Quantum threshold resistant digital signature method and system capable of tolerating high network delay
By adopting Shamir secret sharing and secure multi-party computing protocol in the threshold signature scheme, efficient signature generation is achieved in a high network delay environment, solving the problem of serious signature delay under high delay in the existing technology, and achieving the effect of completing signatures within 2 seconds.
Patent Information
- Application Number
- CN202411820156.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-11
- Filing Date
- 2024-12-11
- Publication Date
- 2025-06-13
AI Technical Summary
The existing threshold signature schemes have scalability challenges in WAN environments with high network latency, especially when more than 15 rounds are required during the online signature phase, resulting in severe communication delays.
A quantum threshold-resistant digital signature scheme is proposed, using Shamir secret sharing and secure multi-party computing protocol, signature generation is completed through two rounds of interaction, and functional interchangeability is supported.
This solution completes signatures in only 2 seconds in a high-latency WAN environment, and the number of rounds is optimized to only 2 rounds, significantly improving the scalability under high-latency networks.
Smart Images

Figure CN120150933A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of cryptography and discloses a quantum-resistant threshold digital signature scheme that tolerates high network latency. It has functional interchangeability, that is, the signatures generated by the threshold scheme can be verified by the same verification algorithm as those generated by the original signature scheme. At the same time, the threshold digital signature scheme of the present invention is efficiently implementable, and the threshold signature protocol in the two-party scenario of the wide area network only takes 2 seconds. Moreover, the present invention has an optimal number of rounds, and its signature algorithm only requires two rounds. Background Art
[0002] Digital signature algorithms have a wide range of applications in today's digital world. They provide a powerful way to ensure the security and credibility of electronic documents and information. Digital signature algorithms are currently widely used in applications such as email security, software verification, and financial transactions. In short, digital signature algorithms play a key role in protecting information security, ensuring identity authentication, strengthening data integrity, and achieving legality. They have become an indispensable tool in the digital age and are applied in various fields to meet the needs of security and trust. The idea of digital signature is that users use private keys for signing to achieve purposes such as identity authentication. The security of the private key is the basis of digital signature algorithms.
[0003] Threshold signature is a multi-party security protocol used to enhance the security and credibility of digital signatures. Different from traditional digital signature methods, threshold signature requires the cooperation of multiple signers. Only when the number of signers reaches a certain "threshold", the signature will be considered valid. The core idea of this method is to divide the signature key into multiple parts and require multi-party cooperation to generate a valid digital signature, thereby increasing the security and anti-attack ability of the signature. According to the requirements of NIST for the standardization of threshold cryptography schemes, threshold signatures should satisfy functional interchangeability, that is, the signatures generated by the threshold scheme can be verified by the verification algorithm of the original signature scheme. Currently, threshold signatures are widely used in fields such as finance, blockchain, multi-party computing, multi-party voting systems, and secure multi-party computing. They provide a highly secure and trustworthy signature mechanism for these fields, helping to protect user data and ensure the fairness of multi-party participation.
[0004] With the continuous in - depth research on quantum computers, people have gradually realized that quantum algorithms, which run on quantum computers, possess more powerful computing capabilities. Different from traditional classical algorithms, quantum algorithms can easily solve problems that are extremely challenging under traditional computing models. For example, traditional public - key cryptosystems mainly rely on the difficulty of number - theoretic problems such as large - integer factorization and discrete logarithms, such as the RSA and Schnorr signature schemes. However, with the continuous development of quantum computing, such as the Shor algorithm and Grover algorithm, the security of many cryptographic schemes based on classical number - theoretic problems has been severely challenged. Therefore, post - quantum cryptography has emerged, among which lattice - based cryptography has become one of the research directions attracting much attention.
[0005] In this context, lattice - based threshold signature schemes have become a current research hotspot. This cryptographic method is based on lattice theory, providing a strong security against the threats brought by quantum computing. It represents the forefront of future cryptography and is expected to bring new breakthroughs and innovations to the field of information security. However, there is currently no efficient threshold lattice signature scheme that satisfies functional interchangeability. An important limitation of existing implementable threshold signature schemes is that even in the online signature phase, it requires more than 15 rounds. When the scheme runs on a wide - area network (WAN), each communication round may introduce a delay of dozens to hundreds of milliseconds. Such a high number of communication rounds indicates that there are potential scalability challenges when applying the scheme to practical applications.
