Multi-party quantum digital signature method and device based on one-time global hash

By introducing a one-time global hash function and quantum key distribution in quantum digital signatures, the problems of low efficiency and participant limitations of existing quantum digital signature schemes are solved, and efficient multi-party quantum digital signatures are achieved, which are suitable for multi-party application scenarios.

CN120128333APending Publication Date: 2025-06-10SHANGHAI QUANTUM SCI RES CENT +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510338114.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing quantum digital signature scheme is inefficient and has limited participants, and cannot meet the security needs in application scenarios that are greater than those in three parties.

Method used

A multi-party quantum digital signature method based on one-time full-domain hash is adopted to generate quantum keys through quantum key division, and a one-time full-domain hash function is used to sign the message. The generated signature results are disclosed through broadcasting and are verified by any verifier.

Benefits of technology

It realizes efficient multi-party quantum digital signatures, which can be verified by any multiple verifiers, significantly improves signature efficiency and is suitable for application scenarios that are greater than three parties.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128333A_ABST
    Figure CN120128333A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-party quantum digital signature method based on one-time global hash, and the method comprises the steps: initializing a signer and a credible authority, enabling each verifier to carry out the quantum key distribution, generating a quantum key, and guaranteeing the safety and uniqueness of the key; and in the signature stage, the message is signed by using the generated quantum key and the one-time global hash function, and the generated signature result is published in a broadcast mode and can be verified by any verifier. In the verification stage, all signers forward received signature results to the trusted authority through a classical authentication channel, the trusted authority compares the signature results forwarded by all the verifiers, if the signature results forwarded by all the verifiers are consistent, the trusted authority TA publishes confidential parameters, and if the signature results forwarded by all the verifiers are not consistent, the trusted authority TA does not publish confidential parameters. A verifier receives confidential parameters disclosed by a ground station through a classical channel (where authentication is not needed), and verifies the signature by using the information to ensure the validity and authenticity of the signature.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of quantum digital signatures, and particularly relates to a multi-party quantum digital signature method and device based on one-time global hashing. Background Art

[0002] Digital signature technology is usually used to ensure the authenticity, integrity, and non-repudiation of messages. Through digital signature technology, the recipient of a message can ensure that the signature indeed comes from the expected message sender and that the message has not been tampered with, while the message sender cannot deny having sent the information. Digital signature technology is one of the important application scenarios of public-key cryptography. By using a pair of keys, namely the public key and the private key, the sender can use its own private key to encrypt data to generate a digital signature, and the recipient can use the sender's public key to verify the digital signature. Digital signature technology relies on the public-key cryptosystem for establishment, and its security stems from mathematically difficult problems. Under the computing power of quantum computers, the current public-key cryptosystem is no longer secure.

[0003] Quantum cryptography refers to the cryptographic technology that realizes secure communication through physical principles. Quantum key distribution (QKD) is one of the important technologies in quantum cryptography. It enables two communicating parties to generate and share a random and secure key, while ensuring that any eavesdropping attack can be detected. Combined with the one-time pad technique, QKD can achieve information-theoretic security. Compared with classical cryptography that relies on mathematical problems, the QKD key cannot be broken no matter what computing power the attacker has.

[0004] However, quantum key distribution can only ensure the confidentiality of information and cannot provide the authenticity, integrity, and non-repudiation of digital signatures in classical cryptography. Quantum digital signature technology, also based on physical principles, is used to provide these information security features. The first quantum digital signature protocol was proposed in 2001, but it could not be implemented due to technical difficulties. After years of development, practical quantum digital signature schemes have been continuously proposed and experimentally verified. However, they all have the following important problems unresolved: (1) Low signature efficiency. Most of their schemes are single-bit signature schemes, and signing the message bit by bit consumes too many quantum bit resources. (2) Limitations of signature participants. For most of the proposed quantum digital signature schemes, the signature participants are limited to within three parties, that is, at most three users are included in the signature system of most schemes, and the signature of one user can only be verified by no more than two parties. The above two points greatly limit the application of quantum digital signatures in most scenarios. In classical digital signature schemes, the signature made by a user can be verified by all users holding his public key, while quantum digital signatures cannot meet the security requirements in application scenarios with more than three parties. Therefore, it is necessary to design an efficient multi-party quantum digital signature scheme. Summary of the Invention

[0005] The object of the present invention is to provide a multi-party quantum digital signature method and device based on one-time universal hashing, which can be verified by any number of verifiers and can perform more efficient digital signatures on files with one-time pad QDS.

