Full-threshold elliptic curve digital signature method based on SPDZ protocol
By combining sacrificial and multiplication in the SPDZ protocol and applying it in ECDSA, the problems of high running time and traffic volume in the prior art are solved, and efficiency improvement in offline stages and fine-grained verification in online stages are achieved.
Patent Information
- Application Number
- CN202510197919.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-27
AI Technical Summary
The existing active full threshold ECDSA scheme has high requirements in terms of operation time and traffic, and it is difficult to effectively reduce the time and traffic of unintentional transmission in the offline stage.
Combining sacrifice and multiplication in the SPDZ protocol, the two-party elliptic curve digital signature algorithm (ECDSA) is introduced, and additional verification is completed by sacrificing the time and communication of the online stage, detecting the correctness of online secret multiplication, and using more efficient cryptography tools in the offline stage.
It reduces the time and traffic required for inadvertent transmission in the offline stage, increases the ability to expand the number of users, and provides more fine-grained inspections in the online stage, improving operational efficiency.
Smart Images

Figure CN120050041A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a technology in the field of information security, specifically a full-threshold elliptic curve digital signature method based on the SPDZ protocol. Background Art
[0002] In a full-threshold signature, the private key is held by multiple users in the form of secret sharing, and all users cooperate to generate a digital signature for a message. Secure multi-party computation is an important primitive in cryptography. Multiple users can use this data to cooperate in computing a public function while keeping their private data secret, which can be used to implement a full-threshold signature. The SPDZ protocol is one of the most practical secure multi-party computation protocols. It generates auxiliary data in the offline phase, which is a phase with a large workload, and can use the auxiliary data to complete specific tasks at high speed in the online phase. As one of the most widely used digital signature schemes currently, implementing an active full-threshold ECDSA scheme that resists malicious attackers can play an important role in fields such as digital currency and blockchain. However, current active full-threshold ECDSA schemes often require heavy zero-knowledge proofs, which pose high requirements for both running time and communication volume. Summary of the Invention
[0003] In view of the above deficiencies in the prior art, the present invention proposes a full-threshold elliptic curve digital signature method based on the SPDZ protocol. It combines the sacrifice in the SPDZ protocol with multiplication and introduces it into the two-party elliptic curve digital signature algorithm (ECDSA). By sacrificing a small amount of time and communication in the online phase to complete additional verification, it can not only detect the correctness of online secret multiplication, but also use more efficient cryptographic tools in the offline phase by relaxing security, significantly reducing the time and communication volume required for extended oblivious transfer in the offline phase, and can further increase the number of users to expand to a full-threshold signature.
[0004] The present invention is realized through the following technical solutions:
[0005] The present invention relates to a full-threshold elliptic curve digital signature method based on the SPDZ protocol, including: generating a sacrifice quintuple in the offline phase and using the sacrifice quintuple to generate a signature in the online phase. Specifically:
[0006] 1) The offline phase specifically includes:
[0007] 1.1) Select an elliptic curve (a, b, p, G, N), where: any point (x, γ) on the elliptic curve satisfies y 3 = x 2 + ax + n (mod p), where: 4a 3 + 27b2 ≠ 0 (mod p). Select some points on the elliptic curve to form a cyclic group, and let G be the generator of this group, and the prime number N be the order of the cyclic group;
[0008] 1.2) Let n be the number of participating users. All users use the passive oblivious transfer protocol to generate three secret sharings [x], [k], [γ] over the finite field Z N Take the secret sharing [x] as an example. Specifically: Each user P i obtains (x i , α i , γ i (x)), where: x i is a shard of the secret, α i is a shard of the global key α, and γ i (x) is a shard of the message authentication code (MAC, message authenticate code), satisfying the following relationships: x = x 1 + … + x n , α = α 1 + … + α n , α·x = γ 1 (x)+ … + γ n (x);
