Elliptic curve dynamic threshold signature scheme with forward security
By combining a dynamic threshold signature scheme based on elliptic curves and signature key sharing of asymmetric binary polynomial Q(x,y), along with dynamic committee management, the shortcomings of forward security in the dynamic threshold signature scheme are resolved, achieving dynamism and high security of signing members, and ensuring forward security of communication content.
Patent Information
- Application Number
- CN202410452882.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-16
- Publication Date
- 2025-10-24
AI Technical Summary
Existing dynamic threshold signature schemes have shortcomings in forward security. Adversaries can recover the signature key by obtaining the information of the signer after exiting the scheme, leading to signature failure and failing to guarantee the forward security of the communication content.
An elliptic curve-based dynamic threshold signature scheme is adopted, which uses an asymmetric binary polynomial Q(x,y) for signature key sharing and a dynamic committee for dynamic management of signature members. By combining the Shamir-(t,n) threshold signature scheme and a distributed key generation scheme, forward security of the signature process is ensured.
It improves the security and robustness of the signature scheme, maintains forward security of communication content even when the signature members change dynamically, prevents adversaries from recovering the signature key with less than 2t+1 signature sub-private key shares, and enhances the dynamic adaptability and security of the signature.
Smart Images

Figure CN120834907A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of blockchain, and mainly relates to a dynamic threshold signature scheme with forward security. BACKGROUND
[0002] In the alliance chain, the threshold signature scheme can reduce the number of fees paid when data is transmitted to the blockchain, thereby reducing network load and greatly reducing network communication cost. However, the threshold signature scheme has many shortcomings. For example, some threshold signature schemes cannot support the addition and exit of threshold signature members, and the flexibility of signature members is insufficient, which makes it difficult to cope with changes in signature participants and makes it difficult to adapt to dynamic environments. In view of the dynamic nature of threshold signature members, researchers have explored some dynamic threshold signature schemes, which can solve the problem of addition and exit of threshold signature members. Its flexibility, real-time adjustment capability, security and management cost reduction make it more suitable for signature requirements in dynamic environments. However, the current dynamic threshold still has some defects. For example, in a dynamic threshold signature process, there is often a flow of signature members, and a new set of signature members is formed after joining or exiting. If an adversary obtains the effective information of the signature members after exiting and the effective information of the signature members in the new set of signature members through technical means, the adversary can recover the threshold value of the signature key, resulting in signature failure. This will cause the lack of forward security. Forward security means that in the case of key leakage, past communication content can still be kept safe. Even if the long-term key is leaked, the attacker cannot use the key to decrypt past communication content. In order to cope with the economic losses and unknown risks caused by the lack of forward security in the previous dynamic threshold signature scheme, we need to adopt a dynamic threshold signature scheme with forward security, so that the dynamic threshold signature is more secure, robust and efficient. SUMMARY
[0003] The purpose of the present application is to solve the problem of the existing dynamic threshold signature scheme that the forward security is insufficient, and the dynamic threshold signature scheme is invalid when the valid message is hijacked by the enemy too much, and the signature key is cracked. The present application provides an elliptic curve-based threshold signature scheme for sharing signature key through dynamic committee, adopts asymmetric binary polynomial Q(x, y) as the function of sharing signature key share, wherein the degree of x and y is t and 2t, t is the threshold value of threshold signature, and the transaction is signed by using the elliptic curve signature scheme. The dynamic committee is used to solve the dynamic problem of signature members, and the asymmetric binary polynomial secret sharing is used to solve the problem of insufficient forward security in the dynamic threshold signature process. The present application distributes the signature sub-private key by using the monomial polynomial with the degree of t, signs the transaction in the alliance chain by using the elliptic curve digital signature scheme through the Shamir-(t, n) threshold signature scheme, and improves the security of the dynamic threshold signature scheme.
