix, the preset number of third matrices, the preset number of fourth matrices and the reversible matrix as the private key.
[0106] Exemplarily, a reversible matrix may also be randomly generated, the number of rows and the number of columns of the reversible matrix being the same as the number of variables in the target unbalanced oil and vinegar algorithm.
[0107] For example, in a finite field A reversible matrix is randomly generated on the y-axis, which can be expressed by the following formula (3):
[0108]
[0109] Among them, S is a reversible matrix; represents a finite field of order q; n represents the number of variables in the target imbalanced oil and vinegar algorithm, Represented by a finite field The group of n*n order reversible matrices in .
[0110] In this way, through the above steps 301-304, a private key is generated, and further, the following steps 305 and 306 can be executed to generate a public key.
[0111] Step 305: construct a center map according to the first matrix, the second matrix, the preset number of third matrices and the preset number of fourth matrices.
[0112] In one possible implementation, this step may include: multiplying the first matrix, the target third matrix and the second matrix to determine the product corresponding to the target third matrix; wherein the target third matrix is any matrix among the preset number of third matrices; summing the product corresponding to the target third matrix and the target fourth matrix to obtain the target multivariate quadratic polynomial corresponding to the central mapping; wherein the target fourth matrix is a matrix among the preset number of fourth matrices corresponding to the target third matrix.
[0113] For example, the central mapping F can consist of m multivariate quadratic polynomials over a finite field, expressed as Where m is the number of first oil variables, n is the number of variables in the target unbalanced oil and vinegar algorithm, and the kth multivariate quadratic polynomial f k It can be expressed by the following formula (4):
[0114] f k (x) = x′·(A·J k ·B+F k )·x……………………(4)
[0115] Where x=(x 1 ,…,x n ) represents the vector composed of n variables in the target unbalanced oil and vinegar algorithm, x′ is the transposed vector of vector x, A is the first matrix, B is the second matrix, J k is the kth third matrix among the m third matrices, F k is the kth fourth matrix among the m fourth matrices. Thus, through formula (4), the first matrix, the kth third matrix and the second matrix can be multiplied to determine the product corresponding to the kth third matrix; the product corresponding to the kth third matrix and the kth fourth matrix are summed to obtain the kth multivariate quadratic polynomial corresponding to the central mapping F.
[0116] Step 306: Use the composite mapping of the reversible matrix and the central mapping as the public key.
[0117] The reversible matrix is the reversible matrix in the above step 304, for example, it can be the reversible matrix S represented by formula (3).
[0118] In the existing multivariate public key cryptographic signature algorithm, in order to make the equation easy to solve for the terminal with the private key and difficult to solve for the terminal with only the public key, it is necessary to construct the corresponding multivariate quadratic polynomial as the central mapping F. The public key is obtained by matrix multiplication based on the central mapping F, that is, Wherein, P represents the public key, S and T are reversible matrices used to mask the properties of the central mapping F, making it difficult to distinguish it from the general multivariable quadratic equations solution problem, where S and T constitute part of the private key, and the remaining part of the private key depends on the construction method of the central mapping F. Since the reversible matrix T does not change the structure of the central mapping F, it can be assumed in the embodiments of the present disclosure that the mapping corresponding to the reversible matrix T is an identity mapping.
[0119] Then the public key P can be expressed by the following formula (5):
[0120]
[0121] Among them, F represents the central mapping, S represents the reversible matrix, and ° represents the composite of the mapping. The mapping corresponding to the reversible matrix S is a The linear mapping is used to mask the properties of the central mapping F, making it difficult to distinguish the central mapping from the general multivariable quadratic equations problem. Then the kth p k It can be expressed by the following formula (6):
[0122] p k =S′·(A·J k ·B+F k )·S……………………(6)
[0123] Where S is a reversible matrix, S′ is the transposed matrix of matrix S; A is the first matrix, B is the second matrix, and J k is the kth third matrix among the m third matrices, F k is the kth fourth matrix among the m fourth matrices. In this way, the public key p can be generated by formula (6): 1 ,…,p m , where the matrices S,A,B,J k , F k as a private key.
