High-throughput national cipher SM2 threshold signature method

By using the high-throughput national cryptographic SM2 threshold signature method, and leveraging techniques such as long-term key generation and bilinear mapping, signatures can be generated in batches within a single protocol. This addresses the shortcomings of the national cryptographic SM2 threshold signature scheme in terms of efficiency and security, and is suitable for high-concurrency scenarios such as blockchain transaction clearing and IoT device authentication.

CN120880652APending Publication Date: 2025-10-31XIDIAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511106111.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-08
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

The existing national cryptographic standard SM2 threshold signature scheme is insufficient in terms of efficiency and identification of malicious nodes, making it difficult to apply to high-concurrency scenarios such as blockchain transaction clearing and IoT device authentication.

Method used

The high-throughput national cryptographic SM2 threshold signature method is adopted. Through long-term key generation, random number and public value generation, signature generation and signature aggregation modules, batch signature generation in a single protocol is realized. Bilinear mapping and super invertible matrix are used to improve security and efficiency.

Benefits of technology

It enables the generation of multiple signatures in a single protocol, reducing communication and computational complexity, and can quickly identify and defend against malicious nodes, making it suitable for high-concurrency scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880652A_ABST
    Figure CN120880652A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of passwords, in particular to a high-throughput national password SM2 threshold signature method, which comprises the following steps of: calculating a long-term key share of each participant; each dealer independently selects a random polynomial, generates a random number share based on the random polynomial, encrypts the random number share by using public keys of other participants, and broadcasts a generated first ciphertext; the shareholder decrypts and verifies the received first ciphertext, and calculates and broadcasts a common value share under the condition that the verification is passed; in a parallel environment, based on the random number share and the common value share, calculating signature shares of all participants, and broadcasting the signature shares in a broadcast channel; signature shares in a broadcast channel are collected and verified by a participant, and after sufficient valid signature shares are collected, all signatures are obtained based on the collected valid signature shares. According to the method, multiple signatures can be generated in batches in single protocol operation, and the efficiency limitation of signature generation is broken through.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cryptography, and in particular to a high-throughput national cryptographic standard SM2 threshold signature method. Background Technology

[0002] Threshold signatures are a distributed cryptographic protocol whose core characteristic is that when the number of honest parties participating in the signature reaches a pre-set threshold, the parties can jointly generate a valid signature; otherwise, no signature can be generated. This signature technology is particularly suitable for critical scenarios requiring collective decision-making and risk diversification, such as multi-party contract signing, joint authorization, and digital wallet management. Currently, many threshold signature schemes based on different underlying digital signature algorithms have been proposed. Wang Guilin et al., based on interpolation formulas in the rational number field, presented a signature scheme requiring threshold RSA (asymmetric encryption algorithm). This scheme is simple, secure, and can verify the correctness of partial signatures. Xu Qiuliang et al. constructed a new threshold RSA signature scheme by introducing additional parameters to identify the authenticity of "partial signatures." This scheme can prevent legitimate share holders from maliciously providing illegal partial signatures, thereby interfering with the signing process. Wu Shuiqing et al. proposed a Schnorr threshold signature scheme based on ECC (Elliptic Curve Cryptography) and analyzed its security. Chen Chunhua et al. proposed a threshold signature scheme based on the standard ECDSA, which has many advantages of threshold and ECC, and can securely and efficiently generate legitimate signatures multiple times by sharing the signature private key once. Peng Qingjun et al., based on an improved elliptic curve digital signature algorithm, constructed a verifiable threshold signature scheme based on ECC using Pedersen verifiable threshold secret sharing technology. This scheme features high robustness, lower communication cost, and high execution efficiency.

