Digital signature method, electronic equipment and non-transitory machine readable storage medium
Through the method of synergistically generating digital signature key pairs between the two parties, the problem of private keys being easily stolen is solved, and high-security digital signatures in the quantum computing environment are realized, and the cost of transformation is low in existing systems is compatible.
Patent Information
- Application Number
- CN202510735328.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-06-03
AI Technical Summary
In the existing digital signature scheme in post-quantum cryptography, the private key is stored on the sender's device and is easily stolen by the attacker, resulting in low security and inability to withstand the attacks of quantum computers.
The method of two parties co-generating digital signature key pairs is adopted. The private keys are privately stored by two devices respectively. Co-signature is achieved through the grid-based rejection LWE assumption to ensure that the private key is not leaked, and the signature cannot be forged if any party's private key is stolen, and the signature can be verified through the ML-DSA verification algorithm.
It improves the security of digital signatures, resists quantum computer attacks, is compatible with existing signature systems to make the transformation cost low, ensuring that the private key is not leaked, and that any private key is stolen and cannot forge the signature.
Smart Images

Figure CN120263412A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cryptography technology, and in particular, to a digital signature method, an electronic device, and a non-transitory machine-readable storage medium. Background Art
[0002] Post-Quantum Cryptography (PQC), also known as quantum-resistant cryptography, is a field of cryptography designed to withstand attacks based on quantum computers. With the development of quantum computing technology, digital signature schemes in post-quantum cryptography have been applied in various application scenarios.
[0003] In digital signature schemes in post-quantum cryptography, such as Module Lattice-Based Digital Signature (ML-DSA), the private key in the key pair is usually stored by the sending device of the message. When the sending device needs to sign a message, it signs the message with the private key it stores. The sending device sends the message and the signature to the receiving device of the message. The receiving device can obtain the public key in the key pair and verify the signature and the message with the public key.
[0004] However, since the private key is stored in the sending device, once the sending device is attacked, the private key in the digital signature key pair may be leaked. An attacker can use the private key to forge the digital signature of the sending device, resulting in low security. Summary of the Invention
[0005] Embodiments of this application provide a digital signature method, an electronic device, and a non-transitory machine-readable storage medium to improve the convenience of prompt input.
[0006] In a first aspect, an embodiment of this application provides a digital signature method, which is applied to a first device. The first device and a second device cooperate to generate a digital signature key pair, where the digital signature key pair includes a public key, a first private key, and a second private key. Among them, the first device stores the first private key; the second device stores the second private key; the first private key contains a first matrix, and the second private key contains the first matrix; the method includes: Generate a first random vector and a second random vector; According to the first matrix, the first random vector, and the second random vector, obtain a first variable value, and send the first variable value to the second device; Receive a second variable value sent by the second device, where the second variable value is obtained by the second device according to the first matrix, a third random vector, and a fourth random vector; Generate a first signature value according to the first random vector, the first variable value, the second variable value, the message, and the first private key; Receive a second signature value sent by the second device, where the second signature value is generated by the second device according to the third random vector, the first variable value, the second variable value, the message, and the second private key; Generate a target signature corresponding to the message according to the first signature value, the second signature value, the public key, and the first matrix.
[0007] In one embodiment, the obtaining the first variable value according to the first matrix, the first random vector, and the second random vector includes: Obtain a first product value between the first matrix and the first random vector; Obtain the sum of the first product value and the second random vector to obtain the first variable value; Correspondingly, the second variable value is obtained by the second device by obtaining a second product value between the first matrix and the third random vector and obtaining the sum of the second product value and the fourth random vector.
[0008] In one embodiment, the public key includes a private key component; the generating the first signature value according to the first random vector, the first variable value, the second variable value, the message, and the first private key includes: Generate a first signature factor according to the first variable value, the second variable value, and the message; Generate a first signature value according to the first random vector, the first signature factor, and the first private key; The generating the target signature corresponding to the message according to the first signature value, the second signature value, the public key, and the first matrix includes: Obtain the sum of the first signature value and the second signature value to obtain a second signature factor; Generate a third signature factor according to the first signature factor, the second signature factor, the private key component, and the first matrix; The target signature is composed of the first signature factor, the second signature factor, and the third signature factor.
[0009] In one embodiment, the generating the first signature factor according to the first variable value, the second variable value, and the message includes: Obtain a total variable value according to the first variable value and the second variable value; Perform a hash process on the message and the total variable value to obtain the first signature factor.
[0010] In one embodiment, the method further includes: Generating a first random matrix, a fifth random vector, and a sixth random vector; Sending the first random matrix and the first hash value to the second device; Receiving a second random matrix and a second hash value sent by the second device, where the second hash value is obtained by the second device through hashing the second random matrix; Verifying the second random matrix based on the first hash value. If the verification passes, performing a synthesis process on the first random matrix and the second random matrix to obtain a first matrix; Obtaining a first sum value according to the first matrix, the fifth random vector, and the sixth random vector; Sending the first sum value and a third hash value to the second device, where the third hash value is obtained by hashing the first sum value, so that the second device verifies the first sum value according to the third hash value. If the verification passes, the second private key is composed of the first matrix, a second sum value, a generated seventh random vector, and an eighth random vector; the second sum value is obtained according to the first matrix, the seventh random vector, and the eighth random vector; The first private key is composed of the first matrix, the first sum value, the fifth random vector, and the sixth random vector.