[0009] 1.3) All users use the passive oblivious transfer protocol to generate sacrifice quintuples over the finite field Z N . Specifically: Each sacrifice quintuple is a quintuple ([a], [a'], [b], [c], [c']), where: a, a′, and b are all random elements over the finite field, c = a·b, c′ = a′·b;
[0010] 2) Online phase, specifically including:
[0011] 2.1) All users set [x] as the private key of the full threshold signature, and partially disclose xG ← [x]G as the public key of the full threshold signature. The specific process is as follows: Each user P i locally calculates x i G and broadcasts it to other users. All users locally calculate xG = x 1 G+ … + x n G;
[0012] 2.2) Calculate the hash value H(m) of the message m to be signed, where: H() is a hash function;
[0013] 2.3) All users calculate [δ] = [kx] and [σ] = [kγ] respectively using the two sacrifice quintuples generated in the offline stage. The process of calculating online multiplication using the sacrifice quintuples is as follows: Let [x] and [y] be the two inputs of the multiplication, and let [z] be the output of the multiplication:
[0014] 2.3.1) Each user P i randomly selects an element t N from the finite field Z i , and makes it public to get t = t 1 +…+t n ;
[0015] 2.3.2) All users partially disclose d ← [x] - [a], e ← [y] - [b] and f ← t[x] - [a ′ . Among them: partially disclosing means only disclosing the secrets of the secret sharing, not the MAC of the secret sharing;
[0016] 2.3.3) All users locally calculate [z] = [c] + d[b] + a[e] + d·e and [w] = t[z] - ([c′] + e[a′] + f[b] + e·f);
[0017] 2.3.4) All users partially disclose w ← [w]. When w = 0, the verification passes. Otherwise, stop the verification;
[0018] 2.4) All users partially disclose σ ← [σ];
[0019] 2.5) All users locally calculate [k -1 = σ -1 [γ];
[0020] 2.6) All users partially disclose k -1 G ← [k -1 G, and let the r in the signature be the abscissa of k -1 G;
[0021] 2.7) All users locally calculate [s] = H(m)[x] + r[δ];
[0022] 2.8) All users partially disclose s ← [s];
[0023] 2.9) All users use MAC to check all partially disclosed secret sharings. Specifically: Let [x] be the partially disclosed secret sharing, and each user P i discloses γ i (x) - α i ·x. When the disclosed values add up to 0, the verification passes. Otherwise, stop the verification.
[0024] 2.10) All users use MAC to check all partially public points. Specifically, let [x]G be a partially public point. Each user P i Public | i (x)G-α i G, when the sum of the public points is equal to the infinity point on the elliptic curve, the verification is passed; otherwise, the verification stops.
[0025] When all verifications pass, all users output (r, s) as signatures and xG as public keys.
[0026] The present invention relates to a system for implementing the above method, comprising: an offline unit and an online unit, wherein: the offline unit performs randomization processing based on a specific elliptic curve using a passive oblivious transfer protocol to obtain a random secret sharing and a sacrifice quintuple, and the online unit performs full-threshold threshold signature processing based on the secret sharing of a private key and a message to obtain a digital signature corresponding to the message. Technical Effects
[0027] Compared with the existing technology, the sacrifice algorithm and online multiplication are improved and organically combined. The correctness of the multiplication result can be verified in the online stage, instead of having to wait until the result is made public to use MAC verification, providing a more fine-grained check; when the sacrifice quintuple is generated in the offline stage, the passive non-oblivious transfer protocol can be used instead of the previous active non-oblivious transfer protocol, saving a lot of time and communication required for zero-knowledge proof, at the cost of a small amount of additional online verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 This is the SPDZ-sacrifice flow chart;
[0029] Figure 2 This is the ECDSA flow chart of two parties under the SPDZ-sacrifice protocol;
[0030] Figure 3 This is a schematic diagram of multiple ECDSA offline running times under different security conditions;
[0031] Figure 4 Schematic diagram of the communication volume of multiple ECDSA offline operations with different security levels;
[0032] Figure 5 This is a schematic diagram of the online running time of multiple ECDSAs of two SPDZ protocols;
[0033] Figure 6 Schematic diagram of the overall running time of multiple ECDSAs of two SPDZ protocols. Specific Embodiment
[0034] As Figure 2 shown, this embodiment includes the following steps:
[0035] Step 1, initialize the public parameters: select a finite field, an elliptic curve based on ECDSA, a generator G and order of the elliptic curve cyclic group, the user's IP address and interface.
