Grid-based key randomization threshold signature method and apparatus, and electronic device

Through the grid-based key randomization method, the problem of low threshold signature efficiency and inability to be applicable to distributed applications of multi-signer in the prior art is solved, efficient and flexible threshold signatures are achieved, and security is enhanced.

CN120165874APending Publication Date: 2025-06-17XIDIAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510227288.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The existing threshold signature method based on grid cryptography algorithm requires three rounds of online interaction, resulting in high overhead and low efficiency, and cannot be applied to distributed application scenarios with multiple signers.

Method used

Through the grid-based key randomization method, the keys of multiple active signers are obtained and re-randomized. The leader's status information is determined in the offline stage, and the threshold signature is generated using a random value aggregation algorithm in the online stage.

Benefits of technology

Improves the efficiency and flexibility of threshold signatures, and can be suitable for distributed application scenarios to prevent security problems caused by key leakage and quantum computing attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165874A_ABST
    Figure CN120165874A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and provides a lattice-based key randomization threshold signature method and device and electronic equipment, and the method comprises the steps: obtaining the keys of a plurality of active signers according to system parameters, and obtaining the key randomization threshold signature of the plurality of active signers according to the keys corresponding to the plurality of active signers, a random character string and an auxiliary character string; and obtaining re-random keys corresponding to the plurality of active signers. In the offline stage, first state information and preprocessing information of a plurality of active signers are obtained, and second state information of a leader is determined according to the first state information and the preprocessing information. And in the online stage, according to the multiple re-random keys, the to-be-signed object, the multiple pieces of first state information and the second state information, obtaining a threshold signature through a random value aggregation algorithm. The method can be applied to a distributed application scene, security risks existing during key leakage are prevented, the flexibility of threshold signature is improved, the security problem caused by quantum computing attack is effectively prevented, and the threshold signature efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a threshold signature method, apparatus, and electronic device based on lattice-based key randomization. Background Art

[0002] With the continuous evolution of the Internet and digital technologies, threshold signature has become a research direction that has received much attention. Threshold signature is an encrypted digital signature protocol that is widely used in fields such as finance, supply chain management, Internet of Things, government services, and healthcare. Specifically, threshold signature improves security and reliability by splitting the private key into multiple parts and requiring at least the number of signers reaching the threshold value to participate in cooperation to generate a valid signature.

[0003] In the prior art, threshold signatures are generated through lattice-based cryptographic algorithms. Specifically, threshold signatures are completed through three or more rounds of online interactions, as well as existing quantum-resistant digital signature schemes with key update functions. However, using the prior art, since generating threshold signatures through lattice-based cryptographic algorithms requires three or more rounds of online interactions, the overhead for completing threshold signatures is large and the efficiency is low. Moreover, for current quantum computers, existing quantum-resistant digital signature schemes with key update functions are only applicable to a single signer and cannot be applied to multiple signers, that is, they do not have the threshold property and cannot be applied to distributed application scenarios. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide a threshold signature method, apparatus, and electronic device based on lattice-based key randomization.

[0005] In a first aspect, an embodiment of the present invention provides a threshold signature method based on lattice-based key randomization, the method comprising:

[0006] Obtaining keys of multiple active signers according to system parameters;

[0007] Obtaining re-randomized keys corresponding to multiple active signers according to the keys corresponding to the multiple active signers, a random string, and an auxiliary string;

[0008] In an offline phase, obtaining first status information of multiple active signers and preprocessing information, and determining second status information of a leader according to the multiple first status information and the preprocessing information;

[0009] In an online phase, obtaining a threshold signature through a random value aggregation algorithm according to the multiple re-randomized keys, an object to be signed, the multiple first status information, and the second status information.

[0010] In one embodiment, before obtaining the keys of multiple active signers according to the system parameters, the following steps are further included:

[0011] Obtain a random matrix;

[0012] Obtain the system parameters according to the random matrix and the preset security parameters.

