Casual transmission method, system and equipment based on elliptic curve and medium
By using elliptic curve encryption and mapping functions and obfuscated ciphertext design methods in the inadvertent transmission protocol, the problem of key exchange and computing complexity in the prior art is solved, efficient and secure data transmission is achieved, and suitable for complex computing scenarios.
Patent Information
- Application Number
- CN202510644678.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-05-20
AI Technical Summary
Existing inadvertent transmission protocols have problems with key exchange and computing complexity, especially in resource-constrained IoT devices, which lead to a surge in communication latency and energy consumption, while it is difficult to adapt to the diversified needs of complex computing scenarios.
The inadvertent transmission method based on elliptic curves is adopted to achieve efficient and low-complex data transmission through elliptic curve encryption, and enhance information protection through mapping functions and obfuscated ciphertexts, supporting a variety of elliptic curves and mapping functions, which are suitable for scenarios such as multi-party security calculations.
It significantly reduces the computational complexity and communication load of key exchange, reduces the number of large digital-to-analog operations and exponential operations, improves the efficiency and security of the protocol in resource-constrained scenarios, and is suitable for complex computing scenarios, providing flexible and powerful information security guarantees.
Smart Images

Figure CN120165870A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and more particularly to an oblivious transfer method, system, device, and medium based on elliptic curves. Background Art
[0002] The oblivious transfer protocol (OT) is one of the fundamental protocols of secure multi-party computation (MPC). The sender can transfer multiple messages to the receiver, but the receiver can only decrypt the selected message, and the sender cannot know the specific selection. This protocol plays an irreplaceable role in fields such as set intersection, federated learning, and secure outsourcing computing.
[0003] Traditional OT schemes generally rely on public key cryptosystems such as RSA or Diffie-Hellman (DH), and a key length of more than 3072 bits is required to cope with the security threats brought by the evolution of computing power. Such long keys lead to frequent execution of large integer modular exponentiation operations during the key negotiation phase, and the single calculation time can reach dozens of milliseconds, which is extremely likely to cause communication delays and a sharp increase in energy consumption in resource-constrained Internet of Things devices. For example, the OT protocol based on DH needs to complete at least two modular exponentiation operations in one interaction, and its computational overhead accounts for more than 30% of the total energy consumption of the device, seriously restricting the real-time requirements.
[0004] In addition, existing OT protocols mostly adopt fixed parameter configurations and are difficult to adapt to the diverse requirements of complex computing scenarios. For example, in cross-institutional multi-party secure computing, participants may adopt different elliptic curve standards, and they cannot dynamically be compatible with multi-curve parameters, resulting in low collaboration efficiency. At the same time, the key generation and ciphertext construction mechanisms lack modular design and are difficult to support customizable mapping functions or dynamic random number injection.
[0005] Therefore, how to design an oblivious transfer method based on elliptic curves to improve the key exchange efficiency, reduce the computational complexity, and enhance the security at the same time is an urgent problem for those skilled in the art. Summary of the Invention
[0006] In view of this, the present invention provides an oblivious transfer method based on elliptic curves, which realizes efficient and low-complexity data transmission by using elliptic curve encryption, and enhances information protection through a mapping function and obfuscated ciphertext; it supports multiple elliptic curves and mapping functions, is applicable to scenarios such as multi-party secure computing, and provides flexible and powerful information security protection.
[0007] To achieve the above object, the present invention adopts the following technical solutions:
[0008] In the first aspect, the present invention provides an oblivious transfer method based on elliptic curves, including the following steps:
[0009] S1. The two communicating parties select an elliptic curve E and determine a base point G on the elliptic curve E; where the order of G is t, satisfying tG = o, and o is the infinite point;
[0010] S2. The sender generates a random private key d and calculates the public key Q = dG, randomly generates a point P0 on the elliptic curve, and makes the public key Q, the random point P0, and the total number of messages n to be transmitted public;
[0011] S3. The receiver generates a random number r k , and maps r k to a point P on the elliptic curve k . For each message index i, construct the confused ciphertext C 1i = r k G+(k - i)P0 and the auxiliary ciphertext C2 = P k +r k Q, and send all (C 1i , C2) to the sender;
[0012] S4. The sender uses the private key d to decrypt each (C 1i , C2), obtains n random numbers, and encrypts the n messages with them as symmetric keys, and sends the encryption result to the receiver;
[0013] S5. The receiver performs symmetric decryption on the k-th encrypted message with the random number r k to obtain the target message m k .
