Digital signature method based on QC-MDPC and pad filling
Through the digital signature method based on QC-MDPC and pad pad filling, the problems of long public key length, high encryption and decryption complexity and insufficient security in the prior art are solved, and signature generation with small public key storage, fast encryption and decryption are achieved, which is suitable for cryptography research that resists quantum attacks.
Patent Information
- Application Number
- CN202510555046.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-07-01
AI Technical Summary
The existing digital signature methods have problems such as long public key length, high encryption and decryption complexity, low efficiency in terms of quantum attack resistance, and insufficient security.
The digital signature method based on QC-MDPC and pad padding is adopted, and the private key is designed using parity check matrix, inverse permutation matrix, scrambling matrix and hash function. The signature is generated through hash operation, random length selection and pad padding. The public key is HQ-1, and the verifier uses the public key to verify the signature.
It realizes digital signatures with small public key storage, low encryption and decryption complexity, high security and fast speed, and is suitable for cryptographic research that resists quantum attacks.
Smart Images

Figure CN120238317A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of digital signatures, and in particular to a digital signature method based on QC-MDPC and pad filling. Background Art
[0002] Digital signature technology has been widely applied in many key fields due to its authenticity, integrity, and non-repudiation.
[0003] The application fields include: information security and network communication, email security, finance and payment systems, e-government and legal documents, etc.
[0004] Yin Hualei et al. proposed a quantum digital signature based on quantum physics, allowing users to sign large documents using secret sharing, one-time pads, and one-time universal hash functions, but the disadvantage is high cost; improving CFS based on the (UU+V) code has the advantages of shorter signature length and faster verification speed; however, the public key length is longer, and the efficiency of signature and key generation is lower; the CFS algorithm based on the modified RM code, but due to certain problems in the signature probability distribution, the security of its algorithm has caused controversy.
[0005] There is also the design of CFS based on GRS codes, adopting the BBCRS method in public key hiding; because GRS codes have the property of permutation equivalence, so in the design, only by sacrificing the decoding space can its security be guaranteed.
[0006] In addition, at the level of security research, mCFS is proposed, replacing the counter with uniformly distributed random values as the input of the hash function, thus improving the security; however, the defects of large public key size and low signature efficiency still exist; Parallel-CFS can generate multiple signatures in parallel and can use smaller security parameters to achieve the standard security level; however, the cost is an increase in signature length and lower efficiency. Summary of the Invention
[0007] Aiming at the deficiencies of the existing methods, the present invention has the characteristics of small public key storage, low encryption and decryption complexity, high security, and fast speed, and has important significance in the field of cryptography research against quantum attacks.
[0008] The technical solution adopted by the present invention is: the digital signature method based on QC-MDPC and pad filling includes the following steps:
[0009] Step 1: Obtain the object to be digitally signed;
[0010] As a preferred embodiment of the present invention, the digital signature object includes: message, image.
[0011] Step 2: Use QC-MDPC as the private key encoding, and design the private key by using a parity-check matrix, an invertible permutation matrix, a scrambling matrix, and a hash function;
[0012] As a preferred embodiment of the present invention, Step 2 specifically includes:
[0013] Construct an r×n order parity-check matrix H;
[0014] Construct an r×r order scrambling matrix S;
[0015] Randomly generate an n×n order invertible permutation matrix Q;
[0016] Select the SHA-512 hash function h;
[0017] Select the BF decoding γ as the QC-MDPC decoding algorithm;
[0018] Construct the private key as: S, H, Q, γ.
[0019] Step 3: Design the public key by using a parity-check matrix and an invertible permutation matrix;
[0020] As a preferred embodiment of the present invention, the public key is pub = HQ -1 .
[0021] Step 4: Perform a hash operation on the digital signature object to obtain a message sequence; randomly select the length of the message sequence, then multiply the randomly selected message sequence by the scrambling matrix to obtain a message digest; then perform pad filling on the message digest until the BF decoding condition is satisfied, complete the construction of the digital signature, and send the signature to the verifier;
[0022] As a preferred embodiment of the present invention, the conditions for satisfying the BF decoding γ and the digital signature are: pubv T = A T , assign the decoded value of x i to v, x i = pad(A), v = γ(xi), let f = v T , where A is the message digest, and x i is the value after the i-th pad filling of the message digest A.