[0013] In one embodiment, the keys include: multiple private keys and one public key. Each private key corresponds to each active signer one by one, and the multiple active signers jointly correspond to the public key. Obtaining the keys of multiple active signers according to the system parameters includes:

[0014] Obtain a random secret value;

[0015] Calculate the public key according to the random matrix, the random secret value, and the preset odd prime number;

[0016] Generate the secret sharing shares corresponding to each active signer through a secret sharing algorithm according to the random secret value;

[0017] Obtain the private keys corresponding to each active signer according to the secret sharing shares and the secret sharing share index values corresponding to each active signer.

[0018] In one embodiment, obtaining the re-randomized keys corresponding to multiple active signers according to the keys corresponding to multiple active signers, a random string, and an auxiliary string includes:

[0019] Obtain the random string;

[0020] Calculate the key random value corresponding to the active signer through a secret sharing algorithm according to the random string and the auxiliary string;

[0021] Obtain the re-randomized keys corresponding to multiple active signers according to the key random value and the keys.

[0022] In one embodiment, the key random value includes: a private key random value and a public key random value. The re-randomized keys include: a re-randomized private key and a re-randomized public key. Obtaining the re-randomized keys corresponding to multiple active signers according to the key random value and the keys includes:

[0023] Obtain the re-randomized private keys corresponding to multiple active signers respectively according to the private key random value and the private keys corresponding to multiple active signers respectively;

[0024] Obtain the re-randomized public key corresponding to multiple active signers jointly according to the public key random value and the public key.

[0025] In one embodiment, in the offline phase, the first status information of multiple active signers and preprocessing information are obtained, and the second status information of the leader is determined according to the multiple first status information and the preprocessing information, including:

[0026] Obtain the first initial status information of multiple active signers and the second initial status information of the leader;

[0027] Obtain update information according to the random sampling vector, the random matrix, and a preset odd prime number;

[0028] Use the update information to update the first initial status information to obtain the first status information of multiple active signers;

[0029] Obtain the preprocessing information of multiple active signers according to the update information;

[0030] Determine the second status information of the leader according to the preprocessing information of multiple active signers and the second initial status information.

[0031] In one embodiment, in the online phase, according to the multiple re-randomized keys, the object to be signed, the multiple first status information, and the second status information, a threshold signature is obtained through a random value aggregation algorithm, including:

[0032] For the object to be signed, calculate the aggregated random value and the challenge value of the active signers through a preset hash function according to the re-randomized public key, the second status information, and the multiple first status information;

[0033] Obtain the initial threshold signature corresponding to each active signer through a random value aggregation algorithm according to the aggregated random value and the challenge value;

[0034] Aggregate multiple initial threshold signatures to obtain the threshold signature.

[0035] In one embodiment, the method further includes:

[0036] Verify the threshold signature to determine whether the threshold signature passes the verification.

[0037] In a second aspect, an embodiment of the present invention provides a lattice-based key randomization threshold signature device, including:

[0038] A key acquisition module, configured to obtain keys of multiple active signers according to system parameters;

[0039] A random key acquisition module, configured to obtain re-randomized keys corresponding to multiple active signers according to the keys, random strings, and auxiliary strings corresponding to the multiple active signers;

[0040] An offline phase processing module, configured to obtain first status information of multiple active signers and preprocessing information in the offline phase, and determine second status information of a leader according to the multiple first status information and the preprocessing information;

[0041] An online phase processing module, configured to obtain a threshold signature through a random value aggregation algorithm according to the multiple re-randomized keys, the object to be signed, the multiple first status information, and the second status information in the online phase.

[0042] In a third aspect, an embodiment of the present invention provides an electronic device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the threshold signature method based on lattice-based key randomization described in the first aspect are implemented.

[0043] The technical solution provided by the embodiment of the present invention has the following advantages compared with the prior art:

[0044] A threshold signature method, apparatus, and electronic device based on lattice-based key randomization provided by an embodiment of the present invention obtain keys of multiple active signers according to system parameters, and obtain re-randomized keys corresponding to the multiple active signers according to the keys, random strings, and auxiliary strings corresponding to the multiple active signers. In the offline phase, first status information of multiple active signers and preprocessing information are obtained, and second status information of a leader is determined according to the multiple first status information and the preprocessing information. In the online phase, a threshold signature is obtained through a random value aggregation algorithm according to the multiple re-randomized keys, the object to be signed, the multiple first status information, and the second status information. Since when performing a threshold signature on the object to be signed, key re-randomization is performed on the keys of multiple active signers to implement key update, it can be applied to a distributed application scenario, and at the same time, prevent security risks existing when keys are leaked, improve the flexibility of the threshold signature, and effectively prevent security problems brought by quantum computing attacks. Further, by completing the threshold signature in two rounds in the offline phase and the online phase, it avoids the need for three or more rounds of online interaction in the prior art, thereby improving the efficiency of the threshold signature. Description of the Drawings

[0045] The drawings here are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present invention, and are used together with the specification to explain the principles of the present invention.