[0014] Furthermore, in the S1,
[0015] the elliptic curve E satisfies the equation of the elliptic curve over the prime field y 2 = x 3 +ax + b, and 4a 3 +27b 2 ≠0; or the 256-bit prime field elliptic curve defined by the national cryptographic standard SM2 is adopted.
[0016] Furthermore, in the S3, when generating the random number r k combine the timestamp T and the hardware unique identifier ID:
[0017] r k = H rand (T||ID||s)
[0018] where s represents the pre-shared seed, and || represents the concatenation operation.
[0019] Furthermore, in the S3, the mapping function is expressed as f: Z t →S, where Z tDenote the finite field \(\{1, 2, \cdots, t - 1\}\) as \(Z_t\), and \(S\) represents the set of points on the elliptic curve; the mapping function satisfies:
[0020] For any \(r\in Z\) t , there exists a unique \(P\in S\) such that \(P = f(r)\); for any \(P\in S\), there exists a unique \(r\in Z\) t , such that \(r = f\) -1 (P); if the point \(P\) generates a new point \(P'\) through elliptic curve operations, then there exists \(r'\in Z\) t such that \(P' = f(r')\).
[0021] Furthermore, in the above \(S_3\), the confused ciphertext \(C\) 1i satisfies the following confusion mechanism:
[0022] When \(i\neq k\), \(C\) 1i contains \((k - i)P_0\) terms, resulting in the random number \(r'\) mapped after decryption i being independent of the true random number \(r\) k , such that the sender cannot infer the recipient's selected bit \(k\) through \(r'\) i ; when \(i = k\), \(C\) 1i = r k G, ensuring that the recipient can uniquely restore \(P\) after decrypting with the private key \(d\) k , and then correctly obtain \(r\) through the inverse mapping function k , achieving the exact decryption of the target elimination \(m\) k .
[0023] Furthermore, the above \(S_4\) includes:
[0024] \(S_{41}\): Calculate \(P' = C_2 - dC\) 1i for each \((C\) i , \(C_2)\) to obtain the point \(P'\) on the elliptic curve 1i ; i
[0025] \(S_{42}\): Restore \(P'\) i to the random number \(r'\) through the inverse mapping function i ;
[0026] \(S_{43}\): Use the random number \(r'\) i as the symmetric key to encrypt the message \(m\) i , and the encryption formula is \(Enc(m\) i ) = H key (r i ) \(\oplus m\) i .
[0027] Furthermore, the above \(S_5\) includes:
[0028] Generate the symmetric key \(H(r\) using the random number \(r\) k k ) Decrypt the k-th encrypted message, and the decryption formula is m k =Enc(m k ) ⊕ H key (r k ).
[0029] In a second aspect, the present invention provides an oblivious transfer system based on elliptic curves, including:
[0030] Parameter initialization module: used for both communication parties to select an elliptic curve E and determine the base point G on the elliptic curve E; where the order of G is t, satisfying tG = o, and o is the infinite point;
[0031] Key generation and public module: used for the sender to generate a random private key d and calculate the public key Q = dG, randomly generate a point P0 on the elliptic curve, and make the public key Q, the random point P0, and the total number of messages to be transmitted n public;
[0032] Ciphertext construction module: used for the receiver to generate a random number r k , map r k to a point P k on the elliptic curve. For each message index i, construct the confused ciphertext C 1i =r k G+(k−i)P0 and the auxiliary ciphertext C2 = P k +r k Q, and send all (C 1i , C2) to the sender;
[0033] Ciphertext decryption and message encryption module: used for the sender to decrypt each (C 1i , C2) using the private key d to obtain n random numbers, and use them as symmetric keys to encrypt n messages, and send the encryption result to the receiver;
[0034] Message decryption module: used for the receiver to perform symmetric decryption on the k-th encrypted message through the random number r k to obtain the target message m k .