[0003] Currently, threshold signature schemes based on internationally accepted signature algorithms (such as RSA, ECDSA, and Schnorr) are relatively mature, but research on thresholding schemes for the Chinese national cryptographic standard SM2 is relatively scarce. SM2 is my country's elliptic curve public-key cryptography standard, encompassing digital signatures, key exchange, and public-key encryption, playing a crucial role in the development and use of commercial cryptographic algorithms in my country. In existing research, Yan Jie et al. proposed a threshold SM2 signature scheme without a trusted center based on the assumption of honesty among most participants, but this scheme suffers from low efficiency and the inability to identify malicious nodes. Liang Huiqiang et al. proposed a non-interactive scheme with identifiable termination, but this scheme is complex to implement and requires multiple rounds of communication. Wang Yalong et al. proposed an SM2 digital signature generation scheme with verifiable evidence encryption, applicable to scenarios such as blockchain conditional payments and financial adjudication; however, existing schemes, including this one, can only generate a signature for a single message per run. When there are many messages to sign (e.g., blockchain transfers), the signing efficiency decreases linearly with the number of signatures, making it unsuitable for batch signing scenarios. Summary of the Invention

[0004] In view of this, embodiments of this application propose a high-throughput national cryptographic SM2 threshold signature method, which can generate multiple signatures in batches during a single protocol run, breaking through the efficiency limitation of single message signature, and providing domestic cryptographic infrastructure support for high-concurrency scenarios such as blockchain transaction clearing and IoT device authentication.

[0005] In a first aspect, embodiments of this application propose a high-throughput national cryptographic SM2 threshold signature method, comprising: generating a long-term key for each participant and calculating the long-term key share for each participant; each distributor independently selects a random polynomial, generates a random number share based on the selected random polynomial, encrypts the random number share using the public keys of other participants, and broadcasts the generated first ciphertext; shareholders decrypt and verify the received first ciphertext, and if the verification is successful, calculate the public value share and broadcast it, while simultaneously verifying the public value shares of other shareholders using a bilinear mapping; in a parallel environment, based on the random number share and the public value share, calculate the signature shares of all participants at once and broadcast them in the broadcast channel; participants collect and verify the signature shares in the broadcast channel, and after collecting valid signature shares that meet a preset minimum collection threshold, obtain all signatures based on the collected valid signature shares.

[0006] In some optional embodiments, long-term key generation is performed for each participant, and the long-term key share for each participant is calculated, including: Each participant independently and randomly selects a degree. The packed polynomial, for the th For each participant, the selected packing polynomial This can be expressed by the formula: ; ; ; in, The total number of participants. For the preset threshold, For the number of identical secrets, As the independent variable, for A finite field of order, It is a large prime number; based on Calculate the secret share of other participants And secretly shared it with them; among them, ; The following formula is used, based on the secret sharing with all other participants to the [number]th [participant]. Secret share of each participant Perform a summation calculation to obtain the first... Long-term key share for each participant: ; in, Indicates the first Long-term key share of each participant.

[0007] In some optional embodiments, each distributor independently selects a random polynomial, generates a random number share based on the selected random polynomial, encrypts the random number share using the public keys of other participants, and broadcasts the generated first ciphertext, including: Each distributor independently selects three degrees respectively. , , The random polynomial, for the th Distributor In particular, the three random polynomials selected are as follows: , , , It's a package A polynomial of different secrets; in which the distributor is the participant in the secret sharing; Calculate using the following formulas respectively , , polynomial commitments , , : ; ; ; in, It is the order. Elliptic curve group of 1st base point, It is a large prime number; based on , , Calculate the random number share separately , , ; in, , , ; Using the public keys of other participants To each , , Encrypt to obtain , , ; in, , , , Indicates the use of Encrypt; Will , , and , , Combined, the first ciphertext is generated and broadcast to the broadcast channel; The first ciphertext is represented as: .

[0008] In some optional embodiments, a shareholder decrypts and verifies the received first ciphertext. If the verification passes, the public value share is calculated and broadcast. Simultaneously, a bilinear mapping is used to verify the public value shares of other shareholders, including: shareholder After receiving the first ciphertext from the broadcast channel, use your own private key. Decrypting the first ciphertext yields... , , , , , Shareholders are those who receive the secrets and participate in signing. Indicates using Decrypt; verify Is it equal to , Is it equal to ,as well as Is it equal to , , , For the corresponding Lagrange coefficients; exist , , If all verifications pass, an empty set is broadcast to the broadcast channel to indicate acceptance; otherwise, a verifiable and valid complaint is broadcast to the broadcast channel to complain about the corresponding corrupt dealer. After the consensus agreement is finalized, a set of honest dealers is obtained. , A group composed of corrupt dealers and a group consisting of honest shareholders. ; Honest shareholders Locally calculated random number share , Simultaneously calculate group elements Based on , , Calculate common value share And broadcast it to the broadcast channel; , , , , This can be expressed by the formula: ; ; ; ; ; in, It is a superinvertible matrix. , , The value is a preset integer; Using bilinear mapping to verify the public value share of other honest shareholders, when collecting... After determining the public value share of each other valid honest shareholder, the public value is calculated by interpolation. ; Public Value This can be expressed by the formula: ; in, It is the Lagrange multiplier. It is arbitrary inclusion A set of effective public value shares.