[0011] In one embodiment, the generating a first signature value according to the first random vector, the first signature factor, and the first private key includes: Performing a sampling process on the first signature factor to obtain a sampled first signature factor; Obtaining a third product value of the sampled first signature factor and the fifth random vector; Obtaining a sum of the third product value and the first random vector to obtain a first signature value; Correspondingly, the second signature value is obtained by the second device performing a sampling process on the first signature factor to obtain a sampled first signature factor; obtaining a fourth product value of the sampled first signature factor and the seventh random vector; and obtaining a sum of the fourth product value and the first random vector.
[0012] In a second aspect, an embodiment of the present application provides a digital signature method applied to a second device. The second device and a first device cooperate to generate a digital signature key pair, where the digital signature key pair includes a public key, a first private key, and a second private key. Among them, the first device stores the first private key; the second device stores the second private key; the first private key includes a first matrix, and the second private key includes the first matrix; the method includes: Receive a first variable value sent by the first device, where the first variable value is obtained by the first device based on the first matrix, the first random vector, and the second random vector; Generate a third random vector and a fourth random vector; Obtain a second variable value according to the first matrix, the third random vector, and the fourth random vector; Send the second variable value to the first device; Receive a first signature value sent by the first device, where the first signature value is generated by the first device based on the first random vector, the first variable value, the second variable value, the message, and the first private key; Generate a second signature value according to the third random vector, the first variable value, the second variable value, the message, and the second private key; Send the second signature value to the first device, so that the first device generates a target signature corresponding to the message according to the first signature value, the second signature value, the public key, and the first matrix.
[0013] In a third aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor, and a communication interface; wherein, an executable code is stored on the memory, and when the executable code is executed by the processor, the processor is caused to execute the digital signature method as described in the first aspect.
[0014] In a fourth aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor, and a communication interface; wherein, an executable code is stored on the memory, and when the executable code is executed by the processor, the processor is caused to execute the digital signature method as described in the second aspect.
[0015] In a fifth aspect, an embodiment of the present application provides a non-transitory machine-readable storage medium, on which an executable code is stored, and when the executable code is executed by a processor of an electronic device, the processor can at least implement the digital signature method as described in the first aspect.
[0016] In a sixth aspect, an embodiment of the present application provides a non-transitory machine-readable storage medium, on which an executable code is stored, and when the executable code is executed by a processor of an electronic device, the processor can at least implement the digital signature method as described in the second aspect.
[0017] In a seventh aspect, an embodiment of the present application provides a computer program product, where the computer program product includes a computer program, and when the computer program is executed by a processor, it can implement the digital signature method as described in the first aspect.
[0018] In an eighth aspect, an embodiment of the present application provides a computer program product, which includes a computer program that can implement the digital signature method as described in the second aspect when executed by a processor.
[0019] In the digital signature scheme provided by the embodiment of the present application, a digital signature key pair is generated through the cooperation of two parties. Among them, the key pair contains two private keys, which are respectively privately stored by two devices, and the public key in the key pair is publicly shared. When one of the devices needs to send a message with a digital signature, based on the lattice-based Rejected Learning With Errors (rejected LWE) assumption as a security basis, the cooperation is realized to complete the digital signature, ensuring that the digital signature requires both parties to use their own private keys to complete the digital signature, and their own private keys will not be exposed during the signature process. Any party cannot complete the digital signature. Even if the private key of any party is illegally stolen, the stealing party cannot forge the signature. In addition, the digital signature generated through this scheme can be verified through the verification algorithm of ML-DSA, which is better compatible with the previous digital signature system, and the transformation cost of the original signature mechanism is relatively low in the scenario of improving the original signature mechanism. Description of the Drawings
[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0021] Figure 1 It is a schematic structural diagram of a digital signature generation system provided by an embodiment of the present application; Figure 2 It is an interaction schematic diagram of a digital signature method provided by an embodiment of the present application; Figure 3 It is an interaction schematic diagram of a digital signature key generation method provided by an embodiment of the present application; Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed Embodiments
[0022] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Apparently, the described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application. Additionally, the sequence of steps in the following method embodiments is merely an example and not a strict limitation.
[0023] It should be noted that in the case where the embodiments of this application involve user information, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the embodiments of this application are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entrances are provided for the user to choose to authorize or reject. Additionally, various models involved in this application (including but not limited to large language models or other models) comply with the relevant laws and standards.
[0024] In digital signature schemes in post - quantum cryptography, such as ML - DSA, the private key in the key pair is usually stored by the sending device of the message. When the sending device needs to sign a message, it signs the message with the private key it stores, obtaining a signature composed of three signature factors. The sending device sends the message and the signature to the receiving device of the message. The receiving device can obtain the public key in the key pair and verify the signature and the message with the public key. In the embodiments of this application, digital signature can also be referred to as signature.
[0025] With the emergence of intelligent terminals and the development of network technology, new services have emerged, such as mobile payment, mobile office, etc. These new services need to be operated on the terminal. To protect user privacy and security, cryptographic technology is indispensable. Among them, digital signature technology is one of the key technologies, which can ensure the integrity, non - repudiation, and identity authentication of transaction data.
[0026] However, the private key used for digital signature by the terminal is stored in the memory, and the terminal is relatively vulnerable to attacks. This private key may be stolen, posing a potential threat to the information security of the terminal.
[0027] In view of the above, the embodiments of the present application provide a digital signature scheme, in which a digital signature key pair is generated through the collaboration of two parties. Among them, the key pair contains two private keys, which are respectively privately stored by two devices, and the public key in the key pair is publicly shared. When one of the devices needs to send a message with a digital signature, based on the lattice-based Rejected Learning With Errors (rejected LWE) assumption as the security basis, the collaboration is realized to complete the digital signature, ensuring that the digital signature requires both parties to use their own private keys to complete the digital signature, and their private keys will not be exposed during the signature process. Neither party can complete the digital signature alone. Even if the private key of any party is illegally stolen, the stealing party cannot forge the signature. In addition, the digital signature generated by this scheme can be verified through the verification algorithm of ML-DSA, which is better compatible with the previous digital signature system, and the transformation cost of the original signature mechanism is relatively low in the scenario of improving the original signature mechanism.
