Multi-party collaborative blind signature method and system

By employing a multi-party collaborative blind signature method and utilizing the SM2 algorithm for blinding and deblinding, the issues of data security and privacy protection in multi-party signatures are resolved, thus achieving security and data integrity in the signing process.

CN120979674APending Publication Date: 2025-11-18BOYA ZHONGKE (BEIJING) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511151623.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-18
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

In multi-party electronic transactions, how can we ensure that the collaborating parties do not know the content of the message when signing, while also guaranteeing the security of the signature, the fairness of the participants, and preventing the original data from being tampered with or leaked?

Method used

A multi-party collaborative blind signature method is adopted. The public key is calculated by randomly selecting the private key, and the data is blinded. The SM2 algorithm is used to calculate the blinding factor and the public key. Each signer collaborates to blind sign the blinded data, and the data is deblinded and the validity is verified on the user end.

Benefits of technology

It achieves data security and privacy protection during multi-party signing, prevents data tampering, ensures the security of the signature, and even if some signer keys are leaked, the complete private key cannot be recovered. Secure signing can be achieved even when the user terminal has no hardware cryptographic computing capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979674A_ABST
    Figure CN120979674A_ABST
Patent Text Reader

Abstract

According to the multi-party collaborative blind signature method and system provided by the invention, the original data are blinded, and the blinded data are sent to the multi-party signature end for blind signature, so that the security problem of sensitive information in the related original data in the receiving, transmitting and processing processes during multi-party signature is solved, and the security of the sensitive information in the related original data is improved. Multiple signers do not know the content of the original data during signature, so that the original data cannot be tampered, after the signature is published, other signers except the user cannot track the signature, the details of the original data are hidden through blind signature, sensitive information in the original data is prevented from being tampered or leaked, and after multi-party collaborative signature is completed, the original data can not be tampered or leaked. And the user side performs blind removal on the blind signature result to obtain a signature of the original data, and then performs validity verification on the signature of the original data based on an SM2 algorithm. And when the verification is valid, the original data is not tampered, and the original data is ensured to be mastered by the user side in the whole signature process.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the field of cryptography, and particularly relates to a multi-party collaborative blind signature method and system. BACKGROUND

[0002] With the development of the Internet, more and more people send and process various information through mobile phones, computers and other computer devices to meet various life needs such as shopping, transferring, office work and the like. These electronic transactions provide convenience for people, but also bring some security risks, such as illegal collection and theft of personal privacy information, which seriously threatens the information security of people.

[0003] In order to improve the security of information sending, processing and storage and the like, defense technology and encryption technology and the like appear. The completion of electronic transactions usually involves multiple participants, and multiple participants need to sign the related messages at the same time, and at the same time, it is hoped that the collaborators do not know the message content when signing, and the collaborators cannot track the signature after the signature is disclosed. The security and fairness requirements of participants give birth to multi-party collaborative blind signature technology. SUMMARY

[0004] The main problem solved by the application is how to sign in the case of multiple participants and without knowing the message content, and a multi-party collaborative blind signature method and system are provided.

[0005] To solve the above technical problems, the technical scheme adopted is: The application provides a multi-party collaborative blind signature method, comprising the following steps: Step 1: each signature party randomly selects a large integer between [1, n-2] as a private key, i represents the i-th, and then calculates the public key P based on the private key of each signature party ; Step 2: the user blinds the original data M to obtain the blinded data ; Step 3: calculate the blinding factor u, the calculation method is that the user performs signature preprocessing based on the SM2 algorithm on the original data M to obtain the message digest e, and the user performs signature preprocessing based on the SM2 algorithm on the blinded data to obtain the message digest , and calculates the blinding factor n is the order number on the elliptic curve E based on the SM2 algorithm, and the blinding factor refers to a parameter participating in blind signature; Step 4: the user end takes the blinding factor as the user end private key, and calculates the user end public key through the blinding factor . And send U to the signatory; Step 5: Each signer collaborates to blind the data based on the user's public key U. Make blind signatures; Step 6: After each signer completes the collaborative blind signature, the user deblinds the blind signature to obtain the signature of the original data; Step 7: Verify the validity of the signature on the original data. If the verification is valid, the original data has not been tampered with.