[0006] To solve the above problems, the technical solution of the present invention is as follows: A multi-party quantum digital signature method based on one-time universal hashing, including: Initialization phase: The trusted authority and the signer and multiple verifiers generate quantum keys respectively through quantum key distribution. Among them, the signer and the trusted authority generate two segments of n-bit keys k1 and k2, and the signer and each verifier generate an n-bit key k i ; Signature phase: The signer obtains an n-bit intermediate result r according to the key k i , using the mapping function; Taking r and k1 as inputs, a one-time universal hash function is generated; based on the file M to be signed and the key k i , a message digest d with a length of n bits is obtained through the one-time universal hash function; Execute sign = d k2 to generate an n-bit string σ as the signature result, and publicly disclose σ through the broadcast method; Verification phase: Phase 1: After receiving the message, any verifier forwards the signature value σ to the trusted authority through an authenticated classical channel. The trusted authority compares whether all the forwarded signature results are consistent. If they are consistent, it enters Phase 2; otherwise, it queries the preset confidential parameters to identify unreliable participants. Phase 2: The trusted authority publicly broadcasts k1, k2, and k i , and after the verifier receives them, it executes σ k2 to obtain σ'; and based on k1 and k i , generates another universal hash function, calculates the message digest d', and verifies whether σ' is the same as d'. If they are the same, the verification passes and the signature is valid.

[0007] According to an embodiment of the present invention, the one-time universal hash function generates a Toeplitz matrix based on a linear feedback shift register and then performs matrix multiplication, specifically including: Using a linear feedback shift register to output an infinite-length binary bit stream; Taking each bit of the output bit stream as the value on the diagonal of the Toeplitz matrix to form a Boolean matrix; According to the length of the message to be hashed, generates a Toeplitz matrix of the corresponding size, then multiplies it with the matrix of the message to be hashed, maps the message to a result matrix of length n, and obtains the hash output.

[0008] According to an embodiment of the present invention, in the system initialization stage, the signer performs quantum key distribution with the trusted authority and each verifier respectively to generate quantum keys, ensuring the security and uniqueness of the keys; and different keys are used for each signature, conforming to the one-time pad principle.

[0009] According to an embodiment of the present invention, in the satellite-ground quantum digital signature scenario, the quantum satellite serves as the signer, the ground station serves as the trusted authority, and other ground nodes or satellites serve as verifiers, and long-distance quantum digital signatures are realized through quantum channels and classical authentication channels.

[0010] According to an embodiment of the present invention, there are quantum channels between the quantum satellite and the ground station and verifiers for quantum key distribution and quantum state transmission, ensuring the security and uniqueness of the keys; There is a classical authentication channel between the ground station and each verifier for transmitting classical information including signature results and key information, and ensuring the authenticity of the identities of both communication parties and the integrity of the information through a strong authentication mechanism.

[0011] According to an embodiment of the present invention, when the quantum satellite performs quantum key distribution with the ground station and verifiers, the decoy state BB84 protocol is adopted to increase the key generation rate, optimize the performance of the quantum channel, reduce photon loss and bit error rate.

[0012] According to an embodiment of the present invention, in the signature phase, the quantum satellite uses the generated quantum key and the one-time universal hash function to sign the message, and the generated signature result is publicly disclosed in a broadcast manner for any verifier to verify.