[0036] Step 2, generate the secret sharing and sacrifice quintuples on the finite field required for the online phase through cryptographic tools offline, specifically: implementing ECDSA once requires generating 3 secret sharings ([x], [k], [γ]) on the finite field and 2 sacrifice quintuples.
[0037] In this embodiment, the cryptographic tool selected for the offline phase is oblivious transfer. Since the sacrifice secret multiplication can be used to verify the correctness of multiplication, this method does not require the correctness of the sacrifice quintuples, so the security of oblivious transfer can be relaxed from active to passive.
[0038] Step 3, sign the given message in the online phase: implementing ECDSA once requires implementing 2 secret multiplications ([kx], [kγ]), 2 verifications of secret sharing (kγ, s), and 2 verifications of secret sharing on the elliptic curve points (xG, k -1 G) in the online phase.
[0039] The communication required for the above operations is shown in Table 1.
[0040] Table 1: Comparison of the online phases of SPDZ and SPDZ - sacrifice
[0041] In the online phase, most operations can be completed locally (including constant addition, secret addition, constant multiplication), except for secret multiplication and verification.
[0042] After specific actual experiments, in the local operating environment, running the above method with an Intel i5 - 10400F CPU, the oblivious transfer for the offline phase is implemented using the Encrypto Group library ( https: / / github.com / encryptogroup / OTExtension ), and the selected elliptic curve is Secp256k1. As shown in Table 1, compared with the original SPDZ protocol, the SPDZ - sacrifice protocol using sacrifice multiplication requires an additional 3 rounds of communication and about 83% more communication volume due to the application of sacrifice for verification in the secret multiplication phase.
[0043] As Figure 3 and Figure 4 shown, in this embodiment, by using the passive oblivious transfer (IKNP) protocol to replace the original active oblivious transfer (ALSZ) protocol, it is possible to achieve a reduction in time and communication volume, and improve the operation efficiency of the offline phase. The relaxation of security brings an improvement in efficiency, which applies to common cryptographic tools. Therefore, regardless of the applicable cryptographic primitive, the execution efficiency of the offline phase of the present invention is superior to the prior art, and the advantage of the execution efficiency is reflected in the running time or communication volume.
[0044] As Figure 5 shown, compared with the SPDZ protocol, the SPDZ-sacrifice protocol has a slightly increased online time required to implement multiple ECDSA. Generally speaking, the increase is about 20%.
[0045] As Figure 6 shown, for multiple complete ECDSA (offline phase + online phase), the SPDZ-sacrifice protocol (passive oblivious transfer + sacrifice multiplication) of this embodiment generally requires less time than the original SPDZ protocol (active oblivious transfer + multiplication), has a faster running speed, and has a smaller demand for bandwidth.
[0046] Compared with the prior art, the present invention generally has a faster running speed, saves more time and communication volume in the offline phase, and can verify the correctness of the secret multiplication every time a multiplication is executed.
[0047] The above specific embodiments can be locally adjusted by those skilled in the art in different ways without departing from the principles and purposes of the present invention. The protection scope of the present invention is subject to the claims and is not limited by the above specific embodiments. All implementation solutions within its scope are subject to the present invention.
