Digital signature method and device, equipment and storage medium
By adopting a threshold digital signature algorithm based on elliptic curve in blockchain wallets, distributed storage of signature public-private key pairs is realized, solving the problems of large calculation overhead and complex key management in blockchain wallets during the signature stage, and improving security and storage efficiency.
Patent Information
- Application Number
- CN202510299704.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-17
AI Technical Summary
The blockchain wallet has a large calculation overhead during the signature stage and requires storing and maintaining a large number of keys, resulting in excessive overhead and a single point of failure.
Using a threshold digital signature algorithm based on elliptic curves, a random polynomial coefficient and seed share are randomly generated by randomly generating polynomial coefficients and seed shares, a random polynomial is constructed and split into multiple shares, realizing distributed storage of signed public-private key pairs, reducing the complexity and computational overhead of key management.
It effectively reduces the computing overhead in the signature stage, improves the security of keys, avoids single point of failure, and realizes more efficient key storage and management.
Smart Images

Figure CN120165875A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and particularly relates to a digital signature method, apparatus, device, and storage medium. Background Art
[0002] With the rise of digital currency and the continuous development of blockchain technology, blockchain wallets have gradually become an important tool for managing digital assets. The development of blockchain wallets can further promote the digital transformation and upgrading of related industries such as medical health and copyright protection. In the blockchain field, the storage and maintenance of encryption keys are usually handled by blockchain wallets. Blockchain wallets are divided into custodial wallets and non-custodial wallets according to whether their keys need to be entrusted.
[0003] However, due to the centralized storage of keys, current custodial wallets and non-custodial wallets both have the potential risk of single-point failure. Once attacked by an attacker, it will cause serious losses. At the same time, in order to avoid the linking of user transaction records, if a new key pair is simply generated for each transaction, then users need to store and maintain a large number of keys, thus greatly increasing unnecessary overhead.
[0004] In summary, aiming at the potential single-point failure risks existing in custodial wallets and non-custodial wallets, how to solve the problems of large computational overhead in the signature stage of current blockchain wallets and excessive overhead caused by the need to store and maintain a large number of keys is still an issue to be further solved at present. Summary of the Invention
[0005] In view of this, the purpose of the present application is to provide a digital signature method, apparatus, device, and storage medium, which can efficiently store keys while solving the problem of transaction linkability, and at the same time realizes the distributed storage of signature public and private key pairs, solves the potential single-point failure risks, and thus improves the security of blockchain wallets. The specific solutions are as follows:
[0006] In the first aspect, the present application discloses a digital signature method, which is applied to any participating party terminal using a blockchain wallet, and includes:
[0007] Randomly generate polynomial coefficients and seed shares for a pseudorandom number generator by using a threshold digital signature algorithm based on an elliptic curve, and construct a random polynomial by using the polynomial coefficients and a preset threshold size;
[0008] Split the random polynomial to obtain multiple polynomial shares, and generate a polynomial coefficient commitment for the current participating party based on the polynomial coefficients;
[0009] Distribute each of the polynomial shares and the seed shares to other participating parties, and broadcast the polynomial coefficient commitment;
[0010] Generate an initial private key share and an initial public key share based on the preset Lagrange coefficients and the polynomial shares of all parties, and generate a shared seed with each of the other parties respectively based on the current party and the seed shares of each of the other parties;
[0011] Use the shared seed to call the pseudo-random number generator to generate relevant random numbers, and use the relevant random numbers and the preset key derivation random numbers to derive the initial private key share and the initial public key share to obtain a new private key share and a new public key share;
[0012] Generate a random number share, and use the relevant random numbers to blind the new private key share and the random number share to obtain blinded shares, and then use the blinded shares of all parties to digitally sign the information to be signed to obtain a signature result.
[0013] Optionally, the randomly generating polynomial coefficients and seed shares for the pseudo-random number generator by using a threshold digital signature algorithm based on an elliptic curve includes:
[0014] Generate system public parameters through a public key infrastructure and using preset security parameters; the system public parameters include a prime order elliptic curve group, a generator, and a prime number;
[0015] Randomly select a first preset number of polynomial coefficients on the prime order elliptic curve group by using a threshold digital signature algorithm based on an elliptic curve, and randomly generate seed shares for the pseudo-random number generator; the number of bits of the seed shares is the same as the preset security parameters;
[0016] Correspondingly, the generating a polynomial coefficient commitment of the current party based on the polynomial coefficients includes:
[0017] Take the polynomial coefficients as the exponents of the generator to obtain the polynomial coefficient commitment of the current party.
[0018] Optionally, the generating an initial private key share and an initial public key share based on the preset Lagrange coefficients and the polynomial shares of all parties includes:
[0019] When receiving the polynomial coefficient commitments, seed shares, and polynomial shares sent by the other parties, perform additive aggregation on the polynomial shares of all parties to obtain the Shamir secret sharing share of the private key of the current party;
[0020] Use the preset Lagrange coefficients to convert the Shamir secret sharing share into an additive secret sharing share of the private key of the current party to obtain the private key share of the current party;
[0021] Multiply and aggregate the commitments of the polynomial constant terms in the polynomial coefficient commitments of all participating parties to obtain the current public key of all participating parties, and use the preset Lagrange coefficients to convert the commitment of the polynomial constant term of the current participating party into a public key share.
[0022] Optionally, generating a shared seed with each of the other participating parties based on the seed shares of the current participating party and each of the other participating parties includes:
[0023] Calculate the sum of the seed shares of each of the other participating parties received and the seed share of the current participating party to obtain the shared seed between the current participating party and the corresponding other participating party;
[0024] Correspondingly, the digital signature method further includes:
[0025] Use the key-derived random number as the exponent of the generator to obtain the target data, and calculate the product of the target data and the current public key to derive a new public key.