[0009] In some optional embodiments, based on the random number share and the public value share, the signature shares of all participants are calculated at once and broadcast in the broadcast channel, including: enter One message In a parallel environment, for each Honest Shareholders Perform the following steps: calculate , ; Will Packed in degrees polynomial In, and will As their own share; of which satisfy , Based on their own share Calculate your own signature share After the calculation is completed, all participants broadcast their signature share in the broadcast channel; This can be expressed by the formula: .

[0010] In some optional embodiments, participants collect and verify signature shares in the broadcast channel. After collecting a preset minimum collection threshold of valid signature shares, all signatures are obtained based on the collected valid signature shares, including: Honest shareholders collect signature shares in the broadcast channel and verify the collected signature shares using a bilinear mapping. In collected After collecting a number of valid signature shares, local interpolation is performed based on these valid signature shares to calculate a signature polynomial to obtain all signatures; where each signature polynomial contains A signature is output after the consensus protocol ends. A signature.

[0011] In some alternative embodiments, Honest shareholders In order to generate random number share It is necessary to ensure the set after the consensus protocol ends. At least one An honest dealer.

[0012] This application proposes a high-throughput SM2 threshold signature method, achieving high-throughput SM2 threshold signature for the first time. This allows multiple signatures to be generated in a single protocol run, making it suitable for batch message signing scenarios. This application only requires one long-term key generation, which is reused in subsequent signature protocols, focusing the efficiency bottleneck on the generation of temporary random numbers and effectively reducing communication and computational complexity. This application uses a verifiable public-key encryption algorithm on the broadcast channel, ensuring that participants can quickly identify and defend against attacks from malicious nodes. In a parallel signature environment, a key aspect of ensuring security is that participants add different secret values ​​to the signature shares to be broadcast, essentially making the coefficients of the two product polynomials completely random again. This method eliminates the linear correlation between signature shares and solves the problem of incomplete randomization of polynomial coefficients without affecting the final signature. Compared to traditional secret sharing, packaged secret sharing embeds more secrets, allowing multiple secrets to be obtained in a single secret sharing. The introduction of superinvertible matrices is also aimed at obtaining more random numbers. In practice, instead of simply summing the secret shares, these secret shares are multiplied by the superinvertible matrix before summing. This method increases the number of generated random numbers from a single number to multiple numbers. In summary, this application overcomes the efficiency limitations of single message signatures, providing domestically developed cryptographic infrastructure support for high-concurrency scenarios such as blockchain transaction clearing and IoT device authentication.

[0013] Secondly, embodiments of this application propose a high-throughput national cryptographic SM2 threshold signature system, comprising: a long-term key generation module, a random number and public value generation module, a signature generation module, and a signature aggregation module; the long-term key generation module is used to generate a long-term key for each participant and calculate the long-term key share for each participant; the random number and public value generation module is used for each distributor to independently select a random polynomial, generate a random number share based on the selected random polynomial, encrypt the random number share using the public key of other participants, and broadcast the generated first ciphertext, which is then decrypted and verified by shareholders. If the verification is successful, the public value share is calculated and broadcast, while simultaneously verifying the public value shares of other shareholders using a bilinear mapping; the signature generation module is used to calculate the signature shares of all participants at once in a parallel environment based on the random number share and public value share and broadcast them in the broadcast channel; the signature aggregation module is used for participants to collect and verify the signature shares in the broadcast channel, and after collecting a set minimum collection threshold of valid signature shares, obtain all signatures based on the collected valid signature shares.

[0014] Thirdly, embodiments of this application provide an electronic device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform a high-throughput national cryptographic SM2 threshold signature method as described in the first aspect above.