[0035] In a third aspect, the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the above-mentioned oblivious transfer method based on elliptic curves.
[0036] In a fourth aspect, the present invention provides a computer-readable storage medium, where the storage medium stores a computer program, and when the computer program is executed by a processor, it implements the above-mentioned oblivious transfer method based on elliptic curves.
[0037] For the descriptions of the second to fourth aspects in the present invention, reference may be made to the detailed description of the first aspect; and for the beneficial effects of the descriptions of the second to fourth aspects, reference may be made to the analysis of the beneficial effects of the first aspect, which will not be elaborated here.
[0038] As can be seen from the above technical solutions, compared with the prior art, the present invention has the following beneficial effects:
[0039] 1. By adopting elliptic curve cryptography to replace the traditional RSA and Diffie-Hellman algorithms, this solution shortens the key length under the same security strength, significantly reducing the computational complexity and communication load in the key exchange phase. Combining symmetric encryption with the mechanism of obfuscated ciphertext further reduces the number of large number modular operations and exponentiation operations, enabling the protocol to still operate efficiently in resource-constrained scenarios such as the Internet of Things and edge computing, effectively alleviating the problems of computational resource consumption and communication delay.
[0040] 2. Through the design of the mapping function and obfuscated ciphertext, the indistinguishability between the ciphertext and the random number is ensured, preventing an adversary from deducing the original information or selecting bit data through the ciphertext, thus providing future-oriented security guarantees for complex computational scenarios such as multi-party secure computing and information set intersection.
[0041] 3. It supports multiple elliptic curves and configurable combinations of mapping functions. By the requirements of the uniqueness, coverage, and invertibility of the bijective function, the generality of the protocol in different complex computational scenarios is ensured. It can be seamlessly integrated into complex applications such as multi-party collaboration and dynamic data fusion, expanding the application boundary of the oblivious transfer technology. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the descriptions of the embodiments or the prior art. Obviously, the drawings in the following descriptions are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0043] Figure 1 It is a flowchart of an oblivious transfer method based on elliptic curves provided for an embodiment of the present invention;
[0044] Figure 2 It is a schematic diagram of the encryption process of the sender provided for an embodiment of the present invention;
[0045] Figure 3 It is a schematic diagram of the specific implementation process of oblivious transfer in a smart home system provided for an embodiment of the present invention;
[0046] Figure 4A framework diagram of an oblivious transfer system based on an elliptic curve provided by an embodiment of the present invention;
[0047] Figure 5 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners
[0048] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0049] The oblivious transfer method provided by the embodiments of the present application can be applied to an oblivious transfer server, and the oblivious transfer server can be hardware or software. When the oblivious transfer server is hardware, it can be implemented as a distributed server cluster providing oblivious transfer services or as a single server. When the oblivious transfer server is software, it can be installed in the servers listed above. It can be implemented as multiple software or software modules, or as a single software or software module, which is not specifically limited herein.
[0050] Embodiment 1;
[0051] As Figure 1 shown, this embodiment provides an oblivious transfer method based on an elliptic curve, including the following steps:
[0052] S1. The two communication parties select an elliptic curve E and determine the base point G on the elliptic curve E; where the order of G is t, satisfying tG = o, and o is the infinite point;
[0053] S2. The sender generates a random private key d and calculates the public key Q = dG, randomly generates a point P0 on the elliptic curve, and makes the public key Q, the random point P0, and the total number n of messages to be transmitted public;
[0054] S3. The receiver generates a random number r k , maps r k to a point P k on the elliptic curve, constructs a confused ciphertext C 1i = r k G+(k−i)P0 and the auxiliary ciphertext C2 = P k +r k Q for each message index i, and sends all (C 1i , C2) to the sender;
[0055] S4. The sender uses the private key d for each (C1i , C2) Decrypt to obtain n random numbers, use them as symmetric keys to encrypt n messages, and send the encryption results to the receiver;
[0056] S5. The receiver uses the random number r k to perform symmetric decryption on the k-th encrypted message to obtain the target message m k .
[0057] This method uses elliptic curve encryption to replace the traditional algorithm, significantly reducing the computational complexity and communication load of key exchange. Through a flexible mapping function and obfuscated ciphertext design, the scheme ensures data security in complex computing scenarios, supports multiple elliptic curves and configurable combinations, enhances the generality and scalability of the protocol, and provides an efficient, secure, and flexible solution for complex applications such as multi-party secure computing.