[0013] According to an embodiment of the present invention, in the verification phase, the verifier receives the key information publicly disclosed by the ground station through the classical authentication channel, and uses this information to verify the signature to ensure the validity and authenticity of the signature; In the verification phase, the ground station prevents the signer from tampering with the signature result and denying it by comparing the signature results forwarded by all verifiers. If the signature results are inconsistent, the confidential parameters are queried to identify unreliable participants in the system.

[0014] A multi-party quantum digital signature device based on one-time universal hashing, comprising: An initialization module, configured to: The trusted authority and the signer and multiple verifiers respectively generate quantum keys through quantum key distribution. Among them, the signer and the trusted authority generate two segments of n-bit keys k1 and k2, and the signer and each verifier generate an n-bit key k i ; A signature module, configured to: The signer obtains an n-bit intermediate result r using the mapping function according to the key k i ; Taking r and k1 as inputs, a one-time universal hash function is generated; based on the file M to be signed and the key k i , a message digest d with a length of n bits is obtained through the one-time universal hash function; Execute sign = d k2 to generate an n-bit string σ as the signature result, and publicly disclose σ in a broadcast manner; A verification module, configured to: Phase 1: After receiving the message, any verifier forwards the signature value σ to the trusted authority through the authenticated classical channel. The trusted authority compares whether all the forwarded signature results are consistent. If they are consistent, it enters Phase 2; otherwise, the preset confidential parameters are queried to identify unreliable participants; Phase 2: The trusted authority publicly discloses k1, k2, and k i through the broadcast channel. After receiving it, the verifier executes σ k2 to obtain σ'; and based on k1 and k i , another universal hash function is generated, and the message digest d' is calculated to verify whether σ' is the same as d'. If they are the same, the verification passes and the signature is valid.

[0015] Due to the adoption of the above technical solutions, the present invention has the following advantages and positive effects compared with the prior art: Aiming at the problems of low signature efficiency, limitations of signature participants, and lack of practicality in existing quantum digital signatures, the present invention provides a multi-party quantum digital signature method based on one-time universal hashing. This method mainly involves quantum digital signatures among a trusted authority, signers, and multiple verifiers. In the initialization stage, quantum key distribution is performed separately between the signers and the trusted authority, and each verifier to generate quantum keys to ensure the security and uniqueness of the keys. In the signature stage, the generated quantum keys and the one-time universal hashing function are used to sign the message, and the generated signature results are publicly disclosed through a broadcast method for any verifier to verify. In the verification stage, the verifiers receive the key information publicly disclosed by the ground station through a classical authentication channel and use this information to verify the signature to ensure the validity and authenticity of the signature. The trusted authority compares the signature results forwarded by all verifiers. If the signature results are inconsistent, the confidential parameters are queried to identify unreliable participants in the system. This method can be verified by any number of verifiers and can perform a one-time pad QDS for more efficient digital signatures of files. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 Schematic diagram of a quantum digital signature system in a satellite-ground scenario in an embodiment of the present invention; Figure 2 Schematic diagram of a linear feedback shift register principle in an embodiment of the present invention; Figure 3 Schematic diagram of a Toeplitz matrix principle in an embodiment of the present invention; Figure 4 Flowchart of the initialization stage in an embodiment of the present invention; Figure 5 Flowchart of the signature stage in an embodiment of the present invention; Figure 6 Flowchart of the first stage of the verification stage in an embodiment of the present invention; Figure 7 Flowchart of the second stage of the verification stage in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] The following further elaborates in detail on a multi-party quantum digital signature method and device based on one-time universal hashing proposed by the present invention in conjunction with the accompanying drawings and specific embodiments. The advantages and features of the present invention will be clearer based on the following description and the claims.

[0018] Aiming at the problem of low efficiency of existing quantum digital signatures, in this embodiment, the efficiency of quantum digital signatures is improved through a one-time universal hash function. The one-time universal hash function has the following characteristics: One-time: Each hash function used for each message will only be used once, and a new universal hash function will be generated next time; Universality: The hash values generated by the hash function can be evenly distributed in the hash space, so it is not vulnerable to collision attacks; One-way: The input and output processes of the hash function are irreversible. By combining the one-time universal hash function with the one-time pad in the protocol design, the single-bit signature efficiency in most schemes can be improved to the level where multiple bits participate in the signature simultaneously, and the efficiency will be greatly improved.