[0015] Fourthly, embodiments of this application propose a computer-readable storage medium storing a computer program that, when executed by a processor, can implement a high-throughput national cryptographic SM2 threshold signature method as described in the first aspect above.

[0016] It is understood that the beneficial effects of the second to fourth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies of this application will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is a flowchart of a high-throughput national cryptographic SM2 threshold signature method provided in one embodiment of this application; Figure 2 This is a flowchart of a multi-set consensus protocol provided in one embodiment of this application; Figure 3 This is a structural diagram of a high-throughput national cryptographic SM2 threshold signature system provided in another embodiment of this application; Figure 4 This is a structural diagram of an electronic device provided in another embodiment of this application. Detailed Implementation

[0019] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the various embodiments of this application will be described in detail below with reference to the accompanying drawings. In the various embodiments of this application, many technical details are presented to enable the reader to better understand this application. However, even without these technical details and various variations and modifications based on the following embodiments, the technical solutions claimed in this application can be implemented. The division of the following embodiments is only for convenience of description and should not constitute any limitation on the specific implementation of this application. The various embodiments can be combined with and referenced by each other without contradiction.

[0020] One embodiment of this application proposes a high-throughput SM2 threshold signature method for use on a server. The implementation details of this high-throughput SM2 threshold signature method are described below. These details are provided for ease of understanding and are not essential for implementing this solution. The specific flow of the high-throughput SM2 threshold signature method proposed in this embodiment can be as follows: Figure 1 As shown, it includes: Step 101: Generate a long-term key for each participant and calculate the long-term key share for each participant.

[0021] In practical implementation, for consensus scenarios, let there be a total of One participant, The value is an integer greater than 2. The server needs to generate a long-term key for each participant and calculate the long-term key share for each participant.

[0022] In one example, each participant in the consensus scenario independently and randomly selects a degree. Packed polynomials.

[0023] For the For each participant, the selected packing polynomial This can be expressed by the formula: , , ; in, The total number of participants. For the preset threshold, For the number of identical secrets, As the independent variable, for A finite field of order, It is a large prime number.

[0024] For the The packed polynomial selected by each participant In other words, it satisfies: ; in, Indicates the first Long-term key share of each participant.

[0025] After completing the selection of the packing polynomial, the first... Each participant needs to be based on Calculate the secret share of other participants And secretly shared it with them, .

[0026] Finally, the following formula is used, based on the secret sharing among all other participants with the [number]th [participant]. Secret share of each participant Perform a summation calculation to obtain the first... Long-term key share for each participant: ; in, Indicates the first Long-term key share of each participant.

[0027] Step 102: Each distributor independently selects a random polynomial, generates a random number share based on the selected random polynomial, encrypts the random number share using the public keys of other participants, and broadcasts the generated first ciphertext.

[0028] In the specific implementation, after the participants complete the calculation of the long-term key share, each dealer (the dealer is the participant who shares the secret) will independently select a random polynomial, generate a random number share based on the selected random polynomial, encrypt the random number share using the public key of other participants, and broadcast the generated first ciphertext.

[0029] In one example, each distributor independently selects three degrees as follows: , , The random polynomial, for the th Distributor ( In this regard, the three random polynomials selected are as follows: , , , It's a package A different secret polynomial, this The secrets are respectively , , , , , satisfy .

[0030] Then, calculate using the following formulas respectively. , , polynomial commitments , , : ; ; ; in, It is the order. Elliptic curve group of 1st base point, It is a large prime number.

[0031] Next, based on the following formula, , , Calculate the random number share separately , , : , , .

[0032] Then, using the public keys of other participants, the following formula is used. To each , , Encrypt to obtain , , : , , ; in, Indicates the use of Encrypt it.

[0033] Finally, , , and , , Combined, the first ciphertext is generated and broadcast to the broadcast channel.

[0034] The first ciphertext is represented as: .

[0035] Step 103: The shareholder decrypts and verifies the received first ciphertext. If the verification is successful, the public value share is calculated and broadcast. At the same time, the public value share of other shareholders is verified using bilinear mapping.

[0036] In the specific implementation, shareholders (participants who receive the secret and participate in signing) receive the first ciphertext from the broadcast channel in real time, decrypt and verify the received first ciphertext, and if the verification is successful, calculate the public value share and broadcast it, while using bilinear mapping to verify the public value share of other shareholders.