[0026] Optionally, generating random number shares and blinding the new private key share and the random number shares with the relevant random number to obtain blinded shares includes:
[0027] Randomly select a second preset number of random number shares from the prime-order elliptic curve group by random uniform sampling;
[0028] Calculate the sum of the relevant random number and the new private key share and the random number shares respectively to obtain the blinded shares.
[0029] Optionally, using the blinded shares of all participating parties to digitally sign the information to be signed to obtain a signature result includes:
[0030] When receiving the blinded shares sent by the other participating parties, generate the additive shares of the current participating party using the blinded shares of each of the other participating parties and the current participating party, and send the additive shares to the corresponding other participating parties;
[0031] When receiving the additive shares sent by the corresponding other participating parties, perform a hash operation on the information to be signed to obtain a hash value, and generate signature materials using the additive shares of each of the other participating parties and the current participating party and the hash value, and send the signature materials to all the other participating parties;
[0032] When receiving the signature materials sent by the other participating parties, generate a signature result for the information to be signed based on the signature materials of all participating parties.
[0033] Optionally, the step of invoking the pseudo-random number generator using the shared seed to generate a relevant random number includes:
[0034] Invoking the pseudo-random number generator using the shared seed, and accumulating the output of the pseudo-random number generator according to a preset rule to obtain a relevant random number;
[0035] Wherein, the preset rule is to determine whether the index of the current participant is greater than the index of the other participants. If the index of the current participant is greater than the index of the other participants, the output of the pseudo-random number generator is accumulated; if the index of the current participant is less than the index of the other participants, the output of the pseudo-random number generator is subtracted.
[0036] In a second aspect, the present application discloses a digital signature device, which is applied to any participant terminal using a blockchain wallet, and includes:
[0037] A first generation module, configured to randomly generate polynomial coefficients and seed shares for a pseudo-random number generator using a threshold digital signature algorithm based on an elliptic curve;
[0038] A construction module, configured to construct a random polynomial using the polynomial coefficients and a preset threshold size;
[0039] A splitting module, configured to split the random polynomial to obtain a plurality of polynomial shares;
[0040] A second generation module, configured to generate a polynomial coefficient commitment of the current participant based on the polynomial coefficients;
[0041] An information sending module, configured to distribute each of the polynomial shares and the seed shares to other participants, and broadcast the polynomial coefficient commitment;
[0042] A third generation module, configured to generate an initial private key share and an initial public key share based on preset Lagrange coefficients and the polynomial shares of all participants, and generate a shared seed between the current participant and each of the other participants based on the seed shares of the current participant and each of the other participants;
[0043] An invocation module, configured to invoke the pseudo-random number generator using the shared seed to generate a relevant random number;
[0044] A derivation module, configured to derive the initial private key share and the initial public key share using the relevant random number and a preset key derivation random number to obtain a new private key share and a new public key share;
[0045] The digital signature module is used to generate random number shares, and blind the new private key shares and the random number shares by using the relevant random numbers to obtain the blinded shares, and then use the blinded shares of all participants to perform digital signature on the information to be signed to obtain a signature result.
[0046] In a third aspect, the present application discloses an electronic device, including a processor and a memory; wherein, when the processor executes the computer program stored in the memory, the foregoing digital signature method is implemented.
[0047] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the foregoing digital signature method is implemented.
[0048] It can be seen that this application is applied to any participating party terminal using a blockchain wallet, including: randomly generating polynomial coefficients and seed shares for a pseudorandom number generator by using a threshold digital signature algorithm based on an elliptic curve, and constructing a random polynomial by using the polynomial coefficients and a preset threshold size; splitting the random polynomial to obtain multiple polynomial shares, and generating a polynomial coefficient commitment for the current participating party based on the polynomial coefficients; distributing each of the polynomial shares and the seed shares to other participating parties, and broadcasting the polynomial coefficient commitment; generating an initial private key share and an initial public key share based on preset Lagrange coefficients and the polynomial shares of all participating parties, and generating a shared seed between the current participating party and each of the other participating parties respectively based on the seed shares of the current participating party and each of the other participating parties; using the shared seed to call the pseudorandom number generator to generate relevant random numbers, and using the relevant random numbers and a preset key-derived random number to derive the initial private key share and the initial public key share to obtain a new private key share and a new public key share; generating random number shares, and blinding the new private key share and the random number shares by using the relevant random numbers to obtain blinded shares, and then using the blinded shares of all participating parties to digitally sign the information to be signed to obtain a signature result. This application randomly generates polynomial coefficients and seed shares by using a threshold digital signature algorithm based on an elliptic curve, and generates an initial private key share and an initial public key share by using the polynomial coefficients, and then generates a shared seed between the current participating party and other participating parties based on the seed shares of the current participating party and other participating parties. Through this shared seed, the pseudorandom number generator can be called to generate relevant random numbers, and then the relevant random numbers are used to derive the initial private key share and the initial public key share to generate a new private key share and a new public key share. Finally, the new private key share is blinded to realize the digital signature of the information to be signed. On the one hand, through the pseudorandom number generator, a non-interactive key derivation phase can be realized, and at the same time, the computational overhead in the signature phase is greatly reduced; on the other hand, the distributed feature of the threshold digital signature algorithm based on an elliptic curve is used to solve the single point of failure problem that may exist in a non-custodial wallet. As long as the number of participating parties damaged by the adversary does not reach the threshold value, the secret information will not be leaked, and a deterministic wallet is realized, thus solving the problem of linkable transactions in a more efficient storage manner. Description of the Drawings
[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0050] Figure 1 Flowchart of a digital signature method disclosed in this application;
[0051] Figure 2 Schematic structural diagram of a digital signature device disclosed in this application;
[0052] Figure 3 Structural diagram of an electronic device disclosed in this application. Specific embodiments
[0053] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0054] The embodiments of this application disclose a digital signature method, which is applied to any participating party terminal using a blockchain wallet. Refer to Figure 1 As shown, the method includes:
[0055] Step S11: Randomly generate polynomial coefficients and seed shares for the pseudo-random number generator using a threshold digital signature algorithm based on an elliptic curve, and construct a random polynomial using the polynomial coefficients and a preset threshold size.