[0023] As a preferred embodiment of the present invention, the BF decoding includes:
[0024] Step 441: Assume that the received word is c = (c0, c1,..., c n-1 );
[0025] Step 442: Let S = mod(Hc T , 2), if S results in an all-zero vector, directly output c;
[0026] Step 443: If the vector S obtained is not an all-zero vector, calculate F = S T H, and find the largest vector component f i ;
[0027] Step 444: Flip the bit at the i-th position in c to obtain c';
[0028] Step 445: Calculate S = mod(Hc' T , 2) again. If the obtained S is an all-zero vector, the decoding is successful and c' is output; if it is not an all-zero vector, determine whether the maximum number of iterations N is reached. If not, repeat Step 443; otherwise, the decoding fails.
[0029] As a preferred embodiment of the present invention, the pad filling randomly generates k bit positions and randomly inserts them into the message digest A, where k = n - r.
[0030] Step Five: The verifier verifies the signature using the message sequence and the public key;
[0031] As a preferred embodiment of the present invention, when the signature verification is successful, A = B; where A = transformedhash and B = mod(pubf, 2).
[0032] As a preferred embodiment of the present invention, the digital signature system based on QC-MDPC and pad filling includes: a memory for storing instructions executable by a processor; and a processor for executing the instructions to implement the digital signature method based on QC-MDPC and pad filling.
[0033] As a preferred embodiment of the present invention, a computer-readable medium storing computer program code, where the computer program code implements the digital signature method based on QC-MDPC and pad filling when executed by a processor.
[0034] Advantages of the present invention:
[0035] The present invention is a post-quantum digital signature scheme based on QC-MDPC in quasi-cyclic. It uses QC-MDP codes, hash functions combined with BF decoding, and converts the bit sequence length through pad filling to execute the decoding algorithm and accelerate signature generation. It has the characteristics of small public key storage, fast speed, low encryption and decryption complexity, and high security, and is of great significance in the field of cryptography research against quantum attacks. Description of the Drawings
[0036] Figure 1 is the flowchart of the digital signature method based on QC-MDPC and pad filling of the present invention;
[0037] Figure 2 is the BF decoding flow chart of the present invention;
[0038] Figure 3 is the change of the BF decoding failure rate and success rate of the present invention with the r value. Specific embodiments
[0039] The present invention will be further described below in conjunction with the accompanying drawings and embodiments. This figure is a simplified schematic diagram, which only illustrates the basic structure of the present invention in a schematic manner. Therefore, it only shows the components related to the present invention.
[0040] As Figure 1 shown, a digital signature method based on QC-MDPC and pad filling includes the following steps:
[0041] Step 1: Obtain the object to be digitally signed;
[0042] The object M to be digitally signed includes: messages, images, etc. in the fields of information security and network communication, email security, finance and payment systems, e-government and legal documents, etc.;
[0043] For example, an email message: Message = "abc123";
[0044] Step 2: Perform parameter selection and key generation based on QC-MDPC (Quasi-Cyclic Moderate-Density Parity-Check);
[0045] Step 2 specifically includes:
[0046] Step 21: For a QC-MDPC with given parameters n, r, and w, if there exists an integer p such that n = n0×p and r = p, then the parity check matrix where H is composed of p×p sized cyclic blocks;
[0047] Select a random vector of length n and weight w as the starting row, and cyclically shift the starting row r - 1 times, that is, p - 1 times to obtain the remaining r - 1 rows; where w is the row weight of each H cyclic block, and n0, p, n, and r are integers;
[0048] That is, construct a parity check matrix H of order r×n;
[0049] Step 22: Select a scrambling matrix S of order r×r, select a randomly generated invertible permutation matrix Q of order n×n, select a SHA-512 secure hash function h, and select the BF decoding algorithm γ as the decoding algorithm for QC-MDPC encoding;
[0050] The constructed private key is: S, H, Q, γ;
[0051] Step 3: Design the public key using the parity-check matrix and the invertible permutation matrix;
[0052] Let the private key be S, H, Q, γ and keep it unpublished, and the public key be pub = HQ -1 , h and make it public;
[0053] Step 4: First, perform a hash operation on the digital signature object M to obtain the message digest a. Randomly select a message sequence b with a set length of r from the message digest a, then multiply b by the scrambling matrix S in the private key to obtain the message sequence A. Then, perform pad filling on A until the decoding condition and the signature condition are satisfied, and construct the digital signature algorithm v;
[0054] The randomly selected message sequence b with a set length of r can be consecutive bits or non-consecutive bits;
[0055] For example, from a = h(M) = 11000111000101101011101110…, the consecutive bits b = [0 1 0 1] are obtained; the non-consecutive bits b = [1 0 0 0];
[0056] Step 4 specifically includes:
[0057] Step 41: Use the hash function SHA-512 to calculate the digital signature object to obtain the message digest h(M) and assign it to a;