[0004] The main parameter symbols involved in the present application are explained as follows:
[0005]
[0006]
[0007] The signature member model and the enemy model used in the present application are as follows:
[0008] The present application divides the signature members into two committees C' and C, the old committee C is the signature node before joining or before exiting, the new committee C' is the signature node after joining or after exiting, the signature node only joins and exits during switching, the distributed key generation scheme is started to generate the signature sub-private key during switching, the signature sub-private key in the committee is updated, the public and private key pairs are formed in the committee, the sub-private key is shared to the committee, then the old committee C is updated to the new committee C' through the active secret sharing based on the binary polynomial, then the new committee C' partially signs and threshold signs the message.
[0009] We assume that an active adversary Ad is able to obtain or destroy the signing sub-private key information sent by the signing members. Furthermore, during the signing process, they can obtain or destroy the signing sub-private key information from different periods of the old and new committees. If they obtain more than t shares of the signing sub-private key information needed to recover the signing sub-private key, they can recover the original signing sub-private key, thereby compromising the signing process. In the present invention, however, we assume that the adversary Ad can only obtain at most t shares of the old committee information and t shares of the new committee information, i.e., at most 2t shares of the committee used for signing. This satisfies the forward security requirement of the present invention that 2t+1 shares of the signing sub-private key information are required to recover the original signing sub-private key. Therefore, both security and integrity are maintained.
[0010] In order to achieve the above-mentioned purpose, the present invention adopts the following technical solutions:
[0011] A forward-secure dynamic threshold signature scheme includes three sub-schemes: (1) a distributed key generation scheme; (2) an active secret sharing scheme based on a dynamic committee; and (3) a threshold signature scheme using an elliptic curve digital signature algorithm. The threshold signature scheme adopts a (t,n) threshold signature strategy and digitally signs transaction data in a consortium chain based on an elliptic curve. The signature key shares generated by the distributed key generation scheme are shares of the signature sub-private key. The active secret sharing scheme based on a dynamic committee uses an asymmetric binary polynomial to divide the signature private key into shares and secretly shares it with other nodes on the consortium chain.
[0012] Furthermore, the digital signature scheme based on elliptic curve generates keys by using a standardized elliptic curve, wherein the elliptic curve is taken from an elliptic curve on a prime number field, and the elliptic curve is selected from a finite field F p (p is a prime number greater than 3) select the elliptic curve equation y 2 =x 3 +ax+b,a,b∈F p , and (4a 3 +27b 2 )modp≠0, elliptic curve E(F p ) is defined as E(F p )={(x,y)|x,y∈F p}, and satisfies the above elliptic curve equation and infinite point O, the number of points on the elliptic curve is the elliptic curve E(F p ) level.
[0013] The specific designs of the three sub-solutions involved in this technical solution are as follows:
[0014] (1) Distributed key generation scheme
[0015] The steps of the distributed key generation scheme are as follows:
[0016] S1: Let the committee before joining or leaving be the old committee, the number of members be n, the threshold value be t, satisfying n>2t, the new committee performs threshold signature on the transaction data, and the signature private key in the old committee is d, from the definition in the finite field F p Elliptic curve E(F p ) Select the base point G = (x', y'), where x', y'∈F p , the order of the base point G is q, so the signature public key is Q = d·G.
[0017] S2: Old committee member C i (i=1,2,3......n) Randomly select polynomial p i (x), where the polynomial degree is t, from the cyclic group modulo a large prime number q Select {a i0 ,a i1 ,...,a it}Constitute the polynomial p i (x)
[0018] p i (x) = a i0 +a i x 1 +...+a it x t
[0019] The old committee member calculates the signature sub-private key s ij =p i (ID j )(where ID j is the serial number information of the new committee node j to be sent to). It is sent to other members C' in the new committee using the active secret sharing scheme based on dynamic committee in the next step. j (j=1,2,3......n'), each node C in the old committee i Calculate broadcast information τ ik =a ik G, where k = 0, 1, 2, ..., t, is broadcast to all alliance chain nodes.
[0020] S3: Node C' in the new committee j Received child private key s ij and broadcast information τ ik After that, the new committee members verified If they are equal, then s ij If it is valid, the private key calculation operation is performed, otherwise the sub-private key is discarded. j Receive n sub-private keys skj Post calculates its own private key and public key PK j = SK j ·G.
