Diithium algorithm collaborative signature method for forcing two parties to be honest

Through the Dilithium algorithm and the Schnorr zero-knowledge proof protocol, the problem of inability to resist quantum computing and malicious forgery of public keys in the existing technology is solved, and a safe and efficient two-party collaborative signature is achieved.

CN120378120APending Publication Date: 2025-07-25THE FIRST RES INST OF MIN OF PUBLIC SECURITY

Patent Information

Application Number
CN202510630124.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The existing collaborative signature schemes of ECDSA and Guomi SM2 cannot resist quantum computing attacks, while the Dilithium-based scheme cannot prevent malicious parties from forging public key attacks, resulting in signature failure.

Method used

The Dilithium algorithm is used to combine the Schnorr zero-knowledge proof protocol, so that participants can generate and verify the zero-knowledge proof of random vectors by generating and verifying their respective public and private key fragments, ensuring the integrity and legality of the signature, and generating a complete signature by aggregating the signature fragments, and finally verifying the validity of the signature by the complete public key.

Benefits of technology

It realizes resistance to quantum computing attacks and malicious public key attacks, ensuring the security and efficiency of signatures while providing better privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378120A_ABST
    Figure CN120378120A_ABST
Patent Text Reader

Abstract

The invention discloses a Diithium algorithm collaborative signature method for forcing two parties to be honesty, which is based on a Diithium signature scheme and a non-interactive Schnoor zero-knowledge proof protocol, enables two parties which are not trusted mutually to complete collaborative signature, can resist signature failure caused by a malicious party forgery public key attack, can also resist quantum computing attack, and has the advantages of being simple in structure, convenient to use and the like. The method has higher efficiency and better security and privacy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to a method for collaborative signature of Dilithium algorithm that enforces the honesty of two parties. Background Art

[0002] The two-party collaborative signature schemes based on ECDSA (Elliptic Curve Digital Signature Algorithm) or national cipher SM2, and the two-party collaborative signature scheme based on Dilithium (one of the NIST post-quantum signature algorithms) are currently commonly used collaborative signature schemes. The signatures of both Alice and Bob follow the following steps:

[0003] (1) Alice and Bob generate their respective private key fragments and collaboratively calculate the complete public key;

[0004] (2) Alice and Bob use their respective private key fragments to sign the message m to generate their respective signature fragments;

[0005] (3) Alice receives Bob's signature fragment and verifies it. After passing the verification, she aggregates her own signature fragment with the signature fragment generated by Bob into a complete signature;

[0006] (4) The verifier uses the complete public key of the signer to verify the validity of the complete signature. If the verification passes, the complete signature is valid; otherwise, it is invalid.

[0007] The two-party collaborative signature scheme based on ECDSA or national cipher SM2 currently has the widest range of use, but it cannot resist quantum computing attacks; the two-party collaborative signature scheme based on Dilithium can resist quantum computing attacks, but it cannot prevent malicious parties from forging public key attacks, resulting in the failure of collaborative signatures. Summary of the Invention

[0008] Aiming at the deficiencies of the prior art, the present invention aims to provide a method for collaborative signature of Dilithium algorithm that enforces the honesty of two parties.

[0009] To achieve the above object, the present invention adopts the following technical solutions:

[0010] A method for collaborative signature of Dilithium algorithm that enforces the honesty of two parties, comprising the following steps:

[0011] Step 1. Two-party key generation:

[0012] (1.1) Two participating parties, Alice and Bob, respectively generate their respective public keys Pub Alice and Pub Bob as well as their respective private key fragments Pri Alice and Pri Bob, and use the Schnorr zero - knowledge proof algorithm to generate their respective Schnorr zero - knowledge proofs and to prove that each of the two parties actually knows its own private key fragment Pri Alice and Pro Bob ;

[0013] (1.2) Two parties, Alice and Bob, send their public keys and Schnorr zero - knowledge proofs to each other;

[0014] (1.3) The two parties respectively verify the Schnorr zero - knowledge proofs of the other party, and then jointly calculate the complete public key Pub Complete ;

[0015] Step Two: Two - party collaborative signature:

[0016] (2.1) Two parties, Alice and Bob, respectively generate their own random vectors and

[0017] (2.2) Alice and Bob respectively use the Schnorr zero - knowledge proof algorithm to generate Schnorr zero - knowledge proofs of their respective random vectors and to prove that they actually know their own random vectors;

[0018] (2.3) Two parties, Alice and Bob, send the Schnorr zero - knowledge proofs of their own random vectors generated in step (2.2) to each other;

[0019] (2.4) Two parties, Alice and Bob, respectively verify the Schnorr zero - knowledge proofs of the random vectors of the other party;

[0020] (2.5) Two parties, Alice and Bob, respectively use their own private key fragments Pri Alice and Pri Bob to sign the message m, generating their own signature fragments Sign Alic e and Sign Bob ;

[0021] (2.6) Two parties, Alice and Bob, respectively send the signature fragments and related hash values generated in step (2.5) to each other;

[0022] (2.7) Two parties, Alice and Bob, respectively verify the related hash values they receive;

[0023] (2.8) One of the participants, Alice, will use her own signature fragment Sign Alice to aggregate with the signature fragment Sign Bob generated by the other participant, Bob, into a complete signature Sign Complete , and then send the complete signature Sign Complete to the other participant, Bob;

[0024] Step 3: Verify the signature:

[0025] The other participant, Bob, uses the complete public key Pub Complete to verify the validity of the complete signature Sign Complete . If the verification passes, the complete signature is valid; otherwise, it is invalid.