[0124] In the disclosed embodiment, based on the existing unbalanced oil-vinegar signature algorithm, the central mapping in the existing unbalanced oil-vinegar signature algorithm is modified and disturbed, thereby changing the size of the oil space in the original unbalanced oil-vinegar algorithm; the variables in the improved target unbalanced oil-vinegar algorithm include multiple first oil variables, multiple second oil variables and multiple vinegar variables, and the target unbalanced oil-vinegar algorithm no longer has the same oil space as the existing unbalanced oil-vinegar signature algorithm, making all attack schemes designed based on the oil space structure in the existing unbalanced oil-vinegar signature algorithm invalid; the public key can be generated by a composite mapping of a reversible matrix and the central mapping, thereby achieving higher security while reducing the size of the public key.
[0125] The specific process of signing the target message using the private key to generate the target signature in the above step 203 is described below.
[0126] Figure 4 A flow chart of a method for generating a target signature according to an embodiment of the present disclosure is shown as follows: Figure 4 As shown, the method may include the following steps:
[0127] Step 401: Process the target message to generate a corresponding hash value.
[0128] Exemplarily, the target message may be hashed by processing the target message through a preset hash function to generate a hash value of a fixed length.
[0129] For example, the hash value can be generated by the following formula (7):
[0130]
[0131] Wherein, H represents a hash function, message represents a target message, and the generated hash value y is of length m, where m is the number of the first oil variable. For example, it can be expressed as y=(y1, y 2 …, y m ).
[0132] Step 402: randomly generate a first vector and a second vector, wherein the number of elements in the first vector is the same as the number of the second oil variables; and the number of elements in the second vector is the same as the number of the vinegar variables.
[0133] For example, in a finite field Randomly generate vectors As the first vector, that is, in the finite field Generate r random numbers in the finite field to form a vector α, where r represents the number of the second oil variable. Randomly generate vectors As the second vector, that is, in the finite field Generate v random numbers to form a vector b, where v represents the number of vinegar variables.
[0134] Step 403: assign each element in the second vector to the vinegar variable to obtain the value of the vinegar variable.
[0135] For example, (x 1 ,…,x n ) represents the n variables in the target imbalanced oil and vinegar algorithm, let (x o+1 , …, x n )=(b 1 ,…,b v), that is, substitute the value x into the vinegar variable o+1 =b 1 , x o+2 =b 2 , …x n =b v , so that each element in the second vector b is assigned to the corresponding vinegar variable in the n variables. Then we can get (x 1 ,…,x o ,b 1 ,b 2 ,…,b v ), thus fixing the value of the vinegar variable among the n variables, and the value of the o oil variables among the n variables remains to be determined.
[0136] Step 404: Establish a system of equations according to the first vector, the first matrix, the second matrix, the preset number of third matrices, the preset number of fourth matrices, and the hash value.
[0137] For example, the following equations (8) and (9) can be established:
[0138] x·A=α′…………………………………………(8)
[0139] α′·J k ·B·x+x′·F k x = y k ………………………………(9)
[0140] Where x=(x 1 ,…,x o ,x o+1 ,…,x n ) represents the vector composed of n variables in the target unbalanced oil and vinegar algorithm, A is the first matrix, B is the second matrix, J k is the kth third matrix among the m third matrices, F k is the kth fourth matrix among the m fourth matrices, y k is the kth hash value corresponding to the target message, α′ is the transposed vector of the first vector α, x′ is the transposed vector of the vector x; m is the number of the first oil variables.
[0141] Step 405: Substitute the value of the vinegar variable into the equation group to solve it and obtain the value of the oil variable.