[0006] In summary, there is currently no practical threshold signature scheme with fewer communication rounds. Constructing such a scheme is worth looking forward to and is of great significance. Summary of the Invention
[0007] The present invention proposes an anti - quantum threshold digital signature scheme that tolerates high network latency and has functional interchangeability, that is, the signatures generated by the threshold scheme and the original signature scheme can be verified by the same verification algorithm. At the same time, the present invention has an excellent number of rounds, and its signature algorithm only requires two rounds and can tolerate running on a wide - area network with high latency.
[0008] The technical solution adopted by the present invention is as follows:
[0009] An efficient anti - quantum threshold digital signature method includes a key - generation phase, a distributed signature phase, and a verification phase;
[0010] In the key - generation phase, a trusted third party randomly selects a key and performs Shamir secret sharing on the key, and distributes the secret - sharing values to each signer;
[0011] In the distributed signature phase, each signer performs packed secret sharing on the secret sharing values and runs the proof sub-circuit of the public key based on the secure multi-party computation protocol. Then, each participant outputs a signature through two rounds of interaction.
[0012] In the verification phase, the verifier verifies the signature.
[0013] Furthermore, the key generation phase includes the following steps:
[0014] (1) A trusted third party generates a random k×k matrix A defined over the polynomial ring R q ; where k and q are both positive integers, and each element in the matrix is an element in the polynomial ring R q . R q is defined as that is, the ring formed by polynomials with coefficients being integers greater than and less than modulo the polynomial f(X). A trusted third party generates two random k-column vectors (s, e) defined over the polynomial ring R η ; where k and η are both positive integers, and each element in the matrix is an element in the polynomial ring R η . R η is defined as that is, the ring formed by polynomials with coefficients being integers greater than and less than modulo the polynomial f(X).
[0015] (2) The trusted third party performs d-th order Shamir secret sharing on each coefficient of the random vectors (s, e) to obtain the secret sharing values ([s] d , [e] d ). Further, the trusted third party calculates b = As + e. Finally, the trusted third party outputs the public key pk = (A, b) and the secret sharing of the private key ([s] d , [e] d ). Assume that the threshold signature algorithm has N 1 signers, where the signer P i obtains the secret sharing values ([s] d (i), [e] d (i)).
[0016] Furthermore, the distributed signature phase includes the following steps:
[0017] (1) In the threshold signature algorithm, each participant P i performs packed secret sharing on the private keys [s] d (i), [e] d (i) Among them, packing secret sharing is a well-known algorithm. The input is a vector composed of the coefficients of the ring elements corresponding to a secret, and the output is the sharing value of the secret vector. The total number of sharing values output by packing secret sharing is N 2 . Among them, represents the private key [s] of the i-th participant d (i) N 2 secret shares obtained through the packing secret sharing algorithm, represents the private key noise part [e] of the i-th participant d (i) N 2 secret shares obtained through the packing secret sharing algorithm, where PSS represents the packing secret sharing algorithm.
[0018] (2) Each signer runs the MPCitH paradigm, where the j-th participant simulated by the i-th signer in the virtual MPC is denoted as Each signer first generates 2η + 1 packing secret sharings for the constants {-η,..., η}, combined with the private key s i,j , e i,j as the private input of P i j .
[0019] (3) The method for checking multiplication gates in the new MPCitH paradigm is given. For a d-order packing secret sharing scheme, the two secret sharing values [x] d and [y] d that need to be multiplied for the input of the multiplication gate, the signer first calculates [z] 2d = [x] d ·[y] d , and then the signer generates a new packing secret sharing [z] d , and takes [z] d as the output. For the verifier, the verifier can require the signer to open the secret sharing values of part of [z] 2d - [z] d , and judge whether [z] d = [x] d ·[y] d by reconstructing and verifying whether it is the packing secret sharing value of 0. The signer uses the new packing secret sharing [z] d to perform the calculation of subsequent circuit gates.