[0056] It should be noted that the digital signature scheme proposed in this application is applied to any participating party terminal using a blockchain wallet, which refers to the terminal or server owned by the wallet owner. Among them, the blockchain wallet can allow users to manage digital assets between different blockchains and freely transfer digital assets by accessing the supported blockchain network.
[0057] In a specific embodiment, the blockchain wallet can specifically be a non-custodial wallet with a deterministic wallet function. A non-custodial wallet means that it is completely operated by the user himself, that is, the user is responsible for the secure generation and storage of his keys. This type of wallet avoids the trust and privacy issues of custodial wallets and allows the user to fully control his keys. Among them, the deterministic wallet function can solve the problem of linkable transactions in a more efficient storage manner. The deterministic wallet consists of an initialization stage, a key derivation stage, and a signature stage. It is initialized with a signature public-private key pair and a random string seed, and uses two deterministic key derivation algorithms, namely the public key derivation algorithm and the private key derivation algorithm, to complete the key derivation stage. These algorithms allow the derivation of the so-called session key pair specified by the user from the signature public-private key pair and the random string seed. The session key pair derived in this way is unlinkable.
[0058] Specifically, non-custodial wallets mainly include hardware wallets, whose private keys are stored on special hardware devices that remain offline most of the time, and software wallets, which mainly run on users' mobile devices or computers. To operate these wallets securely, users need to ensure that the corresponding devices on which the wallets run are well protected from attacks.
[0059] In this embodiment, when data signing is required for the information to be signed, the polynomial coefficients and the seed shares for the pseudorandom number generator (PRNG) can be randomly generated first using the threshold digital signature algorithm based on elliptic curves (i.e., the threshold ECDSA algorithm, Elliptic Curve Digital Signature Algorithm), and then a random polynomial can be constructed using the generated polynomial coefficients and the preset threshold size.
[0060] Among them, the threshold ECDSA algorithm is a signature algorithm based on elliptic curve cryptography, which provides strong authentication and integrity protection for data. This algorithm is based on secure multi-party computation. It divides a private key into multiple shares and distributes them to different n participants. When a signature needs to be generated, any group of participants with a number greater than or equal to the preset threshold value t can jointly calculate a valid ECDSA signature using their respective private key shares without exposing the specific content of the private key shares. This distributed private key management method ensures that no single participant can hold or control the complete private key alone, thus significantly enhancing the security of the private key and preventing the potential risks of private key theft or loss. This application uses the threshold ECDSA signature algorithm for digital signature of blockchain wallets, and can improve the security of the wallet through its distributed characteristics.
[0061] Specifically, the step of randomly generating polynomial coefficients and the seed shares for the pseudorandom number generator using the threshold digital signature algorithm based on elliptic curves may include: generating system public parameters through the public key infrastructure and using preset security parameters; the system public parameters include a prime-order elliptic curve group, a generator, and a prime number; randomly selecting a first preset number of polynomial coefficients on the prime-order elliptic curve group using the threshold digital signature algorithm based on elliptic curves, and randomly generating the seed shares for the pseudorandom number generator; the number of bits of the seed shares is the same as the preset security parameters. For example, any participant (i.e., the current participant P i} i∈{1,...,n} in all participants {P i ) generates system public parameters pp = (G, q, g) through the public key infrastructure (PKI, Public Key Infrastructure) and using the security parameter λ, where G is a prime-order elliptic curve group (i.e., Denote the integer cyclic group of prime order \(q\). By default, all operations are carried out on ), \(g\) is the generator, and \(q\) is a prime number; then, the current participant \(P\) i randomly selects \(t\) polynomial coefficients \(\{a\) \} ik on k∈[0..t-1] ; in addition, the current participant \(P\) i can also randomly generate a seed share of \(\lambda\) bits
[0062] Furthermore, the polynomial coefficients \(\{a\) ik \} k∈[0..t-1] can be used to generate a random polynomial \(f\) of degree \(t - 1\) i \((j)\), where \(t\) is the threshold size.
[0063] In a specific implementation, the threshold size \(t\) can be equal to the number of participants \(n\):
[0064] \(f\) i \((x)=a\) i0 +a\) i1 x+\cdots+a\) it-1 x\) t-1
[0065] Step S12: Split the random polynomial to obtain multiple polynomial shares, and generate a polynomial coefficient commitment of the current participant based on the polynomial coefficients.
[0066] In this embodiment, the random polynomial can be split to obtain multiple polynomial shares \(f\) i \((j)\), and then the above polynomial coefficients \(\{a\) ik \} k∈[0..t-1] are used as the exponents of the generator \(g\) to obtain the polynomial coefficient commitment of the current participant \(P\) i .
[0067] For example, for all \(j = 1,\cdots,n\), the current participant \(P\) i calculates and generates the polynomial share \(f\) i \((j)\), and at the same time makes a power commitment of the coefficients of the polynomial \(\{a\) ik \} k∈[0..t-1] on the group: for all \(k = 0,\cdots,t - 1\), use the polynomial coefficients as exponents to generate the polynomial coefficient commitment where the constant term of the random polynomial is \(a\) i0 , and it can be represented by to represent \(X\) i0 .
