Balanced SM9 digital signature multi-party adapter signature generation method and system
By introducing secret sharing technology and zero-knowledge proof into the SM9 signature solution, the adapter signature is generated under multi-party collaboration, solving the problems of single-point risk and lack of adapter functions, and improving the application capabilities of domestic cryptographic algorithms in complex scenarios.
Patent Information
- Application Number
- CN202510431844.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-01
AI Technical Summary
The existing SM9 signature scheme fails to effectively combine distributed key management, poses a single point of failure risk, and lacks adapter signature function, making it difficult to meet the needs of multi-party collaborative verification and conditional signature.
In a symmetric environment, the key generation center generates the participant's private key shards through secret sharing technology, and generates a public-private key pair for each participant, requesting the pre-signature party to generate difficult relationship examples and zero-knowledge proofs, and other participants verify the legitimacy of the pre-signature, calculate the complete signature, and extract the adapter signature evidence.
It realizes the SM9 pre-signature of the adapter function generated with the joint participation of multiple participants, eliminates single point of risk, supports multi-party collaborative signatures, reduces computing and communication overhead, and is suitable for financial-grade applications with high concurrency and low latency.
Smart Images

Figure CN120238302A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of digital signature technology. Specifically, it relates to a method and system for generating multi-party adapter signatures for balanced SM9 digital signatures. Background Art
[0002] Digital signature, as an important technology in the field of public key cryptography, its core function is to simulate handwritten signatures or seals in the real world through cryptographic means, and can provide security guarantees such as identity authentication, message integrity, and non-repudiation for communication data, and is widely used in scenarios such as electronic contracts and digital certificates. Traditional digital signature technology relies on the Public Key Infrastructure (PKI) and binds the user identity to the public key through digital certificates. However, the PKI system has problems such as complex certificate management, high storage costs, and low public key distribution efficiency, and it is difficult to meet the lightweight requirements especially in distributed systems. To simplify the key management process, Identity-Based Signature (IBS) emerged. It directly generates a public-private key pair using user identity information (such as email, IP address), eliminating the certificate issuance link and significantly reducing the public key management cost. However, in the IBS scheme, the user's private key is usually generated and stored by a single Key Generation Center (KGC), which has a single point of failure risk. Once the private key is leaked or the KGC is attacked, the security of the entire system will be directly threatened. For this reason, Distributed Key Generation (DKG) technology was introduced. By splitting the private key into multiple sub-keys and having different participants collaborate to generate a complete signature, the risk of key centralization was effectively alleviated.
[0003] In recent years, adapter signature has received attention as an enhanced signature technology. It generates a pre-signature by embedding an implicit difficult relationship in the traditional signature. Only when a specific recipient provides evidence of the difficult relationship can the pre-signature be converted into a valid signature. This mechanism makes the validity of the signature bindable to hidden information and has the property that any two elements can be used to deduce the third, providing conditional verification capabilities for scenarios such as atomic swaps and cross-chain transactions. However, existing adapter signature schemes are mostly based on the traditional digital signature framework, fail to be deeply integrated with the identity-based cryptosystem, and lack support for multi-party collaborative signature scenarios.
[0004] In the field of domestic cryptographic algorithms, the SM9 identity-based cryptographic algorithm was released by the State Cryptography Administration and incorporated into the ISO / IEC international standard in 2017. It is the first identity-based cryptographic standard in China based on bilinear pairings. By directly using the user identity as the public key, SM9 naturally supports the identity-based cryptographic system, covering digital signatures, public key encryption, and key exchange protocols, and has been gradually applied in fields such as the Internet of Things and blockchain. However, the existing SM9 signature schemes still have the following limitations: First, the generation of private keys depends on a single KGC and does not incorporate a distributed key management mechanism; second, there is a lack of native support for enhanced functions such as adapter signatures, making it difficult to meet the requirements for conditional signatures and multi-party collaborative verification in emerging scenarios.
[0005] In summary, there is no solution in the prior art that combines the SM9 algorithm with multi-party adapter signatures. How to, based on the domestic cryptographic standard, while retaining its identity-based characteristics, eliminate the single-point risk through distributed key generation, and embed the adapter function to achieve signature conditionalization has become a technical problem that urgently needs to be solved. Summary of the Invention
[0006] The purpose of this application is to provide a method and system for generating multi-party adapter signatures for balanced SM9 digital signatures to overcome the existing technical deficiencies, which can collaboratively generate a national cryptographic SM9 pre-signature with adapter functions and complete the signing of adapter signatures when multiple participants jointly participate in the operation in a symmetric environment.
