Threshold SM2 signature method capable of realizing responsibility investigation

By adopting a accountable threshold SM2 signature method in the distributed system, the problem of unclear responsibility allocation in the signature process of multiple participants is solved, and effective tracking of signers and data security is achieved.

CN120223323APending Publication Date: 2025-06-27XIAN UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510458649.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In large-scale distributed systems such as blockchain and the Internet of Things, the allocation of responsibilities in the signature process of multiple participants is unclear, and malicious signers may affect data security and privacy.

Method used

A accountable threshold SM2 signature method is adopted to ensure that the signer can generate a valid signature when the threshold conditions are met, and the signature is tracked by the tracking key.

Benefits of technology

It realizes effective tracking of contract signers in blockchain and other scenarios, prevents signature forgery, improves data security and privacy, and reduces computing overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223323A_ABST
    Figure CN120223323A_ABST
Patent Text Reader

Abstract

The invention relates to a responsibility-traceable threshold SM2 signature method, which combines a threshold signature with a responsibility-traceable mechanism, and provides the responsibility-traceable threshold SM2 signature method. Comprising the following steps: establishing a system and generating system parameters; generating a key; performing distributed signature; aggregating the signatures; performing aggregation verification; and tracking the signature. According to the invention, the signer signs the message by using the own secret key share, and the aggregator can correctly aggregate the final signature only when the sum of the signers reaches the preset threshold value t. And meanwhile, by introducing a tracker, a signer set can be tracked when a dispute occurs in the collaborative signature process of a plurality of participants, so that effective responsibility investigation of the signers is realized. The basic security requirement of the threshold signature can be met, and malicious behaviors can be effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of blockchain technology, and particularly to a traceable threshold SM2 signature method. Background Art

[0002] In large-scale distributed systems such as blockchain and Internet of Things, the number of users and the amount of data have increased significantly. There are problems in the distribution of responsibilities among multiple parties during the signature process. At the same time, the malicious behaviors of some signers may also affect and endanger data security and participant privacy.

[0003] To address such problems, the common solution is to use threshold signatures. Multiple signers jointly generate a signature using their signature keys. Only when the signature shares meet the preset threshold conditions, the aggregator will aggregate the signature shares into a valid signature. If the preset threshold conditions are not met, a valid signature cannot be recovered. In practical applications, it becomes necessary to trace possible malicious signers.

[0004] That is to say, in the prior art, it is necessary to solve the problem of how to make the threshold SM2 signature traceable for malicious signers in practical applications. Summary of the Invention

[0005] The present invention provides a traceable threshold SM2 signature method to solve the problem of unclear responsibilities in the distributed signature process of multiple participants. In applications such as the signing of electronic contracts on the blockchain, it can effectively trace the contract signers.

[0006] The present invention provides a traceable threshold SM2 signature method, including the following steps:

[0007] Step 100, system establishment, generating system parameters;

[0008] Step 200, key generation;

[0009] Step 300, distributed signature;

[0010] Step 400, aggregated signature;

[0011] Step 500, aggregated verification;

[0012] Step 600, signature tracing.

[0013] In one embodiment, step 100 specifically includes the following steps:

[0014] Step S101, setting security parameter 1 λ , generating a finite field F of order q q , elliptic curve equation E(F q ); G=(xG , y G )(G≠O) is the base point on E(F q ), x G and y G are elements in F q , the order p of G;

[0015] Step S102, set the number of participants to n, and each participant is represented by p i and P = {p1, p2,..., p n}, C ∈ [n] is the signature group, where |C| = t, and set the threshold t;

[0016] Step S103, output the public parameters (p, q, G, n, P, C, t).