[0068] Step S13: Distribute each of the polynomial shares and the seed share to other participants, and broadcast the polynomial coefficient commitment.
[0069] In this embodiment, the current participating party P i After generating the seed share and the polynomial share f i (j), the seed share and the polynomial share f i (j) can be distributed to other participating parties P j , and the polynomial coefficient commitment X ik is broadcasted.
[0070] Step S14: Based on the preset Lagrange coefficients and the polynomial shares of all participating parties, generate the initial private key share and the initial public key share, and generate the shared seeds with the corresponding other participating parties respectively based on the seed shares of the current participating party and each of the other participating parties.
[0071] In this embodiment, based on the preset Lagrange coefficients and the polynomial shares of all participating parties {P i}, i∈{1,...,n} the private key share and the public key share can be generated to obtain the initial private key share and the initial public key share, and then the shared seeds with the corresponding other participating parties P i are generated respectively based on the seed shares of the current participating party P j and each of the other participating parties P j .
[0072] Specifically, the generating of the initial private key share and the initial public key share based on the preset Lagrange coefficients and the polynomial shares of all participating parties may include: when receiving the polynomial coefficient commitment, the seed share and the polynomial share sent by the other participating parties, performing additive aggregation on the polynomial shares of all participating parties to obtain the Shamir secret sharing share of the private key of the current participating party; using the preset Lagrange coefficients to convert the Shamir secret sharing share into the additive secret sharing share of the private key of the current participating party to obtain the private key share of the current participating party; performing multiplicative aggregation on the polynomial constant term commitments in the polynomial coefficient commitments of all participating parties to obtain the current public key of all participating parties, and using the preset Lagrange coefficients to convert the polynomial constant term commitment of the current participating party into the public key share. For example, when receiving the polynomial coefficient commitment X j sent by the other participating party P ji , the seed share and the polynomial share f j (i), for all j = 1,..., n, the current participating party P i can use its own polynomial share f i (i) and the received polynomial share f j(i) Perform additive aggregation to obtain the (t, n) Shamir secret sharing shares of its own private key x where n represents the number of all participating parties; then, using the set Lagrange coefficient λ i , locally convert to the additive secret sharing share x of the key x i , thereby defining its own private key share and satisfying
[0073] Next, the current public key y of all participating parties can be obtained through the broadcast commitment of the constant term of the polynomial for multiplicative aggregation, where Then the current participating party P i uses the set Lagrange coefficient λ i to locally convert the commitment of the constant term of the polynomial to its own public key share
[0074] Specifically, generating the shared seeds with the corresponding other participating parties respectively based on the seed shares of the current participating party and each of the other participating parties may include: calculating the sum of the seed shares of each of the other participating parties received and the seed share of the current participating party to obtain the shared seeds between the current participating party and the corresponding other participating parties. In this embodiment, the current participating party P i can add the seed shares j} j≠i sent by all other participating parties {P to itself to its own seed share to form the shared seeds of both parties It should be noted that the shared seed e i of the current participating party P ij is equal to the shared seed j of the other participating party P for use in the key derivation phase and the signature phase.
[0075] Among them, the index ij of the shared seed e ij represents that it is the shared seed of the current participating party P i and the other participating party P j , is owned by the participating party P i and is the same as the shared seed e j owned by the other participating party P ji .
[0076] It can be understood that the commitment of the constant term of the polynomial is a publicly broadcast value, so the current participating party P iThe set Lagrange coefficient λ can be utilized i , to obtain the public key share of other participant P j .
[0077] Step S15: Invoke the pseudo-random number generator by using the shared seed, to generate relevant random numbers, and use the relevant random numbers and a preset key-derived random number to derive the initial private key share and the initial public key share, so as to obtain a new private key share and a new public key share.
[0078] In this embodiment, the current participant P i can use the shared seed e ij to invoke the pseudo-random number generator, and calculate its own relevant random number by accumulating the output of the pseudo-random number generator, and then use the calculated relevant random number and the preset key-derived random number to derive the above-mentioned initial private key share and the above-mentioned initial public key share, so as to obtain a new private key share and a new public key share, and.
[0079] Specifically, the invoking the pseudo-random number generator by using the shared seed, to generate relevant random numbers, may include: invoking the pseudo-random number generator by using the shared seed, and accumulating the output of the pseudo-random number generator according to a preset rule, to obtain relevant random numbers; wherein, the preset rule is to determine whether the index of the current participant is greater than the index of the other participant, if the index of the current participant is greater than the index of the other participant, then accumulate the output of the pseudo-random number generator, and if the index of the current participant is less than the index of the other participant, then subtract the output of the pseudo-random number generator. For example, the current participant P i uses the shared seed e j with the other participant P ij to invoke the pseudo-random number generator and accumulate the output of the pseudo-random number generator. For all j≠i', the current participant P i subtracts the output {PRG(e ij )} of all pseudo-random number generators where i<j in the index i<j , and accumulates the output {PRG(e ij )} of all pseudo-random number generators where i>j in the index i>j , so as to non-interactively generate the relevant random number ∑ j<i PRG(e ij ) - ∑ j>i PRG(e ij )
[0080] Furthermore, the current participant P i uses the relevant random number ∑ j<i PRG(e ij) - ∑ j>i PRG(e ij ) and the preset key-derived random number ρ are used to derive the initial private key share x i and the initial public key share y i to obtain its own new private key share x' i and new public key share y' i , and the specific calculation formula is:
[0081] x' i = x i + ρ / n + ∑ j<i PRG(e ij ) - ∑ j>i PRG(e ij );
[0082]
[0083] In the formula, n is the number of all participating parties.
