Key generation method and system between two terminals and electronic equipment
By generating public and secret polynomials based on exclusive OR operation and hash compression operation between the two terminals, and determining the public key and intermediate public key, the problems of low efficiency and high risk of information signature caused by the large number of data transmissions in the prior art are solved, and a more efficient and secure signature process is achieved.
Patent Information
- Application Number
- CN202510203811.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-02-24
AI Technical Summary
In the prior art, the information signature efficiency caused by the large number of data transmissions is low, and the risk of information being tampered with or stolen is high.
Each terminal obtains a public random seed based on the exclusive OR operation, performs hash compression operation to obtain public and secret polynomials, determines the public key and the intermediate public key, reduces the number of data transmissions and improves the security of signatures.
It effectively ensures the confidentiality and security of the negotiated public and private keys. Compared with conventional data encryption transmission and decryption operations, it reduces the number of data transmissions and improves the security of signatures.
Smart Images

Figure CN120128322A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of quantum cryptography, and in particular, to a key generation method, system, and electronic device for between two terminals. Background Art
[0002] Digital signature is an important part of the public-key cryptosystem, which has the functions of ensuring the authenticity, integrity, and non-repudiation of digital information, and is widely used in other fields that require information security guarantee such as e-commerce, software distribution, and email. With the popularity of mobile office and remote work, the demand for secure digital signatures on mobile devices by users is increasing continuously. However, in mobile devices such as mobile phones and tablets, there is usually a lack of dedicated hardware cryptographic modules to store secret information such as the user's private key, resulting in attackers being able to easily obtain the signature private key stored in the local device, making the security of signing on mobile devices unable to be guaranteed.
[0003] With the development of quantum computing technology, traditional cryptographic algorithms are facing unprecedented security threats. Traditional public-key encryption algorithms such as the RSA algorithm and the ECC algorithm (Elliptic Curve Cryptography) rely on the computational complexity of mathematical problems such as large integer factorization and discrete logarithm. However, the Shor quantum algorithm can efficiently solve the above difficult problems in polynomial time, thus posing a severe challenge to the security of the existing public-key encryption system. In the prior art, a trusted device is used as a third party to achieve secure communication between two terminals, but this technology requires multiple rounds of communication processes among the three parties to determine each other's identities and encrypt the information transmission, resulting in low information signature efficiency. At the same time, the interaction complexity of the three-party communication will also increase the risk of information being tampered with or stolen. Summary of the Invention
[0004] The present invention provides a key generation method, system, and electronic device for between two terminals, to solve the problems of low information signature efficiency and high risk of information being tampered with or stolen caused by a large number of data transmission times in the prior art.
[0005] An embodiment of this specification provides a key generation method for between two terminals, which is applied to any one of the terminals. The method includes:
[0006] Each terminal obtains a common random seed based on the exclusive OR operation of the random seeds provided by the two terminals shared through mutual interaction;
[0007] Based on the common random seed, a hash compression operation is performed to obtain a common polynomial, and based on the random seeds provided by each terminal, a hash compression operation is performed to obtain a secret polynomial;
[0008] Each terminal determines the public key of each terminal based on the common polynomial and the secret polynomial within the corresponding terminal. Each terminal obtains the intermediate public key based on the exclusive OR operation of the public keys of two terminals shared through two-party interaction.
[0009] Perform a hash operation on the basis of the common random seed and the intermediate public key to obtain the compressed public key.
[0010] Determine that the common random seed and the intermediate public key together are the negotiated public key of any terminal; determine that the common random seed, the compressed public key, the random number parameters provided by each terminal, the secret polynomial corresponding to each terminal, and the public key corresponding to the other terminal are the private key of any terminal.
[0011] Optionally, each terminal obtains the common random seed based on the exclusive OR operation of the random seeds provided by two terminals shared through two-party interaction, including:
[0012] Verify the credibility of the random seeds provided by each terminal.
[0013] Optionally, the verification of the credibility of the random seeds provided by each terminal includes:
[0014] For one selected terminal of the two terminals as the target terminal and the other terminal as the cooperating terminal;
[0015] Perform a hash commitment operation on the random seed provided by the target terminal within the target terminal to obtain the target commitment value; and send the random seed and the target commitment value of the target terminal to the cooperating terminal;
[0016] Perform a hash commitment operation on the random seed provided by the target terminal within the cooperating terminal to obtain the comparison commitment value;
[0017] When the target commitment value is consistent with the comparison commitment value, the random seed provided by the target terminal is credible.
[0018] Optionally, the verification of the credibility of the random seeds provided by each terminal further includes:
[0019] For one selected terminal of the two terminals as the target terminal and the other terminal as the cooperating terminal;
[0020] Perform a hash commitment operation on the random seed provided by the target terminal within the cooperating terminal to obtain the target commitment value; and send the random seed and the target commitment value of the cooperating terminal to the target terminal;
[0021] Perform a hash commitment operation on the random seed provided by the cooperating terminal within the target terminal to obtain the comparison commitment value;
[0022] When the target commitment value is consistent with the comparison commitment value, the random seed provided by the cooperating terminal is credible.
[0023] Optionally, each of the terminals obtains an intermediate public key based on the exclusive OR operation of the public keys of the two terminals shared through mutual interaction, including:
[0024] Verify the trustworthiness of the public keys provided by each terminal.