[0021] S4: Before the process of distributed signature private key generation, the old committee members together select a signature private key, and the signature private key The signature private key value of the entire committee does not change in the change process, and the committee members combine polynomials i = 1, 2,..., n, n is the number of members in the old committee. Then the old committee members broadcast the public key Q = d·G mod p, so that the subsequent new committee members can verify the combined signature after receiving the broadcast public key.
[0022] (2) Active secret sharing scheme based on dynamic committee
[0023] The active secret sharing scheme based on dynamic committee is as follows
[0024] S1: For s ij produced in S2 of the previous step i Perform active secret sharing based on dynamic committee, and the old committee members C ij Take s j as the secret of the secret sharing scheme, and the new committee C' q The size is n', j = 1, 2,..., n'. In the finite field F ij Use an asymmetric binary polynomial Q(x, y) of degree (t, 2t).
[0025] Q(x, y) = s 2 +a1x+a2x t +...+a t x t+1 +a t+2 y+a 2 y 3t +...+a 2t y
[0026] Where a k is also taken from the finite field, where k = 1, 2,..., 3t, Q(0, 0) = s ij . Use this polynomial to actively secret share s ij into sub-shares.
[0027] S2: The old committee members perform share reduction and dimension switching from t dimensions to 2t dimensions. The dimension refers to the threshold value in secret sharing, for example, in the case of dimension t, t+1 members can restore the secret they share. Thus, the new committee will obtain the reduced share polynomial Q(x, j), that is, the old dynamic committee Ci Send the reduced share Q(i,j) to the new dynamic committee member C' j , New Dynamics Committee Member C' j After receiving t+1 reduction shares, the reduction share polynomial Q(x,j) is obtained through Lagrange interpolation method.
[0028] S3: Activation phase, the new dynamic committee randomly selects from the finite field F q Select a masking polynomial R(x,y) of degree (t,2t) (where R(0,0)=0). The coefficient selection method is consistent with S2. By calculating Q′(x,j)=Q(x,j)+R(x,j), Q'(x,j) is distinguished from Q(x,j) in the old committee, and the old share polynomial Q(x,j) is discarded. By covering the old shares, its security is improved.
[0029] S4: Dimensionality reduction stage, recovering the full share from the reduced share, thus reaching a stable state, that is, the new dynamic committee member C' j Send Q'(i,j) to the new committee member C' via Q'(x,j) i , where i=1,2,...,n'. New committee member C' i After receiving 2t+1 shares Q'(i,j) (j=1,2,...,n'), the complete share polynomial Q'(i,y) is calculated through Lagrange interpolation. Let y=0, and the complete share Q'(i,0) is obtained. This achieves the purpose of dimensionality reduction from 2t dimensions to t dimensions. Subsequently, the secret s can be recovered by calculating t+1 complete shares. ij , thereby ensuring the security of the sub-private key when sending it during the threshold signature process.
[0030] (3) Threshold Signature Scheme of Elliptic Curve Signature Algorithm
[0031] The steps of the threshold signature scheme of the elliptic curve signature algorithm are as follows:
[0032] S1: New Dynamics Committee Member C' j After restoring the s sent by other members through the secret sharing scheme based on dynamic committee ij After that, the private key calculated in the distributed key generation scheme is obtained and public key PK j =SK j ·G.
[0033] S2: Partial signature phase:
[0034] 1) New Dynamics Committee Member C' j From the cyclic group Randomly select an integer kj as a temporary key, where p is the order of the cyclic group and compute the hash value e = h(m) of the transaction data message m that needs to be signed.
[0035] 2) C j Compute the temporary key and the product R of the point G on the elliptic curve j = k j · G = (x j , y j ), let r j = x j mod q, if r = 0 then return 1, otherwise proceed to step 3).
[0036] 3) C j In the integer domain Z q select parameters a j and β j such that k j = a j r j + β j m. And compute where the parameter
[0037]
[0038] get the partial signature σ j = (r j , l j , β j ).