[0142] For example, (x o+1 ,…,x n )=(b 1 ,…,b v ) is substituted into the equations shown in (8) and (9), we can obtain:
[0143] (x 1 ,…,x o ,b 1 ,b 2 ,…,b v )A=α′……………………(10)
[0144] α′·J k ·B·x+x′·F k x = y k ………………………………(11)
[0145] Where x=(x 1 ,…,x o ,b 1 ,b 2 ,…,b v ) represents the vector of n variables in the target imbalanced oil and vinegar algorithm, where the vinegar variable (b 1 ,b 2 ,…,b v ) is fixed, the oil variable (x 1 , …, x o ) is to be found, A is the first matrix, B is the second matrix, J k is the kth third matrix among the m third matrices, F k is the kth fourth matrix among the m fourth matrices, y k is the kth hash value corresponding to the target message, α′ is the transposed vector of the first vector α, x′ is the transposed vector of the vector x; m is the number of the first oil variables.
[0146] It can be understood that the central mapping contains the product terms of oil variables and oil variables, the product terms of oil variables and vinegar variables, and the product terms of vinegar variables and vinegar variables. Due to the special structure of the fourth matrix constituting the central mapping, the vinegar variables in the n variables are assigned values, so that the vinegar variables in the central mapping can be fixed, so that the system of equations shown in the above equations (10) and (11) only contains the oil variables, that is, a system of equations with o=m+r unknowns and m+r linear equations. The system of equations is o linear equations about o oil variables, so that the value of the oil variable can be solved; for example, if the solution is (x 1 ,…,x o )=(c 1 ,…,c o ), let x=(c 1 ,…,c o , b 1 ,…,b v), then F(x)=y, where F is the center mapping and y is the hash value corresponding to the target message. If the equation system has no solution, the above step 402 is repeated to reselect α, b, and perform the following steps until the value of the oil variable is obtained.
[0147] Step 406: Generate the target signature according to the value of the oil variable, the value of the vinegar variable and the reversible matrix.
[0148] The process of generating a signature is actually the process of solving the original image of the composite mapping. For example, the process of solving the original image of the mapping P = F°S shown in the above formula (5) is to solve F(x) = y and then calculate the value of each variable x = (c 1 ,…,c o ,b 1 ,…,b v ) and the reversible matrix S, and further solve to obtain the target signature Sign = S -1 (x).
[0149] In this way, through the above steps 401-406, the value of the vinegar variable is first fixed, and then the value of the oil variable is solved, the value of each variable is solved, and then the target signature is generated.
[0150] The quantum-resistant electronic signature verification method provided by the embodiments of the present disclosure is described in detail below.
[0151] Figure 5 A flowchart of a quantum-resistant electronic signature verification method according to an embodiment of the present disclosure is shown. The method can be applied to a terminal for verifying a signature, for example, Figure 1 The second terminal 20 in the electronic signature system, such as Figure 5 As shown, the method may include the following steps:
[0152] Step 501, receiving a target message, a target signature and a public key; wherein the public key is generated based on a target unbalanced oil-vinegar algorithm, and the variables in the target unbalanced oil-vinegar algorithm include a plurality of first oil variables, a plurality of second oil variables and a plurality of vinegar variables; the number of the first oil variables is greater than the number of the second oil variables.
[0153] In one possible implementation, the multivariate quadratic polynomial corresponding to the central mapping of the target unbalanced oil-vinegar algorithm includes a product term of the oil variable and the vinegar variable, a product term of the oil variable and the oil variable, and a product term of the vinegar variable and the vinegar variable, wherein the oil variable includes the first oil variable and the second oil variable.
[0154] Step 502: Perform a calculation using the public key and the target message to obtain a calculation result.
[0155] Exemplarily, the terminal verifying the signature processes the target message through a hash function to obtain a hash value corresponding to the target message, and uses the public key of the terminal generating the signature to decrypt the hash value corresponding to the target message to obtain a calculation result. The hash function used to generate the hash value corresponding to the target message is the same as the hash function used to generate the hash value corresponding to the target signature.
[0156] Step 503: compare the operation result with the target signature. If the operation result is the same as the target signature, the verification result is verification passed; otherwise, the verification result is verification failed.