[0006] Furthermore, based on each signer's own private key The method to calculate the public key P is: 1): Signatory Calculation based on SM2 algorithm public key ,make , Let Q1 be a point on the elliptic curve and send Q1 to the signer. G is the nth-order base point on the elliptic curve E based on the SM2 algorithm; 2): Signatory Calculation based on SM2 algorithm , then calculate , Let the points be on the elliptic curve, and let Send to the signatory ; 3): Signatory Calculation based on SM2 algorithm , then calculate , Let be a point on the elliptic curve, and... Send to the signatory ; ... N-1): Signatory Calculation based on SM2 algorithm , then calculate , Let be a point on the elliptic curve, and... Send to the signatory ; N) Signatory Calculation based on SM2 algorithm , then calculate ,make This makes P the actual public key corresponding to the collaborative signature.

[0007] Furthermore, the signatories collaborated on the blinded data. The method for performing blind signatures is as follows: The process of calculating the blind signature value r: 1) the signing party generates a random number , calculates an elliptic curve point based on the SM2 algorithm according to the random number and its own private key , and sends , U to the signing party ; 2) the signing party generates a random number , calculates an elliptic curve point based on the SM2 algorithm according to the random number and its own private key , and sends , U to the signing party ; 3) the signing party generates a random number , calculates an elliptic curve point based on the SM2 algorithm according to the random number and its own private key , and sends , U to the signing party ; … N-1) the signing party generates a random number , calculates an elliptic curve point based on the SM2 algorithm according to the random number and its own private key , and sends , U to the signing party ; N) the signing party generates a random number , calculates an elliptic curve point based on the SM2 algorithm according to the random number and its own private key , the signing party signs the blinded data for preprocessing to obtain a message digest , denoted as , and the coordinates of V are (x1, y1), and is calculated according to x1 and , if , then the N) step is performed again; the signature value calculation process: 1) the signing party calculates an intermediate parameter according to its own private key , , wherein represents the inverse element of modulo n on Fq; 2) the signing party calculates according to its own private key , , wherein represents inverse of n modulo Fq on Fq; 3) the signer according to the private key of itself calculating , wherein denotes inverse of n modulo Fq on Fq; … N-2) the signer A3 calculates , wherein denotes inverse of n modulo Fq on Fq; N-1) the signer A2 calculates calculating , wherein denotes inverse of n modulo Fq on Fq; N) the signer A1 calculates calculating , wherein denotes inverse of n modulo Fq on Fq, and wherein denotes data concatenation, which is the blind signature result.

[0008] Further, the method for the user to de-blind the blind signature is: the user end de-concatenates to obtain W1, WW1, and calculates , to obtain the signature value ); the signature value is the effective signature of the original data after de-blinding.

[0009] Further, the method for verifying the effectiveness of the signature of the original data is: Step 7.1: the original data M is pre-processed to obtain a message digest e; Step 7.2: calculating , if , the verification fails; Step 7.3: calculating , the coordinates of U are , calculating , if is established, the verification passes, otherwise the verification fails.

[0010] The application further provides a multi-party collaborative blind signature system, which uses a multi-party collaborative blind signature method to realize each step.

[0011] By adopting the technical scheme, the application has the following beneficial effects: The multi-party collaborative blind signature method and system provided by the application can solve the security problems of original data in the process of receiving and processing in multi-party signature, and the data content is unknown to the multi-party signers in the signature process, so that the original data is ensured not to be tampered with, the data details are hidden by blind signature, and the original data is prevented from being tampered with or leaked. In addition, the private keys of each signing party are independently distributed and stored in the collaborative blind signature, and as long as the key of one signing party is securely stored in hardware, the attacker cannot recover the complete signature private key even if the keys of other signing parties are leaked. Therefore, the collaborative blind signature can realize the secure signature of the original data in the case that the user has no hardware password operation capability, that is, the user end (such as a mobile phone, a mobile terminal, a PC terminal, etc.) becomes a signing party (such as an A1 signing party) in the collaborative blind signature by using a software password module. At this time, as long as the key of one of the other signing parties is securely stored in the hardware device, the signature security can be ensured. After all the signing parties complete the collaborative blind signature, the user end removes the blind signature result to obtain the signature of the original data, and then verifies the validity of the signature of the original data based on the SM2 algorithm. When the validity is verified, it indicates that the original data has not been tampered with, and at the same time, it is ensured that the original data is only in the hands of the user end in the whole signature process. BRIEF DESCRIPTION OF DRAWINGS

[0012] Figure 1 The system flowchart of the application is shown. DETAILED DESCRIPTION

[0013] The technical solutions of the application will be described clearly and completely in combination with the drawings. Obviously, the described embodiments are part of the embodiments of the application, rather than all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor belong to the protection scope of the application.