[0007] The purpose of this application is achieved through the following technical solutions:
[0008] In the first aspect, this application proposes a method for generating multi-party adapter signatures for balanced SM9 digital signatures, where the key generation center is connected to multiple participants. The method includes:
[0009] The key generation center initializes the system parameters according to security parameters in a symmetric environment. The system parameters include an elliptic curve group, a bilinear pair, a master private key, a master public key, and a function identifier;
[0010] The key generation center calculates the first temporary variable and the identity-based private key based on the joint identity identifier of the participants, generates shards of the participants' private keys using secret sharing technology, and generates a public-private key pair for each participant for the ideal function of multiplying to adding;
[0011] The participant requesting the pre-signature generates a difficult relation instance and a zero-knowledge proof and broadcasts them. After verification by other participants, the pre-signature is calculated based on the message to be signed, the bilinear pair, and the first temporary variable;
[0012] The participant requesting the pre-signature verifies the legality of the pre-signature by verifying the temporary variable;
[0013] The requesting pre - signed party calculates the complete signature using the pre - signature and evidence when the pre - signature is legal;
[0014] The requesting pre - signed party extracts the adapter signature evidence based on the pre - signature, the complete signature, and the instance of the hard relation, and completes the evidence extraction when the instance generated for the adapter signature evidence is consistent with the instance of the hard relation.
[0015] In a possible implementation, the steps for the key generation center to initialize the system parameters according to the security parameters in a symmetric environment include:
[0016] The key generation center initializes the system parameters according to the security parameter λ where and are additive cyclic groups of order q, with generators and is a multiplicative cyclic group of order q, and e is a bilinear mapping satisfying e: ;
[0017] Generate a random number as the master private key and calculate the master public key through the random number;
[0018] Select the signature private key generation function identifier hid.
[0019] In a possible implementation, the steps for the key generation center to calculate the first temporary variable and the identity - based private key based on the participating party's joint identity identifier, generate the participating party's private key shards using the secret sharing technology, and generate the public - private key pair for the multiplicative - to - additive ideal function for each participating party include:
[0020] The key generation center calculates the first temporary variable α1 and the identity - based private key d using the function identifier hid ID , where the first temporary variable α1 is α1 = msk·(H1(ID||hid,q)+msk) -1 mod q, msk is the signature private key, H1(·) is a cryptographic function derived from a cryptographic hash function, mod q represents the modulo - q operation, ID is the participating party's identity identifier, q is a prime number, and the private key d II is: d ID =α1·G1;
[0021] The key generation center randomly selects t - 1 random numbers a1, a2,…, a t-1 Construct a polynomial of degree t - 1 where the coefficient a1 = α1;
[0022] The key generation center calculates the private key shard d i =f(x)·G1 for each participating party and satisfies
[0023] The key generation center generates a public-private key pair (x , Q i ) for each participant for the ideal function i , where x i ∈[n], Q i = x i ·G1, and distributes the sharded private key d i and the public-private key pair (x i , Q i ) to the corresponding participants through a secure channel.
[0024] In a possible implementation, the participant requesting the pre-signature generates a hard relation instance and a zero-knowledge proof and broadcasts them. After verification by other participants, the steps for calculating the pre-signature based on the message to be signed, the bilinear pair, and the first temporary variable include:
[0025] The participant requesting the pre-signature randomly selects the evidence y to calculate the hard relation instance Y and the zero-knowledge proof π y and broadcasts (Y, π y );
[0026] After each participant verifies (Y, π y ), it calculates the bilinear pair g and randomly selects a parameter to calculate the first temporary variable and broadcasts the first temporary variable R i and the zero-knowledge proof π y through the ideal function;
[0027] Each participant verifies the correctness of the zero-knowledge proof π y . If a participant's verification fails, it aborts. If all participants' verifications pass, it calculates the second temporary variable R and combines it with the message to be signed m to calculate the first part h = H2(m||R, q) of the pre-signature;
[0028] Each participant calculates the third temporary variable φ i and jointly executes the ideal function with the remaining participants to obtain the output;
[0029] Each participant calculates the additive fragment D i and broadcasts it to the remaining participants;
[0030] When receiving the additive fragments D i sent by all participants, each participant calculates the second part S pre = ∑ j∈[n] D j , and outputs the pre-signature value σ of the message m to be signed.pre =(h, S pre ).
[0031] In a possible implementation, the steps for the party requesting the pre-signature to verify the legality of the pre-signature by verifying the temporary variable include:
[0032] The party requesting the pre-signature calculates the verification temporary variable β = e(S pre , (H1(ID)·G2 + Q mpk ))·Y·g h and the first part h' = H2(m||β) corresponding to the verification temporary variable β, and determines whether the first part h' corresponding to the verification temporary variable β is consistent with the first part h. If they are consistent, the pre-signature value σ pre is a legal pre-signature, otherwise it is invalid.
[0033] In a possible implementation, the steps for the party requesting the pre-signature to calculate the complete signature using the pre-signature and evidence when the pre-signature is legal include:
[0034] The party requesting the pre-signature calculates the second part S = S pre + y of the complete signature according to the pre-signature value σ pre and the evidence y, and outputs the complete signature σ = (h, S).
[0035] In a possible implementation, the steps for extracting the adapter signature evidence according to the pre-signature, the complete signature, and the instance of the difficult relationship, and completing the evidence extraction when the instance of the adapter signature evidence generation is consistent with the instance of the difficult relationship include:
[0036] For a given pre-signature value σ pre and its corresponding signature value σ and the instance of the difficult relationship Y, calculate the evidence value y' = S - S pre ;
[0037] Calculate the instance Y' = e(y, H1(ID)·G2 + Q mpk ) of the adapter signature evidence generation and determine whether it is equal to Y. If they are equal, the evidence extraction is successful and the evidence value y' is output, otherwise the extraction fails.