[0046] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0047] Figure 1 It is a schematic flow chart of a lattice-based key randomization threshold signature method provided by an embodiment of the present invention;

[0048] Figure 2 It is a schematic structural diagram of a lattice-based key randomization threshold signature device provided by an embodiment of the present invention. Detailed implementation manners

[0049] In order to be able to more clearly understand the above objects, features, and advantages of the present invention, the following will further describe the solution of the present invention. It should be noted that, without conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other.

[0050] In the following description, many specific details are set forth to fully understand the present invention, but the present invention can also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only a part of the embodiments of the present invention, rather than all the embodiments.

[0051] With the continuous evolution of the Internet and digital technologies, threshold signature has become a research direction that has received much attention. Threshold signature is an encrypted digital signature protocol that is widely used in fields such as finance, supply chain management, Internet of Things, government services, and healthcare. Specifically, threshold signature divides the private key into multiple parts and requires at least the number of signers reaching the threshold value to participate in cooperation to generate a valid signature, thereby improving security and reliability through this method.

[0052] In the prior art, threshold signatures are generated through lattice-based cryptographic algorithms. Specifically, threshold signatures are completed through three or more rounds of online interactions, as well as existing quantum-resistant digital signature schemes with key update functions. However, using the prior art, since generating threshold signatures through lattice-based cryptographic algorithms requires three or more rounds of online interactions, it results in high overhead and low efficiency for completing threshold signatures. Moreover, for current quantum computers, the existing quantum-resistant digital signature schemes with key update functions are only applicable to a single signer and cannot be applied to multiple signers, that is, they do not have the threshold property and cannot be applied to distributed application scenarios.

[0053] Therefore, the present invention provides a threshold signature method based on lattice-based key randomization. By obtaining the keys of multiple active signers according to system parameters, and obtaining the re-randomized keys corresponding to the multiple active signers based on the keys corresponding to the multiple active signers, a random string, and an auxiliary string. In the offline phase, obtain the first status information of multiple active signers and preprocessing information, and determine the second status information of the leader according to the multiple first status information and the preprocessing information. In the online phase, according to the multiple re-randomized keys, the object to be signed, the multiple first status information, and the second status information, obtain the threshold signature through a random value aggregation algorithm. In this way, since when performing the threshold signature on the object to be signed, key re-randomization is performed on the keys of multiple active signers to achieve key update, it can be applied to distributed application scenarios, while preventing the security risks existing when the key is leaked, improving the flexibility of the threshold signature, and effectively preventing the security problems brought by quantum computing attacks. Further, by completing the threshold signature in two rounds in the offline phase and the online phase, it avoids the need for three or more rounds of online interaction in the prior art, thereby improving the efficiency of the threshold signature.

[0054] In one embodiment, as Figure 1 shown, Figure 1 is a schematic flow chart of a threshold signature method based on lattice-based key randomization provided by an embodiment of the present invention, which specifically includes the following steps:

[0055] S10: Obtain the keys of multiple active signers according to system parameters.

[0056] Among them, the system parameters are used to obtain the respective keys of multiple active signers. An active signer refers to a signer participating in the threshold signature.

[0057] Optionally, on the basis of the above embodiment, in some embodiments of the present invention, a way to obtain the system parameters can be:

[0058] Obtain a random matrix.

[0059] Among them, the random matrix is obtained by uniform random sampling through a preset random function.

[0060] Obtain system parameters according to the random matrix and a preset security parameter.