[0037] In one example, shareholders After receiving the first ciphertext from the broadcast channel, you can use your own private key. Decrypting the first ciphertext yields... , , .

[0038] in, , , , Indicates using Decryption is performed.

[0039] Next, verification Is it equal to , Is it equal to ,as well as Is it equal to , , , is the corresponding Lagrange coefficient.

[0040] After the consensus agreement is finalized, a set of honest dealers is obtained. , A group composed of corrupt dealers and a group consisting of honest shareholders. .

[0041] After that, Honest shareholders Locally calculated random number share , Simultaneously calculate group elements Based on , , Calculate common value share And broadcast it to the broadcast channel.

[0042] , , , , This can be expressed by the formula: ; ; ; ; ; in, It is a superinvertible matrix. , , It is a preset integer.

[0043] Finally, the common value share of other honest shareholders is verified using a bilinear mapping, i.e., verification. Is it equal to When collecting After determining the public value share of each other valid honest shareholder, the public value is calculated by interpolation. .

[0044] Public Value This can be expressed by the formula: ; in, It is the Lagrange multiplier. It is arbitrary inclusion A set of effective public value shares.

[0045] Step 104: In a parallel environment, based on the random number share and the public value share, calculate the signature share of all participants at once and broadcast it in the broadcast channel.

[0046] In the specific implementation, after the calculation of the random number share and the public value share is completed, the signature share of all participants can be calculated at once and broadcast in the broadcast channel in a parallel environment based on the random number share and the public value share.

[0047] In one example, suppose the input One message In a parallel environment, for each Honest Shareholders The following steps will be performed: First, calculate , ; Next, Packed in degrees polynomial In, and will As their own share. It should be noted that... satisfy .

[0048] Finally, based on their own share Calculate your own signature share After the calculation is completed, all participants broadcast their signature share in the broadcast channel.

[0049] This can be expressed by the formula: .

[0050] In one example, the process of a multi-set consensus protocol can be as follows: Figure 2 As shown. Shareholders Continuously add the dealer who first initiated the broadcast to each set. In, until satisfied ( ), that is, to perform an operation .shareholder Broadcast a message containing information about All verifiable complaints against corrupt dealers are collected. If no corrupt dealer is found, an empty set is broadcast, indicating that all verifications of secret shares are valid. When the previous... After a valid complaint is filed by a shareholder, the operation will be carried out. , , . judge If true, output the set. , and Otherwise, proceed to the next step. Keep and Unchanged, will Set to empty set. Continue adding new distributors to the previously uninitiated broad list. In the middle, until That is, to perform an operation .shareholder Broadcast a message containing information about All verifiable complaints against corrupt dealers are collected. If no corrupt dealer is found, an empty set is broadcast, indicating that all verifications of secret shares are valid. When the previous set is collected again... After a valid complaint is filed by a shareholder, the operation will be carried out. , , Finally, output the set. and Then terminate the consensus protocol.

[0051] Step 105: Participants collect and verify signature shares in the broadcast channel. After collecting a set minimum collection threshold of valid signature shares, all signatures are obtained based on the collected valid signature shares.

[0052] In the specific implementation, after the calculation and broadcasting of the signature share are completed, the participants collect and verify the signature shares in the broadcast channel. After collecting a set minimum collection threshold of valid signature shares, all signatures are obtained based on the collected valid signature shares.

[0053] In one example, honest shareholders Collect signature shares from the broadcast channel, and verify the collected signature shares using a bilinear mapping, i.e., verification. Is it equal to .

[0054] For each After collecting After collecting a number of valid signature shares, local interpolation is performed based on these valid signature shares to calculate a signature polynomial to obtain all signatures; where each signature polynomial contains A signature is output after the consensus protocol ends. A signature. If set... Therefore, this embodiment can generate consensus protocols in a single run. A signature.

[0055] It's important to note that the generation of random numbers is unrelated to the degree of the polynomial, but rather to the number of honest dealers in the set required to calculate the secret share. Therefore, shareholders need to generate... random number share It is necessary to ensure the set after the consensus protocol ends. At least one An honest dealer.