[0038] In a second aspect, the present application proposes a multi-party adapter signature generation system for balanced SM9 digital signatures. The system includes a key generation center and multiple parties, including:
[0039] The key generation center is used to initialize the system parameters according to the security parameters in a symmetric environment. The system parameters include an elliptic curve group, a bilinear pair, a master private key, a master public key, and a function identifier;
[0040] A key generation center, which is used to calculate a first temporary variable and an identity-based private key based on the joint identity identifier of the participating parties, generate shards of the private keys of the participating parties by using secret sharing technology, and generate a public-private key pair for the multiplication-to-addition ideal function for each participating party;
[0041] The participating party requesting pre-signature, which is used to generate a hard relation instance and a zero-knowledge proof and broadcast them. After verification by other participating parties, calculate the pre-signature based on the message to be signed, the bilinear pair, and the first temporary variable;
[0042] The participating party requesting pre-signature, which is used to verify the legality of the pre-signature by verifying the temporary variable;
[0043] The participating party requesting pre-signature, which is used to calculate the complete signature by using the pre-signature and the evidence when the pre-signature is legal;
[0044] The participating party requesting pre-signature, which is used to extract adapter signature evidence according to the pre-signature, the complete signature, and the hard relation instance, and complete the evidence extraction when the instance for generating the adapter signature evidence is consistent with the hard relation instance.
[0045] The main solution of the present application and its various further alternative solutions described above can be freely combined to form multiple solutions, all of which are solutions that can be adopted and claimed by the present application; and in the present application, (each non-conflicting alternative) alternatives can be freely combined with each other and with other alternatives. Those skilled in the art can understand that there are various combinations according to the prior art and common general knowledge after understanding the solution of the present application, all of which are technical solutions to be protected by the present application, and will not be enumerated here.
[0046] The present application discloses a method and system for generating a multi-party adapter signature for a balanced SM9 digital signature. The key generation center initializes the system parameters according to security parameters in a symmetric environment, generates shards of the private keys of the participating parties by using secret sharing technology, and generates a public-private key pair for the multiplication-to-addition ideal function for each participating party. The participating party requesting pre-signature generates a hard relation instance and a zero-knowledge proof and broadcasts them. After verification by other participating parties, calculate the pre-signature, verify the legality of the pre-signature by verifying the temporary variable, calculate the complete signature when the pre-signature is legal, extract adapter signature evidence according to the pre-signature, the complete signature, and the hard relation instance, and complete the evidence extraction when the instance for generating the adapter signature evidence is consistent with the hard relation instance, and can collaboratively generate a national cryptography SM9 pre-signature with adapter function and complete the signing of the adapter signature when multiple participants jointly participate in the operation in a symmetric environment. Description of the Drawings
[0047] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and thus should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0048] Figure 1 The flowchart shows a method for generating a multi-party adapter signature of a balanced SM9 digital signature proposed in an embodiment of the present application.
[0049] Figure 2 The flowchart shows the specific implementation flowchart proposed in an embodiment of the present application. Detailed implementation manners
[0050] The following uses specific examples to illustrate the implementation manners of the present application. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0051] Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by the present application.
[0052] In the prior art, there has not been a solution that combines the SM9 algorithm with multi-party adapter signatures. How to eliminate the single-point risk through distributed key generation while retaining its identity-based characteristics based on the domestic cryptographic standard, and embed the adapter function to achieve signature conditioning has become a technical problem that urgently needs to be solved.
[0053] Therefore, to solve the above technical problems, the embodiments of the present application propose a method and system for generating a multi-party adapter signature of a balanced SM9 digital signature. Only when n participants jointly participate in the operation in a symmetric environment can the adapter signature be signed. At the same time, on the basis of the SM9 signature structure, the adapter function is added, which can further improve the domestic functional cryptographic algorithm system.
[0054] To ensure generality, the parameters selected in the embodiments of the present application are consistent with the standard parameters of the "SM9 Identity-Based Cryptographic Algorithm" specification. The specific symbol descriptions are: P1, P2,..., P n represent n participants, n≥2; q is a prime number; represents the set composed of 1, 2,..., q - 1; Denote an additive cyclic group of order q; Denote a multiplicative cyclic group of order q; G1 and G2 are respectively the generators of the elliptic curve group ; e denotes a bilinear mapping satisfying ; msk denotes the signature master private key; Q mpk Denote the signature master public key; k·P denotes the k-fold point of point P on the elliptic curve; x||y denotes the concatenation of x and y; hid denotes the signature private key generation function identifier represented by one byte; Denote the zero-knowledge proof about the discrete logarithm relationship; Denote the algorithm for generating the zero-knowledge proof about the discrete logarithm relationship; Denote the conversion algorithm for converting the multiplication result of two parties into addition in the group ; m denotes the message to be signed; H1(·) and H2(·) denote the cryptographic functions derived from the cryptographic hash function.
