Digital signature method, electronic device and non-transitory machine readable storage medium

The two-party devices jointly generate digital signature key pairs, and use the improved ML-DSA of homomorphic commitment mechanism to solve the problem of easy leakage of private keys, realize high-security digital signatures, are compatible with existing systems and have low modification costs.

CN120342641AActive Publication Date: 2025-07-18BEIJING INFOSEC TECH CO LTD +1

Patent Information

Application Number
CN202510814443.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-07-18
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

In the existing digital signature scheme in post-quantum cryptography, the private key is stored on the sender's device. Once attacked, it is easily leaked, resulting in low security. The attacker can forge his signature.

Method used

The two-party devices are used to jointly generate digital signature key pairs. The private keys are privately stored by the two devices. The ML-DSA improved by the homomorphic commitment mechanism is collaboratively signed to ensure that the private key is not leaked, and the signature cannot be forged when either party's private key is stolen. The public key is introduced to generate the first signature factor to be compatible with ML-DSA verification.

Benefits of technology

It improves the security of digital signatures, ensures that the private key is not leaked, and that the signature cannot be forged when either party’s private key is stolen. It is also compatible with the existing digital signature system, and the transformation cost is low.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342641A_ABST
    Figure CN120342641A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a digital signature method, electronic equipment and a non-temporary machine readable storage medium, and is applied to the technical field of information security. The two devices cooperatively generate a digital signature key pair, and the key pair comprises two private keys which are privately stored by the two devices respectively. When one device needs to send a message with a digital signature, through the ML-DSA improved by the two devices based on a homomorphic commitment mechanism, the two devices cooperatively complete the digital signature by using own private keys, the own private keys are not exposed in the signature process, and any one cannot complete the digital signature. Even if the private key of any party is illegally stolen, the stealing party cannot forge the signature. The first signature factor is generated in combination with the public key, so that the digital signature containing the first signature factor can be verified through the ML-DSA verification algorithm, the digital signature system is compatible with the previous digital signature system, and the reconstruction cost is low in the scene of improving the original signature mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and particularly to a digital signature method, an electronic device, and a non-transitory machine-readable storage medium. Background Art

[0002] Post-Quantum Cryptography (PQC), also known as quantum-resistant cryptography, is a field of cryptography designed to withstand attacks based on quantum computers. With the development of quantum computing technology, digital signature schemes in post-quantum cryptography have been applied in various application scenarios.

[0003] Digital signature schemes in post-quantum cryptography, such as Module Lattice-Based Digital Signature (ML-DSA), usually have the private key in the key pair saved by the sending device of the message. When the sending device needs to sign a message, it signs the message with the private key it saves to obtain a signature composed of three signature factors. The sending device sends the message and the signature to the receiving device of the message. The receiving device can obtain the public key in the key pair and verify the signature and the message with the public key.

[0004] However, since the private key is saved in the sending device, once the sending device is attacked, the private key in the digital signature key pair may be leaked. An attacker can then use the private key to forge the digital signature of the sending device, resulting in low security. Summary of the Invention

[0005] Embodiments of this application provide a digital signature method, an electronic device, and a non-transitory machine-readable storage medium to improve the security of digital signatures.

[0006] In a first aspect, embodiments of this application provide a digital signature method applied to a first device. The first device and a second device cooperate to generate a digital signature key pair, where the digital signature key pair includes a public key, a first private key, and a second private key. The first device stores the first private key, and the second device stores the second private key. The method includes: Cooperatively generate a commitment key with the second device according to a random seed; Determine a first secret value for generating a signature according to the first private key, generate a first commitment value based on the commitment key and the first secret value, and send the first commitment value to the second device; Receive a second commitment value sent by the second device, where the second commitment value is generated by the second device based on the commitment key and the second private key; Generate a first signature factor according to the message, the first commitment value, the second commitment value, and the public key; Generate a first signature value according to the first signature factor and the first private key; Receive a second signature value sent by the second device, where the second signature value is generated by the second device according to the first signature factor and the second private key; Generate a second signature factor according to the first signature value and the second signature value; Generate a third signature factor according to the first signature factor, the second signature factor, the public key, the first private key, and the first secret value; The target signature corresponding to the message is composed of the first signature factor, the second signature factor, and the third signature factor.

[0007] In one embodiment, the generating the first signature factor according to the message, the first commitment value, the second commitment value, and the public key includes: Obtain the sum of the first commitment value and the second commitment value to get the total commitment value; Perform a hashing process and a sampling process on the message, the total commitment value, and the public key to obtain the first signature factor.

[0008] In one embodiment, the generating the first commitment value based on the commitment key and the first secret value includes: Generate a first random number; Generate the first commitment value according to the commitment key, the first secret value, and the first random number; Correspondingly, the second commitment value is generated by the second device based on the commitment key, the second secret value, and the generated second random number; the second secret value is determined by the second device based on the second private key; The method further includes: Receive the second random number sent by the second device.

[0009] In one embodiment, the method further includes: Generate a first random matrix, a first random vector, and a second random vector; Send the first random matrix and the first hash value to the second device; Receive a second random matrix and a second hash value sent by the second device, where the second hash value is obtained by the second device performing a hashing operation on the second random matrix; Verify the second random matrix based on the first hash value. If the verification passes, perform a synthesis process on the first random matrix and the second random matrix to obtain a first matrix; Obtain a first sum value according to the first matrix, the first random vector, and the second random vector; Send the first sum value and a third hash value to the second device, where the third hash value is obtained by performing a hash operation on the first sum value, so that the second device verifies the first sum value according to the third hash value. If the verification passes, the second private key is composed of the first matrix, the second sum value, the generated third random vector, and the fourth random vector; the second sum value is obtained according to the first matrix, the third random vector, and the fourth random vector; The first private key is composed of the first matrix, the first sum value, the first random vector, and the second random vector.

[0010] In one embodiment, the generating a second signature factor according to the first signature value and the second signature value includes: Predict the second secret value determined by the second device according to the first matrix, the second signature value, the second sum value, and the first signature factor to obtain a predicted second secret value; Verify the second commitment value, the predicted second secret value, and the second random number according to the commitment key; if the verification passes, generate a second signature factor according to the first signature value and the second signature value.

[0011] In one embodiment, the public key includes a private key component, and the private key component is the sum of the first sum value and the second sum value; the generating a third signature factor according to the first signature factor, the second signature factor, the public key, the first private key, and the first secret value includes: Obtain a first sub-component according to the first matrix, the first signature factor, the second signature factor, and the private key component; Obtain a second sub-component according to the first secret value and the predicted second secret value; Extract the value of the higher first preset number of bits of the first sub-component and the second sub-component as the third signature factor.

