Post-quantum threshold signature method and device based on DFORS algorithm, equipment and medium
By constructing a public-private key pair and generating a target public key using the DFORS algorithm, and combining this with a hash function to determine the post-quantum threshold signature value, the problem of insufficient security in existing post-quantum threshold signature schemes is solved, achieving higher security and reducing technical risks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CETC CYBERSPACE SECURITY TECH CO LTD
- Filing Date
- 2026-02-27
- Publication Date
- 2026-05-15
AI Technical Summary
There are few existing post-quantum threshold signature schemes, and they all rely on a single technical approach, primarily based on lattice cryptography algorithms. This makes it difficult to guarantee security and carries high technical risks.
A post-quantum threshold signature method based on the DFORS algorithm is adopted. A public-private key pair is constructed by using DFORS algorithm parameters and a preset hash tree. The target public key and the post-quantum threshold signature value are generated by combining the preset hash function, and the signature verification operation is performed.
It improves the security of post-quantum threshold signatures, reduces technical risks, provides multiple technical options, and the security of hash-based schemes does not depend on mathematically difficult problems, supporting the upgrading and replacement of hash functions.
Smart Images

Figure CN122053052A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to a post-quantum threshold signature method, apparatus, device, and medium based on the DFORS algorithm. Background Technology
[0002] Currently, most mainstream threshold signature algorithms are based on RSA (Rivest-Shamir-Adleman Algorithm, an asymmetric encryption algorithm) or elliptic curve cryptography, while existing encryption algorithms face security threats from quantum computing. Therefore, a threshold signature algorithm based on post-quantum cryptography provides a more secure multi-party computation solution for post-quantum migrations.
[0003] However, there are few existing post-quantum threshold signature schemes, and these schemes have a single technical approach, which is basically based on the design of lattice cryptography algorithms. Once the lattice difficulty problem is solved, the security of the signature scheme is difficult to guarantee, and the technical risks are high. Summary of the Invention
[0004] In view of this, the purpose of this invention is to provide a post-quantum threshold signature method, apparatus, device, and medium based on the DFORS algorithm, which can improve the security of post-quantum threshold signatures for messages and reduce the technical risks of post-quantum threshold signatures. The specific solution is as follows:
[0005] Firstly, this application provides a post-quantum threshold signature method based on the DFORS algorithm, applied to a target signer in a government affairs system, wherein the target signer is the last signer in the signer sequence corresponding to the government affairs message to be signed; the method includes:
[0006] For the government message to be signed, based on its own DFORS algorithm parameters and preset hash tree construction rules, the corresponding public and private key pair generation result is determined.
[0007] The target public key is determined based on the preset hash function, the public-private key pair generation result corresponding to itself, and the public-private key pair generation results received from other signers; the other signers are signers in the signer sequence other than the target signer.
[0008] After determining the target public key, the system receives the target signature data to be integrated corresponding to the government message to be signed, sent by the previous signer. Based on the target signature data to be integrated, the corresponding DFORS algorithm parameters, and the public-private key pair generation result, the system determines the target quantum threshold signature value. The target signature data to be integrated includes the signature data generated by the other signers.
[0009] The government message to be signed, the target post-quantum threshold signature value, and the target public key are sent to the signature verifier so that the signature verification operation corresponding to the target post-quantum threshold signature value can be triggered by the signature verifier.
[0010] Optionally, for the government message to be signed, determining the corresponding public-private key pair generation result based on its own DFORS algorithm parameters and preset hash tree construction rules includes:
[0011] For a government message to be signed, obtain its corresponding DFORS algorithm parameters; the DFORS algorithm parameters include key seed length, private key length, public key length, the height of the hash tree and the number of leaf nodes, and the number of signers corresponding to the government message to be signed;
[0012] Determine your own key seed based on the key seed length;
[0013] Based on the key seed, the number of signers, the private key length, the number of leaf nodes, and a preset pseudo-random function, determine its own private key set;
[0014] Based on the private key set, the first preset one-way function, and the one-way function output length in the DFORS algorithm parameters, determine the node value corresponding to each leaf node in its own hash tree;
[0015] Based on the tree height, the node value, and the binary Merkle tree structure, determine its own hash tree and the target root node value of the root node in the hash tree.
[0016] Optionally, determining the target public key based on a preset hash function, the public-private key pair generation result corresponding to itself, and the received public-private key pair generation results corresponding to other signers includes:
[0017] Receive the target root node value sent by the previous signer, which corresponds to each of the other signers;
[0018] Based on the target root node values corresponding to the other signers and itself, and using a preset hash function, the hash function output length in the DFORS algorithm parameters, and the public key length, the target public key corresponding to the government message to be signed is determined.
[0019] Optional, also includes:
[0020] The hash value of the first message is determined by the first signer in the signer sequence and based on the second preset one-way function and the government message to be signed; wherein the second preset one-way function is a one-way function carrying a hash key.