[0039] S3: Threshold signature phase:
[0040] 1) C c Compute the parameter γ i = (l i + β i m) mod q (q is the order of the cyclic group of points on the elliptic curve), v i = x i ' mod p, (x i ', y i ') = γ i G - eρ i PK i where e = h(m), C c is the combiner of partial signatures, and verify the partial signature σ i using v i .
[0041] 2) C c Verify whether v i is equal to r i , if they are equal then the signature σ i is valid, then sign the signature σ iCombine, otherwise discard.
[0042] 3) C c Receive threshold t+1 valid signatures sigma i Post-computing Then R=x,
[0043] 4) C c Broadcast threshold signature information sigma=(R, l, beta) in the alliance chain network.
[0044] 5) The alliance chain node receiving the signature verifies the threshold signature, the verifier calculates gamma=(l+beta*m)mod q, and calculates the point (x', y')=gammaG-eQ in the same way, if x'=R, the signature is valid, the signature is successful, otherwise the signature is invalid.
[0045] The beneficial effects of the present application are as follows:
[0046] 1) The existing elliptic curve threshold signature scheme adopted in the present application has high security, the elliptic curve has very good one-way property, and the attacker wants to crack the elliptic curve problem is not inferior to cracking the discrete logarithm problem, and the threshold signature scheme using the elliptic curve has shorter key, faster processing speed and smaller storage ratio compared with other public key encryption. Therefore, using the elliptic curve to digitally sign the transaction in the alliance chain is beneficial to the signature efficiency in the alliance chain. In addition, the basic model of dynamic committee is added to the existing elliptic curve threshold signature scheme in terms of signature members, so that the threshold signature scheme can have dynamic nature and be applicable to the environment where the signature members change.
[0047] 2) The present application has forward security and dynamicity in terms of security, and can support the addition and exit of signature members through dynamic committee and secret sharing based on asymmetric binary polynomial, and can guarantee forward security and adapt to the scene with high liquidity of signature members. Specifically, during the dimension switching process, the secret share of the signer's sub-private key can be leaked in the future or past time, and the security of the subsequent signature will not be affected.
[0048] 3) The present application uses asymmetric binary polynomial for signature key sharing, compared with the traditional monomial signature key sharing, the dimension switching from t to 2t, compared with the t threshold key sharing, even if the enemy gets more than t sub-shares, it cannot restore the shared signature key, so the enemy needs to control 2t+1 nodes to get the signature key, greatly improving the security of the signature key, solving the problem that the enemy controls t nodes to get the signature key in the traditional signature key sharing. BRIEF DESCRIPTION OF DRAWINGS
[0049] Figure 1is the schematic diagram of the distributed key generation scheme of the present application
[0050] Figure 1 In the formula, C represents the set of the old dynamic committee, C' represents the set of the new dynamic committee, the members in the old committee perform the distributed key generation, distribute the sub-private key, and send it to each member in the new committee, and the members in the new committee perform accumulation to obtain the partial signature private key after receiving all the sub-private keys sent by the members in the old committee.
[0051] Figure 2 is the schematic diagram of the active sharing signature sub-private key scheme based on the dynamic committee of the present application
[0052] Figure 2 In the formula, the dynamic committee composed of four signature members is taken as an example, wherein C4 is the node that exits in the dynamic change, and C5 is the node that joins in the dynamic change, the original secret S=Q(0,0) is shared by the asymmetric binary polynomial Q(x,y) to reduce and restore the share between the new and old committees, and the cover polynomial R(x,y) is added to ensure the forward security during the switching of the new and old committees.
[0053] Figure 3 is the schematic diagram of the combination process of the threshold signature scheme in the present application
[0054] Figure 3 It is indicated that after the threshold signature is performed, as long as t+1 valid partial signatures exist in the new committee, the complete signature can be combined, which is the process of accumulating t+1 partial signatures to obtain the complete signature of the message.
[0055] Specific example demonstration
[0056] In order to better understand the present application for the personnel in the technical field, the present application is further described in detail in combination with a small example.