[0058] The following further elaborates on each step in the above method;
[0059] In this embodiment S1, the two communicating parties select an elliptic curve E and determine the base point G on the elliptic curve E; where the order of G is t, satisfying tG = o, and o is the infinite point;
[0060] Among them, the elliptic curve E satisfies the equation y 2 = x 3 + ax + b for the elliptic curve over a prime field, and 4a 3 + 27b 2 ≠ 0; or the 256-bit elliptic curve over a prime field defined by the national cryptography standard SM2. Specifically, the parameters of the elliptic curve E are dynamically selected during the protocol initialization phase, including the two communicating parties negotiating and selecting elliptic curves with different prime field lengths based on real-time network latency, device computing power, or a preset security level.
[0061] In this embodiment S2, the sender generates a random private key d and calculates the public key Q = dG, randomly generates a point P0 on the elliptic curve, and makes the public key Q, the random point P0, and the total number of messages n to be transmitted public;
[0062] In this step, the sender first generates a random private key d, and performs a scalar multiplication operation on the base point G on the elliptic curve to obtain the public key Q = dG. Then, the sender randomly selects a point P0 on the elliptic curve as a parameter during the protocol execution. Finally, the sender makes the public key Q, the random point P0, and the total number of messages n to be transmitted public so that the receiver can generate corresponding obfuscated ciphertexts based on this information and participate in the oblivious transfer protocol.
[0063] In this embodiment S3, the receiver generates a random number r k , and through the mapping function, r kMap to the point P on the elliptic curve k , for each message index i, construct the obfuscated ciphertext C 1i = r k G+(k−i)P0 and the auxiliary ciphertext C2 = P k + r k Q, and send all (C 1i , C2) to the sender;
[0064] Among them, generate the random number r k Combine the timestamp T with the hardware unique identifier ID:
[0065] r k = H rand (T||ID||s)
[0066] Among them, s represents the pre-shared seed, || represents the concatenation operation, and H rand Adopts a collision-resistant hash function.
[0067] Furthermore, the mapping function is expressed as f: Z t → S, where Z t represents the finite field {1, 2...... t - 1}, and S represents the set of points on the elliptic curve; the mapping function satisfies:
[0068] For any r ∈ Z t , there exists a unique P ∈ S such that P = f(r); for any P ∈ S, there exists a unique r ∈ Z t such that r = f -1 (P); if the point P generates a new point P' through elliptic curve operations, then there exists r' ∈ Z t such that P' = f(r').
[0069] Specifically, the mapping function can adopt a hierarchical hash-elliptic curve encoding mechanism, specifically including: passing the random number r k through the hash function H1 to generate the intermediate value h = H1(r k ), and then passing the intermediate value h through the hash function H2 to generate the deterministic elliptic curve point P k , and restoring r layer by layer during the inverse mapping k ; among them, the first hash function H1 is a collision-resistant hash function, and the output length is compatible with the elliptic curve encoding algorithm; the second hash function H2 is a deterministic reversible elliptic curve point encoding function.
[0070] Furthermore, the obfuscated ciphertext C 1i satisfies the following obfuscation mechanism:
[0071] When i ≠ k, C 1i contains the (k−i)P0 term, resulting in the random number r' iIndependent of the true random number r k such that the sender cannot infer the receiver's selected bit k through r′ i ; when i = k, C 1i = r k G, ensuring that the receiver uniquely restores P k by decrypting with the private key d, and then correctly obtains r k through the inverse mapping function, achieving the precise decryption of the target elimination m k .
[0072] In this embodiment S4, the sender uses the private key d to decrypt each (C 1i , C2) to obtain n random numbers, and uses them as symmetric keys to encrypt n messages, and sends the encryption results to the receiver; as Figure 2 shown, it specifically includes:
[0073] S41. Calculate P′ 1i = C2 − dC i for each (C 1i to obtain the point P′ i on the elliptic curve;
[0074] S42. Restore P′ i to the random number r′ i through the inverse mapping function;
[0075] S43. Use the random number r′ i as the symmetric key to encrypt the message m i , and the encryption formula is Enc(m i ) = H key (r i ) ⊕ m i .