[0017] In one embodiment, step 200 specifically includes the following steps:

[0018] Step S201, randomly select the private key sk i ← F q , where and i ∈ [n], and the final public key result is pk = (sk - 1)G;

[0019] Step S202, calculate pk i = sk i G, set pk' ← (pk1,..., pk n ), randomly select ψ ← F q , and encrypt the threshold t using the ElGamal encryption algorithm to obtain: (T0, T1) = (ψG, ψY + tG);

[0020] Step S203, generate the public and private keys (sk cs , pk cs ) of the aggregator using the key generation algorithm;

[0021] Step S204, randomly sample sk e ← F q , and calculate pk t = sk e G, set the public key of the verifier to pk ← (pk', pk t , pk cs , T0, T1), the private key of the aggregator is sk c ← (pk, sk cs , t, ψ), and the tracing key is sk t ← (pk, sk e , t);

[0022] Step S205, finally output (pk, {sk1,..., skn ,sk c ,sk t )。

[0023] In one embodiment, step 300 specifically includes the following steps:

[0024] Step S301, each participant randomly selects k i ←F q , calculates and broadcasts k i ×G;

[0025] Step S302, each party uses the k i ×G saved locally through the broadcast to obtain and sets the elliptic curve point R = (r x ,r y );

[0026] Step S303, each party calculates e = H v (m), and obtains r = (e + r x ) mod p;

[0027] Step S304, each party calculates and saves and sends the signature share δ i = (r, s i ) to the aggregator.

[0028] In one embodiment, step 400 specifically includes the following steps:

[0029] Step S401, the aggregator aggregates the signature s←∑ i∈C s i ∈F q , and then verifies the equation sG = R - w∑ i∈C pk i ;

[0030] Step S402, encrypts the signature s using the ElGamal encryption algorithm, randomly selects ρ←F q and obtains the encryption result: ct: = (c0, c1)←(ρG, ρpk t + sG);

[0031] Step S403, sets (b1,..., b n )∈{0, 1}, if i∈C then b i = 1;

[0032] Step S404, for the relationship generates a zero-knowledge proof π,

[0033] (s, ρ, ψ, γ, b1,..., b n, φ1, ..., φ n )} Where:

[0034] Step S405, sign with the private key of the aggregator

[0035] Step S406, output the accountable threshold SM2 signature σ ← (r, ct, π, tg).

[0036] In one embodiment, step 500 specifically includes the following steps:

[0037] Step S501, the verifier receives the signature σ = (r, ct, π, tg), where ct = (c0, c1). Expand the public key pk = (pk′, pk t , pk cs , T0, T1) and set e = H v (m), verify the equation Whether it holds. If it does not hold, the verification fails. Otherwise, proceed to the next step;

[0038] Step S502, the signature verification algorithm verifies Whether it holds. If it does not hold, the verification fails. Otherwise, proceed to the next step;

[0039] Step S503, verify whether π is a valid proof of the relationship With the statement (G, Y, pk′, pk t , T0, T1, R, w, ct = (c0, c1)). If not, the verification fails. Otherwise, the verification passes;

[0040] Step S504, if the verification passes, output 1; otherwise, output 0.

[0041] In one embodiment, step 600 specifically includes the following steps:

[0042] Step S601, judge the aggregated verification result. If That is, the verification fails, then terminate; otherwise, proceed to the next step;

[0043] Step S602, expand σ into (r, ct, π, tg), and ct = (c0, c1). Set e = H v (m), and obtain r = (e + r x ) mod p;

[0044] Step S603, decrypt the aggregated signature result s with the ElGamal decryption algorithm, and decrypt ct = (c0, c1) into c1 - sk e c0, that is, s′ + ρpk t -ρsk eG;

[0045] Step S604, find a set \(C\in[n]\) where \(|C| = t\) and verify the equation \(s'G=R - w\sum_{k = 1}^{t}p_{k}\). If the equation verification passes, output \(C\), otherwise output failure. i∈C \(p_{k}\) i . If the equation verification passes, output \(C\), otherwise output failure.

[0046] Compared with the prior art, the advantages of the present invention are that it can effectively resist forgery attacks and has good privacy. Compared with traditional solutions, the computational overhead has obvious advantages. It can maintain a low computational overhead while increasing accountability. In scenarios such as electronic contract signing on the blockchain, it can effectively track contract signers. Brief Description of the Drawings

[0047] The present invention will be described in more detail below based on embodiments and with reference to the drawings.

[0048] Figure 1 It is a schematic diagram of generating keys according to an embodiment of the present invention.

[0049] Figure 2 It is a schematic diagram of generating an SM2 signature and a tracing method according to an embodiment of the present invention. Detailed Embodiments

[0050] In order to make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described below in conjunction with embodiments.