[0025] Optionally, the verification of the trustworthiness of the public keys provided by each terminal includes:
[0026] For any one of the two terminals selected as the target terminal, the other terminal is the cooperating terminal;
[0027] Perform a hash commitment operation on the public key provided by the target terminal within the target terminal to obtain a target commitment value; and send the public key and the target commitment value of the target terminal to the cooperating terminal;
[0028] Perform a hash commitment operation on the public key provided by the target terminal within the cooperating terminal to obtain a comparison commitment value;
[0029] When the target commitment value is consistent with the comparison commitment value, the public key provided by the target terminal is trustworthy.
[0030] Optionally, the verification of the trustworthiness of the public keys provided by each terminal further includes:
[0031] For any one of the two terminals selected as the target terminal, the other terminal is the cooperating terminal;
[0032] Perform a hash commitment operation on the public key provided by the cooperating terminal within the cooperating terminal to obtain a target commitment value; and send the public key and the target commitment value of the cooperating terminal to the target terminal;
[0033] Perform a hash commitment operation on the public key provided by the target terminal within the target terminal to obtain a comparison commitment value;
[0034] When the target commitment value is consistent with the comparison commitment value, the public key provided by the cooperating terminal is trustworthy.
[0035] An embodiment of the present specification provides a key generation system for between two terminals, characterized by including a target terminal and a cooperating terminal, and the system includes:
[0036] The target terminal and the cooperating terminal obtain a common random seed based on the exclusive OR operation of the random seeds provided by the two terminals shared through mutual interaction;
[0037] The target terminal and the cooperating terminal perform a hash compression operation based on the common random seed to obtain a common polynomial, and perform a hash compression operation based on the random seeds provided by each terminal to obtain the secret polynomial of each terminal;
[0038] The target terminal and the cooperating terminal determine the public keys of each terminal based on a common polynomial and the secret polynomials within the corresponding terminals. Each terminal obtains an intermediate public key based on the exclusive OR operation of the public keys of the two terminals shared through mutual interaction.
[0039] The target terminal and the cooperating terminal respectively perform a hash operation based on the common random seed and the intermediate public key to obtain the compressed public keys of each terminal.
[0040] The target terminal and the cooperating terminal determine that the common random seed and the intermediate public key together are the negotiated public key for the two terminals. The target terminal determines the common random seed, the compressed public key, the random number parameter provided by the target terminal, the secret polynomial corresponding to the target terminal, and the public key corresponding to the cooperating terminal as the private key of the target terminal. The cooperating terminal determines the common random seed, the compressed public key, the random number parameter provided by the cooperating terminal, the secret polynomial corresponding to the cooperating terminal, and the public key corresponding to the target terminal as the private key of the cooperating terminal.
[0041] An electronic device includes a memory and a processor. Computer instructions are stored in the memory, and the processor is configured to run the computer instructions to execute the method described above.
[0042] A storage medium stores computer instructions, and the computer instructions are configured to execute the method described above when running.
[0043] The beneficial effects are as follows: In this application, since the common random seed is obtained based on the exclusive OR operation of the random seeds provided by the two terminals, and the intermediate public key is obtained based on the exclusive OR operation of the public keys of the two terminals shared through mutual interaction, it effectively ensures the confidentiality and security of the negotiated public key and the private key determined by the common random seed and the intermediate public key. Compared with the conventional data encryption, transmission, and decryption operations, it reduces the number of data transmissions and improves the security of signatures. Description of the Drawings
[0044] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0045] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0046] Figure 1 It is a flowchart of a key generation method for two terminals provided by an embodiment of this specification.
[0047] Figure 2A schematic diagram of the public key and private key generation process for key generation between two terminals provided by the embodiments of this specification;
[0048] Figure 3 A schematic diagram of the signature generation process for two terminals provided by the embodiments of this specification;
[0049] Figure 4 A structural diagram of a key generation system for two terminals provided by the embodiments of this specification;
[0050] Figure 5 A schematic diagram of the structure of an electronic device provided by the embodiments of this specification;
[0051] Figure 6 A schematic diagram of the principle of a computer-readable medium provided by the embodiments of this specification. Detailed implementation manners
[0052] The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0053] The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0054] It should be noted that: unless otherwise specifically stated, the relative arrangements, numerical expressions, and values of the components and steps set forth in these embodiments do not limit the scope of the present invention.
[0055] The following description of at least one exemplary embodiment is merely illustrative in nature and in no way serves as a limitation on the present invention or its application or use.
[0056] Technologies, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, such technologies, methods, and devices should be regarded as part of the specification.
[0057] In all the examples shown and discussed here, any specific value should be construed as merely exemplary and not as a limitation. Therefore, other examples of the exemplary embodiments may have different values.
[0058] It should be noted that: like reference numerals and letters denote like items in the following drawings, and thus, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.
[0059] Refer to Figure 1A schematic diagram of the key generation principle for two terminals provided by the embodiments of this specification, including: S101: Each terminal obtains a common random seed based on the exclusive OR operation of the random seeds provided by the two terminals shared through mutual interaction between the two parties; S102: A common polynomial is obtained through hash compression operation based on the common random seed, and a secret polynomial is obtained through hash compression operation based on the random seeds provided by each terminal; S103: Each terminal determines the public key of each terminal based on the common polynomial and the secret polynomial in the corresponding terminal, and each terminal obtains an intermediate public key based on the exclusive OR operation of the public keys of the two terminals shared through mutual interaction between the two parties; S104: A compressed public key is obtained through hash operation based on the common random seed and the intermediate public key; S105: It is determined that the common random seed and the intermediate public key together are the negotiated public key of any terminal; it is determined that the common random seed, the compressed public key, the random number parameters provided by each terminal, the secret polynomial corresponding to each terminal, and the public key corresponding to the other terminal are the private key of any terminal.