[0012] In one embodiment, the obtaining a first sub-component according to the first matrix, the first signature factor, the second signature factor, and the private key component includes: Obtain a first product value of the first matrix and the second signature factor; Obtain a second product value between the first signature factor and the value of the higher second preset number of bits of the private key component; Obtain the difference between the first product value and the second product value; Extract the value of the higher two-signature range parameter bits of the difference as the first sub-component.

[0013] In a second aspect, an embodiment of the present application provides a digital signature method, which is applied to a second device. The second device and a first device cooperate to generate a digital signature key pair, where the digital signature key pair includes a public key, a first private key, and a second private key. Among them, the first device stores the first private key; the second device stores the second private key; the method includes: Cooperate with the first device to generate a commitment key according to a random seed; Receive a first commitment value sent by the first device; the first commitment value is determined by the first device according to the first private key for generating a signature for the first secret value, and is generated based on the commitment key and the first secret value; Generate a second commitment value based on the commitment key and the second private key, and send the second commitment value to the first device; Generate the first signature factor according to the message, the first commitment value, the second commitment value, and the public key; Generate a second signature value according to the first signature factor and the second private key; Send the second signature value to the first device, so that the first device generates a second signature factor according to the first signature value and the second signature value; and generate a third signature factor according to the first signature factor, the second signature factor, the public key, the first private key, and the first secret value; the target signature is composed of the first signature factor, the second signature factor, and the third signature factor.

[0014] In a third aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor, and a communication interface; among them, an executable code is stored on the memory. When the executable code is executed by the processor, the processor executes the digital signature method as described in the first aspect.

[0015] In a fourth aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor, and a communication interface; among them, an executable code is stored on the memory. When the executable code is executed by the processor, the processor executes the digital signature method as described in the second aspect.

[0016] In a fifth aspect, an embodiment of the present application provides a non-transitory machine-readable storage medium, on which an executable code is stored. When the executable code is executed by a processor of an electronic device, the processor can at least implement the digital signature method as described in the first aspect.

[0017] Sixth aspect, an embodiment of the present application provides a non-transitory machine-readable storage medium, on which executable code is stored. When the executable code is executed by a processor of an electronic device, the processor can at least implement the digital signature method as described in the second aspect.

[0018] In the digital signature method solution provided by the embodiment of the present application, a digital signature key pair is generated collaboratively by two parties. Among them, the key pair contains two private keys, which are respectively privately stored by two devices, and the public key in the key pair is publicly shared. When one of the devices needs to send a message with a digital signature, through the ML-DSA improved based on the homomorphic commitment mechanism by the two parties, the collaborative digital signature is realized, ensuring that the digital signature requires both parties to use their own private keys to complete the digital signature, and their own private keys will not be exposed during the signature process. Any party cannot complete the digital signature. Even if the private key of any party is illegally stolen, the stealing party cannot forge the signature. In addition, the public key is combined to generate the first signature factor, so that the digital signature containing the first signature factor can be verified through the verification algorithm of ML-DSA, which is better compatible with the previous digital signature system, and the transformation cost of the original signature mechanism is relatively low in the scenario of improving the original signature mechanism. Description of the Drawings

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0020] Figure 1 It is a schematic structural diagram of a digital signature generation system provided by an embodiment of the present application; Figure 2 It is an interaction schematic diagram of a digital signature method provided by an embodiment of the present application; Figure 3 It is an interaction schematic diagram of a digital signature key generation method provided by an embodiment of the present application; Figure 4 It is a schematic structural diagram of an electronic device provided by this embodiment. Detailed Embodiments

[0021] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application. Additionally, the sequence of steps in the following method embodiments is only an example and is not strictly limited.

[0022] It should be noted that in the case where the embodiments of this application involve user information, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the embodiments of this application are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or reject. Additionally, various models involved in this application (including but not limited to large language models or other models) comply with relevant laws and standards.

[0023] In digital signature schemes in post-quantum cryptography, such as ML-DSA, the private key in the key pair is usually stored by the sending device of the message. When the sending device needs to sign a message, it signs the message with the private key it stores to obtain a signature consisting of three signature factors. The sending device sends the message and the signature to the receiving device of the message. The receiving device can obtain the public key in the key pair and verify the signature and the message with the public key. In the embodiments of this application, digital signature can also be referred to as signature.

[0024] With the emergence of intelligent terminals and the development of network technology, new services have emerged, such as mobile payment, mobile office, etc. These new services need to be operated on terminals. To protect user privacy and security, cryptographic technology is indispensable. Among them, digital signature technology is one of the key technologies, which can ensure the integrity, non-repudiation, and identity authentication of transaction data.

[0025] However, the private key used for digital signature by the terminal is stored in the memory, and the terminal is relatively vulnerable to attacks. This private key may be stolen, posing a potential threat to the information security of the terminal.

[0026] In view of the above, the embodiments of the present application provide a digital signature scheme. A digital signature key pair is jointly generated by two parties. The key pair contains two private keys, which are respectively privately stored by two devices, and the public key in the key pair is publicly shared. When one of the devices needs to send a message with a digital signature, through the ML-DSA improved based on the homomorphic commitment mechanism by the two parties, the collaborative completion of the digital signature is achieved, ensuring that the digital signature requires both parties to use their own private keys to complete the digital signature, and their private keys will not be exposed during the signature process. Neither party can complete the digital signature alone. Even if the private key of any party is illegally stolen, the stealing party cannot forge the signature. In addition, the digital signature generated by this scheme can be verified through the verification algorithm of ML-DSA, which is better compatible with the previous digital signature system, and the transformation cost of the original signature mechanism is relatively low in the scenario of improving the original signature mechanism.

[0027] Please refer to Figure 1 , Figure 1 which is a schematic structural diagram of a digital signature generation system provided by the embodiments of the present application. The digital signature generation system includes a first device and a second device. The first device and the second device jointly generate a digital signature key pair, which includes a public key, a first private key, and a second private key. Among them, the first device stores the first private key; the second device stores the second private key.

[0028] Generally, any one of the first device and the second device is the signature initiator. In the embodiments of the present application, the first device is used as the signature initiator for exemplary illustration. Both the first device and the second device can be electronic devices, and the electronic devices can be personal computers, mobile phones, tablet devices, smart wearable devices, set application programs, servers, etc. Exemplarily, in scenarios such as mobile payment, the first device can be a terminal, and the second device can be a server.