[0058] Step 42: Randomly select a message sequence b with a length of r from a, and right-multiply b by the matrix S to obtain the message digest A;
[0059] Step 43: Perform pad filling on A until the length of A is a message sequence x of n i ;
[0060] That is, perform the first filling on A and assign it to x1, the second filling and assign it to x2, until the filled x i value satisfies the decoding condition;
[0061] Step 44: When x i satisfies the BF decoding γ condition and the digital signature condition, that is, satisfies pubv T = A T ; Assign the decoded value of x i to v, x i = pad(A), v = γ(x i ), let f = v T , and send f to the verifier;
[0062] As Figure 2 shown, BF decoding, that is, v = γ(xi ) The process includes:
[0063] Step 441: Assume the received word is c = (c0, c1,..., c n-1 ), H is the parity check matrix, and N is the maximum number of iterations;
[0064] Step 442: Input c, and let S = mod(Hc T , 2). If S results in an all-zero vector, directly output c;
[0065] Step 443: If S does not result in an all-zero vector, calculate F = S T H, without performing modulo-2 operation, obtain the number of each symbol in F that does not satisfy the parity check matrix, and find the maximum vector component f i ;
[0066] Step 444: Flip the bit at the i-th position in c to obtain c';
[0067] Step 445: Calculate S = mod(Hc' T , 2) again. If the resulting S is an all-zero vector, the decoding is successful and output c'; if it is not an all-zero vector, determine whether the maximum number of iterations N has been reached. If not, repeat step 443; otherwise, the decoding fails;
[0068] When the digital signature object M is not public, {M, f, A} are transmitted to the verifier together; when the digital signature object M is public, {f, A} are transmitted to the verifier together;
[0069] Among them, pad fills randomly with k bits and inserts them randomly into the message digest A, where k = n - r;
[0070] Preferably for pad filling, when k = 3, the corresponding six filling methods include:
[0071] First, select a random position to insert the information bit 01, and then select another random position to insert the information bit 0;
[0072] Second, select a random position to insert the information bit 01, and then select another random position to insert the information bit 1;
[0073] Third, select a random position to insert the information bit 10, and then select another random position to insert the information bit 0;
[0074] Fourth, select a random position to insert the information bit 10, and then select another random position to insert the information bit 1;
[0075] Fifth, randomly select positions to insert information bits 00, and then randomly select another position to insert information bit 1;
[0076] Sixth, randomly select positions to insert information bits 11, and then randomly select another position to insert information bit 0;
[0077] Preferably, for pad filling, when k = 4, the corresponding six filling methods include:
[0078] First, randomly select a position to insert information bit 1, then randomly select another position to insert information bits 11, and finally randomly select a position to insert information bit 0;
[0079] Second, randomly select a position to insert information bit 0, then randomly select another position to insert information bits 00, and finally randomly select a position to insert information bit 1;
[0080] Third, randomly select a position to insert information bit 1, then randomly select another position to insert information bits 01, and finally randomly select a position to insert information bit 0;
[0081] Fourth, randomly select a position to insert information bit 0, then randomly select another position to insert information bits 10, and finally randomly select a position to insert information bit 1;
[0082] Fifth, randomly select a position to insert information bit 1, then randomly select another position to insert information bits 11, and finally randomly select a position to insert information bit 1;
[0083] Sixth, randomly select a position to insert information bit 0, then randomly select another position to insert information bits 00, and finally randomly select a position to insert information bit 0.
[0084] Step Five: Signature verification stage;
[0085] Step 51: The verifier accepts the signature f and the message digest A, and calculates the values of A and B:
[0086] A = transformed hash
[0087] B = mod(pubf, 2)
[0088] Step 52: If A = B, the verification is successful; otherwise, the verification fails.
[0089] Specific example:
[0090] Parameter selection and key generation:
[0091] Select n = 8, r = 4, w = 3;
[0092] For the convenience of calculation and to clarify the logic of the entire process, simply set the parity-check matrix H, substitution matrix Q, scrambling matrix S, and public key pub as follows:
[0093]
[0094] Signature process:
[0095] E-mail message: Message = "abc123";
[0096] Through the hash function SHA-512 and converting the hash value into binary message bits, we get a = h(M) = 11000111000101101011101110…;
[0097] Select any shorter message bits with a length of r = 4, and let b = [0 1 0 1];
[0098] Right-multiply b by S to get the message digest A = bS = [0 1 1 0];
[0099] Taking k = 4 as an example, the padding technique is as follows:
[0100] Through the first type of pad filling, we get:
[0101] x1 = [0 1 1 1 1 1 0 0];
[0102] Through the BF decoding algorithm for x1, that is, the γ algorithm, we get
[0103] v = γ(x1) = [0 1 0 1 1 1 0 0];
[0104] Among them, Hv T = [0 0 0 0] T , pubv T = [1 0 0 1] T ≠A. According to the algorithm conditions, it can be seen that the decoding condition is satisfied, but the signature condition is not satisfied.