[0076] In this embodiment S5, the receiver performs symmetric decryption on the k-th encrypted message using the random number r k to obtain the target message m k ; specifically including:
[0077] Use the random number r k to generate the symmetric key H(r k ); decrypt the k-th encrypted message, and the decryption formula is m k = Enc(m k ) ⊕ H key (r k ), where
[0078] H key adopts a lightweight hash function.
[0079] The following is about the correctness and security of an oblivious transfer method based on elliptic curves in this embodiment
[0080] For further illustration:
[0081] In terms of correctness, it is based on the closure of elliptic curve operations and the invertibility of the mapping function. The receiver constructs the confused ciphertext C 1i =r k G+(k−i)P0 and the auxiliary ciphertext C2=P k +r k Q. During decryption, the private key d is used for calculation to calculate P′ i =C2−dC 1i , obtaining the point P′ on the elliptic curve i . Combining with the inverse mapping function, the random number r can be uniquely restored k , thereby correctly decrypting the target message m k ; The sender ensures that the receiver can only decrypt the specified message through the closure of elliptic curve points. The remaining confused ciphertexts remain irreversible because the original points and confused points cannot be distinguished, thus ensuring the correctness of the protocol execution.
[0082] In terms of security, the protocol relies on the dual mechanisms of the elliptic curve discrete logarithm problem (ECDLP) and symmetric encryption. ECDLP ensures that the private key d cannot be deduced from the public key Q=dG. The structural design of the confused ciphertext and the auxiliary cipher further prevents the sender from inferring the message index k selected by the receiver. At the same time, the mapping function and the hierarchical hash coding technology ensure the uniqueness of the generation and restoration of elliptic curve points, avoiding information leakage.
[0083] This method significantly reduces the computational and communication overheads through the dynamic negotiation of elliptic curve parameters and the efficient implementation of lightweight hash functions, and is applicable to complex computational scenarios with high real-time requirements.
[0084] Example 2;
[0085] In a smart home system, the smart door lock needs to encrypt and transmit the user's unlocking logs to the cloud server, requiring the cloud to only decrypt the logs for a specified time period (such as the last 24 hours).
[0086] This example realizes the efficient and secure selective transmission of logs through the oblivious transfer protocol of elliptic curves, as Figure 3 shown. The specific implementation steps include:
[0087] 1) Initialization of elliptic curve parameters;
[0088] The smart door lock (sender) and the cloud server (receiver) dynamically negotiate the elliptic curve parameters. The 256-bit prime field elliptic curve of the national cryptographic standard SM2 is selected, which satisfies the equation y 2 =x 3+ax + b (mod p), where p is a 256-bit prime number, and the specific parameters conform to the GM / T 0003-2012 standard. The two parties determine that the order of the base point G is t, satisfying tG = o, where o is the infinite point.
[0089] 2) Sender key generation and parameter disclosure;
[0090] The smart lock generates a random private key d ∈ {1, 2,..., t−1}, calculates the public key Q = dG, and randomly selects an elliptic curve point P0. Subsequently, the public key Q, the random point P0, and the total number of logs n = 24 are disclosed to the cloud; the private key d is only retained by the sender for subsequent decryption operations.
[0091] 3) Receiver constructs the obfuscated ciphertext;
[0092] The cloud needs to decrypt the logs at the k = 12th hour (example). First, a random number r is generated by concatenating the timestamp T, the device unique identifier ID, and the pre-shared seed s. k , Subsequently, r is mapped to an elliptic curve point P k through hierarchical hash encoding. k , and the obfuscated ciphertext is constructed:
[0093] For each hour index i ∈ {1, 2,..., 24}, generate C 1i = r k G+(12−i)P0 and the auxiliary ciphertext C2 = P k + r k Q; and send all (C 1i , C2) to the smart lock to ensure that the sender cannot infer the target index.