[0029] In the embodiments of the present application, when the first device needs to sign a message, the first device can generate a commitment key through a random seed. The second device obtains the same commitment key. The first device and the second device respectively determine the secret values for generating the signature, and process the secret values through the shared commitment key to obtain commitment values. The respective commitment values are sent to the other device, so as to ensure that the secret values are private to each device and will not disclose their own secret values during the signature process. The first device and the second device respectively generate the first signature factor in the target signature according to the message, their own commitment values, the commitment values sent by the other device, and the public key, and use their own private keys and the first signature factor to generate their own signature values. The first device and the second device exchange the signature values generated by themselves. The first device generates the second signature factor according to its own signature value and the signature value sent by the second device. The third signature factor is generated according to the first signature factor, the second signature factor, the public key, the first private key, and the first secret value. The target signature is composed of the first signature factor, the second signature factor, and the third signature factor. Based on the homomorphic commitment mechanism, the first device and the second device cooperate to perform signature through two interactions without disclosing their own secret values. Digital signature requires both parties to use their own private keys to complete the digital signature, and their private keys will not be exposed during the signature process, ensuring that neither party can complete the digital signature. Even if the private key of any party is illegally stolen, the stealing party cannot forge the signature. In addition, the digital signature generated by this solution combines the public key to generate the first signature factor, and can be verified through the verification algorithm of ML-DSA, which is better compatible with the previous digital signature system, and has a lower transformation cost for the original signature mechanism in the scenario of improving the original signature mechanism.

[0030] The following will introduce in detail the execution process of the digital signature method provided by the embodiments of the present application with reference to the accompanying drawings.

[0031] Figure 2 It is an interaction schematic diagram of a digital signature method provided by an embodiment of the present application. As Figure 2 shown, the first device and the second device cooperate to generate a digital signature key pair, and the digital signature key pair includes a public key, a first private key, and a second private key. Among them, the first device stores the first private key. The second device stores the second private key. This method can be applied to the above Figure 1 shown digital signature system. The method includes the following steps: 201. The first device and the second device cooperate to generate a commitment key according to a random seed.

[0032] 202. The first device determines a first secret value for generating a signature according to the first private key, generates a first commitment value based on the commitment key and the first secret value, and sends the first commitment value to the second device.

[0033] 203. The second device generates a second commitment value based on the commitment key and the second private key, and sends the second commitment value to the first device.

[0034] 204. The first device generates a first signature factor based on the message, the first commitment value, the second commitment value, and the public key, and generates a first signature value based on the first signature factor and the first private key.

[0035] 205. The second device generates a first signature factor based on the message, the first commitment value, the second commitment value, and the public key; generates a second signature value based on the first signature factor and the second private key, and sends the second signature value to the first device.

[0036] 206. The first device generates a second signature factor based on the first signature value and the second signature value.

[0037] 207. The first device generates a third signature factor based on the first signature factor, the second signature factor, the public key, the first private key, and the first secret value.

[0038] 208. The first device forms the target signature corresponding to the message from the first signature factor, the second signature factor, and the third signature factor.

[0039] In practical applications, the first device and the second device jointly generate a digital signature key pair. In this application, this digital signature key pair is simply referred to as the key pair. The key pair includes the publicly shared public key, the first private key privately saved by the first device, and the second private key privately saved by the second device. It can be understood that the first private key of the first device has the same structure as the second private key of the second device, but some or all of the content in the private key of any device cannot be obtained by other devices.

[0040] After the first device and the second device jointly generate a digital signature key pair, when any one of the first device and the second device needs to perform a digital signature on a message, the two devices can jointly generate the digital signature. Here, an example is given with the first device as the initiator of the digital signature for exemplary introduction.

[0041] The first device and the second device can jointly generate the same commitment key using a random seed. Specifically, the first device can select a random seed and generate a commitment key based on the random seed. The random seed is shared with the second device, so that the second device and the first device can use the same random seed to generate the same commitment key, which can further ensure that the signatures completed by the two devices meet the agreed conditions, ensuring the security and immutability of the signatures. Then, after the first device selects a random seed, it can send the random seed to the second device, and the second device generates a commitment key based on the random seed. Additionally, other methods can also be used to share the random seed selected by the first device with the second device, and the embodiments of the present application do not limit this.

[0042] In an optional embodiment, the specific implementation process of the first device or the second device generating a commitment key based on a random seed may include: using a preset pseudo-random function to generate a third random matrix and a fourth random matrix based on the random seed, and performing a splicing process on the third random matrix and the identity matrix to obtain a spliced matrix. A commitment key is generated based on the spliced matrix and the fourth random matrix. The first device and the second device can generate the commitment key in the same way.

[0043] For example, the first device randomly selects a random seed "seed" and uses a preset pseudo-random function to generate a third random matrix and a fourth random matrix . Among them, , . Perform a splicing process on the third random matrix and the identity matrix to obtain a spliced matrix . Horizontally splice the spliced matrix and the fourth random matrix to generate a commitment key, that is, the commitment key is .

[0044] After generating the commitment key, the first device and the second device respectively use the commitment key and their own private keys to generate commitment values and send the commitment values to the other device.

[0045] In an optional embodiment, the first device determines a first secret value for generating a signature based on the first private key, processes the first secret value determined by itself using the commitment key to obtain a first commitment value, and sends the first commitment value to the second device. The second device determines a second secret value for generating a signature based on the second private key, generates a second commitment value based on the commitment key and the second secret value, and sends the second commitment value to the first device.

[0046] Further, the specific process for the first device to determine the first secret value may be as follows: Obtain the first private key of the first device, where the first private key includes a first matrix. Randomly generate a first mask vector, which is used to mask the first matrix to improve the security of the first matrix. Determine the first secret value according to the first mask vector and the first matrix.

[0047] Optionally, the specific implementation for determining the first secret value according to the mask vector and the first matrix may be: Obtain the product value of the first mask vector and the first matrix; Extract the high-order bits from the product value as the first secret value. For example, the higher two-fold signature range parameter bits of the product value may be extracted. In practical applications, if the product value is directly determined as the first secret value for generating the signature, too much data information about the first device may be leaked. Therefore, to improve the security of the data information of the first device, by extracting the high-order bits from the product value, the first device can hide most of the details in the product value while maintaining sufficient information to verify the commitment, thereby protecting the privacy of the data and reducing the data volume, thus reducing communication and storage costs. At the same time, since the high-order bits often contain the "important" or "significant" parts of the data, they may also be more difficult to be tampered with or forged, thereby enhancing the security of the commitment.

[0048] For example, the private key corresponding to the first device is , where the first matrix is A. Randomly generate the first mask vector , that is , where is the signature range parameter. Obtain the product value of the first mask vector and the first matrix , and extract the high-order bits from the product value as the first secret value, that is , where is used to extract the high-order bits from the data input to the function. represents extracting the higher bit values from

[0049] Among them, the process for the second device to determine the second secret value is similar to the process for the first device to determine the first secret value. For relevant descriptions, please refer to the above process for the first device to determine the first secret value, which will not be elaborated below. It may be: Obtain the second private key of the second device, where the second private key includes a first matrix, and the first matrix is the same as the first matrix included in the first private key. Randomly generate a second mask vector, and the second mask vector corresponds to the first mask vector. The second device determines the second secret value according to the second mask vector and the first matrix.