[0019] Regarding the existing quantum digital signatures, the participants in the signature are all limited to within three parties, that is, at most three users are included in the signature system of most schemes, and the signature of one user can only be verified by no more than two parties. This embodiment provides a multi-party quantum digital signature method based on one-time universal hashing, which can be verified by any number of verifiers.

[0020] The multi-party quantum digital signature method based on one-time universal hashing includes: Initialization phase: The trusted authority, the signer, and multiple verifiers generate quantum keys respectively through quantum key distribution. Among them, the signer and the trusted authority generate two segments of n-bit keys k1 and k2, and the signer and each verifier generate an n-bit key k i ; Signature phase: The signer obtains an n-bit intermediate result r according to the key k i using the mapping function; Taking r and k1 as inputs, a one-time universal hash function is generated; Based on the file M to be signed and the key k i a message digest d with a length of n bits is obtained through the one-time universal hash function; Execute sign = d k2 to generate an n-bit string σ as the signature result, and publicly announce σ through the broadcast method; Verification phase: Phase 1: After receiving the message, any verifier forwards the signature value σ to the trusted authority. The trusted authority compares whether all the forwarded signature results are consistent. If they are consistent, it enters Phase 2; otherwise, it queries the preset confidential parameters to identify unreliable participants; Phase 2: The trusted authority publicly announces k1, k2, and k i through the broadcast channel. After receiving them, the verifier executes σ k2 to obtain σ'; and based on k1 and k i, generate another global hash function, calculate the message digest d', and verify whether σ' is the same as d'. If they are the same, the verification passes and the signature is valid.

[0021] This method combines quantum key distribution (QKD) with one-time global hashing. In terms of security, QKD is based on the principles of quantum mechanics, ensuring that both parties in communication can generate and share a random, secure key, and any eavesdropping behavior will be detected. One-time global hashing has strong anti-collision and one-way properties, making it difficult for attackers to find two different messages mapped to the same hash value, and it is also difficult to infer the original message from the hash value. The combination of the two can effectively resist multiple security threats such as eavesdropping attacks, man-in-the-middle attacks, and forgery attacks. In terms of signature efficiency, one-time global hashing can map messages of any length to a summary containing only hundreds of bits, and the quantum key generated by QKD is used for the selection of hash functions and the encryption of the summary. This method only requires hundreds of quantum keys to sign the entire file at one time, greatly improving the signature efficiency. Compared with the traditional single-bit scheme, the signature efficiency will be improved by eight to nine orders of magnitude. When processing large files, the one-time global hashing quantum digital signature scheme has excellent performance. As the length of the signature increases, the size of the signature file grows exponentially under the same probability of failure. For example, a gigabyte-sized file can be processed more than 10 times per second at a transmission attenuation of 20 dB, bringing hope for real-time transactions within a metropolitan area.

[0022] The combination of QKD and one-time global hashing is not only applicable to traditional ground communication scenarios, but can also be applied to satellite-to-ground communications, metropolitan quantum networks, intercity quantum networks, and other scenarios. As long as the roles participating in the system have QKD capabilities and certain computing capabilities, the solution can be applied, expanding the application boundaries of quantum digital signature technology.

[0023] The following uses the satellite-to-ground one-to-many quantum digital signature scenario as an example to introduce the multi-party quantum digital signature method based on one-time global hashing. Figure 1 , this method mainly involves the following system structure: 1. Trusted Authority (TA): The trusted ground station of QKD in the satellite-to-ground scenario exists as a trusted authority TA. Similar to the classical cryptographic system, we introduce a trusted authority TA to implement the function of CA. Similar to CA, TA is also trustworthy and provides a source of trust for the entire system. All other personnel in the system trust the information released by TA. For a practical signature system, the purpose of introducing a trusted center is to add an administrator whose identity is recognized as safe to the system. Otherwise, in a system, there is no object that is recognized as safe by everyone. Anyone can be an attacker. The trust of the entire system has no source, and everyone can suspect each other's identity.