[0051] Symbols and Definitions

[0052] \(\lambda\): Security parameter;

[0053] \(t\): Aggregator aggregation signature threshold;

[0054] \(n\): Total number of participants;

[0055] \(C\): Set of participants participating in the accountable threshold SM2 signature;

[0056] \(F\) q : Finite field;

[0057] \(a,b\): Elements in the finite field;

[0058] \(E(F\) q ) : Elliptic curve equation;

[0059] \(G\): Base point on the elliptic curve;

[0060] \(p\): Order of the base point \(G\);

[0061] \(kp\): \(k\) times point of point \(P\) on the elliptic curve, where \(k\) is a positive integer;

[0062] (\(r\)x , r y ): the value of the x - coordinate and the value of the y - coordinate of a certain point;

[0063] (sk cs , pk cs ): the public - private key of the aggregator;

[0064] sk t : the tracing key;

[0065] (M, σ): the message - signature pair.

[0066] Reference Figure 1 and Figure 2 As shown in and , the present invention provides a accountable threshold SM2 signature method, including the step of system establishment for generating system parameters, specifically including the following steps:

[0067] Step S101, set the security parameter 1 λ , generate a finite field F of order q q , the elliptic curve equation E(F q ); G=(x G , y G )(G≠O) is the base point on E(F q ), x G and y G are elements in F q , the order p of G;

[0068] Step S102, set the number of participants as n, each participant is represented by p i , and P = {p1, p2,..., p n}, C∈[n] is the signature group, where |C| = t, set the threshold value t;

[0069] Step S103, output the public parameters (p, q, G, n, P, C, t).

[0070] Reference Figure 1 and Figure 2 As shown in and , the present invention provides a accountable threshold SM2 signature method, further including the following steps:

[0071] Step 200, key generation;

[0072] Step 300, distributed signature;

[0073] Step 400, aggregate signature;

[0074] Step 500, aggregate verification;

[0075] Step 600, signature tracing.

[0076] According to the above steps, multiple signers use their own signature keys to jointly generate a signature. Only when the signature shares meet the preset threshold condition, the aggregator will aggregate the signature shares into a valid signature. At the same time, by introducing a tracker, when there are problems or disputes with the signature, the tracker can trace the set of signers to ensure that the malicious behavior of the signers is effectively supervised and prevent the occurrence of signature forgery.

[0077] Specifically, in one embodiment, step 200 key generation specifically includes the following steps:

[0078] Step S201, randomly select the private key sk of the participant i ←F q , where and i ∈ [n], and the final public key result is pk = (sk−1)G;

[0079] Step S202, calculate pk i = sk i G, set pk′ ← (pk1,..., pk n ), randomly select ψ ← F q , and encrypt the threshold t using the ElGamal encryption algorithm to obtain: (T0, T1) = (ψG, ψY + tG);

[0080] Step S203, use the key generation algorithm to generate the public and private keys (sk cs , pk cs ) of the aggregator;

[0081] Step S204, randomly sample sk e ←F q , and calculate pk t = sk e G, set the public key of the verifier to pk ← (pk′, pk t , pk cs , T0, T1), and the private key of the aggregator is sk c ←(pk, sk cs , t, ψ), and the tracing key is sk t ←(pk, sk e , t);

[0082] Step S205, finally output (pk, {sk1,..., sk n}}, sk c , sk t ).

[0083] Generate keys according to the above steps. Take the security parameter λ, the number of participants n, and the threshold t as inputs. Output the public key pk, the signer keys sk1,..., sk n, the combiner key sk c and the tracing key sk t .

[0084] Specifically, in one embodiment, step 300 for distributed signature specifically includes the following steps:

[0085] Step S301, each participant randomly selects k i ←F q , calculates and broadcasts k i ×G;

[0086] Step S302, each party uses the k i ×G locally saved through broadcasting to obtain and sets the elliptic curve point R = (r x , r y );

[0087] Step S303, each party calculates e = H v (m), and obtains r = (e + r x ) mod p;

[0088] Step S304, each party calculates and saves and sends the signature share δ i = (r, s i ) to the aggregator.