[0026] Further, in step (1.1), the process for the participant to generate its own public key and private key fragments is as follows:

[0027] Select a random matrix, random vector, and calculate the relevant hash values:

[0028] For one of the participants, Alice:

[0029]

[0030] The participant Alice performs the following calculations:

[0031]

[0032] hk Alice = H1(A Alice );

[0033] Finally, the public key Pub Alice of the participant Alice is obtained as (A Alice , r Alice ) and the private key

[0034] For the other participant, Bob:

[0035]

[0036] The other participant, Bob, performs the following calculations:

[0037]

[0038] hk Bob = H1(A Bob );

[0039] Finally, the public key Pub Bob of the other participant, Bob, is obtained as (ABob , r Bob ) and the private key

[0040] Among them, R q represents the quotient ring Z = Z q [x] / (x n + 1), n ∈ N, Z represents the set of integers, i.e., the integer ring, and N represents the set of positive integers; Z q = Z / qZ = {0, 1, 2,..., q - 1}, q ∈ N, and Z[x] represents the polynomial ring with coefficients taking values in Z; represents a k×k dimensional matrix over R q , k ∈ N, and S η represents the set of all p ∈ R such that ||p|| ∞ ≤ η; represents a k-dimensional matrix over S η ; H1 represents a collision-resistant secure hash function.

[0041] Furthermore, in step (1.1), the process for the two parties to calculate their own Schnorr zero-knowledge proofs is as follows:

[0042] Select a suitable collision-resistant secure hash function H4;

[0043] One of the parties, Alice, performs the following calculations:

[0044]

[0045] c Alice = H0(w Alice );

[0046]

[0047] The other participant, Bob, performs the following calculations:

[0048]

[0049] c Bob = H0(w Bob );

[0050]

[0051] Among them, H0 represents a special class of hash functions that output a vector of a specific length, with exactly τ coefficients being 1 or -1 and the remaining coefficients being 0;

[0052] Verify Whether the four inequalities hold simultaneously, where β = τ·η. If they do not hold simultaneously, reselect the hash function H4 for calculation until the four inequalities hold simultaneously. Then, the two parties respectively output their Schnorr zero-knowledge proofs:

[0053]

[0054] Furthermore, in step (1.2), one of the parties, Alice, sends the public key (A Alice , r Alice ), the Schnorr zero-knowledge proof and the calculated hk Alice to the other party, Bob. The other party, Bob, sends the public key (A Bob , r Bob ), the Schnorr zero-knowledge proof and the calculated hk Bob to the party Alice.

[0055] Still further, the specific process of step (1.3) is as follows:

[0056] (1.3.1) The two parties verify whether the data transmitted by the other party has been tampered with:

[0057] (A) Party Alice verifies whether the data transmitted by Party Bob has been tampered with:

[0058] (A1) Calculate H1(A Bob ), and compare the received hk Bob with the calculated H1(A Bob ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the next verification step A2;

[0059] (A2) Party Alice verifies the Schnorr zero-knowledge proof

[0060] sent by Party Bob as follows:

[0061]

[0062] c′ Bob = H0(w′ Bob )

[0063] Compare c′ Bob with c Bob . If they are not equal, the verification fails and the process terminates. If they are equal, the verification passes;

[0064] (B) Party Bob verifies whether the data transmitted by Party Alice has been tampered with:

[0065] (B1) Calculate H1(A Alice ), and then compare the received hk Alice with the calculated H1(A Alice ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the next verification step B2;

[0066] (B2) Party Bob verifies the Schnorr zero - knowledge proof sent by Party Alice

[0067]

[0068] c′ Alice =H0(w′ Alice )

[0069] Compare c′ Alice with c Alice . If they are not equal, the verification fails and the process terminates. If they are equal, the verification is successful;

[0070] When both step A and step B are successfully verified, proceed to step (1.3.2). Otherwise, the process terminates;

[0071] (1.3.2) Calculate the complete public - key fragment and the hash value:

[0072] One of the parties, Alice, performs the following calculations:

[0073] A = A Alice +A Bob

[0074]

[0075] comk Alice =H2(t Alice )

[0076] The other party, Bob, performs the following calculations:

[0077] A = A Alice +A Bob

[0078]

[0079] comk Bob =H2(t Bob )

[0080] Among them, H2 represents a collision - resistant secure hash function;

[0081] (1.3.3) Send data to each other again:

[0082] Participant Alice sends comk Alice and t Alice to Participant Bob;

[0083] Participant Bob sends comk Bob and t Bob to Participant Alice;

[0084] (1.3.4) Verify the data again:

[0085] Participant Alice calculates and verifies comk Bob =H2(t Bob ) to see if it holds. If it holds, the verification is successful;

[0086] Participant Bob calculates and verifies comk Alice =H2(t Alice ) to see if it holds. If it holds, the verification is successful;

[0087] If the verification fails for either party, the process terminates. If both parties' verifications are successful, proceed to step (1.3.5);

[0088] (1.3.5) Both participants Alice and Bob calculate the remaining complete public key fragment according to the following formula:

[0089] t = t Alice +t Bob ;

[0090] (1.3.6) Calculate the complete public key:

[0091] Both participants Alice and Bob calculate the complete public key Pub Complete :

[0092] Pub Complete =(A, t).