[0021] Based on the hash value of the first message and the preset function, determine the first signature private key index corresponding to itself;
[0022] The first signing party determines the first signing private key from its corresponding private key set based on the first signing private key index.
[0023] The first signer determines its own first leaf node based on the first signing private key and the first preset one-way function;
[0024] The first signer obtains the first path information from the first leaf node to the root node in the hash tree in its corresponding hash tree;
[0025] The first signer determines its own first signature data based on the first message hash value, the first signature private key, and the first path information.
[0026] The first signature data is sent to the second signature in the signature sequence via the first signature party.
[0027] Optional, also includes:
[0028] When the second signer is not the target signer, the first signature private key and the first message hash value are obtained from the first signature data through the second signer.
[0029] By using the second signer and based on the first signing private key, the hash key corresponding to the second preset one-way function is updated to determine the currently updated second preset one-way function;
[0030] The second signer determines its own second message hash value based on the currently updated second preset one-way function, the government message to be signed, and the first message hash value.
[0031] The second signer determines its own second signature private key index based on the second message hash value and the preset function;
[0032] The second signer determines the second signing private key from its corresponding private key set based on the second signing private key index.
[0033] The second signer determines its corresponding second leaf node based on the second signing private key and the second preset one-way function;
[0034] The second signer obtains the second path information from the second leaf node to the root node in the hash tree in its corresponding hash tree;
[0035] The second signer determines its own second signature data based on the second message hash value, the second signature private key, and the second path information;
[0036] The second signature data is sent to the third signature in the signature sequence via the second signature party.
[0037] Optionally, determining the target quantum threshold signature value based on the target signature data to be integrated, its corresponding DFORS algorithm parameters, and the public-private key pair generation result includes:
[0038] From the target signature data to be integrated, obtain the signature private key and message hash value corresponding to the previous signer;
[0039] Based on the signature private key corresponding to the previous signer, the hash key corresponding to the second preset one-way function is updated to determine the currently updated second preset one-way function;
[0040] Based on the currently updated second preset one-way function, the government message to be signed, and the message hash value corresponding to the previous signer, determine the target message hash value corresponding to itself;
[0041] Based on the target message hash value and the preset function, determine the target private key index corresponding to itself;
[0042] Based on the target private key index, the target private key is determined from the corresponding private key set;
[0043] Based on the target private key and the first preset one-way function, determine the target leaf node corresponding to itself;
[0044] In the corresponding hash tree, obtain the target path information from the target leaf node to the root node in the hash tree;
[0045] From the target signature data to be integrated, obtain the signature private key and path information corresponding to the other signers;
[0046] Based on the target private key and target path information corresponding to itself, as well as the signing private key and path information corresponding to the other signers, the target quantum threshold signature value is determined.
[0047] Optionally, triggering the signature verification operation corresponding to the target post-quantum threshold signature value through the signature verifier includes:
[0048] After receiving the government message to be signed, the target post-quantum threshold signature value, and the target public key from the target signer through the signature verification party,
[0049] The verification party, based on the second preset one-way function, the preset function, the government message to be signed, and the target post-quantum threshold signature value, performs path authentication to determine the root node value to be verified corresponding to each of the signatories.
[0050] The public key to be verified is determined by the signature verification party, based on the root node to be verified and the preset hash function;
[0051] The verification party determines whether the public key to be verified and the target public key are consistent, thereby determining the public key verification result.
[0052] Based on the public key judgment result, the signature verification operation corresponding to the target quantum threshold signature value is completed.
[0053] Secondly, this application provides a post-quantum threshold signature device based on the DFORS algorithm, applied to a target signer in a government affairs system, wherein the target signer is the last signer in the signer sequence corresponding to the government affairs message to be signed; the device includes:
[0054] The key pair generation module is used to determine the public-private key pair generation result for the government message to be signed based on its own DFORS algorithm parameters and preset hash tree construction rules.
[0055] The public key determination module is used to determine the target public key based on a preset hash function, the public-private key pair generation result corresponding to itself, and the public-private key pair generation result received from other signers; the other signers are signers in the signer sequence other than the target signer;
[0056] The signature value determination module is used to receive, after determining the target public key, the target signature data to be integrated corresponding to the government message to be signed sent by the previous signer, and determine the target quantum threshold signature value based on the target signature data to be integrated, the corresponding DFORS algorithm parameters, and the public-private key pair generation result; the target signature data to be integrated includes the signature data generated by the other signers;
[0057] The signature verification module is used to send the government message to be signed, the target post-quantum threshold signature value, and the target public key to the signature verifier, so that the signature verifier can trigger a signature verification operation corresponding to the target post-quantum threshold signature value.
[0058] Thirdly, this application provides an electronic device, comprising:
[0059] Memory, used to store computer programs;
[0060] A processor is configured to execute the computer program to implement the steps of the aforementioned post-quantum threshold signature method based on the DFORS algorithm.