[0105] Through the second type of pad filling, we get:
[0106] x2 = [0 1 1 1 1 1 1 0];
[0107] Through the BF decoding algorithm for x2, that is, the γ algorithm, we get:
[0108] v = γ(x2) = [0 1 0 0 1 1 1 0].
[0109] Among them, Hv T =
[1010] T , pubvT =
[1010] T ≠A. According to the algorithm conditions, it can be seen that neither the decoding condition nor the signature condition is satisfied.
[0110] Obtained through the third type of pad filling:
[0111] x3 = [0 1 0 0 0 1 0 0];
[0112] By performing the BF decoding algorithm on x3, that is, the γ algorithm, we get:
[0113] v = γ(x3) = [1 1 1 0 0 1 0 0];
[0114] Among them, Hv T =[0 0 0 0] T , pubv T =[1 0 1 1] T ≠A. According to the algorithm conditions, it can be seen that the decoding condition is satisfied, but the signature condition is not satisfied.
[0115] Obtained through the fourth filling technique:
[0116] x4 = [0 1 0 0 0 1 1 0];
[0117] By performing the BF decoding algorithm on x4, that is, the γ algorithm, we get:
[0118] v = γ(x4) = [1 0 0 1 0 1 1 0];
[0119] Among them, Hv T =[0 0 0 0] T , pubv T =[0 1 1 0] T =A. According to the algorithm conditions, it can be seen that not only the decoding condition is satisfied, but also the signature condition is satisfied.
[0120] Then the signature is represented as f = v T =[1 0 0 1 0 1 1 0], and f is sent to the verifier.
[0121] Verification process:
[0122] The verifier accepts f and left-multiplies it by the public key pub to get B = mod(pubf, 2) = [0 1 1 0], which is equal to A, indicating that the signature verification is successful.
[0123] Experimental analysis:
[0124] Security analysis of the accelerated digital signature algorithm based on QC-MDPC and specific padding:
[0125] The present invention randomly selects a shorter transformed hash value b from the output of the hash function. It should be noted that this random selection process ensures that each generated transformed hash value is different, and this characteristic significantly increases the complexity of the random number sequence required for an attacker to identify the specific hash value used for signature generation. The hash value undergoes a transformation process of right-multiplying the scrambling matrix S and assigning it to A, that is, A = Sb. Therefore, the primary problem currently faced by the attacker is to identify the correct scrambling matrix in order to forge a signature.
[0126] Even if the attacker can successfully determine the correct scrambling matrix, they still need to overcome another major challenge, that is, to identify a message sequence of length n that is both correct and meets the decoding conditions. To achieve this goal, the attacker needs to try at least different sequences, and this process is extremely time-consuming and resource-intensive.
[0127] Efficiency analysis of the accelerated digital signature algorithm based on QC-MDPC and specific padding:
[0128] When n0 = 4 and the security level is 256, the key amount based on QC-MDPC is approximately 94 times lower than that of Goppa, greatly reducing the key amount and improving practicality. Compared with the CFS digital signature algorithm based on Goppa code, CFS requires at least 1 + t! hash attempts and t! decoding attempts, while the present invention only requires 1 hash attempt and at most 6 decoding attempts, greatly improving the encoding and decoding efficiency and saving a large amount of time and cost.
[0129] As shown in the appendix Figure 3 The decoding success rate of BF of the present invention is getting higher and higher as r increases.
[0130] Table 1 Comparison of digital signature methods
[0131] Signature scheme Encoding Hash attempt Decoding attempt CFS Goppa code 1+t! t! The algorithm in this paper QC-MDPC code 1 6
[0132] As shown in Table 1, the signature method of the present invention is superior to the traditional CFS signature method in both hash attempts and encoding attempts. In the traditional CFS signature scheme, for a Goppa code with given parameters n and k, satisfying n = 2 m , k = n - mt, the number of syndromes that can be decoded The total number of syndromes is N t = 2 n-k = 2 mt = n t The probability of randomly obtaining a decodable one That is, the success probability of the CFS digital signature algorithm is For example, when t = 10, on average, 10! = 3,628,800 attempts are required to obtain a signature. The computational complexity is not only high but also requires a large amount of computing resources.