[0093] Furthermore, the specific process of step two is as follows:

[0094] (2.1) Both participants select random vectors and calculate relevant hash values:

[0095] For Participant Alice:

[0096]

[0097] com Alice =HomH(g Alice );

[0098] h Alice= H3(com Alice );

[0099] For participant Bob:

[0100]

[0101] com Bob = HomH(g Bob );

[0102] h Bob = H3(com Bob );

[0103] where S γ-1 denotes the set of all p ∈ R such that ||p|| ∞ ≤ (γ - 1), denotes a k-dimensional matrix over S γ-1 ; H3 represents a collision-resistant secure hash function; HomH represents a homomorphic hash function;

[0104] (2.2) The two participants respectively compute the Schnorr zero-knowledge proofs of their own random vectors:

[0105] Select a suitable collision-resistant secure hash function H5;

[0106] Participant Alice performs the following calculations

[0107]

[0108] such that

[0109]

[0110] d Alice = H0(u Alice );

[0111]

[0112] For participant Bob, the following calculations are performed:

[0113]

[0114] such that

[0115]

[0116] d Bob = H0(u Bob );

[0117]

[0118] Verify Whether the four inequalities hold simultaneously, where β = τ·η. If they do not hold simultaneously, both parties return to the first step and re-select the hash function H5 for calculation until the aforementioned inequalities hold simultaneously, and then output the Schnorr zero-knowledge proof of the random vector:

[0119]

[0120] (2.3) Send data to each other

[0121] Participant Alice sends h Alice , com Alice to Participant Bob;

[0122] Participant Bob sends h Bob , com Bob to Participant Alice;

[0123] (2.4) Verify data

[0124] (C) Participant Alice verifies whether the data transmitted by Participant Bob has been tampered with:

[0125] (C1) Calculate H3(com Bob ), and compare the received h Bob with the calculated H3(com Bob ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the next verification step C2;

[0126] (C2) Participant Alice verifies the Schnorr zero-knowledge proof of Participant Bob

[0127] Calculate:

[0128]

[0129] d′ Bob = H0(u′ Bob );

[0130] Compare d′ Bob with d Bob . If they are not equal, the verification fails and the process terminates. If they are equal, the verification is successful;

[0131] (D) Participant Bob verifies whether the data transmitted by Participant Alice has been tampered with:

[0132] (D1) Calculate H3(comAlice ), compare the received h Alice with the calculated H3(com Alice ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the next verification of D2;

[0133] (D2) Party Bob verifies Party Alice's Schnorr zero - knowledge proof

[0134] Calculate:

[0135] d′ Alice = H0(u′ Alice );

[0136] Compare d′ Alice with d Alice . If they are not equal, the verification fails and the process terminates. If they are equal, the verification succeeds;

[0137] When both step C and step D are successfully verified, proceed to step (2.5). Otherwise, the process terminates;

[0138] (2.5) Calculate the signature and hash value:

[0139] Party Alice performs the following calculations:

[0140] com = com Alice + com Bob ;

[0141] c = H0(m||com);

[0142]

[0143] If or where β = τ·η, go back to step (2.1) to re - select the calculation. Otherwise, output the signature fragment:

[0144]

[0145] Party Bob performs the following calculations:

[0146] com = com Alice + com Bob ;

[0147] c = H0(m||com);

[0148]

[0149] If Or If β = τ·η, then go back to step (2.1) to reselect Perform the calculation, otherwise output the signature fragment:

[0150]

[0151] (2.6) Send data to each other again:

[0152] Participant Alice sends Sign Alice to Participant Bob,

[0153] Participant Bob sends Sign Bob to Participant Alice;

[0154] (2.7) Verify the data again

[0155] Participant Alice calculates and verifies

[0156] Verify whether com Bob is equal to HomH(g′ Bob ). If they are not equal, terminate the process. If they are equal, the verification is successful;

[0157] Bob performs the verification calculation:

[0158] Verify whether com Alice is equal to HomH(g′ Alice ). If they are not equal, terminate the process. If they are equal, the verification is successful;

[0159] When both participants Alice and Bob have successful verifications, go to step (2.8);

[0160] (2.8) Output the collaborative signature

[0161] Participant Alice calculates:

[0162]

[0163] Output the collaborative signature: Sign Complete =(z1, z2, c);

[0164] Participant Alice sends the collaborative signature Sign Complete to Participant Bob.