[0084] In addition, the current participating party P i can also use the key-derived random number ρ as the exponent of the generator g to obtain the target data, and calculate the product of the target data and the current public key y to derive its own new public key. Among them, the calculation formula of the new public key is:
[0085] y' = y · g ρ = g x+ρ
[0086] It should be noted that the sum of the relevant random numbers of all participating parties in this application is 0.
[0087] It can be understood that a pseudo-random number generator can receive a short random seed as input and output a seemingly random digital sequence with a length much longer than the seed. This output sequence exhibits characteristics similar to true random numbers statistically, such as uniform distribution and non-periodicity. Its reproducibility also brings additional advantages, ensuring that the same random number sequence can be obtained every time the same random seed is used. In this application, by using a pseudo-random number generator for digital signature, the key derivation phase of a deterministic wallet can be achieved without interaction, and at the same time, it can be used to blind secret shares (such as private key shares) in the signature phase, thus reducing the computational overhead while ensuring that the secret information is not leaked.
[0088] Step S16: Generate random number shares, use the relevant random numbers to blind the new private key share and the random number shares to obtain blinded shares, and then use the blinded shares of all participating parties to perform digital signature on the information to be signed to obtain a signature result.
[0089] In this embodiment, the current participant P i can first generate random number shares from an elliptic curve group of prime order , and then use the relevant random number ∑ j<i PRG(e ij ) - ∑ j>i PRG(e ij ) to blind the above-mentioned new private key share and the above-mentioned random number share to obtain the blinded shares, and then use the blinded shares of all participants to digitally sign the information M to be signed to obtain the corresponding signature result.
[0090] Specifically, the generation of random number shares and the use of the relevant random number to blind the new private key share and the random number share to obtain the blinded shares may include: randomly selecting a second preset number of random number shares from the elliptic curve group of prime order by means of random uniform sampling; respectively calculating the sum of the relevant random number and the new private key share and the random number share to obtain the blinded shares. For example, the current participant P i randomly selects random number shares from the elliptic curve group of prime order , where ←$ represents random uniform sampling. For all j ≠ i, the relevant random number ∑ constructed by the pseudorandom number generator j<i PRG(e ij ) - ∑ j>i PRG(e ij ) is used to blind the random number share and the private key share x i , and the following calculations are performed in sequence:
[0091]
[0092] In the formula, and represent two different random number shares (also called nonce shares); is the seed share of the pseudorandom number generator. The superscript of e ij is only for distinction and is the same as e ij .
[0093] Next, calculate and secretly send the blinded φ i to other participants P j , and broadcast the public key shares y i and
[0094] That is, the current participant P i first randomly generates shares of two nonce shares (including k and φ) Then, blind the private key share x j and the nonce share with the relevant random numbers of other participating party P i , and then send the blinded φ i to the corresponding other participating party P j , and broadcast the public key share y i and the power commitment R i of the blinded nonce k share.
[0095] Specifically, using the blinded shares of all participating parties to perform a digital signature on the information to be signed to obtain a signature result may include: when receiving the blinded shares sent by the other participating parties, respectively generate the additive share of the current participating party using the blinded shares of each of the other participating parties and the current participating party, and send the additive share to the corresponding other participating parties; when receiving the additive shares sent by the corresponding other participating parties, perform a hash operation on the information to be signed to obtain a hash value, and generate a signature material using the additive shares of each of the other participating parties and the current participating party and the hash value, and send the signature material to all the other participating parties; when receiving the signature materials sent by the other participating parties, generate a signature result for the information to be signed based on the signature materials of all participating parties. For example, the current participating party P i first calculates using the broadcast R i Calculate using the broadcast R i Calculate and let r be the abscissa of R, let r = R| x-axis ;
[0096] Next, for the blinded random number share φ j sent by the other participating party P j , the current participating party Pi randomly generates an additive share from and calculates and generates the additive share α i of φ j ·w i using the blinded private key share w ji , where the calculation formula of α ji is:
[0097] α ji = φ j ·w i - β ji
[0098] Further, the current participating party P i randomly generates another additive share from and then calculates and generates φ using the blinded nonce share k i j ·k i Additive share u ji , where u ji The calculation formula is:
[0099] u ji = φ j ·k i - v ji ;
[0100] Then the current participant P i Sends the generated additive share α ji and u ji to the corresponding other participants P j .
[0101] It can be understood that the current participant P i Calculates the multiplicative aggregation of R i and combines the blinded random number shares φ j sent by other participants P j with its own blinded random number share k i and the private key share w i for operation, and then sends the operation result to the corresponding other participants P j , which can realize the conversion of the multiplicative shares k i , φ i , w i to the additive shares α ij , β ji , u ij , v ji .
[0102] Next, the current participant P i Accumulates all the received additive shares α ij with all its local β ji and uses the blinded nonce share φ i and the blinded private key share w i it owns to obtain the additive share ρ i of φ·x. The specific calculation formula is:
[0103] ρ i = φ i ·w i + ∑ j∈[1...n],j≠i (α ij + β ji );
[0104] In the formula, φ i is the blinded nonce share owned by the current participant P i , w i is the blinded private key share owned by the current participant P iThe blinded private key share α ij and β ji are additive shares;
[0105] Furthermore, the current participant P i accumulates all the received additive shares u ij with all the local v ji and uses the blinded nonce share k i and the blinded nonce share φ i to obtain the additive share σ i of k·φ, and uses it as the first signature material σ i for the signature. The specific calculation formula is:
[0106] σ i = φ i ·k i + ∑ j∈[1...n],j≠i (u ij + v ji );
[0107] In the formula, φ i is the blinded nonce share owned by the current participant P i , k i is the blinded nonce share owned by the current participant P i , u ij and v ji are additive shares;
[0108] Furthermore, the current participant P i performs a hash operation on the message M to be signed, generates the hash value m = Hash(M) of the message, and then uses the hash value m, the blinded nonce share φ i owned by itself, and r and ρ i to generate the second signature material δ i in the form of an additive share required for the signature. The specific calculation formula is:
[0109] δ i = m·φ i + r·ρ i ;
[0110] Then, the current participant P i sends the first signature material σ i and the second signature material δ i to all other participants P j .