[0056] In the multi-set consensus protocol used in this embodiment, participants can reach a consensus on a set consisting of specific dealers and shareholders, and then use these sets to calculate secret shares. To achieve this, after the consensus protocol concludes, we only need to... There is An honest dealer, and to , There are no special requirements, as long as there are honest dealers. Therefore, we will initially focus on the number of dealers who initiate the broadcast. Set as This ensures that at least one of the first batch of added distributors is honest (at most...). (A corrupt distributor). Therefore, after the first round of screening, it can be guaranteed that the group... , The number of honest dealers in the system is greater than or equal to 1, but is not certain. Is there any in China? One honest reseller. After evaluation, if the criteria are not met, continue adding new resellers who have not yet initiated a broadcast. In the middle, until This ensures that even if it exists Even a corrupt distributor could make it possible to succeed after the second round of screening. The number of honest dealers in the middle meets the requirements .

[0057] This embodiment proposes a high-throughput SM2 threshold signature method, achieving high-throughput SM2 threshold signature for the first time. This allows multiple signatures to be generated in a single protocol run, making it suitable for batch message signing scenarios. This embodiment only requires one long-term key generation, which is reused in subsequent signature protocols, focusing the efficiency bottleneck on the generation of temporary random numbers and effectively reducing communication and computational complexity. This embodiment uses a verifiable public-key encryption algorithm on the broadcast channel, ensuring that participants can quickly identify and defend against attacks from malicious nodes. In a parallel signature environment, a key aspect of ensuring security is that participants add different secret values ​​to the signature shares to be broadcast, essentially making the coefficients of the two product polynomials completely random again. This method eliminates the linear correlation between signature shares and solves the problem of incomplete randomization of polynomial coefficients without affecting the final signature. Compared to traditional secret sharing, packaged secret sharing embeds more secrets, allowing multiple secrets to be obtained in a single secret sharing. The introduction of superinvertible matrices is also aimed at obtaining more random numbers. Specifically, instead of simply summing the secret shares, the method multiplies these secret shares by the superinvertible matrix and then sums them. This increases the number of generated random numbers from a single number to multiple numbers. In summary, this embodiment overcomes the efficiency limitations of single message signatures, providing domestically developed cryptographic infrastructure support for high-concurrency scenarios such as blockchain transaction clearing and IoT device authentication.

[0058] The steps described above are for clarity only. In practice, they can be combined into one step or broken down into multiple steps, as long as they involve the same logical relationship, they are all within the scope of protection of this application. Any insignificant modifications or introductions to the algorithm or process that do not change the core design of the algorithm and process are also within the scope of protection of this application.

[0059] Another embodiment of this application proposes a high-throughput national cryptographic SM2 threshold signature system. The implementation details of the high-throughput national cryptographic SM2 threshold signature system proposed in this embodiment are described in detail below. The following implementation details are provided for ease of understanding and are not necessary for implementing this example. Figure 3 This is a schematic diagram of the structure of a high-throughput national cryptographic SM2 threshold signature system proposed in this embodiment. The system includes: a long-term key generation module 201, a random number and public value generation module 202, a signature generation module 203, and a signature aggregation module 204.

[0060] The long-term key generation module 201 is used to generate a long-term key for each participant and calculate the long-term key share for each participant.

[0061] The random number and public value generation module 202 is used for each dealer to independently select a random polynomial, generate random number shares based on the selected random polynomial, encrypt the random number shares using the public keys of other participants, and broadcast the generated first ciphertext. Shareholders decrypt and verify the received first ciphertext. If the verification is successful, the public value shares are calculated and broadcast. At the same time, the public value shares of other shareholders are verified using a bilinear mapping.

[0062] The signature generation module 203 is used to calculate the signature share of all participants at once and broadcast it in the broadcast channel in a parallel environment, based on the random number share and the public value share.

[0063] The signature aggregation module 204 is used by participants to collect and verify signature shares in the broadcast channel. After collecting a set minimum collection threshold of valid signature shares, it obtains all signatures based on the collected valid signature shares.

[0064] It is worth mentioning that all modules involved in this embodiment are logical modules. In practical applications, a logical unit can be a physical unit, a part of a physical unit, or a combination of multiple physical units. Furthermore, to highlight the innovative aspects of this application, this embodiment does not introduce units that are not closely related to solving the technical problems proposed in this application; however, this does not mean that other units are absent in this embodiment.