[0133] Analysis of the signature length and public key amount of the accelerated digital signature algorithm based on QC-MDPC and specific padding:
[0134] Under the QC-MDPC quasi-cyclic structure of the present invention, the structure of the public key is very compact, and the complete structure can be restored through one row or one column. The length of the public key is (n - r) bits. As shown in Table 2, through comprehensive security analysis, the present invention provides recommended security parameters, including three different security levels k = 80, 128, and 256.
[0135] Table 2 Selection of recommended security parameters
[0136] Security level <![CDATA[n0]]> n r w t 80 2 9600 4800 90 84 128 2 19712 9856 142 134 256 2 65536 32768 274 264
[0137] Table 3 Comparison of public key amounts
[0138] Security level CFS / bits The algorithm in this paper / bits 80 167772160 4800 128 4194304000 9856 256 16777216000 32768
[0139] As shown in Table 3, when the CFS scheme is under the recommended parameters of the optimal implementation Parallel-CFS and compared with the public key size of the present invention, the public key amount of the present invention is much less than that of CFS.
[0140] Inspired by the ideal embodiments of the present invention described above, through the above description, relevant staff can make various changes and modifications completely within the scope of not departing from the technical idea of the present invention. The technical scope of the present invention is not limited to the content in the specification, and its technical scope must be determined according to the scope of the claims.
Claims
1. A digital signature method based on QC-MDPC and pad filling, characterized in that: The following steps are involved: Step 1: Get the object to be digitally signed; Step 2: Use QC-MDPC as the private key encoding, and use the parity check matrix, reversible permutation matrix, scrambling matrix and hash function to design the private key; Step 3: Design a public key using a parity check matrix and a reversible permutation matrix; Step 4: Perform a hash operation on the digital signature object to obtain a message digest; The message digest is randomly length-selected, and then the randomly selected message digest is multiplied by the scrambling matrix to obtain a message sequence. The message sequence is then padded until the BF decoding condition and the signature condition are met. The digital signature construction is completed and the signature is sent to the verifier. Step 5: The verifier uses the message sequence and public key to verify the signature.
2. The digital signature method based on QC-MDPC and pad filling according to claim 1 is characterized in that: Step 2 specifically includes: Construct an r×n order parity check matrix H; Construct an r×r order disturbance matrix S; Randomly generate an n×n order reversible permutation matrix Q; Select the SHA-512 hash function h; Select BF decoding γ as the QC-MDPC decoding algorithm; The private key is constructed as: S, H, Q, γ.
3. The digital signature method based on QC-MDPC and pad filling according to claim 1 is characterized in that: The BF decoding γ condition and digital signature condition are: pubv T =A T , x i The decoded value is assigned to v, x i = pad(A), v = γ(x i ), let f = v T , where A is the message digest, x i is the value after padding the message digest A for the i-th time.
4. The digital signature method based on QC-MDPC and pad filling according to claim 3 is characterized in that: BF decoding includes: Step 441: Assume that the received word is c=(c0, c1, ..., c n-1 ); Step 442: Let S = mod (Hc T ,2),If S is an all-zero vector, directly output c; Step 443: If S does not produce a zero vector, calculate F = S T H, find the largest vector component f i ; Step 444, flip the bit at the i-th position in c to obtain c′; Step 445, calculate S=mod(Hc′) again T , 2), if the obtained S is an all-zero vector, the decoding is successful and c′ is output; if it is not an all-zero vector, determine whether the maximum number of iterations N has been reached. If not, repeat step 443, otherwise the decoding fails.
5. The digital signature method based on QC-MDPC and pad filling according to claim 1 is characterized in that: Pad filling is to randomly generate k bits and randomly insert them into the message digest A, where k = nr.
6. The digital signature method based on QC-MDPC and pad filling according to claim 1 is characterized in that: When the signature verification succeeds, A=B, where A=transformed hash and B=mod(pubf,2).
7. The digital signature method based on QC-MDPC and pad filling according to claim 1 is characterized in that: Digital signature objects include: messages and images.
8. The digital signature method based on QC-MDPC and pad filling according to claim 1 is characterized in that: The public key is pub=HQ -1 .
9. The digital signature system based on QC-MDPC and pad filling is characterized by: include: a memory for storing instructions executable by a processor; A processor, configured to execute instructions to implement a digital signature method based on QC-MDPC and pad filling as described in any one of claims 1 to 8.
10. A computer readable medium storing computer program code, characterized in that: When the computer program code is executed by a processor, the digital signature method based on QC-MDPC and pad filling as described in any one of claims 1 to 8 is implemented.