Multi-participant elliptic curve attack method and device and storage medium
Through the collision detection method of random walk and point sharing between participants, the problem of low private key solution of elliptic curve digital signature algorithm in multiple participants scenarios is solved, and efficient security evaluation and attack performance improvement is achieved.
Patent Information
- Application Number
- CN202510218032.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-26
AI Technical Summary
The existing elliptic curve digital signature algorithm is difficult to efficiently solve the private key in multiple participants scenarios, resulting in inefficient security evaluation.
Collision detection is carried out through random walks combined with point sharing between participants, and the calculation and security evaluation of the private keys of multiple participants are realized. The specific steps include randomly roaming the participant's public key to calculate the points and perform collision detection within the range of the point sequence calculated by the participant to solve the discrete logarithm and obtain the private key.
The efficiency of multi-participating elliptic curve attacks is significantly improved, the solution complexity is reduced, and the security evaluation efficiency of the elliptic curve digital signature algorithm is improved.
Smart Images

Figure CN120074793A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of encryption security verification, and in particular to an elliptic curve attack method for multiple parties. Background Art
[0002] The birth of blockchain technology has driven a new round of technological revolution in the computer field. This technology has characteristics such as being publicly transparent, tamper-proof, decentralized, and traceable, and is expected to be widely applied in fields such as digital currency, database storage, fintech, and the Internet of Things. As the underlying security cornerstone of blockchain technology, cryptographic primitives represented by digital signature algorithms play a crucial role in blockchain. Bitcoin and Ethereum mainly use the Elliptic Curve Digital Signature Algorithm (ECDSA) based on the elliptic curve secp256k1. When a transfer transaction occurs in the Bitcoin and Ethereum networks, the transaction initiator needs to use the private key of its Bitcoin wallet to sign the transaction, thereby proving the identity of the Bitcoin owner and preventing the transaction from being repudiated. Any scale of Bitcoin transaction depends on the ECDSA algorithm of the secp256k1 standard. The security of Bitcoin is equivalent to the security of the Bitcoin private key. Once the private key is leaked, the corresponding Bitcoin will be stolen. Even if it is known that the currency has been stolen, the illegal transaction cannot be reversed. Therefore, the research on Bitcoin key management has received great attention from the academic and industrial circles and has become a major research topic at present.
[0003] The security of the elliptic curve digital signature algorithm is based on the difficulty of solving the elliptic curve discrete logarithm problem (ECDLP). The elliptic curve digital signature algorithm is a digital signature system based on the discrete logarithm problem. At the same security level, the characteristic of a short signature length makes it widely adopted in many practical applications. The public key cryptosystem based on elliptic curves was first independently proposed by Koblitz and Miller in 1985. Given an elliptic curve E of order n defined over a finite field F p with rational points P, Q, the elliptic curve discrete logarithm problem is to find the smallest integer x such that Q = xP. For the general elliptic curve discrete logarithm problem, it can be solved by the baby-step giant-step algorithm, Pollard's lambda algorithm, and Pollard's Rho algorithm. Among them, the time complexity of Pollard's Rho algorithm is p When solving the discrete logarithm problem of the elliptic curve of u parties, the time complexity of u times of calling Pollard's Rho algorithm becomes Summary of the Invention
[0004] To solve the above technical problems or at least partially solve the above technical problems, the present invention provides a multi-party elliptic curve attack method, device, and storage medium.
[0005] In a first aspect, the present invention provides a multi-party elliptic curve attack method, including:
[0006] Multiple parties generate keys using the target elliptic curve digital signature algorithm based on independent random signature private keys to obtain the public keys Q of all parties i i ∈ [1, u], where u is the number of parties;
[0007] Collect the public keys Q of all parties i , i ∈ [1, u], and obtain the elliptic curve base point G of the elliptic curve digital signature algorithm;
[0008] The purpose of the attack is to solve the signature private keys k of all parties given the public keys of all parties and the elliptic curve base point of the elliptic curve digital signature algorithm i , and use random walk combined with point sharing among parties to perform collision detection to implement multi-party private key calculation, including:
[0009] For the public key Q of all parties i , i ∈ [1, u], for the public key Q of the first party 1 , randomly select a coefficient Using the current coefficient Public key Q 1 And base point G to calculate the point where Q 1 = k 1 G; continue to select a coefficient through random walk Using the current coefficient Public key Q 1 And base point G to calculate the point After each random walk calculates a point, perform collision detection within the range of the point sequence calculated by the first party. If a collision occurs, solve the discrete logarithm according to the collision result to obtain k 1 ; starting from the public key Q of the second party 2 , when performing collision detection, perform collision detection within the range of the point sequences calculated by the current party and all previous parties; when a collision occurs, solve the discrete logarithm according to the collision result to obtain k i , i ≥ 2.