[0020] (4) A new method for proving linear transformation gates is proposed. For the packing secret sharing scheme, first pre-calculate and generate a linear transformation pair [r] d and [Ar] d . The signer first calculates [s] d +[r] d, then perform reconstruction to obtain the value of s + r. Further, the signer can calculate A(s + r), and then perform packed secret sharing on the result to obtain [A(s + r)] d . Finally, the signer calculates [A(s + r)] d - [Ar] d + [e] d , and then perform reconstruction to determine whether it is equal to the public key b.
[0021] (5) A new pre - calculation generation method is proposed. First, the signer generates k + v + 1 random pairs ([f 0 d , [Af 0 d ), ([f 1 d , [Af 1 d ),..., ([f k+v d , [Af k+v d ). Then the verifier generates k + v random challenge values α 1 , α 2 ,..., α k+v . According to the challenge values, the signer calculates and For i ∈ [1, k], the signer publishes [β i and [γ i . The verifier verifies A[β i = [γ i . For the remaining i ∈ [k + 1, v], the signer will use the linear transformation relationship between [β i and [γ i to perform the proof of the linear transformation gate in (4) to achieve the soundness and zero - knowledge of the underlying MPCitH paradigm proof.
[0022] (6) A new general threshold signature construction framework is proposed. This framework requires two - round calculations among the signers holding the private keys. In the first round, each signer, according to the shared values of the private key ([s], [e]), first calls the method of checking the multiplication gate in (3) to calculate ) and at the same time performs reconstruction on the result, proving that the final result is 0 to prove that the secret in their hands satisfies that is, it satisfies the requirement that the private keys s and e are short in the LWE problem. Then, the signer calls the proof method of the linear transformation gate in (4) to prove that the secret in their hands satisfies b = As + e, that is, it satisfies the linear relationship of LWE. Finally, each signer generates the proof process P i j Copy V i j . To achieve functional interchangeability, each signer commits the copy by invoking a homomorphic commitment scheme and broadcasts the commitment to other signers holding the private keys. When a signer receives the commitment values generated by the first-round calculation from other signing parties, it starts the second-round calculation. The signer first reconstructs using the reconstruction method of the Shamir secret sharing algorithm to obtain the reconstructed N 2 copies. Then, the hash function is invoked for the reconstructed N 2 copies and the message to be signed to obtain random challenge values. The corresponding commitment values are opened according to the challenge values, and the opened commitment values are output as signature shares. Finally, the signature verifier collects the signature shares of each signer, aggregates them, and executes the verification algorithm.
[0023] Furthermore, a new verification algorithm is proposed in the verification phase. According to the proof π and the corresponding public input, the verifier runs the following verification algorithm:
[0024] a) The verifier recalculates ([r ,[Ar i ) i based on the opened i∈[1,k] , and then reconstructs the k packed secret sharing values to obtain (r,Ar i ) i∈[1,k] . Further, the verifier verifies whether it satisfies the relation: A(r i )=Ar i .
[0025] b) The verifier verifies the correct distribution of the keys: The verifier recalculates [u d (i),[e] d (i)] i based on the opened secret values [s] 2d in the proof π. Combining the [u i 2d of the users not opened in the proof for reconstruction, it verifies whether the N values belong to the same secret sharing polynomial and whether the reconstructed packed secret values are all 0.
[0026] c) The verifier verifies the correct linear relationship of the keys: The verifier calculates [s i -r i d based on the secret sharing values in the signature, and reconstructs and verifies whether all values belong to the same polynomial by combining the [s i -r i d in the unopened view copy in the signature. Further, the verifier calculates A(s i -ri ), and then the verifier re - secret - shares it to get [A(s i -r i )] d . Further, the verifier calculates [A(s i -r i )] d +[Ar i d to get [As i )] d and calculates [As i )] d +[e i )] d , and then combines the unopened [As i +e i )] d to verify whether it is equal to the public key b.
[0027] d) The verifier verifies whether all commitment values are correctly opened: The verifier recalculates according to the opened recalculates combines with in the proof. The verifier recalculates H c (com 1 , com 2 , …, com N ) and determines whether it is equal to
[0028] e) Finally, the verifier recalculates the running result of circuit C according to the opened secret value and and determines whether it is equal to 1.
[0029] Furthermore, the method of the present invention is applicable to signature schemes under any hard assumptions, including threshold signatures and single - digital signature schemes, including standard LWE and SIS problems, as well as Ring - LWE and Ring - SIS problems. The present invention's specification only takes the modular LWE problem as an example to introduce the method of the present invention.