[0050] Optionally, the specific implementation of determining the second secret value according to the second masking vector and the first matrix may be: obtaining the product value of the second masking vector and the first matrix, and extracting the high-order bits from the third product value as the second secret value.

[0051] For example, the second private key of the second device is , where the first matrix is A. Randomly generate the second masking vector , that is , where is the signature range parameter. Obtain the product value of the second masking vector and the first matrix , and extract the high-order bits from this product value as the second secret value, that is , where is used to extract the high-order bits from the data input to this function. represents extract the higher bit values.

[0052] Furthermore, the first device can process the commitment key and the first secret value through a preset commitment function to generate a first commitment value. The second device can process the commitment key and the second secret value through a preset commitment function to generate a second commitment value.

[0053] In addition, in order to increase the unpredictability and security of the commitment value, a blinding factor can be added when generating the first commitment value and the second commitment value, so as to blind the first commitment value (or the second commitment value) through the blinding factor. In this way, even if the first secret value (or the second secret value) is obtained, the first secret value (or the second secret value) cannot be directly inferred.

[0054] Optionally, the implementation of generating the first commitment value based on the commitment key and the first secret value may be: generating a first random number. Generating the first commitment value according to the commitment key, the first secret value, and the first random number. Wherein, the randomly generated number here is equivalent to the blinding factor.

[0055] For example, in an alternative embodiment, the first device may use a preset commitment function to process the first secret value and the first random number to obtain the first commitment value , that is . Wherein, , is the concatenated matrix in the above example , is the fourth random matrix in the above example . Similarly, the second device can use a preset commitment function Process the second secret value and the second random number to obtain a second commitment value , that is . Among them , is the concatenation matrix in the above example , is the fourth random matrix in the above example .

[0056] As can be seen from the above description: In the embodiment of the present application, based on the homomorphic commitment scheme of random matrix and high-bit bit extraction, the first commitment value corresponding to the first device and the second commitment value corresponding to the second device are generated, and information can be securely transmitted and verified between the first device and the second device. In the process of generating the target signature, the first device and the second device mainly perform two rounds of interaction. Here, the first device and the second device complete the first round of interaction by transmitting their respective corresponding commitment values to each other.

[0057] In an optional embodiment, after generating the first commitment value, the first device can also perform a hash operation on the first commitment value to obtain the hash value corresponding to the first commitment value, and send the hash value to the second device. After generating the second commitment value, the second device can also perform a hash operation on the second commitment value to obtain the hash value corresponding to the second commitment value, and send the hash value to the first device. After receiving the hash value corresponding to the second commitment value sent by the second device, the first device can verify the second commitment value through the hash value corresponding to the second commitment value to prevent the second commitment value from being tampered with during data transmission or by the second device, so as to ensure the correctness of the second commitment value, and thus ensure the correctness of the generated target signature. After receiving the hash value corresponding to the first commitment value sent by the first device, the second device can verify the first commitment value through the hash value corresponding to the first commitment value to prevent the first commitment value from being tampered with during data transmission or by the first device.

[0058] For example, the first device can perform a hash operation on the second commitment value to obtain an operation result, and compare whether the operation result is equal to the hash value corresponding to the second commitment value. If they are equal, it indicates that the second commitment value is correct. If they are not equal, it indicates that the second commitment value has been tampered with, and the signature should be immediately terminated. The first commitment value can be verified in the same way, which will not be elaborated here.

[0059] After that, the first device and the second device respectively generate a first signature factor according to the message, the first commitment value, the second commitment value, and the public key, and generate their own signature values through the first signature factor and their own private keys. Since the first device initiates this signature, the second device only needs to send the generated second signature value to the first device. The first device performs subsequent signature steps based on the signature values obtained by the two devices to obtain the second completed signature. Thus, the second device sending the second signature value obtained by itself to the first device completes the second-round interaction. Among them, the message is the message for which the first device needs to generate a signature, so that when the third device receives this message, it can verify according to the received signature. This message can be a text message, video, audio, file, or transaction information, etc. The embodiments of the present application do not limit the data type and data content corresponding to the message.

[0060] It should be noted that the target signature generated by the first device includes three parts, which are respectively referred to as the first signature factor, the second signature factor, and the third signature factor in this application.

[0061] In an optional embodiment, the implementation manner for the first device to generate the first signature factor according to the message, the first commitment value, the second commitment value, and the public key can be: the first device obtains the sum of the first commitment value and the second commitment value to get the total commitment value. Perform a hash process on the message, the total commitment value, and the public key, and perform a sampling process to obtain the first signature factor. By performing a hash process on the message, the total commitment value, and the public key, and performing a sampling process, it can make the verification process of the target signature the same as the verification algorithm of ML-DSA.

[0062] For example, the first device performs a merging process on the first commitment value and the second commitment value to obtain the total commitment value , that is . Perform a hash process on the message m, the total commitment value , and the public key pk to obtain , where represents the hash function. Perform a sampling process on to obtain the first signature factor c, that is , where is the sampling function.

[0063] After the first device obtains the first signature factor, it generates a first signature value according to the first signature factor and its own first private key. In an optional embodiment, the private key corresponding to the first device includes a first random vector, which is randomly generated by the first device during the process of jointly generating a key pair by the first device and the second device and is unknown to other devices including the second device. The first device obtains the sum of the product value of the first random vector and the first signature factor and the first mask vector to obtain the first signature value, that is, the first device completes its own signature through the first private key saved by itself. For example, the first signature value is obtained through the following formula (1) .

[0064] Formula (1) where is the first mask vector, c is the first signature factor,[[]] is the first random vector.

[0065] Correspondingly, the implementation manner for the second device to generate the first signature factor according to the message, the first commitment value, the second commitment value, and the public key can be: the second device obtains the sum of the first commitment value and the second commitment value to obtain the total commitment value. The message, the total commitment value, and the public key are hashed and sampled to obtain the first signature factor. The process for the second device to obtain the first signature factor is the same as that of the first device and will not be elaborated here.

[0066] After the second device obtains the first signature factor, it generates a second signature value according to the first signature factor and its own second private key. In an optional embodiment, the private key corresponding to the second device includes a third random vector, which is randomly generated by the second device during the process of jointly generating a key pair by the first device and the second device and is unknown to other devices including the first device. The second device obtains the sum of the product value of the third random vector and the first signature factor and the second mask vector to obtain the second signature value, that is, the second device completes its own signature through the second private key saved by itself. For example, the second signature value is obtained through the following formula (2) .

[0067] Formula (2) where is the second mask vector, c is the first signature factor,[[]] is the third random vector.