[0010] Furthermore, the elliptic curves of the target elliptic curve digital signature algorithms adopted by all parties have the same base point and the same order.
[0011] Further, the key generation by multiple parties using the same elliptic curve digital signature algorithm based on independent random signature private keys includes:
[0012] Set the key generation for u parties. For party i ∈ [1, u], the following steps are taken to achieve key generation:
[0013] Randomly select an integer k i As the signature private key of the i-th party, where 1 ≤ k i ≤ n - 1; then Q i = k i G, k i ∈ {1, 2,..., n - 1}, Q i Represents the signature public key of the i-th party.
[0014] Further, in the case of the same parties, the security is judged according to the time required to solve all private keys. The shorter the required time, the lower the security.
[0015] Further, the random walk includes: performing a random walk collision through the Floyd algorithm:
[0016] Define the first pointer and the second pointer pointing to points. The first pointer updates the point and coefficients once according to the update formula in each iteration, and the second pointer updates the point and coefficients twice according to the update formula in each iteration. Starting from the initial coefficients and the initial point, the first pointer and the second pointer respectively update the point and coefficients until the first pointer and the second pointer point to the same point.
[0017] Further, the update formula is as follows:
[0018] In the elliptic curve group E(F p ) of the target elliptic curve digital signature algorithm, define the point R of any party i = a i Q + b i G, where Q = kG; where Q is the public key of any party and k is the private key of any party; a i b i Is the coefficient randomly selected by any party for the i-th time;
[0019] Divide E(F p ) into three non-interacting subgroups S 1 , S 2 , S 3 ,
[0020] Randomly select the initial values a i , b i of the coefficients a 0 , b0 , calculate the initial point \(R\) 0 = a 0 Q + b 0 G;
[0021] For the current point \(R\) i = a i Q + b i G, define the update according to the subgroup it belongs to as follows:
[0022] If \(R\) i \(\in S\) 1 , then \(R\) i+1 = R i + G, coefficient update: a i+1 = a i , b i+1 = b i + 1 (mod n);
[0023] If \(R\) i \(\in S\) 2 , then \(R\) i+1 = R i + Q, coefficient update: a i+1 = a i + 1 (mod n), b i+1 = b i ;
[0024] If \(R_i\in S\) 3 , then \(R_i+\) 1 = 2R_i, coefficient update: a i+1 = 2a i (mod n), b i+1 = 2b i (mod n).
[0025] Furthermore, when a collision occurs, let the collision result be \(a\) i Q + b i G = \(a\) 2i Q + b 2i G;
[0026] Also, since \(Q = kG\), substituting into the collision result gives:
[0027] (\(a\) i k + b i )G = (\(a\) 2i k + b 2i )G;
[0028] Because the order of the elliptic curve group is \(n\), i.e., \(nG = O\), where \(O\) is the infinite point, and the scalar coefficients on both sides are equal modulo \(n\), the following equation holds:
[0029] \(a\) i k + b i≡a 2i k + b 2i (mod n),
[0030] Transpose and rearrange to obtain a linear congruence equation for k:
[0031] b i -b 2i ≡ (a 2i -a i )k (mod n),
[0032] Solve for k using the linear congruence equation of k.
[0033] Furthermore, the process of solving for k using the linear congruence equation of k includes:
[0034] If (a 2i -a i ) and n are relatively prime, i.e., gcd((a 2i -a i ), n) = 1, then (a 2i -a i ) has an inverse modulo n, and k can be directly solved as:
[0035] k ≡ (b i -b 2i )(a 2i -a i ) -1 (mod n),
[0036] If (a 2i -a i ) and n are not relatively prime, gcd((a 2i -a i ), N) = d > 1, check whether d divides (b i -b 2i ). If not, there is no solution and the coefficients need to be randomly selected again. If so, the equation is simplified to: (b i -b 2i ) / d ≡ k((a 2i -a i ) / d) mod (n / d), and then find the inverse of (a 2i -a i ) / d to solve for k.