[0055] In addition, a multiplication protocol will be used to implement the basic cross-multiplication operation, that is, for the inputs (a1, b1) and (a2, b2) of both parties, c1 and c2 are respectively output to both parties such that c1 + c2 = a1b2 + a2b1 mod q.
[0056] Please refer to Figure 1 and Figure 2 , Figure 1 FIG. shows the flowchart of a method for generating a multi-party adapter signature of a balanced SM9 digital signature proposed in an embodiment of the present application, Figure 2 FIG. shows the specific implementation flowchart proposed in an embodiment of the present application. The key generation center is connected to multiple participants, including the following steps:
[0057] Step S1, the key generation center initializes the system parameters according to the security parameters in a symmetric environment.
[0058] The system parameters include an elliptic curve group, a bilinear pair, a master private key, a master public key, and a function identifier.
[0059] When the key generation center (KGC) initializes the system parameters according to the security parameters in a symmetric environment, it first defines the cryptographic infrastructure based on the "SM9 Identity-Based Cryptography Algorithm" specification. Specifically, it includes: generating two additive cyclic groups of prime order and a multiplicative cyclic group, selecting a bilinear mapping to ensure non-degeneracy and computability, randomly generating a master private key and calculating the master public key, and at the same time publicly disclosing the signature private key generation function identifier to standardize the key derivation process.
[0060] Step S1 includes:
[0061] The key generation center initializes the system parameters according to the security parameter λ wherein and are additive cyclic groups (elliptic curve groups) of order q, and the generators are respectively and is a multiplicative cyclic group (the output group of the bilinear pair), and e is a bilinear mapping satisfying e: ;
[0062] Generate a random number as the master private key and calculate the master public key through the random number;
[0063] Select the signature private key generation function identifier hid.
[0064] According to the "SM9 Identity-Based Cryptography Algorithm" specification, the key generation center (KGC) initializes the system parameters, inputs the security parameter λ to determine the security strength of the cryptosystem, and initializes the system parameters wherein The selection of e needs to conform to the "SM9 Identity-Based Cryptography Algorithm" standard. Randomly select the master private key (randomly selected from {1, 2,..., q - 1}), and the master private key msk must be strictly confidential and only held by the KGC. Calculate Q mpk = msk·G2 as the master public key and Q mpk needs to be publicly released for all users to verify signatures and perform encryption. Select the signature private key generation function identifier hid, where the function identifier hid is an identifier of one byte (8 bits), used to distinguish different private key generation functions, and can combine the user identity (such as email, mobile phone number) and hid to generate the user private key in the identity-based cryptosystem, ensuring the independence of keys for different purposes.
[0065] Step S2: The key generation center calculates the first temporary variable and the identity-based private key based on the joint identity identifier of the participating parties, generates the private key shards of the participating parties using the secret sharing technology, and generates the public-private key pair for the multiplicative-to-additive ideal function for each participating party.
[0066] The key generation center (KGC) calculates the first temporary variable through the hash function and the master private key based on the joint identity identifier of the participating parties and the signature private key generation function identifier, and generates the identity-based private key. This step binds the master private key to the user identity, ensuring the uniqueness and anti-attack ability of the key. Subsequently, the KGC constructs a polynomial of degree t - 1 using the secret sharing technology and generates private key shares for each participating party to achieve distributed key management and eliminate the risk of single point of failure.
[0067] To support secure computations (such as multiplication to addition) in subsequent multi-party collaborative signatures, the KGC generates a dedicated public-private key pair for each participant. This key pair is used to protect the private inputs of the participants in distributed computing and ensure that the private key shards are not exposed during the computing process. The KGC distributes the private key shards and the key pairs to the corresponding participants through a secure channel, providing secure and compliant underlying support for subsequent adapter signatures.
[0068] Step S2 includes:
[0069] The key generation center calculates the first temporary variable α1 and the identity-based private key d using the function identifier hid ID , where the first temporary variable α1 is α1 = msk·(H1(ID||hid,q) + msk) -1 mod q, msk is the signature private key, H1(·) is a cryptographic function derived from a cryptographic hash function, mod q represents modular q operation, ID is the identity identifier of the participant, q is a prime number, and the private key d ID is: d ID = α1·G1;
[0070] The key generation center randomly selects t - 1 random numbers a1, a2, …, a t-1 to construct a polynomial of degree t - 1 where the coefficient a0 = α1;
[0071] The key generation center calculates the private key shard d for each participant using the polynomial f(x) i = f(t)·G1 and satisfies
[0072] The key generation center generates a public-private key pair (x , Q i ), x i ∈[n], Q i = x i ·G1 for each participant for the ideal function i and distributes the private key shard d i and the public-private key pair (x i , Q i ) to the corresponding participants through a secure channel.