[0061] Fourthly, this application provides a computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the steps of the aforementioned post-quantum threshold signature method based on the DFORS algorithm.
[0062] As can be seen, in this application, the target signer in the government affairs system is the last signer in the signer sequence corresponding to the government affairs message to be signed; the method includes: for the government affairs message to be signed, determining the public-private key pair generation result corresponding to itself based on its own DFORS algorithm parameters and preset hash tree construction rules; determining the target public key based on the preset hash function, the public-private key pair generation result corresponding to itself, and the received public-private key pair generation results corresponding to other signers; the other signers are the signers in the signer sequence other than the target signer. The signer, after determining the target public key, receives the target unintegrated signature data corresponding to the government message to be signed, sent by the previous signer. Based on the target unintegrated signature data, its own corresponding DFORS algorithm parameters, and the public-private key pair generation result, it determines the target post-quantum threshold signature value. The target unintegrated signature data includes the signature data generated by other signers. The government message to be signed, the target post-quantum threshold signature value, and the target public key are sent to the verification party so that the verification party can trigger the signature verification operation corresponding to the target post-quantum threshold signature value. In other words, in this application, the target signer first determines its own public-private key pair generation result for the government message to be signed using the DFORS algorithm parameters and preset hash tree construction rules, and then determines the target public key based on the preset hash function and the public-private key pair generation results corresponding to other signers. Subsequently, based on the target signature data to be integrated corresponding to the government message to be signed sent by the previous signer, as well as its own DFORS algorithm parameters and public-private key pair generation results, the target post-quantum threshold signature value corresponding to the government message to be signed is determined. Then, the government message to be signed, the target post-quantum threshold signature value, and the target public key are sent to the verification party so that the verification party can trigger the signature verification operation. This improves the security of post-quantum threshold signing of messages and reduces the technical risks associated with post-quantum threshold signing. Attached Figure Description
[0063] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0064] Figure 1 A flowchart of a post-quantum threshold signature method based on the DFORS algorithm is provided for this application;
[0065] Figure 2A flowchart of a specific post-quantum threshold signature method based on the DFORS algorithm is provided for this application;
[0066] Figure 3 A schematic diagram of a threshold signature algorithm framework provided in this application;
[0067] Figure 4 A schematic diagram of a hash tree provided for this application;
[0068] Figure 5 A schematic diagram of a post-quantum threshold signature device based on the DFORS algorithm provided for this application;
[0069] Figure 6 This application provides a structural diagram of an electronic device. Detailed Implementation
[0070] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0071] Existing post-quantum threshold signature schemes are few in number, and these schemes generally follow a single technical approach, primarily based on lattice cryptography algorithms. Once the lattice difficulty problem is solved, the security of the signature scheme cannot be guaranteed, and the technical risks are relatively high. Therefore, this application provides a post-quantum threshold signature scheme based on the DFORS algorithm, which can improve the security of post-quantum threshold signatures and reduce the technical risks associated with them.
[0072] See Figure 1 As shown, this embodiment of the invention discloses a post-quantum threshold signature method based on the DFORS algorithm, applied to the target signer in a government affairs system. The target signer is the last signer in the signer sequence corresponding to the government affairs message to be signed. The method includes:
[0073] Step S11: For the government message to be signed, based on its own DFORS algorithm parameters and preset hash tree construction rules, determine the corresponding public and private key pair generation result.
[0074] In this application, combined with Figure 2 As shown, each signer in the signing sequence generates a public-private key pair in turn using their respective key seed. Finally, the generated public-private key pairs are accumulated and transmitted to the designated signer in sequence to synthesize the overall public key. It is understandable that, since each signer generates public and private key pairs sequentially according to the order in the signer sequence during the key generation process, the designated signer is usually placed at the end of the signer sequence, that is, the target signer is used as the designated signer to synthesize the overall public key (represented by PK.root).
[0075] It is important to understand that, in this embodiment, the process of the target signer generating a public-private key pair includes: obtaining the corresponding DFORS algorithm parameters for the government message to be signed; the DFORS algorithm parameters include the key seed length, private key length, public key length, the height of the hash tree and the number of leaf nodes, and the number of signers corresponding to the government message to be signed; determining the key seed based on the key seed length; determining the private key set based on the key seed, the number of signers, the private key length, the number of leaf nodes, and a preset pseudo-random function; determining the node value corresponding to each leaf node in the hash tree based on the private key set, a first preset one-way function, and the one-way function output length in the DFORS algorithm parameters; and determining the hash tree and the target root node value of the root node in the hash tree based on the tree height, the node value, and the binary Merkle tree structure. The Merkle tree structure used in the DFORS algorithm can be a tree structure of the XMSS binary tree (Extended Merkle Signature Scheme), or it can be further optimized based on actual needs.