[0037] In a second aspect, the present invention provides a multi-party elliptic curve attack device, including: at least one processing unit, the processing unit is connected to a storage unit through a bus unit, the storage unit stores a computer program, and when the computer program is executed by the processing unit, the multi-party elliptic curve attack method as described above is implemented.
[0038] In a third aspect, the present invention provides a computer-readable storage medium storing a computer program, which when executed by a processor, implements the elliptic curve attack method for multiple parties as described above.
[0039] The above technical solutions provided by the embodiments of the present invention have the following advantages compared with the prior art:
[0040] The present invention uses a random walk combined with point sharing among parties to perform collision detection to realize the private key calculation of multiple parties. Specifically, for the public keys Q of all parties i , for the public key Q of the first party among Q 1 , randomly select a coefficient Using the current coefficient public key Q 1 and the base point G to calculate the point where, Q 1 = k 1 G; continue to select a coefficient through random walk Using the current coefficient public key Q 1 and the base point G to calculate the point After each random walk calculates a point, perform collision detection within the range of the point sequence calculated by the first party. If there is a collision, solve the discrete logarithm according to the collision result to obtain k 1 ; starting from the public key Q of the second party 2 , when performing collision detection, perform collision detection within the range of the point sequences calculated by the current party and all previous parties; when there is a collision, solve the discrete logarithm according to the collision result to obtain k i , i≥2. By dealing with the elliptic curve discrete logarithm problem of multiple parties (such as u parties), if the complexity of repeated solution u times is The complexity of using the multi-party solution technology is Therefore, the solution complexity is improved by times compared with multiple calls to Pollard's Rho algorithm, thereby improving the efficiency of the elliptic curve attack against multiple parties and making the security of the elliptic curve digital signature algorithm for multiple parties more efficient. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present invention and used together with the specification to explain the principles of the present invention.
[0042] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0043] Figure 1 It is a flowchart of a multi-party elliptic curve attack method provided by an embodiment of the present invention;
[0044] Figure 2 It is a schematic diagram of a network relationship diagram provided by an embodiment of the present invention;
[0045] Figure 3 It is a schematic diagram of a multi-party elliptic curve attack device provided by an embodiment of the present invention. Detailed implementation manners
[0046] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0047] It should be noted that in this article, the term "comprising", "including", or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article, or device. Without further limitations, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article, or device including the said element.
[0048] To clearly illustrate the solution of this application, first, the mathematical principle of the elliptic curve discrete logarithm problem will be described:
[0049] In the prime field F p , where p > 3, the elliptic curve is represented as:
[0050] E: y 2 = x 3 + ax + b;
[0051] Among them, a, b ∈ F p , and a, b satisfy the discriminant Δ = -16(4a 3 + 27b 3) ≠ 0, ensuring that the elliptic curve has no singular points; over the prime field F p On the elliptic curve E, a solution is a point (x, y), where x and y satisfy the equation y 2 = x 3 + ax + b. The elliptic curve group E(F p ) represents the set of all solutions of the elliptic curve E over the prime field F p along with the point at infinity O. The elliptic curve group E(F p ) forms an Abelian group.
[0052] Abelian group operation rules:
[0053] Identity element O of the Abelian group: satisfies (x, y) + O = O + (x, y) = (x, y);
[0054] Inverse element: The inverse of the point (x, y) is (x, -y), satisfying (x, y) + (x, -y) = O;
[0055] Point addition:
[0056] Point addition of the same point, i.e., doubling the point: (x, y) + (x, y) = (λ 2 - 2x, λ(x - λ 2 + 2x) - y), where:
[0057]
[0058] Point addition of different points: (x 1 , y 1 ) + (x 2 , y 2 ) = (μ 2 - x 1 - x 2 , μ(2x 1 - μ 2 + x 2 ) - y 1 ), where:
[0059]
[0060] Definition of the Elliptic Curve Discrete Logarithm Problem (ECDLP):
[0061] The inverse of a solution (x, y) is (x, -y), and (x, -y) is also a solution of the equation. Moreover, the result of the point addition of these two solution points is also a solution of the equation. Let the order of E(F p ) be N, and the base point P generates a cyclic subgroup , given another point Q on the elliptic curve, Q ∈ Find the value of the integer k such that Q = kP, where k ∈ {1, 2, …, N - 1}.