[0028] Please refer to Figure 1 , Figure 1 FIG. is a schematic structural diagram of a digital signature generation system provided by an embodiment of the present application. The digital signature generation system includes a first device and a second device. The first device and the second device collaborate to generate a digital signature key pair, and the digital signature key pair includes a public key, a first private key, and a second private key. Among them, the first device stores the first private key. The second device stores the second private key. The first private key contains a first matrix. The second private key contains a first matrix.
[0029] Generally, any one of the first device and the second device is the signature initiator. In the embodiments of the present application, the first device is used as the signature initiator for exemplary illustration. Both the first device and the second device can be electronic devices, and the electronic devices can be personal computers, mobile phones, tablet devices, smart wearable devices, set application programs, and servers, etc. Exemplarily, in scenarios such as mobile payment, the first device can be a terminal, and the second device can be a server.
[0030] In the embodiments of the present application, when the first device needs to sign a message, the first device may generate a first random vector and a second random vector. Based on the Reject Learning with Errors (RLWE) assumption, a first variable value is obtained according to a first matrix, the first random vector, and the second random vector, and the first variable value is sent to the second device. Based on the RLWE assumption, the second device obtains a second variable value according to the first matrix, a third random vector generated by itself, and a fourth random vector generated by itself, and sends the second variable value to the first device. Thus, the respective variable values are sent to the other device, ensuring that the random numbers generated by each device are private and will not be leaked during the signature process. The first device and the second device generate their own signature values based on the random vectors they generate themselves, the first variable value, the second variable value, the message, and their own private keys. The first device and the second device exchange the signature values they generate themselves. Thus, the distributed signature process is completed. The first device obtains the target signature corresponding to the generated message according to the first signature value, the second signature value, the first signature factor, the public key, and the first matrix. Based on the RLWE assumption on lattices, the first device and the second device cooperate to perform signature through two interactions without leaking their own random vectors. Digital signature requires both parties to use their own private keys to complete the digital signature, and their private keys will not be exposed during the signature process, ensuring that neither party can complete the digital signature alone. Even if the private key of any party is illegally stolen, the stealing party cannot forge the signature. In addition, the digital signature generated by this solution can be verified through the verification algorithm of ML-DSA, which is better compatible with the previous digital signature system, and the cost of transforming the original signature mechanism is relatively low in the scenario of improving the original signature mechanism.
[0031] The execution process of the digital signature method provided by the embodiments of the present application is introduced in detail below with reference to the accompanying drawings.
[0032] Figure 2 FIG. is an interaction schematic diagram of a digital signature method provided by an embodiment of the present application. As Figure 2 shown, the first device and the second device cooperate to generate a digital signature key pair, and the digital signature key pair includes a public key, a first private key, and a second private key. Among them, the first device stores the first private key, and the first private key contains a first matrix. The second device stores the second private key, and the second private key contains a first matrix. This method can be applied to the above Figure 1 shown digital signature system. The method includes the following steps: 201. The first device generates a first random vector and a second random vector, obtains a first variable value according to the first matrix, the first random vector, and the second random vector, and sends the first variable value to the second device.
[0033] 202. The second device generates a third random vector and a fourth random vector, obtains a second variable value according to the first matrix, the third random vector, and the fourth random vector, and sends the second variable value to the first device.
[0034] 203. The first device generates a first signature value according to the first random vector, the first variable value, the second variable value, the message, and the first private key.
[0035] 204. The second device generates a second signature value according to the third random vector, the first variable value, the second variable value, the message, and the second private key, and sends the second signature value to the first device.
[0036] 205. The first device generates a target signature corresponding to the message according to the first signature value, the second signature value, the public key, and the first matrix.
[0037] In practical applications, the first device and the second device cooperate to generate a digital signature key pair. In this application, this digital signature key pair is simply referred to as the key pair. The key pair includes a publicly shared public key, a first private key privately saved by the first device, and a second private key privately saved by the second device. It can be understood that the first private key of the first device and the second private key of the second device have the same structure, but some or all of the content in the private key of any device cannot be obtained by other devices.
[0038] After the first device and the second device cooperate to generate a digital signature key pair, when any one of the first device and the second device needs to perform a digital signature on a message, the two devices can cooperate to generate the digital signature. Here, taking the first device as the initiator of the digital signature as an example for exemplary introduction, it can be understood that it does not constitute a limitation to this application.
[0039] The first device and the second device can respectively use the two generated random vectors to generate their respective variable values. Specifically, the first device generates a first random vector and a second random vector, obtains a first variable value according to the first matrix, the first random vector, and the second random vector, and sends the first variable value to the second device. Among them, the generated first random vector and second random vector are private to the first device, and other devices including the second device do not know the first random vector and the second random vector. And based on the Regev LWE assumption, obtaining the first variable value according to the first matrix, the first random vector, and the second random vector makes it impossible to infer the first random vector and the second random vector even if the first variable value and the first matrix are known, and it can resist the attack of quantum computers.
[0040] In an optional embodiment, the implementation process for the first device to obtain the first variable value may be: obtaining a first product value between the first matrix and the first random vector. Obtaining the sum of the first product value and the second random vector to obtain the first variable value.
[0041] For example, the first device randomly generates a first random vector , and a second random vector , where , , are security parameters. Obtain the first matrix A. Obtain the first product value between the first matrix A and the first random vector . Obtain the sum of the first product value and the second random vector to obtain a first variable value . That is . .