[0060] Among them, the step that each terminal obtains a common random seed based on the exclusive OR operation of the random seeds provided by the two terminals shared through mutual interaction between the two parties includes: verifying the credibility of the random seeds provided by each terminal. Specifically: For one of the two terminals selected as the target terminal and the other as the cooperating terminal; perform a hash commitment operation on the random seed provided by the target terminal in the target terminal to obtain a target commitment value; and send the random seed and the target commitment value of the target terminal to the cooperating terminal; perform a hash commitment operation on the random seed provided by the target terminal in the cooperating terminal to obtain a comparison commitment value; when the target commitment value is consistent with the comparison commitment value, the random seed provided by the target terminal is credible; For one of the two terminals selected as the target terminal and the other as the cooperating terminal; perform a hash commitment operation on the random seed provided by the target terminal in the cooperating terminal to obtain a target commitment value; and send the random seed and the target commitment value of the cooperating terminal to the target terminal; perform a hash commitment operation on the random seed provided by the cooperating terminal in the target terminal to obtain a comparison commitment value; when the target commitment value is consistent with the comparison commitment value, the random seed provided by the cooperating terminal is credible.
[0061] In an alternative embodiment, such as Figure 2As shown in the figure, taking the target terminal and the cooperating terminal as examples, the target terminal performs a hash commitment operation on the first random seed ρ1 of the public polynomial provided by the target terminal to obtain a target commitment value h1; and sends the target commitment value h1 to the cooperating terminal; then, the target terminal sends the first random seed ρ1 to the cooperating terminal, and the cooperating terminal performs a hash commitment operation on the first random seed ρ1 to obtain a comparison standard commitment value h2. When the comparison standard commitment value h2 is the same as the target commitment value h1, it indicates that the first random seed ρ1 sent by the target terminal to the cooperating terminal has not been tampered with, and the first random seed ρ1 provided by the target terminal is trustworthy; similarly, the cooperating terminal performs a hash commitment operation on the second random seed ρ2 of the public polynomial provided by the cooperating terminal to obtain a target commitment value h3; and sends the target commitment value h3 to the target terminal; then, the cooperating terminal sends the second random seed ρ2 to the target terminal, and the target terminal performs a hash commitment operation on the second random seed ρ2 to obtain a comparison standard commitment value h4. When the comparison standard commitment value h4 is the same as the target commitment value h3, it indicates that the second random seed ρ2 sent by the cooperating terminal to the target terminal has not been tampered with, and the second random seed provided by the cooperating terminal is trustworthy; thereby improving the security of the public and private keys generated by both ends.
[0062] Optionally, each terminal obtains an intermediate public key based on the exclusive OR operation of the public keys of the two terminals shared through mutual interaction between the two parties, and further includes: verifying the trustworthiness of the public keys provided by each terminal. Specifically, it includes: taking any one of the two terminals as the target terminal and the other terminal as the cooperating terminal; performing a hash commitment operation on the public key provided by the target terminal in the target terminal to obtain a target commitment value; and sending the public key and the target commitment value of the target terminal to the cooperating terminal; performing a hash commitment operation on the public key provided by the target terminal in the cooperating terminal to obtain a comparison commitment value; when the target commitment value is the same as the comparison standard commitment value, the public key provided by the target terminal is trustworthy. Taking any one of the two terminals as the target terminal and the other terminal as the cooperating terminal; performing a hash commitment operation on the public key provided by the cooperating terminal in the cooperating terminal to obtain a target commitment value; and sending the public key and the target commitment value of the cooperating terminal to the target terminal; performing a hash commitment operation on the public key provided by the target terminal in the target terminal to obtain a comparison commitment value; when the target commitment value is the same as the comparison standard commitment value, the public key provided by the cooperating terminal is trustworthy.