[0062] The difficulty of the elliptic curve discrete logarithm problem stems from the following characteristics of the elliptic curve group:
[0063] No sub - exponential time algorithm: Different from the discrete logarithm in finite fields, the most effective attack algorithm for the elliptic curve discrete logarithm problem currently (such as Pollard's Rho) has a time complexity of and requires exponential - level computing resources.
[0064] Complexity of group structure: The point operations in the elliptic curve group lack a linear structure, making it difficult to accelerate the solution through algebraic simplification.
[0065] According to the definition of the elliptic curve discrete logarithm problem, the security is affected by the order N: If the order N is a prime number or contains a large prime factor, the difficulty of the elliptic curve discrete logarithm problem is high. Generally, the order N is chosen to be a prime number or N = h·q, where q is a large prime number and h is a co - factor, and h is as small as possible (such as 1, 2, 4).
[0066] Embodiment 1
[0067] The technology of the present invention realizes a multi - party elliptic curve attack method, which supports the security analysis of the multi - user elliptic curve digital signature algorithm in the blockchain. By optimizing the multi - party elliptic curve discrete logarithm problem, the solution complexity is increased by times compared with multiple calls to the Pollard’s Rho algorithm, where u is the number of parties. Therefore, the attack performance of the multi - party - based elliptic curve attack method is more efficient, and the security evaluation of the elliptic curve discrete logarithm problem is more efficient.
[0068] As Figure 1 shown, the process of this application includes:
[0069] S100, Multiple parties generate keys using the same elliptic curve digital signature algorithm based on independent random signature private keys to obtain the public keys Q of all parties i where i ∈ [1, u] and u is the number of parties.
[0070] Set the key generation of u parties. The elliptic curve of the same elliptic curve digital signature algorithm applied by all parties is the same elliptic curve defined over the finite field F p with the same base point G and the same order n.
[0071] In the blockchain of Bitcoin, the elliptic curve applied for key generation is the elliptic curve secp256k1 defined over the finite field F p : y 2 = x 3 + 7, where p = 2 256 -2 32 -2 9 -2 8 -2 7 -2 6 -2 4 -1 is a prime number of 256 bits. The base point of the elliptic curve secp256k1 is G, and the order is n. secp256k1 refers to the elliptic curve used in Bitcoin public key cryptography and is defined in the Standards for Efficient Cryptography (SEC).
[0072] For participant i ∈ [1, u], the following steps are taken to implement key generation:
[0073] Randomly select an integer k i As the signature private key of the i-th participant, where 1 ≤ k i ≤ n - 1;
[0074] Then Q i = k i G, k i ∈ {1, 2,..., n - 1}, Q i represents the signature public key of the i-th participant.
[0075] The purpose of this application to attack and verify security is: Given all participants' Q i and G, solve k for all participants i . The shorter the time to obtain k for all participants i , the lower the security of the elliptic curve digital signature algorithm and the stronger the attack performance.
[0076] S200. Collect the public keys Q i of all participants, i ∈ [1, u], and obtain the base point G of the elliptic curve of the elliptic curve digital signature algorithm. Because the public keys of users on the blockchain are publicly available, after the u participants generate keys, u public keys Q i , i ∈ [1, u] can be collected from the blockchain.
[0077] S300. Use random walk combined with point sharing among participants to perform collision detection to achieve multi-participant private key calculation. As Figure 2 shown, the calculation process includes:
[0078] S301. For the public key Q i of the first participant among all participants' public keys Q 1 , i ∈ [1, u], randomly select a coefficient Use the current coefficient to calculate the public key Q 1 and the base point G to calculate the point where Q 1 = k 1 G;
[0079] After each calculation of the point, if the last set bits of the abscissa of the result are all 0, record the corresponding coefficient and point and
[0080] S302, iteratively continue to select the coefficient through random walk the current coefficient public key Q 1 and the base point G to calculate the point If the last set bits of the abscissa of the result are all 0, record the corresponding and
[0081] S303, after each random walk calculates the point, perform collision detection within the range of the point sequence calculated by the first party, and try to find that different coefficients point to the same point
[0082] S304, detect whether there is a collision. If there is no collision, execute S302.