[0157] Exemplarily, the operation result is compared with the target signature. If the operation result is the same as the target signature, the target signature is verified, indicating that the target signature and the message are sent by the terminal to which the public key belongs; if the operation result is different from the target signature, the target signature is not verified, indicating that the target signature or the message is not sent by the terminal to which the public key belongs. For example, in a scenario where a user needs to download a software installation package from a server, the user can store the public key of the authenticated service provider locally in advance. After the user receives the software installation package and the electronic signature, the service provider's public key can be used to perform an operation on the software installation package to obtain the operation result, and the operation result can be compared with the electronic signature. If the operation result is the same as the electronic signature, it indicates that the electronic signature is the signature of the service provider. If they are different, it indicates that the software installation package may be tampered with by other persons, or it is possible that other persons impersonate the identity of the service provider; thereby verifying the integrity of the message and the identity of the message sender.
[0158] Based on the same inventive concept of the above method embodiment, the embodiment of the present disclosure also provides a quantum-resistant electronic signature generation device, which can be used to execute the technical solution described in the above quantum-resistant electronic signature generation method embodiment.
[0159] Figure 6 A structural diagram of a quantum-resistant electronic signature generation device according to an embodiment of the present disclosure is shown, which is applied to a terminal generating a signature, such as Figure 6As shown, the device may include: a public-private key pair module 601, used to generate a public key and a private key based on a target unbalanced oil-vinegar algorithm; wherein the variables in the target unbalanced oil-vinegar algorithm include multiple first oil variables, multiple second oil variables and multiple vinegar variables; the number of the first oil variables is greater than the number of the second oil variables; an acquisition module 602, used to acquire a target message; a signature module 603, used to sign the target message using the private key to generate a target signature; a sending module 604, used to send the target message, the target signature and the public key to a terminal for verifying the signature, so that the terminal for verifying the signature uses the target message and the public key to verify the target signature.
[0160] In the disclosed embodiment, on the basis of the existing unbalanced oil-vinegar signature algorithm, the size of the oil space is improved, thereby transforming the center mapping in the existing unbalanced oil-vinegar signature algorithm, and the variables in the improved target unbalanced oil-vinegar algorithm include multiple first oil variables, multiple second oil variables and multiple vinegar variables. The target unbalanced oil-vinegar algorithm no longer has the same oil space as the existing unbalanced oil-vinegar signature algorithm, so that the attack schemes designed based on the oil space structure in the existing unbalanced oil-vinegar signature algorithm are invalid, and the size of the public key generated under the oil space is small; in addition, the private key generated based on the target unbalanced oil-vinegar algorithm is used to generate the first oil variable, the second oil variable and the vinegar variable. The target message is signed, a target signature is generated, and the target message, the target signature and the public key are sent to the terminal for verifying the signature, so that the terminal for verifying the signature verifies the target signature using the target message and the public key. The above process of generating an electronic signature and verifying the signature by the terminal for verifying the signature is still similar to the existing unbalanced oil and vinegar signature algorithm, and therefore still has the characteristics of short signature and high efficiency in the multivariate signature algorithm. Its security still depends on the solution of a multivariate equation group, and it is difficult to forge a signature. It still has the characteristics of resisting quantum computers; thereby achieving higher security while reducing the size of the public key.
[0161] In one possible implementation, the multivariate quadratic polynomial corresponding to the central mapping of the target unbalanced oil-vinegar algorithm includes a product term of the oil variable and the vinegar variable, a product term of the oil variable and the oil variable, and a product term of the vinegar variable and the vinegar variable, wherein the oil variable includes the first oil variable and the second oil variable.
[0162] In a possible implementation, the public-private key pair module 601 is also used to: randomly generate a first matrix and a second matrix, wherein the number of rows of the first matrix and the number of columns of the second matrix are the same as the number of variables in the target unbalanced oil and vinegar algorithm, and the number of columns of the first matrix and the number of rows of the second matrix are the same as the number of the second oil variables; randomly generate a preset number of third matrices, wherein the third matrix is a circulant matrix, and the number of rows and columns of the third matrix are the same as the number of the second oil variables, and the preset number is the number of the first oil variables; randomly generate a preset number of fourth matrices, wherein the number of rows and the number of rows of the fourth matrix are the same as the number of variables in the target unbalanced oil and vinegar algorithm; randomly generate a reversible matrix; and use the first matrix, the second matrix, the preset number of third matrices, the preset number of fourth matrices and the reversible matrix as the private key.