[0063] In an alternative embodiment, as Figure 2As shown, taking the target terminal and the cooperating terminal as examples, the target terminal performs an exclusive OR operation on the first random seed ρ1 and the second random seed ρ2 to obtain a common random seed ρ, and performs a hash compression operation on the common random seed ρ, that is, performs a Keccak operation and uniform sampling on the common random seed ρ to obtain the common polynomial A, and performs a hash compression operation on the random seed ρ1' of the secret polynomial provided by the target terminal, that is, performs a Keccak operation and uniform sampling on the random seed ρ1' to obtain the first secret polynomial s1_s and the second secret polynomial s2_s; then, the target terminal determines the first public key t_s according to the common polynomial A, the first secret polynomial s1_s, and the second secret polynomial s2_s, that is, calculates t_s = As1_s + s2_s using the formula t = As1 + s2, and performs a hash commitment operation on the first public key t_s to obtain the target commitment value h5; and sends the target commitment value h5 to the cooperating terminal; finally, the target terminal sends the first public key t_s to the cooperating terminal, and the cooperating terminal performs a hash commitment operation on the first public key t_s to obtain a comparison commitment value h6. When the comparison commitment value h6 is the same as the target commitment value h5, it indicates that the first public key t_s sent by the target terminal to the cooperating terminal has not been tampered with, and the first public key t_s provided by the target terminal is trustworthy; similarly, the cooperating terminal performs an exclusive OR operation on the second random seed ρ2 and the first random seed ρ1 to obtain the common random seed ρ, and performs a hash compression operation on the common random seed ρ, that is, performs a Keccak operation and uniform sampling on the common random seed ρ to obtain the common polynomial A, and performs a hash compression operation on the random seed ρ2' of the secret polynomial provided by the cooperating terminal, that is, performs a Keccak operation and uniform sampling on the random seed ρ2' to obtain the third secret polynomial s1_h and the fourth secret polynomial s2_h; then, the cooperating terminal determines the second public key t_h according to the common polynomial A, the third secret polynomial s1_h, and the fourth secret polynomial s2_h, that is, calculates t_h = As1_h + s2_h using the formula t = As1 + s2, and performs a hash commitment operation on the second public key t_h to obtain the target commitment value h7; and sends the target commitment value h6 to the target terminal; finally, the cooperating terminal sends the second public key t_h to the target terminal, and the target terminal performs a hash commitment operation on the second public key t_h to obtain a comparison commitment value h8. When the comparison commitment value h8 is the same as the target commitment value h7, it indicates that the second public key t_h sent by the cooperating terminal to the target terminal has not been tampered with, and the second public key t_h provided by the cooperating terminal is trustworthy; thus, further enhancing the security of the public and private keys generated by both ends.
[0064] Then, the target terminal performs an exclusive OR operation on the first public key t_s and the second public key t_h to obtain an intermediate public key t, and performs a hash operation on the common random seed ρ and the intermediate public key t to obtain a compressed public key tr, and determines that the common random seed ρ and the intermediate public key t together are the negotiated public key (ρ, t) of the target terminal; the target terminal determines that the common random seed ρ, the compressed public key tr, the random number parameter K1 provided by the target terminal, the secret polynomials s1_s and s2_s corresponding to the target terminal, and the public key t_h corresponding to the cooperating terminal are the private key (ρ, tr, K1, s1_s, s2_s, t_h) of the target terminal; similarly, the cooperating terminal performs an exclusive OR operation on the first public key t_s and the second public key t_h to obtain an intermediate public key t, and performs a hash operation on the common random seed ρ and the intermediate public key t to obtain a compressed public key tr, and determines that the common random seed ρ and the intermediate public key t together are the negotiated public key (ρ, t) of the cooperating terminal; the cooperating terminal determines that the common random seed ρ, the compressed public key tr, the random number parameter K2 provided by the cooperating terminal, the secret polynomials s1_h and s2_h corresponding to the cooperating terminal, and the public key t_s corresponding to the target terminal are the private key (ρ, tr, K2, s1_h, s2_h, t_s) of the cooperating terminal. Through the above method, the security of the negotiated public key and private key in any terminal is greatly improved. Taking one terminal as the signer, the signer can use the negotiated public key to sign the message to be signed. Taking the other terminal as the verifier, the verifier uses the private key to verify the message to be signed that has been signed, realizing the secure transmission of the message to be signed.
[0065] Optionally, a commitment key is obtained by performing a hash operation on the information to be signed and a target public key including the public key information of the two terminals.
[0066] In an alternative embodiment, the target terminal performs a hash operation on the message M to be signed and the target public key T to obtain a commitment secret key ck; similarly, the cooperating terminal performs a hash operation on the message M to be signed and the target public key T to obtain a commitment secret key ck, where the target public key of the public key information of the two terminals is one of the compressed public key tr, the common random seed ρ, and the intermediate public key t. When the target seed is the compressed public key tr, the information contained is more and more secure. Therefore, it is best when the target seed is the compressed public key tr.
[0067] Optionally, the result of the homomorphic hash commitment operation on the intermediate commitment value is encrypted using the commitment key to obtain an initial commitment value to be verified; specifically: a homomorphic hash commitment operation is performed on the random number provided by the terminal and the intermediate commitment value to obtain an intermediate result; the intermediate result is encrypted using the commitment key to obtain an initial commitment value to be verified. Among them, the intermediate commitment value is obtained by performing a signature calculation on the terminal private key. Specifically: a hash operation is performed on the random number parameter stored in the terminal private key to obtain a secret value; a signature calculation is performed on the secret value based on the public polynomial.
[0068] In an alternative embodiment, as Figure 3 shown, taking the target terminal and the cooperating terminal as examples, the target terminal performs a hashing operation on the random number parameter K1 and the preset initial count value in the private key (ρ, tr, K1, s1_s, s2_s, t_h) of the target terminal to obtain a fixed-length random seed, and performs a Keccak operation and uniform sampling on the fixed-length random seed to obtain a secret value y1. Then, based on the public polynomial A, a signature calculation is performed on the secret value y1 to obtain an intermediate commitment value w1; where the signature calculation formula is w1 = Ay1. Finally, the target terminal performs a homomorphic hash commitment operation on the random number rand1 provided by the target terminal and the intermediate commitment value w1 to obtain an intermediate result, and encrypts the intermediate result using the commitment key ck to obtain an initial commitment value to be verified com1, where com1 = Commit(w1, rand1, ck); similarly, the cooperating terminal performs a hashing operation on the random number parameter K2 and the preset initial count value in the private key (ρ, tr, K2, s1_h, s2_h, t_s) of the cooperating terminal to obtain a fixed-length random seed, and performs a Keccak operation and uniform sampling on the fixed-length random seed to obtain a secret value y2. Then, based on the public polynomial A, a signature calculation is performed on the secret value y2 to obtain an intermediate commitment value w2; where the signature calculation formula is w2 = Ay2. Finally, the cooperating terminal performs a homomorphic hash commitment operation on the random number rand2 provided by the cooperating terminal and the intermediate commitment value w2 to obtain an intermediate result, and encrypts the intermediate result using the commitment key ck to obtain an initial commitment value to be verified com2, where com2 = Commit(w2, rand2, ck); the randomness of the intermediate result is improved by performing a homomorphic hash commitment operation on the random number rand1 and the intermediate commitment value w1 to obtain an intermediate result and by performing a homomorphic hash commitment operation on the random number rand2 and the intermediate commitment value w2 to obtain an intermediate result, enhancing the signature security of the subsequent message to be signed.