[0030] The present invention also provides a quantum - resistant threshold digital signature system that tolerates high network latency, which includes:
[0031] A key generation module, used to randomly select a key by a trusted third party and perform Shamir secret sharing on the key, and distribute the secret - shared values to each signer;
[0032] A distributed signature module, used to perform packaged secret sharing on the secret - shared values by each signer, run the proof sub - circuit of the public key based on the secure multi - party computation protocol, and then each participant outputs a signature through two - round interaction;
[0033] A verification module, used by a verifier to verify a signature.
[0034] Compared with existing lattice-based threshold signature schemes, the present invention has the following properties and advantages:
[0035] (1) Functional interchangeability: In the threshold scheme of the present invention, the sizes of the signature and the public key are independent of the number of participants, and all system parameters and verification algorithms are consistent with the original signature scheme.
[0036] (2) High efficiency and feasibility: In the online phase of the signature protocol of the present invention, when the network delay is 300 ms in a two-party scenario, the signature time does not exceed 2 seconds.
[0037] (3) Round optimization: The number of rounds of this digital signature scheme is only 2 rounds, and it can tolerate digital signature schemes in high-latency networks. Description of the Drawings
[0038] Figure 1 is the overall flowchart of the method of the present invention.
[0039] Figure 2 is the flowchart of the distributed signature protocol of the present invention. Detailed Embodiments
[0040] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below through specific embodiments and the accompanying drawings.
[0041] The overall process of the method of the present invention is as Figure 1 shown. In the key generation phase, a trusted third party randomly selects a key and performs Shamir secret sharing on the key, and distributes the secret sharing values to each signer; in the distributed signature phase, each signer performs packaged secret sharing on the secret sharing values, runs the proof sub-circuit of the public key based on the secure multi-party computation protocol, and then each participant outputs a signature through two rounds of interaction; in the verification phase, the verifier verifies the signature.
[0042] This embodiment uses a secret-sharing-based MPC protocol, using the symbol [·] d (i) to represent the i-th share value in the Shamir secret sharing scheme of order d. Opening a secret value means that each participant discloses its own secret fragment and combines it with the remaining d - 1 secret fragments to obtain the secret value. The addition operation of sharing secrets does not require interaction. Assume that each participant P i has the i-th fragment of the shared secret value [x] d (i) and [y] d (i). Then each participant P i calculates [x] d (i) + [y]d (i) Then we can obtain [x + y] d The i-th segment of (i). The multiplication operation takes [x] d (i) and [y] d (i) as inputs and outputs [z] d (i) satisfies z = x·y mod q. The linear transformation gate operation takes as inputs the packed secret sharing [x] and the linear transformation matrix A to be performed, and outputs [Ax].
[0043] I. Key Generation Protocol
[0044] The key generation protocol KeyGen(1 λ ) is run by a trusted third party and distributes the generated public key and the shared private key shares to each signer. The protocol process is as follows:
[0045] 1. A trusted third party generates a random k×k matrix A defined over the polynomial ring R q ; where k and q are both positive integers, and each element in the matrix is an element in the polynomial ring R q . R q is defined as That is, the ring formed by polynomials with integer coefficients greater than and less than modulo the polynomial f(X); A trusted third party generates two random k-column vectors (s, e) defined over the polynomial ring R η ; where k and η are both positive integers, and each element in the matrix is an element in the polynomial ring R η . R η is defined as That is, the ring formed by polynomials with integer coefficients greater than and less than modulo the polynomial f(x).
[0046] 2. The trusted third party performs Shamir secret sharing on each coefficient of the random vectors (s, e) to obtain the shared values ([s] t , [e] t ). Further, the trusted third party calculates b = As + e. Finally, the trusted third party outputs the public key pk = (A, b) and the secret sharing of the private key ([s] t , [e] t ), assuming that the threshold signature algorithm has N 1 signers, where signer P i gets the secret sharing values ([s] t (i), [e] t (i)).