[0111] It should be noted that the sum of ρ i in the second signature material is the product of the private key x and the nonce φ, that is The first signature material σ i The sum is the product of nonce k and nonce φ, that is
[0112] Finally, the current participant P i After receiving the first signature materials {σ j} j∈[1...n],j≠i and the second signature materials {δ j} j∈[1...n],j≠i from all other participants, locally calculates and outputs the generated r and s together as a signature pair (r, s) to obtain the signature result.
[0113] It can be seen that the embodiment of the present application uses a threshold digital signature algorithm based on elliptic curves to randomly generate polynomial coefficients and seed shares for a pseudo-random number generator, and uses the polynomial coefficients to generate initial private key shares and initial public key shares. Then, based on the seed shares of the current participant and the seed shares of other participants, a shared seed between the two is generated. Through this shared seed, a pseudo-random number generator can be called to generate relevant random numbers. Then, the relevant random numbers are used to derive the initial private key shares and initial public key shares to generate new private key shares and new public key shares. Finally, by blinding the new private key shares, the digital signature of the information to be signed is realized. On the one hand, the present application can achieve the key derivation stage of a deterministic wallet without interaction, and at the same time blinds the secret shares in the signature stage, thereby reducing the computational overhead and ensuring that the secret information is not leaked. On the other hand, the secure multi-party computing technology using a threshold digital signature algorithm based on elliptic curves distributes the signature public and private key pairs among multiple participants, solving the possible single-point failure problem. As long as the number of compromised participants by the adversary does not reach the threshold value, the secret information will not be leaked, thereby enhancing the security of the wallet. Compared with the method of storing and maintaining a large number of keys to prevent linkage, the present application only needs to store the initial public and private key pairs and the seeds of the pseudo-random number generator. In addition, the present application realizes a non-custodial wallet. Different from a custodial wallet that needs to fully trust the service provider, the blockchain wallet provided by the present application puts all the signature keys under its own control and does not need to trust other third parties.
[0114] Correspondingly, the embodiment of the present application also discloses a digital signature device, which is applied to any participant terminal using a blockchain wallet. Refer to Figure 2 as shown. The device includes:
[0115] A first generation module 11, configured to randomly generate polynomial coefficients and seed shares for a pseudo-random number generator by using a threshold digital signature algorithm based on elliptic curves;
[0116] Construction module 12, configured to construct a random polynomial by using the polynomial coefficients and a preset threshold size;
[0117] Splitting module 13, configured to split the random polynomial to obtain a plurality of polynomial shares;
[0118] Second generation module 14, configured to generate a polynomial coefficient commitment of the current participating party based on the polynomial coefficients;
[0119] Information sending module 15, configured to distribute each of the polynomial shares and the seed shares to other participating parties, and broadcast the polynomial coefficient commitment;
[0120] Third generation module 16, configured to generate an initial private key share and an initial public key share based on preset Lagrange coefficients and the polynomial shares of all participating parties, and generate a shared seed between the current participating party and each of the other participating parties respectively based on the seed shares of the current participating party and each of the other participating parties;
[0121] Invocation module 17, configured to invoke the pseudo-random number generator by using the shared seed to generate relevant random numbers;
[0122] Derivation module 18, configured to derive the initial private key share and the initial public key share by using the relevant random numbers and a preset key derivation random number to obtain a new private key share and a new public key share;
[0123] Digital signature module 19, configured to generate a random number share, blind the new private key share and the random number share by using the relevant random numbers to obtain blinded shares, and then perform a digital signature on the information to be signed by using the blinded shares of all participating parties to obtain a signature result.
[0124] Wherein, the specific working processes of the above-mentioned various modules may refer to the corresponding content disclosed in the foregoing embodiments, and will not be elaborated herein.
[0125] It can be seen that in the embodiments of the present application, a threshold digital signature algorithm based on an elliptic curve is used to randomly generate polynomial coefficients and seed shares, and the polynomial coefficients are used to generate initial private key shares and initial public key shares. Then, a shared seed between the current participant's seed share and the seed shares of other participants is generated. Through this shared seed, a pseudo-random number generator can be invoked to generate relevant random numbers. Then, the relevant random numbers are used to derive the initial private key shares and initial public key shares, so as to generate new private key shares and new public key shares. Finally, by blinding the new private key shares, the digital signature of the information to be signed is realized. On the one hand, through the pseudo-random number generator, a non-interactive key derivation phase can be realized, and at the same time, the computational overhead in the signature phase is greatly reduced. On the other hand, the distributed characteristics of the threshold digital signature algorithm based on the elliptic curve are used to solve the single point of failure problem that may exist in non-custodial wallets. As long as the number of compromised participants by the adversary does not reach the threshold value, the secret information will not be leaked, and a deterministic wallet is realized, thus solving the problem of linkable transactions in a more efficient storage manner.