[0073] First, calculate the main temporary variable and the identity private key. The KGC generates the function identifier hid based on the combined identity identifier ID of the participant and the signature private key, and calculates the non-zero variable α1 = msk·(H1(ID||hid,q) + msk) - 1 mod q and generates the identity-based private key d ID= α1·G1. Then construct the polynomial sharded master private key. The KGC adopts a secret sharing scheme to construct a polynomial of degree t - 1 with coefficient a0 = α1, and a1…a t-1 being t - 1 random numbers. For each participant Pi, i ∈ [n], calculate its point value f(i) on the polynomial and generate a sharded private key di i = f(i)·G1. All shards satisfy i to ensure that the complete private key d can be recovered with at least t shards . Finally, generate a secure multi-party computation key pair. To support secure computations in subsequent collaborative signatures (such as multiplication to addition), the KGC generates a dedicated key pair for the ideal function for each participant: randomly select a private key and calculate the public key Q ID = x i ·G1. This key pair is used to protect the private inputs of participants in distributed computations and prevent information leakage. The KGC sends the sharded private key di i and the public-private key pair (x i , Q ), x i , Q i ), x i ∈[n], Q i = x i ·G1 for the corresponding participant Pi i through a secure channel, ensuring confidentiality and tamper-proofing during transmission.
[0074] Step S3: The participant requesting the pre-signature generates a hard relation instance and a zero-knowledge proof and broadcasts them. After other participants verify, they calculate the pre-signature based on the message to be signed, the bilinear pair, and the first temporary variable.
[0075] The participant requesting the pre-signature randomly selects a secret witness, calculates the hard relation instance through the bilinear pair, generates the corresponding zero-knowledge proof, and broadcasts it. Other participants verify the correctness of the zero-knowledge proof. If the verification passes, each participant calculates the common bilinear pair, randomly selects a parameter to generate the first temporary variable, and at the same time proves the validity of the first temporary variable through the zero-knowledge proof and calculates the pre-signature.
[0076] The steps of Step S3 include:
[0077] The participant requesting the pre-signature randomly selects a witness y to calculate the hard relation instance Y and the zero-knowledge proof π y and broadcasts (Y, π y );
[0078] Each participant verifies (Y, π y ) and then calculates the bilinear pair g and randomly selects a parameter to calculate the first temporary variable Broadcast the first temporary variable R through the ideal function i and the zero - knowledge proof π y ;
[0079] Each participant verifies the correctness of the zero - knowledge proof π y . If a participant's verification fails, the process is aborted. If all participants' verifications pass, calculate the second temporary variable R, and calculate the first part h = H2(m||R, q) of the pre - signature in combination with the message m to be signed;
[0080] Each participant calculates the third temporary variable φ i and jointly executes the ideal function with the remaining participants respectively to obtain the output;
[0081] Each participant calculates the additive fragment D i and broadcasts it to the remaining participants;
[0082] When receiving the additive fragments D sent by all participants i each participant calculates the second part S of the pre - signature pre = ∑ j∈[n] D j , and outputs the pre - signature value σ of the message m to be signed pre =(h, S pre ).
[0083] First, the requester generates a hard - relation instance. The participant P0 requesting the pre - signature randomly selects a secret witness y, calculates the hard - relation instance Y = e(y, H1(ID)·G2 + Q mpk ) through the bilinear pairing, and generates the corresponding zero - knowledge proof π y , then broadcasts (Y, π y ), where the hard - relation instance Y implies the binding relationship between the secret witness y and the system public key, ensuring that the subsequent signature validity depends on the revelation of the secret witness y. Verify the legitimacy of Y through the zero - knowledge proof π y to prevent malicious requesters from forging instances. Then each participant P i verifies the correctness of the zero - knowledge proof π y . If the verification fails, the protocol terminates; otherwise, enter the temporary variable generation stage.
[0084] Secondly, calculate the bilinear pairing and random numbers. Each participant P i calculates the public bilinear pairing = e(G1, Q mpk ), and randomly selects to generate the first temporary variable and sends (prove, R i , r i ) to the ideal function (i.e., Pi Broadcast R i and its zero - knowledge proof π ri ); When P i receives the (proof, R ) from all parties in the ideal function j , j ∈ [n]\i, each party verifies the correctness of these zero - knowledge proofs π rj . If one verification fails, abort the protocol. Otherwise, calculate the second temporary variable R = ∏ j∈[n] R j ·Y.
[0085] After that, generate the first part of the pre - signature. Calculate the first part of the pre - signature h = H2(m||R, q), binding the message m to the global random value R to generate the first part of the pre - signature h. Calculate the second part of the pre - signature: Each party P i , i ∈ [n] calculates the third temporary variable φ i =(r i - h / n) mod q, proportionally sharing the influence of its own random number r i to balance the contributions of multiple parties. Perform the secure multiplication - to - addition protocol. Each party P i and the remaining parties P j , j ∈ [n]\i execute the ideal function with inputs (d i , φ i ) and (d j , φ j ), and output the additive shares d ij and d ji (P i obtains the output d ij , P j obtains d ji ). Through multi - party secure computation (MPC), convert the multiplication operation of the private - key shard d i and the temporary variable φ i into additive sharing to avoid exposing the private - key shard. Perform the aggregation of additive fragments. Each party P i calculates the local additive fragment D i =∑ j∈[n] d ij mod q and broadcasts it. After all parties collect D j (j ∈ [n]), calculate the second part of the pre - signature S pre =∑ j∈[n] D j . Finally, output the pre - signature σ pre =(h, S pre), where the first part h of the pre-signature represents the hash result of the message m and the global random value R, ensuring that the signature is bound to the message. The second part S of the pre-signature pre is the aggregated value of the signature fragments generated for multi-party collaboration, and needs to be combined with the secret y to be converted into a complete signature later.