[0047] II. Distributed Signature Protocol
[0048] The process of the distributed signature protocol of the present invention is as follows Figure 2 shown. The distributed signature protocol DSign([s], [e], pk, μ) is run by N 2 participants. Each participant inputs the public key pk, the message μ, and the corresponding private key fragments [s], [e]. The specific process is as follows:
[0049] 1. Signer P i First, perform the d - order packed secret sharing algorithm on its own private key fragments ([s] t (i), [e] t (i)), and calculate [s i d ←PSS([s] t (i)), [e i d ←PSS([e] t (i)), where the function PSS represents the packed secret sharing function. Its input is a group of l - length secret values to be secretly shared, and the output is N 2 secret sharing values of this group of secrets. l is the number of coefficients of the underlying ring elements. For the packed secret sharing function PSS, assume its threshold is t, the number of secrets to be shared is l, and its order d satisfies: d = t + l + 1. The function first selects a d - order polynomial F(x) that satisfies: F(-i) = w i , i ∈ [1, l], and then randomly selects t + 1 points q i that satisfy: F(i) = q i , i ∈ [0, t]. According to the interpolation polynomial F(x), calculate its secret sharing value as PSS(w) = [w] d = (F(1), F(2), …, F(N)).
[0050] 2. Signer P i According to the packed secret sharing values of the evidence ([s i d (i), [e i d (i)), run the proof algorithm for the LWE problem:
[0051] 2.1. Pre - calculation algorithm (1 λ , A): For any j ∈ {0, 1,..., c + v}, each signer locally generates c + v + 1 l - length random vectors Then for each signer, locally generate the d - order packed secret sharing and and record it in the copy V of each virtual participant i Then the signer P i calculates its commitment value as where i ∈ {1, 2,..., N 2}, and H com is a publicly known hash function. And record Tcom i in the copy V of each virtual participant i Then the signer calculates the challenge value as where H C is a publicly known collision-resistant hash function. For any k ∈ {1,..., c}, the signer calculates and and saves them in the copy V of each virtual participant i Furthermore, for k ∈ {c + 1,..., c + v}, the signer calculates and Then pass them into the subsequent linear proof algorithm
[0052] 2.2. Proof of linear relationship b = As + e algorithm The signer uses the linear transformation generated in the precomputation stage (as shown in the precomputation stage of (2.1)) for [r i , [Ar i . First, the signer calculates [s i + [r i and records it in the copy V of each virtual participant i Then perform reconstruction to obtain s i + r i . The signer calculates A(s i + r i ) according to the matrix A that needs to perform the linear transformation, and then re-performs secret sharing to obtain [A(s i + r i . According to [A(s i + r i )] and the other element [Ar i of the linear transformation pair, the signer calls the addition gate to calculate [A(s i + r i )] - [Ar i = [As i . Finally, the signer calculates the packed secret sharing value [As i + [e i and records it in the copy V of each virtual participant i
[0053] 2.3. Algorithm SHORT([s] to prove that each coefficient of the secret key is in the range [-η, η] d (i), [e] d (i)): The signer generates 2η + 1 packed secret sharing values of different numbers [con] d (i), [con′] d (i), where con is a vector of length l with each element being con, and con ∈ [-η, η]. Further, the signer calculates [s] d (i) - [con] d (i) and [e] d (i) - [con′] d (i) and calculates [u] 2d = ([s] d (i) - [con] d (i))([s] d (i) - [-con] d (i)). Then the signer performs re - secret sharing to obtain [u] d , and at the same time calculates [z] 2d = [u] 2d - [u] d . Finally, the signer records [z] 2d and [u] d in the copy V i of each virtual participant.
[0054] 3. After the signer runs the proof algorithm for the LWE problem, it generates N 2 view copies [V] = (V 1 , …, V N ) of the proof process records. Each V i contains the messages generated by running each packed secret sharing operation gate, that is, V i = ([s i d (i), [e i d (i), [s i (i) + [r i (i), [z i 2d , [u i d , [f j (i), [Af j ). Then the signer calculates the commitment value for each copy as: and broadcasts this commitment value. Among them, HCOM H is a homomorphic commitment scheme.
[0055] 4. After each signer receives the homomorphic commitments of the views sent by the other t signers, the signer runs the Shamir secret sharing reconstruction algorithm of order t to obtain: where ShamirC is the publicly available Shamir secret sharing reconstruction algorithm of order t. Then the signer calculates the challenge value as where m is the message to be signed.