[0076] The XMSS binary tree is an XMSS binary Merkle tree structure with a height of [missing information]. It has +1 floor, there is a floor 0. = There are n leaf nodes (each with a size of n bits). And in the The layer has an n-bit root node. The node of the j-th layer is represented as... ,in ,and To construct the tree, each hash calculation uses a hash function G and a 2n-bit mask q. These bit masks are introduced to provide resistance to quadratic foreimages, and the reason for using a different bit mask for each hash calculation is to mitigate multi-target attacks.
[0077] Step S12: Determine the target public key based on the preset hash function, the public-private key pair generation result corresponding to itself, and the public-private key pair generation results received from other signer parties.
[0078] In this embodiment, other signers in the sequence send their generated public-private key pairs to the target signer. The target signer then uses a preset hash function and the public-private key pairs of each signer to generate the target public key. That is, the target signer receives the target root node values sent by the previous signer, which correspond to the other signers respectively. Based on the target root node values corresponding to the other signers and itself, and using the preset hash function, the hash function output length in the DFORS algorithm parameters, and the public key length, the target public key corresponding to the government message to be signed is determined.
[0079] Specifically, in one implementation, the DFORS algorithm parameters include: (1) n: security parameters, and the bit lengths of the key seed, public key, and private key, as well as the output bit lengths of the one-time one-way function F and the hash function G used; (2) : Number of signers, number of substrings in the input message; (3) : Height of the hash tree, bit length of the message substring; (4) : , representing the number of leaf nodes in each hash tree and the number of elements in the private key set of each signer; (5) : , is a one-way function carrying the key, where the subscript k is the key. That is, the signing sequence contains a total of Signature That is, government information that needs to be signed The key will only take effect after being signed sequentially. The key generation process can be summarized as follows:
[0080] 1) The (i+1)th signer in the signer sequence Generate key seed , ,calculate Then the private key set of the signer can be obtained as follows: ;
[0081] 2) Calculate based on private key ,get = Each value is used as a leaf node to construct a node of height. The XMSS binary tree is finally denoted as the root node. ;
[0082] 3) Front -1 signer will root node Send to the Signature , combined Figure 3 As shown, The target public key is calculated based on these root nodes. And made public, among which, This represents a concatenation in a binary bit string.
[0083] Step S13: After determining the target public key, receive the target signature data to be integrated corresponding to the government message to be signed sent by the previous signer, and determine the target quantum threshold signature value based on the target signature data to be integrated, the corresponding DFORS algorithm parameters and the public-private key pair generation result.
[0084] In this embodiment, combined with Figure 2 As shown, after determining the public key, each signer sequentially generates its own signature data and sends it to the next signer until the designated signer, i.e., the target signer, receives the signature data sent by the previous signer to synthesize a complete signature value. That is, from the target signature data to be integrated, the signing private key and message hash value corresponding to the previous signer are obtained; based on the signing private key corresponding to the previous signer, the hash key corresponding to the second preset one-way function is updated to determine the currently updated second preset one-way function; based on the currently updated second preset one-way function, the government message to be signed, and the message hash value corresponding to the previous signer, the target signer is determined. The process involves: determining the target private key index based on the target message hash value and the preset function; determining the target private key from the private key set based on the target private key index; determining the target leaf node based on the target private key and the first preset one-way function; obtaining the target path information from the target leaf node to the root node in the hash tree; obtaining the signing private key and path information corresponding to the other signers from the target signature data to be integrated; and determining the target post-quantum threshold signature value based on the target private key and target path information corresponding to itself, as well as the signing private key and path information corresponding to the other signers.
[0085] It is important to understand that during the signature generation process, for the first signer in the sequence, the signature generation process is as follows: The first signer in the signatureer sequence determines a first message hash value based on a second preset one-way function and the government message to be signed; wherein the second preset one-way function is a one-way function carrying a hash key; based on the first message hash value and the preset function, the first signature private key index corresponding to itself is determined; the first signer, based on the first signature private key index, determines a first signature private key from its corresponding private key set; the first signer, based on the first signature private key and the first preset one-way function, determines its corresponding first leaf node; the first signer, in its corresponding hash tree, obtains first path information from the first leaf node to the root node of the hash tree; the first signer, based on the first message hash value, the first signature private key, and the first path information, determines its corresponding first signature data; the first signer sends the first signature data to the second signer in the signatureer sequence.
[0086] Furthermore, for the second signer in the sequence, when the second signer is not the target signer, the signature generation process is as follows: The second signer obtains the first signing private key and the first message hash value from the first signature data; the second signer updates the hash key corresponding to the second preset one-way function based on the first signing private key to determine the currently updated second preset one-way function; the second signer determines its own corresponding second message hash value based on the currently updated second preset one-way function, the government message to be signed, and the first message hash value; the second signer determines its own corresponding second message hash value based on the second message hash value and the preset function. The second signature private key index is used; the second signature private key is determined from the private key set corresponding to itself by the second signature party and based on the second signature private key index; the second leaf node corresponding to itself is determined by the second signature party and based on the second signature private key and the second preset one-way function; the second path information from the second leaf node to the root node in the hash tree corresponding to itself is obtained by the second signature party; the second signature data corresponding to itself is determined by the second signature party and based on the second message hash value, the second signature private key and the second path information; the second signature data is sent to the third signature party in the signature party sequence by the second signature party. Wherein, the preset function is function z, assuming... Then there is .