[0014] Figure 1 The specific embodiment of the multi-party collaborative blind signature method provided by the application is shown, which includes the following steps: Step 1: each signing party randomly selects a large integer between 1 and n-2 as a private key, i represents the i-th, and then calculates the public key P based on the private key of each signing party

[0015] ​In this embodiment, based on the private key of each signatory The method for calculating the public key P is: 1) Signatory Based on the SM2 algorithm to calculate The public key Let , be a point on the elliptic curve, and send Q1 to the signatory G is the base point of the elliptic curve E based on the SM2 algorithm n order; 2) Signatory Based on the SM2 algorithm to calculate The public key , and then calculate , be a point on the elliptic curve, and send to the signatory ; 3) Signatory Based on the SM2 algorithm to calculate The public key , and then calculate , be a point on the elliptic curve, and send to the signatory ; … N-1) Signatory Based on the SM2 algorithm to calculate The public key , and then calculate , be a point on the elliptic curve, and send to the signatory ; N) Signatory Based on the SM2 algorithm to calculate , and then calculate Let , so that P is the actual public key corresponding to the collaborative signature.

[0016] Step 2: The user blinds the original data M to obtain blinded data .

[0017] In this embodiment, blinding is to hide sensitive information in the original data at the user end, so that the blinded data is different from the original data. The way to hide sensitive information can be to delete the detailed description of the original data, to obtain blinded data by hiding operations such as blackening, desensitization, and encryption , obviously .

[0018] Step 3: Calculate the blinding factor u, the calculation method is that the user performs signature preprocessing based on the SM2 algorithm on the original data M to obtain a message digest e, and the user performs signature preprocessing based on the SM2 algorithm on the blinding data to obtain a message digest , and calculates the blinding factor n is the order on the elliptic curve E based on the SM2 algorithm, and the blinding factor refers to the parameter participating in the blinding signature. In this embodiment, the method of signature preprocessing is according to Chapter 6 “Generation Algorithm and Process of Digital Signature” in GB / T 32918.2-2016 “Information Security Technology SM2 Elliptic Curve Public Key Cryptography Part 2: Digital Signature Algorithm”. When signing, the pre-processing of the data to be signed is required according to the requirements of GB / T 35276-2017 “Information Security Technology SM2 Cryptographic Algorithm Usage Specification”.

[0019] Step 4: The user end calculates the user end public key based on the SM2 algorithm with the blinding factor as the user end private key, and sends U to the signature party.

[0020] In this embodiment, when the user end sends the blinding factor to the service end, in order to prevent the blinding factor from being leaked, the blinding factor is sent after being processed into a public key using the SM2 algorithm.

[0021] Step 5: Each signature party cooperates to perform blind signature on the blinding data based on the user end public key U. Since the blind signature is performed based on the user end public key U and the blinding data , each signature party cannot see the original data, thereby ensuring the security and privacy of the original data and preventing the original data from being tampered with.

[0022] In this embodiment, the method of each signature party performing blind signature on the blinding data is as follows: Blind signature value r calculation process: 1) Signature party generates a random number , calculates an elliptic curve point based on the SM2 algorithm according to the random number and its own private key, and sends and U to signature party ; 2) Signature party generates a random number , calculates an elliptic curve point based on the SM2 algorithm according to the random number and its own private key, and sends and U to signature party ;​ 3) Signatory Generate random numbers Elliptic curve points are calculated based on random numbers and the user's private key using the SM2 algorithm. and will U is sent to the signing party ; ... N-1) Signatory Generate random numbers Elliptic curve points are calculated based on random numbers and the user's private key using the SM2 algorithm. and will U is sent to the signing party ; N) Signatory Generate random numbers Elliptic curve points are calculated based on random numbers and the user's private key using the SM2 algorithm. Signatory Blinded data Perform signature preprocessing to obtain the message digest. ,remember The coordinates of V are (x1, y1), based on x1 and calculate ,like Then repeat step N); Signature value Calculation process: 1) Signatory Based on their own private key Calculate intermediate parameters , ,in express The inverse modulo n in Fq; 2) Signatory Calculate based on its own private key , ,in express The inverse modulo n in Fq; 3) Signatory Calculate based on its own private key , ,in express The inverse modulo n in Fq; ... (N-2) Signer A3 calculates based on their own private key , ,in express( The inverse of Fq modulo n; N-1) Signature A2 calculates , wherein represents the inverse element of n modulo on Fq; N) Signature A1 calculates , wherein represents the inverse element of n modulo on Fq, denoted as wherein represents data concatenation, i.e. the blind signature result.