[0083] S305, if there is a collision, set j > l, indicating that after the j-th random walk, the determined is the same as the one determined by the previous l-th random walk then the two corresponding points are: Stop the random walk, solve the discrete logarithm according to the collision result to obtain k 1 .
[0084] An example of random walk includes:
[0085] In the elliptic curve group E(F p ) of the target elliptic curve digital signature algorithm, define the point R of any party i = a i Q + b i G, where Q = kG; where Q is the public key of any party and k is the private key of any party; a i b i is the coefficient randomly selected by any party for the i-th time.
[0086] Divide E(F p ) into three non-interacting subgroups S 1 , S 2 , S 3 ,
[0087] Randomly select the coefficient a i , b i 's initial value a 0 , b 0 , calculate the initial point R 0 = a 0 Q + b 0 G;
[0088] For the current point R i = a i Q + b i G, define the update according to the subgroup it belongs to as follows:
[0089] If R i ∈ S 1 , then R i+1 = R i + G, coefficient update: a i+1 = a i , b i+1 = b i + 1 (mod n);
[0090] If Ri ∈ S 2 , then Ri + 1 = Ri + Q, coefficient update: a i+1 = a i + 1 (mod n), bi + 1 = bi;
[0091] If R i ∈ S 3 , then R i+1 = 2R i , coefficient update: a i+1 = 2a i (mod n), b i+1 = 2b i (mod n).
[0092] Perform random walk collision through the Floyd algorithm:
[0093] Define the first pointer and the second pointer. The first pointer updates the point once per iteration, and the second pointer updates the point twice per iteration. Starting from the initial coefficients and the initial point, the first pointer and the second pointer update the points respectively until the first pointer and the second pointer point to the same point. Set that at the i-th iteration, different coefficients correspond to the same point: R i = R 2i , a i Q + b i G = a 2i Q + b 2i G.
[0094] Solve the discrete logarithm according to the collision result:
[0095] Collision result a i Q + b i G = a 2i Q + b 2i G;
[0096] Also, since Q = kG, substituting into the collision result gives:
[0097] (a i k + b i )G = (a 2i k + b 2i )G;
[0098] Because the order of the elliptic curve group is n, i.e., nG = O, where O is the infinite point, and the scalar coefficients on both sides are equal modulo n, the following equation holds:
[0099] a i k + b i ≡ a 2i k + b 2i (mod n),
[0100] Moving terms and arranging gives a linear congruence equation for k:
[0101] b i - b 2i ≡ (a 2i - a i )k (mod n),
[0102] If (a 2i - a i ) is relatively prime to n, i.e., gcd((a 2i - a i ), n) = 1, then (a 2i - a i ) has an inverse modulo n, and we can directly solve for:
[0103] k ≡ (b i - b 2i )(a 2i - a i ) -1 (mod n),
[0104] If (a 2i - a i ) is not relatively prime to n, gcd((a 2i - a i ), N) = d > 1, we need to check if d divides (b i - b 2i ). If not, there is no solution and the algorithm needs to be run again. If so, the equation simplifies to: (b i - b 2i ) / d ≡ k((a 2i -a i ) / d) mod (n / d), and then find (a 2i -a i ) / d's multiplicative inverse to solve for k.
[0105] Steps S301 to S303 are for the first participant. Within the range of the point sequence calculated by the first participant, find the collision point through random walk, thereby establishing an equation to solve for k 1 .
[0106] S306. Share the point sequences of all current participants with subsequent participants. For example, the point sequence of the first participant needs to be contributed to the second participant to the last participant, the point sequence of the second participant needs to be contributed to the third participant to the last participant, and so on.
[0107] S307. Starting from the public key Q of the second participant 2 , compared with the calculation process of the first participant, when performing collision detection, perform collision detection within the range of the point sequences calculated by the current participant and all previous participants.