[0087] Furthermore, in one specific implementation, the relevant steps of the above signature generation process can be as follows:
[0088] 1) Given a government message m to be signed, the first signer calculate Then, based on the index In its own private key set Select Signature Private Key And calculate the leaf nodes. And record the distance from the leaf node to the root node. path ,Pick ,Will As part of the signature, it is sent to the second signer. ;
[0089] 2) The second signatory calculate , Then, based on the index In its own private key set Select Signature Private Key Calculate the leaf nodes And record the distance from the leaf node to the root node. path ,Pick ,Will Send as a partial signature to the third signer ;
[0090] 3) The (i+1)th signer calculate Using the obtained hash value Calculate key index Then, based on the index In its own private key set Select Signature Private Key Calculate the leaf nodes And record the distance from the leaf node to the root node. path ,Pick ,Will Send a partial signature to the (i+2)th signer. ;
[0091] 4) And so on, the last signatory, i.e. the target signatory. After performing similar calculations, the final complete signature is output. .
[0092] In addition, regarding path information, combined with Figure 4 The image shows a binary hash tree, assuming it is the hash tree corresponding to a certain signer. =8. In the diagram, leaf node L3 (marked in black) is selected as the leaf node during signature generation, and the authentication path nodes related to L3 are marked in gray. The authentication path information corresponding to L3 is represented as follows: .
[0093] Step S14: Send the government message to be signed, the target post-quantum threshold signature value, and the target public key to the signature verifier so that the signature verification operation corresponding to the target post-quantum threshold signature value can be triggered by the signature verifier.
[0094] In this embodiment, the message and signature value are sent to the verifier (signature verifier) for verification. Specifically: after receiving the government message to be signed, the target post-quantum threshold signature value, and the target public key from the target signer through the verifier, the verifier performs path authentication based on the second preset one-way function, the preset function, the government message to be signed, and the target post-quantum threshold signature value to determine the root node value to be verified for each signer; the verifier determines the public key to be verified based on the root node to be verified and the preset hash function; the verifier determines whether the public key to be verified and the target public key are consistent to determine the public key judgment result; and based on the public key judgment result, the signature verification operation corresponding to the target post-quantum threshold signature value is completed.
[0095] It should be understood that, in one specific implementation, the relevant steps of the signature verification process may be as follows:
[0096] 1) For a given Verification and signing calculation Obtain the leaf index of the first hash tree. Then calculate Finally, based on the authentication path calculate ;
[0097] 2) Similarly, calculate the leaf index of each subsequent hash tree. And calculate based on the authentication path Finally, the calculation was completed. The key is compared with the target public key PK.root. If they match, the verification passes; otherwise, it fails.
[0098] Furthermore, it is understood that the solution proposed in this embodiment can be applied not only to government systems, but also to blockchain, finance, medical and other scenarios that require relevant threshold signatures. That is, the message to be signed can be a government message, or a blockchain message, a financial message, a medical message, etc.
[0099] In summary, this embodiment perfectly combines the DFORS algorithm structure with the distributed scenario. The DFORS algorithm signature private key is divided as follows: the private key corresponding to a tree is distributed to one signer. In this way, (1) the public key size is small, easy to understand and implement; (2) there is a breakthrough in the technical route, abandoning the conventional idea of designing threshold signature schemes based on lattice cryptography, and providing more technical options; (3) the security risk is reduced, the security of hash-based schemes does not depend on mathematical difficulties, but only on the hash function used, and the hash function can be upgraded and replaced.
[0100] Therefore, in this embodiment, the target signer first determines its own public-private key pair generation result for the government message to be signed using DFORS algorithm parameters and preset hash tree construction rules. It then combines this result with the public-private key pair generation results from other signers based on a preset hash function to determine the target public key. Next, based on the target unintegrated signature data corresponding to the government message to be signed sent by the previous signer, and its own corresponding DFORS algorithm parameters and public-private key pair generation result, it determines the target post-quantum threshold signature value for the government message to be signed. Finally, it sends the government message to be signed, the target post-quantum threshold signature value, and the target public key to the verification party, so that the verification party can trigger a signature verification operation. This improves the security of post-quantum threshold signing of messages and reduces the technical risks associated with post-quantum threshold signing.
[0101] See Figure 5 As shown in the figure, this application also discloses a post-quantum threshold signature device based on the DFORS algorithm, applied to a target signer in a government affairs system, wherein the target signer is the last signer in the signer sequence corresponding to the government affairs message to be signed; the device includes:
[0102] The key pair generation module 11 is used to determine the public-private key pair generation result of itself based on its corresponding DFORS algorithm parameters and preset hash tree construction rules for the government message to be signed.