[0023] Since the private keys of the respective signers in the collaborative blind signature are independently distributed, as long as the key of one signer is securely stored in hardware, the attacker cannot recover the complete signature private key even if the keys of other signers are leaked. Therefore, the collaborative blind signature can realize the secure signature of the original data without the hardware cryptographic operation capability of the user, i.e. the user end (such as a mobile phone, a mobile terminal, a PC terminal, etc.) becomes one signer (such as the A1 signer) in the collaborative blind signature by using a software cryptographic module. At this time, as long as the key of one of the other signers is securely stored in a hardware device, the signature security can be ensured. Obviously, the present example can solve the demand for secure signature without the hardware cryptographic operation capability of the user end.

[0024] Step 6: After the respective signers complete the collaborative blind signature, the user de-blinds the blind signature to obtain the signature of the original data.

[0025] In the present embodiment, the method for the user to de-blind the blind signature is as follows: The user end de-concatenates to obtain W1, WW1, and calculates according to the blinding factor , to obtain the signature value ); the signature value is the effective signature of the original data after de-blinding.

[0026] In this embodiment, data is blinded using a blinding factor, then blindly signed. After all signers complete the collaborative blind signing, the blind signature is deblinded using the blinding factor to obtain a collaborative signature of the original data from multiple signers. The validity of the signature is then verified to confirm its legitimacy. If the signature verification passes, it indicates that the original data has not been tampered with. Compared to the general SM2 signature, which requires preprocessing of the original data before signing, blind signing preprocesses the blinded data during the signing process. Clearly, blind signing better protects the privacy of the original data.

[0027] Step 7: Verify the validity of the signature on the original data. If the verification is valid, it indicates that the original data has not been tampered with.

[0028] In this embodiment, the method for validating the signature of the original data is a digital signature verification method based on the SM2 algorithm, specifically as follows: Step 7.1: Perform signature preprocessing on the original data M to obtain the message digest e; Step 7.2: Calculate intermediate parameters ,like If so, the verification fails; Step 7.3: Calculate the points on the elliptic curve The coordinates of U are ( ),calculate ,like If the result is true, the verification passes; otherwise, the verification fails.

[0029] The blind signature in the embodiment is a special cryptographic signature technology, and multiple signers sign information without knowing the specific content of the signature. A user can send the information to be signed to the multiple signers after performing “blinding” processing on the information, so that the multiple signatures are completed under the condition that the original data is kept secret. After the multiple signers collaboratively perform blind signature, the user performs “deblinding” on the signature, and finally obtains the effective signature of the original data. Therefore, the method ensures that the original data is kept in the user end, hides the data details through blind signature, and prevents the private information in the original data from being tampered with or leaked in the signature process. In addition, when the multiple signers collaboratively perform blind signature, the private keys of the signers are independently distributed and stored. As long as the key of one signer is securely stored in hardware, even if the keys of other signers are leaked, the attacker cannot recover the complete signature private key. Therefore, the collaborative blind signature can realize the secure signature of the original data without the hardware cryptographic operation capability of the user, that is, the user end (such as a mobile phone, a mobile terminal, a PC terminal, etc.) becomes one signer (such as an A1 signer) in the collaborative blind signature by using a software cryptographic module. At this time, as long as the key of one of the other signers is securely stored in a hardware device, the security of the signature can be ensured.