[0069] Optionally, a common commitment value is obtained based on the exclusive OR operation of the initial commitment values to be verified of the two terminals shared through mutual interaction between the two parties; a target parameter for reconstructing the intermediate commitment value is obtained based on the common commitment value, the message to be signed, and the target public key.
[0070] In an alternative embodiment, as Figure 3As shown below, taking the target terminal and the cooperating terminal as examples, the target terminal sends the initial commitment value to be verified, com1, to the cooperating terminal. Then, the cooperating terminal performs an exclusive OR operation on the initial commitment value to be verified, com1, and the initial commitment value to be verified, com1, to obtain the common commitment value, com. Finally, the cooperating terminal performs a hash derivation operation based on the common commitment com, the information to be signed, M, and the target public key to obtain the target parameters for reconstructing the intermediate commitment value. Similarly, the cooperating terminal sends the initial commitment value to be verified, com2, to the target terminal. Then, the target terminal performs an exclusive OR operation on the initial commitment value to be verified, com1, and the initial commitment value to be verified, com2, to obtain the common commitment value, com. Finally, the target terminal performs a hash derivation operation based on the common commitment com, the information to be signed, M, and the target public key to obtain the target parameters for reconstructing the intermediate commitment value. Through the above method, the target terminal and the cooperating terminal can each obtain the target parameters for reconstructing the intermediate commitment value, providing data support for the subsequent calculation of the reconstructed intermediate commitment value.
[0071] Optionally, the hash derivation operation based on the common commitment value, the information to be signed, and the target public key to obtain the target parameters for reconstructing the intermediate commitment value includes: performing a hash derivation operation based on the common commitment value, the information to be signed, and the target public key to obtain a challenge value; determining the response values of each terminal based on the challenge value and the relationship between the challenge and the response, where the relationship between the challenge and the response is the relationship between the response value and the challenge value and the secret term, and the secret term includes a secret value obtained by performing a hash operation on the random number parameter stored in the terminal private key and a secret polynomial; where the number of secret polynomials is greater than 1; determining the challenge value and the response value as the target parameters.
[0072] In an alternative embodiment, as Figure 3 shown below, taking the target terminal and the cooperating terminal as examples, the target terminal performs a key derivation operation based on the common commitment value com, the information to be signed, M, and the target public key to obtain the challenge value c. Then, the target terminal uses the challenge value c, the secret value y1, the secret polynomial s1_s, and the second secret polynomial s2_s to determine the first response value z1, that is, calculates the first response value z1 using the formula z1 = y1 + cs1_s + cs2_s. Similarly, the configuration terminal performs a key derivation operation based on the common commitment value com, the information to be signed, M, and the target public key to obtain the challenge value c. Then, the configuration terminal uses the challenge value c, the secret value y2, the secret polynomial s1_h, and the second secret polynomial s2_h to determine the first response value z2, that is, calculates the first response value z2 using the formula z2 = y2 + cs1_h + cs2_h. By calculating the target parameters in the above way, data support is provided for the subsequent reconstruction of the intermediate commitment value. At the same time, the complexity of the subsequent calculation of the reconstructed intermediate commitment value is reduced by using the above method for calculating the response value.
[0073] Optionally, obtaining target parameters for reconstructing an intermediate commitment value through hash derivation based on the public commitment value, information to be signed, and the target public key further includes: verifying whether the response values of each terminal meet a preset condition; in response to the response value of any terminal not meeting the preset condition, updating the secret item and then re - executing the process of determining the response values of each terminal based on the challenge value and the relationship between the challenge and the response.
[0074] In an alternative embodiment, as Figure 3 shown, taking the target terminal and the cooperating terminal as examples of terminals, the target terminal verifies whether the first response value z1 meets the preset condition, that is, verifies whether the first response value z1 is less than the preset infinity - norm threshold. When the first response value z1 is less than the preset infinity - norm threshold, the first response value z1 meets the preset condition, and the target terminal sends the first response value z1 and the random number rand1 to the cooperating terminal; otherwise, update the secret item and re - execute the process of determining the response values of each terminal based on the challenge value c and the relationship between the challenge and the response until the first response value z1 meets the preset requirements. Similarly, the cooperating terminal verifies whether the second response value z2 meets the preset condition, that is, verifies whether the second response value z2 is less than the preset infinity - norm threshold. When the second response value z2 is less than the preset infinity - norm threshold, the second response value z2 meets the preset condition, and the cooperating terminal sends the second response value z2 and the random number rand2 to the target terminal; otherwise, update the secret item and re - execute the process of determining the response values of each terminal based on the challenge value c and the relationship between the challenge and the response until the second response value z2 meets the preset requirements. By the above method, it is ensured that the response values of each end meet the signature requirements, ensuring the effectiveness of subsequent signature of the message to be signed. Among them, updating the secret item is essentially updating the preset initial count value. For example, the target terminal performs a hash operation on the random number parameter K1 in the private key (ρ, tr, K1, s1_s, s2_s, t_h) of the target terminal and the updated preset initial count value to obtain a new fixed - length random seed, and performs a Keccak operation and uniform sampling on the new fixed - length random seed to obtain a new secret value y1.