[0086] Step S4: The party requesting the pre-signature verifies the legality of the pre-signature through the verification temporary variable.
[0087] The party requesting the pre-signature verifies the legality of the pre-signature by calculating the verification temporary variable. The party calculates h' and compares it with h in the pre-signature. If h' = h, it indicates that the pre-signature generation process is correct and has not been tampered with, the signature is bound to the message m and the secret evidence y effectively, and the pre-signature is legal; otherwise, the pre-signature is invalid. This verification step ensures that the pre-signature meets the mathematical constraints of the SM9 algorithm and the security requirements of the adapter signature by reconstructing the randomness and hash consistency during signature generation.
[0088] Step S4 includes:
[0089] The party requesting the pre-signature calculates the verification temporary variable β = e(S pre ,(H1(ID)·G2 + Q mpk ))·Y·g h and the first part h' = H2(m||β) corresponding to the verification temporary variable β, and judges whether the first part h' corresponding to the verification temporary variable β is consistent with the first part h. If they are consistent, the pre-signature value σ pre is a legal pre-signature, otherwise it is invalid.
[0090] After receiving the pre-signature, the party requesting the pre-signature verifies its legality, calculates the verification temporary variable β = e(S pre ,(H1(ID)·G2 + Q mpk ))·Y·g h using the bilinear pair. It aggregates the signature fragment S pre , the secret binding value Y and the randomness g h for reconstructing the verification conditions consistent with the original signature generation process. Then, the first part (verification hash value) h' = H2(m||β) corresponding to the verification temporary variable β is generated, and the message m is concatenated with the temporary variable β and then hashed. Then, a consistency verification is performed to judge whether h' and h are consistent. If they are consistent, then σ pre is a legal pre-signature, otherwise, the pre-signature is invalid;
[0091] Step S5: When the pre-signature is legal, the party requesting the pre-signature calculates the complete signature using the pre-signature and the evidence.
[0092] In a multi-party collaborative signature protocol, the participating party (P0) needs to first verify the legality of the pre-signature, including verifying the integrity of the hash value h and the compliance of the identity of the generating party. If the verification passes, the pre-signature component is combined with external evidence through linear superposition to generate the final signature component and output the complete signature. This process relies on the homomorphic properties of cryptography (such as elliptic curve addition) to ensure that the synthesized signature conforms to the standard format and is not forgeable.
[0093] The steps of step S5 include:
[0094] The participating party requesting the pre-signature calculates the second part S of the complete signature according to the pre-signature value σ pre and the evidence y, and calculates S = S pre + y and outputs the complete signature σ = (h, S).
[0095] When the participating party P0 verifies the validity of the pre-signature σ pre and then receives the pre-signature value σ pre and the evidence y, calculates the second part S of the complete signature S = S pre + y, outputs the complete signature σ = (h, S), and completes the construction of the final signature by linearly combining the pre-signature component S pre with the external evidence y while keeping the original signature parameter h unchanged. This process requires that the pre-signature must pass the validity verification before the adaptation operation is allowed.
[0096] Step S6: The participating party requesting the pre-signature extracts the adapter signature evidence according to the pre-signature, the complete signature, and the instance of the hard relation, and completes the evidence extraction when the instance generated for the adapter signature evidence is consistent with the instance of the hard relation.
[0097] The participating party first calculates the difference through the pre-signature and the complete signature to generate the evidence value to be verified, and combines the instance of the hard relation to verify whether it satisfies the mathematical constraints of the instance. If the equation holds, it proves that the evidence is generated by a legitimate party and has not been tampered with, and the extraction is successful; otherwise, it indicates that there is an abnormality in the pre-signature or the complete signature, and the process terminates.
[0098] Step S6 includes:
[0099] For a given pre-signature value σ pre and its corresponding signature value σ and the instance Y of the hard relation, calculate the evidence value y' = S - S pre ;
[0100] Calculate the instance Y' = e(y, H1(ID)·G2 + Q mpk ) generated by the adapter signature evidence and determine whether it is equal to Y. If they are equal, the evidence extraction is successful and the evidence value y' is output; otherwise, the extraction fails.
[0101] Input the pre-signature σ pre, given a complete signature σ, a difficult relation instance Y, calculate the evidence value y′ = S - S pre (based on the difference of signature components), and then calculate the corresponding difficult relation instance Y′ = e(y, H1(ID)·G2 + Q mpk ) and determine whether it is equal to the difficult relation instance Y. If the verification passes, output the valid evidence y′; otherwise, determine it as illegal or tampered.
[0102] It should be noted that a method for generating a multi - party adapter signature of a balanced SM9 digital signature proposed in an embodiment of the present application is applied to a balanced environment. All participating parties (P1, P2,..., P n ) have symmetric permissions and roles, and jointly and equally participate in signature generation. There is no central node, and all steps are completed through distributed cooperation. Different from the unbalanced environment where there is a dominant party (P1, and other participants (P2,..., P n ) only provide partial computational support, and the dominant party is responsible for aggregating the results and generating the final pre - signature, forming an asymmetric structure of "leader - participant".