[0057] In the present scheme, the dynamic threshold signature is performed by the dynamic committee, the size of the old committee n is 3, the threshold t of the threshold signature is 1, the condition n>2t is met, the signature scheme adopted is the ECDSA digital signature scheme based on the elliptic curve, and the elliptic curve E:y ≡x 2 +2x+2mod17 is taken on a small field 3 The point G=(5,1) is taken on the elliptic curve, all the points on the elliptic curve form a cyclic group, the order q=19 of the group, and the element list is as follows:
[0058]
[0059] 20G = 19G + G = o + G = G, thus a cyclic group is obtained. Considering such a case, assume that the original committee has three members C1, C2, C3 and C4 in total. During switching, the C4 member exits, and a C5 node is added, so C1, C2, C3 and C5 constitute a new committee, and C1, C2 and C3 constitute an old committee. Based on such a case, the following cases are calculated and described.
[0060] 1) Distributed signature key generation:
[0061] Old committee member C i (i = 1, 2, 3) randomly generates polynomials p1(x) = 1 + 2x, p2(x) = 2 + 3x, and p3(x) = 3 + 4x, calculates P(x) = 6 + 9x, and the committee signature private key d = P(0) = 6.
[0062] C1 calculates s 11 = p1(1) = 3, s 12 = p1(2) = 5, s 13 = p1(3) = 7, s 15 = p1(5) = 11 and s 12 , s 13 and s 15 will be sent to C'2, C'3 and C'5 respectively based on the dynamic committee proactive secret sharing scheme. Similarly, C2 calculates s 21 = p2(1) = 5, s 22 = p2(2) = 8, s 23 = p2(3) = 11, s 25 = p2(5) = 17, C3 calculates s 31 = p3(1) = 7, s 32 = p3(2) = 11, s 33 = p3(3) = 15, s 35 = p3(5) = 23. Taking C1 as an example, C1 calculates the broadcast information μ 10 = a 10 ·G = G = (5, 1), μ 11 = a 11 ·G = 2G = (6, 3), which is broadcast to other nodes in the alliance chain. Similarly, μ 20 = a 20 ·G = 2G = (6, 3), μ 21 = a 21 ·G = 3G = (10, 6), μ 30 = a 30 ·G = 3G = (10, 6), μ 31 = a 31 ·G = 4G = (3, 1).
[0063] C'1 verifies the correctness of the sub-private key s 21 and s 31 , respectively, and calculates the partial signature private key of C'1 as 2k and μ 3k Similarly, C'2 can verify the correctness of the sub-private key s Similarly, C'2 can verify the correctness of the sub-private key s 12 and s 32 . The partial signature private key of C'1 is calculated as The public key is PK1 = SK1 · G = 15G = (3, 16). Similarly, SK2 = 24, PK2 = SK2 · G = 24G = 5G = (9, 16), SK3 = 33, PK3 = SK3 · G = 33G = 14G = (9, 1), SK5 = 51, and PK5 = SK5 · G = 51G = 13G = (16, 4).
[0064] 2) Active secret sharing based on dynamic committee
[0065] Take the sub-private key s 12 as an example of secret sharing, the old committee member C i (i = 1, 2, 3) randomly selects an asymmetric binary polynomial Q(x, y) = s 12 + a1x + a2y + a3y 2 = 5 + x + 2y + 3y 2 as the generator of the secret sharing, C1 calculates Q(1, 1) = 11, Q(1, 2) = 22, Q(1, 3) = 39, Q(1, 5) = 91 and sends Q(1, 2), Q(1, 3) and Q(1, 5) to the new committee members C'2, C'3 and C'5, respectively. Similarly, C2 calculates Q(2, 1) = 12, Q(2, 2) = 23, Q(2, 3) = 40, Q(2, 5) = 92 and sends Q(2, 1), Q(2, 3) and Q(2, 5) to the new committee members C'1, C'3 and C'5, respectively. C3 calculates Q(3, 1) = 13, Q(3, 2) = 24, Q(3, 3) = 41, Q(3, 5) = 93 and sends Q(3, 1), Q(3, 2) and Q(3, 5) to the new committee members C'1, C'2 and C'5, respectively. C'1 calculates Q(x, 1) by Lagrange difference calculation through the received Q(2, 1) and Q(3, 1), and the calculation process is as follows:
[0066]
[0067] Similarly, C'2 can obtain Q(x, 2) = x + 21, C'3 can obtain Q(x, 3) = x + 38, and C'5 can obtain Q(x, 5) = x + 90.