[0163] In a possible implementation, the public-private key pair module 601 is further used to: construct a central mapping based on the first matrix, the second matrix, the preset number of third matrices and the preset number of fourth matrices; and use the composite mapping of the reversible matrix and the central mapping as the public key.
[0164] In a possible implementation, the public-private key pair module 601 is further used to: multiply the first matrix, the target third matrix and the second matrix to determine the product corresponding to the target third matrix; wherein the target third matrix is any matrix among the preset number of third matrices; sum the product corresponding to the target third matrix and the target fourth matrix to obtain the target multivariate quadratic polynomial corresponding to the central mapping; wherein the target fourth matrix is a matrix among the preset number of fourth matrices corresponding to the target third matrix.
[0165] In a possible implementation, the signature module 603 is further used to: process the target message to generate a corresponding hash value; randomly generate a first vector and a second vector, wherein the number of elements in the first vector is the same as the number of the second oil variable; the number of elements in the second vector is the same as the number of the vinegar variable; assign each element in the second vector to the vinegar variable to obtain the value of the vinegar variable; establish a system of equations based on the first vector, the first matrix, the second matrix, the preset number of third matrices, the preset number of fourth matrices and the hash value; substitute the value of the vinegar variable into the system of equations for solving to obtain the value of the oil variable; generate the target signature based on the value of the oil variable, the value of the vinegar variable and the reversible matrix.
[0166] The embodiments of the present disclosure also provide a quantum-resistant electronic signature verification device, which can be used to execute the technical solution described in the above-mentioned quantum-resistant electronic signature verification method embodiment.
[0167] Figure 7 A structural diagram of a quantum-resistant electronic signature verification device according to an embodiment of the present disclosure is shown, which is applied to a terminal for verifying a signature, such as Figure 7 As shown, the device may include: a receiving module 701, used to receive a target message, a target signature and a public key; wherein the public key is generated based on a target unbalanced oil-vinegar algorithm, and the variables in the target unbalanced oil-vinegar algorithm include multiple first oil variables, multiple second oil variables and multiple vinegar variables; the number of the first oil variables is greater than the number of the second oil variables; an operation module 702, used to use the public key and the target message to perform an operation to obtain an operation result; a verification module 703, used to compare the operation result with the target signature, if the operation result is the same as the target signature, the verification result is verification passed, otherwise, the verification result is verification failed.
[0168] In the disclosed embodiment, a public key is used to perform an operation on a target message to obtain an operation result, and the operation result is compared with the target signature, thereby verifying the integrity of the message and the identity of the message sender.
[0169] In one possible implementation, the multivariate quadratic polynomial corresponding to the central mapping of the target unbalanced oil-vinegar algorithm includes a product term of the oil variable and the vinegar variable, a product term of the oil variable and the oil variable, and a product term of the vinegar variable and the vinegar variable, wherein the oil variable includes the first oil variable and the second oil variable.
[0170] Above Figure 6 and Figure 7 The technical effects and specific descriptions of the device shown and its various possible implementations can be found in the above method embodiments, which will not be repeated here.
[0171] It should be understood that the division of the modules in the above device is only a division of logical functions, and in actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. In addition, the modules in the device can be implemented in the form of a processor calling software; for example, the device includes a processor, the processor is connected to a memory, and instructions are stored in the memory. The processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of the modules of the device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory inside the device or a memory outside the device. Alternatively, the modules in the device can be implemented in the form of hardware circuits, and the functions of some or all modules can be realized by designing the hardware circuits, and the hardware circuits can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of some or all modules above are realized by designing the logical relationship of the components in the circuit; for another example, in another implementation, the hardware circuit can be realized by a programmable logic device (PLD), taking a field programmable gate array (FPGA) as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of some or all modules above. All modules of the above device can be realized in the form of a processor calling software, or in the form of hardware circuits, or in part by a processor calling software, and the rest by hardware circuits.