[0108] For example, for the public key Q of the second participant 2 :
[0109] Randomly select a coefficient Calculate the point
[0110] Detect whether there is a result in the range of the point sequence calculated by the first participant that is the same as ;
[0111] If not, on the one hand, record the point calculated by the second participant If the last set bits of the abscissa of the result are all 0, record the corresponding and On the other hand, continue to randomly select a coefficient through random walk Calculate the point
[0112] If there is, stop the random walk and solve for the discrete logarithm according to the collision result to obtain k 2 .
[0113] Starting from the second calculation point of the second participant, the points calculated by the second participant form a sequence; after each random walk calculates a point, detect whether there is a result in the range of the point sequences calculated by the second participant and the first participant before it that is the same as the current calculated point.
[0114] If or , then Q can be solved 2 Obtain the private key \(k\) of the discrete logarithm 2 . Assume that during the calculation process, collisions may occur between different participating parties, and collisions may also occur within the point sequence of the same participating party, that is is the same as the point in the point sequence calculated by the first participating party or is the same as the previous point sequence calculated by the second participating party . If then there is a cross-party collision equation, and thus the private key \(k\) of the second participating party's public key \(Q\) can be solved 2 . For example, assume 2 then there is . Here is the coefficient corresponding to the point in the point sequence calculated by the first participating party is the coefficient corresponding to the point in the point sequence calculated by the second participating party. Substitute \(Q\) 1 = \(k\) 1 \(G\) and \(Q\) 2 = \(k\) 2 \(G\), and we get That is Therefore, the equation can be obtained: At this time, since \(k\) 1 is already known, then the above equation is an equation about \(k\) 2 and can be used to solve for \(k\) 2 .
[0115] And so on, until the discrete logarithms of all participating parties are solved, and thus the private keys \(k\) of all participating parties are obtained i .
[0116] When performing security judgment, in the case of the same participating party, the security is judged according to the time required to solve all private keys. The shorter the required time, the lower the security
[0117] The process of calculating the private keys of multiple participating parties in the present invention includes: for the public keys \(Q\) of all participating parties i , the public key \(Q\) of the first participating party in \(i\in[1, u]\) 1 , randomly select the coefficient Use the current coefficient public key \(Q\) 1 and the base point \(G\) to calculate the point . Among them, \(Q\) 1 = \(k\) 1 \(G\); continue to select the coefficient by random walk and use the current coefficient public key \(Q\) 1 and the base point \(G\) to calculate the point After each random walk calculation point, collision detection is performed within the range of the point sequence calculated by the first participant. If a collision occurs, the discrete logarithm is solved according to the collision result to obtain k 1 ; starting from the public key Q of the second participant 2 When performing collision detection, collision detection is performed within the range of the point sequences calculated by the current participant and all previous participants; when a collision occurs, the discrete logarithm is solved according to the collision result to obtain k i , i≥2. By dealing with the elliptic curve discrete logarithm problem of multiple participants (such as u participants), if the complexity of repeated solution u times is The complexity of using the multi-participant solution technology is Therefore, the solution complexity is improved by times, thereby improving the efficiency of the elliptic curve attack against multiple participants and making the security of the elliptic curve digital signature algorithm for multiple participants more efficient. By reusing the cross-participant point sequences in collision detection, the complexity is significantly reduced.
[0118] Embodiment 2
[0119] Refer to Figure 3 As shown, the embodiment of the present invention provides a multi-participant elliptic curve attack device, including: at least one processing unit, the processing unit is connected to the storage unit through a bus unit, and the storage unit is used as a computer-readable storage medium, which can be used to store software programs, computer-executable programs, and modules, such as the software programs, computer-executable programs, and modules corresponding to a multi-participant elliptic curve attack method in the embodiment of the present invention. The processing unit realizes the above-mentioned multi-participant elliptic curve attack method by running the software programs, computer-executable programs, and modules stored in the storage unit, including:
[0120] Multiple participants use the target elliptic curve digital signature algorithm based on independent random signature private keys to generate keys to obtain the public keys Q of all participants i i∈[1, u], where u is the number of participants;
[0121] Collect the public keys Q of all participants i , i∈[1, u], and obtain the elliptic curve base point G of the elliptic curve digital signature algorithm;
[0122] The purpose of the attack is to solve the signature private keys k of all participants under the condition of knowing the public keys of all participants and the elliptic curve digital signature algorithm base point i , and the process of calculating the multi-participant private key includes:
[0123] For the public keys Q of all participants i , the public key Q of the first participant among i∈[1, u] 1 , randomly select coefficients Use the current coefficients public key Q 1 and the base point G to calculate the point where Q 1 = k 1 G; continue to select coefficients through random walk Use the current coefficients public key Q 1 and the base point G to calculate the point After calculating the point for each random walk, perform collision detection within the range of the point sequence calculated by the first participant. If there is a collision, solve the discrete logarithm according to the collision result to obtain k 1 ; starting from the public key Q 2 of the second participant, when performing collision detection, perform collision detection within the range of the point sequence calculated by the current participant and all previous participants; when there is a collision, solve the discrete logarithm according to the collision result to obtain k i , i≥2.