[0068] New dynamic committee C' j (j = 1, 2, 3, 5) randomly selected from the finite field within the number of times (1, 2) cover-up polynomial R(x, y) = x + y + y 2 (where R(0, 0) = 0), R(x, 1) = x + 2, R(x, 2) = x + 6, R(x, 3) = x + 12, R(x, 5) = x + 30, C'1 Q'(x, 1) = Q(x, 1) + R(x, 1) = 2x + 12, similarly C'2 can be obtained Q'(x, 2) = 2x + 27, C'3 can be obtained Q'(x, 3) = 2x + 50, C'5 can be obtained Q'(x, 5) = 2x + 120, thus each member of the new committee gets its own polynomial related to x, if the enemy wants to get the sub- private key must obtain 3 such shares, thus the difficulty of cracking compared with the previous scheme security has been improved.
[0069] In the stable stage, the new dynamic committee member C'1 by calculating Q'(1, 1) = 14, Q'(2, 1) = 16, Q'(3, 1) = 18 and Q'(5, 1) = 22, and Q'(2, 1), Q'(3, 1) and Q'(5, 1) = 22 are sent to the new committee members C'2, C'3 and C'5. Similarly, C'2 by calculating Q'(1, 2) = 29, Q'(2, 2) = 31, Q'(3, 2) = 33 and Q'(5, 2) = 37, and Q'(1, 2), Q'(3, 2) and Q'(5, 2) are sent to the new committee members C'1, C'3 and C'5, C'3 by calculating Q'(1, 3) = 52, Q'(2, 3) = 54, Q'(3, 3) = 56 and Q'(5, 3) = 60, and Q'(1, 3), Q'(2, 3) and Q'(5, 3) are sent to the new committee members C'1, C'2 and C'5, C'5 by calculating Q'(1, 5) = 122, Q'(2, 5) = 124, Q'(3, 5) = 126 and Q'(5, 5) = 130, and Q'(1, 5), Q'(2, 5) and Q'(3, 5) are sent to the new committee members C'1, C'2 and C'3, C'1 after receiving Q'(1, 2), Q'(1, 3) and Q'(1, 5), and its own Q'(1, 1), can be obtained by Lagrange interpolation calculation method Q'(1, y), the calculation is as follows:
[0070]
[0071] Similarly, C'2 can obtain Q'(2, y) = 9 + 3y + 4y 2 , C'3 can obtain Q'(3, y) = 11 + 3y + 4y 2 , C'5 can obtain Q'(5, y) = 15 + 3y + 4y 2, C'1, C'2, C'3 and C'5 take value 0 for variable y in Q'(1, y), Q'(2, y), Q'(3, y) and Q'(5, y) respectively, which results in the value of the polynomial only about x, which can be recovered from four points Q'(1, 0), Q'(2, 0), Q'(3, 0) and Q'(5, 0) to get the polynomial about x Q'(x, 0) = 5 + 2x, and then the shared sub-private key value s can be recovered 12 = 5.
[0072] 3) Threshold signature scheme based on elliptic curve
[0073] Let message m = 3, e = h(m) = 26, the order q = 19 of elliptic curve E, take p = 17 in small field , the following calculations are carried out with C'1 as an example.
[0074] C'1 randomly selects k1 = 42 from , calculates the point R1 = (x1, y1) = k1G mod p = 42G mod 17 = (3, 1) on the elliptic curve, and lets r1 = x1 = 3, randomly selects α1 and β1 from such that k1 = α1r1 + β1m holds, and takes α1 = 10 and β1 = 4, calculates l1 = α1r1 + eρ1·SK1, where
[0075]
[0076] Then l1 = α1r1 + eρ1·SK1 = 10 × 3 + 26 × 2 × 15 = 810, and then the partial signature σ1 = (r1, l1, β1) = (3, 810, 4) can be obtained.