[0126] In some specific embodiments, the first generation module 11 may specifically include:
[0127] A first generation unit, configured to generate system public parameters through a public key infrastructure and using preset security parameters; the system public parameters include a prime order elliptic curve group, a generator, and a prime number;
[0128] A first selection unit, configured to randomly select a first preset number of polynomial coefficients on the prime order elliptic curve group by using a threshold digital signature algorithm based on an elliptic curve;
[0129] A second generation unit, configured to randomly generate a seed share for the pseudo-random number generator; the number of bits of the seed share is the same as the preset security parameter;
[0130] Correspondingly, the second generation module 14 may specifically include:
[0131] A commitment generation unit, configured to use the polynomial coefficient as the exponent of the generator to obtain a polynomial coefficient commitment of the current participant.
[0132] In some specific embodiments, the third generation module 16 may specifically include:
[0133] An addition aggregation unit, configured to, when receiving the polynomial coefficient commitments, seed shares, and polynomial shares sent by the other participants, perform addition aggregation on the polynomial shares of all participants to obtain a Shamir secret sharing share of the private key of the current participant;
[0134] A first conversion unit, configured to convert the Shamir secret sharing share into an additive secret sharing share of the private key of the current participant by using a preset Lagrange coefficient, so as to obtain a private key share of the current participant;
[0135] A multiplication aggregation unit, configured to perform multiplication aggregation on the polynomial constant term commitments in the polynomial coefficient commitments of all participants to obtain the current public key of all participants;
[0136] A second conversion unit, configured to convert the polynomial constant term commitment of the current participant into a public key share by using the preset Lagrange coefficient.
[0137] In some specific embodiments, the third generation module 16 may specifically include:
[0138] A first calculation unit, configured to calculate the sum of the seed shares of each of the other participants received and the seed share of the current participant to obtain a shared seed between the current participant and the corresponding other participant;
[0139] Correspondingly, the digital signature device may further include:
[0140] A second calculation unit, configured to use the key derivation random number as the exponent of the generator to obtain a target data, and calculate the product of the target data and the current public key to derive a new public key.
[0141] In some specific embodiments, the digital signature module 19 may specifically include:
[0142] A second selection unit, configured to randomly select a second preset number of random number shares from the prime order elliptic curve group by means of random uniform sampling;
[0143] A third calculation unit, configured to calculate the sum of the relevant random number, the new private key share, and the random number share respectively to obtain a blinded share.
[0144] In some specific embodiments, the digital signature module 19 may specifically include:
[0145] A third generation unit, configured to, when receiving the blinded shares sent by the other participants, generate an additive share of the current participant by using the blinded shares of each of the other participants and the current participant respectively;
[0146] A first sending unit, configured to send the additive share to the corresponding other participant;
[0147] A hash operation unit, configured to perform a hash operation on the information to be signed to obtain a hash value when receiving the additive share sent by the corresponding other participant;
[0148] A fourth generation unit, configured to generate signature materials by using the addition shares of each of the other participating parties and the current participating party and the hash value;
[0149] A second sending unit, configured to send the signature materials to all of the other participating parties;
[0150] A fifth generation unit, configured to, when receiving the signature materials sent by the other participating parties, generate a signature result for the information to be signed based on the signature materials of all the participating parties.
[0151] In some specific embodiments, the calling module 17 may specifically include:
[0152] A related random number generation unit, configured to call the pseudo-random number generator by using the shared seed and accumulate the output of the pseudo-random number generator according to a preset rule to obtain a related random number;
[0153] Wherein, the preset rule is to determine whether the index of the current participating party is greater than the index of the other participating parties. If the index of the current participating party is greater than the index of the other participating parties, the output of the pseudo-random number generator is accumulated; if the index of the current participating party is less than the index of the other participating parties, the output of the pseudo-random number generator is subtracted.
[0154] Furthermore, an embodiment of the present application also discloses an electronic device, Figure 3 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment. The content in the figure should not be considered as any limitation on the scope of use of the present application.
[0155] Figure 3 It is a schematic structural diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Wherein, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the digital signature method disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0156] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and specific limitations are not imposed thereon here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitations are imposed here.
[0157] In addition, as a carrier for storing resources, the memory 22 can be a read-only memory, a random access memory, a magnetic disk, an optical disc, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc. The storage method can be transient storage or permanent storage.
[0158] Among them, the operating system 221 is used to manage and control each hardware device and the computer program 222 on the electronic device 20, and it can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the digital signature method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 can further include computer programs that can be used to complete other specific tasks.
[0159] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the digital signature method disclosed above is implemented. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.
[0160] Furthermore, an embodiment of the present application also discloses a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the digital signature method disclosed above are implemented.
[0161] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and reference can be made to the description of the method part for related parts.
[0162] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0163] The steps of the methods or algorithms described in connection with the embodiments disclosed herein may be implemented directly in hardware, in software modules executed by a processor, or in a combination thereof. The software modules may be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium well known in the art.
[0164] Finally, it should also be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0165] The above has provided a detailed introduction to a digital signature method, apparatus, device, and storage medium provided by the present application. Specific examples are used herein to elaborate on the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, based on the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A digital signature method, characterized in that: Applicable to any participant terminal using blockchain wallet, including: Randomly generate polynomial coefficients and a seed share for a pseudo-random number generator using a threshold digital signature algorithm based on an elliptic curve, and construct a random polynomial using the polynomial coefficients and a preset threshold size; Splitting the random polynomial to obtain a plurality of polynomial shares, and generating a polynomial coefficient commitment of the current participant based on the polynomial coefficients; Distributing each of the polynomial shares and the seed share to other participants, and broadcasting the polynomial coefficient commitment; Generate an initial private key share and an initial public key share based on the preset Lagrangian coefficients and the polynomial shares of all participants, and generate a shared seed between the current participant and the other participants based on the seed shares of the current participant and the other participants; Using the shared seed to call the pseudo-random number generator to generate a related random number, and using the related random number and a preset key derivation random number to derive the initial private key share and the initial public key share to obtain a new private key share and a new public key share; Generate a random number share, and use the relevant random number to blind the new private key share and the random number share to obtain a blinded share, and then use the blinded shares of all participants to digitally sign the information to be signed to obtain a signature result.