[0103] The public key determination module 12 is used to determine the target public key based on a preset hash function, the public-private key pair generation result corresponding to itself, and the public-private key pair generation result received from other signers; the other signers are signers in the signer sequence other than the target signer.
[0104] The signature value determination module 13 is used to receive, after determining the target public key, the target signature data to be integrated corresponding to the government message to be signed sent by the previous signer, and determine the target quantum threshold signature value based on the target signature data to be integrated, the corresponding DFORS algorithm parameters and the public-private key pair generation result; the target signature data to be integrated includes the signature data generated by the other signers;
[0105] The signature verification module 14 is used to send the government message to be signed, the target post-quantum threshold signature value and the target public key to the signature verifier, so that the signature verifier can trigger the signature verification operation corresponding to the target post-quantum threshold signature value.
[0106] In some specific embodiments, the key pair generation module 11 may specifically include:
[0107] The parameter acquisition unit is used to acquire the DFORS algorithm parameters corresponding to the government message to be signed; the DFORS algorithm parameters include key seed length, private key length, public key length, tree height and number of leaf nodes of the hash tree, and the number of signers corresponding to the government message to be signed;
[0108] A seed determination unit is used to determine its own key seed based on the key seed length;
[0109] The private key determination unit is used to determine its own private key set based on the key seed, the number of signers, the length of the private key, the number of leaf nodes, and a preset pseudo-random function;
[0110] The node value determination unit is used to determine the node value corresponding to each leaf node in its own hash tree based on the private key set, the first preset one-way function and the one-way function output length in the DFORS algorithm parameters.
[0111] The root node determination unit is used to determine its own hash tree and the target root node value of the root node in the hash tree based on the tree height, the node value and the binary Merkle tree structure.
[0112] In some specific embodiments, the public key determination module 12 may specifically include:
[0113] A root node value receiving unit is used to receive the target root node values sent by the previous signer, which correspond to the values of the other signers respectively.
[0114] The public key determination unit is used to determine the target public key corresponding to the government message to be signed based on the target root node values corresponding to the other signers and itself, and using a preset hash function, the hash function output length in the DFORS algorithm parameters, and the public key length.
[0115] In some specific embodiments, the post-quantum threshold signature device based on the DFORS algorithm may further include:
[0116] The first hash value determination unit is used to determine the hash value of the first message by using the first signer in the signer sequence and based on the second preset one-way function and the government message to be signed; wherein the second preset one-way function is a one-way function carrying a hash key;
[0117] The first index determining unit is used to determine its own first signature private key index based on the hash value of the first message and a preset function;
[0118] The first private key determining unit is used to determine the first signing private key from the private key set corresponding to itself, based on the first signing party and the first signing private key index.
[0119] The first target node determining unit is used to determine its own first leaf node by means of the first signer and based on the first signing private key and the first preset one-way function;
[0120] The first path determination unit is used to obtain first path information from the first leaf node to the root node in the hash tree in the hash tree corresponding to the first signer.
[0121] The first signature determination unit is used to determine its own first signature data by means of the first signer and based on the first message hash value, the first signature private key and the first path information;
[0122] A signature sending unit is configured to send the first signature data to the second signature in the signature sequence via the first signature party.
[0123] In some specific embodiments, the post-quantum threshold signature device based on the DFORS algorithm may further include:
[0124] The first data acquisition unit is used to obtain the first signature private key and the first message hash value from the first signature data through the second signature party when the second signer does not belong to the target signer.
[0125] The first function update unit is used to update the hash key corresponding to the second preset one-way function by using the second signer and based on the first signing private key, so as to determine the currently updated second preset one-way function;
[0126] The second hash value determination unit is used to determine its own second message hash value by using the second signer and based on the currently updated second preset one-way function, the government message to be signed, and the first message hash value.
[0127] The second index determining unit is used to determine its own corresponding second signature private key index by using the second signer and based on the second message hash value and the preset function;
[0128] The second private key determination unit is used to determine the second signing private key from the private key set corresponding to itself, based on the second signing party and the second signing private key index.
[0129] The second target node determination unit is used to determine its own corresponding second leaf node by means of the second signer and based on the second signature private key and the second preset one-way function;
[0130] The second path determination unit is used to obtain second path information from the second leaf node to the root node in the hash tree in the hash tree corresponding to the second signer.
[0131] The signature determination unit is used to determine its own second signature data by using the second signer and based on the second message hash value, the second signature private key and the second path information;
[0132] A signature sending unit is used to send the second signature data to the third signature in the signature sequence via the second signature party.