[0075] Optionally, using a commitment key to encrypt the result of the homomorphic hash commitment operation on the target commitment to obtain a target verification commitment value; where the target commitment is reconstructed based on the target parameters, specifically: for any one of the two terminals selected as the target terminal and the other terminal as the cooperating terminal; the target terminal reconstructs the commitment based on the public polynomial, the challenge value, the response value of the cooperating terminal, and the public key of the cooperating terminal to obtain the target commitment.
[0076] In an alternative embodiment, as Figure 3As shown below, taking the target terminal and the cooperating terminal as examples of the terminals, the target terminal calculates the target commitment w3 according to the second response value, the public polynomial A, the challenge value c, and the second public key th, that is, calculates the target commitment w3 using the formula w3 = Az2 - cth; the target terminal performs a homomorphic hashing commitment operation on the target commitment w3 and the random number rand2 provided by the cooperating terminal to obtain an intermediate result, and encrypts the intermediate result using the commitment key ck to obtain the target verification commitment value com3, where com3 = Commit(w3, rand2, ck); similarly, the cooperating terminal calculates the target commitment w4 according to the second response value, the public polynomial A, the challenge value c, and the first public key ts, that is, calculates the target commitment w4 using the formula w4 = Az1 - cts; the cooperating terminal performs a homomorphic hashing commitment operation on the target commitment w4 and the random number rand1 provided by the target terminal to obtain an intermediate result, and encrypts the intermediate result using the commitment key ck to obtain the target verification commitment value com4, where com4 = Commit(w4, rand1, ck). The calculation of the target verification commitment value is achieved in the above manner, providing data support for the subsequent comparison between the initial commitment value to be verified and the target verification commitment value.
[0077] S105: If the initial commitment value to be verified is the same as the target verification commitment value, then sign the message to be signed using the public commitment value.
[0078] In an alternative embodiment, as Figure 3 shown below, taking the target terminal and the cooperating terminal as examples of the terminals, when the initial commitment value to be verified com2 in the target terminal is the same as the target verification commitment value com3, and the initial commitment value to be verified com1 in the cooperating terminal is the same as the target verification commitment value com4, it indicates that the public commitment value com obtained by the two terminals is the same, and the two terminals can use the public commitment value com to sign the message M to be signed, thereby realizing the secure signature of the message M to be signed and ensuring that the message M to be signed is not tampered with or leaked.
[0079] The public commitment value of this application is obtained based on the exclusive OR operation of the initial commitment values to be verified of the two terminals. The initial commitment value to be verified of each terminal is the result of the homomorphic hashing commitment operation of the signature calculation of the public key information stored in the terminal private key and the encryption based on the commitment key, effectively ensuring the confidentiality and randomness of the public commitment value. During the process, only the two terminals need to interact and share the initial commitment values to be verified. Compared with the conventional data encryption transmission and decryption operations, the number of data transmissions is reduced and the signature verification effect is improved.
[0080] In an alternative embodiment, the information to be signed is signed using a common commitment value com and a common response value z, further enhancing the signature security. Here, z is obtained by performing an exclusive OR operation on a first response value z1 and a second response value z2.
[0081] In an alternative embodiment, the information to be signed is signed using a common commitment value com, a common response value z, and a common random number rand, further enhancing the signature security. Here, rand is obtained by performing an exclusive OR operation on a random number ran1 and rand2.
[0082] In an alternative embodiment, first, a verifier for verifying the signed message that has already been signed is determined. Then, the message to be signed M, the signature, and the negotiated public key (ρ, t) are input into the verifier. Then, the verifier calculates a public matrix A, a commitment key ck, and a challenge c based on the message to be signed M, the signature, and the negotiated public key (ρ, t). After that, the reconstructed commitment w = Az - ct is calculated, and the common commitment value com' is obtained by opening the commitment using the calculated commitment w. If the common commitment value com' is the same as the common commitment com and the infinity norm of the challenge value z is less than twice the preset infinity norm threshold, the verifier determines that the signed message to be signed passes the verification. The verification of the signature is achieved in the above manner to ensure the secure transmission of the message to be signed.
[0083] In an alternative embodiment, taking the target terminal and the cooperating terminal as examples, the first random seed ρ1 of the public polynomial, the random seed ρ1' of the secret polynomial, and the random number parameter K1 in the target terminal are obtained by performing a key derivation algorithm on a random seed ζ1 for key generation randomly generated locally by the target terminal, that is, the first random seed ρ1, the random seed ρ1', and the random number parameter K1 are obtained by performing a key derivation algorithm process on the random seed ζ1. Similarly, by performing a key derivation algorithm on a random seed ζ2 for key generation randomly generated locally by the cooperating terminal, that is, the second random seed ρ2, the random seed ρ2', and the random number parameter K2 are obtained by performing a key derivation algorithm process on the random seed ζ1. This increases the complexity and security of the public and private keys of the target terminal and the cooperating terminal.