[0042] Correspondingly, the second device generates a third random vector and a fourth random vector, obtains a second variable value according to the first matrix, the third random vector and the fourth random vector, and sends the second variable value to the first device. Among them, the generated third random vector and fourth random vector are private to the second device, and other devices including the first device are unaware of the third random vector and the fourth random vector. And based on the decisional Learning with Errors (LWE) assumption, obtaining the second variable value according to the first matrix, the third random vector and the fourth random vector, so that even if the second variable value and the first matrix are known, the third random vector and the fourth random vector cannot be inferred, and it can resist the attack of quantum computers.
[0043] In an alternative embodiment, the implementation process for the second device to obtain the second variable value may be: obtain the second product value between the first matrix and the third random vector. Obtain the sum of the second product value and the fourth random vector to obtain the second variable value.
[0044] For example, the second device randomly generates a third random vector , and a fourth random vector , where , , are security parameters. Obtain the first matrix A. Obtain the second product value between the first matrix A and the third random vector . Obtain the sum of the second product value and the fourth random vector to obtain a second variable value . That is . .
[0045] So far, the first device and the second device have respectively obtained their own variable values and sent them to the other device. Then the first device and the second device respectively perform distributed signature on the message through their own private keys. Among them, the first device generates a first signature value according to the first random vector, the first variable value, the second variable value, the message and the first private key.
[0046] In an alternative embodiment, the first device generates a first signature factor based on a first variable value, a second variable value, and a message. It can be understood that the target signature corresponding to the message contains three signature factors, and the first signature factor is one of them. A first signature value is generated based on a first random vector, the first signature factor, and a first private key.
[0047] Optionally, the first private key stored in the first device further includes: a fifth random vector and a sixth random vector. After the first device obtains the first signature factor, the implementation process of generating the first signature value can be: performing a sampling process on the first signature factor to obtain the sampled first signature factor; obtaining a third product value of the sampled first signature factor and the fifth random vector; obtaining the sum of the third product value and the first random vector to obtain the first signature value.
[0048] For example, the first device obtains a total variable value based on the first variable value , the second variable value . Calculate . Among them, , is a signature range parameter, is used to extract the high-order bits from the data input to this function, represents extracting the higher bit values from . The first signature factor , hash() represents a hashing process or a hashing operation, m is the message, is a security parameter. represents concatenation or connection. Performing a sampling process on the first signature factor to obtain the sampled first signature factor can be expressed as . The first random vector is , and the fifth random vector in the first private key is , then the third product value of the first signature factor and the fifth random vector can be obtained, and the sum of the third product value and the first random vector is obtained to obtain the first signature value , that is, .
[0049] Correspondingly, the second device generates a second signature value based on a third random vector, the first variable value, the second variable value, the message, and a second private key.
[0050] In an optional embodiment, the second device generates a first signature factor based on the first variable value, the second variable value, and the message. The process by which the second device generates the first signature factor is the same as that of the first device and will not be elaborated here.
[0051] Optionally, the second private key stored in the second device further includes: a seventh random vector and an eighth random vector. After the second device obtains the first signature factor, the implementation process of generating the second signature value may be: performing a sampling process on the first signature factor to obtain the sampled first signature factor. Obtaining a fourth product value of the sampled first signature factor and the seventh random vector; obtaining the sum of the fourth product value and the third random vector to obtain the second signature value.
[0052] For example, the second device obtains the total variable value based on the first variable value and the second variable value . Calculate , where is the signature range parameter, which is used to extract the high-order bits from the data input to this function, represents extracting the higher bits from . The first signature factor , where hash() represents a hashing process or a hashing operation, m is the message, is the security parameter, represents concatenation or connection. Performing a sampling process on the first signature factor to obtain the sampled first signature factor , which can be expressed as . The third random vector is , and the seventh random vector in the second private key is , then the fourth product value of the first signature factor and the seventh random vector can be obtained, and the sum of the fourth product value and the third random vector is obtained to get the second signature value , that is, .
[0053] In addition, the first device and the second device in the embodiments of the present application cooperate to generate a target signature based on a lattice-based digital signature algorithm. Then, the generated signature value should satisfy the mathematical difficult problem of the lattice, so that the generated target signature can better resist quantum computer attacks. Then, in an optional embodiment, after the first device generates the first signature value, it can also verify whether the first signature value satisfies the mathematical difficult problem of the lattice. If it satisfies the mathematical difficult problem of the lattice, the cooperative signature continues. If not, the first device re-determines the first variable value used for signature. Similarly, after the second device generates the second signature value, it can also perform a verification operation on whether the second signature value satisfies the mathematical difficult problem of the lattice, which will not be elaborated here.
[0054] Since the signature is initiated by the first device, the second device sends the second signature value to the first device, and the first device performs the subsequent signature process. In addition, after the second device sends the second signature value, it has completed this signature, and the second device can also perform the subsequent signature process. Its subsequent signature process is the same as that of the first device. Therefore, to avoid redundancy, only the subsequent signature process of the first device will be introduced next.
[0055] The first device generates a target signature corresponding to the message according to the first signature value, the second signature value, the public key, and the first matrix.
[0056] In an optional embodiment, the public key contains a private key component, and the implementation manner of generating the target signature can be: obtaining the sum of the first signature value and the second signature value to obtain a second signature factor. Generating a third signature factor according to the first signature factor, the second signature factor, the private key component, and the first matrix. Obtaining the composition of the target signature according to the first signature factor, the second signature factor, and the third signature factor.