[0024] 2. Signer: The Quantum Satellite exists as the signer. The signer needs to conduct QKD with the TA and all verifiers respectively to generate quantum keys, and use the generated quantum keys to sign messages; one signature corresponds to one message, and the key becomes invalid after the signature verification process is completed, which conforms to the one-time pad principle. The signer (satellite) can continuously conduct QKD with the ground station and verification nodes to accumulate more quantum keys for signing.

[0025] 3. Verifier: The verifier generally appears as the ground station. Compared with the TA, the verifier is not required to be trusted. QKD is conducted between the verifier and the signer to generate quantum keys for signing messages. The verifier can be one person or many people, and multiple people can complete multiple verifications of the signature.

[0026] There is a classical authentication channel between the verifier and the trusted authority, and the classical channel can be constructed in the form of optical fiber or free space. There are quantum channels between the signer and the verifier, and between the signer and the trusted authority. All three parties of the trusted authority, the signer, and the verifier should have QKD capabilities and certain computing capabilities to achieve long-distance quantum digital signatures.

[0027] Specifically, the technical design of the one-time global hash involved in this embodiment can be summarized as: generating a Toeplitz matrix based on a linear feedback shift register and then performing matrix multiplication. The principle of the linear feedback shift register is as follows Figure 2 .

[0028] The input of the linear feedback shift register is The output is an infinite-length binary bit stream, where is used as the initial value of the linear feedback shift register, and is used as the gating value of the linear feedback shift register.

[0029] A Toeplitz matrix refers to a matrix in which the elements on the main diagonal of the Leeds matrix are equal, and the elements parallel to the main diagonal are also equal, such as Figure 3 . The output of the linear feedback shift register is used bit by bit as the value on the diagonal of the Toeplitz matrix, that is, the output of the linear feedback shift register is respectively assigned to to form a one-time global hash Toeplitz matrix. The output value of the linear feedback shift register is 0 / 1, so this matrix is a Boolean matrix. At the same time, since the output length of the linear feedback shift register is infinite, the column length of this matrix is also infinite. Assuming the length of the message to be hashed is , then a Toeplitz matrix of size can be generated (the number of columns of the matrix is the same as the text length), and matrix multiplication is performed. The Multiply the Toeplitz matrix and the message matrix, thereby mapping the message to a result matrix of length . In summary, the input of the one-time universal hash function is two binary sequences , message , and the output is a result matrix of length , that is, a bit string.

[0030] In the satellite-ground quantum digital signature scenario, the signer is the quantum satellite QS (Quantum Satellite) equipped with quantum communication equipment, the verifier Ver (Verifiers) is a ground node or other satellites, and the ground station GS (Ground Station) is the trusted authority TA. The file to be signed is , and its length is bits. The process of this scheme is as follows: (1) System initialization phase: As Figure 4 , in this phase, QKD is mainly completed. QS and TA, Verifiers respectively perform QKD once. Two segments of n-bit keys are generated between QS and TA, denoted as X and Y; QS and all verifiers participating in the verification respectively generate n-bit keys, denoted as X 1 , X 2 , X 3 ,... X n .

[0031] (2) Signature phase As Figure 5 , QS inputs X 1 , X 2 , X 3 ,... X n into the mapping function f( ) to obtain map = f(X 1 , X 2 , X 3 ,... X n ). The length of map is n bits.

[0032] QS takes map and X as inputs to generate a one-time universal hash function hash, and executes to obtain a message digest of length n bits.

[0033] Finally, execute to generate an n-bit string. The Sign value is the result of this signature. After the signature is completed, QS publicly broadcasts , and any verifier Ver can accept this information.

[0034] (3) Verification phase: In phase one Figure 6 : When any Ver receives the message, he will initiate a verification request and forward the signature value to the trusted authoritative ground station GS through the authentication channel. To save communication overhead, the file doc does not need to be forwarded together.