[0094] 4) Sender encrypts the logs;
[0095] The smart lock decrypts the received ciphertext using the private key d. For each (C 1i , C2), calculate P′ i = C2−dC 1i ,
[0096] After simplification, only when i = 12, P′ i = P k , and the rest are invalid obfuscated points; P′ i is restored to the random number r′ i through the inverse mapping function. Only r′ 12 = r k is valid; subsequently, the random number r′ i is used as the symmetric key to encrypt the log m i , and the encryption formula is Enc(m i ) = H key (r i ) ⊕ mi , and send the encryption result to the cloud.
[0097] 5) The recipient decrypts;
[0098] The cloud uses r k to generate the symmetric key K 12 , decrypt the target log Enc(m 12 ) ⊕ K 12 = m 12 ; Through the time index k and the obfuscated ciphertext design, the cloud can only decrypt the log with k = 12, and the historical data cannot be restored due to key obfuscation;
[0099] In this embodiment, through dynamic parameter negotiation, obfuscated ciphertext design, and lightweight hash function, efficient log transmission is achieved in the smart home scenario. The cloud can only decrypt the logs within a specified time period, and the remaining data is irreversible due to the obfuscation mechanism, meeting the information protection requirements and being applicable to resource-constrained IoT devices.
[0100] Embodiment 3;
[0101] As Figure 4 shown, this embodiment provides an oblivious transfer system based on elliptic curves, including:
[0102] Parameter initialization module: used for both communication parties to select an elliptic curve E and determine the base point G on the elliptic curve E; where the order of G is t, satisfying tG = o, and o is the infinite point;
[0103] Key generation and public module: used for the sender to generate a random private key d and calculate the public key Q = dG, randomly generate a point P0 on the elliptic curve, and publicly disclose the public key Q, the random point P0, and the total number of messages n to be transmitted;
[0104] Ciphertext construction module: used for the recipient to generate a random number r k , map r k to a point P on the elliptic curve through a mapping function k , for each message index i, construct the obfuscated ciphertext C 1i = r k G + (k - i)P0 and the auxiliary ciphertext C2 = P k + r k Q, and send all (C 1i , C2) to the sender;
[0105] Ciphertext decryption and message encryption module: used for the sender to decrypt each (C 1i , C2) using the private key d, obtain n random numbers, and encrypt n messages as the symmetric key, and send the encryption result to the recipient;
[0106] Message decryption module: For the receiving party to perform symmetric decryption on the k-th encrypted message through the random number r k to obtain the target message m k .
[0107] This embodiment provides an oblivious transfer system based on elliptic curves, including a parameter initialization module, a key generation and public module, a ciphertext construction module, a ciphertext decryption and message encryption module, and a message decryption module. Through this series of modules, efficient and secure data transmission is achieved. It not only reduces the computational complexity and communication load in traditional OT schemes, but also can be applied to various application scenarios that require high information protection, such as federated learning, etc., ensuring the integrity of data during transmission.
[0108] Embodiment 4;
[0109] As Figure 5 shown, this embodiment provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the oblivious transfer method based on elliptic curves in the above embodiment.
[0110] Embodiment 5;
[0111] This embodiment provides a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, it implements the oblivious transfer method based on elliptic curves in the above embodiment.
[0112] In the above embodiments provided by the present application, it should be understood that the disclosed methods, systems, devices, and media can be implemented in other ways. The method, system, device, and media embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division, and there may be other division methods in actual implementation. Each functional unit can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0113] Combined with the units and algorithm steps of each example described in the embodiments disclosed herein, they can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present application.
[0114] Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory, random access memory, electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0115] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. An oblivious transmission method based on elliptic curves, characterized in that: The following steps are involved: S1. The two communicating parties select an elliptic curve E and determine the base point G on the elliptic curve E; where the order of G is t, and tG=o is satisfied, and o is a point at infinity; S2. The sender generates a random private key d and calculates the public key Q=dG, randomly generates a point P0 on the elliptic curve, and makes the public key Q, the random point P0, and the total number of messages to be transmitted n public; S3. The receiver generates a random number r k , r is transformed by mapping function k Mapped to a point P on the elliptic curve k , for each message index i, construct the obfuscated ciphertext C 1i =r k G+(k−i)P0 and auxiliary ciphertext C2=P k +r k Q, and all (C 1i ,C2) sent to the sender; S4, the sender uses the private key d to 1i ,C2) decrypts to obtain n random numbers, and uses them as symmetric keys to encrypt n messages, and sends the encrypted results to the receiver; S5, the receiver passes the random number r k Symmetrically decrypt the kth encrypted message to obtain the target message m k .