[0068] In addition, the first device and the second device in the embodiments of the present application cooperate to generate a target signature based on a lattice-based digital signature algorithm. Then, the generated signature value should satisfy the mathematical difficult problem of the lattice, so that the generated target signature can better resist quantum computer attacks. Then, in an optional embodiment, after the first device generates the first signature value, it can also verify whether the first signature value satisfies the mathematical difficult problem of the lattice. If it satisfies the mathematical difficult problem of the lattice, the cooperative signature continues. If not, the first device re-determines the first secret value used for signing. Similarly, after the second device generates the second signature value, it can also perform a verification operation on whether the second signature value satisfies the mathematical difficult problem of the lattice, which will not be elaborated here.

[0069] After the first device receives the second sub-signature value sent by the second device, it can determine the second signature factor according to the first signature value and the second signature value. Optionally, the first device can obtain the second sum value in the second private key. For example, during the process of the first device and the second device cooperating to generate a key pair, the first device can obtain this second sum value. Predict the second secret value determined by the second device according to the first matrix, the second signature value, the second sum value, and the first signature factor, and obtain the predicted second secret value. And receive the second random number sent by the second device. Use the commitment key to verify the second random number, the predicted second secret value, and the second commitment value. If the verification fails, the signature is terminated. If the verification passes, the first signature value and the second signature value are merged to obtain the second signature factor.

[0070] For example, the predicted second secret value can be obtained through the following formula (3) .

[0071] Formula (3) where A is the first matrix, is the second signature value, c is the first signature factor, is the second sum value in the second private key, is the signature range parameter, () is the high-bit extraction function.

[0072] The verification can be performed through the commitment opening function . Specifically, if the obtained value after opening is not equal to 1, that is , the signature is terminated. If the obtained value after opening is equal to 1, then the first signature value and the second signature value are merged to obtain the second signature factor z. That is, z = .

[0073] The first device generates a third signature factor based on a first signature factor, a second signature factor, a public key, a first private key, and a first secret value. The target signature is composed of the first signature factor, the second signature factor, and the third signature factor.

[0074] In a possible embodiment, the implementation manner of obtaining the third signature factor may be: obtaining a first sub-component according to a first matrix, a first signature factor, a second signature factor, and a private key component; obtaining a second sub-component according to the first secret value and a predicted second secret value; and extracting the values of the bits of the first preset number of the relatively higher positions from the first sub-component and the second sub-component as the third signature factor.

[0075] For example, the first sub-component is obtained according to the following formula (4) .

[0076] Formula (4) where A is the first matrix, c is the first signature factor, z is the second signature factor, is the high bit of the private key component, is the signature range parameter.

[0077] The second sub-component is obtained according to the following formula (5) .

[0078] Formula (5) where is the first secret value, is the predicted second secret value.

[0079] Thus, the third signature factor is obtained, where is the function of extracting high bits.

[0080] Output the target signature , where c is the first signature factor, z is the second signature factor, and h is the third signature factor.

[0081] It should be noted that after two rounds of interaction between the first device and the second device, since the first device is the signature initiator, the subsequent signature process can be completed by the first device to obtain the target signature. It can be understood that the second device can also use the same method to complete the subsequent signature process to obtain the target signature. This will not be elaborated here.

[0082] In the embodiments of the present application, through the solution provided by the embodiments of the present application, when the first device needs to sign a message, the first device can generate a commitment key through a random seed, the second device obtains the same commitment key, the first device and the second device respectively determine the secret values for generating the signature, and process the secret values through the shared commitment key to obtain commitment values. The respective commitment values are sent to the other device, so as to ensure that the secret values are private to each device and will not disclose their own secret values during the signature process. The first device and the second device respectively generate the first signature factor in the target signature according to the message, their own commitment values, the commitment values sent by the other device, and the public key, and use their own private keys and the first signature factor to generate their own signature values. The first device and the second device exchange the signature values they generate with each other. The first device generates the second signature factor according to its own signature value and the signature value sent by the second device. The third signature factor is generated according to the first signature factor, the second signature factor, the public key, the first private key, and the first secret value. The target signature is composed of the first signature factor, the second signature factor, and the third signature factor. Based on the homomorphic commitment mechanism, the first device and the second device cooperate to perform signature through two interactions without disclosing their own secret values. Digital signature requires both parties to use their own private keys to complete the digital signature, and their private keys will not be exposed during the signature process, ensuring that neither party can complete the digital signature. Even if the private key of any party is illegally stolen, the stealing party cannot forge the signature. In addition, for the digital signature generated by this solution, the public key is introduced in the calculation process of obtaining the first signature factor, and the obtained signature can be verified through the verification algorithm of ML-DSA, which is better compatible with the previous digital signature system. In the scenario of improving the original signature mechanism, the transformation cost of the original signature mechanism is relatively low.

[0083] The following introduces a method for generating keys for digital signature provided by the present application. It can be understood that the method of this embodiment can be executed alone or in combination with the digital signature method of the above embodiment. If the method of this embodiment is executed in combination with the digital signature method of the above embodiment, the method of this embodiment is executed before the digital signature method of the above embodiment, which is a process of jointly generating a digital signature key pair for the first device and the second device. That is, after the first device and the second device jointly generate a digital signature key pair, the public key in the key pair can be publicly shared, and the first device and the second device respectively privately store their own private keys. When the first device and / or the second device needs to generate a signature, the digital signature method provided by the above embodiment is used to obtain the signature.

[0084] Please refer to Figure 3 , Figure 3 which is an interaction schematic diagram of a method for generating keys for digital signature provided by the embodiments of the present application. The method provided by this embodiment includes the following steps: 301. The first device generates a first random matrix, a first random vector, and a second random vector, obtains a first hash value by performing a hash operation on the first random matrix, and sends the first random matrix and the first hash value to the second device.

[0085] 302. The second device generates a second random matrix, a third random vector, and a fourth random vector, obtains a second hash value by performing a hash operation on the second random matrix, and sends the second random matrix and the second hash value to the first device.

[0086] 303. The first device verifies the second random matrix based on the second hash value. If the verification passes, it performs a synthesis process on the first random matrix and the second random matrix to obtain a first matrix. According to the first matrix, the first random vector, and the second random vector, it obtains a first sum value. It obtains a third hash value by performing a hash operation on the first sum value. And it sends the first sum value and the third hash value to the second device.

[0087] 304. The second device verifies the first random matrix based on the first hash value. If the verification passes, it performs a synthesis process on the first random matrix and the second random matrix to obtain a first matrix. And according to the first matrix, the third random vector, and the fourth random vector, it obtains a second sum value. It obtains a fourth hash value by performing a hash operation on the second sum value. And it sends the second sum value and the fourth hash value to the first device.