[0124] Of course, the computer program stored in the storage unit of the device for implementing the multi-party elliptic curve attack method provided by the embodiments of the present invention is not limited to the method operations described above, and can also execute the related operations in the multi-party elliptic curve attack method provided by any embodiment of the present invention.
[0125] Embodiment 3
[0126] The embodiments of the present invention provide a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed, the multi-party elliptic curve attack method is implemented, including:
[0127] Multiple participants use the target elliptic curve digital signature algorithm based on independent random signature private keys to generate keys to obtain the public keys Q i i∈[1, u], where u is the number of participants;
[0128] Collect the public keys Q i of all participants, i∈[1, u], and obtain the elliptic curve base point G of the elliptic curve digital signature algorithm;
[0129] The purpose of the attack is to solve the signature private keys k i of all participants given the public keys of all participants and the elliptic curve base point of the elliptic curve digital signature algorithm. The process of calculating the multi-party private keys includes:
[0130] For the public key Q i of the first participant among all participants' public keys Q 1 , randomly select coefficients Using the current coefficients public key Q 1 and the base point G to calculate the point where Q 1 = k 1 G; continue to select coefficients through random walks Using the current coefficients public key Q 1 and the base point G to calculate the point After each random walk calculates the point, collision detection is performed within the range of the point sequence calculated by the first participant. If there is a collision, the discrete logarithm is solved according to the collision result to obtain k 1 ; starting from the public key Q 2 of the second participant, when performing collision detection, collision detection is performed within the range of the point sequences calculated by the current participant and all previous participants; when there is a collision, the discrete logarithm is solved according to the collision result to obtain k i , i ≥ 2.
[0131] A computer-readable storage medium provided by an embodiment of the present invention, the computer program stored therein is not limited to the method operations as described above, and can also execute the relevant operations in a multi-party elliptic curve attack method provided by any embodiment of the present invention.
[0132] In the embodiments provided by the present invention, it should be understood that the disclosed structures and methods can be implemented in other ways. For example, the structural embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces, indirect coupling or communication connection of structures or units, and can be in electrical, mechanical or other forms.
[0133] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0134] In addition, the functional units in each embodiment of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0135] The above are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features claimed herein.
Claims
1. A multi-party elliptic curve attack method, characterized in that: include: Multiple participants use the target elliptic curve digital signature algorithm to generate keys based on independent random signature private keys to obtain the public keys Q of all participants. i i∈[1,u], u is the number of participants; Collect the public keys Q of all participants i , i∈[1,u], obtain the elliptic curve base point G of the elliptic curve digital signature algorithm; The purpose of the attack is to solve the signature private key k of all participants when the public keys of all participants and the base point of the elliptic curve digital signature algorithm are known. i , using random walk combined with point sharing between participants to perform collision detection to achieve multi-party private key calculation, including: Public keys Q for all participants i , the public key Q1 of the first participant in i∈[1,u], and the randomly selected coefficient Using the current coefficients Public key Q1 and base point G to calculate the point Among them, Q1=k1G; continue to select coefficients through random walk Using the current coefficient Public key Q1 and base point G to calculate the point After each random walk calculates a point, a collision check is performed within the point sequence calculated by the first participant. If a collision occurs, the discrete logarithm is solved based on the collision result to obtain k1. Starting from the public key Q2 of the second participant, when performing a collision check, a collision check is performed within the point sequence calculated by the current participant and all the previous participants. If a collision occurs, the discrete logarithm is solved based on the collision result to obtain k. i ,i≥2.