[0061] Among them, the preset security parameter refers to a parameter that can be used to quantify the system security and can determine the computing resources required to resist attacks. Thus, the security under quantum computing is determined, and the preset security parameter is set to 1 k , where κ is used to represent the degree of security. For example, κ can be 128, but it is not limited thereto. The present invention does not specifically limit it, and those skilled in the art can set it according to the actual situation.

[0062] Specifically, a random matrix is uniformly and randomly obtained through a preset random function. After obtaining the random matrix, system parameters are obtained according to the random matrix and a preset security parameter.

[0063] Optionally, based on the above embodiments, in some embodiments of the present invention, the key includes: multiple private keys and one public key. Each private key corresponds to each active signer one by one, and multiple active signers jointly correspond to one public key. One implementation manner of S10 may be:

[0064] S101: Obtain a random secret value.

[0065] Among them, the random secret value is used to obtain the public key. The random secret value can be uniformly and randomly sampled from a preset set through a preset hash function. Each active signer corresponds to a random secret value.

[0066] Specifically, for multiple active signers, the corresponding random secret values are obtained.

[0067] S102: Calculate the public key according to the random matrix, the random secret value, and a preset odd prime number.

[0068] Among them, the preset odd prime number is the modulus of the polynomial ring defined in the lattice cryptography algorithm. Using the preset odd prime number can avoid the even value problem in the ring structure, thereby ensuring the reversibility of the operation. It should be noted that the size of the preset odd prime number directly affects the difficulty of the lattice cryptography algorithm, and thus determines the security of generating the threshold signature.

[0069] Specifically, when obtaining the random secret value, according to the random matrix, the random secret value, and the preset odd prime number set in advance, the same public key jointly corresponding to multiple active signers is obtained.

[0070] Optionally, based on the above embodiments, in some embodiments of the present invention, according to the random matrix, the random secret value, and the preset odd prime number, the public key can be calculated through a preset expression. The preset expression is defined as: t = A sk mod q, where A represents the random matrix, sk represents the random secret value, and q represents the preset odd prime number.

[0071] S103: Generate the secret sharing shares corresponding to each active signer through a secret sharing algorithm according to the random secret value.

[0072] Specifically, the random secret value is input into the secret sharing algorithm, and through the secret sharing algorithm, the secret sharing shares corresponding to each active signer are generated.

[0073] S104: Obtain the private key corresponding to each active signer according to the secret sharing share and the secret sharing share index value corresponding to each active signer.

[0074] Among them, for each active signer, there is a set of index values of secret sharing shares, and the index values of the secret sharing shares are used to obtain the data corresponding to the index value in the secret sharing shares, that is, the private keys corresponding to each of the active signers.

[0075] Specifically, for the secret sharing shares corresponding to each active signer, through the index values of the secret sharing shares corresponding to each active signer, the private keys corresponding to each active signer are obtained from the secret sharing shares.

[0076] S11: Obtain the re-randomized keys corresponding to multiple active signers according to the keys, random strings, and auxiliary strings corresponding to multiple signers.

[0077] Among them, the random string is obtained through the GenRand algorithm, and the random string is a binary string of 0 and 1.

[0078] The auxiliary string refers to the relevant information existing in the process of generating the threshold signature. This relevant information can be, for example, the privacy information of the object to be signed on behalf of. The auxiliary string is a binary string of 0 and 1.

[0079] Specifically, obtain the re-randomized keys corresponding to multiple active signers according to the keys, random strings, and auxiliary strings corresponding to multiple signers.

[0080] Optionally, on the basis of the above embodiments, in some embodiments of the present invention, one implementation manner of S11 may be:

[0081] S111: Obtain the random string.

[0082] S112: According to the random string and the auxiliary string, calculate the key random value corresponding to the active signer through the secret sharing algorithm.

[0083] Specifically, obtain the random string, input the random string and the auxiliary string into a preset hash function to obtain the initial hash parameter value, and calculate the key random value corresponding to each active signer according to the initial hash parameter value using the secret sharing algorithm.

[0084] S113: Obtain the re-randomized keys corresponding to multiple active signers according to the key random value and the key.

[0085] Specifically, after obtaining the key random value corresponding to each active signer, determine the re-randomized key corresponding to each active signer according to the key random value and the key corresponding to each active signer.