[0056] 5. According to the challenge value I, each signer P i outputs the signature share as: Finally, according to the challenge value and the signature shares of the t participating parties received, the aggregated signature is output as
[0057] III. Algorithm Verification Protocol
[0058] 1. The verifier recomputes the computational view copies of the t participating parties based on the input m and the {V j} j∈I part in the signature σ, and then uses the Shamir secret sharing reconstruction algorithm to recover the commitment values of the t participating parties: {com j} j∈I . The verifier further combines the remaining commitment values provided in the signature to compute I′ and checks its consistency with I. If I = I′, i.e., the check passes, it means that all the t commitments are correctly opened.
[0059] 2. The verifier recomputes [z i 2d based on the opened secrets of the t individuals, and combines [z i 2d in the signature to reconstruct [z i 2d and checks whether it is 0.
[0060] 3. The verifier verifies whether the precomputation is correctly executed: The verifier recomputes the precomputed [r j (i), [Af j based on [f k , and combines the opened [r k and [Ar k where k ∈ [1, c], and verifies whether it satisfies the relationship of the linear transformation matrix A. k
[0061] 4. The verifier verifies the correctness of the output, according to the opened [u i d , the verifier verifies whether its output is 0; further, according to [s i (i)+[r i (i), the verifier verifies whether the final output satisfies b = As + e.
[0062] IV. Experimental Data
[0063] An experiment of this algorithm module was developed in the present invention to simulate the solution of the present invention in a real environment. The algorithm module was implemented using the C++17 language. The polynomial and vector operations in the protocol were implemented using the NTL 11.5.12 and GNU Multiple Precision Algorithm 6.2.13 libraries, and the SHA256 and SHAKE256 algorithms in the OpenSSL library were selected as the random oracle model. The performance benchmark was carried out on a 14-inch Apple MacBook Pro laptop computer, which is driven by Apple Silicon M1 Pro (3.2 GHz), has 10 cores and 16 GB of memory.
[0064] The signature size output by this algorithm is 601.57 KB, and the communication overhead for each party is 31.92 MB. The time required for each component of the algorithm was tested in Table 1. The time required for the proof linear relation module is 85 ms, and the time required for the proof secret vector range module is 387 ms. Finally, a specific implementation is given, whose signature time is only 1.1 s and the pre-computation time is 798 ms.
[0065] Table 1. Running Time of Algorithm Module
[0066] Time Pre - calculation module Linear proof module Key proof module Commitment module 798ms 85ms 367ms 341ms
[0067] Further, the running time of this algorithm was tested on the WAN. For the WAN setting, the latency was selected to be approximately 0.3 ms and 200 ms. Table 2 shows the efficiency of the signature algorithm module of the present invention in the wide area network setting. The algorithm module of the present invention is about 15 times faster than the distributed signature protocol. The algorithm module of the present invention takes 1.95 seconds in the case of two parties.
[0068] Table 2. Running Time of Algorithm Module Network Latency Test
[0069] Wide - area network test Latency 0.3ms Latency 200ms Output size 1.911s 1.95ms 31.92MB
[0070] The present invention can be applied to application scenarios such as secure multi-party computation, key management, secure storage and access control, and cryptocurrency. For example, in cryptocurrency, since currency transactions are authorized through digital signatures, stealing the signature key can translate into specific economic losses. By adopting the solution of the present invention, the secure threshold signature of the present invention can be used to create a multi-signature wallet, and authorization by multiple private keys is required to complete a transaction. In this solution, the private key is split and distributed to multiple owners, and only when the preset threshold signature number is reached can the transaction be recognized and executed. This mechanism improves security and prevents the risk of single-point failure or private key loss.
[0071] Another embodiment of the present invention provides a quantum-resistant threshold digital signature system that tolerates high network latency, which includes:
[0072] A key generation module, configured to randomly select a key by a trusted third party and perform Shamir secret sharing on the key, and distribute the secret sharing values to each signer;
[0073] A distributed signature module, configured to perform packaged secret sharing on the secret sharing values by each signer, and run the proof sub-circuit of the public key based on the secure multi-party computation protocol, and then each participating party outputs a signature through two rounds of interaction;
[0074] A verification module, configured to verify the signature by a verifier.