2. The multi-party elliptic curve attack method according to claim 1, characterized in that: The elliptic curves of the target elliptic curve digital signature algorithm adopted by all participants have the same base point and the same order.
3. The multi-party elliptic curve attack method according to claim 1, characterized in that: Multiple parties use the same elliptic curve digital signature algorithm to generate keys based on independent random signature private keys, including: Assume u participants to generate keys. For participant i∈[1,u], perform the following steps to implement key generation: Randomly select an integer k i As the signature private key of the i-th participant, where 1≤k i ≤n-1; then Q i =k i G,k i ∈{1,2,...,n-1}, Q i Represents the signature public key of the i-th participant.
4. The multi-party elliptic curve attack method according to claim 1, characterized in that: In the case of the same participants, security is judged based on the time required to solve all private keys. The shorter the time required, the lower the security.
5. The multi-party elliptic curve attack method according to claim 1, characterized in that: The random walk includes: performing random walk collision by Floyd algorithm: Define a first pointer and a second pointer pointing to a point. The first pointer updates the point and coefficient once according to the update formula in each iteration. The second pointer updates the point and coefficient twice according to the update formula in each iteration. Starting from the initial coefficient and the initial point, the first pointer and the second pointer update the point and coefficient respectively until the first pointer and the second pointer point to the same point.
6. The multi-party elliptic curve attack method according to claim 5, characterized in that: The update formula is as follows: In the elliptic curve group E(F p ), define the point R of any participant i =a i Q+b i G, where Q = kG; where Q is the public key of any participant and k is the private key of any participant; a i b i is the random coefficient of any participant for the i-th time; E(F p ) is divided into three non-interacting subgroups S1, S2, and S3 of similar size according to the coordinate modulo 3 method. Random selection coefficient a i ,b i The initial value of a 0 ,b 0 , calculate the initial point R 0 =a 0 Q+b 0 G; For the current point R i =a i Q+b i G, the definition is updated as follows according to the subgroup it belongs to: If R i ∈S1, then R i+1 =R i +G, coefficient update: a i+1 =a i , b i+1 =b i +1(modn); If R i ∈S2, then R i+1 =R i +Q, coefficient update: a i+1 =a i +1(mod n), b i+1 =b i ; If R i ∈S3, then R i+1 =2R i , coefficient update: a i+1 =2a i (mod n), b i+1 =2b i (mod n).
7. The multi-party elliptic curve attack method according to claim 5, characterized in that: When a collision occurs, let the collision result be a i Q+b i G = a 2i Q+b 2i G; And Q = kG, substituting the collision result into: (a i k+b i )G=(a 2i k+b 2i )G; Since the order of the elliptic curve group is n, that is, nG = O, O is the point at infinity, and the scalar coefficients on both sides are equal under the modulus n, the following equation holds: a i k+b i ≡a 2i k+b 2i (mod n), By transposing the terms, we can get the linear congruential equation of k: b i -b 2i ≡(a 2i -a i )k(mod n), Use the linear congruential equation for k to solve for k.
8. The multi-party elliptic curve attack method according to claim 7, characterized in that: The process of solving k using its linear congruential equation includes: If (a 2i -a i ) is relatively prime to n, that is, gcd((a 2i -a i ),n)=1, then (a 2i -a i ) has an inverse under the modulo n, and can be solved directly: k≡(b i -b 2i (the) 2i -a i ) -1 (modern), If (a 2i -a i ) and n are not coprime, gcd((a 2i -a i ),N)=d>1, check whether d is divisible by (b i -b 2i ), if not, there is no solution and the random coefficients need to be re-set. If so, the equation is simplified to: (b i -b 2i ) / d≡k((a 2i -a i ) / d)mod(n / d), then find (a 2i -a i ) / d and solve for k.
9. A multi-party elliptic curve attack device, characterized in that: include: At least one processing unit, the processing unit is connected to a storage unit via a bus unit, the storage unit stores a computer program, and when the computer program is executed by the processing unit, the multi-participant elliptic curve attack method as described in any one of claims 1-8 is implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the multi-party elliptic curve attack method as described in any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Method and device for attacking elliptic curve signature algorithm, equipment and storage medium
CN115473649A
Cryptographic key analysis method, cryptographic key analyzer, and cryptographic key analysis program
JP2012010039A