[0065] It is not difficult to see that this embodiment is a system embodiment corresponding to the above method embodiments, and this embodiment can be implemented in conjunction with the above method embodiments. The relevant technical details and technical effects mentioned in the above method embodiments are still valid in this embodiment, and will not be repeated here to reduce repetition. Accordingly, the relevant technical details mentioned in this embodiment can also be applied to the above method embodiments.

[0066] Another embodiment of this application proposes an electronic device, the specific structure of which is as follows: Figure 4 As shown, it includes: at least one processor 301; and a memory 302 communicatively connected to the at least one processor 301; wherein the memory 302 stores instructions executable by the at least one processor 301, the instructions being executed by the at least one processor 301 to enable the at least one processor 301 to execute a high-throughput national cryptographic SM2 threshold signature method as described in the above method embodiment.

[0067] The memory and processor can be connected via a bus, which can include any number of interconnecting buses and bridges, connecting various circuits of one or more processors and the memory. The bus can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and will not be described further herein. The bus interface is responsible for providing an interface between the bus and the transceiver. The transceiver can be a single component or multiple components, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by the processor is transmitted over the wireless medium via an antenna, which further receives data and transmits it to the processor.

[0068] The processor manages the bus and general processing, and also provides various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. Memory is used to store data used by the processor during operation.

[0069] Another embodiment of this application proposes a computer-readable storage medium storing a computer program that, when executed by a processor, can implement a high-throughput national cryptographic SM2 threshold signature method as described in the above method embodiments.

[0070] That is, those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a device (such as a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, portable hard drive, ROM (Read-Only Memory), RAM (Random Access Memory), magnetic disk, or optical disk.

[0071] Those skilled in the art will understand that the above embodiments are specific embodiments for implementing this application, and in practical applications, various changes can be made to them in form and detail without departing from the spirit and scope of this application.

Claims

1. A high-throughput national cryptographic SM2 threshold signature method, characterized in that, include: For each participant, a long-term key is generated, and the long-term key share for each participant is calculated. Each distributor independently selects a random polynomial, generates a random number share based on the selected random polynomial, encrypts the random number share using the public keys of other participants, and broadcasts the generated first ciphertext. The shareholders decrypt and verify the first ciphertext they receive. If the verification is successful, they calculate the public value share and broadcast it. At the same time, they use bilinear mapping to verify the public value share of other shareholders. In a parallel environment, based on random number shares and public value shares, the signature shares of all participants are calculated at once and broadcast in the broadcast channel; Participants collect and verify signature shares in the broadcast channel. After collecting a set minimum collection threshold of valid signature shares, all signatures are obtained based on the collected valid signature shares.

2. The high-throughput national cryptographic SM2 threshold signature method according to claim 1, characterized in that, Long-term key generation is performed for each participant, and the long-term key share for each participant is calculated, including: Each participant independently and randomly selects a degree. The packed polynomial, for the th For each participant, the selected packing polynomial This can be expressed by the formula: ; ; ; in, The total number of participants. For the preset threshold, For the number of identical secrets, As the independent variable, for A finite field of order, It is a large prime number; based on Calculate the secret share of other participants And secretly shared it with them; among them, ; The following formula is used, based on the secret sharing with all other participants to the [number]th [participant]. Secret share of each participant Perform a summation calculation to obtain the first... Long-term key share for each participant: ; in, Indicates the first Long-term key share of each participant.

3. The high-throughput national cryptographic SM2 threshold signature method according to claim 2, characterized in that, Each distributor independently selects a random polynomial, generates a random number share based on the selected random polynomial, encrypts the random number share using the public keys of other participants, and broadcasts the generated first ciphertext, including: Each distributor independently selects three degrees respectively. , , The random polynomial, for the th Distributor In particular, the three random polynomials selected are as follows: , , , It's a package A polynomial of different secrets; in which the distributor is the participant in the secret sharing; Calculate using the following formulas respectively , , polynomial commitments , , : ; ; ; in, It is the order. Elliptic curve group of 1st base point, It is a large prime number; based on , , Calculate the random number share separately , , ; in, , , ; Using the public keys of other participants To each , , Encrypt to obtain , , ; in, , , , Indicates the use of Encrypt; Will , , and , , Combined, the first ciphertext is generated and broadcast to the broadcast channel; The first ciphertext is represented as: .