[0075] The above division of each module is only an example. In actual applications, the above functions can be assigned to different functional modules according to needs to complete all or part of the functions described in the foregoing method. The specific working processes of the above modules can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0076] Another embodiment of the present invention provides a computer device (such as a computer, a server, a smart phone, etc.), which includes a memory and a processor. The memory stores a computer program, and the computer program is configured to be executed by the processor. The computer program includes instructions for executing each step in the method of the present invention.
[0077] Another embodiment of the present invention provides a computer-readable storage medium (such as ROM / RAM, a disk, an optical disc), and the computer-readable storage medium stores a computer program. When the computer program is executed by a computer, each step of the method of the present invention is implemented.
[0078] The specific embodiments of the present invention disclosed above are intended to help understand the content of the present invention and implement it accordingly. Those of ordinary skill in the art can understand that various substitutions, changes, and modifications are possible without departing from the spirit and scope of the present invention. The present invention should not be limited to the content disclosed in the embodiments of this specification, and the protection scope of the present invention shall be subject to the scope defined by the claims.
Claims
1. A quantum threshold digital signature method that tolerates high network delays, characterized in that: It includes key generation phase, distributed signature phase and verification phase; During the key generation phase, the trusted third party randomly selects a key and performs Shamir secret sharing on the key, distributing the secret sharing value to each signer; In the distributed signature phase, each signer packages the secret sharing value and runs the public key proof subcircuit based on the secure multi-party computing protocol. Then each participant outputs the signature through two rounds of interaction. During the verification phase, the verifier verifies the signature.
2. The method according to claim 1, characterized in that The key generation phase includes the following steps: A trusted third party generates a polynomial ring R q A is a random matrix A with k rows and k columns on the y-axis, where k and q are both positive integers and each element in the matrix is a polynomial ring R. q Elements in R q Defined as That is greater than Less than The ring of polynomials with integer coefficients under the modular polynomial f(X); a trusted third party generates two polynomials defined in the polynomial ring R η k-column random vector (s, e) on the matrix, where k and η are both positive integers, and each element in the matrix is a polynomial ring R η Elements in R η Defined as That is greater than Less than The ring of polynomials with integer coefficients under the modular polynomial f(X); The trusted third party performs d-order Shamir secret sharing on each coefficient of the random vector (s, e) and obtains the secret sharing value ([s] d ,[e] d ); the trusted third party calculates b = As + e; finally, the trusted third party outputs the public key pk = (A, b) and the secret sharing of the private key ([s] d ,[e] d ), assuming that the threshold signature algorithm has N1 signers, of which signer P i Get the secret shared value ([s] d (i),[e] d (i)).
3. The method according to claim 2, characterized in that The distributed signature phase includes the following steps: In the threshold signature algorithm, each participant P i Pair of private key[s] d (i),[e] d (i) Perform package secret sharing The input of the packaged secret sharing is a vector of coefficients of the ring elements corresponding to a secret, and the output is the shared value of the secret vector. The total number of shared values output by the packaged secret sharing is N2; represents the private key of the i-th participant[s] d (i) N2 secret shares obtained by the packaged secret sharing algorithm, represents the noise part of the private key of the ith participant [e] d (d) N2 secret shares obtained by the packaged secret sharing algorithm, where PSS represents the packaged secret sharing algorithm; Each signer runs the MPCitH paradigm, where the jth party simulated by the i-th signer in the virtual MPC is denoted by Each signer first generates 2η+1 packaged secret shares about constants {-η,...,η}, combined with the private key s i,j ,e i,j As Private input of The signers holding the private key complete two rounds of calculations: In the first round, each signer first calls the method of checking the multiplication gate according to the shared value of the private key ([s], [e]) to calculate At the same time, the result is reconstructed to prove that the final result is 0 to prove that the secret in his hand satisfies Then the signer calls the linear transformation gate proof method to prove that the secret in his hand satisfies b=As+e. Finally, each signer generates a proof process. A copy of V i j ; In order to achieve functional interchangeability, each signer calls the homomorphic commitment scheme on the copy to make a commitment, and broadcasts the commitment to other signers holding private keys; when the signer obtains the commitment value generated by the first round of calculation from other signatories, the second round of calculation begins. The signer first uses the reconstruction method of the Shamir secret sharing algorithm to reconstruct and obtain the reconstructed N2 copies, and then calls the hash function on the reconstructed N2 copies and the message to be signed to obtain a random challenge value, opens the corresponding commitment value according to the challenge value, and outputs the opened commitment value as the signature share. Finally, the signature verifier collects the signature shares of each signer for aggregation and executes the verification algorithm.