[0133] In some specific embodiments, the signature value determination module 13 may specifically include:
[0134] The second data acquisition unit is used to acquire the signature private key and message hash value corresponding to the previous signer from the target signature data to be integrated;
[0135] The second function update unit is used to update the hash key corresponding to the second preset one-way function based on the signing private key corresponding to the previous signer, so as to determine the currently updated second preset one-way function;
[0136] The target hash value determination unit is used to determine its own target message hash value based on the currently updated second preset one-way function, the government message to be signed, and the message hash value corresponding to the previous signer.
[0137] The target index determination unit is used to determine its own target private key index based on the target message hash value and the preset function.
[0138] The target private key determination unit is used to determine the target private key from the private key set corresponding to itself based on the target private key index;
[0139] The target node determination unit is used to determine its own corresponding target leaf node based on the target private key and the first preset one-way function;
[0140] The target path determination unit is used to obtain the target path information from the target leaf node to the root node in the hash tree in its corresponding hash tree;
[0141] The private key and path acquisition unit is used to acquire the signature private key and path information corresponding to the other signers from the target signature data to be integrated;
[0142] The signature value determination unit is used to determine the target post-quantum threshold signature value based on the target private key and the target path information corresponding to itself, as well as the signature private key and the path information corresponding to the other signers.
[0143] In some specific embodiments, the signature verification module 14 may specifically include:
[0144] The data receiving unit is configured to, after receiving the government message to be signed, the target post-quantum threshold signature value, and the target public key sent by the target signer through the signature verifier,
[0145] The root node value determination unit is used to determine the root node value to be verified for each signer by performing path authentication based on the signer and the second preset one-way function, the preset function, the government message to be signed, and the target post-quantum threshold signature value.
[0146] The public key determination unit is used to determine the public key to be verified by the signature verifier and based on the root node to be verified and the preset hash function.
[0147] The judgment unit is used to determine whether the public key to be verified and the target public key are consistent through the signature verification party, so as to determine the public key judgment result;
[0148] The verification completion unit is used to complete the signature verification operation corresponding to the target post-quantum threshold signature value based on the public key judgment result.
[0149] Furthermore, embodiments of this application also disclose an electronic device, Figure 6 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.
[0150] Figure 6 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the post-quantum threshold signature method based on the DFORS algorithm disclosed in any of the foregoing embodiments. Alternatively, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0151] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.
[0152] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0153] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the post-quantum threshold signature method based on the DFORS algorithm disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.
[0154] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned disclosed post-quantum threshold signature method based on the DFORS algorithm. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.
[0155] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.
[0156] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0157] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0158] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0159] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A post-quantum threshold signature method based on the DFORS algorithm, characterized in that, The method is applied to a target signer in a government affairs system, wherein the target signer is the last signer in the signer sequence corresponding to the government affairs message to be signed; the method includes: For the government message to be signed, based on its own DFORS algorithm parameters and preset hash tree construction rules, the corresponding public and private key pair generation result is determined. The target public key is determined based on the preset hash function, the public-private key pair generation result corresponding to itself, and the public-private key pair generation results received from other signers; the other signers are signers in the signer sequence other than the target signer. After determining the target public key, the system receives the target signature data to be integrated corresponding to the government message to be signed, sent by the previous signer. Based on the target signature data to be integrated, the corresponding DFORS algorithm parameters, and the public-private key pair generation result, the system determines the target quantum threshold signature value. The target signature data to be integrated includes the signature data generated by the other signers. The government message to be signed, the target post-quantum threshold signature value, and the target public key are sent to the signature verifier so that the signature verification operation corresponding to the target post-quantum threshold signature value can be triggered by the signature verifier.
2. The post-quantum threshold signature method based on the DFORS algorithm according to claim 1, characterized in that, The process of determining the public-private key pair generation result for the government message to be signed, based on its corresponding DFORS algorithm parameters and preset hash tree construction rules, includes: For a government message to be signed, obtain its corresponding DFORS algorithm parameters; the DFORS algorithm parameters include key seed length, private key length, public key length, the height of the hash tree and the number of leaf nodes, and the number of signers corresponding to the government message to be signed; Determine your own key seed based on the key seed length; Based on the key seed, the number of signers, the private key length, the number of leaf nodes, and a preset pseudo-random function, determine its own private key set; Based on the private key set, the first preset one-way function, and the one-way function output length in the DFORS algorithm parameters, determine the node value corresponding to each leaf node in its own hash tree; Based on the tree height, the node value, and the binary Merkle tree structure, determine its own hash tree and the target root node value of the root node in the hash tree.
3. The post-quantum threshold signature method based on the DFORS algorithm according to claim 2, characterized in that, The process of determining the target public key based on the preset hash function, the public-private key pair generation result corresponding to itself, and the received public-private key pair generation results corresponding to other signers includes: Receive the target root node value sent by the previous signer, which corresponds to each of the other signers; Based on the target root node values corresponding to the other signers and itself, and using a preset hash function, the hash function output length in the DFORS algorithm parameters, and the public key length, the target public key corresponding to the government message to be signed is determined.