[0088] 305. The first device verifies through the second sum value and the fourth hash value. If the verification passes, a first private key is formed by the first matrix, the first sum value, the first random vector, and the second random vector.

[0089] 306. The second device verifies through the first sum value and the third hash value. If the verification passes, a second private key is formed by the first matrix, the second sum value, the third random vector, and the fourth random vector.

[0090] In some embodiments, the first device and / or the second device outputs a public key composed of a public matrix and private key components. Among them, the public matrix is obtained from the first matrix and the identity matrix. The private key components are obtained from the first sum value and the second sum value.

[0091] In practical applications, the first device generates a first random matrix, performs a hash operation on the first random matrix to obtain the hash value corresponding to the first random matrix, and sends the hash value and the first random matrix to the second device. The second device generates a second random matrix, performs a hash operation on the second random matrix to obtain the hash value corresponding to the second random matrix, and sends the hash value and the second random matrix to the first device. Among them, the first device and the second device exchange randomly generated random matrices, which can ensure that both parties have a common randomness basis, and the generation of the first random matrix and the second random matrix is independent of the other device, thereby increasing the security of this method.

[0092] Among them, the first random matrix and the second random matrix can be a k×l matrix. Optionally, a k×l matrix can be randomly and uniformly selected from the ring Rq as the first random matrix. A k×l matrix can be randomly and uniformly selected from the ring Rq as the second random matrix.

[0093] The first device receives the second random matrix and the hash value corresponding to the second random matrix sent by the second device, uses the hash value corresponding to the second random matrix to verify the second random matrix. If the verification passes, the first random matrix and the second random matrix are synthesized to obtain a first matrix. Similarly, the second device receives the first random matrix and the hash value corresponding to the first random matrix sent by the first device, uses the hash value corresponding to the first random matrix to verify the first random matrix. If the verification passes, the first random matrix and the second random matrix are synthesized to obtain a first matrix.

[0094] The first device and the second device verify whether the other party has generated a random matrix by exchanging hash values. Specifically, the first device can perform a hash operation on the second random matrix to obtain an operation result. If the operation result is equal to the hash value corresponding to the received second random matrix, it indicates that the verification passes, indicating that the second device has indeed generated a second random matrix. Similarly, the second device can perform a hash operation on the received first random matrix to obtain an operation result. If the operation result is equal to the hash value corresponding to the received first random matrix, it indicates that the verification passes, indicating that the first device has indeed generated a second random matrix.

[0095] Optionally, the specific implementation method of synthesizing the first random matrix and the second random matrix to obtain the first matrix can be: determining the sum value of the first random matrix and the second random matrix, and determining this sum value as the first matrix. For example, the first random matrix is , and the second random matrix is , then the obtained first matrix is A, .

[0096] In practical applications, the signature public key is usually public. If the first matrix is directly used as part of the signature public key, then if an attacker obtains the random matrix corresponding to any end, they can directly infer the random matrix corresponding to the other end based on the first matrix and the random matrix corresponding to one end, and then forge the corresponding target signature. In this way, the security of the target signature will be threatened. Therefore, in order to improve the security of this signature method, after obtaining the first matrix, a common matrix can be determined based on the first matrix and the identity matrix, and this common matrix is used as part of the signature public key.

[0097] Optionally, the specific implementation of determining the common matrix can be: horizontally concatenate the first matrix and the identity matrix to obtain the first matrix. Among them, the first matrix can be a k×l matrix, and its elements come from the ring Rq. The identity matrix can be a k×k matrix, and the elements on its diagonal are all unit elements in Rq. Then the obtained common matrix is a matrix. For example, the first matrix is , and the identity matrix is , and the obtained common matrix is .

[0098] In addition, after obtaining the first matrix, the first device can generate a first random vector and a second random vector, and generate a first private key corresponding to the first device according to the first matrix, the first random vector, and the second random vector. Among them, the first private key contains the first matrix, the first random vector, and the second random vector. The second device generates a third random vector and a fourth random vector, and generates a second private key corresponding to the second device according to the first matrix, the third random vector, and the fourth random vector. Among them, the second private key contains the first matrix, the third random vector, and the fourth random vector.

[0099] To improve the security of the private key corresponding to the first device and the private key corresponding to the second device generated, when generating the corresponding private key, after the first device generates the first random vector and the second random vector, a first sum value corresponding to the first device can be determined according to the first matrix, the first random vector, and the second random vector. Similarly, the second device can determine a second sum value corresponding to the second device according to the first matrix, the third random vector, and the fourth random vector.

[0100] In an alternative embodiment, obtain the product value of the first matrix and the first random vector, and obtain the first sum value of this product value and the second random vector. For example, continuing with the above example, the first matrix is A, the first random vector is , and the second random vector is , then the obtained first sum value is . Among them, the value ranges corresponding to the first random vector and the second random vector can also be specified here , 。

[0101] For the second device, the product value of the first matrix and the third random vector can be obtained, and the second sum value of the product value and the fourth random vector can be obtained. For example, the first matrix is A, the third random vector is , and the fourth random vector is , then the obtained second sum value is . Here, the value ranges corresponding to the third random vector and the fourth random vector can also be specified , 。

[0102] After obtaining the first sum value, the first device can perform a hash operation on the first sum value to obtain a third hash value, and send the first sum value and the third hash value to the second device. After obtaining the second sum value, the second device can perform a hash operation on the second sum value to obtain a fourth hash value, and send the second sum value and the fourth hash value to the first device. The first device verifies the fourth hash value. After passing the verification, the first device performs a synthesis process on the first sum value and the second sum value to obtain a private key component, and determines a signature public key based on the public matrix and the private key component. The first device determines a first private key based on the target matrix, the private key component, the first random vector, and the second random vector. The second device verifies the third hash value. After passing the verification, the second device performs a synthesis process on the first sum value and the second sum value to obtain a private key component, and determines a second private key based on the first matrix, the private key component, the third random vector, and the fourth random vector.

[0103] For example, the first matrix is A, the first sum value is , the second sum value is , the private key component is , the first random vector is , the second random vector is , the third random vector is , the fourth random vector is , the determined signature public key is , the first private key corresponding to the first device obtained is , and the second private key corresponding to the second device obtained is 。

[0104] In the method provided in this embodiment, the first device generates a first random matrix, performs a hash operation on the first random matrix to obtain a first hash value, and sends the first random matrix and the first hash value to the second device. Similarly, the second device generates a second random matrix, performs a hash operation on the second random matrix to obtain a second hash value, and sends the second random matrix and the second hash value to the first device. Then, the first device verifies the second random matrix based on the second hash value. If the verification passes, the first random matrix and the second random matrix are combined to obtain a first matrix. Similarly, the second device verifies the first random matrix based on the first hash value. If the verification passes, the first random matrix and the second random matrix are combined to obtain a first matrix. Thus, the first device and the second device securely transfer the randomly generated matrices of their own to each other's devices through hash operations. Then, the first device generates a first random vector and a second random vector, and generates a first private key according to the target matrix, the first random vector, and the second random vector. The second device generates a third random vector and a fourth random vector, and generates a second private key according to the target matrix, the third random vector, and the fourth random vector. Finally, a signature public key is generated according to the target matrix, the first random vector, the second random vector, the third random vector, and the fourth random vector.