[0084] In an alternative embodiment, the two terminals can be a hardware-based terminal and a software-based terminal, applicable to the software architecture of a mobile phone and a cryptographic hardware device embedded in the mobile phone.
[0085] Refer to Figure 4 FIG. is a schematic structural diagram of a key generation system for two terminals provided by an embodiment of this specification, including a target terminal and a cooperating terminal. The system includes:
[0086] The target terminal and the cooperating terminal perform a hashing operation based on the information to be signed of their respective terminals and a target public key including the public key information of their respective terminals to obtain the commitment keys of their respective terminals;
[0087] The target terminal and the cooperating terminal use the commitment keys to encrypt the result of the homomorphic hashing commitment operation on the intermediate commitment value to obtain the initial commitment values to be verified of their respective terminals; wherein, the intermediate commitment value is obtained by signing the terminal private key;
[0088] The target terminal and the cooperating terminal obtain a common commitment value based on the exclusive OR operation of the initial commitment values to be verified of their respective terminals shared through mutual interaction; the target terminal and the cooperating terminal perform a hashing derivation operation based on the common commitment value, the information to be signed, and the target public key of their respective terminals to obtain the target parameters of their respective terminals for reconstructing the intermediate commitment value;
[0089] The target terminal and the cooperating terminal use the commitment keys of their respective terminals to encrypt the result of the homomorphic hashing commitment operation on the target commitment to obtain the target verification commitment values of their respective terminals; wherein, the target commitment is reconstructed based on the target parameters;
[0090] If the initial commitment values to be verified of the target terminal and the cooperating terminal are consistent with the target verification commitment values of their respective terminals, then the target terminal and the cooperating terminal use the common commitment value of their respective terminals to sign the information to be signed of their respective terminals.
[0091] Regarding the system in the above embodiments, the processes of performing operations in each step have been described in detail in the embodiments related to the method, and will not be elaborated here.
[0092] Refer to Figure 5 which is a schematic structural diagram of an electronic device provided by an embodiment of this specification. The following refers to Figure 5 to describe the electronic device 300 according to this embodiment of the present invention. Figure 5 The electronic device 300 shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention.
[0093] As Figure 5 shown, the electronic device 300 is presented in the form of a general-purpose computing device. The components of the electronic device 300 may include but are not limited to: at least one processing unit 310, at least one storage unit 320, a bus 330 connecting different device components (including the storage unit 320 and the processing unit 310), a display unit 340, etc.
[0094] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 310, so that the processing unit 310 executes the steps according to various exemplary embodiments of the present invention described in the above processing method part of this specification. For example, the processing unit 310 can execute steps as Figure 1 shown.
[0095] The storage unit 320 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 3201 and / or a cache storage unit 3202, and may further include a read-only storage unit (ROM) 3203.
[0096] The storage unit 320 may further include a program / utilities 3204 having a set (at least one) of program modules 3205. Such program modules 3205 include, but are not limited to: an operating device, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.
[0097] The bus 330 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus structures.
[0098] The electronic device 300 may also communicate with one or more external devices 400 (such as a keyboard, a pointing device, a Bluetooth device, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 300, and / or communicate with any device that enables the electronic device 300 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication may be performed through an input / output (I / O) interface 350. And the electronic device 300 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 360. The network adapter 360 may communicate with other modules of the electronic device 300 through the bus 330. It should be understood that although Figure 5 not shown, other hardware and / or software modules may be used in conjunction with the electronic device 300, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID devices, tape drives, and data backup storage devices, etc.
[0099] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described in the present invention can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present invention can be embodied in the form of a software product, which can be stored in a computer-readable storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on the network, including several instructions to enable a computing device (which can be a personal computer, a server, or a network device, etc.) to execute the above method according to the present invention. When the computer instructions are executed by a data processing device, the computer-readable medium can implement the above method of the present invention, that is: as Figure 1 the method shown.
[0100] Referring to Figure 6 is a schematic diagram of the principle of a computer-readable medium provided by an embodiment of this specification.
[0101] Implement Figure 1 The computer instructions for implementing the method shown can be stored on one or more computer-readable media. The computer-readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor device, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0102] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable storage medium can also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution device, apparatus, or device. The program code contained on the readable storage medium can be transmitted by any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the above.
[0103] The program code for performing the operations of the present invention can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).
[0104] In summary, the present invention can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art should understand that general-purpose data processing devices such as microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some or all of the components in the embodiments of the present invention. The present invention can also be implemented as a device or apparatus program (e.g., a computer program and a computer program product) for performing some or all of the methods described herein. Such a program for implementing the present invention can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.
[0105] The specific embodiments described above further elaborate on the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the present invention is not inherently related to any specific computer, virtual device, or electronic device, and various general-purpose devices can also implement the present invention. The above are only specific embodiments of the present invention and are not used to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
[0106] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the key point of each embodiment is to illustrate the differences from other embodiments.
[0107] The above are only embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included within the scope of the claims of the present application.