[0165] Furthermore, the specific process of step three is as follows:

[0166] Participant Bob calculates: V = Az1 + z2 - ct;

[0167] Verify c = H(m||HomH(V)) and ||z1|| ∞ <γ - β, ||z2|| ∞ <Whether γ - β all hold, β = τ·η. If all hold, the collaborative signature verification is successful; otherwise, it fails.

[0168] The beneficial effects of the present invention are as follows: Based on the Dilithium signature scheme and the non - interactive Schnoor zero - knowledge proof protocol, the present invention enables two mutually untrusted parties to complete collaborative signatures, can resist the forgery of public - key attacks by malicious parties resulting in signature failures, and can also resist quantum - computing attacks, having higher efficiency, better security, and privacy. BRIEF DESCRIPTION OF THE DRAWINGS

[0169] Figure 1 It is a flowchart of the method of the embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0170] The present invention will be further described below in conjunction with the drawings. It should be noted that this embodiment is based on the present technical solution and gives detailed implementation manners and specific operation processes, but the protection scope of the present invention is not limited to this embodiment.

[0171] This embodiment provides a collaborative signature method of a Dilithium algorithm (one of the NIST post - quantum signature algorithms) that enforces two - party honesty. Based on the Dilithium signature scheme and the non - interactive Schnoor zero - knowledge proof protocol, two mutually untrusted parties can complete collaborative signatures. The method of this embodiment includes two equal participating parties, denoted as Alice and Bob. Alice and Bob jointly hold a certain property on the blockchain, and it is required that the property can only be spent when both Alice and Bob agree.

[0172] As Figure 1 shown, the collaborative signature method of the Dilithium algorithm that enforces two - party honesty includes the following steps:

[0173] Step 1: Two - party key generation:

[0174] (1.1) Two participating parties, Alice and Bob, respectively generate their own public keys Pub Alice and Pub Bob as well as their own private - key fragments Pri Alice and Pri Bob , and respectively use the Schnorr zero - knowledge proof algorithm to generate their own Schnorr zero - knowledge proofs and for proving that the two participating parties respectively truly know their own private - key fragments Pri Alice and PriBob .

[0175] (1.2) The two participants, Alice and Bob, send their public keys and Schnorr zero-knowledge proof to each other.

[0176] (1.3) The two parties verify each other’s Schnorr zero-knowledge proof and then jointly calculate the complete public key Pub Complete .

[0177] It should be noted that zero-knowledge proof is a cryptographic protocol that allows the prover to prove that a certain assertion is correct without providing any useful information to the verifier.

[0178] Step 2: Two parties sign together:

[0179] (2.1) Two participants, Alice and Bob, generate their own random vectors and

[0180] (2.2) Alice and Bob use the Schnorr zero-knowledge proof algorithm to generate Schnorr zero-knowledge proofs for their respective random vectors. and Used to prove that each party knows its own random vector;

[0181] (2.3) The two participants, Alice and Bob, send each other the Schnorr zero-knowledge proof of their own random vectors generated in step (2.2);

[0182] (2.4) Two participants, Alice and Bob, verify each other’s Schnorr zero-knowledge proof of random vectors;

[0183] (2.5) The two participants, Alice and Bob, use their own private key fragments Pri Alice With Pri Bob Sign the message m and generate its own signature fragment Sign Alice Sign Bob ;

[0184] (2.6) The two participants, Alice and Bob, send the signature fragments and related hash values generated in step (2.5) to each other respectively;

[0185] (2.7) The two participants Alice and Bob verify the relevant hash values received respectively;

[0186] (2.8) One of the participants, Alice, sends her signature fragment Sign AliceGenerate a signature fragment Sign with another party Bob Bob Aggregate it into a complete signature Sign Complete , and then send the complete signature Sign Complete to another party Bob.

[0187] Step 3: Verify the signature:

[0188] Another party Bob uses the complete public key Pub Complete to verify the validity of the complete signature Sign Complete . If the verification passes, the complete signature is valid; otherwise, it is invalid.

[0189] In this embodiment, in step (1.1), the process for a party to generate its own public key and private key fragment is as follows:

[0190] Select random matrices, random vectors, and calculate relevant hash values:

[0191] For one of the parties, Alice, there is:

[0192]

[0193] Party Alice performs the following calculations:

[0194]

[0195] hk Alice = H1(A Alice ).

[0196] Finally, the public key Pub of party Alice is obtained Alice = (A Alice , r Alice ) and the private key

[0197] For another party Bob, there is:

[0198]

[0199] Another party Bob performs the following calculations:

[0200]

[0201] hk Bob = H1(A Bob ).

[0202] Finally, the public key Pub of another party Bob is obtained Bob = (A Bob , r Bob ) and the private key

[0203] Among them, R q represents the quotient ring Z = Z q [x] / (x n +1), n ∈ N, Z represents the set of integers, i.e., the integer ring, and N represents the set of positive integers. Z q = Z / qZ = {0, 1, 2,..., q - 1}, q ∈ N, and Z[x] represents the polynomial ring with coefficients taking values in Z. represents a k×k dimensional matrix over R q , k ∈ N, and S η represents the set of all p ∈ R such that ||p|| ∞ ≤ η. represents a k-dimensional matrix over S η ; H1 represents a collision-resistant secure hash function.