[0172] In the embodiments of the present disclosure, the processor is a circuit with the ability to process signals. In one implementation, the processor may be a circuit with the ability to read and run instructions, such as a CPU, a microprocessor, a graphics processing unit (GPU), a digital signal processor (DSP), a neural-network processing unit (NPU), a tensor processing unit (TPU), etc.; in another implementation, the processor may implement certain functions through the logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable, such as a hardware circuit implemented by an ASIC or PLD, such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above modules.
[0173] It can be seen that each module in the above device can be one or more processors (or processing circuits) configured to implement the above embodiment method, such as: CPU, GPU, NPU, TPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms. In addition, each module in the above device can be fully or partially integrated together, or can be implemented independently, which is not limited.
[0174] The present disclosure also provides an electronic device, comprising: a processor; a memory for storing instructions executable by the processor; wherein the processor is configured to implement the method of the above embodiment when executing the instructions. Figure 2 , Figure 3 , Figure 4 or Figure 5 The steps of the method shown in .
[0175] Figure 8 A schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure is shown. For example, the electronic device may be the above-mentioned Figure 1 The first terminal 10 or the second terminal 20; Figure 8 As shown, the electronic device may include: at least one processor 801 , a communication line 802 , a memory 803 and at least one communication interface 804 .
[0176] The processor 801 may be a general-purpose central processing unit, a microprocessor, a specific application integrated circuit, or one or more integrated circuits for controlling the execution of the program of the disclosed solution; the processor 801 may also include a heterogeneous computing architecture of multiple general-purpose processors, for example, it may be a combination of at least two of a CPU, a GPU, a microprocessor, a DSP, an ASIC, and an FPGA; as an example, the processor 801 may be a CPU+GPU or a CPU+ASIC or a CPU+FPGA.
[0177] The communication link 802 may include a pathway to transmit information between the above-mentioned components.
[0178] The communication interface 804 uses any transceiver or other device for communicating with other devices or communication networks, such as Ethernet, RAN, wireless local area networks (WLAN), etc.
[0179] The memory 803 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited to this. The memory can be independent and connected to the processor through a communication line 802. The memory can also be integrated with the processor. The memory provided in the embodiment of the present disclosure can generally have non-volatility. Among them, the memory 803 is used to store the computer execution instructions for executing the scheme of the present disclosure, and the execution is controlled by the processor 801. The processor 801 is used to execute the computer-executable instructions stored in the memory 803, so as to implement the method provided in the above embodiment of the present disclosure; illustratively, the above Figure 2 , Figure 3 , Figure 4 or Figure 5 The steps of the method shown in .
[0180] Optionally, the computer-executable instructions in the embodiments of the present disclosure may also be referred to as application program codes, which is not specifically limited in the embodiments of the present disclosure.
[0181] Exemplarily, the processor 801 may include one or more CPUs, for example, Figure 8 The processor 801 may also include a CPU, and any one of a GPU, an ASIC, and an FPGA, for example, Figure 8 CPU0+GPU0 or CPU 0+ASIC0 or CPU0+FPGA0.
[0182] Exemplarily, an electronic device may include multiple processors, such as Figure 8 801 and processor 807 in the embodiment. Each of these processors may be a single-CPU processor, a multi-CPU processor, or a heterogeneous computing architecture including multiple general-purpose processors. The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0183] In a specific implementation, as an embodiment, the electronic device may further include an output device 805 and an input device 806. The output device 805 communicates with the processor 801 and may display information in a variety of ways. For example, the output device 805 may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. For example, it may be a display device such as a vehicle-mounted HUD, an AR-HUD, a display, etc. The input device 806 communicates with the processor 801 and may receive user input in a variety of ways. For example, the input device 806 may be a mouse, a keyboard, a touch screen device, a sensor device, etc.
[0184] The embodiments of the present disclosure provide a computer-readable storage medium on which computer program instructions are stored. When the computer program instructions are executed by a processor, the method in the above embodiments is implemented. Figure 2 , Figure 3 , Figure 4 or Figure 5 The steps of the method shown in .