[0030] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for multi-party collaborative blind signature, characterized in that, Includes the following steps: Step 1: Each signatory Randomly select a large integer between [1, n-2] As the private key, i represents the i-th signer, and then based on each signer's own private key... Calculate the public key P, where n is the order on the elliptic curve E based on the SM2 algorithm; Step 2: The user blinds the original data M to obtain the blinded data. ; Step 3: Calculate the blinding factor u. The calculation method is as follows: the user performs signature preprocessing on the original data M based on the SM2 algorithm to obtain the message digest e, and the user performs blinding data... Perform signature preprocessing based on the SM2 algorithm to obtain the message digest. Calculate the blinding factor The blinding factor refers to the parameter involved in the blinding signature; Step 4: The user terminal uses the SM2 algorithm to adjust the blinding factor. As the user's private key, through the aforementioned blinding factor Calculate the client public key And send U to the signatory; Step 5: Each signer collaborates to blind the data based on the user's public key U. Make blind signatures; Step 6: After each signer completes the collaborative blind signature, the user deblinds the blind signature to obtain the signature of the original data; Step 7: Verify the validity of the signature on the original data. If the verification is valid, the original data has not been tampered with.

2. The method for multi-party collaborative blind signature according to claim 1, characterized in that, Based on each signer's own private key The method to calculate the public key P is: 1): Signatory Calculation based on SM2 algorithm public key ,make , Let Q1 be a point on the elliptic curve and send Q1 to the signer. G is the nth-order base point on the elliptic curve E based on the SM2 algorithm; 2): Signatory Calculation based on SM2 algorithm , then calculate , Let be a point on the elliptic curve, and... Send to the signatory ; 3): Signatory Calculation based on SM2 algorithm , then calculate , Let be a point on the elliptic curve, and... Send to the signatory ; …… N-1): Signatory Calculation based on SM2 algorithm , then calculate , Let be a point on the elliptic curve, and... Send to the signatory ; N) Signatory Calculation based on SM2 algorithm , then calculate ,make This makes P the actual public key corresponding to the collaborative signature.

3. The method for multi-party collaborative blind signature according to claim 2, characterized in that, The signatories collaborated on the blinding of the data. The method for performing blind signatures is as follows: The process of calculating the blind signature value r: 1) Signatory Generate random numbers Elliptic curve points are calculated based on random numbers and the user's private key using the SM2 algorithm. and will U is sent to the signing party ; 2) Signatory Generate random numbers Elliptic curve points are calculated based on random numbers and the user's private key using the SM2 algorithm. and will U is sent to the signing party ; 3) Signatory Generate random numbers Elliptic curve points are calculated based on random numbers and the user's private key using the SM2 algorithm. and will U is sent to the signing party ; …… N-1) Signatory Generate random numbers Elliptic curve points are calculated based on random numbers and the user's private key using the SM2 algorithm. and will U is sent to the signing party ; N) Signatory Generate random numbers Elliptic curve points are calculated based on random numbers and the user's private key using the SM2 algorithm. Signatory Blinded data Perform signature preprocessing to obtain the message digest. ,remember The coordinates of V are (x1, y1), based on x1 and calculate ,like Then repeat step N); Signature value Calculation process: 1) Signatory Based on their own private key Calculate intermediate parameters , ,in express The inverse modulo n in Fq; 2) Signatory Calculate based on its own private key , ,in express The inverse modulo n in Fq; 3) Signatory Calculate based on its own private key , ,in express The inverse modulo n in Fq; …… N-2) Signer A3 calculates based on their own private key , ,in express( The inverse of Fq modulo n; (N-1) Signer A2 calculates based on their own private key , ,in express The inverse modulo n in Fq; N) Signer A1 calculates based on their own private key , in express The inverse element modulo n over the finite field Fq is denoted by . ,in Indicates data concatenation. This is the result of a blind signature.

4. The method for multi-party collaborative blind signature according to claim 3, characterized in that, The method for users to deblind signatures is as follows: User-side desplicing We obtain W1 and WW1, and calculate... , , obtain the signature value ( ); signature value ( This is the valid signature of the original data after "deblinding".

5. The method for multi-party collaborative blind signature according to claim 3, characterized in that, The method for validating the signature of the original data is as follows: Step 7.1: Perform signature preprocessing on the original data M to obtain the message digest e; Step 7.2: Calculation ,like If so, the verification fails; Step 7.3: Calculation The coordinates of U are ( ),calculate ,like If the result is true, the verification passes; otherwise, the verification fails.

6. A multi-party collaborative blind signature system, characterized in that, The method is implemented using each step of the multi-party collaborative blind signature method as described in any one of claims 1 to 5.