[0057] For example, continuing with the above example, the first signature value is , the second signature value is , obtaining the first signature value and the second signature value to obtain the second signature factor , that is, . Calculating the third signature factor , where c is the sampled first signature factor, is the low bit of the private key component, is the high bit of the private key component, is the system parameter, is the signature range parameter, is the function of extracting the high bit. Outputting the target signature , is the first signature factor, z is the second signature factor, and h is the third signature factor.
[0058] In this embodiment, when the first device needs to sign a message, the first device can generate a first random vector and a second random vector. Based on the Rejected Learning with Errors (RLWE) assumption, a first variable value is obtained according to the first matrix, the first random number vector, and the second random number vector, and the first variable value is sent to the second device. Based on the RLWE assumption, the second device obtains a second variable value according to the first matrix, a third random number vector generated by itself, and a fourth random number vector, and sends the second variable value to the first device. Thus, each device sends its variable value to the other device, ensuring that the random numbers generated by itself are private and will not be leaked during the signature process. The first device and the second device generate their own signature values based on the random vectors generated by themselves, the first variable value, the second variable value, the message, and their own private keys. The first device and the second device exchange the signature values generated by themselves. Thus, the distributed signature process is completed. The first device obtains the target signature corresponding to the generated message according to the first signature value, the second signature value, the first signature factor, the public key, and the first matrix. Based on the RLWE assumption on lattices, the first device and the second device cooperate to perform signature through two interactions without leaking their own random vectors. Digital signature requires both parties to use their own private keys to complete the digital signature, and their private keys will not be exposed during the signature process, ensuring that neither party can complete the digital signature alone. Even if the private key of any party is illegally stolen, the stealing party cannot forge the signature. In addition, the digital signature generated by this solution can be verified through the verification algorithm of ML-DSA, which is better compatible with the previous digital signature system, and the transformation cost of the original signature mechanism is relatively low in the scenario of improving the original signature mechanism.
[0059] The following introduces a key generation method for digital signature provided by this application. It can be understood that the method of this embodiment can be executed independently or in combination with the digital signature method of the above embodiment. If the method of this embodiment is executed in combination with the digital signature method of the above embodiment, the method of this embodiment is executed before the digital signature method of the above embodiment, which is a process of jointly generating a digital signature key pair for the first device and the second device. That is, after the first device and the second device jointly generate a digital signature key pair, the public key in the key pair can be publicly shared, and the first device and the second device privately save their own private keys. When the first device and / or the second device needs to generate a signature, the digital signature method provided by the above embodiment is used to obtain the signature.
[0060] Please refer to Figure 3 , Figure 3 which is an interaction schematic diagram of a key generation method for digital signature provided by an embodiment of this application. The method provided by this embodiment includes the following steps: 301. The first device generates a first random matrix, a fifth random vector, and a sixth random vector, obtains a first hash value by performing a hash operation on the first random matrix, and sends the first random matrix and the first hash value to the second device.
[0061] 302. The second device generates a second random matrix, a seventh random vector, and an eighth random vector, obtains a second hash value by performing a hash operation on the second random matrix, and sends the second random matrix and the second hash value to the second device.
[0062] 303. The first device verifies the second random matrix based on the second hash value. If the verification passes, it performs a synthesis process on the first random matrix and the second random matrix to obtain a first matrix. And based on the first matrix, the fifth random vector, and the sixth random vector, it obtains a first sum value, obtains a third hash value by performing a hash operation on the first sum value, and sends the first sum value and the third hash value to the second device.
[0063] 304. The second device verifies the first random matrix based on the first hash value. If the verification passes, it performs a synthesis process on the first random matrix and the second random matrix to obtain a first matrix. And based on the first matrix, the seventh random vector, and the eighth random vector, it obtains a second sum value, obtains a fourth hash value by performing a hash operation on the second sum value. And sends the second sum value and the fourth hash value to the first device.
[0064] 305. The first device verifies through the second sum value and the fourth hash value. If the verification passes, a first private key is composed of the first matrix, the first sum value, the fifth random vector, and the sixth random vector.
[0065] 306. The second device verifies through the first sum value and the third hash value. If the verification passes, a first private key is composed of the first matrix, the second sum value, the seventh random vector, and the eighth random vector.
[0066] In some embodiments, the first device and / or the second device outputs a public key composed of a public matrix and a private key component. Wherein, the public matrix is obtained from the first matrix and the identity matrix. The private key component is obtained from the first sum value and the second sum value.
[0067] In practical applications, the first device generates a first random matrix, performs a hash operation on the first random matrix to obtain the hash value corresponding to the first random matrix, and sends the hash value and the first random matrix to the second device. The second device generates a second random matrix, performs a hash operation on the second random matrix to obtain the hash value corresponding to the second random matrix, and sends the hash value and the second random matrix to the first device. Among them, the first device and the second device exchange randomly generated random matrices, which can ensure that both parties have a common randomness basis, and the generation of the first random matrix and the second random matrix is independent of the other device, thereby increasing the security of this method.
[0068] Among them, the first random matrix and the second random matrix can be a k×l matrix. Optionally, a k×l matrix can be randomly and uniformly selected from the ring Rq as the first random matrix. A k×l matrix can be randomly and uniformly selected from the ring Rq as the second random matrix.
[0069] The first device receives the second random matrix and the hash value corresponding to the second random matrix sent by the second device, uses the hash value corresponding to the second random matrix to verify the second random matrix. If the verification passes, the first random matrix and the second random matrix are synthesized to obtain a first matrix. Similarly, the second device receives the first random matrix and the hash value corresponding to the first random matrix sent by the first device, uses the hash value corresponding to the first random matrix to verify the first random matrix. If the verification passes, the first random matrix and the second random matrix are synthesized to obtain a first matrix.