[0035] After the trusted authority receives the results forwarded by all verifiers, it will compare whether the results of all signatures received later are consistent to prevent the signer from tampering with the signature result and denying it (it is possible to sign multiple documents with the same key and send them to different people, destroying non-repudiation). If the comparison results are consistent, continue with the following verification phase two.

[0036] If the comparison results are inconsistent, then there are only two cases: 1. An attacker forged the signature, and this attacker may be one of the verifiers. 2. The signatures sent by the signer QS to different users are inconsistent. In both cases, the attacker's attack behavior is traceable because in the whole process, all confidential parameters are strongly related to the user identity. Once either the signer or the verifier tries to forge, it will bring a great risk of being traced. Therefore, in the case of inconsistent results, the trusted authority TA will query all confidential parameters to check whether there are unreliable participants in the system.

[0037] In phase two Figure 7 : GS determines whether all verifiers have participated in verification process one based on the number of signature users received. When GS determines that all verifiers have forwarded, GS publicly broadcasts X, Y, X 1 , X 2 , X 3 ,... X n . After the verifiers receive this information, they execute , which is n bits. And based on X 1 , X 2 , X 3 ,... X n and X to generate a one-time global hash function , calculate , and verify whether the values of and are the same. If the two are the same, the verification passes, the signature is valid. After {X, Y, X 1 , X 2 , X 3 ,... X n} is announced, this key will no longer be used, and the next digital signature will use a new QKD key, which conforms to the one-time pad principle.

[0038] As described above, there are quantum channels between the quantum satellite and the ground station and the verifier for quantum key distribution and quantum state transmission to ensure the security and uniqueness of the key. There is a classical authentication channel between the ground station and each verifier for transmitting classical information including signature results and key information, and the strong authentication mechanism ensures the authenticity of the identities of both communication parties and the integrity of the information.

[0039] Among them, the strong authentication mechanism is used in the classical authentication channel to ensure the authenticity of the identities of both communication parties and the integrity of the information. For example, digital certificate authentication based on the public key infrastructure (PKI) is adopted, or authentication is combined with the post-quantum cryptography (PQC) algorithm to resist potential quantum computing attacks.

[0040] Furthermore, in this embodiment, when the quantum satellite performs quantum key distribution with the ground station and the verifier, the decoy-state BB84 protocol is adopted to increase the key generation rate, optimize the performance of the quantum channel, and reduce photon loss and bit error rate. The principle of the decoy-state BB84 protocol is as follows: The decoy-state BB84 protocol copes with the PNS attack by randomly inserting two or more optical pulses with different intensities (signal state and decoy state) during the key distribution process: Signal state: with higher intensity, used to carry real key information.

[0041] Decoy state: with lower intensity (even close to the single-photon level), used to monitor channel anomalies.

[0042] Since the attacker cannot distinguish multi-photon pulses of the signal state and the decoy state, it cannot adjust the interception strategy for pulses with different intensities in the photon number splitting (PNS) attack. If the attacker intercepts the decoy-state pulse, its behavior will cause significant differences in the transmission statistical characteristics (such as counting rate and bit error rate) between the decoy state and the signal state, which can be detected by both communication parties.

[0043] The process of the decoy-state BB84 protocol is as follows: Pulse preparation: The quantum satellite randomly selects a signal state (intensity μμ) or a decoy state (intensity ν < μν < μ) and encodes the quantum state (such as polarization or phase); Quantum transmission: The pulse is transmitted to the verifier through the quantum channel; Measurement and screening: The verifier randomly selects a measurement basis for measurement, and both parties screen out the pulses with matching basis vectors through the classical channel; Parameter estimation: Both parties disclose part of the decoy-state data, calculate the gain and bit error rate of the single-photon component, and verify the channel security; Key generation: If the parameters are normal, error correction and privacy amplification are performed to generate the final key.