[0077] In the new dynamic committee, a member (e.g. C'3) is randomly selected to combine and verify the partial signatures of other members, calculate, (x1', y1') = γ1G-eρ1PK1=5G-26×2×15G=4G=(3,1), v1=x1'modp=3mod17=3, where e=h(m). Since v1=r1, the signature is valid, and by calculating the same parameters as C'1, σ2=(r2,l2,β2)=(3,-594,4), σ3=(r3,l3,β3)=(3,888,4), σ5=(r5,l5,β5)=(3,251,4) are obtained. Finally, C3 integrates the valid partial signatures σ1 and σ2 into σ=(13,450,8), and then broadcasts to the consortium chain. Finally, the integrated signature is verified, and the signature is completed if the verification is valid. Since the private key of the signature in the committee is d=6, and the public key is PK=6G=(16,3), the calculation has γ=(l+βm)modq=(216+8×3)mod19=12, where the verification point (x', y') = γG-eQ=12G-26×6G=-144G=8G=(13,7) is calculated. Since v=x'=13, the threshold signature is valid.
Claims
1. An elliptic curve dynamic threshold signature scheme with forward security, characterized by the following basic processes: A distributed key generation phase: by selecting a committee size and a signature threshold, each member in the old committee generates a signature sub-private key, which is shared to the new committee. A dynamic committee secret sharing phase: the committee is divided into an old committee and a new committee, and the old committee shares the signature sub-private key between the old and new committees by selecting an asymmetric binary polynomial. An elliptic curve threshold digital signature phase: the new committee uses elliptic curve digital signature (ECDSA) to integrate the signature sub-private key into a partial signature private key, and combines the partial signature private key into a threshold signature in the committee by verifying the validity of the partial signature private key.
2. The method of claim 1, wherein, The distributed key generation phase includes the following steps: S1: Each signature member in the old committee randomly selects a monomial that meets the requirements, and all monomials are combined into a complete polynomial, and the value of the complete polynomial at zero is equal to the signature private key in the committee; S2: The members in the old committee calculate the signature sub-private key using the identity information of the signature members in the new committee, and share it as a secret in the committee; S3: The members in the old committee each calculate the broadcast information for verification, so that the signature sub-private key received in the new committee can be verified.
3. The method of claim 2, wherein, The dynamic committee secret sharing phase includes the following steps: S1: Build the interval of switching between the old and new committees, and select a specific interval for active secret sharing; S2: The old committee shares the signature sub-private key as a secret in the secret sharing process, and selects an asymmetric binary polynomial for active secret sharing; S3: The old committee switches the dimension, converts the complete share into a reduced share through the asymmetric binary polynomial, and sends the reduced share to the new committee, increasing the number of shares needed to recover the secret and increasing the threshold in the signature process; S4: After receiving the reduced share, each member in the new committee calculates the new reduced share using the masking polynomial to mask the reduced share, so that the new reduced share is different from the old reduced share; S5: The new committee calculates the new reduced share to restore the complete share through Lagrange interpolation.
4. The method of claim 3, wherein, The elliptic curve threshold digital signature phase includes the following steps: S1: After receiving the signature sub-private key sent by the old committee, each member of the new committee integrates it into a partial signature private key and calculates a partial signature public key; S2: The new committee uses the partial signature private key to partially sign the information based on the elliptic curve digital signature scheme; S3: The new committee integrates the partial signature by randomly selecting a signature combiner to obtain the threshold signature of the entire committee.
5. The method of claim 2, wherein, In S1, the committee that selects the polynomial is the old committee, and the signature sub-private key of the old committee needs to be sent to the new committee. When a member exits during the switching process between the old and new committees, the committee member who exits randomly selects a polynomial for distributed key generation. When a member joins during the switching process between the old and new committees, the committee member who joins before the switching process randomly selects a polynomial for distributed key generation.
6. The method of claim 3, wherein, The time period selection in the old-new committee switching process in S1 is adjusted based on the activity level of the current signing node, when the signing node is more active, the interval of dynamic threshold signature is shortened, and when the signing node is more stable, the interval of dynamic threshold signature can be appropriately expanded.