[0105] To facilitate the understanding of the implementation process of the above digital signature, it is described in combination with a specific application scenario. In specific applications, it is assumed that the first device is a client device and the second device is a server device, where the server can be a cloud server. The specific implementation process may include the following steps: Step 1, obtain system parameters.

[0106] Among them, the system parameters include n, k, l, q, η, τ, , , β. n is the degree of the polynomial in the ring R, k and l are the number of rows and columns of the first matrix A respectively, q is the modulus, η is the range of the private key, τ is the number of ±1 in c, , are signature range parameters, and β is a signature truncation parameter.

[0107] Step 2, generate signature keys.

[0108] Among them, the client device and the server device cooperate to generate their respective private keys and signature public keys. Among them, a part of the user's signature key is generated by the client device and a part is generated on the server device, and the final key pair is generated by the interaction of the two parties, which improves the security of the key. Specifically, it includes the following steps: Step 21, the client device randomly generates a first random matrix , indicating randomly and uniformly selecting a Matrix. And calculate the first hash value , and send to the server device.

[0109] Step 22: The server device randomly generates a second random matrix , and calculates the second hash value , and sends to the client device.

[0110] Step 23: The client device receives , and sends the first random matrix to the server device. The server device receives , and sends the second random matrix to the client device.

[0111] Step 24: The client verifies . If they are not equal, terminate. Otherwise, calculate , and generate the public matrix .

[0112] Step 25: The client device randomly generates a sub-private key , and calculates , and calculates the third hash value , and sends the third hash value to the server device. Among them, means randomly selecting an element or subset from the l-dimensional space related to the private key range η, and assigning this element or subset to the variable.

[0113] Step 26: The server device randomly generates a sub-private key , and calculates , and calculates the fourth hash value , and sends the fourth hash value to the client device.

[0114] Step 27: The client device verifies . If it does not hold, terminate the signature. Otherwise, calculate .

[0115] Step 28: Output the public key , the first private key of the client device, and the second private key of the server device.

[0116] Step 3: The two ends generate the target signature through interaction and collaboration.

[0117] When generating the target signature, the homomorphic commitment mechanism of the lattice is utilized. Through two rounds of interaction between both ends, the target signature is collaboratively generated using their respective private keys. In this way, even if the private key of the client device is leaked, the signature cannot be successfully forged, improving the security of the signature. At the same time, it can also ensure that the client device and the server device have completed the signature according to the agreement, so as to adapt to the data transmission in the cloud environment application scenario. The client device and the server device generate the target signature through two rounds of interaction. Specifically, the following steps can be included: Step 31: The server device and the client device respectively randomly generate matrices using the same seed , . And let , generate the commitment key . Among them, represents the matrix formed by horizontally concatenating and .

[0118] Step 32: The client device randomly generates the first mask vector , the first random number , calculates , the first secret value .

[0119] Step 33: The client device generates the first commitment value , calculates its hash value , and sends the hash value and the first commitment value to the server device.

[0120] Step 34: The server device randomly generates the second mask vector , the second random number , calculates , the second secret value .

[0121] Step 35: The server device generates the second commitment value , calculates its hash value , and sends the hash value and the second commitment value to the client device.

[0122] Step 36: The server device verifies , if it does not hold, the signature is terminated.

[0123] Step 37: The client device verifies , if it does not hold, the signature is terminated, otherwise, continue the following operations: calculate the total commitment value , calculate , m is the message to be signed, and calculate the first signature factor . Calculate the first signature value , if , or , then return to step 32, otherwise, , Send it to the server device. Denotes the infinity norm or the maximum norm.

[0124] Step 38: The server device calculates the total commitment value , calculate , m is the message to be signed, and calculate the first signature factor . Calculate the second signature value , if , or , then return to step 32, otherwise, , Send it to the server device. Among them, Denotes extracting the low-order bits from a certain number.

[0125] Step 39: The client device calculates , if , then terminate the signature, otherwise, continue as follows: Calculate , , if , then return to step 32, otherwise, continue as follows: , , the third signature factor .

[0126] Step 310: Output the target signature .

[0127] In this embodiment, a two-party collaborative post-quantum signature method is proposed. The core idea of this method utilizes the lattice-based homomorphic commitment mechanism, effectively protecting the security of the private key of the post-quantum signature algorithm ML-DSA. The signature key is generated distributively, and its keys are independently generated on two devices. Even if the private key in one of the devices is leaked, it is impossible to forge a signature successfully. At the same time, there is no need to modify the ML-DSA verification algorithm, which better compatible with the previous digital signature system and has high security.

[0128] Figure 4 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As Figure 4 shown, in practice, the electronic device includes: a memory 21 and a processor 22.

[0129] A memory 21 for storing computer programs and configurable to store various other data to support operations on the electronic device. Examples of such data include instructions for any application or method operating on the electronic device, data structures, contact data, phone book data, messages, pictures, videos, and the like.

[0130] A processor 22, coupled to the memory 21, for executing the computer programs in the memory 21 to implement the steps performed by the first device or the second device in the digital signature method provided in the foregoing embodiments.

[0131] Furthermore, as Figure 4 shown, the electronic device further includes: other components such as a communication component 23, a display 24, a power supply component 25, an audio component 26, etc. Figure 4 Only some components are schematically shown herein, and it does not mean that the electronic device only includes Figure 4 the components shown. The electronic device of this embodiment can be implemented as a terminal device such as a desktop computer, a laptop computer, a smart phone, or an IOT device, or can also be a second device such as a conventional server, a cloud server, or a server array.

[0132] The foregoing memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc.

[0133] The foregoing communication component is configured to facilitate communication between the device where the communication component is located and other devices in a wired or wireless manner. The device where the communication component is located can access a wireless network based on a communication standard, such as a mobile communication network such as 2G, 3G, 4G / LTE, 5G, or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel.

[0134] The above-mentioned display includes a screen, which may include a Liquid Crystal Display (LCD) and a Touch Panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from users. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can not only sense the boundaries of touch or swipe actions, but also detect the duration and pressure associated with the touch or swipe operations.

[0135] The above-mentioned power supply component provides power for various components of the device where the power supply component is located. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the device where the power supply component is located.