4. The post-quantum threshold signature method based on the DFORS algorithm according to claim 3, characterized in that, Also includes: The hash value of the first message is determined by the first signer in the signer sequence and based on the second preset one-way function and the government message to be signed; wherein the second preset one-way function is a one-way function carrying a hash key. Based on the hash value of the first message and the preset function, determine the first signature private key index corresponding to itself; The first signing party determines the first signing private key from its corresponding private key set based on the first signing private key index. The first signer determines its own first leaf node based on the first signing private key and the first preset one-way function; The first signer obtains the first path information from the first leaf node to the root node in the hash tree in its corresponding hash tree; The first signer determines its own first signature data based on the first message hash value, the first signature private key, and the first path information. The first signature data is sent to the second signature in the signature sequence via the first signature party.
5. The post-quantum threshold signature method based on the DFORS algorithm according to claim 4, characterized in that, Also includes: When the second signer is not the target signer, the first signature private key and the first message hash value are obtained from the first signature data through the second signer. By using the second signer and based on the first signing private key, the hash key corresponding to the second preset one-way function is updated to determine the currently updated second preset one-way function; The second signer determines its own second message hash value based on the currently updated second preset one-way function, the government message to be signed, and the first message hash value. The second signer determines its own second signature private key index based on the second message hash value and the preset function; The second signer determines the second signing private key from its corresponding private key set based on the second signing private key index. The second signer determines its corresponding second leaf node based on the second signing private key and the second preset one-way function; The second signer obtains the second path information from the second leaf node to the root node in the hash tree in its corresponding hash tree; The second signer determines its own second signature data based on the second message hash value, the second signature private key, and the second path information; The second signature data is sent to the third signature in the signature sequence via the second signature party.
6. The post-quantum threshold signature method based on the DFORS algorithm according to claim 5, characterized in that, The process of determining the target quantum threshold signature value based on the target signature data to be integrated, the corresponding DFORS algorithm parameters, and the public-private key pair generation result includes: From the target signature data to be integrated, obtain the signature private key and message hash value corresponding to the previous signer; Based on the signature private key corresponding to the previous signer, the hash key corresponding to the second preset one-way function is updated to determine the currently updated second preset one-way function; Based on the currently updated second preset one-way function, the government message to be signed, and the message hash value corresponding to the previous signer, determine the target message hash value corresponding to itself; Based on the target message hash value and the preset function, determine the target private key index corresponding to itself; Based on the target private key index, the target private key is determined from the corresponding private key set; Based on the target private key and the first preset one-way function, determine the target leaf node corresponding to itself; In the corresponding hash tree, obtain the target path information from the target leaf node to the root node in the hash tree; From the target signature data to be integrated, obtain the signature private key and path information corresponding to the other signers; Based on the target private key and target path information corresponding to itself, as well as the signing private key and path information corresponding to the other signers, the target quantum threshold signature value is determined.
7. The post-quantum threshold signature method based on the DFORS algorithm according to any one of claims 4 to 6, characterized in that, The step of triggering a signature verification operation corresponding to the target post-quantum threshold signature value through the signature verifier includes: After receiving the government message to be signed, the target post-quantum threshold signature value, and the target public key from the target signer through the signature verification party, The verification party, based on the second preset one-way function, the preset function, the government message to be signed, and the target post-quantum threshold signature value, performs path authentication to determine the root node value to be verified corresponding to each of the signatories. The public key to be verified is determined by the signature verification party, based on the root node to be verified and the preset hash function; The verification party determines whether the public key to be verified and the target public key are consistent, thereby determining the public key verification result. Based on the public key judgment result, the signature verification operation corresponding to the target quantum threshold signature value is completed.
8. A post-quantum threshold signature device based on the DFORS algorithm, characterized in that, The target signer is used in the government affairs system, where the target signer is the last signer in the signer sequence corresponding to the government affairs message to be signed. The device includes: The key pair generation module is used to determine the public-private key pair generation result for the government message to be signed based on its own DFORS algorithm parameters and preset hash tree construction rules. The public key determination module is used to determine the target public key based on a preset hash function, the public-private key pair generation result corresponding to itself, and the public-private key pair generation result received from other signers; the other signers are signers in the signer sequence other than the target signer; The signature value determination module is used to receive, after determining the target public key, the target signature data to be integrated corresponding to the government message to be signed sent by the previous signer, and determine the target quantum threshold signature value based on the target signature data to be integrated, the corresponding DFORS algorithm parameters, and the public-private key pair generation result; the target signature data to be integrated includes the signature data generated by the other signers; The signature verification module is used to send the government message to be signed, the target post-quantum threshold signature value, and the target public key to the signature verifier, so that the signature verifier can trigger a signature verification operation corresponding to the target post-quantum threshold signature value.
9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the post-quantum threshold signature method based on the DFORS algorithm as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, Used to store a computer program, which, when executed by a processor, implements the post-quantum threshold signature method based on the DFORS algorithm as described in any one of claims 1 to 7.