Claims
1. A full threshold elliptic curve digital signature method based on the SPDZ protocol, characterized in that: include: 1) Offline stage, including: 1.1) Choose an elliptic curve (a, b, p, G, N), where any point (x, y) on the elliptic curve satisfies y 3 =x 2 +ax+n(mod p), where: 4a 3 +27b 2 ≠0(mod p), select some points on the elliptic curve to form a cyclic group, let G be the generator of the cyclic group, and the prime number N be the order of the cyclic group; 1.2) Let n be the number of participating users. All users use the passive oblivious transfer protocol to generate three finite fields Z N The secret sharing [x], [k], [γ] on the network is as follows: Each user P i Get (x i , α i , γ i (x)), where: x i is the secret shard, α i is the key shard of the global key α, γ i (x) is a fragment of a message authentication code (MAC), satisfying the following relationship: x = x1 + ... + x n ,α=α1+…+α n , α·x=γ1(x)+…+γ n (x); 1.3) All users use the passive oblivious transfer protocol to generate two finite fields Z N The five-tuple of sacrifice on the field is as follows: each five-tuple of sacrifice is a five-tuple of ([a], [a′], [b], [c], [c′]), where a, a′ and b are all random elements on the finite field, c = a·b, c′ = a′·b; 2) Online stage, including: 2.1) All users set [x] as the private key of the full threshold signature and partially disclose xG←[x]G as the public key of the full threshold signature. The specific process is as follows: Each user P i Local Computingx i G and broadcast it to other users, all users locally calculate xG = x1G + ... + x n G; 2.2) Calculate the hash value H(m) of the message to be signed, where: H() is a hash function; 2.3) All users use the two sacrifice quintuples generated in the offline phase to calculate [δ] = [kx] and [σ] = [kγ] respectively; 2.4) All users partially disclose σ←[σ]; 2.5) All users calculate [k -1 ]=σ -1 [γ]; 2.6) All users partially disclose k -1 G←[k -1 ]G, and let r in the signature be k -1 The horizontal coordinate of G; 2.7) All users locally calculate [s] = H(m)[x] + r[δ]; 2.8) All users partially disclose s←[s]; 2.9) All users use MAC to check all partially public secret shares. Specifically, let [x] be a partially public secret share. Each user P i Public | i (x)-α i x, when the sum of the public values equals 0, the verification is passed; otherwise, the verification stops; 2.10) All users use MAC to check all partially public points. Specifically, let [x]G be a partially public point. Each user P i Public | i (x)G-α i xG, when the sum of the public points is equal to the infinite point on the elliptic curve, the verification is passed; otherwise, the verification stops; When all verifications pass, all users output (r, s) as signatures and xG as public keys.
2. The full threshold elliptic curve digital signature method based on the SPDZ protocol according to claim 1 is characterized in that: The step 2.3 uses the sacrifice quintuple to calculate the online multiplication, specifically including: let [x] and [y] be two inputs of the multiplication, let [z] be the output of the multiplication; 2.3.1) Each user P i Randomly select a finite field Z N The element t on i , and publish it to get t = t1 + ... + t n ; 2.3.2) All users partially disclose d←[x]-[a], e←[y]-[b] and f←t[x]-[a ′ ], where: Partial disclosure means that only the secret of secret sharing is disclosed, and the MAC of secret sharing is not disclosed; 2.3.3) All users locally compute [z] = [c] + d[b] + a[e] + d·e and [w] = t[z] - ([c′] + e[a′] + f[b] + e·f); 2.3.4) All users partially disclose w←[w]. When w=0, verification is passed, otherwise verification stops.
3. A full threshold elliptic curve digital signature system based on the SPDZ protocol for implementing any of the methods described in claim 1 or 2, characterized in that: include: Offline unit and online unit, wherein: the offline unit performs randomization processing according to a specific elliptic curve using a passive oblivious transfer protocol to obtain a random secret sharing and a sacrifice quintuple; the online unit performs full-threshold threshold signature processing according to the secret sharing of the private key and the message to obtain a digital signature corresponding to the message.