Claims
1. A method for generating a key between two terminals, characterized in that: Applied to either end, the method comprises: Each terminal obtains a public random seed based on an XOR operation of random seeds provided by two terminals shared by both parties; Perform hash compression operation based on the public random seed to obtain a public polynomial, and perform hash compression operation based on the random seed provided by each terminal to obtain a secret polynomial; Each terminal determines the public key of each terminal based on the public polynomial and the secret polynomial in the corresponding terminal, and each terminal obtains the intermediate public key based on the exclusive OR operation of the public keys of the two terminals shared by both parties; A compressed public key is obtained by performing a hash operation based on the public random seed and the intermediate public key; Determine that the public random seed and the intermediate public key are jointly the negotiated public key of any terminal; determine that the public random seed, the compressed public key, the random number parameters provided by each terminal, the secret polynomial corresponding to each terminal, and the public key corresponding to the other terminal are the private key of any terminal.
2. The method according to claim 1, characterized in that Each terminal obtains a public random seed based on an XOR operation of random seeds provided by two terminals through interactive sharing by both parties, including: Verify the credibility of the random seeds provided by each terminal.
3. The method according to claim 2, characterized in that The verification of the credibility of the random seeds provided by each terminal includes: One of the two terminals is selected as the target terminal, and the other terminal is selected as the cooperating terminal; Performing a hash commitment operation on the random seed provided by the target terminal in the target terminal to obtain a target commitment value; and sending the random seed and the target commitment value of the target terminal to the cooperating terminal; Performing a hash commitment operation on the random seed provided by the target terminal in the cooperating terminal to obtain a comparison commitment value; When the target commitment value is consistent with the comparison target commitment value, the random seed provided by the target terminal is credible.
4. The method according to claim 2, characterized in that The verification of the credibility of the random seeds provided by each terminal also includes: One of the two terminals is selected as the target terminal, and the other terminal is selected as the cooperating terminal; Performing a hash commitment operation on the random seed provided by the target terminal in the cooperating terminal to obtain a target commitment value; and sending the random seed and the target commitment value of the cooperating terminal to the cooperating target terminal; Performing a hash commitment operation on the random seed provided by the cooperation terminal in the target terminal to obtain a comparison commitment value; When the target commitment value is consistent with the comparison commitment value, the random seed provided by the cooperation terminal is credible.
5. The method according to claim 1, characterized in that Each terminal obtains an intermediate public key based on an exclusive OR operation of the public keys of the two terminals shared interactively by both parties, and further includes: Verify the credibility of the public keys provided by each terminal.
6. The method according to claim 5, characterized in that The verification of the credibility of the public key provided by each terminal includes: Any terminal selected from the two terminals is a target terminal, and the other terminal is a matching terminal; Performing a hash commitment operation on the public key provided by the target terminal in the target terminal to obtain a target commitment value; and sending the public key of the target terminal and the target commitment value to the cooperating terminal; Performing a hash commitment operation on the public key provided by the target terminal in the cooperating terminal to obtain a comparison commitment value; When the target commitment value is consistent with the comparison commitment value, the public key provided by the target terminal is credible.
7. The method according to claim 5, characterized in that The verification of the credibility of the public key provided by each terminal also includes: Any terminal selected from the two terminals is a target terminal, and the other terminal is a matching terminal; Performing a hash commitment operation on the public key provided by the cooperating terminal in the cooperating terminal to obtain a target commitment value; and sending the public key of the cooperating terminal and the target commitment value to the target terminal; Performing a hash commitment operation on the public key provided by the target terminal in the target terminal to obtain a comparison commitment value; When the target commitment value is consistent with the comparison commitment value, the public key provided by the cooperation terminal is credible.
8. A key generation system between two terminals, characterized in that: Comprising a target terminal and a matching terminal, the system comprises: The target terminal and the cooperating terminal obtain a public random seed based on an exclusive OR operation of random seeds provided by the two terminals through interactive sharing by both parties; The target terminal and the cooperating terminal perform a hash compression operation based on a public random seed to obtain a public polynomial, and perform a hash compression operation based on a random seed provided by each terminal to obtain a secret polynomial of each terminal; The target terminal and the cooperating terminal determine the public key of each terminal based on the public polynomial and the secret polynomial in the corresponding terminal, and each terminal obtains the intermediate public key based on the exclusive OR operation of the public keys of the two terminals shared by both parties; The target terminal and the cooperating terminal respectively perform hash operations based on the public random seed and the intermediate public key to obtain the compressed public key of each terminal; The target terminal and the cooperating terminal determine the public random seed and the intermediate public key to jointly negotiate a public key for the two terminals; the target terminal determines the public random seed, the compressed public key, the random number parameter provided by the target terminal, the secret polynomial corresponding to the target terminal, and the public key corresponding to the cooperating terminal as the private key of the target terminal, and the cooperating terminal determines the public random seed, the compressed public key, the random number parameter provided by the cooperating terminal, the secret polynomial corresponding to the cooperating terminal, and the public key corresponding to the target terminal as the private key of the cooperating terminal.
9. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores computer instructions, and the processor is configured to execute the computer instructions to perform the method according to any one of claims 1 to 7.
10. A storage medium, characterized in that: The storage medium stores computer instructions, and the computer instructions are configured to execute the method according to any one of claims 1 to 7 when executed.
Citation Information
Patent Citations
Key negotiation method and device
CN112636906A
Data signature method, device and equipment and computer readable storage medium
CN116545631A
Multi-party key negotiation method and system based on national secret algorithm
CN116707780A
Session key generation method and device, processor and electronic equipment
CN117176329A
Information verification method and related equipment
CN118174967A
Cited By
Multi-party collaborative anti-quantum signature method and system based on homomorphic hash
CN120979680A