[0185] The embodiments of the present disclosure provide a computer program product, which may include, for example, a computer-readable code or a non-volatile computer-readable storage medium carrying the computer-readable code; when the computer program product is run on a computer, the computer executes the method in the above embodiment. Figure 2 , Figure 3 , Figure 4 or Figure 5 The steps of the method shown in .
[0186] The present disclosure may be a system, a method and / or a computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for causing a processor to implement various aspects of the present disclosure.
[0187] A computer-readable storage medium may be a tangible device that can hold and store instructions used by an instruction execution device. A computer-readable storage medium may be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples of computer-readable storage media (a non-exhaustive list) include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device, such as a punch card or a raised structure in a groove on which instructions are stored, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium is not to be interpreted as a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse through a fiber optic cable), or an electrical signal transmitted through a wire.
[0188] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.
[0189] The computer program instructions for performing the operation of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages, such as Smalltalk, C++, etc., and conventional procedural programming languages, such as "C" language or similar programming languages. Computer-readable program instructions may be executed completely on a user's computer, partially on a user's computer, as an independent software package, partially on a user's computer, partially on a remote computer, or completely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., using an Internet service provider to connect via the Internet). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may be customized by utilizing the state information of the computer-readable program instructions, and the electronic circuit may execute the computer-readable program instructions, thereby realizing various aspects of the present disclosure.
[0190] Various aspects of the present disclosure are described herein with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer-readable program instructions.
[0191] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, so that when these instructions are executed by the processor of the computer or other programmable data processing device, a device that implements the functions / actions specified in one or more boxes in the flowchart and / or block diagram is generated. These computer-readable program instructions can also be stored in a computer-readable storage medium, and these instructions cause the computer, programmable data processing device, and / or other equipment to work in a specific manner, so that the computer-readable medium storing the instructions includes a manufactured product, which includes instructions for implementing various aspects of the functions / actions specified in one or more boxes in the flowchart and / or block diagram.
[0192] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operating steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to implement the functions / actions specified in one or more boxes in the flowchart and / or block diagram.
[0193] The flow chart and block diagram in the accompanying drawings show the possible architecture, function and operation of the system, method and computer program product according to multiple embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a part of a module, program segment or instruction, and a part of the module, program segment or instruction includes one or more executable instructions for realizing the specified logical function. In some alternative implementations, the function marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two continuous square boxes can actually be executed substantially in parallel, and they can sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs the specified function or action, or can be implemented with a combination of special hardware and computer instructions.
[0194] The embodiments of the present disclosure have been described above, and the above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and changes will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The selection of terms used herein is intended to best explain the principles of the embodiments, practical applications, or technical improvements in the market, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein.
Claims
1. A method for generating quantum-resistant electronic signatures, It is characterized in that Applied to a terminal for generating a signature, the method comprises: Generate a public key and a private key based on a target unbalanced oil and vinegar algorithm; wherein the variables in the target unbalanced oil and vinegar algorithm include a plurality of first oil variables, a plurality of second oil variables and a plurality of vinegar variables; the number of the first oil variables is greater than the number of the second oil variables; Get the target message; Signing the target message using the private key to generate a target signature; The target message, the target signature and the public key are sent to a terminal for verifying the signature, so that the terminal for verifying the signature verifies the target signature using the target message and the public key.
2. The method according to claim 1, It is characterized in that The multivariate quadratic polynomial corresponding to the central mapping of the target unbalanced oil-vinegar algorithm includes a product term of the oil variable and the vinegar variable, a product term of the oil variable and the oil variable, and a product term of the vinegar variable and the vinegar variable, wherein the oil variable includes the first oil variable and the second oil variable.