4. The high-throughput national cryptographic SM2 threshold signature method according to claim 3, characterized in that, The first ciphertext received by a shareholder is decrypted and verified. If the verification passes, the public value share is calculated and broadcast. Simultaneously, a bilinear mapping is used to verify the public value shares of other shareholders, including: shareholder After receiving the first ciphertext from the broadcast channel, use your own private key. Decrypting the first ciphertext yields... , , , , , Shareholders are those who receive the secrets and participate in signing. Indicates using Decrypt; verify Is it equal to , Is it equal to ,as well as Is it equal to , , , For the corresponding Lagrange coefficients; exist , , If all verifications pass, an empty set is broadcast to the broadcast channel to indicate acceptance; otherwise, a verifiable and valid complaint is broadcast to the broadcast channel to complain about the corresponding corrupt dealer. After the consensus agreement is finalized, a set of honest dealers is obtained. , A group composed of corrupt dealers and a group consisting of honest shareholders. ; Honest shareholders Locally calculated random number share , Simultaneously calculate group elements Based on , , Calculate common value share And broadcast it to the broadcast channel; , , , , This can be expressed by the formula: ; ; ; ; ; in, It is a superinvertible matrix. , , The value is a preset integer; Using bilinear mapping to verify the public value share of other honest shareholders, when collecting... After determining the public value share of each other valid honest shareholder, the public value is calculated by interpolation. ; Public Value This can be expressed by the formula: ; in, It is the Lagrange multiplier. It is arbitrary inclusion A set of effective public value shares.

5. A high-throughput national cryptographic SM2 threshold signature method according to claim 4, characterized in that, In a parallel environment, based on random number shares and public value shares, the signature shares of all participants are calculated at once and broadcast in the broadcast channel, including: enter One message In a parallel environment, for each Honest Shareholders Perform the following steps: calculate , ; Will Packed in degrees polynomial In, and will As their own share; of which satisfy , Based on their own share Calculate your own signature share After the calculation is completed, all participants broadcast their signature share in the broadcast channel; This can be expressed by the formula: .

6. The high-throughput national cryptographic SM2 threshold signature method according to claim 5, characterized in that, Participants collect and verify signature shares in the broadcast channel. After collecting a preset minimum collection threshold of valid signature shares, all signatures are obtained based on the collected valid signature shares, including: Honest shareholders collect signature shares in the broadcast channel and verify the collected signature shares using a bilinear mapping. In collected After collecting a number of valid signature shares, local interpolation is performed based on these valid signature shares to calculate a signature polynomial to obtain all signatures; where each signature polynomial contains A signature is output after the consensus protocol ends. A signature.

7. A high-throughput national cryptographic SM2 threshold signature method according to claim 6, characterized in that, Honest shareholders In order to generate random number share It is necessary to ensure the set after the consensus protocol ends. At least one An honest dealer.

8. A high-throughput national cryptographic SM2 threshold signature system, characterized in that, include: The long-term key generation module is used to generate long-term keys for each participant and calculate the long-term key share for each participant. The random number and public value generation module is used for each dealer to independently select a random polynomial, generate a random number share based on the selected random polynomial, encrypt the random number share using the public key of other participants, and broadcast the generated first ciphertext. Shareholders decrypt and verify the received first ciphertext. If the verification is successful, the public value share is calculated and broadcast. At the same time, the public value share of other shareholders is verified using a bilinear mapping. The signature generation module is used to calculate the signature share of all participants at once and broadcast it in the broadcast channel in a parallel environment, based on the random number share and the public value share. The signature aggregation module is used by participants to collect and verify signature shares in the broadcast channel. After collecting a set minimum collection threshold of valid signature shares, all signatures are obtained based on the collected valid signature shares.

9. An electronic device, characterized in that, include: At least one processor; And, a memory communicatively connected to the at least one processor; The memory stores instructions that can be executed by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform a high-throughput national cryptographic SM2 threshold signature method as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it can implement a high-throughput national cryptographic SM2 threshold signature method as described in any one of claims 1 to 7.