[0070] The first device and the second device verify whether the other party has generated a random matrix by exchanging hash values. Specifically, the first device can perform a hash operation on the second random matrix to obtain the operation result. If the operation result is equal to the hash value corresponding to the received second random matrix, it indicates that the verification passes, indicating that the second device has indeed generated a second random matrix. Similarly, the second device can perform a hash operation on the received first random matrix to obtain the operation result. If the operation result is equal to the hash value corresponding to the received first random matrix, it indicates that the verification passes, indicating that the first device has indeed generated a second random matrix.
[0071] Optionally, the specific implementation manner of synthesizing the first random matrix and the second random matrix to obtain the first matrix can be: determining the sum value of the first random matrix and the second random matrix, and determining this sum value as the first matrix. For example, the first random matrix is , and the second random matrix is , then the obtained first matrix is A, .
[0072] In practical applications, the signature public key is usually public. If the first matrix is directly used as part of the signature public key, then if an attacker obtains the random matrix corresponding to either end, they can directly infer the random matrix corresponding to the other end based on the first matrix and the random matrix corresponding to one end, and then forge the corresponding target signature. In this way, the security of the target signature will be threatened. Therefore, in order to improve the security of this signature method, after obtaining the first matrix, a common matrix can be determined based on the first matrix and the identity matrix, and this common matrix is used as part of the signature public key.
[0073] Optionally, the specific implementation of determining the common matrix can be: horizontally concatenate the first matrix and the identity matrix to obtain the first matrix. Among them, the first matrix can be a k×l matrix, whose elements come from the ring Rq, and the identity matrix can be a k×k matrix, and the elements on its diagonal are all identity elements in Rq. Then the obtained common matrix is a matrix. For example, the first matrix is , and the identity matrix is , and the obtained common matrix is .
[0074] In addition, after obtaining the first matrix, the first device can generate a fifth random vector and a sixth random vector, and generate the first private key corresponding to the first device based on the first matrix, the fifth random vector, and the sixth random vector. Among them, the first private key contains the first matrix, the fifth random vector, and the sixth random vector. The second device generates a seventh random vector and an eighth random vector, and generates the second private key corresponding to the second device based on the first matrix, the seventh random vector, and the eighth random vector. Among them, the second private key contains the first matrix, the seventh random vector, and the eighth random vector.
[0075] To improve the security of the private key corresponding to the first device and the private key corresponding to the second device generated, when generating the corresponding private key, after the first device generates the fifth random vector and the sixth random vector, the first sum value corresponding to the first device can be determined based on the first matrix, the fifth random vector, and the sixth random vector. Similarly, the second device can determine the second sum value corresponding to the second device based on the first matrix, the seventh random vector, and the eighth random vector.
[0076] In an alternative embodiment, obtain the product value of the first matrix and the fifth random vector, and obtain the first sum value of this product value and the sixth random vector. For example, continuing the above example, the first matrix is A, the fifth random vector is , and the sixth random vector is , then the obtained first sum value is . Among them, the value ranges corresponding to the fifth random vector and the sixth random vector can also be specified here , 。
[0077] For the second device, the product value of the first matrix and the seventh random vector can be obtained, and the second sum value of the product value and the eighth random vector can be obtained. For example, if the first matrix is A, the seventh random vector is , and the eighth random vector is , then the obtained second sum value is . Here, the value ranges corresponding to the seventh random vector and the eighth random vector can also be specified , 。
[0078] After obtaining the first sum value, the first device can perform a hash operation on the first sum value to obtain a third hash value, and send the first sum value and the third hash value to the second device. After obtaining the second sum value, the second device can perform a hash operation on the second sum value to obtain a fourth hash value, and send the second sum value and the fourth hash value to the first device. The first device verifies the fourth hash value. After the verification passes, the first sum value and the second sum value are combined to obtain a private key component, and a signature public key is determined based on the public matrix and the private key component. The first device determines a first private key based on the target matrix, the private key component, the fifth random vector, and the sixth random vector. The second device verifies the third hash value. After the verification passes, the first sum value and the second sum value are combined to obtain a private key component, and a second private key is determined based on the first matrix, the private key component, the seventh random vector, and the eighth random vector.
[0079] For example, if the first matrix is A, the first sum value is , the second sum value is , the private key component is , the fifth random vector is , the sixth random vector is , the seventh random vector is , the eighth random vector is , the determined signature public key is , the first private key corresponding to the first device obtained is , and the second private key corresponding to the second device obtained is 。
[0080] In the method provided in this embodiment, the first device generates a first random matrix, performs a hash operation on the first random matrix to obtain a first hash value, and sends the first random matrix and the first hash value to the second device. Similarly, the second device generates a second random matrix, performs a hash operation on the second random matrix to obtain a second hash value, and sends the second random matrix and the second hash value to the first device. Then, the first device verifies the second random matrix based on the second hash value. If the verification passes, the first random matrix and the second random matrix are combined to obtain a first matrix. Similarly, the second device verifies the first random matrix based on the first hash value. If the verification passes, the first random matrix and the second random matrix are combined to obtain a first matrix. Thus, the first device and the second device securely transfer the randomly generated matrices of their own to the other device through hash operations. Then, the first device generates a fifth random vector and a sixth random vector, and generates a first private key according to the target matrix, the fifth random vector, and the sixth random vector. The second device generates a seventh random vector and an eighth random vector, and generates a second private key according to the target matrix, the seventh random vector, and the eighth random vector. Finally, a signature public key is generated according to the target matrix, the fifth random vector, the sixth random vector, the seventh random vector, and the eighth random vector.
[0081] To facilitate understanding of the implementation process of the above digital signature, it is described in combination with a specific application scenario. In specific applications, assume that the first device is a client device and the second device is a server device, where the server can be a cloud server. Its specific implementation process may include the following steps.