[0089] According to the above steps, for the input signer key sk i and the message m, in some constructions it is convenient to allow the signer to know the membership of the signature group C ∈ [n], so it is taken as an optional input. The output is the signature share δ i generated by the signer using the key pair sk i for the message m, and the signature share δ i = (r, s i ) is sent to the aggregator.

[0090] Specifically, in one embodiment, step 400 for aggregating signatures specifically includes the following steps:

[0091] Step S401, the aggregator aggregates the signatures s ← ∑ i∈C s i ∈F q , then verifies the equation sG = R - wΣ i∈C pk i ;

[0092] Step S402, encrypts the signature s using the ElGamal encryption algorithm, randomly selects ρ ← F q and obtains the encryption result: ct := (c0, c1) ← (ρG, ρpk t + sG);

[0093] Step S403, set (b1,..., b n ) ∈ {0, 1}, if i ∈ C then b i = 1;

[0094] Step S404, for the relation generate a zero - knowledge proof π,

[0095] (s, ρ, ψ, γ, b1,..., b n , φ1,..., φ n )};

[0096] Step S405, sign with the private key of the aggregator

[0097] Step S406, output the accountable threshold SM2 signature σ ← (r, ct, π, tg).

[0098] According to the above steps, take the private key of the combiner, the message m, the number of legitimate signers C ∈ [n] as inputs, where |C| = t, and there are t valid signature shares in C. If the input is valid, use the aggregator to aggregate the signatures, encrypt the signatures using the ElGamal encryption algorithm, generate a zero - knowledge proof for the relation, and sign with the private key of the aggregator, and finally output the overall signature.

[0099] Specifically, in one embodiment, step 500 for aggregation verification specifically includes the following steps:

[0100] Step S501, the verifier receives the signature σ = (r, ct, π, tg), where ct = (c0, c1). Expand the public key pk = (pk′, pk t , pk cs , T0, T1) and set e = H v (m), and verify whether the equation holds. If it does not hold, the verification fails; otherwise, proceed to the next step;

[0101] Step S502, the signature verification algorithm verifies whether holds. If it does not hold, the verification fails; otherwise, proceed to the next step;

[0102] Step S503, verify whether π is a valid proof of the relation and the statement (G, Y, pk′, pk t , T0, T1, R, w, ct = (c0, c1)). If not, the verification fails; otherwise, the verification passes;

[0103] Step S504, if the verification passes, output 1; otherwise, output 0.

[0104] According to the above steps, input the public key pk, the message, and the signature of the message. According to the verification algorithm and the verification judgment of zero-knowledge proof, output 0 or 1, where output 1 indicates that the signature verification passes, otherwise output 0 indicating that the signature is invalid.

[0105] Specifically, in one embodiment, step 600 signature tracing specifically includes the following steps:

[0106] Step S601, judge the aggregated verification result. If it is a verification failure, then terminate; otherwise, proceed to the next step;

[0107] Step S602, expand σ into (r, ct, π, tg), and ct = (c0, c1). Set e = H v (m), and obtain r = (e + r x ) mod p;

[0108] Step S603, decrypt the aggregated signature result s using the ElGamal decryption algorithm, and decrypt ct = (c0, c1) into c1 - sk e c0, that is, s′ + ρpk t -ρsk e G;

[0109] Step S604, find a set C ∈ [n], where |C| = t and verify the equation s′G = R - w∑ i∈C pk i . If the equation verification passes, output C, otherwise output failure.

[0110] According to the above steps, use the tracer's key, message, and the signature of the message as input. Output a set C ∈ [n] or the special message fail, where |C| = t. If the set C is output, it means that this set is a group of signers who generated the signature, otherwise the tracing fails.

[0111] Although the present invention has been described with reference to the preferred embodiments, various improvements can be made to it and components therein can be replaced with equivalents without departing from the scope of the present invention. In particular, as long as there is no structural conflict, the technical features mentioned in each embodiment can be combined in any way. The present invention is not limited to the specific embodiments disclosed in the text, but includes all technical solutions falling within the scope of the claims.

Claims

1. A threshold SM2 signature method with accountability, characterized in that: The following steps are involved: Step 100, system establishment, generating system parameters; Step 200, key generation; Step 300, distributed signature; Step 400, aggregate signature; Step 500, aggregation verification; Step 600, signature tracking.