[0103] Compared with the prior art, the embodiments of the present application have the following beneficial effects:
[0104] First, realize multi - party adapter signature within the SM9 framework, support multiple participating parties to jointly generate pre - signatures and convert them into complete signatures through an evidence extraction and verification mechanism, strengthening the function coverage of domestic cryptographic algorithms in complex collaboration scenarios.
[0105] Second, through distributed management of key sharding, avoid single - point trust risks; combine multiplication - to - addition operations to optimize the computational load. While ensuring quantum - resistant security, significantly reduce the multi - party interaction communication overhead, and are applicable to financial - level applications with high concurrency and low latency.
[0106] Third, any user can extract difficult relation evidence from the difference between the pre - signature and the complete signature, ensuring the non - repudiation of condition triggering.
[0107] The following gives a possible implementation of a multi - party adapter signature generation system for a balanced SM9 digital signature, which is used to execute each execution step and the corresponding technical effects of the multi - party adapter signature generation method shown in the above embodiments and possible implementations.
[0108] It includes:
[0109] A key generation center, used to initialize system parameters according to security parameters in a symmetric environment, where the system parameters include an elliptic curve group, a bilinear pair, a master private key, a master public key, and a function identifier;
[0110] A key generation center, which is used to calculate a first temporary variable and an identity-based private key based on the joint identity identifier of the participating parties, generate shards of the private keys of the participating parties by using the secret sharing technology, and generate a public-private key pair for each participating party for the multiplication-to-addition ideal function;
[0111] The participating party requesting pre-signature, which is used to generate a hard relation instance and a zero-knowledge proof and broadcast them. After verification by other participating parties, calculate the pre-signature based on the message to be signed, the bilinear pair, and the first temporary variable;
[0112] The participating party requesting pre-signature, which is used to verify the legality of the pre-signature by verifying the temporary variable;
[0113] The participating party requesting pre-signature, which is used to calculate the complete signature by using the pre-signature and the evidence when the pre-signature is legal;
[0114] The participating party requesting pre-signature, which is used to extract the adapter signature evidence according to the pre-signature, the complete signature, and the hard relation instance, and complete the evidence extraction when the instance in which the adapter signature evidence is generated is consistent with the hard relation instance.
[0115] In summary, the present application discloses a method and system for generating a multi-party adapter signature for balanced SM9 digital signature. The key generation center initializes the system parameters according to the security parameters in a symmetric environment, generates shards of the private keys of the participating parties by using the secret sharing technology, and generates a public-private key pair for each participating party for the multiplication-to-addition ideal function. The participating party requesting pre-signature generates a hard relation instance and a zero-knowledge proof and broadcasts them. After verification by other participating parties, calculate the pre-signature, verify the legality of the pre-signature by verifying the temporary variable, calculate the complete signature when the pre-signature is legal, extract the adapter signature evidence according to the pre-signature, the complete signature, and the hard relation instance, and complete the evidence extraction when the instance in which the adapter signature evidence is generated is consistent with the hard relation instance. It can collaboratively generate a national cipher SM9 pre-signature with adapter function and complete the signing of the adapter signature when multiple participants jointly participate in the operation in a symmetric environment.
[0116] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for generating a multi-party adapter signature of a balanced SM9 digital signature, characterized in that: The key generation center is connected to a plurality of participants, and the method includes: The key generation center initializes system parameters according to security parameters in a symmetric environment, wherein the system parameters include an elliptic curve group, a bilinear pairing, a master private key, a master public key, and a function identifier; The key generation center calculates the first temporary variable and the identity-based private key based on the joint identity identifier of the participant, generates the private key shards of the participant by using the secret sharing technology, and generates a public-private key pair for each participant for the ideal function of multiplication-to-addition; The party requesting the pre-signature generates a difficult relation instance and a zero-knowledge proof and broadcasts them. After verification by other parties, the pre-signature is calculated based on the message to be signed, the bilinear pairing and the first temporary variable. The party requesting the pre-signature verifies the legitimacy of the pre-signature by verifying the temporary variable; The party requesting the pre-signature calculates the full signature using the pre-signature and evidence if the pre-signature is legitimate; The party requesting the pre-signature extracts the adapter signature evidence based on the pre-signature, the complete signature and the difficult relationship instance, and completes the evidence extraction when the instance generated by the adapter signature evidence is consistent with the difficult relationship instance.
2. The method for generating a multi-party adapter signature according to claim 1, wherein: The steps of initializing system parameters according to security parameters in a symmetric environment by the key generation center include: The key generation center initializes the system parameters according to the security parameter λ in and is an additive cyclic group of order q, with generators and is a multiplicative cyclic group of order q, and e satisfies Bilinear mapping of ; Generate a random number as the master private key and calculate the master public key from the random number; Select the signature private key generation function identifier hid.