4. The method according to claim 3, characterized in that The method for checking a multiplication gate comprises: For a d-order packed secret sharing scheme, the multiplication gate inputs the two secret sharing values [x] that need to be multiplied. d and [y] d , the signer first calculates [z] 2d =[x] d ·[y] d , then the signer generates a new packed secret share [z] d , and [z] d As output; For the verifier, the verifier requires the signer to open part [z] 2d -[z] d The secret sharing value of [z] is determined by reconstructing and verifying whether it is a packaged secret sharing value of 0. d =[x] d ·[y] d ; The signer uses the new packed secret share [z] d Perform calculations for subsequent circuit gates.
5. The method according to claim 3, characterized in that: The linear transformation gate proof method comprises: For the packaged secret sharing scheme, a linear transformation pair [r] is first generated through a pre-calculation algorithm. d and [Ar] d , the signer first calculates [s] d +[r] d , and then reconstruct to get the value of s+r; The signer calculates A(s+r), and then packages the result and shares it secretly to get [A(s+r)] d , and finally the signer calculates [A(s+r)] d -[Ar] d +[e] d , and then reconstruct to determine whether it is equal to the public key b.
6. The method according to claim 5, characterized in that The pre-calculation algorithm used in the distributed signature stage includes: The signer generates k+v+1 random pairs ([f0] d ,[Af0] d ),([f1] d ,[Af1] d ),...,([f k+v ] d ,[Af k+v ] d ). Then the verifier generates k+v random challenge values α1, α2, ..., α k+v ; Based on the challenge value, the signer calculates and For i∈[1,k], the signer publicly i ] and [γ i ]. The verifier verifies A[β i ]=[γ i ], for the remaining i∈[k+1,v], the signer uses [β i ] and [γ i ] to perform the proof of linear transformation gates to achieve the soundness and zero-knowledge of the underlying MPCitH paradigm proof.
7. The method according to claim 1, characterized in that The verification phase includes the following steps: The verifier opens Recalculate ([r i ],[Ar i ]) i∈[1,k] , and then reconstruct the k packaged secret sharing values to obtain (r i ,Ar i ) i∈[1,k] , the verifier verifies whether it satisfies the relationship: A(r i )=Ar i ; The verifier verifies the correctness of the key distribution: the verifier verifies the secret value [s] opened in the proof π d (i),[e] d (i) Recalculate [u i ] 2d , combined with the user's [u i ] 2d Reconstruct and verify whether the N values belong to the same secret sharing polynomial and whether the reconstructed packaged secret values are all 0; The verifier verifies the correctness of the linear relationship of the key: the verifier calculates [s i -r i ] d , combined with the [s i -r i ] d Reconstruct it and verify that all values belong to the same polynomial; the verifier calculates A(s i -r i ), and then the verifier re-shares the secret to obtain [A(s i -r i )] d ; The verifier calculates [A(s i -r i )] s +[Ar i ] d Get [As i ] d And calculate [As i ] d +[e i ] d , then combined with the unopened [As i +e i ] d Verify that it is equal to public key b; The verifier verifies that all commitment values are opened correctly: the verifier verifies that all commitment values are opened correctly. Recalculate Combined with the proof The verifier recalculates H c (com1,com2,…,com N ) and determine whether it is equal to The verifier uses the opened secret value and Recalculate the operation result of circuit C and determine whether it is equal to 1.
8. A quantum threshold digital signature system that tolerates high network delays, characterized in that: include: The key generation module is used for a trusted third party to randomly select a key and perform Shamir secret sharing on the key, and distribute the secret sharing value to each signer; The distributed signature module is used for each signer to package and secretly share the secret sharing value, and run the public key certification subcircuit based on the secure multi-party computing protocol. Then each participant outputs the signature through two rounds of interaction; The verification module is used to verify the signature by the verifier.
9. A computer device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program comprises instructions for executing the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Multi-party collaborative anti-quantum signature method and system based on homomorphic hash
CN120979680A
Quantum-resistant verifiable rational secret sharing method
CN121485937A
Quantum-resistant verifiable rational secret sharing method
CN121485937B