2. The digital signature method according to claim 1, characterized in that: The method of randomly generating polynomial coefficients and seed shares for a pseudo-random number generator using a threshold digital signature algorithm based on an elliptic curve includes: Generate system public parameters through public key infrastructure and using preset security parameters; the system public parameters include prime-order elliptic curve groups, generators and prime numbers; A first preset number of polynomial coefficients are randomly selected on the prime-order elliptic curve group using an elliptic curve-based threshold digital signature algorithm, and a seed share for a pseudo-random number generator is randomly generated; the number of bits of the seed share is the same as the preset security parameter; Accordingly, generating the polynomial coefficient commitment of the current participant based on the polynomial coefficient includes: The polynomial coefficient is used as the exponent of the generator to obtain the polynomial coefficient commitment of the current participant.
3. The digital signature method according to claim 2, characterized in that: The generating of the initial private key share and the initial public key share based on the preset Lagrangian coefficient and the polynomial shares of all participants includes: When receiving the polynomial coefficient commitment, seed share and polynomial share sent by the other participants, performing addition aggregation on the polynomial shares of all participants to obtain the Shamir secret sharing share of the private key of the current participant; The Shamir secret sharing share is converted into an additive secret sharing share of the private key of the current participant by using a preset Lagrangian coefficient to obtain the private key share of the current participant; The polynomial constant term commitments in the polynomial coefficient commitments of all participants are multiplied and aggregated to obtain the current public keys of all participants, and the polynomial constant term commitments of the current participant are converted into public key shares using the preset Lagrange coefficients.
4. The digital signature method according to claim 3, characterized in that: The generating of shared seeds between the current participant and the corresponding other participants based on the seed shares of the current participant and the seed shares of each of the other participants respectively includes: Calculate the sum of the received seed shares of each of the other participants and the seed share of the current participant to obtain a shared seed between the current participant and the corresponding other participants; Accordingly, the digital signature method further includes: The key derivation random number is used as the exponent of the generator to obtain target data, and the product of the target data and the current public key is calculated to derive a new public key.
5. The digital signature method according to claim 2, characterized in that: The generating of the random number share, and blinding the new private key share and the random number share using the relevant random number to obtain the blinded share, includes: Randomly selecting a second preset number of random number shares from the prime-order elliptic curve group by random uniform sampling; The sum of the relevant random number, the new private key share and the random number share is calculated respectively to obtain a blinded share.
6. The digital signature method according to claim 5, characterized in that: The method of using the blinded shares of all participants to digitally sign the information to be signed to obtain a signature result includes: When receiving the blinded shares sent by the other participants, respectively using the blinded shares of each of the other participants and the current participant to generate the added share of the current participant, and sending the added share to the corresponding other participants; When receiving the addition shares sent by the corresponding other participants, performing a hash operation on the information to be signed to obtain a hash value, and using the addition shares of each other participant and the current participant and the hash value to generate a signature material, and sending the signature material to all the other participants; When the signature materials sent by the other participants are received, a signature result for the information to be signed is generated based on the signature materials of all the participants.
7. The digital signature method according to any one of claims 1 to 6, characterized in that: The using the shared seed to call the pseudo-random number generator to generate a related random number includes: Using the shared seed to call the pseudo-random number generator, and accumulating the output of the pseudo-random number generator according to a preset rule to obtain a related random number; Among them, the preset rule is to determine whether the index of the current participant is greater than the index of the other participants. If the index of the current participant is greater than the index of the other participants, the output of the pseudo-random number generator is accumulated; if the index of the current participant is less than the index of the other participants, the output of the pseudo-random number generator is subtracted.
8. A digital signature device, characterized in that: Applicable to any participant terminal using blockchain wallet, including: A first generation module, used for randomly generating polynomial coefficients and seed shares for a pseudo-random number generator by using a threshold digital signature algorithm based on an elliptic curve; A construction module, used to construct a random polynomial using the polynomial coefficients and a preset threshold size; A splitting module, used for splitting the random polynomial to obtain a plurality of polynomial shares; A second generating module, used for generating a polynomial coefficient commitment of the current participant based on the polynomial coefficient; An information sending module, used to distribute each of the polynomial shares and the seed share to other participants, and broadcast the polynomial coefficient commitment; A third generation module is used to generate an initial private key share and an initial public key share based on a preset Lagrangian coefficient and the polynomial shares of all participants, and to generate a shared seed between the current participant and the other participants based on the seed shares of the current participant and the other participants; A calling module, used to call the pseudo-random number generator using the shared seed to generate a related random number; A derivation module, used to derive the initial private key share and the initial public key share by using the relevant random number and a preset key derivation random number to obtain a new private key share and a new public key share; The digital signature module is used to generate a random number share, and use the relevant random number to blind the new private key share and the random number share to obtain a blinded share, and then use the blinded shares of all participants to digitally sign the information to be signed to obtain a signature result.
9. An electronic device, characterized in that: It comprises a processor and a memory; wherein, when the processor executes the computer program stored in the memory, the digital signature method as claimed in any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein, when the computer program is executed by a processor, the digital signature method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Two-round threshold ECDSA signature method and system
CN120896700A