2. The oblivious transmission method based on elliptic curve according to claim 1, characterized in that: In S1, The elliptic curve E satisfies the equation y 2 =x 3 +ax+b prime field elliptic curve, and 4a 3 +27b 2 ≠0; or use the 256-bit prime field elliptic curve defined by the national cryptographic standard SM2.
3. The oblivious transmission method based on elliptic curve according to claim 1, characterized in that: In S3, a random number r is generated. k Combine the timestamp T with the hardware unique identification ID: r k =H rand (T||ID||s) Among them, s represents the pre-shared seed, and || represents the concatenation operation.
4. The oblivious transmission method based on elliptic curve according to claim 1, characterized in that: In S3, the mapping function is represented by f:Z t →S, where Z t represents a finite field {1,2...t-1}, S represents a point set on an elliptic curve; the mapping function satisfies: For any r∈Z t , there is a unique P∈S such that P=f(r); for any P∈S, there is a unique r∈Z t , so that r = f -1 (P); If point P generates a new point P' through elliptic curve operation, then there exists r'∈Z t So that P'=f(r').
5. The oblivious transmission method based on elliptic curve according to claim 1, characterized in that: In S3, the obfuscated ciphertext C 1i The following obfuscation mechanisms are met: When i≠k, C 1i Contains (k−i)P0 items, resulting in the random number r′ mapped after decryption i With the real random number r k irrelevant, so that the sender cannot pass r′ i Infer the receiver's selection bit k; when i=k, C 1i =r k G, ensures that the receiver can only restore P after decryption using the private key d k , and then correctly obtain r through the inverse mapping function k , achieve the target elimination k Accurate decryption.
6. The oblivious transmission method based on elliptic curve according to claim 1, characterized in that: The S4 includes: S41. For each (C 1i ,C2) Calculate P′ i =C2−dC 1i , get the point P′ on the elliptic curve i ; S42, P′ is transformed into i Restore to random number r′ i ; S43, using random number r' i As a symmetric key pair for message m i Encryption is performed, and the encryption formula is Enc(m i )=H key (r i )⊕m i .
7. The oblivious transmission method based on elliptic curve according to claim 1, characterized in that: The S5 includes: Use a random number r k Generate a symmetric key H(r k ); decrypt the kth encrypted message, the decryption formula is m k =Enc(m k )⊕H key (r k ).
8. An oblivious transmission system based on elliptic curves, characterized in that: include: Parameter initialization module: used by the communicating parties to select an elliptic curve E and determine the base point G on the elliptic curve E; where the order of G is t, and tG=o is satisfied, and o is the point at infinity; Key generation and disclosure module: used by the sender to generate a random private key d and calculate the public key Q=dG, randomly generate a point P0 on the elliptic curve, and disclose the public key Q, the random point P0, and the total number of messages to be transmitted n; Ciphertext building block: used by the receiver to generate a random number r k , r is transformed by mapping function k Mapped to a point P on the elliptic curve k , for each message index i, construct the obfuscated ciphertext C 1i =r k G+(k−i)P0 and auxiliary ciphertext C2=P k +r k Q, and all (C 1i ,C2) sent to the sender; Ciphertext decryption and message encryption module: used by the sender to use the private key d for each (C 1i ,C2) decrypts to obtain n random numbers, and uses them as symmetric keys to encrypt n messages, and sends the encrypted results to the receiver; Message decryption module: used by the receiver to pass the random number r k Symmetrically decrypt the kth encrypted message to obtain the target message m k .
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the oblivious transmission method based on elliptic curve according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the oblivious transmission method based on elliptic curves according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Mass transmission method and device based on elliptic curve
CN112055021A
Data casual transmission method and device, electronic equipment and storage medium
CN113259329A
Verifiable casual transmission method based on elliptic curve
CN114422135A
Homomorphic encryption-based casual transmission method, medium and electronic equipment
CN116781243A
Casual transmission method and device
CN119172078A