[0204] In this embodiment, in step (1.1), the process for two participating parties to calculate their own Schnorr zero-knowledge proofs is as follows:

[0205] Select a suitable collision-resistant secure hash function H4;

[0206] One of the participating parties, Alice, performs the following calculations:

[0207]

[0208] c Alice = H0(w Alice );

[0209]

[0210] The other participant, Bob, performs the following calculations:

[0211]

[0212] c Bob = H0(w Bob );

[0213]

[0214] Among them, H0 represents a special class of hash functions that outputs a vector of a specific length, with exactly τ coefficients being 1 or -1 and the remaining coefficients being 0.

[0215] Verify Whether the four inequalities hold simultaneously, β = τ·η. If they do not hold simultaneously, reselect the hash function H4 for calculation until the four inequalities hold simultaneously. Then, the two parties respectively output their Schnorr zero-knowledge proofs:

[0216]

[0217] In this embodiment, in step (1.2), one of the parties, Alice, sends the public key (A Alice , r Alice ), the Schnorr zero-knowledge proof and the calculated hk Alice to the other party, Bob. The other party, Bob, sends the public key (A Bob , r Bob ), the Schnorr zero-knowledge proof and the calculated hk Bob to the party Alice.

[0218] In this embodiment, the specific process of step (1.3) is as follows:

[0219] (1.3.1) The two parties verify whether the data transmitted by the other party has been tampered with:

[0220] (A) Party Alice verifies whether the data transmitted by Party Bob has been tampered with:

[0221] (A1) Calculate H1(A Bob ), and compare the received hk Bob with the calculated H1(A Bob ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the next verification step A2;

[0222] (A2) Party Alice verifies the Schnorr zero-knowledge proof

[0223] sent by Party Bob and performs the following calculations:

[0224]

[0225] c′ Bob = H0(w′ Bob )

[0226] Compare c′ Bod with c Bob . If they are not equal, the verification fails and the process terminates. If they are equal, the verification passes.

[0227] (B) Party Bob verifies whether the data transmitted by Party Alice has been tampered with:

[0228] (B1) Calculate H1(A Alice ), and then compare the received hk Alice with the calculated H1(A Alice ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the next verification step B2;

[0229] (B2) Party Bob verifies the Schnorr zero - knowledge proof sent by Party Alice

[0230]

[0231] c′ Alice =H0(w′ Alice )

[0232] Compare c′ Alice with c Alice . If they are not equal, the verification fails and the process terminates. If they are equal, the verification is successful;

[0233] When both step A and step B are successfully verified, proceed to step (1.3.2). Otherwise, the process terminates;

[0234] (1.3.2) Calculate the complete public - key fragment and the hash value:

[0235] One of the parties, Alice, performs the following calculations:

[0236] A = A Alice +A Bob

[0237]

[0238] comk Alice =H2(t Alice )

[0239] The other party, Bob, performs the following calculations:

[0240] A = A Alice +A Bob

[0241]

[0242] comk Bob =H2(t Bob )

[0243] Among them, H2 represents a collision - resistant secure hash function.

[0244] (1.3.3) Send data to each other again:

[0245] Participant Alice sends comk Alice and t Alice to Participant Bob;

[0246] Participant Bob sends comk Bob and t Bob to Participant Alice;

[0247] (1.3.4) Verify the data again:

[0248] Participant Alice calculates and verifies comk Bob =H2(t Bob ) to see if it holds. If it holds, the verification is successful;

[0249] Participant Bob calculates and verifies comk Alice =H2(t Alice ) to see if it holds. If it holds, the verification is successful;

[0250] If the verification fails for either party, the process terminates. If both parties' verifications are successful, proceed to step (1.3.5);

[0251] (1.3.5) Both participants Alice and Bob calculate the remaining complete public key fragments according to the following formula:

[0252] t = t Alice +t Bob .

[0253] (1.3.6) Calculate the complete public key:

[0254] Both participants Alice and Bob calculate the complete public key Pub Complete :

[0255] Pub Complete =(A, t).

[0256] In this embodiment, the specific process of step two is as follows:

[0257] (2.1) The two participants respectively select random vectors and calculate the relevant hash values:

[0258] For Participant Alice:

[0259]

[0260] com Alice =HomH(g Alice );

[0261] h Alice= H3(com Alice ).

[0262] For participant Bob:

[0263]

[0264] com Bob = HomH(g Bob );

[0265] h Bob = H3(com Bob ).

[0266] Where, S γ-1 represents the set of all p ∈ R such that ||p|| ∞ ≤ (γ - 1), represents a k-dimensional matrix on S γ-1 . H3 represents a collision-resistant secure hash function; HomH represents a homomorphic hash function.