[0136] The above-mentioned audio component can be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC), which is configured to receive external audio signals when the device where the audio component is located is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory or sent via the communication component. In some embodiments, the audio component further includes a speaker for outputting audio signals.

[0137] Accordingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to be able to implement the steps in the above method embodiments. Among them, the computer-readable storage medium can be implemented by volatile or non-volatile or a combination thereof, and can be removable or non-removable. Examples of computer-readable storage media include, but are not limited to, Phase-change RandomAccess Memory (PRAM), Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), other types of Random-Access Memory (RAM), Read-Only Memory (ROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), flash memory or other memory technologies, Compact Disc Read-Only Memory (CD-ROM), Digital Video Disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices or any other non-transmission medium Accordingly, an embodiment of the present application further provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are executed by a processor, the processor is enabled to implement each step in the above method embodiments. It should be understood that each process or a combination of multiple processes in the above method flow can be implemented by the computer program or instructions. In addition, these computer programs or instructions can be applied to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices, so that the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices can be used as devices to implement the corresponding functions in the above method embodiments.

[0138] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A digital signature method, characterized in that, Applied to a first device, the first device and a second device cooperate to generate a digital signature key pair, where the digital signature key pair includes a public key, a first private key, and a second private key. Among them, the first device stores the first private key; the second device stores the second private key; the method includes: Generate a commitment key in cooperation with the second device according to a random seed; Determine a first secret value for generating a signature according to the first private key, generate a first commitment value based on the commitment key and the first secret value, and send the first commitment value to the second device; Receive a second commitment value sent by the second device, where the second commitment value is generated by the second device based on the commitment key and the second private key; Generate a first signature factor according to the message, the first commitment value, the second commitment value, and the public key; Generate a first signature value according to the first signature factor and the first private key; Receive a second signature value sent by the second device, where the second signature value is generated by the second device according to the first signature factor and the second private key; Generate a second signature factor according to the first signature value and the second signature value; Generate a third signature factor according to the first signature factor, the second signature factor, the public key, the first private key, and the first secret value; The target signature corresponding to the message is composed of the first signature factor, the second signature factor, and the third signature factor.

2. The method according to claim 1, wherein The generating a first signature factor according to the message, the first commitment value, the second commitment value, and the public key includes: Obtain the sum of the first commitment value and the second commitment value to obtain a total commitment value; Perform a hash process on the message, the total commitment value, and the public key, and perform a sampling process to obtain a first signature factor.

3. The method according to claim 1, characterized in that, The generating a first commitment value based on the commitment key and the first secret value includes: Generate a first random number; Generate a first commitment value according to the commitment key, the first secret value, and the first random number; Correspondingly, the second commitment value is generated by the second device based on the commitment key, a second secret value, and a generated second random number; the second secret value is determined by the second device based on the second private key; The method further includes: Receive the second random number sent by the second device.

4. The method according to any one of claims 1 to 3, characterized in that The method further includes: Generate a first random matrix, a first random vector, and a second random vector; Send the first random matrix and a first hash value to the second device; Receive a second random matrix and a second hash value sent by the second device, where the second hash value is obtained by the second device through a hash operation on the second random matrix; Verify the second random matrix based on the first hash value. If the verification passes, perform a synthesis process on the first random matrix and the second random matrix to obtain a first matrix; Obtain a first sum value according to the first matrix, the first random vector, and the second random vector; Send the first sum value and the third hash value to the second device, where the third hash value is obtained by hashing the first sum value, so that the second device verifies the first sum value according to the third hash value. If the verification passes, the second private key is composed of the first matrix, the second sum value, the generated third random vector, and the fourth random vector; the second sum value is obtained according to the first matrix, the third random vector, and the fourth random vector; The first private key is composed of the first matrix, the first sum value, the first random vector, and the second random vector.

5. The method according to claim 4, wherein Generating a second signature factor according to the first signature value and the second signature value includes: Predict a predicted second secret value for the second secret value determined by the second device according to the first matrix, the second signature value, the second sum value, and the first signature factor; Verify the second commitment value, the predicted second secret value, and the second random number according to the commitment key; if the verification passes, generate a second signature factor according to the first signature value and the second signature value.

6. The method according to claim 5, wherein The public key includes a private key component, and the private key component is the sum of the first sum value and the second sum value; generating a third signature factor according to the first signature factor, the second signature factor, the public key, the first private key, and the first secret value includes: Obtain a first sub-component according to the first matrix, the first signature factor, the second signature factor, and the private key component; Obtain a second sub-component according to the first secret value and the predicted second secret value; Extract the value of the higher first preset number of bits of the first sub-component and the second sub-component as the third signature factor.

7. The method according to claim 6, wherein The obtaining a first sub-component according to the first matrix, the first signature factor, the second signature factor, and the private key component includes: Obtain a first product value of the first matrix and the second signature factor; Obtain a second product value between the value of the higher second preset number of bits of the first signature factor and the private key component; Obtain the difference between the first product value and the second product value; Extract the value of the higher two-fold signature range parameter bits of the difference as the first sub-component.

8. A digital signature method, characterized in that, Applied to a second device, the second device and the first device jointly generate a digital signature key pair, where the digital signature key pair includes a public key, a first private key, and a second private key. Among them, the first device stores the first private key; the second device stores the second private key; the method includes: Generate a commitment key jointly with the first device according to a random seed; Receive a first commitment value sent by the first device; the first commitment value is determined by the first device according to the first private key for a first secret value used to generate a signature, and is generated based on the commitment key and the first secret value; Generate a second commitment value based on the commitment key and the second private key, and send the second commitment value to the first device; Generate the first signature factor according to the message, the first commitment value, the second commitment value, and the public key; Generate a second signature value according to the first signature factor and the second private key; Send the second signature value to the first device, so that the first device generates a second signature factor according to the first signature value and the second signature value; and generate a third signature factor according to the first signature factor, the second signature factor, the public key, the first private key, and the first secret value; the target signature is composed of the first signature factor, the second signature factor, and the third signature factor.

9. An electronic device, characterized in that, Comprising: A memory, a processor, and a communication interface; wherein, executable code is stored on the memory, and when the executable code is executed by the processor, the processor executes the method according to any one of claims 1 to 8.

10. A non-transitory machine-readable storage medium, characterized in that, Executable code is stored on the non-transitory machine-readable storage medium, and when the executable code is executed by a processor of an electronic device, the processor executes the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Identification based digital signature method and device

    CN107395370A

  • Digital signature method and system

    CN115941194A

  • Post-quantum signature method and device

    CN118631455A

  • Two-party collaborative Aigis-sig post-quantum signature method

    CN120074817A

  • Post-quantum threshold signature

    EP4496261A1

Cited By

  • Anti-quantum collaborative signature method, signature verification method, system, equipment and medium

    CN121585375A