[0086] Optionally, based on the above embodiments, in some embodiments of the present invention, the key random value includes: a private key random value and a public key random value, and the re-randomized key includes: a re-randomized private key and a re-randomized public key. It should be noted that each active signer corresponds to a re-randomized private key, and multiple active signers jointly correspond to the same re-randomized public key. Based on this, one implementation manner of S113 may be:

[0087] S1131: Obtain the re-randomized private keys corresponding to multiple active signers according to the private key random value and the private keys respectively corresponding to multiple active signers.

[0088] Specifically, after obtaining the private key random value corresponding to each active signer, determine the re-randomized private key corresponding to each active signer according to the private key random value and the private key corresponding to each active signer.

[0089] S1132: Obtain the re-randomized public key jointly corresponding to multiple active signers according to the public key random value and the public key.

[0090] Specifically, after obtaining the public key random value corresponding to each active signer, determine the re-randomized public key jointly corresponding to multiple active signers according to the public key random value and the public key corresponding to each active signer.

[0091] Optionally, obtaining the re-randomized public key may specifically be to first calculate a parameter value through the public key random value, a random matrix, and a preset odd prime number. Further, determine the re-randomized public key according to the parameter value and the public key.

[0092] In this way, the lattice-based key randomization threshold signature method provided in this embodiment can improve the anti-attack ability in the process of generating the threshold signature by randomly obtaining the re-randomized private key and the re-randomized public key. The re-randomized private keys and the re-randomized public keys of each active signer are updated through key re-randomization, which improves the anti-attack ability against the outside world and avoids the problem of low security caused by key leakage.

[0093] S12: In the offline phase, obtain the first state information of multiple active signers and the preprocessing information, and determine the second state information of the leader according to the multiple first state information and the preprocessing information.

[0094] Wherein, the leader is any one of the multiple active signers, that is, it can be understood that one active signer is randomly determined from the multiple active signers as the leader.

[0095] The above first state information includes information such as the identification information and public key of each active signer.

[0096] The above preprocessing information is calculated based on a random matrix, a random sampling vector, and a preset odd prime number. Exemplarily, the preprocessing information can be determined according to the expression R = A * r mod q, where r represents the random vector, A represents the random matrix, and q represents the preset odd prime number.

[0097] Specifically, in the offline phase, for multiple active signers, obtain the first status information of each active signer and the preprocessing information, and determine the second status information of the leader according to the first status information of the multiple active signers and the preprocessing information.

[0098] Optionally, based on the above embodiments, in some embodiments of the present invention, one implementation manner of S12 may be:

[0099] S121: Obtain the first initial status information of multiple active signers and the second initial status information of the leader.

[0100] Among them, the first initial status information refers to the original status information of multiple active signers, including: the identification information of the active signer and the information of the private key. The second initial status information refers to the original status information of the leader, including: the identification information of the leader and the information of the private key.

[0101] Specifically, obtain the first initial status information corresponding to each active signer, that is, the identification information of the active signer and the information of the private key, and the second initial status information corresponding to the leader, that is, the identification information of the leader and the information of the private key.

[0102] S122: Obtain update information according to the random sampling vector, the random matrix, and the preset odd prime number.

[0103] Among them, the random sampling vector is a vector obtained by uniformly random sampling according to a preset function.

[0104] S123: Use the update information to update the first initial status information to obtain the first status information of multiple active signers.

[0105] Specifically, calculate the update information of the active signer according to the random sampling vector, the random matrix, and the preset odd prime number. After obtaining the update information of the active signer, update the first initial status information corresponding to each active signer to obtain the first status information of each active signer.

[0106] S124: Obtain the preprocessing information of multiple active signers according to the update information.

[0107] Specifically, after obtaining the update information of the active signer, obtain the preprocessing information of multiple active signers according to the update information.

[0108] S125: Determine the second state information of the leader according to the preprocessing information of multiple active signers and the second initial state information.

[0109] Specifically, after obtaining the preprocessing information of each active signer, determine the second state information of the leader according to the preprocessing information of each active signer and the second initial state information corresponding to the leader.

[0110] Optionally, based on the above embodiments, in some embodiments of the present invention, one implementation manner of determining the second state information of the leader according to the preprocessing information of multiple active signers and the second initial state information may be to add the preprocessing information according to multiple active signers to the second initial state information corresponding to the leader to determine the second state information of the leader.