3. The multi-party adapter signature generation method according to claim 2, characterized in that: The key generation center calculates the first temporary variable and the identity-based private key based on the joint identity identifier of the participant, generates the participant's private key shards by using the secret sharing technology, and generates a public-private key pair for each participant for the multiplication-to-addition ideal function, including: The key generation center uses the function identifier hid to calculate the first temporary variable α1 and the identity-based private key d ID , where the first temporary variable α1 is α1=msk·(H1(ID||hid,q)+msk) -1 mod q, msk is the signature private key, H1(·) is the cryptographic function derived from the cryptographic hash function, mod q represents the modulo q operation, ID is the identifier of the participant, q is a prime number, and the private key d ID For: ID =α1·G1; The key generation center randomly selects t-1 random numbers a1, a2, …, a t-1 Construct t-1 order polynomial The coefficient a0 = α1; The key generation center uses the polynomial f(x) to calculate the private key shard d of each participant. i =f(x)·G1 and satisfies The key generation center generates the ideal function for each participant The public and private key pair (x i ,Q i ),x i ∈[n],Q i =x i G1, and divide the private key into shards d i and the public-private key pair (x i ,Q i ) is distributed to the corresponding participants through a secure channel.
4. The method for generating a multi-party adapter signature according to claim 3, wherein: The participant requesting the pre-signature generates a difficult relation instance and a zero-knowledge proof and broadcasts them. After verification by other participants, the steps of calculating the pre-signature based on the message to be signed, the bilinear pairing and the first temporary variable include: The party requesting the pre-signature randomly selects evidence y to compute the difficult relation instance Y and the zero-knowledge proof π y And broadcast (Y,π y ); Each participant verifies (Y,π y ) and then calculate the bilinear pairing g and randomly select parameters Calculate the first temporary variable Broadcast the first temporary variable R through the ideal function i And zero-knowledge proof π y ; Each participant verifies the zero-knowledge proof π y If one party fails the verification, the process is terminated. If all parties pass the verification, the second temporary variable R is calculated, and the first part of the pre-signature h=H2(m||R,q) is calculated in combination with the message to be signed m. Each participant calculates the third temporary variable φ i And execute the ideal function together with other participants Get the output; Each participant calculates the addition fragment D based on the output i And broadcast to other participants; When receiving the addition fragments D sent by all participants i After that, each participant calculates the second part S of the pre-signature pre =∑ j∈[n] D j , and output the pre-signature value σ of the message m to be signed pre =(h,S pre ).
5. The method for generating a multi-party adapter signature according to claim 4, wherein: The steps for the party requesting the pre-signature to verify the legitimacy of the pre-signature by verifying the temporary variable include: The party requesting the pre-signature calculates and verifies the temporary variable β = e(S pre ,(H1(ID)·G2+Q mpk ))·Y·g h And the first part h′ corresponding to the verification temporary variable β = H2(m||β), determine whether the first part h′ corresponding to the verification temporary variable β is consistent with the first part h, if they are consistent, the pre-signature value σ pre It must be a legal pre-signature, otherwise it is invalid.
6. The method for generating a multi-party adapter signature according to claim 5, wherein: The steps for the party requesting the pre-signature to calculate the complete signature using the pre-signature and evidence if the pre-signature is legal include: The party requesting the pre-signature pre and evidence y, calculate the second part of the complete signature S = S pre +y and output the complete signature σ=(h,S).
7. The method for generating a multi-party adapter signature according to claim 1, wherein: Extracting adapter signature evidence based on the pre-signature, the full signature, and the difficult relationship instance, and completing the steps of evidence extraction when the instance generated by the adapter signature evidence is consistent with the difficult relationship instance, including: For a given pre-signed value σ pre and its corresponding signature value σ and difficult relation instance Y, calculate the evidence value y′=SS pre ; Compute an instance of adapter signature evidence generation Y′=e(y,H1(ID)·G2+Q mpk ) and judge whether it is equal to Y. If they are equal, the evidence extraction is successful and the evidence value y′ is output, otherwise the extraction fails.
8. A balanced SM9 digital signature multi-party adapter signature generation system, characterized in that: The system includes a key generation center and multiple participants, including: A key generation center, used to initialize system parameters according to security parameters in a symmetric environment, wherein the system parameters include an elliptic curve group, a bilinear pairing, a master private key, a master public key, and a function identifier; A key generation center, used to calculate a first temporary variable and an identity-based private key based on a joint identity identifier of the participant, generate a shard of the participant's private key using a secret sharing technique, and generate a public-private key pair for an ideal multiplication-to-addition function for each participant; The party requesting the pre-signature generates and broadcasts a difficult relation instance and a zero-knowledge proof. After verification by other parties, the pre-signature is calculated based on the message to be signed, the bilinear pairing, and the first temporary variable. The party requesting the pre-signature verifies the legitimacy of the pre-signature by verifying the temporary variable; The party requesting the pre-signature uses the pre-signature and evidence to calculate the full signature if the pre-signature is legal; The party requesting the pre-signature is used to extract the adapter signature evidence based on the pre-signature, the full signature and the difficult relationship instance, and complete the evidence extraction when the instance generated by the adapter signature evidence is consistent with the difficult relationship instance.
Citation Information
Cited By
Electronic seal management and control method and system
CN120528598A
Electronic seal management method and system
CN120528598B