[0267] (2.2) The two participants respectively calculate the Schnorr zero-knowledge proofs of their own random vectors:

[0268] Select a suitable collision-resistant secure hash function H5;

[0269] Participant Alice performs the following calculations

[0270]

[0271] such that

[0272]

[0273] d Alice = H0(u Alice );

[0274]

[0275] For participant Bob, the following calculations are performed:

[0276]

[0277] such that

[0278]

[0279] d Bob = H0(u Bob );

[0280]

[0281] Verify Whether the four inequalities hold simultaneously, where β = τ·η. If they do not hold simultaneously, both parties return to the first step and re - select the hash function H5 for calculation until the aforementioned inequalities hold simultaneously, and then output the Schnorr zero - knowledge proof of the random vector:

[0282]

[0283] (2.3) Send data to each other

[0284] Participant Alice sends h Alice , com Alice to participant Bob;

[0285] Participant Bob sends h Bob , com Bob to participant Alice.

[0286] (2.4) Verify data

[0287] (C) Participant Alice verifies whether the data transmitted by participant Bob has been tampered with:

[0288] (C1) Calculate H3(com Bob ), compare the received h Bob with the calculated H3(com Bob ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the next verification step C2;

[0289] (C2) Participant Alice verifies the Schnorr zero - knowledge proof of participant Bob

[0290] Calculate:

[0291]

[0292] d′ Bob = H0(u′ Bob );

[0293] Compare d′ Bob with d Bob . If they are not equal, the verification fails and the process terminates. If they are equal, the verification is successful.

[0294] (D) Participant Bob verifies whether the data transmitted by participant Alice has been tampered with:

[0295] (D1) Calculate H3(comAlice ) Compare the received h Alice with the calculated H3(com Alice ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the next verification of D2;

[0296] (D2) Party Bob verifies Party Alice's Schnorr zero - knowledge proof

[0297] Calculate:

[0298]

[0299] d′ Alice = H0(u′ Alice );

[0300] Compare d′ Alice with d Alice . If they are not equal, the verification fails and the process terminates. If they are equal, the verification succeeds.

[0301] When both the verification in step C and step D succeed, continue with step (2.5). Otherwise, the process terminates.

[0302] (2.5) Calculate the signature and hash value:

[0303] Party Alice performs the following calculations:

[0304] com = com Alice + com Bob ;

[0305] c = H0(m||com);

[0306]

[0307] If or where β = τ·η, then go back to step (2.1) to re - select the calculation. Otherwise, output the signature fragment:

[0308]

[0309] Party Bob performs the following calculations:

[0310] com = com Alice + com Bob ;

[0311] c = H0(m||com);

[0312]

[0313] If or β = τ·η, then go back to step (2.1) to reselect for calculation, otherwise output the signature fragment:

[0314]

[0315] (2.6) Send data to each other again:

[0316] Participant Alice sends Sign Alice to participant Bob,

[0317] Participant Bob sends Sign Bob to participant Alice.

[0318] (2.7) Verify the data again

[0319] Participant Alice calculates and verifies

[0320] Verify whether com Bob is equal to HomH(g′ Bob ). If not, terminate the process; if equal, the verification is successful.

[0321] Bob performs the verification calculation:

[0322] Verify whether com Alice is equal to HomH(g′ Alice ). If not, terminate the process; if equal, the verification is successful.

[0323] When both participants Alice and Bob verify successfully, go to step (2.8).

[0324] (2.8) Output the collaborative signature

[0325] Participant Alice calculates:

[0326]

[0327] Output the collaborative signature: Sign Complete =(z1, z2, c).

[0328] Participant Alice sends the collaborative signature Sign Complete to participant Bob.

[0329] In this embodiment, the specific process of step three is as follows:

[0330] The participant Bob calculates: V = Az1 + z2 - ct;

[0331] Verify that c = H(m||HomH(V)) and ||z1|| ∞ <γ-β, ||z2|| ∞ <Whether γ-β all hold, β = τ·η. If all hold, the collaborative signature verification is successful; otherwise, it fails.

[0332] For those skilled in the art, various corresponding changes and deformations can be given according to the above technical solutions and concepts, and all such changes and deformations should be included within the protection scope of the claims of the present invention.