[0111] In this way, the threshold signature method based on lattice-based key randomization provided in this embodiment obtains the first state information and preprocessing information of multiple active signers in the offline stage, and determines the second state information of the leader according to the multiple first state information and preprocessing information, so as to facilitate the subsequent online stage to complete the threshold signature of the object to be signed, improving the efficiency of the threshold signature.

[0112] S13: In the online stage, obtain the threshold signature through the random value aggregation algorithm according to multiple re-randomized keys, the object to be signed, multiple first state information, and the second state information.

[0113] The object to be signed refers to the object that needs to be threshold-signed currently. For example, it can be a transmitted message, a file, etc., but is not limited thereto. The present invention does not specifically limit it, and those skilled in the art can set it according to the actual situation.

[0114] Specifically, in the online stage, when receiving the object to be signed, for the object to be signed, calculate the aggregated threshold signature through the random value aggregation algorithm according to the re-randomized keys of multiple active signers, multiple first state information, and the second state information of the leader.

[0115] Optionally, based on the above embodiments, in some embodiments of the present invention, one implementation manner of S13 may be:

[0116] S131: For the object to be signed, calculate the aggregated random value and challenge value of the active signers through a preset hash function according to the re-randomized public key, the second state information, and multiple first state information.

[0117] The preset hash function includes a first preset hash function for generating the aggregated random value and a second preset hash function for generating the challenge value.

[0118] Specifically, for the object to be signed, according to the re-randomized public key corresponding to the active signer, the second state information of the leader, and the first state information corresponding to the active signer, the aggregated random value of the active signer is calculated through a first preset hash function. Further, according to the aggregated random value and the re-randomized public key corresponding to the active signer, the challenge value of the active signer is calculated through a second preset hash function.

[0119] Optionally, based on the above embodiments, in some embodiments of the present invention, an implementation manner of calculating the aggregated random value of the active signer according to the re-randomized public key corresponding to the active signer, the second state information of the leader, and the first state information corresponding to the active signer through a first preset hash function may be: According to the re-randomized public key corresponding to the active signer, the second state information of the leader, and the first state information corresponding to the active signer, the random number of the active signer is calculated through a first preset hash function, and the aggregated random value is determined according to multiple random numbers.

[0120] S132: According to the aggregated random value and the challenge value, through a random value aggregation algorithm, the initial threshold signatures respectively corresponding to each active signer are obtained.

[0121] Specifically, after obtaining the aggregated random value and the challenge value, the initial threshold signatures respectively corresponding to each active signer are calculated through a random value aggregation algorithm.

[0122] Optionally, it can be determined according to the expression where

[0123] z represents the threshold signature corresponding to each active signer, r0, r j represents the random sampling vector, b j represents the random number obtained through a preset hash function, c represents the challenge value, represents the recombination coefficient of the secret sharing algorithm, is the re-randomized key.

[0124] S133: Aggregate multiple initial threshold signatures to obtain a threshold signature.

[0125] Specifically, after obtaining the initial threshold signatures respectively corresponding to multiple active signers, aggregate multiple initial threshold signatures to obtain an aggregated threshold signature.

[0126] In this way, the lattice-based key randomization threshold signature method provided in this embodiment obtains the keys of multiple active signers according to system parameters, and obtains the re-randomized keys corresponding to the multiple active signers according to the keys, random strings, and auxiliary strings corresponding to the multiple active signers. In the offline stage, the first state information of multiple active signers and preprocessing information are obtained, and the second state information of the leader is determined according to the multiple first state information and the preprocessing information. In the online stage, according to the multiple re-randomized keys, the object to be signed, the multiple first state information, and the second state information, a threshold signature is obtained through a random value aggregation algorithm. In this way, since the key is updated by re-randomizing the keys of multiple active signers when performing the threshold signature on the object to be signed, it can be applied to distributed application scenarios, while preventing the security risks existing in key leakage, improving the flexibility of the threshold signature, and effectively preventing the security problems brought by quantum computing attacks. Further, by completing the threshold signature in two rounds in the offline stage and the online stage, it is avoided that three or more rounds of online interactions are required in the prior art, thereby improving the efficiency of the threshold signature.