[0082] Step 1, obtain system parameters.
[0083] Among them, the system parameters include n, k, l, q, η, τ, γ, γ ', β. n is the degree of the polynomial in the ring R, k and l are the number of rows and columns of the first matrix A respectively, q is the modulus, η is the range of the private key, τ is the number of ±1 in c, 、 is the signature range parameter, and β is the signature truncation parameter.
[0084] Step 2, generate signature keys.
[0085] Among them, the client device and the server device cooperate to generate their respective private keys and signature public keys. Among them, a part of the user's signature key is generated by the client device and a part is generated on the server device. The final key pair is generated through the interaction of the two parties, which improves the security of the key. Specifically, it includes the following steps: Step 21, the client device randomly generates a first random matrix , indicating randomly and uniformly selecting a matrix from the ring Rq. And calculate the first hash value , send to the server device.
[0086] Step 22: The server device randomly generates a second random matrix , and calculates the second hash value , and sends to the client device.
[0087] Step 23: The client device receives , and sends the first random matrix to the server device. The server device receives , and sends the second random matrix to the client device.
[0088] Step 24: The client verifies , if they are not equal, terminate; otherwise, calculate the first matrix , and generate the public matrix .
[0089] Step 25: The client device randomly generates a sub-private key , and calculates , and calculates the third hash value , and sends the third hash value to the server device. Among them, represents randomly selecting an element or subset from the l-dimensional space related to the private key range η, and assigning this element or subset to the variable.
[0090] Step 26: The server device randomly generates a sub-private key , and calculates , and calculates the fourth hash value , and sends the fourth hash value to the client device.
[0091] Step 27: The client device verifies , if it does not hold, terminate the signature; otherwise, calculate .
[0092] Step 28: Output the public key , the first private key of the client device, and the second private key of the server device.
[0093] Step 3: The two ends generate the target signature through interaction and collaboration.
[0094] Step 31: The client device randomly generates a first random vector and a second random vector , where , , are system parameters, and calculate the first variable value , and send to the server device.
[0095] Step 32: The server device randomly generates , and calculates the second variable value , and sends to the client device.
[0096] Step 33: The client device calculates the total variable value and, calculates , the first signature factor , calculates the first signature value , if then stop, otherwise, send to the server device.
[0097] Step 34: The server device calculates the total variable value and, calculates , the first signature factor , calculates the second signature value , if , then stop, otherwise, send to the client device. represents the infinity norm or the maximum norm.
[0098] Step 35: The client device calculates , if , then terminate the signature, otherwise, calculate the third signature factor .
[0099] Step 36: The client device outputs the signature result .
[0100] This embodiment proposes a two-party collaborative post-quantum signature method, which utilizes a lattice-based homomorphic commitment mechanism to effectively protect the security of the ML-DSA private key. The signature key is generated distributively, and its keys are independently generated on the client and server sides respectively. Even if the client is leaked, it is impossible to forge a signature successfully. At the same time, there is no need to modify the ML-DSA verification algorithm.
[0101] Figure 4 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As Figure 4 shown, in practice, the electronic device includes: a memory 21 and a processor 22.
[0102] A memory 21 for storing computer programs and configurable to store various other data to support operations on the electronic device. Examples of such data include instructions for any application or method operating on the electronic device, data structures, contact data, phone book data, messages, pictures, videos, etc.
[0103] A processor 22 coupled to the memory 21 for executing the computer programs in the memory 21 to implement the digital signature method provided in the foregoing embodiments.
[0104] Furthermore, as Figure 4 shown, the electronic device further includes: other components such as a communication component 23, a display 24, a power supply component 25, an audio component 26, etc. Figure 4 Only some components are schematically shown herein, and it does not mean that the electronic device only includes Figure 4 the components shown. The electronic device of this embodiment can be implemented as a terminal device such as a desktop computer, a laptop computer, a smart phone, or an IOT device, or can also be a server device such as a conventional server, a cloud server, or a server array.
[0105] The above-mentioned memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.
[0106] The above-mentioned communication component is configured to facilitate communication between the device where the communication component is located and other devices in a wired or wireless manner. The device where the communication component is located can access a wireless network based on a communication standard, such as a mobile communication network such as 2G, 3G, 4G / LTE, 5G, etc., or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel.
[0107] The above-mentioned display includes a screen, which may include a Liquid Crystal Display (LCD) and a Touch Panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from users. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can not only sense the boundaries of touch or swipe actions, but also detect the duration and pressure associated with the touch or swipe operations.
[0108] The above-mentioned power supply component provides power for various components of the device where the power supply component is located. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the device where the power supply component is located.
[0109] The above-mentioned audio component can be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC), which is configured to receive external audio signals when the device where the audio component is located is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory or sent via the communication component. In some embodiments, the audio component further includes a speaker for outputting audio signals.
[0110] Accordingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to be able to implement the steps in the above method embodiments. Among them, the computer-readable storage medium can be implemented by a volatile or non-volatile or a combination thereof, and can be removable or non-removable. Examples of computer-readable storage media include, but are not limited to, Phase-change RandomAccess Memory (PRAM), Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), other types of Random-Access Memory (RAM), Read-Only Memory (ROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), flash memory or other memory technologies, Compact Disc Read-Only Memory (CD-ROM), Digital Video Disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium.
[0111] Accordingly, an embodiment of the present application further provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are executed by a processor, the processor is enabled to implement each step in the above method embodiment. It should be understood that each process or the combination of multiple processes in the above method flow can be implemented by the computer program or instructions. In addition, these computer programs or instructions can be applied to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices, so that the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices can be used as devices to implement the corresponding functions in the above method embodiment.