Claims

1. A collaborative signature method of the Dilithium algorithm that enforces honesty between two parties, characterized in that, It includes the following steps: Step 1: Generation of two-party keys: (1.1) Two participants, Alice and Bob, respectively generate their own public keys Pub Alice and Pub Bob as well as their respective private key fragments Pri Alice and Pri Bob , and respectively use the Schnorr zero - knowledge proof algorithm to generate their respective Schnorr zero - knowledge proofs and to prove that each of the two participants truly knows their own private key fragments Pri Alice and Pri Bob ; (1.2) Two parties, Alice and Bob, send their public keys and Schnorr zero-knowledge proofs to each other; (1.3) The two participating parties respectively verify the Schnorr zero-knowledge proofs of each other, and then jointly calculate the complete public key Pub Complete ; Step 2: Two-party collaborative signature: (2.1) Two participating parties, Alice and Bob, respectively generate their own random vectors and (2.2) Alice and Bob respectively use the Schnorr zero-knowledge proof algorithm to generate Schnorr zero-knowledge proofs of their respective random vectors and to prove that they each truly know their own random vectors; (2.3) Two parties, Alice and Bob, send Schnorr zero-knowledge proofs of their respective random vectors generated in step (2.2) to each other; (2.4) Two parties, Alice and Bob, respectively verify the Schnorr zero-knowledge proofs of the random vectors of the other party; (2.5) Two participants, Alice and Bob, respectively use their own private key fragments Pri Alice and Pri Bob to sign the message m, generating their own signature fragments Sign Alice and Sign Bob ; (2.6) Two parties, Alice and Bob, respectively send the signature fragments and related hash values generated in step (2.5) to each other; (2.7) Two parties, Alice and Bob, respectively verify the related hash values received; (2.8) One of the participating parties, Alice, combines her signature fragment Sign Alice with the signature fragment Sign Bob generated by the other participating party, Bob, to form a complete signature Sign Complete , and then sends the complete signature Sign Complete to the other participating party, Bob; Step 3: Verification of signature: Another participant Bob uses the complete public key Pub Complete to verify the validity of the complete signature Sign Complete If the verification passes, the complete signature is valid; otherwise, it is invalid.

2. The method according to claim 1, wherein In step (1.1), the process for a party to generate its own public key and private key fragments is as follows: Select a random matrix, random vector, and calculate related hash values: For one of the parties, Alice: Party Alice performs the following calculations: hk Alice = H1(A Alice ); Finally, obtain the public key Pub of the participant Alice Alice =(A Alice , r Alice ) and the private key For the other party, Bob: The other party, Bob, performs the following calculations: hk Bob = H1(A Bob ); Finally, obtain the public key Pub of another party Bob Bob =(A Bob , r Bob ) and the private key Among them, R q represents the quotient ring Z = Z q [x] / (x n + 1), n ∈ N, Z represents the set of integers, i.e., the integer ring, and N represents the set of positive integers; Z q = Z / qZ = {0, 1, 2,..., q - 1}, q ∈ N, and Z[x] represents the polynomial ring with coefficients taking values in Z; represents a k×k dimensional matrix over R q , k ∈ N, and S η represents the set of all p ∈ R such that ||p|| ∞ ≤ η; represents a k-dimensional matrix over S η ; H1 represents a collision-resistant secure hash function.

3. The method according to claim 2, characterized in that In step (1.1), the process for the two parties to calculate their own Schnorr zero-knowledge proofs is as follows: Select a suitable collision-resistant secure hash function H4; One of the parties, Alice, performs the following calculations: c Alice = H0(w Alice ); The other participant, Bob, performs the following calculations: c Bob = H0(w Bob ); Among them, H0 represents a special type of hash function that outputs a vector of a specific length, with exactly τ coefficients being 1 or -1 and the remaining coefficients being 0; Verification Verify whether the four inequalities hold simultaneously. Let β = τ·η. If they do not hold simultaneously, re - select the hash function H4 for calculation until the four inequalities hold simultaneously. Then, the two parties respectively output their Schnorr zero - knowledge proofs:

4. The method according to claim 3, wherein In step (1.2), one of the parties, Alice, sends the public key (A Alice , r Alice ), the Schnorr zero - knowledge proof and the calculated hk Alice to the other party, Bob. The other party, Bob, sends the public key (A Bob , r Bob ), the Schnorr zero - knowledge proof zk - and the calculated hk Bob to the party Alice.

5. The method according to claim 4, wherein The specific process of step (1.3) is as follows: (1.3.1) The two parties verify whether the data transmitted by the other party has been tampered with: (A) Party Alice verifies whether the data transmitted by Party Bob has been tampered with: (A1) Calculate H1(A Bob ), compare the received hk Bob with the calculated H1(A Bob ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the verification of the next step A2; (A2) Participant Alice verifies the Schnorr zero-knowledge proof transmitted by Participant Bob Perform the following calculations: c′ Bob = H0(w′ Bob ) Compare c′ Bob with c Bob to check if they are equal. If they are not equal, the verification fails and the process terminates. If they are equal, the verification passes; (B) Party Bob verifies whether the data transmitted by Party Alice has been tampered with: (B1) Calculate H1(A Alice ), then compare the received hk Alice with the calculated H1(A Alice ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the verification of the next step B2; (B2) Party Bob verifies the Schnorr zero - knowledge proof sent by Party Alice c′ Alice = H0(w′ Alice ) Compare c' Alice with c Alice If they are not equal, the verification fails and the process terminates. If they are equal, the verification succeeds; When both verification in step A and step B are successful, proceed to step (1.3.2), otherwise the process terminates; (1.3.2) Calculate the complete public key fragments and hash values: One of the parties, Alice, performs the following calculations: A = A Alice + A Bob comk Alice = H2(t Alice ) The other party, Bob, performs the following calculations: A = A Alice + A Bob comk Bob = H2(t Bob ) Among them, H2 represents a collision-resistant secure hash function; (1.3.3) Send data to each other again: Participant Alice sends comk Alice and t Alice to Participant Bob; Participant Bob sends comk Bob and t Bob to Participant Alice; (1.3.4) Verify the data again: The participant Alice calculates and verifies comk Bob = H2(t Bob ) holds. If it holds, the verification is successful; Participant Bob calculates and verifies comk Alice = H2(t Alice ) holds. If it holds, the verification is successful; If any party's verification fails, the process terminates. If both parties' verifications are successful, proceed to step (1.3.5); (1.3.5) Both parties, Alice and Bob, calculate the remaining complete public key fragments according to the following formula: t = t Alice + t Bob ; (1.3.6) Calculate the complete public key: Both parties Alice and Bob perform the calculation of the complete public key Pub Complete : Pub Complete = (A, t).