[0044] Furthermore, in the quantum channel of the ground segment, an optical fiber with low loss, low noise, and high stability is selected to reduce the loss and interference of the quantum state during transmission. The transmission loss of the optical fiber should be as low as possible to maintain the high fidelity of the quantum state.

[0045] When quantum optical signals are transmitted in an optical fiber, they are affected by dispersion and loss. Dispersion causes the optical quantum pulses transmitted in the optical fiber to broaden, resulting in crosstalk, reducing the efficiency of gated quantum measurement, and weakening the phase interference contrast. The existence of loss causes the survival rate of single-photon pulse signals transmitted in the optical fiber to continuously decrease as the transmission distance increases. Optical fibers with wavelengths of 890 nm, 1310 nm, or 1550 nm can be used. Among them, the 1310 nm optical transmission window is also known as the zero-dispersion window, and the optical signal has the minimum dispersion when transmitted in this window. In practical applications, the influence of the dispersion effect can also be reduced by controlling the bandwidth of the light source.

[0046] Based on the same concept, this embodiment also provides a multi-party quantum digital signature device based on one-time universal hashing. The device includes: An initialization module, configured to: The trusted authority and the signer and multiple verifiers respectively generate quantum keys through quantum key distribution. Among them, the signer and the trusted authority generate two segments of n-bit keys k1 and k2, and the signer and each verifier generate an n-bit key k i ; A signature module, configured to: The signer obtains an n-bit intermediate result r by using a mapping function according to the key k i ; Taking r and k1 as inputs, generate a one-time universal hashing function; based on the file M to be signed and the key k i , obtain a message digest d with a length of n bits through the one-time universal hashing function; Execute sign = d k2 to generate an n-bit string σ as the signature result, and publicly disclose σ through a broadcast method; A verification module, configured to: Phase 1: After receiving the message, any verifier forwards the signature value σ to the trusted authority. The trusted authority compares whether all the forwarded signature results are consistent. If they are consistent, enter Phase 2; otherwise, query the preset confidential parameters to identify unreliable participants; Phase 2: The trusted authority publicly discloses k1, k2, and k i through the broadcast channel. After receiving it, the verifier executes σ k2 to obtain σ'; and based on k1 and k i, generate another universal hash function, calculate the message digest d', and verify whether σ' is the same as d'. If they are the same, the verification passes and the signature is valid.

[0047] This device is used to implement the above multi-party quantum digital signature method based on one-time universal hashing. Its functions and implementation manners are similar and will not be elaborated here.

[0048] The embodiments of the present invention have been described in detail above in conjunction with the accompanying drawings. However, the present invention is not limited to the above embodiments. Even if various changes are made to the present invention, provided that these changes fall within the scope of the claims of the present invention and their equivalent technologies, they still fall within the protection scope of the present invention.

Claims

1. A multi-party quantum digital signature method based on one-time global hashing, characterized in that: include: Initialization phase: The trusted authority, the signer, and multiple verifiers generate quantum keys through quantum key distribution. The signer and the trusted authority generate two n-bit keys k1 and k2, and the signer and each verifier generate an n-bit key k i ; Signature phase: The signer uses the key k i , use the mapping function to obtain the n-bit intermediate result r; Take r and k1 as input to generate a one-time global hash function; based on the file to be signed M and the key k i , obtain the message digest d with a length of n bits through a one-time global hash function; Execute sign=d k2, generates an n-bit string σ as the signature result, and makes σ public through broadcasting; Verification phase: Phase 1: After receiving the message, any verifier forwards the signature value σ to the trusted authority through the authenticated classical channel. The trusted authority compares all the forwarded signature results to see if they are consistent. If they are consistent, it enters Phase 2; otherwise, it queries the preset confidential parameters to exclude unreliable participants. Phase 2: The trusted authority publishes k1, k2, and k through a broadcast channel i , the verifier receives it and executes σ k2, get σ'; and according to k1 and k i , generate another global hash function, calculate the message digest d', and verify whether σ' is the same as d'. If they are the same, the verification passes and the signature is valid.