[0127] Optionally, on the basis of the above embodiment, in some embodiments of the present invention, after executing S13, it further includes:

[0128] S14: Verify the threshold signature to determine whether the threshold signature passes the verification.

[0129] Specifically, after obtaining the threshold signature, verify the threshold signature to determine whether the threshold signature passes the verification.

[0130] Optionally, on the basis of the above embodiment, in some embodiments of the present invention, an implementation manner of S14 may be:

[0131] For the object to be signed, verify the threshold signature according to the re-randomized public key. When the verification passes, verify the threshold signature according to the re-randomized public key, the aggregated random value, the preset odd prime number, the challenge value, and the random matrix to determine whether the threshold signature passes the verification.

[0132] Optionally, on the basis of the above embodiment, in some embodiments of the present invention, when verifying the threshold signature according to the re-randomized public key and the preset signature, and when the verification passes, an implementation manner of verifying the threshold signature according to the re-randomized public key, the aggregated random value, the preset odd prime number, the challenge value, and the random matrix to determine whether the threshold signature passes the verification may be that when the expression Az = R + 2c· is satisfied, it is determined that the threshold signature passes the verification, where A represents the random matrix, q represents the preset odd prime number, c represents the challenge value, Let \(p\) represent the re-randomized public key, \(z\) represent the aggregated threshold signature, and \(R\) represent the aggregated random value.

[0133] It should be understood that although Figure 1 the steps in the flowchart of Figure 1 are shown in sequence according to the indication of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover,

[0134] In one embodiment, as Figure 2 shown, a threshold signature device based on lattice-based key randomization is provided, including: a key acquisition module 10, a random key acquisition module 11, an offline stage processing module 12, and an online stage processing module 13.

[0135] Among them, the key acquisition module 10 is used to acquire the keys of multiple active signers according to the system parameters;

[0136] The random key acquisition module 11 is used to acquire the re-randomized keys corresponding to multiple active signers according to the keys, random strings, and auxiliary strings corresponding to the multiple active signers;

[0137] The offline stage processing module 12 is used to acquire the first status information of multiple active signers and preprocessing information in the offline stage, and determine the second status information of the leader according to the multiple first status information and preprocessing information;

[0138] The online stage processing module 13 is used to obtain a threshold signature through a random value aggregation algorithm according to the multiple re-randomized keys, the object to be signed, the multiple first status information, and the second status information in the online stage.

[0139] In the above embodiments, the key acquisition module acquires the keys of multiple active signers according to system parameters; the random key acquisition module acquires the re-randomized keys corresponding to the multiple active signers according to the keys, random strings, and auxiliary strings corresponding to the multiple active signers; the offline phase processing module acquires the first status information of the multiple active signers and preprocessing information during the offline phase, and determines the second status information of the leader according to the multiple first status information and the preprocessing information; the online phase processing module acquires a threshold signature through a random value aggregation algorithm according to the multiple re-randomized keys, the object to be signed, the multiple first status information, and the second status information during the online phase. Since the key is re-randomized for the keys of multiple active signers when the threshold signature for the object to be signed is completed, it can be applied to distributed application scenarios, while preventing the security risks existing in key leakage, improving the flexibility of the threshold signature, and effectively preventing the security problems brought by quantum computing attacks. Further, by completing the threshold signature in two rounds during the offline phase and the online phase, it avoids the need for three or more rounds of online interaction in the prior art, thereby improving the efficiency of the threshold signature.

[0140] For the specific limitations of the threshold signature device based on lattice-based key randomization, reference can be made to the limitations of the threshold signature method based on lattice-based key randomization in the above text, which will not be elaborated here. Each module in the above server can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0141] An embodiment of the present invention provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it can implement the threshold signature method based on lattice-based key randomization provided by the embodiment of the present invention. For example, when the processor executes the computer program, it can implement Figure 1 The technical solutions of any of the method embodiments shown, and their implementation principles and technical effects are similar, which will not be elaborated here.

[0142] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided by the present invention can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static random access memory (SRAM) and dynamic random access memory (DRAM), etc.

[0143] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0144] The above-described embodiments merely represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the invention patent should be subject to the appended claims.