6. The method according to claim 5, characterized in that, The specific process of step 2 is as follows: (2.1) The two parties respectively select random vectors and calculate related hash values: For Party Alice: com Alice = HomH(g Alice ); h Alice = H3(com Alice ); For Party Bob: com Bob = HomH(g Bob ); h Bob = H3(com Bob ); Among them, S γ-1 represents the set of all p ∈ R such that ||p|| ∞ ≤ (γ - 1), represents a k-dimensional matrix on S γ-1 ; H3 represents a collision-resistant secure hash function; HomH represents a homomorphic hash function; (2.2) The two parties respectively calculate Schnorr zero-knowledge proofs of their own random vectors: Select a suitable collision-resistant secure hash function H5; Party Alice performs the following calculations Enable d Alice = H0(u ALice ); For Party Bob, perform the following calculations: Enable d Bob = H0(u Bob ); Verification Verify whether the four inequalities hold simultaneously, where β = τ·η. If they do not hold simultaneously, both parties return to the first step and reselect the hash function H5 for calculation until the aforementioned inequalities hold simultaneously, and then output the Schnorr zero-knowledge proof of the random vector: (2.3) Send data to each other Participant Alice sends h Alice , com Alice to Participant Bob; Participant Bob sends h Bob 、com Bob to Participant Alice; (2.4) Verify data (C) Party Alice verifies whether the data transmitted by Party Bob has been tampered with: (C1) Calculate H3(com Bob ), compare the received h Bob with the calculated H3(com Bob ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the next verification step C2; (C2) The participant Alice verifies the Schnorr zero - knowledge proof of the participant Bob Calculate: d′ Bob = H0(u′ Bob ); Compare d' Bob with d Bob If they are not equal, the verification fails and the process terminates; if they are equal, the verification is successful. (D) Party Bob verifies whether the data transmitted by Party Alice has been tampered with: (D1) Calculate H3(com Alice ), compare the received h Alice with the calculated H3(com Alice ). If they are not equal, the verification fails and the process terminates. If they are equal, proceed to the verification of the next step D2; (D2) The participant Bob verifies the Schnorr zero-knowledge proof of the participant Alice Calculate: d′ Alice = H0(u′ Alice ); Compare d′ Alice with d Alice If they are not equal, the verification fails and the process terminates. If they are equal, the verification is successful; When the verification in both Step C and Step D is successful, proceed to Step (2.5); otherwise, terminate the process. (2.5) Calculate the signature and hash value: Party Alice performs the following calculations: com = comAlice + comBob; c = H0(m||com); If or where β = τ·η, then go back to step (2.1) to reselect Calculate, otherwise output the signature fragment: Party Bob performs the following calculations: com = com Alice + com Bob ; c = H0(m||com); If Or then go back to step (2.1) to reselect perform the calculation, otherwise output the signature fragment: (2.6) Send data to each other again: Participant Alice sends Sign Alice to Participant Bob, Participant Bob sends Sign Bob to Participant Alice; (2.7) Verify data again Participant Alice calculates and verifies Verify com Bob is equal to HomH(g′ Bob ), if not equal, terminate the process, if equal, the verification is successful; Bob performs verification calculations: Verify com Alice is equal to HomH(g′ Alice ). If not, terminate the process; if equal, the verification is successful. When both parties, Party Alice and Party Bob, verify successfully, proceed to Step (2.8); (2.8) Output the collaborative signature The participant Alice calculates: Output collaborative signature: Sign Complete = (z1, z2, c); The participant Alice will co-sign Sign Complete and send it to the participant Bob.

7. The method according to claim 6, characterized in that, The specific process of Step Three is as follows: Party Bob calculates: V = Az1 + z2 - ct; Verify c = H(m||HomH(V)) and ||z1|| ∞ <γ-β, ||z2|| ∞ <Whether γ-β all hold, β = τ·η. If all hold, the co-signature verification is successful; otherwise, it fails.

Citation Information

Patent Citations

  • Efficient anti-quantum threshold signature method and system

    CN118157865A

  • Grid-based two-round n-out-of-n threshold signature generation method under quantum random oracle model

    CN118509172A

  • Post-quantum signature method and device

    CN118631455A

  • Method and system for protecting digital signatures

    US20240422010A1

Cited By

  • Multi-party collaborative anti-quantum signature method and system based on homomorphic hash

    CN120979680A