2. The multi-party quantum digital signature method based on one-time global hashing according to claim 1 is characterized in that: The one-time global hash function generates a Toeplitz matrix based on a linear feedback shift register, and then performs matrix multiplication, specifically including: Use linear feedback shift register to output binary bit stream of unlimited length; The output bit stream is used bit by bit as the value on the diagonal of the Toeplitz matrix to form a Boolean matrix; According to the length of the message to be hashed, a Toeplitz matrix of the corresponding size is generated, and then multiplied by the matrix of the message to be hashed, the message is mapped to the result matrix of length n to obtain the hash output.

3. The multi-party quantum digital signature method based on one-time global hashing according to claim 1 is characterized in that: During the system initialization phase, the signer distributes quantum keys with the trusted authority and each verifier to generate quantum keys to ensure the security and uniqueness of the keys; and each signature uses a different key, in line with the one-time-one-key principle.

4. The multi-party quantum digital signature method based on one-time global hashing according to claim 1 is characterized in that: In the satellite-to-ground quantum digital signature scenario, the quantum satellite acts as the signer, the ground station acts as the trusted authority, and other ground nodes or satellites act as verifiers, realizing long-distance quantum digital signatures through quantum channels and classical authentication channels.

5. The multi-party quantum digital signature method based on one-time global hashing according to claim 4 is characterized in that: There are quantum channels between the quantum satellite and the ground station and the verifier for quantum key distribution and quantum state transmission to ensure the security and uniqueness of the key; There is a classic authentication channel between the ground station and each verifier, which is used to transmit classic information including signature results and key information, and ensure the identity authenticity and information integrity of the communicating parties through a strong authentication mechanism.

6. The multi-party quantum digital signature method based on one-time global hashing according to claim 4 is characterized in that: When the quantum satellite distributes quantum keys with the ground station and the verifier, the decoyed state BB84 protocol is adopted to increase the key generation rate, optimize the performance of the quantum channel, and reduce photon loss and bit error rate.

7. The multi-party quantum digital signature method based on one-time global hashing according to claim 4 is characterized in that: During the signing phase, the quantum satellite uses the generated quantum key and a one-time global hash function to sign the message, and the generated signature result is made public through broadcasting for verification by any verifier.

8. The multi-party quantum digital signature method based on one-time global hashing according to claim 4 is characterized in that: During the verification phase, the verifier receives the key information disclosed by the ground station through the classic authentication channel, and uses this information to verify the signature to ensure the validity and authenticity of the signature; During the verification phase, the ground station compares the signature results forwarded by all verifiers through the authenticated classical channel to prevent the signer from tampering with the signature result and denying it. If the signature results are inconsistent, the confidential parameters are queried to exclude unreliable participants in the system.

9. A multi-party quantum digital signature device based on one-time global hashing, characterized in that: include: Initialization module, configured as: The trusted authority, the signer, and multiple verifiers generate quantum keys through quantum key distribution. The signer and the trusted authority generate two n-bit keys k1 and k2, and the signer and each verifier generate an n-bit key k i ; The signature module is configured as follows: The signer uses the key k i , use the mapping function to obtain the n-bit intermediate result r; Take r and k1 as input to generate a one-time global hash function; based on the file to be signed M and the key k i , obtain the message digest d with a length of n bits through a one-time global hash function; Execute sign=d k2, generates an n-bit string σ as the signature result, and makes σ public through broadcasting; The authentication module is configured as follows: Phase 1: After receiving the message, any verifier forwards the signature value σ to the trusted authority. The trusted authority compares all the forwarded signature results to see if they are consistent. If they are consistent, it enters Phase 2; otherwise, it queries the preset confidential parameters to exclude unreliable participants; Phase 2: The trusted authority publishes k1, k2, and k through a broadcast channel i , the verifier receives it and executes σ k2, get σ'; and according to k1 and k i , generate another global hash function, calculate the message digest d', and verify whether σ' is the same as d'. If they are the same, the verification passes and the signature is valid.