Claims

1. A threshold signature method based on lattice key randomization, characterized in that: include: According to the system parameters, obtain the keys of multiple active signers; Obtain the re-random keys corresponding to the multiple active signers according to the keys, random strings and auxiliary strings corresponding to the multiple active signers; In the offline stage, first state information and pre-processing information of multiple active signers are obtained, and second state information of the leader is determined according to the first state information and pre-processing information; In the online stage, a threshold signature is obtained through a random value aggregation algorithm according to the multiple re-random keys, the object to be signed, the multiple first state information and the second state information.

2. The method according to claim 1, characterized in that Before obtaining the keys of multiple active signers according to the system parameters, the method further includes: Get a random matrix; The system parameters are obtained according to the random matrix and preset security parameters.

3. The method according to claim 2, characterized in that The key includes: multiple private keys and a public key, each of the private keys corresponds to each of the active signers one by one, and multiple active signers correspond to the public key together. The obtaining of the keys of the multiple active signers according to the system parameters includes: Get a random secret value; Calculate the public key according to the random matrix, the random secret value and a preset odd prime number; Generate a secret sharing share corresponding to each of the active signers according to the random secret value through a secret sharing algorithm; According to the secret sharing share and the secret sharing share index value corresponding to each of the active signers, a private key corresponding to each of the active signers is obtained.

4. The method according to claim 1, characterized in that: The obtaining, according to the keys, random strings, and auxiliary strings corresponding to the multiple active signers, re-random keys corresponding to the multiple active signers includes: Obtain the random character string; Calculate the random key value corresponding to the active signer through a secret sharing algorithm according to the random string and the auxiliary string; According to the key random value and the key, re-random keys corresponding to multiple active signers are obtained.

5. The method according to claim 4, characterized in that The key random value includes: a private key random value and a public key random value, the re-random key includes: a re-random private key and a re-random public key, and obtaining the re-random keys corresponding to multiple active signers according to the key random value and the key includes: Obtaining re-random private keys corresponding to the multiple active signers respectively according to the private key random value and the private keys corresponding to the multiple active signers respectively; According to the public key random value and the public key, a re-random public key corresponding to multiple active signers is obtained.

6. The method according to claim 2, characterized in that In the offline stage, obtaining first state information and preprocessing information of multiple active signers, and determining second state information of the leader according to the multiple first state information and preprocessing information, includes: Obtaining first initial state information of multiple active signers and second initial state information of the leader; Acquire update information according to the random sampling vector, the random matrix and the preset odd prime number; Using the update information, updating the first initial state information to obtain first state information of multiple active signers; Obtaining the pre-processed information of multiple active signers according to the updated information; The second state information of the leader is determined according to the pre-processed information of multiple active signers and the second initial state information.

7. The method according to claim 5, characterized in that In the online stage, obtaining a threshold signature through a random value aggregation algorithm according to the multiple re-random keys, the object to be signed, the multiple first state information and the second state information includes: For the object to be signed, according to the re-random public key, the second state information and a plurality of the first state information, by using a preset hash function, calculate the aggregate random value and the challenge value of the active signer; According to the aggregated random value and the challenge value, an initial threshold signature corresponding to each of the active signers is obtained through a random value aggregation algorithm; Aggregation processing is performed on multiple initial threshold signatures to obtain the threshold signature.

8. The method according to claim 1, characterized in that The method further comprises: The threshold signature is verified to determine whether the threshold signature passes the verification.

9. A threshold signature device based on lattice key randomization, characterized in that: include: A key acquisition module, used to obtain keys of multiple active signers according to system parameters; A random key acquisition module, used to acquire re-random keys corresponding to multiple active signers according to keys, random strings and auxiliary strings corresponding to multiple active signers; An offline phase processing module, used for obtaining first state information and pre-processing information of multiple active signers in the offline phase, and determining second state information of the leader according to the first state information and pre-processing information; The online stage processing module is used to obtain a threshold signature through a random value aggregation algorithm in the online stage according to multiple re-random keys, objects to be signed, multiple first state information and the second state information.

10. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the threshold signature method based on lattice key randomization described in any one of claims 1 to 8 are implemented.