2. The accountable threshold SM2 signature method according to claim 1, characterized in that: The step 100 specifically includes the following steps: Step S101, setting security parameter 1 λ , generating a finite field F of order q q , the elliptic curve equation E(F q ); G = (x G ,y G )(G≠O) is E(F q ) on the base point, x G and G F q The elements in , the order of G is p; Step S102, set the number of participants to n, and each participant uses p i Indicates that, and P = {p1, p2, ..., p n }, C∈[n] is the signature group, where |C|=t, and the threshold value t is set; Step S103, output public parameters (p, q, G, n, P, C, t).

3. The accountable threshold SM2 signature method according to claim 1, characterized in that: The step 200 specifically includes the following steps: Step S201, randomly select the participant's private key sk i ←F q ,in And i∈[n], the final public key result is pk=(sk-1)G; Step S202, calculate pk i =sk i G, set pk′←(pk1,…,pk n ), randomly select ψ←F q , Encrypt the threshold t using the ElGamal encryption algorithm, and obtain: (T0, T1) = (ψG, ψY + tG); Step S203, using the key generation algorithm to generate the aggregator's public and private keys (sk cs ,pk cs ); Step S204, randomly sampling sk e ←F q , and calculate pk t =sk e G, set the public key of the verifier to pk←(pk′,pk t ,pk cs ,T0,T1), the aggregator’s private key is sk c ←(pk,sk cs ,t,ψ), the tracking key is sk t ←(pk,sk e ,t); Step S205, finally output (pk, {sk1, ..., sk n },sk c ,sk t ).

4. The accountable threshold SM2 signature method according to claim 1, characterized in that: The step 300 specifically includes the following steps: Step S301: Each participant randomly selects k i ←F q , calculate and broadcast k i ×G; Step S302, each party uses the k stored locally by broadcasting i ×G gets And set the elliptic curve point R = (r x ,r y ); Step S303, each party calculates e=H v (m), we get r = (e + r x )modp; Step S304: All parties calculate and save And the signature share δ i =(r,s i ) is sent to the aggregator.

5. The accountable threshold SM2 signature method according to claim 1, characterized in that: The step 400 specifically includes the following steps: Step S401, aggregator aggregates signature s←∑ i∈C s i ∈F q , then verify the equation sG=Rw∑ i∈C pk i ; Step S402: Encrypt the signature s using the ElGamal encryption algorithm and randomly select ρ←F q And get the encryption result: ct:=(c0,c1)←(ρG,ρpk t +sG); Step S403, set (b1, ..., b n )∈{0,1}, if i∈C then b i =1; Step S404, for the relationship Generate zero-knowledge proof π, Step S405: Sign with the aggregator’s private key Step S406, output the accountability threshold SM2 signature σ←(r,ct,π,tg).

6. The accountable threshold SM2 signature method according to claim 1, characterized in that: The step 500 specifically includes the following steps: Step S501: The verifier receives the signature σ=(r,ct,π,tg), where ct=(c0,c1); the public key pk=(pk′,pk t ,pk cs ,T0,T1) and set e=H v (m), verify the equation Is it true? If not, the verification fails, otherwise proceed to the next step; Step S502: signature verification algorithm verification Is it true? If not, the verification fails, otherwise proceed to the next step; Step S503, verify whether π is a relation AND statement (G,Y,pk′,pk t ,T0,T1,R,w,ct=(c0,c1)) is a valid proof. If not, the verification fails. Otherwise, the verification passes. Step S504: if the verification is successful, output 1; otherwise, output 0.

7. The accountable threshold SM2 signature method according to claim 1, characterized in that: The step 600 specifically includes the following steps: Step S601, judging the aggregate verification result, if If the verification fails, the process is terminated; otherwise, proceed to the next step; Step S602, expand σ to (r, ct, π, tg), and ct = (c0, c1), set e = H v (m), and we get r = (e + r x )modp; Step S603: Decrypt the aggregate signature result s using the ElGamal decryption algorithm, and decrypt ct = (c0, c1) into c1-sk e c0, that is, s′+ρpk t -ρsk e G; Step S604, find a set C∈[n], where |C|=t and verify the equation s′G=R-wΣ i∈C pk i ; If the equation verification passes, output C, otherwise output failure.