[0112] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A digital signature method, characterized in that, Applied to a first device, the first device and a second device cooperate to generate a digital signature key pair, which includes a public key, a first private key, and a second private key. Among them, the first device stores the first private key; the second device stores the second private key; the first private key contains a first matrix, and the second private key contains the first matrix; the method includes: Generating a first random vector and a second random vector; Obtaining a first variable value according to the first matrix, the first random vector, and the second random vector, and sending the first variable value to the second device; Receiving a second variable value sent by the second device, where the second variable value is obtained by the second device according to the first matrix, a third random vector, and a fourth random vector; Generating a first signature value according to the first random vector, the first variable value, the second variable value, a message, and the first private key; Receiving a second signature value sent by the second device, where the second signature value is generated by the second device according to the third random vector, the first variable value, the second variable value, the message, and the second private key; Generating a target signature corresponding to the message according to the first signature value, the second signature value, the public key, and the first matrix.
2. The method according to claim 1, wherein The obtaining the first variable value according to the first matrix, the first random vector, and the second random vector includes: Obtaining a first product value between the first matrix and the first random vector; Obtaining the sum of the first product value and the second random vector to obtain the first variable value; Correspondingly, the second variable value is obtained by the second device by obtaining a second product value between the first matrix and the third random vector and obtaining the sum of the second product value and the fourth random vector.
3. The method according to claim 1, characterized in that, The public key contains a private key component; the generating the first signature value according to the first random vector, the first variable value, the second variable value, the message, and the first private key includes: Generating a first signature factor according to the first variable value, the second variable value, and the message; Generating a first signature value according to the first random vector, the first signature factor, and the first private key; The generating the target signature corresponding to the message according to the first signature value, the second signature value, the public key, and the first matrix includes: Obtaining the sum of the first signature value and the second signature value to obtain a second signature factor; Generating a third signature factor according to the first signature factor, the second signature factor, the private key component, and the first matrix; Composing the target signature from the first signature factor, the second signature factor, and the third signature factor.
4. The method according to claim 3, wherein The generating the first signature factor according to the first variable value, the second variable value, and the message includes: Obtaining a total variable value according to the first variable value and the second variable value; Performing a hashing process on the message and the total variable value to obtain the first signature factor.
5. The method according to claim 4, characterized in that, The method further includes: Generating a first random matrix, a fifth random vector, and a sixth random vector; Send the first random matrix and the first hash value to the second device; Receive the second random matrix and the second hash value sent by the second device, where the second hash value is obtained by the second device through hashing the second random matrix; Verify the second random matrix based on the first hash value. If the verification passes, perform a synthesis process on the first random matrix and the second random matrix to obtain a first matrix; Obtain a first sum value according to the first matrix, the fifth random vector, and the sixth random vector; Send the first sum value and the third hash value to the second device. The third hash value is obtained by hashing the first sum value, so that the second device verifies the first sum value according to the third hash value. If the verification passes, the second private key is composed of the first matrix, the second sum value, the generated seventh random vector, and the eighth random vector; the second sum value is obtained according to the first matrix, the seventh random vector, and the eighth random vector; The first private key is composed of the first matrix, the first sum value, the fifth random vector, and the sixth random vector.
6. The method according to claim 5, characterized in that, The generating the first signature value according to the first random vector, the first signature factor, and the first private key includes: Perform a sampling process on the first signature factor to obtain the sampled first signature factor; Obtain a third product value of the sampled first signature factor and the fifth random vector; Obtain the sum of the third product value and the first random vector to obtain the first signature value; Correspondingly, the second signature value is obtained by the second device performing a sampling process on the first signature factor to obtain the sampled first signature factor; obtaining a fourth product value of the sampled first signature factor and the seventh random vector; and obtaining the sum of the fourth product value and the first random vector.
7. A digital signature method, characterized in that, Applied to the second device, the second device and the first device cooperate to generate a digital signature key pair, where the digital signature key pair includes a public key, a first private key, and a second private key. Among them, the first device stores the first private key; the second device stores the second private key; the first private key contains the first matrix, and the second private key contains the first matrix; the method includes: Receive the first variable value sent by the first device, where the first variable value is obtained by the first device according to the first matrix, the first random vector, and the second random vector; Generate a third random vector and a fourth random vector; Obtain a second variable value according to the first matrix, the third random vector, and the fourth random vector; Send the second variable value to the first device; Receive the first signature value sent by the first device, where the first signature value is generated by the first device according to the first random vector, the first variable value, the second variable value, the message, and the first private key; Generate a second signature value according to the third random vector, the first variable value, the second variable value, the message, and the second private key; Send the second signature value to the first device, so that the first device generates a target signature corresponding to the message according to the first signature value, the second signature value, the public key, and the first matrix.
8. An electronic device, characterized in that, Comprising: A memory, a processor, and a communication interface; wherein, an executable code is stored on the memory, and when the executable code is executed by the processor, the processor executes the method according to any one of claims 1 to 7.
9. A non-transitory machine-readable storage medium, characterized in that, An executable code is stored on the non-transitory machine-readable storage medium, and when the executable code is executed by a processor of an electronic device, the processor executes the method according to any one of claims 1 to 7.
10. A computer program product, characterized in that, Comprising: A computer program, and when the computer program is executed by a processor of an electronic device, the processor executes the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Grid digital signature method and related equipment
CN115694820A
Post-quantum signature method and device
CN118631455A
Lattice based signatures with uniform secrets
US20220353089A1
Quantum-resistant blind signature method, user equipment, signature apparatus and signature verification apparatus
WO2023207523A1