3. The method according to claim 1 or 2, It is characterized in that The method of generating a private key based on the target unbalanced oil and vinegar algorithm includes: Randomly generate a first matrix and a second matrix, wherein the number of rows of the first matrix and the number of columns of the second matrix are the same as the number of variables in the target unbalanced oil and vinegar algorithm, and the number of columns of the first matrix and the number of rows of the second matrix are the same as the number of the second oil variables; Randomly generate a preset number of third matrices, wherein the third matrix is a circulant matrix, and the number of rows and the number of columns of the third matrix are the same as the number of the second oil variables, and the preset number is the number of the first oil variables; Randomly generate a preset number of fourth matrices, wherein the number of rows and the number of rows of the fourth matrix are the same as the number of variables in the target unbalanced oil and vinegar algorithm; A reversible matrix is randomly generated; and the first matrix, the second matrix, the preset number of third matrices, the preset number of fourth matrices and the reversible matrix are used as the private key.
4. The method according to claim 3, It is characterized in that The method of generating a public key based on a target unbalanced oil and vinegar algorithm includes: constructing a center map according to the first matrix, the second matrix, the preset number of third matrices, and the preset number of fourth matrices; A composite mapping of the reversible matrix and the central mapping is used as the public key.
5. The method according to claim 4, It is characterized in that The constructing a center mapping according to the first matrix, the second matrix, the preset number of third matrices, and the preset number of fourth matrices includes: Multiplying the first matrix, the target third matrix and the second matrix to determine a product corresponding to the target third matrix; wherein the target third matrix is any matrix among the preset number of third matrices; The product corresponding to the target third matrix and the target fourth matrix are summed to obtain a target multivariate quadratic polynomial corresponding to the central mapping; wherein the target fourth matrix is a matrix corresponding to the target third matrix among the preset number of fourth matrices.
6. The method according to claim 4, It is characterized in that The step of signing the target message using the private key to generate a target signature includes: Processing the target message to generate a corresponding hash value; Randomly generate a first vector and a second vector, wherein the number of elements in the first vector is the same as the number of the second oil variables; the number of elements in the second vector is the same as the number of the vinegar variables; Assign each element in the second vector to the vinegar variable to obtain the value of the vinegar variable; Establishing a system of equations according to the first vector, the first matrix, the second matrix, the preset number of third matrices, the preset number of fourth matrices, and the hash value; Substituting the value of the vinegar variable into the equation group and solving it to obtain the value of the oil variable; The target signature is generated according to the value of the oil variable, the value of the vinegar variable and the reversible matrix.
7. A quantum-resistant electronic signature verification method, It is characterized in that Applied to a terminal for verifying a signature, the method comprises: Receive a target message, a target signature and a public key; wherein the public key is generated based on a target unbalanced oil-vinegar algorithm, and variables in the target unbalanced oil-vinegar algorithm include a plurality of first oil variables, a plurality of second oil variables and a plurality of vinegar variables; the number of the first oil variables is greater than the number of the second oil variables; Performing a calculation using the public key and the target message to obtain a calculation result; The operation result is compared with the target signature. If the operation result is the same as the target signature, the verification result is verification passed; otherwise, the verification result is verification failed.
8. A quantum-resistant electronic signature generation device, It is characterized in that Applicable to a terminal for generating a signature, the device comprising: A public-private key pair module, used to generate a public key and a private key based on a target unbalanced oil-vinegar algorithm; wherein the variables in the target unbalanced oil-vinegar algorithm include a plurality of first oil variables, a plurality of second oil variables and a plurality of vinegar variables; the number of the first oil variables is greater than the number of the second oil variables; An acquisition module is used to acquire target messages; A signature module, used to sign the target message using the private key to generate a target signature; The sending module is used to send the target message, the target signature and the public key to the terminal for verifying the signature, so that the terminal for verifying the signature verifies the target signature using the target message and the public key.
9. An electronic device, It is characterized in that include: processor; a memory for storing processor-executable instructions; Wherein, the processor is configured to implement the method described in any one of claims 1 to 6 or the method described in claim 7 when executing the instructions stored in the memory.
10. A computer-readable storage medium having computer program instructions stored thereon, It is characterized in that When the computer program instructions are executed by a processor, the method according to any one of claims 1 to 6 or the method according to claim 7 is implemented.